Need help? Ask the community or hire an expert.
Go to Avira Answers
Date discovered:10/01/2012
In the wild:No
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low
File size:61.952 Bytes
MD5 checksum:48E38C1D8BD97F13BC0ACFAE45880ED3
VDF version:
IVDF version:

 General Method of propagation:
   • No own spreading routine

   •  Kaspersky: Trojan.Win32.Lebag.ktq
   •  Microsoft: Trojan:Win32/Ransom.EJ

Platforms / OS:
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003
   • Windows Vista
   • Windows Server 2008
   • Windows 7

Side effects:
   • Downloads a file
   • Falsely reports malware infection or system problems and offers to fix them if the user buys the application.
   • Registry modification

 Registry The following registry key is added in order to run the process after reboot:

– [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
   • "Mozilla Firefox"="%APPDATA%\MozillaFirefox\firefox.exe"

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with the following runtime packer:
   • UPX

Description inserted by Jan-Eric Herting on Wednesday, January 18, 2012
Description updated by Jan-Eric Herting on Wednesday, January 18, 2012

Back . . . .