Troj/Ransom-MN

Category: Viruses and Spyware Protection available since:19 Jan 2013 22:57:10 (GMT)
Type: Trojan Last Updated:19 Jan 2013 22:57:10 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Ransom-MN exhibits the following characteristics:

File Information

Size
49K
SHA-1
c420f667984c41370e34dfe97d46335fe7dac414
MD5
ff4979e644dd8106bbd5116897ea8991
CRC-32
9e4590ef
File type
Windows executable
First seen
2013-01-19

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Zzppllmmq\ttlleepbvmu.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    vjkubvmu
    c:\Documents and Settings\test user\Zzppllmmq\ttlleepbvmu.exe
Processes Created
  • c:\docume~1\support\locals~1\temp\dbbjjpkkee.pre
  • c:\windows\system32\ctfmon.exe
  • c:\windows\system32\svchost.exe
HTTP Requests
  • http://namelesscorn.net/UTP402HEAD.php
DNS Requests
  • namelesscorn.net

download Try Sophos products for free
Download now