Troj/Ransom-OK exhibits the following characteristics:
File Information
- Size
- 42K
- SHA-1
- 56b93336d198a1cf9be7691e6323d664baee79f0
- MD5
- 5fb9ae65f72f438c3b8d2a202ab189ef
- CRC-32
- dd7a58b2
- File type
- Windows executable
- First seen
- 2013-02-20
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Application Data\skype.dat
Registry Keys Modified
- HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
- Shell
- explorer.exe,c:\Documents and Settings\test user\Application Data\skype.dat
Processes Created
- c:\windows\system32\svchost.exe