Home Malware Programs Trojans Trojan.Ransomlock.X

Trojan.Ransomlock.X

Posted: October 8, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 7
First Seen: October 8, 2012
OS(es) Affected: Windows

Trojan.Ransomlock.X is a Trojan that locks the desktop of the compromised PC and makes the PC unusable. Trojan.Ransomlock.X locks the targeted machine and displays a fake pop-up warning message, which states to come from law enforcement. The bogus pop-up notification related to Trojan.Ransomlock.X claims that the PC user has been recognized to perform illegitimate activities on their computers. Trojan.Ransomlock.X then asks the affected PC user to pay a so-called fine of 100 Euro through various online payment systems, such as Ukash or Paysafecard to unlock it. Once executed, Trojan.Ransomlock.X creates the certain file on the vulnerable computer system.

Aliases

Trj/CI.A [Panda]W32/Weelsof.B!tr [Fortinet]Trojan.Win32.Weelsof [Ikarus]Trojan/Win32.Weelsof [AhnLab-V3]TR/Weelsof.sj.1 [AntiVir]UnclassifiedMalware [Comodo]Mal/Weelsof-A [Sophos]Win32:Dropper-gen [Drp] [Avast]Trojan.Ransomlock.X [Symantec]Generic Downloader.rn [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\hiffjqms.exe File name: hiffjqms.exe
Size: 105.98 KB (105984 bytes)
MD5: 8f4b31d6f90ea4654a2162b7a0499f78
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 9, 2012
%WINDIR%\qtjyicec.exe File name: qtjyicec.exe
Size: 134.65 KB (134656 bytes)
MD5: 09c8e92fd2662d3cc7077f19420a4f44
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: December 3, 2012

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}%UserProfile%\Application Data\[RANDOM CHARACTERS FILE NAME]
Loading...