This is a ransomware scam that pretends to be a threatening message from Scotland Yard but actually hijacks the user's computer and demands money to unlock it.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan executes another instance of explorer.exe where it injects itself. It then opens a notepad.exe process and injects its codes into it. The injected code in notepad.exe then disables the desktop of the affected user and open a browser window connecting to a certain site.
This Trojan may be unknowingly downloaded by a user while visiting malicious websites.
It modifies the Internet Explorer Zone Settings.
File size: Varies
File type: DLL
Memory resident: Yes
Initial samples received date: 14 Feb 2012
Payload: Disables desktop, Terminates processes, Connects to URLs/IPs
Arrival Details
This Trojan may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This Trojan drops the following files:
- %User Startup%\{malware filename}.lnk - autostart component
(Note: %User Startup% is the current user's Startup folder, which is usually C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup on Windows NT, and C:\Documents and Settings\{User name}\Start Menu\Programs\Startup.)
Other System Modifications
This Trojan adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
NoProtectedModeBanner = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Policies\
System
DisableTaskMgr = "1"
Process Termination
This Trojan terminates the following services if found on the affected system:
Web Browser Home Page and Search Page Modification
This Trojan modifies the Internet Explorer Zone Settings.
NOTES:
Upon execution, it executes another instance of explorer.exe where it injects itself. It then opens a notepad.exe process and injects its codes into it.
The injected code in notepad.exe then disables the desktop of the affected user and open a browser window connecting to the following site:
- http://{BLOCKED}.{BLOCKED}.163.204/
The site asks a user to pay a certain amount of money in order to recover the disabled system.
As of this writing, the said site is inaccessible.
Connect with us on
| | | |