Malware

Win32:LockScreen-ZO [Trj] removal instruction

Malware Removal

The Win32:LockScreen-ZO [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:LockScreen-ZO [Trj] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32:LockScreen-ZO [Trj]?


File Info:

crc32: 98BEEE9B
md5: 8c382ee1eef5d1cf4808a0f5fa53e850
name: 8C382EE1EEF5D1CF4808A0F5FA53E850.mlw
sha1: 78d7c736c36aa1a7d3a52d2c3cac945044936216
sha256: e9aec5a31fe2db1e7c533905af01b1b7a13e14c8419d8dd4933252f9ad33b3f3
sha512: ecde92f0860ea605bfdea03635e040f3a994fa006c88c231c7e9074cf0e26cde690275d7176f9dea3728242b082b776023e99db7278c350ca535c79745cae9de
ssdeep: 1536:HlbyN0tna2La5EP+cUMvmdPQcjVxoJ7X+qhxB6UTeT1QzKwa+LKzBvcy6R:FbNFX2cUrjVmV+qx6USJQedvc1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2011
InternalName: elsasmp
ProductVersion: 3, 0, 3, 321
OriginalFilename: elsasmp.exe
Translation: 0x0419 0x0064

Win32:LockScreen-ZO [Trj] also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0040f4b11 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.8128
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Urausy.C
McAfeeRansom-FCIS!8C382EE1EEF5
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.16459
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Urausy.b1d96e7e
K7GWTrojan ( 0040f4b11 )
Cybereasonmalicious.1eef5d
BaiduWin32.Trojan.Kryptik.nj
CyrenW32/FakeAlert.WR.gen!Eldorado
SymantecTrojan.Ransomlock.Q
ESET-NOD32a variant of Win32/Kryptik.BGND
APEXMalicious
AvastWin32:LockScreen-ZO [Trj]
ClamAVWin.Ransomware.Generickdz-9825512-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.FakeAlert.127
NANO-AntivirusTrojan.Win32.RiskGen.cqosxa
ViRobotTrojan.Win32.Ransom.110592.C
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanGen:Variant.FakeAlert.127
TencentMalware.Win32.Gencirc.10b6e07e
Ad-AwareGen:Variant.FakeAlert.127
SophosMal/Generic-R + Mal/FakeAV-KL
ComodoTrojWare.Win32.Ransom.Foreign.DLK@4yi08e
BitDefenderThetaGen:NN.ZexaF.34628.gq0@aauYh6hi
VIPRETrojan.Win32.FakeAV.ka (v)
TrendMicroTROJ_RANSOM.SMMD
McAfee-GW-EditionRansom-FCIS!8C382EE1EEF5
FireEyeGeneric.mg.8c382ee1eef5d1cf
EmsisoftGen:Variant.FakeAlert.127 (B)
JiangminTrojan/Foreign.hpc
WebrootW32.Rogue.Gen
AviraTR/Ransom.4563215
eGambitGeneric.Malware
KingsoftWin32.HeurC.KVM099.a.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.AFQ
GDataGen:Variant.FakeAlert.127
AhnLab-V3Trojan/Win32.FakeAV.R69654
Acronissuspicious
VBA32SScope.Malware-Cryptor.Hlux
MAXmalware (ai score=100)
MalwarebytesTrojan.Agent
PandaTrj/Resdec.HEU
TrendMicro-HouseCallTROJ_RANSOM.SMMD
RisingTrojan.Agent!1.6A2B (CLOUD)
YandexTrojan.GenAsa!C0Xt39AEFEo
FortinetW32/FakeAV.SE!tr
AVGWin32:LockScreen-ZO [Trj]
Qihoo-360Win32/Trojan.Ransom.caa

How to remove Win32:LockScreen-ZO [Trj]?

Win32:LockScreen-ZO [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment