Malware

What is “Win32/LockScreen.HV”?

Malware Removal

The Win32/LockScreen.HV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.HV virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

Related domains:

edgedl.me.gvt1.com

How to determine Win32/LockScreen.HV?


File Info:

crc32: 762E9919
md5: 289d9fee05fe67e182739b80ade0c98d
name: 289D9FEE05FE67E182739B80ADE0C98D.mlw
sha1: f93440ed5bfd66232a3341577c31f2bb91e8fae3
sha256: 387ec85d0b47aac7fd68ed3049ffca1eb0a3bfa3280d1c15031f01b50d5ed21a
sha512: 6a656466c7587f2d335d4b88557f24d30df637a56da8b1b3868aea947078fdbf9b2a3a585be034b4ef78c93755489637176d6f22dd2bfe6f8afb525922ca9492
ssdeep: 6144:1DI4Jfjds07TCZuVclnNTEqXEipsd19GL3Fw0o:pRNjdj7TG/gqRY19GzF+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009
InternalName: Codec Install
FileVersion: 1, 23, 1, 5
ProductName: Codec Install
ProductVersion: 1, 23, 1, 5
FileDescription: Codec Install
OriginalFilename: Codec Install
Translation: 0x0419 0x04b0

Win32/LockScreen.HV also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.2264
ALYacDropped:Trojan.GenericKD.2222409
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.7493
SangforTrojan.Win32.PinkBlocker.cmw
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRansom:Win32/PinkBlocker.1f862e6b
K7GWTrojan ( 0055e4091 )
K7AntiVirusTrojan ( 0055e4091 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.HV
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.PinkBlocker.cmw
BitDefenderDropped:Trojan.GenericKD.2222409
NANO-AntivirusTrojan.Win32.PinkBlocker.fccjoq
MicroWorld-eScanDropped:Trojan.GenericKD.2222409
TencentWin32.Trojan.Pinkblocker.Hsjd
Ad-AwareDropped:Trojan.GenericKD.2222409
SophosMal/Generic-S
BitDefenderThetaAI:Packer.C87EBE241C
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.289d9fee05fe67e1
EmsisoftDropped:Trojan.GenericKD.2222409 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Blocker.cr
AviraTR/Crypt.ZPACK.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.184E5DA
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanDropper:Win32/Genasom.B
ZoneAlarmTrojan-Ransom.Win32.PinkBlocker.cmw
GDataDropped:Trojan.GenericKD.2222409
AhnLab-V3Trojan/Win32.PinkBlocker.C79358
Acronissuspicious
McAfeeGenericR-PHC!289D9FEE05FE
MAXmalware (ai score=99)
VBA32BScope.Trojan.Bojotuc
MalwarebytesMalware.AI.596253126
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:FbohZIh3k1tudVH3n5gD8g)
YandexTrojan.GenAsa!EeUMpvjslzI
IkarusTrojan-Dropper.Win32.Blocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.2921D9!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASOkA

How to remove Win32/LockScreen.HV?

Win32/LockScreen.HV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment