Malware

Win32/LockScreen.AAI removal tips

Malware Removal

The Win32/LockScreen.AAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.AAI virus can do?

  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com
r8—sn-bpb5oxu-3c2r.gvt1.com
update.googleapis.com

How to determine Win32/LockScreen.AAI?


File Info:

crc32: C0DA1615
md5: bb143a5ebaf804edb48fc0675a17109e
name: BB143A5EBAF804EDB48FC0675A17109E.mlw
sha1: 92145f858ba0abf24b358539c207e90c78ee77db
sha256: 477a825da4177c9b81b50d403fd87e2d93c9bb0451b5bf01f0fa0b394e87ecaa
sha512: 4b96d7865b3ab0b8ae62dc0aca9c117697370bcf74788c7e2644325d7c6e3755a4e3f4158f1b5476dff0b1060aeaf665f6780de5cd64121ba3516b631a79a3c5
ssdeep: 768:9tW7kZz4dVWR/HXqb5DspiMwadl1tdKmUoONhM8Qwdkw8+XvED/n9pJtq1jSyNd:DW7kZz4ax31dnKx1zMokwuHJANdwV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/LockScreen.AAI also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e4091 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed.317
CynetMalicious (score: 100)
CAT-QuickHealTrojanDropper.Wlock.AA6
ALYacGen:Variant.Ser.Mikey.2065
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.8206
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/HmBlocker.38074013
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.ebaf80
CyrenW32/Ransom.E.gen!Eldorado
SymantecTrojan.Ransomlock
ESET-NOD32a variant of Win32/LockScreen.AAI
APEXMalicious
AvastWin32:LockScreen-DE [Trj]
KasperskyTrojan-Ransom.Win32.HmBlocker.aqj
BitDefenderGen:Variant.Ser.Mikey.2065
NANO-AntivirusTrojan.Win32.Winlock.bsinq
ViRobotTrojan.Win32.A.HmBlocker.49152.B
MicroWorld-eScanGen:Variant.Ser.Mikey.2065
TencentWin32.Trojan.Hmblocker.Pezc
Ad-AwareGen:Variant.Ser.Mikey.2065
SophosMal/Generic-S
ComodoTrojWare.Win32.Trojan.Ransom.~B@465pcw
F-SecureTrojan.TR/Ransom.ace
BitDefenderThetaAI:Packer.319642661F
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.bb143a5ebaf804ed
EmsisoftGen:Variant.Ser.Mikey.2065 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/HmBlocker.bmj
AviraTR/Ransom.ace
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.179FD0
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftRansom:Win32/Genasom.FF
ArcabitTrojan.Ser.Mikey.D811
AegisLabTrojan.Win32.HmBlocker.lkxD
ZoneAlarmTrojan-Ransom.Win32.HmBlocker.aqj
GDataGen:Variant.Ser.Mikey.2065
AhnLab-V3Trojan/Win32.HmBlocker.R2314
Acronissuspicious
McAfeeRansom-AA
MAXmalware (ai score=100)
VBA32OScope.Trojan.PornoBlocker.Restarter
MalwarebytesMalware.Heuristic.1006
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!RxlE2kuTsl8
IkarusTrojan-Ransom.HmBlocker
FortinetW32/Kryptik.19500!tr
AVGWin32:LockScreen-DE [Trj]
Paloaltogeneric.ml

How to remove Win32/LockScreen.AAI?

Win32/LockScreen.AAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment