GEMA Locker - Trojan:Win32/LockScreen.BO
9/43 >> 20.9%
Copies itself to %appdata%\ActiveX32_64lo.exe.
Autorun from:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\olmwKSKlNdgCU6b
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\olmwKSKlNdgCU6b
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr
[www].fuehlediecon.com GET /wasgehtalter_panel/gate.php?...
[www].fuehlediebezahlung.com GET /wirbrauchenbass_bezahlung/index.php
[www].uploadmusic.org GET /MUSIC/6540321325490242.mp3