Infection Channel: Downloaded from the Internet
This Trojan may be downloaded by other malware/grayware from remote sites.
File size: 66,048 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 27 Sep 2012
Payload: Displays ransom message, Terminates processes
Arrival Details
This Trojan may be downloaded by the following malware/grayware from remote sites:
It may be downloaded from the following remote site(s):
- http://{BLOCKED}0.com/c/osnovnoj2.exe?{random number}
Other System Modifications
This Trojan modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
(Default) = "{malware path and file name}"
(Note: The default value data of the said registry entry is {blank}.)
It deletes the following registry keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\SafeBoot\Minimal
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\SafeBoot\Network
Process Termination
This Trojan terminates the following processes if found running in the affected system's memory:
- cmd.exe
- msconfig.exe
- regedit.exe
- taskmgr.exe
NOTES:
It removes the taskbar.
It accesses the following URL to display the ransom message:
- http://{random characters}.unionfilesexchnges.su/get.php?id=2 - detected by Trend Micro as HTML_RANSOM.CMY
Connect with us on
| | | |