Troj/Ransom-MW

Category: Viruses and Spyware Protection available since:04 Feb 2013 23:23:57 (GMT)
Type: Trojan Last Updated:04 Feb 2013 23:23:57 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/Ransom-MW include:

Example 1

File Information

Size
133K
SHA-1
0306513db03648ed7b13654dababec23b820f96d
MD5
86068abd6aaa53ec3c8c38dedc3d7572
CRC-32
70a48e60
File type
Windows executable
First seen
2013-01-20

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\skype.dat
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Shell
    explorer.exe,c:\Documents and Settings\test user\Application Data\skype.dat
Processes Created
  • c:\windows\system32\svchost.exe

Example 2

File Information

Size
97K
SHA-1
130ff4614a846020175c5e70376b61b88c5388ef
MD5
c0a4093d89adaa3561481267a52e119f
CRC-32
298d1c0c
File type
Windows executable
First seen
2013-02-02

Other vendor detection

Avira
TR/Crypt.XPACK.Gen

download Try Sophos products for free
Download now