Malware

What is “Win32/LockScreen.AFR”?

Malware Removal

The Win32/LockScreen.AFR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.AFR virus can do?

  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/LockScreen.AFR?


File Info:

crc32: AD71F8AB
md5: ba417fbd876182ecb478fac0d94ab41f
name: BA417FBD876182ECB478FAC0D94AB41F.mlw
sha1: 5f6577b67814d61d96a82c77f38488b051b8a3d3
sha256: 5828d1480ada7539cc153fe3fc407aba7d2e12cbc3a9514fcbb16031f9b06f70
sha512: 23bb89af3c4325706ca379eefe84ca74bb1e9bbc8ec4327d1c22d0b332c1e0c30bbb8717dc531e442f8f9d3e9ad959a7c5f0cb77ab2be9696c14c987d91dc6a0
ssdeep: 1536:LvKH37pEyxwV8SaIokjJy/lTN33o0iYmvlzCAA4A:LElSaJ/lT60ozCB4A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/LockScreen.AFR also known as:

K7AntiVirusTrojan ( 00242a081 )
DrWebTrojan.Winlock.3260
CynetMalicious (score: 100)
CAT-QuickHealTrojanRansom.Foreign
ALYacGen:Trojan.ShellStartup.fqW@ai4PAuji
CylanceUnsafe
ZillyaTrojan.Chameleon.Win32.61
SangforRansom.Win32.Foreign.mlbp
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Foreign.6cdba777
K7GWTrojan ( 00242a081 )
Cybereasonmalicious.d87618
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AFR
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Foreign.mlbp
BitDefenderGen:Trojan.ShellStartup.fqW@ai4PAuji
NANO-AntivirusTrojan.Win32.Chameleon.dzqcb
ViRobotTrojan.Win32.A.Foreign.135168
MicroWorld-eScanGen:Trojan.ShellStartup.fqW@ai4PAuji
Ad-AwareGen:Trojan.ShellStartup.fqW@ai4PAuji
SophosMal/Generic-S
ComodoMalware@#2yhde0eb9hvxj
BitDefenderThetaGen:NN.ZexaCO.34628.fqW@ai4PAuji
VIPREBehavesLike.Win32.Malware.wlk (mx-v)
TrendMicroRansom_Genasom.R002C0DB421
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.ba417fbd876182ec
EmsisoftGen:Trojan.ShellStartup.fqW@ai4PAuji (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Chameleon.bo
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_98%
MicrosoftRansom:Win32/Genasom.EY
AegisLabTrojan.Win32.Generic.lulW
ZoneAlarmTrojan-Ransom.Win32.Foreign.mlbp
GDataGen:Trojan.ShellStartup.fqW@ai4PAuji
AhnLab-V3Trojan/Win32.HDC.C147507
McAfeeArtemis!BA417FBD8761
MAXmalware (ai score=83)
VBA32Hoax.Foreign
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Genasom.R002C0DB421
RisingRansom.Foreign!8.292 (CLOUD)
YandexTrojan.GenAsa!zPIwtmVcDqg
IkarusTrojan.Win32.Ransom
FortinetW32/Foreign.AFR!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Ransom.Genasom.HgIASOYA

How to remove Win32/LockScreen.AFR?

Win32/LockScreen.AFR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment