Malware

Win32/LockScreen.OM removal guide

Malware Removal

The Win32/LockScreen.OM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.OM virus can do?

  • Executable code extraction
  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • A process attempted to delay the analysis task by a long amount of time.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/LockScreen.OM?


File Info:

crc32: 4B7CA1D7
md5: 39233d8a3685eda28d834849f851c821
name: 39233D8A3685EDA28D834849F851C821.mlw
sha1: 44373d2cac2bc75011214d7a61a899ec6460b55c
sha256: 13d339915589b69e353be006f0c687a47a353cde14a69e5cd09c11718bd0f3f4
sha512: dfe03727987b4e3c2ababbc63204806e5a18a8e46b99e7824941fdf5543217793a64f91e4f15a920d82b83c368028f4b763528b17995a2f1ad3faad933aaeff6
ssdeep: 1536:yyal+HuQ3VXemMgJR+n4tjUjv/dNe2eZI5N9+liVoyLMywYT04LyWNNdhAUOVyM:yjm/3N5r9yNe2f74yLM4LhdMyMF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009
InternalName: Flash Install
FileVersion: 1, 23, 2, 5
ProductName: Flash Install
ProductVersion: 1, 23, 2, 5
FileDescription: Flash Install
OriginalFilename: Codec Install
Translation: 0x0419 0x04b0

Win32/LockScreen.OM also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.13037
ALYacGen:Variant.Strictor.105013
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.8304
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaRansom:Win32/PinkBlocker.848daba3
K7GWTrojan ( 00143f451 )
K7AntiVirusTrojan ( 00143f451 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.OM
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Strictor.105013
NANO-AntivirusTrojan.Win32.PinkBlocker.dgejoa
MicroWorld-eScanGen:Variant.Strictor.105013
TencentMalware.Win32.Gencirc.114c0dd1
Ad-AwareGen:Variant.Strictor.105013
SophosMal/Generic-S
ComodoMalware@#1sp3uk5131d3z
BitDefenderThetaGen:NN.ZexaF.34088.iq0@aGFxs4pk
VIPRETrojan.Win32.Kuluoz.i (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.39233d8a3685eda2
EmsisoftGen:Variant.Strictor.105013 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PinkBlocker.cb
AviraTR/Crypt.ZPACK.Gen
eGambitGeneric.Malware
MicrosoftTrojan:Win32/Azorult!ml
ArcabitTrojan.Strictor.D19A35
GDataGen:Variant.Strictor.105013
AhnLab-V3Trojan/Win32.PinkBlocker.C79358
Acronissuspicious
McAfeeGenericRXHL-GG!39233D8A3685
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bojotuc
MalwarebytesMalware.AI.596253126
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:bx8YtOjmsV9mdxJTqfl3XQ)
YandexTrojan.GenAsa!WHGU8kG52cE
IkarusTrojan-Dropper.Win32.Blocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/LockScreen.OW!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/LockScreen.OM?

Win32/LockScreen.OM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment