Page 3 of 9

Re: Trojan Winlock / Ransom / ScreenLocker

PostPosted:Fri Jan 14, 2011 9:46 am
by Xylitol

Re: Trojan Winlock / Ransom / ScreenLocker

PostPosted:Sat Jan 15, 2011 8:55 pm
by Xylitol
another video_XXXXX.avi.ExE
https://www.virustotal.com/file-scan/re ... 1295123475
dunno the unlock code

Thread split

PostPosted:Sun Jan 16, 2011 3:19 pm
by EP_X0FF
Offtopic post about Windows load order moved to separate thread

Re: Trojan Winlock / Ransom / ScreenLocker

PostPosted:Sun Jan 16, 2011 5:44 pm
by EP_X0FF
Porno Media Module (Adult Ban, sub family or lockers)

remembers me this http://forum.sysinternals.com/trojan-ra ... 22054.html

Crap drops to %Documents and Settings%\All Users\Media (XP)

Image

http://www.virustotal.com/file-scan/rep ... 1295197172

Unblock, two stages:

1. 28527548
2. 35676549

Or kill it with help of any non standard taskmanager.

Image
Image

In attach both original and unpacked.

Re: Trojan Winlock / Ransom / ScreenLocker

PostPosted:Mon Jan 17, 2011 9:56 am
by xhandsome
"see archive comment for password" ?
I don't know how to get the password, Please guide for me how to get the pass word,
thanks

Re: Trojan Winlock / Ransom / ScreenLocker

PostPosted:Mon Jan 17, 2011 10:45 am
by nullptr
xhandsome wrote:"see archive comment for password" ?
I don't know how to get the password, Please guide for me how to get the pass word,
thanks
Depends on what archive app you use, but for the archives in question the pw is xylibox

Thread split

PostPosted:Mon Jan 17, 2011 3:28 pm
by EP_X0FF
Thread split.

All Lock Em All related discussion moved to Trojan.Winlock - Lock Em All thread.

Thread split

PostPosted:Fri Jan 21, 2011 2:56 pm
by EP_X0FF
Thread split, BlueTrash and Homoblocker discussion moved to special separate topic. This was done because both lockers constantly updating - changing hardcoded unblock keys. There is no need to post them again and again (because they are nothing new except codes), as in fact all what required - tel number, unblock code, VT report (if available) and malware source (if available).

Thread split

PostPosted:Sat Feb 05, 2011 3:31 pm
by EP_X0FF
Thread split.

Delphi pornoblocker (virtual keyboard) stuff moved to dedicated topic

Re: Trojan.Winlock - WinAD

PostPosted:Thu Feb 24, 2011 2:43 pm
by mrbelyash