Malware

Win32/LockScreen.ABO (file analysis)

Malware Removal

The Win32/LockScreen.ABO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.ABO virus can do?

  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/LockScreen.ABO?


File Info:

crc32: F382587E
md5: 0ded277701d2055fea635dce81de4b34
name: 0DED277701D2055FEA635DCE81DE4B34.mlw
sha1: 99ebde5992cb6879e9d88230ad333c4809fc56e1
sha256: b8e32f36eb4632815858cdfa9907f2ce3d33837f5f30a9371546e2772d4fc9da
sha512: 004a42a4d5c6a463e67b3250d868056908144529970ef296f7240b2ce1e7276cac4df3f0cbf322784afd6b7b1c9f5b85e847fa78d285b60d419818d87dc23136
ssdeep: 6144:J4rhk3Qi52SBsimmsGJJ7iVTEcUahucFYkLdHHexabB5g5KimJin7pwUR/YQUh:JpQi52SBs710JZcD5ReMNu5Ft7iQu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/LockScreen.ABO also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.2868
CynetMalicious (score: 100)
CAT-QuickHealRansom.GenasomIH.S15898821
ALYacGen:Variant.Barys.673
CylanceUnsafe
ZillyaTrojan.Fullscreen.Win32.31
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Birele.270a3193
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.701d20
BaiduWin32.Trojan.LockScreen.bm
CyrenW32/Trojan.CWDU-1290
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.ABO
APEXMalicious
AvastWin32:Delf-UFJ [Trj]
ClamAVWin.Trojan.Ransom-4951
KasperskyTrojan-Ransom.Win32.Birele.fz
BitDefenderGen:Variant.Barys.673
NANO-AntivirusTrojan.Win32.Fullscreen.cdkba
MicroWorld-eScanGen:Variant.Barys.673
TencentTrojan.Win32.LockScreen.abo
Ad-AwareGen:Variant.Barys.673
SophosML/PE-A + Troj/Ransom-AFZ
ComodoTrojWare.Win32.LockScreen.ABO@4qbrjn
BitDefenderThetaGen:NN.ZelphiF.34796.GKW@aCAt8JdQ
VIPRETrojan.Win32.Ransom.c (v)
TrendMicroTROJ_RANSOM.SMC1
McAfee-GW-EditionBehavesLike.Win32.Infected.hh
FireEyeGeneric.mg.0ded277701d2055f
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Fullscreen.ag
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASMalwS.20218
MicrosoftRansom:Win32/Genasom.CN
ArcabitTrojan.Barys.673
ZoneAlarmTrojan-Ransom.Win32.Birele.fz
GDataGen:Variant.Barys.673
AhnLab-V3Trojan/Win32.Scar.R16731
McAfeeGeneric.dyu
MAXmalware (ai score=100)
VBA32Hoax.Birele
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RANSOM.SMC1
RisingTrojan.Generic@ML.90 (RDML:MnlBkbH0YrKtQ7g7ldRlug)
YandexTrojan.GenAsa!TEFHsbpF6SQ
IkarusTrojan-Ransom.Fullscreen
FortinetW32/Birele.FZ!tr
AVGWin32:Delf-UFJ [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Birele.HgIASOcA

How to remove Win32/LockScreen.ABO?

Win32/LockScreen.ABO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment