Malware

What is “Win32/LockScreen.AQP”?

Malware Removal

The Win32/LockScreen.AQP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.AQP virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.youtube.com
ocsp.pki.goog
crl.pki.goog
www.gstatic.com

How to determine Win32/LockScreen.AQP?


File Info:

crc32: 75675893
md5: 33cb534ef7a60e674dd47667ff2ff60c
name: 33CB534EF7A60E674DD47667FF2FF60C.mlw
sha1: c7d82483a7770929152d71706f272657fe8bccf0
sha256: 787405f73ea0acc21d2f324621bef16be15163679cf085a234eccb373f5a8f6a
sha512: 4b84bec911179989a99d8d1d2d03f782c2e870417edd353697aeef0e82aba441d089523d72ef0793c172575c225f23747a812095997d6c3686432d8ee79ec50e
ssdeep: 12288:xXBGG01oDKrj5Q2tzlAW7aBKcrpBzJ8bTT:xxX04Krj5HdhyrLta
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/LockScreen.AQP also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.Winlock.9378
Qihoo-360Win32/Ransom.Blocker.HgIASOcA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Blocker.j!c
SangforRansom.Win32.Blocker.ckxo
K7GWTrojan ( 0055e4091 )
K7AntiVirusTrojan ( 0055e4091 )
BitDefenderThetaGen:NN.ZelphiF.34608.IGW@aOw1NBlc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.AQP
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.ckxo
AlibabaRansom:Win32/Blocker.aa4ad072
NANO-AntivirusTrojan.Win32.Blocker.cqjvoe
RisingHoax.BadJoke!8.41C (CLOUD)
SophosMal/Generic-S
ComodoMalware@#1x9rc9ou8y7qf
ZillyaTrojan.Blocker.Win32.11283
McAfee-GW-EditionGenericR-ABY!33CB534EF7A6
JiangminTrojan/Blocker.kvp
WebrootW32.Malware.Heur
Antiy-AVLHackTool[Hoax]/Win32.FakeBlocker
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Blocker
GridinsoftRansom.Win32.Blocker.sa
ZoneAlarmTrojan-Ransom.Win32.Blocker.ckxo
AhnLab-V3Trojan/Win32.Blocker.C1166673
McAfeeGenericR-ABY!33CB534EF7A6
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Winlock.gen
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TencentWin32.Trojan.Blocker.Lknz
YandexTrojan.GenAsa!FUWrrWj++zM
IkarusTrojan-Ransom.Delf
FortinetW32/LockScreen.APP!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/LockScreen.AQP?

Win32/LockScreen.AQP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment