Troj/Ransom-MW

Category: Viruses and Spyware Protection available since:04 Feb 2013 23:23:57 (GMT)
Type: Trojan Last Updated:21 Aug 2013 20:49:15 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/Ransom-MW include:

Example 1

File Information

Size
133K
SHA-1
002b50182565a7757a5b6e9f5481b6d927966319
MD5
d7108339095097f6eb2dd1c0a19d27ed
CRC-32
38c4a7e8
File type
Windows executable
First seen
2013-02-04

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\skype.dat
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Shell
    explorer.exe,c:\Documents and Settings\test user\Application Data\skype.dat
Processes Created
  • c:\windows\system32\svchost.exe

Example 2

File Information

Size
41K
SHA-1
00495229f89f7bf62c3315bff8526192c9b81293
MD5
dcf2ddab89b4c2861fdd3434af33eb00
CRC-32
5a35f1c2
File type
Windows executable
First seen
2013-02-01

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\skype.dat
Dropped Files
  • c:\Documents and Settings\test user\Application Data\skype.ini
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Shell
    explorer.exe,c:\Documents and Settings\test user\Application Data\skype.dat
Processes Created
  • c:\windows\system32\svchost.exe
HTTP Requests
  • http://efbm.su/news/kqcb-kydf_tmysgl-gavt-nopm-faosltezarhcatuyuogjgaqupyukuucb-yttyjpqcptof_pflxmxkqqjll-hcfajg.html
  • http://rdvc.ru/forums/cjynspgbnnrpfaaunf-stkd-uxxjqkvqlgsttiuamyjuosdrmpbwxoyb-ksfzcj-acsiauionevppqoupmsdla-vi.html
DNS Requests
  • efbm.su
  • rdvc.ru

Example 3

File Information

Size
133K
SHA-1
0306513db03648ed7b13654dababec23b820f96d
MD5
86068abd6aaa53ec3c8c38dedc3d7572
CRC-32
70a48e60
File type
Windows executable
First seen
2013-01-20

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\skype.dat
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Shell
    explorer.exe,c:\Documents and Settings\test user\Application Data\skype.dat
Processes Created
  • c:\windows\system32\svchost.exe

download Try Sophos products for free
Download now