Home Malware Programs Trojans Trojan.Winlock.7431

Trojan.Winlock.7431

Posted: November 27, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 323
First Seen: November 27, 2012
Last Seen: May 4, 2024
OS(es) Affected: Windows

Trojan.Winlock.7431 is a Trojan that is associated with TDSS rootkit and other malware threats. Trojan.Winlock.7431 is used by attackers to spread various ransomware infections. Trojan.Winlock.7431 steals personal information and money from affected computer user. Once executed, Trojan.Winlock.7431 locks the targeted computer system and displays the fake pop-up image/alert supposedly sent by the police or other legitimate security organization. The fraudulent warning message of the certain ransomware program delivered by Trojan.Winlock.7431 accuses PC users of violating certain laws and asks them to pay a fine to avoid arrest. The bogus pop-up notification created and displayed by Trojan.Winlock.7431 provides PC users with instructions on how to unlock the computer.

Aliases

Suspicious file [Panda]Win32/Cryptor [AVG]W32/Injector.ZVR!tr [Fortinet]Win32.SuspectCrc [Ikarus]Mal/EncPk-AGD [Sophos]TR/Symmi.14935.41 [AntiVir]UDS:DangerousObject.Multi.Generic [Kaspersky]Suspicious.Cloud.5 [Symantec]Artemis!7F9AB2CBFFC4 [McAfee]Trj/CI.A [Panda]Downloader.Generic13.XUW [AVG]W32/Andromeda.ELT!tr.dldr [Fortinet]Downloader/Win32.Andromeda [AhnLab-V3]TR/Graftor.59939.1 [AntiVir]Trojan.Winlock.7431 [DrWeb]
More aliases (33)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\Microsoft\Windows\2575\sqlncli.exe File name: sqlncli.exe
Size: 88.57 KB (88576 bytes)
MD5: 931d0c608562f9200f42665040c98af1
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Microsoft\Windows\2575
Group: Malware file
Last Updated: February 7, 2013
%ALLUSERSPROFILE%\fbbbfabefbcsacfsfdsf.exe File name: fbbbfabefbcsacfsfdsf.exe
Size: 146.43 KB (146432 bytes)
MD5: 7f9ab2cbffc4e8e8579ec4da7e7a7437
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 22, 2013
Loading...