Error » Security Error » Security News » Ransom-C

Security News The Latest Computer Security News

Post New Thread Reply
  Ransom-C
LinkBack Thread Tools Display Modes
Old 22-Jan-2007, 04:51 AM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,715
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default Ransom-C

Ransom-C

Risk Assessment - Home Users: Low - Corporate Users: Low Date Discovered: 1/12/2007 Date Added: 1/12/2007 Origin: N/A Length: Varies Type: Trojan SubType: Win32 DAT Required: 4938 Virus Characteristics

Ransom-C is a trojan that delete files from the infected machine, and display a message in Chinese requesting for a fee from the user to recover the deleted data.
This trojan can often arrive in a spoofed e-mail notifying the user of a "important events" or "great deals" such as the following:

This e-mail spoofs as the mail administrator notifying the user of a "system upgrade", requesting the user to open the attachmen to prevent the account from being terminated.
More recently, websites were discovered to be hosting Exploit-MS06-014 that installs Ransom-C without a need for user interaction on vulnerable web browsers. They include legitimate financial news, medical websites, etc. that were believed to have been penetrated by the trojan author. When the exploit is successful, it follows to download and install a abc.exe.pif executable containing Ransom-C.
In some cases, a.RAR file which resembles the file attachments used in the spoofed e-mails are placed on a spoofed hyperlink on the penetrated website. For example, the hyperlink could be displaying a description of "Directions to the XYZ Hospital" but lets the user download a .RAR containing the Ransom-C trojan:

Upon execution, Ransom-C makes a copy of itself in the Start-Programs->Startup menu as svchost.exe as well as X:\Documents and Settings\%User%\Application Data\Microsoft\win1ogon.exe.
(Where X: is the system drive letter e.g. C:, and %User% is the current user ID)
It then displays the following pop-up window:

This pop-up window claims that unlicensed software was detected and have been moved to a restricted folder. To unlock these files, the user must send an e-mail to webmas[hidden]@yahoo.com.cn to purchase the "licensed" software.
NOTE: Our analysis shows that the files are not moved but effectively deleted from the infected computer including mounted drives on external media (e.g. memory cards, hard drives). This implies a reliable method to fully recover the files would be unlikely.
Ransom-C drops a text file on the desktop reiterating its claims and reboots the system each time the pop-up window is closed.



Indications of Infection

Presence and/or modification of the following registry keys:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ Run\"svchost.exe" = "X:\Documents and Settings\%User%\Application Data\Microsoft\win1ogon.exe"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\shell\ open\command\ = "X:\Documents and Settings\%User%\Application Data\Microsoft\win1ogon.exe" (hooks to the opening of text files)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ Explorer\Advanced\Folder\Hidden
Presence of the following file(s):
  • X:\Documents and Settings\%User%\Application Data\Microsoft\win1ogon.exe (Ransom-C)
  • "X:\Documents and Settings\%User%\Start Menu\Startup\svchost.exe (Ransom-C)
(Where X: is the system drive letter e.g. C:, and %User% is the current user ID)
Display of the pop up windows depicted in "Characteristics".


Method of Infection

Ransom-C has been known to be propagated via spoofed e-mails with attachments, browsing upon hacked websites hosting spoofed hyperlinks and/or Exploit-MS06-14.



Removal Instructions

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination. Additional Windows ME/XP removal considerations
Instead of encrypting or moving files from the victim's machine, Ransom-C effectively deletes them. A reliable method to fully recover the files is unlikely. Due to the design of the Windows file system. Disk segments marked deleted can be overwritten by new data.
Data deleted by Ransom-C should be restored from backup.
Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 11:26 PM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228