Malware

Win32/LockScreen.DU removal tips

Malware Removal

The Win32/LockScreen.DU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.DU virus can do?

  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/LockScreen.DU?


File Info:

crc32: 7E16F801
md5: 06b87c6f74a1887a9e8d9821fea34d38
name: 06B87C6F74A1887A9E8D9821FEA34D38.mlw
sha1: f17b7128703051ed59c5051d9d5bc67df7af569b
sha256: f37c3be36acac410d636c223d56513400b76e099a70c91b955922c952f5935dc
sha512: b9f53276b38a908ca0d86adbc32e61063ccc62d658c94792ca5ae17d4c29e8c84d0c20585bcdfb547d0ff38ebf20280a44648e54b6e756217fef0834a7a7ed78
ssdeep: 6144:VUI1RPo4ZDCaSj6PazGYi/c/yT/KSgKI5l/4b1TBMl7ZAOu8wkNM9VQ:uIE4Z+n6Paz6cqT/KCI/4JT2l7Z/a
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/LockScreen.DU also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.UserStartup.wuW@a4ZCPge
FireEyeGeneric.mg.06b87c6f74a1887a
ALYacGen:Trojan.UserStartup.wuW@a4ZCPge
CylanceUnsafe
ZillyaTrojan.PogBlock.Win32.377
SangforTrojan.Win32.Save.a
BitDefenderGen:Trojan.UserStartup.wuW@a4ZCPge
Cybereasonmalicious.f74a18
BitDefenderThetaAI:Packer.0F8E6E721E
CyrenW32/Risk.SWQE-0382
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.DU
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Pogblock-10
KasperskyTrojan-Ransom.Win32.PogBlock.kw
AlibabaRansom:Win32/PogBlock.53f633db
NANO-AntivirusTrojan.Win32.PogBlock.bowze
ViRobotTrojan.Win32.Ransom.361984.G
RisingRansom.PogBlock!8.4E51 (CLOUD)
Ad-AwareGen:Trojan.UserStartup.wuW@a4ZCPge
SophosMal/Generic-S
ComodoSuspicious@#1f9v283nl74av
F-SecureHeuristic.HEUR/AGEN.1130296
DrWebTrojan.Winlock.591
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_RANSOM.SMM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftGen:Trojan.UserStartup.wuW@a4ZCPge (B)
IkarusTrojan-Ransom.PogBlock
JiangminTrojan/PogBlock.av
MaxSecureTrojan.Malware.74124880.susgen
AviraHEUR/AGEN.1130296
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.PogBlock
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Orsam!rts
ArcabitTrojan.UserStartup.ED09A8
AhnLab-V3Trojan/Win32.Xema.C90050
ZoneAlarmTrojan-Ransom.Win32.PogBlock.kw
GDataGen:Trojan.UserStartup.wuW@a4ZCPge
CynetMalicious (score: 100)
McAfeeArtemis!06B87C6F74A1
TACHYONTrojan/W32.PogBlock.361984
VBA32Hoax.PogBlock
MalwarebytesMachineLearning/Anomalous.100%
PandaGeneric Malware
TrendMicro-HouseCallTROJ_RANSOM.SMM
TencentWin32.Trojan.Pogblock.Gls
YandexTrojan.GenAsa!eNm3Rx8J8tA
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_94%
FortinetW32/PogBlock.KW!tr
WebrootW32.Orsam.Gen
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.48c

How to remove Win32/LockScreen.DU?

Win32/LockScreen.DU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment