Home Malware Programs Trojans Trojan.Ransom.EZ

Trojan.Ransom.EZ

Posted: July 20, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 105
First Seen: July 20, 2012
OS(es) Affected: Windows

Trojan.Ransom.EZ (Trojan:Win32/Ransom.EZ) is a Trojan that poses as a genuine software program and, thus, attempts to mislead and convince affected PC users into downloading and installing it. Trojan:Win32/Ransom.EZ is generated by web attackers to stay hidden on an infected computer. Trojan:Win32/Ransom.EZ enables attackers to obtain remote access and control over the compromised PC. Trojan:Win32/Ransom.EZ can steal personal information from victims and send it to a remote server via the Internet. Trojan:Win32/Ransom.EZ may serve simply as a 'backdoor' program, opening network ports to enable other malware threats invade a corrupted PC. Trojan:Win32/Ransom.EZ is also capable of initiating Denial of Service (DoS) attacks. Trojan:Win32/Ransom.EZ can download or upload files on the affected computer. Trojan:Win32/Ransom.EZ can also modify or delete files. Trojan:Win32/Ransom.EZ can spread via spam email attachments, instant messaging, image files or system vulnerabilities.

Aliases

Win32.SuspectCrc [Ikarus]Heuristic.LooksLike.Win32.Suspicious.B [McAfee-GW-Edition]TR/FakeAV.EB.8 [AntiVir]Trojan.AVKill.19024 [DrWeb]Gen:Variant.Graftor.35625 [BitDefender]Trojan-Ransom.Win32.Agent.azd [Kaspersky]Win32/Adware.SystemSecurity.AL [NOD32]FakeAlert-SecurityTool.er [McAfee]Generic28.BXMF [AVG]W32/Gimemo.G!tr [Fortinet]Trojan.SuspectCRC [Ikarus]Backdoor/Win32.Bifrose [AhnLab-V3]Mal/VBInj-G [Sophos]TR/Crypt.PEPM.Gen [AntiVir]Trojan.Winlock.5554 [DrWeb]
More aliases (263)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\0.7605177068147073.exe File name: 0.7605177068147073.exe
Size: 118.78 KB (118784 bytes)
MD5: 67192be100fa0e8c34d227aedd258e68
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: July 20, 2012
%APPDATA%\Hibhlhn\95AF81FBA43664882967.exe File name: 95AF81FBA43664882967.exe
Size: 58.36 KB (58368 bytes)
MD5: e7016f6fcdd11124077c030f45d7bf22
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Hibhlhn
Group: Malware file
Last Updated: July 30, 2012
Loading...