MSIL/LockScreen [Threat Name] go to Threat

MSIL/LockScreen.G [Threat Variant Name]

Category trojan
Size 83456 B
Short description

MSIL/LockScreen.G is a trojan that blocks access to the Windows operating system. To regain access to the operating system the user is asked to send an SMS message to a specified telephone number in exchange for a password. When the correct password is entered the trojan is deactivated. The trojan is probably a part of other malware.

Installation

The trojan does not create any copies of itself.

Other information

The trojan displays the following dialog box:

When the correct password is entered the trojan is deactivated.


The password to regain access to the operating system is one of the following:

  • 4e6b9f
  • 7a7a7a

Some examples follow.

The trojan may turn off the computer.


The trojan connects to the following addresses:

  • http://sonny.kx.cz
  • ftp://sonny.kx.cz

The trojan may set the following Registry entries:

  • [HKEY_LOCAL_MACHINE\­SOFTWARE\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "System32" = ""
    • "System" = ""
  • [HKEY_CURRENT_USER\­Software\­Microsoft\­Windows\­CurrentVersion\­Policies\­System]
    • "DisableTaskMgr" = "1"

Trojan requires the .NET Framework 3.5 SP1 to run.

Please enable Javascript to ensure correct displaying of this content and refresh this page.