TROJ_CRYPCTB.TMC
Ransom:Win32/Critroni.A (MICROSOFT), a variant of Win32/Injector.BRJT trojan (NOD32)
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
Downloaded from the Internet, Dropped by other malware
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
827,392 bytes
EXE
Yes
Encrypts files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- %User Profile%\My Documents\Decrypt All Files {random characters}.bmp - image used as wallpaper
- %User Profile%\My Documents\Decrypt All Files {random characters}.txt - ransom note in text file
- %User Profile%\My Documents\{random characters}.html - contains ransom note and list of encrypted files
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
Autostart Technique
This Trojan drops the following files:
- C:\Windows\Tasks\{random filename}.job
Other System Modifications
This Trojan modifies the following registry entries:
HKEY_CURRENT_USER\Control Panel\Desktop
Wallpaper = "%User Profile%\My Documents\Decrypt All Files {random characters}.bmp"
(Note: The default value data of the said registry entry is {user-defined}.)
Other Details
This Trojan encrypts files with the following extensions:
- 7z
- arj
- bz2
- cab
- chm
- cpio
- dmg
- flv
- gz
- lha
- lzh
- lzma
- rar
- swm
- tar
- tbz2
- tgz
- wim
- xar
- xz
- z
- zip
- 3gp
- aac
- ans
- ape
- asc
- asm
- asp
- aspx
- avi
- awk
- bas
- bat
- bmp
- c
- cs
- cls
- clw
- cmd
- cpp
- csproj
- css
- ctl
- cxx
- def
- dep
- dlg
- dsp
- dsw
- eps
- f
- f77
- f90
- f95
- fla
- flac
- frm
- gif
- h
- hpp
- hta
- htm
- html
- hxx
- ico
- idl
- inc
- ini
- inl
- java
- jpeg
- jpg
- js
- la
- mak
- manifest
- wmv
- mov
- mp3
- mp4
- mpe
- mpeg
- mpg
- m4a
- ofr
- ogg
- pac
- pas
- php
- php3
- php4
- php5
- phptml
- pl
- pm
- png
- ps
- py
- pyo
- ra
- rb
- rc
- reg
- rka
- rm
- rtf
- sed
- sh
- shn
- shtml
- sln
- sql
- srt
- swa
- tcl
- tex
- tiff
- tta
- txt
- vb
- vcproj
- vbs
- wav
- wma
- wv
- xml
- xsd
- xsl
- xslt