Threat Database Trojans Trojan.LockScreen.C

Trojan.LockScreen.C

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 31
First Seen: July 21, 2023
Last Seen: November 28, 2025
OS(es) Affected: Windows

The detection of Trojan.LockScreen.C on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.LockScreen.C?

Trojan.LockScreen.C is a type of Trojan horse malware that can lock your computer screen, denying you access to your system and data. Trojans are malicious programs that disguise themselves as legitimate software, but in reality, they are designed to cause harm or provide unauthorized access to your system. The ".LockScreen.C" part of the name suggests that this specific variant may be designed to lock the screen of the infected computer.

How Trojan.LockScreen.C Operates

Trojan.LockScreen.C, like other Trojans, operates by exploiting vulnerabilities in your system or by tricking you into installing it. Once installed, it can perform a variety of malicious actions, including locking your screen, stealing sensitive information, or installing additional malware. The exact mechanisms of operation can vary, but the end result is always harmful to your system and your data.

Trojans often rely on social engineering tactics to spread, such as phishing emails, infected software downloads, or compromised websites. They can also exploit weaknesses in operating systems or applications to gain unauthorized access.

Symptoms of Infection

Identifying a Trojan.LockScreen.C infection can be challenging because it may not always exhibit obvious symptoms. However, some common signs of infection include a locked computer screen, slow system performance, unexpected pop-ups or advertisements, and unfamiliar programs or icons on your desktop. If you notice any of these symptoms, it's crucial to take immediate action to protect your system and data.

How to Remove Trojan.LockScreen.C

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware. Ensure the tool is updated with the latest definitions to improve the chances of successful removal.
  3. Uninstall any suspicious programs that you don't recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or settings that the malware might have altered.
  5. Reboot your computer and run another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed. This step is crucial to confirm that your system is clean.

Conclusion

Removing Trojan.LockScreen.C requires careful and immediate action to prevent further damage to your system and data. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious with emails and downloads, you can protect your computer from similar threats in the future. Remember, prevention and vigilance are key to maintaining the security and integrity of your digital environment.

Analysis Report

General information

Family Name: Trojan.LockScreen.C
Signature status: No Signature

Known Samples

MD5: ff4b6e0cbfbccd8827a87c20a11d30a3
SHA1: fdea6bb684ea16e20a9d42edc873c3d62f254bc8
SHA256: 167B1405976139D894C4E59A283B46F078B26B3E910DD4993A5EA8242D1E5EDD
File Size: 2.65 MB, 2647552 bytes
MD5: 936d9287e758c773a8cfd29885f19f12
SHA1: 29703e5d5c88dc98db20df784e8710774aebcfb8
SHA256: 2B271AC534A4C93155E57FB0D4D143CE5F15BE7BD1CEAE3FA4EAC9EC36DFE2FF
File Size: 2.65 MB, 2647552 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 3,947
Potentially Malicious Blocks: 194
Whitelisted Blocks: 3,753
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banker.RDA
  • LockScreen.C

Files Modified

File Attributes
\device\harddisk0\dr0 Generic Read,Generic Execute,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 786496
c:\mbr.bin Generic Read,Generic Execute,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 786496
c:\users\user\downloads\time.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\time2.ini Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\policies\microsoft\windows\system::disablecmd  RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::enablelua RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::java c:\users\user\downloads\fdea6bb684ea16e20a9d42edc873c3d62f254bc8_0002647552 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\explorer.exe::debugger c:\users\user\downloads\fdea6bb684ea16e20a9d42edc873c3d62f254bc8_0002647552 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe::debugger c:\users\user\downloads\fdea6bb684ea16e20a9d42edc873c3d62f254bc8_0002647552 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\uninstall::noaddremoveprograms  RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::hidefastuserswitching  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer\advanced::noclose  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\system::disablelockworkstation  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\system::disablechangepassword  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\policies\explorer::nochangestartmenu  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nocontrolpanel  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nonetworkconnections  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::norecentdocsmenu  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nowinkeys  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nofavoritesmenu  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nostartmenumoreprograms  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nostartmenupinnedlist  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::noclose  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nocommongroups  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nocustomizewebview  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::noprintertabs  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nodesktop  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nofind  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nofilemenu  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nofolderoptions  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::norun  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\explorer::nologoff  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::java c:\users\user\downloads\29703e5d5c88dc98db20df784e8710774aebcfb8_0002647552 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\explorer.exe::debugger c:\users\user\downloads\29703e5d5c88dc98db20df784e8710774aebcfb8_0002647552 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe::debugger c:\users\user\downloads\29703e5d5c88dc98db20df784e8710774aebcfb8_0002647552 RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Process Terminate
  • TerminateProcess

Related Posts

Trending

Most Viewed

Loading...