Saturday, 30 April 2011

Trojan.Ransom (video72.avi.exe)



This trojan blocker ( MD5: 3ac583144db09e3c8b64d809a93b592e ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
According to VirusTotal the sample was detected by just 2 Antivirus: https://www.virustotal.com/file-scan/report.html?id=24deedcb7860dde2c9de6a2501a2436f611b9daa79ed9e70a07242a7c16ba5a2-1304083200

Crypter in visual basic and ransom in Delphi.
Infected users have 1440 minutes (1 day) to enter the good serial.


Number to Call: 8 (906) 096-4547 ~ 89060964547
Code to unlock Windows: 878-878-878-878-878-878-878

Serial check:


Thanks to mrbelyash for the sample

No comments:

Post a Comment