This ransomware Trojan uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed. Specifically, upon its execution, the infected system is shut down and then restart, rendering the system unusable. It prompts user to pay a certain amount to receive the key that would unlock the system.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

It locks the Windows desktop and prompts the user to call the number 9653919220 and pay the 450 Rubles ($15) ransom to receive a key. Based on its code, the key to unlock the desktop is "TNMTTF". Unless the user pays the ransom, the system remains unusable. It displays the following GUI:

This Trojan may be dropped by other malware. It may be unknowingly downloaded by a user while visiting malicious websites.
File size: 53,760 bytes
File type: PE
Memory resident: Yes
Initial samples received date: 21 Jan 2011
Payload: Displays windows, Disables Windows desktop
Arrival Details
This Trojan may be dropped by other malware.
It may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This Trojan drops the following files:
- %User Profile%\161933172\161933172.exe - also detected as TROJ_RANSOM.JM
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
It creates the following folders:
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
ZDF161933172AWrt161933172AdsWrt161933172aAdsWrtenZDF161933172_1619331720 = %User Profile%\161933172\161933172.EXE
Other Details
This Trojan does the following:
- Locks the Windows desktop and prompts the user to call a certain number and pay the 450 Rubles ($15) ransom to receive a key. Based on its code, the key to unlock the desktop is "TNMTTF". Unless the user pays the ransom, the system remains unusable. It displays the following GUI:

Connect with us on
| | | |