Win32/Ransom [Threat Name] go to Threat
Win32/Ransom.K [Threat Variant Name]
Category | trojan |
Size | 382464 B |
Aliases | Trojan-Ransom.Win32.Agent.bn (Kaspersky) |
Trojan:Win32/Ransom.F (Microsoft) | |
Trojan.Winlock.104 (Dr.Web) |
Short description
Win32/Ransom.K is a trojan that blocks access to the Windows operating system. To regain access to the operating system the user is asked to send an SMS message to a specified telephone number in exchange for a password. When the correct password is entered the trojan removes itself from the computer.
Installation
When executed, the trojan copies itself into the following location:
- %windir%\Media\sound.exe (382464)
In order to be executed on system start, the trojan sets the following Registry entry:
- [HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\RunOnce]
- "sound" = "%windir%\Media\sound.exe"
Other information
The trojan displays the following dialog box:
When the correct password is entered the trojan removes itself from the computer.
The password to regain access to the operating system is one of the following:
- ub5761