Home Malware Programs Trojans Trojan.Ransomlock.Y

Trojan.Ransomlock.Y

Posted: October 10, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 19
First Seen: October 10, 2012
Last Seen: April 21, 2022
OS(es) Affected: Windows

Trojan.Ransomlock.Y is a Trojan that is a part of the FBI Green Dot Moneypak Virus ransomware threat. Trojan.Ransomlock.Y locks the desktop of the compromised PC and makes the computer unusable. Trojan.Ransomlock.Y then asks the PC user to pay a ransom to unlock it. Once executed, Trojan.Ransomlock.Y creates the certain file on the affected computer system. Trojan.Ransomlock.Y creates the certain registry entry so that it can run automatically every time you start Windows. Trojan.Ransomlock.Y also creates several other registry entries. Trojan.Ransomlock.Y deletes the particular registry entries in an attempt to disable Safe Mode Boot. Trojan.Ransomlock.Y stops the legitimate processes, such as msconfig.exe, taskmgr.exe, cmd.exe and regedit.exe making it difficult to stop the threat from running.

Aliases

Trj/WL.A [Panda]W32/Agent.AB!tr [Fortinet]W32/Trojan2.NURT [F-Prot]Trojan.Agent.uyaj.cw7 [CAT-QuickHeal]W32/Zbot.DHN!tr [Fortinet]Trojan.Signed [Ikarus]Trojan/Win32.Zbot [AhnLab-V3]TR/Crypt.ZPACK.Gen8 [AntiVir]Trojan.Gen [Symantec]Trojan.Agent.uyre [CAT-QuickHeal]Trj/Genetic.gen [Panda]Mal/Ransom-AB [Sophos]Trojan.Generic.KDZ.353 [BitDefender]PWS-Zbot.gen.aqt [McAfee]Trojan.Tobfy [CAT-QuickHeal]
More aliases (126)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\013b42455bee.exe File name: 013b42455bee.exe
Size: 252.4 KB (252408 bytes)
MD5: 8fd1760a1b92e96a4ec4d1f12ce890f5
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 19, 2012
%TEMP%\013b41f1fd3c.exe File name: 013b41f1fd3c.exe
Size: 252.4 KB (252408 bytes)
MD5: 4be9beb19245028606f2647fe7df33fa
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 17, 2012
%TEMP%\013b525322ba.exe File name: 013b525322ba.exe
Size: 215.03 KB (215032 bytes)
MD5: 454c042cb640f9d7df1da5e049a78b2e
Detection count: 55
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 12, 2012
%TEMP%\013aeaed16db.exe File name: 013aeaed16db.exe
Size: 190.62 KB (190624 bytes)
MD5: b8daa3f9f1d2aef78d95aa9467a84ba3
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: November 15, 2012
%TEMP%\013b4629c367.exe File name: 013b4629c367.exe
Size: 247.28 KB (247288 bytes)
MD5: f641382a6ebb664642dba2bec3c3af63
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 19, 2012
[TROJAN PATH]/1.mp3 File name: [TROJAN PATH]/1.mp3
Mime Type: unknown/mp3
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft Updater"="[TROJAN PATH AND FILENAME]"HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\netHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\mini
Loading...