Threat Database Trojans Trojan-Ransom.Win32.Chameleon.mw

Trojan-Ransom.Win32.Chameleon.mw

By ZulaZuza in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 62
First Seen: September 6, 2011
Last Seen: May 9, 2022
OS(es) Affected: Windows

The Trojan-Ransom.Win32.Chameleon.mw Trojan is associated with a variety of ransomware that manifests itself as a message from 'La Policia ESPAÑOLA', or the Spanish Police. This malware threat is related to similar ransomeware scams involving the Metropolitan Police or the "Bundespolizei". The Trojan-Ransom.Win32.Chameleon.mw Trojan is the underlying cause of these annoying messages. These messages usually involve blocking the infected computer completely, until the victim pays the fake police's "fine." ESG malware analysts recommend ignoring anything that is contained in the message displayed by the Trojan-Ransom.Win32.Chameleon.mw Trojan. There are ways of removing the message from the fake police and its associated Trojan, without any need of spending the 100 Euros in the demanded fine. Using an anti-malware program to remove the Trojan-Ransom.Win32.Chameleon.mw Trojan will usually get rid of the fake Spanish Police ransomware.

How the Trojan-Ransom.Win32.Chameleon.mw Trojan Scam Works

The Trojan-Ransom.Win32.Chameleon.mw scam usually involves displaying a highly realistic-looking message that claims that the infected computer has been involved in illegal activities. This message is all the more convincing, because of its use of the Spanish Police crest and because it displays easily-obtainable information, like the infected computer's IP address and operating system. The criminals behind this scam will usually demand the payment of a 100 Euro fine through UKash. If the problem stopped at a simple annoying message, this scam would be a non-issue. However, Trojan-Ransom.Win32.Chameleon.mw also has the ability to block your access to your computer system completely. Below, ESG security researchers have listed a few ways in which the Trojan-Ransom.Win32.Chameleon.mw Trojan can block your computer system:

  1. Trojan-Ransom.Win32.Chameleon.mw has the ability to prevent you from accessing your desktop, start menu or any application on your computer.
  2. Trojan-Ransom.Win32.Chameleon.mw blocks access to the Task Manager, preventing you from simply using the control, alt, delete combination of keys to shut down the message from the Fake Spanish Police.
  3. Trojan-Ransom.Win32.Chameleon.mw also blocks access to the Internet or to any security programs that may be present on the infected computer.

The message that results from the Trojan-Ransom.Win32.Chameleon.mw Trojan also threatens to erase all files on the infected computer within 24 hours, unless the fine is payed. ESG malware analysts recommend ignoring this warning. The Trojan-Ransom.Win32.Chameleon.mw Trojan has no way of deleting your files. To bypass the Trojan-Ransom.Win32.Chameleon.mw Trojan's complete hold over your computer system, ESG malware analysts recommend starting up your computer system in Safe Mode or from a different source (like a CD or an external drive.)

Registry Details

Trojan-Ransom.Win32.Chameleon.mw may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell = Trojan-Ransom.Win32.Chameleon.mw

Trending

Most Viewed

Loading...