MSIL/LockScreen [Threat Name] go to Threat
MSIL/LockScreen.K [Threat Variant Name]
Category | trojan |
Size | 234725 B |
Aliases | Trojan-Ransom.MSIL.Losya.a (Kaspersky) |
Trojan.ADH (Symantec) |
Short description
MSIL/LockScreen.K is a trojan that blocks access to the Windows operating system.
Installation
When executed, the trojan copies itself into the following location:
- C:\temp_sys.exe
The following Registry entry is set:
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
- "Userinit"="%originalvalue%,\temp_sys.exe"
This causes the trojan to be executed on every system start.
Other information
MSIL/LockScreen.K is a trojan that blocks access to the Windows operating system.
To regain access to the operating system the user is asked to send an SMS message to a specified telephone number in exchange for a password.
The trojan displays the following dialog box:
Trojan requires the Microsoft .NET Framework to run.