Threat Database Trojans Trojan.Ransomlock.N

Trojan.Ransomlock.N

By ZulaZuza in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 25
First Seen: May 10, 2012
OS(es) Affected: Windows

Trojan.Ransomlock.N is a cybercriminal's online version of a kidnapping that demands ransom for the release of your computer. Trojan.Ransomlock.N attacks Windows-based systems and contains programming able to lock up or kidnap the infected computer's functionality. Victims will be blocked from using the keyboard or mouse and all applications, and will be shown a ransom note containing a lewd image that accuses them of watching gay porn for free. To supposedly unlock the infected system, victims must make a Beeline system payment of $400 USD.

While the Russian-based ransom scam promises to 'release' or unlock the system for payment, this is a bold-face lie. The systematic attack is programmed to repeat at each Windows start. In truth, the data has not been removed as threaten it, one only needs to reverse this selection. However, as mentioned earlier, this will not make the infection go away since Trojan.Ransomlock.N has been cleverly stored and hidden in the memory.

To remove Trojan.Ransomlock.N and protect your system going forth from continuous malware attacks, you should rely on a professional anti-malware solution to bail out your system. A reliable anti-malware system can restore corrupted files and components, reverse malicious system changes and unearth as well as destroy hidden malware without harming your hard drive.

Aliases

10 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Suspicious file
AVG Dropper.Generic7.IGF
AhnLab-V3 Trojan/Win32.Inject
AntiVir TR/Rogue.kdv.788924
Comodo UnclassifiedMalware
Sophos Mal/EncPk-AGD
Kaspersky Trojan-Dropper.Win32.Dinwod.acr
Avast Win32:Carberp-ALL [Trj]
Symantec Trojan.Ransomlock.N
McAfee Artemis!3A7FEF568856

SpyHunter Detects & Remove Trojan.Ransomlock.N

File System Details

Trojan.Ransomlock.N may create the following file(s):
# File Name MD5 Detections
1. e54yher4h6j.exe 3a7fef568856529bfcfc7cdd75ace515 9
2. itunes_service01.exe 56f4d5837af32b12069576fae8c2b3c5 7
3. ArchiverforWin.exe 51efd076876fe7fa49fe69f377720e85 7
4. flint4ytw.exe 21e582cc765de5bb58191200e9f54e77 2
5. %UserProfile%\Application Data\itunes_service01.exe

Registry Details

Trojan.Ransomlock.N may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "%UserProfile%\Application Data\itunes_service01.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "%UserProfile%\Application Data\itunes_service01.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideIcons" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\"1400" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\"DefaultConnectionSettings"
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "%UserProfile%\Application Data\itunes_service01.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "%UserProfile%\Application Data\itunes_service01.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoDesktop" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableRegistryTools" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\"1400" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "%UserProfile%\Application Data\itunes_service01.exe,C:\WINDOWS\System32\userinit.exe,"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{Bj9oGoDo-wn3q-TS4w-kuRv-OWYzmoDRGxZa}\"[RANDOM CHARACTERS]" = "\"%UserProfile%\Application Data\itunes_service01.exe\" /ActiveX"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "%UserProfile%\Application Data\itunes_service01.exe,C:\WINDOWS\System32\userinit.exe,"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableTaskMgr" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1400" = "0"

Trending

Most Viewed

Loading...