Examples of Troj/Ransom-MW include:
Example 1
File Information
- Size
- 133K
- SHA-1
- 0306513db03648ed7b13654dababec23b820f96d
- MD5
- 86068abd6aaa53ec3c8c38dedc3d7572
- CRC-32
- 70a48e60
- File type
- Windows executable
- First seen
- 2013-01-20
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Application Data\skype.dat
Registry Keys Modified
- HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
- Shell
- explorer.exe,c:\Documents and Settings\test user\Application Data\skype.dat
Processes Created
- c:\windows\system32\svchost.exe
Example 2
File Information
- Size
- 97K
- SHA-1
- 130ff4614a846020175c5e70376b61b88c5388ef
- MD5
- c0a4093d89adaa3561481267a52e119f
- CRC-32
- 298d1c0c
- File type
- Windows executable
- First seen
- 2013-02-02
Other vendor detection
- Avira
- TR/Crypt.XPACK.Gen