Home / malwarePDF  

Trojan:Win32/Lyposit.B


First posted on 11 December 2012.
Source: Microsoft

Aliases :

There are no other names known for Trojan:Win32/Lyposit.B.

Explanation :



Trojan:Win32/Lyposit.B is ransomware that prevents you from accessing your computer. It covers your entire desktop with an image pretending to be from your local authorities, asking you to pay a fine to regain access. The image covering the desktop is downloaded from a certain website.



Installation

When run, Trojan:Win32/Lyposit.B drops a copy of itself as a randomly named file in the following folders:

  • %ALLUSERSPROFILE%\Application Data
  • %LOCALAPPDATA%


For example:

C:\Documents and Settings\Administrator\Local Settings\Application Data\rttevjmgloi.exe

It creates the following registry key so that its copy automatically runs when Windows starts:

In subkey: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Sets value: "Shell"
With data: "explorer.exe, %ALLUSERSPROFILE%\Application Data\<malware file name>"

It creates the following registry key as part of its installation process:

In subkey: HKCU\Software\Microsoft
Sets value: "AutoRun"
With data: "%ALLUSERSPROFILE%\Application Data\<malware file name>"

It then forces your computer to restart so that it automatically runs.



Payload

Blocks computer access

Trojan:Win32/Lyposit.B prevents you from accessing your computer, as it displays an image that covers your entire desktop. The image contains instructions and information about paying a fine for you to regain access to the computer. The image may look similar to the following:

If your IP address is located in France:



If your IP address is located in Germany:



If your IP address is located in Spain:



If your IP address is located in Switzerland:



It downloads this image from a certain website. Lyposit has been known to download images from the following:

  • hali<blocked>were.org
  • iwhf8<blocked>fueuofbejkh.org
  • n8efhi<blocked>ifhuenfe.com
  • neufb<blocked>jefnike.com
  • urla<blocked>purla.org


If the website where it downloads the image from is unavailable, it displays the following instead:



Disables Task Manager

Trojan:Win32/Lyposit.B prevents you from accessing Task Manager by modifying the following registry entry:

In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
Sets value: "DisableTaskMgr"
With data: "1"

Closes all windows

Trojan:Win32/Lyposit.B monitors your computer for all open windows on the desktop. It then closes all windows except for its own process.



Analysis by Zarestel Ferrer

Last update 11 December 2012

 

TOP