Trojan-Ransom.Win32.Blocker.dpbm

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Trojan-Ransom.Win32.Blocker.dpbm also known as TROJ_FORUCON.BMC, Win32:Malware-gen, VirTool:Win32/CeeInject.gen!JE.

Malware Analysis of Trojan-Ransom.Win32.Blocker.dpbm

Created files:

%Appdata%\google.ss.exe
C:\sand-box\jansson.dll
C:\sand-box\msvcr100.dll
C:\sand-box\pthreadVC2.dll
C:\sand-box\subsystem.exe

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Google Security: 43 3A 5C 44 6F 63 75 6D 65 6E 74 73 20 61 6E 64 20 53 65 74 74 69 6E 67 73 5C 41 64 6D 69 6E 69 73 74 72 61 74 6F 72 5C 41 70 70 6C 69 63 61 74 69 6F 6E 20 44 61 74 61 5C 67 6F 6F 67 6C 65 2E 73 73 2E 65 78 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: 43 3A 5C 57 49 4E 44 4F 57 53 5C 73 79 73 74 65 6D 33 32 5C 75 73 65 72 69 6E 69 74 2E 65 78 65 2C 43 3A 5C 44 6F 63 75 6D 65 6E 74 73 20 61 6E 64 20 53 65 74 74 69 6E 67 73 5C 41 64 6D 69 6E 69 73 74 72 61 74 6F 72 5C 41 70 70 6C 69 63 61 74 69 6F 6E 20 44 61 74 61 5C 67 6F 6F 67 6C 65 2E 73 73 2E 65 78 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Detected by UnHackMe:

GOOGLE.SS.EXE
Default location: %APPDATA%\GOOGLE.SS.EXE

Dropper hash(md5): 0e4b3854cb9aada078285003332c5d81

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

4
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera