Home Malware Programs Trojans Trojan.Ransomlock.Q

Trojan.Ransomlock.Q

Posted: September 28, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 42
First Seen: September 28, 2012
OS(es) Affected: Windows

Trojan.Ransomlock.Q is a Trojan that locks the desktop of the targeted machine and makes the PC unusable. Trojan.Ransomlock.Q then asks the affected PC user to pay a ransom to unlock it. Once executed, Trojan.Ransomlock.Q creates several potentially malicious files. Trojan.Ransomlock.Q also creates several registry entries and one specific entry that allows it to run automatically every time you start Windows. Trojan.Ransomlock.Q determines the geographical location of the vulnerable PC and displays an image specific to a certain location.

Aliases

Suspicious file [Panda]UDS:DangerousObject.Multi.Generic [Kaspersky]Trj/Dtcontx.A [Panda]Generic31.RQU [AVG]W32/LockScreen.AQC!tr [Fortinet]Win32.Rootkit [Ikarus]Win32:Rootkit-gen [GData]Trojan/Win32.Ransomlock [AhnLab-V3]TR/LockScreen.CS [AntiVir]Trojan.DownLoader7.49132 [DrWeb]Troj/Ransom-MR [Sophos]Win32:Rootkit-gen [Rtk] [Avast]Trojan.Ransomlock.Q [Symantec]Artemis!303D4A6E8B39 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Users\<username>\AppData\Roaming\skype.dat File name: skype.dat
Size: 84.99 KB (84992 bytes)
MD5: 303d4a6e8b39143e5ced87c4f244b607
Detection count: 26
File type: Data file
Mime Type: unknown/dat
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: February 14, 2013
%APPDATA%\AltShell.dat File name: AltShell.dat
Size: 31.74 KB (31744 bytes)
MD5: 990f5f3274ee543ad80f6ed1f074e415
Detection count: 16
File type: Data file
Mime Type: unknown/dat
Path: %APPDATA%
Group: Malware file
Last Updated: September 14, 2013
%UserProfile%\Application Data\msconfig.ini File name: %UserProfile%\Application Data\msconfig.ini
Mime Type: unknown/ini
Group: Malware file
%UserProfile%\Application Data\msconfig.dat File name: %UserProfile%\Application Data\msconfig.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "explorer.exe,%UserProfile%\Application Data\msconfig.dat"HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Loading...