JTWWUOOG.EXE – Trojan-Ransom Winlock

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

JTWWUOOG.EXE – Trojan-Ransom Winlock removal

File MD5 Virus Alias
JTWWUOOG.EXE 475b66300491ec59d5e70b7b1adcb003 Trojan-Ransom Winlock
JTWWUOOG.EXE 475b66300491ec59d5e70b7b1adcb003 Trojan SuspiciousFile
JTWWUOOG.EXE 475b66300491ec59d5e70b7b1adcb003 Trojan Artemis
JTWWUOOG.EXE 475b66300491ec59d5e70b7b1adcb003 Trojan Crypt

JTWWUOOG.EXE size: 104761 bytes
JTWWUOOG.EXE hash: 475B66300491EC59D5E70B7B1ADCB003

Created files:

%Program Files%\Windows Media Player\jTWwUoog.exe
%Local AppData%\Microsoft\BovXdYyO.exe
%SysDir%\config\systemprofile\Start Menu\Programs\Startup\sdmmVYnN.exe
%TEMP%\OLCjeUbW.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: %WinDir%\System32\userinit.exe,,%Program Files%\Windows Media Player\jTWwUoog.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\AkjsDDLS: %WinDir%\System32\config\Systemprofile\Local Settings\Application Data\Microsoft\BovXdYyO.exe

Detected by UnHackMe:

JTWWUOOG.EXE
Default location: %PROGRAM FILES%\WINDOWS MEDIA PLAYER\JTWWUOOG.EXE

Dropper information:
MD5: 475b66300491ec59d5e70b7b1adcb003
File size: 104761 bytes

Leave a Reply