Aliases: TR/Kovter.C.1 (Avira) Win32/LockScreen.BEH trojan (ESET) W32/LockScreen.BEH!tr (Fortinet)
Windows Defender detects and removes this threat.
It lets a malicious hacker access and control your PC from a command and control server (C&C).
It also lowers the security settings for Internet Explorer.
You can read more about this threat on the Microsoft Malware Protection Center (MMPC) blog:
- Improved scripts in .lnk files now deliver Kovter in addition to Locky
- Kovter becomes almost file-less, creates a new file type, and gets some new certificates
- Large Kovter digitally-signed malvertising campaign and MSRT cleanup release
Use the following free Microsoft software to detect and remove this threat:
You should also run a full scan. A full scan might find other, hidden malware.
Additional remediation instructions for this threat
This threat might make lasting changes to your PC's settings that won't be restored when it's cleaned. The following steps can help change these settings back to what you want:
Get more help
You can also see our advanced troubleshooting page for more help.
If you’re using Windows XP, see our Windows XP end of support page.