Malware

Win32/LockScreen.ASV malicious file

Malware Removal

The Win32/LockScreen.ASV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.ASV virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/LockScreen.ASV?


File Info:

crc32: C97D802B
md5: 63970c5530ff10732c67420c41508384
name: 63970C5530FF10732C67420C41508384.mlw
sha1: af844fba9e4507b23682312f6562909cf9c527ae
sha256: 804bdea255b4d15ea9295013b6677c968b97b31743651cafa812498a364948b0
sha512: 94694b65610ad3a415bb734fabb745c5936a239d9e0017bc0105878ac11dcf6f12879e254ffadf926c1d7092560090f06ca56b545e4cebe140c40cd41bd14f72
ssdeep: 24576:4+ez/NFhW/AkVH+gN3nVNWqrlVyIv1TEG36:v6QVeYv9ld1TEG3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/LockScreen.ASV also known as:

DrWebTrojan.AVKill.23914
CynetMalicious (score: 100)
ALYacGen:Trojan.RegistryDisabler.9GW@aGEoAgoI
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.6201
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Gimemo.477f56d7
K7GWTrojan ( 004bf8bf1 )
K7AntiVirusTrojan ( 004bf8bf1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.ASV
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Gimemo.azpb
BitDefenderGen:Trojan.RegistryDisabler.9GW@aGEoAgoI
NANO-AntivirusTrojan.Win32.Gimemo.bsjttk
MicroWorld-eScanGen:Trojan.RegistryDisabler.9GW@aGEoAgoI
TencentWin32.Trojan.Gimemo.Wogd
Ad-AwareGen:Trojan.RegistryDisabler.9GW@aGEoAgoI
SophosMal/Generic-S
ComodoMalware@#1ws9yau9eetot
BitDefenderThetaAI:Packer.8F8B71BE21
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_LockScreen
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.63970c5530ff1073
EmsisoftGen:Trojan.RegistryDisabler.9GW@aGEoAgoI (B)
JiangminTrojan/Gimemo.fyn
WebrootW32.Trojan.Registrydisabler.9gw
AviraHEUR/AGEN.1117464
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.RegistryDisabler.E4B518
AegisLabTrojan.Win32.Gimemo.j!c
ZoneAlarmTrojan-Ransom.Win32.Gimemo.azpb
GDataGen:Trojan.RegistryDisabler.9GW@aGEoAgoI
McAfeeArtemis!63970C5530FF
MAXmalware (ai score=89)
VBA32TScope.Trojan.Delf
PandaGeneric Malware
TrendMicro-HouseCallMal_LockScreen
RisingRansom.Gimemo!8.306 (CLOUD)
YandexTrojan.Gimemo!7ptYiRT7kOU
IkarusPacked.Win32.Katusha
FortinetW32/Gimemo.AZPB!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Gimemo.HwUBOBkB

How to remove Win32/LockScreen.ASV?

Win32/LockScreen.ASV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment