Selected viruses, spyware, and other threats: sorted alphabetically
To regain access to the operating system use the key generator which can be downloaded here . In order to be executed on every system start, the trojan sets the following Registry entry: A string with variable content is used instead of %filename% .
To regain access to the operating system one of the following passwords can be used:The trojan disables the following key combinations: ALT + F4 .
Short description
Win32/LockScreen.AL is a trojan that blocks access to the Windows operating system. To regain access to the operating system the user is asked to send an SMS message to a specified telephone number in exchange for a password. When the correct password is entered the trojan is deactivated. The file is run-time compressed using UPX . Installation
When executed, the trojan copies itself in the %appdata% folder using one of the following filenames: - ffptd.exe
- loumg.exe
- ttvao.exe
- ukdne.exe
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run]
"wscco" = "%appdata%\%filename%.exe"
Other information
The trojan displays the following dialog box: When the correct password is entered the trojan is deactivated. To regain access to the operating system one of the following passwords can be used:
- 5748839

