Malware

Win32/LockScreen.OW removal

Malware Removal

The Win32/LockScreen.OW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/LockScreen.OW virus can do?

  • Executable code extraction
  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • A process attempted to delay the analysis task by a long amount of time.

How to determine Win32/LockScreen.OW?


File Info:

crc32: 2C62AC14
md5: dfccad0283d260c6f380e8aa75c1c1cb
name: DFCCAD0283D260C6F380E8AA75C1C1CB.mlw
sha1: 4430c9cca23557d661c68baa9c862ed0d5d481b0
sha256: 8990d9744855e48e16847f6bcf7d714e22540581be32e72ea9766adeed7743e3
sha512: 5cf584fa80343ab670eeea2fc6ba7cf482c0c7725031968368e50f5824d0f4944f7ed367b66807f13f3c96a12097452caf40299e7e8fe062cec74763c85190e1
ssdeep: 1536:6E07Jj8hkRKaR5yX5q9U8pCaQ2asjg/t21XUQXW1a9hbUFSTDVLSWS0/cKXyXxY:6WhkRKaHYTwYsjg12dTXWE3VLQsyXF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009
InternalName: Flash Install
FileVersion: 1, 23, 2, 5
ProductName: Flash Install
ProductVersion: 1, 23, 2, 5
FileDescription: Flash Install
OriginalFilename: Codec Install
Translation: 0x0419 0x04b0

Win32/LockScreen.OW also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00143f451 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Strictor.105013
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.7621
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/PinkBlocker.627ba60a
K7GWTrojan ( 00143f451 )
Cybereasonmalicious.283d26
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.OW
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.PinkBlocker.my
BitDefenderGen:Variant.Strictor.105013
NANO-AntivirusTrojan.Win32.Winlock.dgenli
MicroWorld-eScanGen:Variant.Strictor.105013
TencentWin32.Trojan.Lockscreen.Wwoi
Ad-AwareGen:Variant.Strictor.105013
SophosMal/Generic-S
ComodoMalware@#19hbhxbbeo8s0
BitDefenderThetaGen:NN.ZexaF.34670.iq0@aiBx1tgk
VIPRETrojan.Win32.Kuluoz.i (v)
McAfee-GW-EditionGenericRXHL-GG!DFCCAD0283D2
FireEyeGeneric.mg.dfccad0283d260c6
EmsisoftGen:Variant.Strictor.105013 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PinkBlocker.co
AviraTR/Crypt.ZPACK.Gen
eGambitGeneric.Dropper
MicrosoftTrojan:Win32/Dynamer!ac
ArcabitTrojan.Strictor.D19A35
AegisLabTrojan.Win32.Buterat.lDnL
GDataGen:Variant.Strictor.105013
AhnLab-V3Trojan/Win32.PinkBlocker.C79358
Acronissuspicious
McAfeeGenericRXHL-GG!DFCCAD0283D2
MAXmalware (ai score=99)
VBA32BScope.Trojan.Bojotuc
MalwarebytesMalware.AI.596253126
PandaTrj/CI.A
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!WHGU8kG52cE
IkarusTrojan-Dropper.Win32.Blocker
FortinetW32/LockScreen.OW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCEpsA

How to remove Win32/LockScreen.OW?

Win32/LockScreen.OW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment