Malware

Win32/LockScreen.AEE removal tips

Malware Removal

The Win32/LockScreen.AEE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.AEE virus can do?

  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/LockScreen.AEE?


File Info:

name: 512D325C7457059C533F.mlw
path: /opt/CAPEv2/storage/binaries/bcb1037559fb80416ae87e199a9baf7a52785b2ad984bcf184a28e6daecf2bb8
crc32: 6EDAE90C
md5: 512d325c7457059c533f681325915661
sha1: ad4593c4f3aefd74a298899aa54235f3c4aa5012
sha256: bcb1037559fb80416ae87e199a9baf7a52785b2ad984bcf184a28e6daecf2bb8
sha512: ceffe3e50d9c5865ccf3793e2993d7917925a5a4874e05cf9585da017c4d742ea173e26f52fb24a90b26fb1fef7437f9f12a6da06585c6d8464d799a1c525f20
ssdeep: 768:63VE0yY6pgwDp3OZkJSUM50vvAli4tgtXSt53hK1Fk+O42iED8ndfxLqVZuiBjlD:63CPFSxmXInc2T6Fk+/d5Wxl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A535B1777A0F133D06248702424AB93196EBA30677244DBFB895EFA9E312E74B29753
sha3_384: 5c9a7149f821b25e81ea82111962fae683ae366d037293d49be762ec38182eea51c0010c763058932d08202c469faf4b
ep_bytes: e877180000e989feffff8bff558bec83
timestamp: 2011-02-22 14:00:29

Version Info:

0: [No Data]

Win32/LockScreen.AEE also known as:

LionicTrojan.Win32.HmBlocker.lkxD
AVGWin32:Ransom-CR [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.3084
MicroWorld-eScanGen:Variant.Doina.10388
FireEyeGeneric.mg.512d325c7457059c
SkyhighRansom-AA
McAfeeRansom-AA
ZillyaTrojan.HmBlocker.Win32.435
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 0055e4091 )
AlibabaRansom:Win32/LockScreen.85e6e42e
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.c74570
BitDefenderThetaGen:NN.ZexaF.36802.duW@ai3q6Bhk
VirITTrojan.Win32.Generic.CDTK
SymantecTrojan.Ransomlock
ESET-NOD32Win32/LockScreen.AEE
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Doina.10388
NANO-AntivirusTrojan.Win32.LockScreen.bxzug
AvastWin32:Ransom-CR [Trj]
TencentWin32.Trojan.Lockscreen.Psmw
EmsisoftGen:Variant.Doina.10388 (B)
F-SecureTrojan.TR/Fraud.Gen2
VIPREGen:Variant.Doina.10388
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Ransom.HmBlocker
JiangminTrojan/HmBlocker.aak
WebrootW32.Malware.Gen
VaristW32/Ransom.F.gen!Eldorado
AviraTR/Fraud.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.HmBlocker
KingsoftWin32.Trojan.Generic.a
MicrosoftRansom:Win32/LockScreen.gen!B
XcitiumTrojWare.Win32.Trojan.Ransom.~B@465pcw
ArcabitTrojan.Doina.D2894
ViRobotTrojan.Win32.A.HmBlocker.62976
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Doina.10388
GoogleDetected
AhnLab-V3Trojan/Win32.HmBlocker.R2657
VBA32Hoax.HmBlocker
ALYacGen:Variant.Doina.10388
Cylanceunsafe
PandaTrj/Genetic.gen
RisingRansom.LockScreen!8.83D (TFE:5:pluYTIPJUYT)
YandexTrojan.GenAsa!WNK5LAGToTw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1735251.susgen
FortinetW32/Generic.AC.2620AF!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/LockScreen.AEE

How to remove Win32/LockScreen.AEE?

Win32/LockScreen.AEE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment