Malware

About “Win32/LockScreen.AUC” infection

Malware Removal

The Win32/LockScreen.AUC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.AUC virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Syriac
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/LockScreen.AUC?


File Info:

crc32: 43439B99
md5: 0358283a7429aaef3563907bc1acf527
name: 0358283A7429AAEF3563907BC1ACF527.mlw
sha1: e74ab096bfb8118c78f0086e8334a71284971f1d
sha256: 70a841ed4ffaa2f608515acdc92a4e5481865c27bee47e48b30b5926da53a4c4
sha512: 42b02ca90ce4e1f3d74d4ef0e45a93c2d2f819907d5497f677a3239a5d82583b421c9a0b878b76dbdc7aab1a782601ad26f18d08cbfb7c635dfb72db84e3efca
ssdeep: 1536:S/may5QFr9kgUlGma26+ULNKv+0kPPHVmntiQYYrV4dd/yQcJiHl4thnhcgwZfx:O9UlGFwvUVOlrV4dsQc0qt1wBS1rSd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2011 Simon Tatham.
InternalName: PuTTY
FileVersion: Release 0.62
CompanyName: Simon Tatham
ProductName: PuTTY suite
ProductVersion: Release 0.62
FileDescription: SSH, Telnet and Rlogin client
OriginalFilename: PuTTY
Translation: 0x0809 0x04b0

Win32/LockScreen.AUC also known as:

BkavW32.BeimaK.Trojan
K7AntiVirusTrojan ( 0040f8241 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.8811
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.22861
CylanceUnsafe
ZillyaTrojan.PornoAsset.Win32.15552
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/LockScreen.825a56bb
K7GWTrojan ( 0040f8241 )
Cybereasonmalicious.a7429a
CyrenW32/S-f21b3f83!Eldorado
SymantecPacked.Generic.457
ESET-NOD32Win32/LockScreen.AUC
APEXMalicious
AvastWin32:Crypt-PNE [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.22861
MicroWorld-eScanTrojan.GenericKDZ.22861
TencentWin32.Trojan.Lockscreen.Dbc
Ad-AwareTrojan.GenericKDZ.22861
SophosML/PE-A + Mal/Wonton-AN
ComodoMalware@#18smhgckfd3av
BitDefenderThetaGen:NN.ZexaF.34686.ju0@aaKdmygO
VIPRETrojan.Win32.Reveton.a (v)
TrendMicroTROJ_SPNR.15GB13
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.ch
FireEyeGeneric.mg.0358283a7429aaef
EmsisoftTrojan.GenericKDZ.22861 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.dwgvp
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1127899
eGambitGeneric.Malware
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Loktrom.B
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKDZ.22861
TACHYONTrojan/W32.PornoAsset.158208.H
AhnLab-V3Trojan/Win32.Foreign.C169121
Acronissuspicious
McAfeeArtemis!0358283A7429
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Oop
MalwarebytesTrojan.FakePutt
PandaTrj/Dtcontx.F
TrendMicro-HouseCallTROJ_SPNR.15GB13
RisingRansom.Loktrom!8.B04 (CLOUD)
YandexTrojan.GenAsa!INuwqfEcCps
IkarusTrojan-Ransom.Foreign
FortinetW32/Generic.AC.209C1A!tr
AVGWin32:Crypt-PNE [Trj]

How to remove Win32/LockScreen.AUC?

Win32/LockScreen.AUC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment