MSIL/LockScreen [Threat Name] go to Threat

MSIL/LockScreen.K [Threat Variant Name]

Category trojan
Size 234725 B
Aliases Trojan-Ransom.MSIL.Losya.a (Kaspersky)
  Trojan.ADH (Symantec)
Short description

MSIL/LockScreen.K is a trojan that blocks access to the Windows operating system.

Installation

When executed, the trojan copies itself into the following location:

  • C:\­temp_sys.exe

The following Registry entry is set:

  • [HKEY_LOCAL_MACHINE\­SOFTWARE\­Microsoft\­Windows NT\­CurrentVersion\­Winlogon]
    • "Userinit"="%originalvalue%,\­temp_sys.exe"

This causes the trojan to be executed on every system start.

Other information

MSIL/LockScreen.K is a trojan that blocks access to the Windows operating system.


To regain access to the operating system the user is asked to send an SMS message to a specified telephone number in exchange for a password.


The trojan displays the following dialog box:

Trojan requires the Microsoft .NET Framework to run.

Please enable Javascript to ensure correct displaying of this content and refresh this page.