Threat Database Trojans Trojan.Ransomcrypt.C

Trojan.Ransomcrypt.C

By JubileeX in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 18
First Seen: April 17, 2013
Last Seen: August 18, 2020
OS(es) Affected: Windows

Trojan.Ransomcrypt.C is a Trojan that encrypts specific documents on the compromised PC. Once run, Trojan.Ransomcrypt.C creates harmful files. Trojan.Ransomcrypt.C creates the registry entries so that it can load automatically whenever you start Windows. Trojan.Ransomcrypt.C adds itself into the process named 'msiexec.exe'. Trojan.Ransomcrypt.C checks for an Internet connection by connecting to the specific domains. Trojan.Ransomcrypt.C scans all local drives for files with the extensions such as .ddrw, .pptm, .dotm, .xltx, .text, .docm, .djvu, .potx, .jpeg, .pptx, .sldm, .xlsm, .sldx, .xlsb, and many more. Trojan.Ransomcrypt.C encrypts all files that it finds and inserts a .html extension.

File System Details

Trojan.Ransomcrypt.C may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\SoftwareDistribution\WPDShServiceObj.exe
2. %UserProfile%\Application Data\SQL Server Compact Edition\TimeDateMUICallback.exe
3. %UserProfile%\Application Data\SoftwareDistribution\WPDShServiceObj.mui
4. %UserProfile%\Application Data\SQL Server Compact Edition\TimeDateMUICallback.mui
5. %UserProfile%\Application Data\10050

Registry Details

Trojan.Ransomcrypt.C may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"TimeDateMUICallback" = "%UserProfile%\Application Data\SQL Server Compact Edition\TimeDateMUICallback.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"WPDShServiceObj" = "%UserProfile%\Application Data\SoftwareDistribution\WPDShServiceObj.exe"

Trending

Most Viewed

Loading...