This thread if about Trojan Winlock aka Ransom/Homoblocker/ScreenLocker/LockScreen/Wlock.
VirusTotal
http://www.virustotal.com/ru/analisis/3 ... 1277403545
Runs through HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit key.
Works in safe mode. Displays some pr0n and locks desktop screen.
VirusTotal
http://www.virustotal.com/ru/analisis/3 ... 1277403545
Runs through HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit key.
Works in safe mode. Displays some pr0n and locks desktop screen.
Attachments
pass: malware
(114.03 KiB) Downloaded 209 times
(114.03 KiB) Downloaded 209 times
Ring0 - the source of inspiration