Threat Encyclopedia

Selected viruses, spyware, and other threats: sorted alphabetically

MSIL/LockScreen.G

Type of infiltration:Trojan  
Size:83456 B 
Affected platforms:Microsoft Windows 
Signature database version:5106 (20100511) 

Short description

MSIL/LockScreen.G is a trojan that blocks access to the Windows operating system. To regain access to the operating system the user is asked to send an SMS message to a specified telephone number in exchange for a password. When the correct password is entered the trojan is deactivated. Trojan is probably a part of other malware.

Installation

The trojan does not create any copies of itself.

Other information

The trojan displays the following dialog box:
1(1).jpg
2(1).jpg
When the correct password is entered the trojan is deactivated.

The password to regain access to the operating system is one of the following:
  • 4e6b9f
  • 7a7a7a
Some examples follow.
3(1).jpg
The trojan may turn off the computer.

The trojan connects to the following addresses:
  • http://sonny.kx.cz
  • ftp://sonny.kx.cz
The trojan may set the following Registry entries:
  • [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion
    Run]
    "System32" = ""
    "System" = ""
  • [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
    PoliciesSystem]
    "DisableTaskMgr" = "1"
Trojan requires the .NET Framework 3.5 SP1 to run.