Home→Descriptions→Trojan-Ransom.Win32.DigiPog.xp
| Detected | Aug 26 2010 03:14 GMT |
| Released | Aug 26 2010 13:12 GMT |
| Published | Oct 26 2010 13:24 GMT |
This Trojan disables a machine in order to obtain a ransom for restoring the system to its original condition. It is a Windows application (PE EXE file). It is 151 040 bytes in size. It is written in C++.
Once launched, the Trojan performs the following actions:
Tmas.exe ekrn.exe gcasServ.exe msscli.exe avp.exe dwengine.exe avastsvc.exe avguard.exe winroute.exe zlclient.exe op_mon.exe
%WorkDir%\libgcc_s_dw2-1.dll %WorkDir%\libgcj_s.dll
%USERPROFILE%\Application Data\efhhcwck.ddr (1598 bytes)It also creates the following system registry key:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform] "0X29A"
%USERPROFILE%\Application Data\efhhcwck.exe
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "PC Health Status" = "%USERPROFILE%\Application Data\efhhcwck.exe" [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "PC Health Status" = "%USERPROFILE%\Application Data\efhhcwck.exe"It also creates the shortcut:
%USERPROFILE%\Start Menu\Programs\Startup\healm_jamc.lnkThis shortcut points to the created copy.



188.***.168the following HTTP requests:
HTTP/1.0 GET /_req/?type=e&sid=2&sw=00000000000000000&ostype=2&ossp=2&osbits=0&osfwtype=2&osrights=255 /_req/?type=m&sid=2&sw=00000000000000000
Once launched, the Trojan performs the following actions:
%USERPROFILE%\Application Data\efhhcwck.ddr
Global\dobeDNNLjpgo
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr" = "1" [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoLogoff" = "1"Thereby it stops the Task Manager from launching, and hides the "Shut down" sub-menu in the Start menu.
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "MigrateProxy" = "1" "ProxyEnable" = "1" "ProxyServer" = "http=127.0.0.1:41653;"At the same time, it deletes the following keys:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyOverride" "AutoConfigURL"These keys are created and deleted in an endless cycle.
www.drweb.com/unlocker www.esetnod32.ru/.support/winlock http://virusinfo.info/deblocker http://support.kaspersky.ru/viruses/deblocker
far.exe msconfig.exe taskmgr.exe taskkill.exe avz.exe regedit.exe procmon.exe

188.***.168the following request:
HTTP/1.0 GET _req/?type=s&sid=2&sw=00000000000000001&ostype=2&ossp=2&osbits=0&osfwtype=2&osrights=255
If your computer does not have antivirus protection and has been infected by this malicious program, follow the instructions below to delete it:
%USERPROFILE%\Application Data\efhhcwck.ddr %USERPROFILE%\Application Data\efhhcwck.exe %USERPROFILE%\Start Menu\Programs\Startup\healm_jamc.lnk
[HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform] "0X29A" [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "PC Health Status" = "%USERPROFILE%\Application Data\efhhcwck.exe" [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "PC Health Status" = "%USERPROFILE%\Application Data\efhhcwck.exe" [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr" = "1" [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoLogoff" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "MigrateProxy" "ProxyEnable" "ProxyServer" "ProxyOverride" "AutoConfigURL"
MD5: 5433BBDADE3E6801BAC602D2FD636E74
SHA1: 95D34CCFBC0E8B0DDDC12B120634ED686F6A8721
This type of Trojan modifies data on the victim computer so that the victim can no longer use the data, or it prevents the computer from running correctly. Once the data has been “taken hostage" (blocked or encrypted), the user will receive a ransom demand.
The ransom demand tells the victim to send the malicious user money; on receipt of this, the cyber criminal will send a program to the victim to restore the data or restore the computer’s performance.