Home Malware Programs Trojans Trojan:Win32/Ransom.Q

Trojan:Win32/Ransom.Q

Posted: November 16, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 96
First Seen: November 16, 2012
Last Seen: November 26, 2022
OS(es) Affected: Windows

Trojan:Win32/Ransom.Q is a Trojan that is a part of Russian ransomware. Trojan:Win32/Ransom.Q locks the compromised PC stating that the installed version of Windows is not valid and demands a ransom from the affected computer user by asking him/her to send a text message to a premium-charge number in order to receive a response code to make a targeted machine usable. Once executed, Trojan:Win32/Ransom.Q drops potentially malicious files. Trojan:Win32/Ransom.Q displays a fake pop-up image/alert supposedly sent by the Microsoft Corporation including an invalid phone number; however the number given in a bogus notification uses an incorrect country code, +4 instead of +7, and is not a Microsoft support number. Trojan:Win32/Ransom.Q may be installed on the corrupted computer by other malware threats and may be existent as a file in the Windows folder, with an icon, which resembles a Microsoft PowerPoint data file. When activated, Trojan:Win32/Ransom.Q modifies the Windows Registry so that it can run automatically every time you start Windows. Trojan:Win32/Ransom.Q also attempts to stop numerous legitimate processes on the infected computer system. Trojan:Win32/Ransom.Q blocks certain programs on an infected computer. When the Windows shell is terminated, Trojan:Win32/Ransom.Q disables many common user operations.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%windir%\mfo.exe File name: %windir%\mfo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "mfo.exe" = "%windir%\mfo.exe"
Loading...