Home Malware Programs Trojans Trojan.Ransomcrypt.C

Trojan.Ransomcrypt.C

Posted: April 17, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 42
First Seen: April 17, 2013
Last Seen: August 18, 2020
OS(es) Affected: Windows

Trojan.Ransomcrypt.C is a Trojan that encrypts certain documents on the affected computer system. When executed, Trojan.Ransomcrypt.C creates potentially malicious files. Trojan.Ransomcrypt.C creates the registry entries so that it can run automatically every time Windows is started. Trojan.Ransomcrypt.C inserts itself into the process called 'msiexec.exe'. Trojan.Ransomcrypt.C checks for an Internet connection by connecting to the particular web address. Trojan.Ransomcrypt.C scans all local drives for files with the extensions such as .ddrw, .pptm, .dotm, .xltx, .text, .docm, .djvu, .potx, .jpeg, .pptx, .sldm, .xlsm, .sldx, .xlsb, and many more. Trojan.Ransomcrypt.C encrypts all files that it finds and adds a .html extension.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\10050 File name: %UserProfile%\Application Data\10050
Group: Malware file
%UserProfile%\Application Data\SQL Server Compact Edition\TimeDateMUICallback.exe File name: %UserProfile%\Application Data\SQL Server Compact Edition\TimeDateMUICallback.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Application Data\SoftwareDistribution\WPDShServiceObj.exe File name: %UserProfile%\Application Data\SoftwareDistribution\WPDShServiceObj.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Application Data\SQL Server Compact Edition\TimeDateMUICallback.mui File name: %UserProfile%\Application Data\SQL Server Compact Edition\TimeDateMUICallback.mui
Mime Type: unknown/mui
Group: Malware file
%UserProfile%\Application Data\SoftwareDistribution\WPDShServiceObj.mui File name: %UserProfile%\Application Data\SoftwareDistribution\WPDShServiceObj.mui
Mime Type: unknown/mui
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"WPDShServiceObj" = "%UserProfile%\Application Data\SoftwareDistribution\WPDShServiceObj.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"TimeDateMUICallback" = "%UserProfile%\Application Data\SQL Server Compact Edition\TimeDateMUICallback.exe"
Loading...