Malware

Win32/LockScreen.AAT removal tips

Malware Removal

The Win32/LockScreen.AAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.AAT virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Win32/LockScreen.AAT?


File Info:

crc32: ADA61646
md5: 0e0295ad1fe91587e15bfc3aa9fb250d
name: 0E0295AD1FE91587E15BFC3AA9FB250D.mlw
sha1: ade8f43332c9a43f55d4ef771355d672376b96c9
sha256: 6141b53c561f45b18575a15cf82de6bb355883f251d7c53acd9cb1e1e3795772
sha512: 24f51a39a7195c30627087bdb8bc7c96c3093eca5dc66537da6e3fa7c5493cdeda9d72460a65c0a3cde142a9054f83bd8a1eeacca88b72cb6db9e9d4784eeebc
ssdeep: 768:5GqhjaCb1jFjekEmG66Fsih3H9KaUfDruh4yhnMTXEnC5vuRXDaMkkoMM4SPNQY:QcaClJekEDsuXY5KhbnTnYCmMkaSXd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/LockScreen.AAT also known as:

BkavW32.RansomTO.Fam.Trojan
K7AntiVirusTrojan ( 0055e4091 )
LionicTrojan.Win32.HmBlocker.lwU0
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Gamania.45868
CynetMalicious (score: 100)
CAT-QuickHealTrojanDropper.Wlock.AA6
ALYacGen:Variant.Palevo.6
CylanceUnsafe
ZillyaTrojan.HmBlocker.Win32.1070
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/HmBlocker.5cf3da20
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.d1fe91
CyrenW32/Ransom.E.gen!Eldorado
SymantecTrojan.Ransomlock
ESET-NOD32a variant of Win32/LockScreen.AAT
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.HmBlocker.afs
BitDefenderGen:Variant.Palevo.6
NANO-AntivirusTrojan.Win32.Winlock.bsinq
MicroWorld-eScanGen:Variant.Palevo.6
TencentWin32.Trojan.Hmblocker.Fhy
Ad-AwareGen:Variant.Palevo.6
SophosMal/Generic-R + Mal/Agent-IE
ComodoTrojWare.Win32.Trojan.Ransom.~B@465pcw
BitDefenderThetaAI:Packer.7852FED31F
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_WLOCK.SM2
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.0e0295ad1fe91587
EmsisoftGen:Variant.Palevo.6 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/HmBlocker.cq
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.254B78
KingsoftWin32.Troj.Dialer.b.(kcloud)
MicrosoftTrojanDropper:Win32/Wlock.A
GDataGen:Variant.Palevo.6
AhnLab-V3Trojan/Win32.HmBlocker.R2314
McAfeeArtemis!0E0295AD1FE9
MAXmalware (ai score=100)
VBA32OScope.Trojan.PornoBlocker.Restarter
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_WLOCK.SM2
RisingAdware.Dialer!1.99F1 (CLASSIC)
YandexTrojan.GenAsa!AZtTaYFYKmA
IkarusTrojan-Ransom.HmBlocker
MaxSecureTrojan.Malware.5823814.susgen
FortinetW32/Kryptik.19500!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Ransom.Generic.HwsBPRMA

How to remove Win32/LockScreen.AAT?

Win32/LockScreen.AAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment