Malware

Should I remove “Win32/LockScreen.AGD”?

Malware Removal

The Win32/LockScreen.AGD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.AGD virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/LockScreen.AGD?


File Info:

crc32: 46C6EC79
md5: e97c20f74c30f07962e6660c38d0fc2b
name: E97C20F74C30F07962E6660C38D0FC2B.mlw
sha1: ebd023b1b2a0fdbe25ade753019780cd78996df1
sha256: 51179ec1239ded7f945c12c388b80f87c3a2b8b515535b36ad9171ee87c58e45
sha512: 453d683adcd1fe5fc4dfdf1b6e310b583386160c242fcb50b0472cddaaa63025e044142bd7921e3e1078f1c137022531785786c97fb4f3838f12bf04f5915aa3
ssdeep: 192:xlG5K+zfjyFOjfGqJwQbBuNm+rgL0wRh0Emul7w92dIQx6eKW4eZb6PwmzCZ2Q1:mFfjZjuubBaYLl7wpeKxGi1z7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/LockScreen.AGD also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 002451e21 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.3445
CynetMalicious (score: 100)
ALYacGen:Trojan.ShellStartup.leW@aCOF4vbc
CylanceUnsafe
ZillyaTrojan.PornoAsset.Win32.23919
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/PornoAsset.bbc465b1
K7GWTrojan ( 002451e21 )
Cybereasonmalicious.74c30f
CyrenW32/Heuristic-114!Eldorado
SymantecTrojan.Ransomlock
ESET-NOD32a variant of Win32/LockScreen.AGD
APEXMalicious
AvastWin32:LockScreen-EP [Trj]
KasperskyTrojan-Ransom.Win32.PornoAsset.cojo
BitDefenderGen:Trojan.ShellStartup.leW@aCOF4vbc
NANO-AntivirusTrojan.Win32.MLW.dvgiu
MicroWorld-eScanGen:Trojan.ShellStartup.leW@aCOF4vbc
TencentWin32.Trojan.Pornoasset.Aliq
Ad-AwareGen:Trojan.ShellStartup.leW@aCOF4vbc
SophosMal/Generic-R + Mal/EncPk-ZE
ComodoMalware@#3dvqpe2bxgawq
BitDefenderThetaGen:NN.ZexaF.34670.leW@aCOF4vbc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Infected.cz
FireEyeGeneric.mg.e97c20f74c30f079
EmsisoftGen:Trojan.ShellStartup.leW@aCOF4vbc (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.hcvc
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_84%
MicrosoftRansom:Win32/Trasbind.A
ArcabitTrojan.ShellStartup.E590D9
AegisLabTrojan.Win32.PornoAsset.j!c
ZoneAlarmHEUR:Worm.Win32.Generic
GDataGen:Trojan.ShellStartup.leW@aCOF4vbc
TACHYONTrojan/W32.PornoAsset.188416
AhnLab-V3Trojan/Win32.Ransomlock.C3661811
Acronissuspicious
McAfeeGenericRXJG-AX!E97C20F74C30
MAXmalware (ai score=82)
VBA32BScope.Trojan.Invader
MalwarebytesMalware.Heuristic.1006
PandaGeneric Malware
RisingRansom.Trasbind!8.292E (CLOUD)
YandexTrojan.PornoAsset!VEItlgyEpLg
IkarusTrojan-Downloader.Win32.Bubnix
FortinetW32/PornoAsset.AGD!tr
AVGWin32:LockScreen-EP [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.PornoAsset.HxMBqZ8A

How to remove Win32/LockScreen.AGD?

Win32/LockScreen.AGD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment