Malware

About “Win32/LockScreen.ASQ” infection

Malware Removal

The Win32/LockScreen.ASQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.ASQ virus can do?

  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.400kg.com
www1.400kg.com
parkingcrew.net
iyfnz.com
i3.cdn-image.com
pxlgnpgecom-a.akamaihd.net
ocsp.digicert.com

How to determine Win32/LockScreen.ASQ?


File Info:

crc32: 79B1DDFC
md5: 7af89777461804bcc379016703db71e7
name: 7AF89777461804BCC379016703DB71E7.mlw
sha1: 2f8dd3d92cd6850465040e33f280232afa36d833
sha256: 416a14885399e7e931b58d9371989d778fde6915c7ce76e68599c8cc4064c014
sha512: bae7ca84ce9a39a9c0d170b25417c1a63cbdead6dc2f3d7c323927aeb577dfd4355ecf162e9b8f82fd10d4eab1cf58b007bdc489b52a66a046207315aa8c45b1
ssdeep: 24576:/BNXietVWDAQ4iJqESs4UjROdD15eT/2o:ZNXix4NeTe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/LockScreen.ASQ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005671771 )
CynetMalicious (score: 99)
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.8179
SangforTrojan.Win32.Strictor.frtl
AlibabaRansom:Win32/Gimemo.89f811af
K7GWTrojan ( 005671771 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.ASQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gimemo.bjpw
NANO-AntivirusTrojan.Win32.Gimemo.cigmuz
TencentWin32.Trojan.Gimemo.Amcu
SophosMal/Generic-S
ComodoMalware@#p3uh5ihclcpu
BitDefenderThetaGen:NN.ZelphiF.34790.tHW@ayCCufaQ
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Gimemo.xb
AviraTR/Strictor.31253.3
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.4AEDC3
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
McAfeeArtemis!7AF897774618
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
PandaTrj/CI.A
RisingTrojan.Generic@ML.80 (RDML:T7E/GfT+CfKqIBUE6Hj7Dw)
YandexTrojan.Gimemo!LLNKrLCUWmQ
IkarusTrojan.Win32.LockScreen
FortinetW32/LockScreen.ASQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Gimemo.HgAASQ4A

How to remove Win32/LockScreen.ASQ?

Win32/LockScreen.ASQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment