VRUPCIQF.EXE – Trojan-Ransom Winlock

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

VRUPCIQF.EXE – Trojan-Ransom Winlock removal

FileMD5Virus Alias
VRUPCIQF.EXE 9631dd6ea45524fe3ad0bdefdc1a25d0 Trojan-Ransom Winlock
VRUPCIQF.EXE 9631dd6ea45524fe3ad0bdefdc1a25d0 Trojan FrauDrop
VRUPCIQF.EXE 9631dd6ea45524fe3ad0bdefdc1a25d0 Trojan Artemis
VRUPCIQF.EXE 9631dd6ea45524fe3ad0bdefdc1a25d0 Trojan XPACK
VRUPCIQF.EXE 9631dd6ea45524fe3ad0bdefdc1a25d0 Trojan Downloader
VRUPCIQF.EXE 9631dd6ea45524fe3ad0bdefdc1a25d0 Trojan Agent

VRUPCIQF.EXE size: 98304 bytes
VRUPCIQF.EXE hash: 9631DD6EA45524FE3AD0BDEFDC1A25D0

Created files:

%Program Files%\Mozilla Firefox\vrupCiqF.exe
%Local AppData%\Microsoft\BovXdYyO.exe
%SysDir%\config\systemprofile\Start Menu\Programs\Startup\sdmmVYnN.exe
%TEMP%\OLCjeUbW.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: %WinDir%\System32\userinit.exe,,%Program Files%\Mozilla Firefox\vrupCiqF.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\AkjsDDLS: %WinDir%\System32\config\Systemprofile\Local Settings\Application Data\Microsoft\BovXdYyO.exe

Detected by UnHackMe:

VRUPCIQF.EXE
Default location: %PROGRAM FILES%\MOZILLA FIREFOX\VRUPCIQF.EXE

Dropper information:
MD5: 9631dd6ea45524fe3ad0bdefdc1a25d0
File size: 98304 bytes

Leave a Reply