Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJANRANSOM.PORNOASSEST.ZG

 

 

 

Name:

TrojanRansom.PornoAsset.zg

Added:

October 14, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Description:

 

When TrojanRansom.PornoAsset.zg is executed, it performs the following activities:

After execution, it drops the following files:

%Appdata%\22CC6C32.exe
%Appdata%\yO3jzO4kzP4.exe
%system%\03014D3F.exe

It modifies the following files:

%system%\taskmgr.exe
%system%\userinit.exe
%system%\dllcache\taskmgr.exe
%system%\dllcache\userinit.exe

It creates/modifies the following registry entries:

Shell: "%Appdata%\22CC6C32.exe"
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

When the user logins to the system, it displays the following screen and does not allow the user to go inside.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Malware problems?
We can help.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Evaluate Thirtyseven4 Antivirus Now

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4