This trojan blocker prevents all software execution by displaying all top window that constantly redraws. To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Named Lock Em All because of the specific window name.
Once installed it looks like:
Autoruns through HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit as %systemroot%\system32\usrinit.exe
UPDATE July 2011.
Locker has evolved a few months later.
URLS list 26.07.2011
starting from 26 July Lock'Em'All ransomware moved to dedicated bulletproof server hosted by SIA LEMGA criminals affiliated hosting
Lock'Em'All URL's list at 26.01.2011
Update 28.01.2011
Due to our abuse Yandex suspended all listed below sites.
And the only difference inside Winlock is tel numbers (string array, number selects randomly) and unblock code they have on board.
Winlock packed with UPX and protected by some crappy VB cryptor.
Named Lock Em All because of the specific window name.
Once installed it looks like:
Autoruns through HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit as %systemroot%\system32\usrinit.exe
UPDATE July 2011.
Locker has evolved a few months later.
URLS list 26.07.2011
starting from 26 July Lock'Em'All ransomware moved to dedicated bulletproof server hosted by SIA LEMGA criminals affiliated hosting
hxxp://binxx3fi.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://rim5ttds.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://kinvivifas.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://boomfporka.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://z4nixxxi.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://rim5tporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://azxpoixx.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://ebatporkas.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://fingopas.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://xxxbuxc.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://3rewporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://ttedhoki.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://sukazporka.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://cbipoxf.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://ndcporka.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://frtnnbc.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w2biporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://zx1uporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://llz3porn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://ebpoino.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://5uporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://4tporl.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://llkzporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://hnyporka.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://1qporka.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://sukporn1.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://hhn3por.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://2tipornn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://wq1porm.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://4youporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://3vvporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://ffporm.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://sv2porn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w3nixx.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://gnpotk.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://2bioko.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://us1porn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w3vporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w2yporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w1porka.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://new3porn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://rim2bi.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://4xrubin.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://diporn1.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://3zuporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://2nporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://1biporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://z4porn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://qqyygf.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://hnkporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://llzxzt.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://mixntrd.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://zzporrno.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://fimsporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://xvidcoms.s3.amazonaws.com/xxx_video.exe DELETED
All client.jp domains suspended or deleted due to abuse.
hxxp://farsioce.client.jp/xxx_video.exe DELETED
hxxp://lecwovil.client.jp/xxx_video.exe DELETED
hxxp://gutfmulti.client.jp/xxx_video.exe DELETED
hxxp://longhanbi.client.jp/xxx_video.exe DELETED
hxxp://ceinopxent.client.jp/xxx_video.exe DELETED
hxxp://clucessnor.client.jp/xxx_video.exe DELETED
hxxp://schoolcountthu.client.jp/xxx_video.exe DELETED
hxxp://rachaword.client.jp/xxx_video.exe DELETED
hxxp://saterdest.client.jp/xxx_video.exe DELETED
hxxp://liaschedaf.client.jp/xxx_video.exe DELETED
hxxp://terdesa.client.jp/xxx_video.exe DELETED
hxxp://visadchi.client.jp/xxx_video.exe DELETED
hxxp://neutricfer.client.jp/xxx_video.exe DELETED
hxxp://idabcoun.client.jp/xxx_video.exe DELETED
hxxp://pzigoket.client.jp/xxx_video.exe DELETED
hxxp://comvapun.client.jp/xxx_video.exe DELETED
hxxp://comdunnbeantrocart.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
hxxp://racviphossotu.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
hxxp://northvalgikacen.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
hxxp://glitiheslynchea.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
hxxp://nievialansscharen.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
hxxp://brazunengavi.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
hxxp://caropesiter.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
hxxp://penfbaddisctranev.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
hxxp://mobejustita.narod.ru/xxx_video.exe INVESTIGATED/CLOSED
Lock'Em'All URL's list at 26.01.2011
Update 28.01.2011
Due to our abuse Yandex suspended all listed below sites.
hxxp://lyudmilazhmkosomovnn.narod2.ru/xxx_video.exeAll these sites are duplicate. The only difference (not always) in payload Winlock.
hxxp://gennadiyeimisalovuk.narod2.ru/xxx_video.exe
hxxp://efimyuyguskovshcha.narod2.ru/xxx_video.exe
hxxp://varvaraishkandinskiyf.narod2.ru/xxx_video.exe
hxxp://daniilgrkrutoyzu.narod2.ru/xxx_video.exe
hxxp://lidiyadmvitinskiyvm.narod2.ru/xxx_video.exe
hxxp://adolftsboyarinove.narod2.ru/xxx_video.exe
hxxp://stepanyggorokhovshchk.narod2.ru/xxx_video.exe
hxxp://evgeniyayaiardankinyae.narod2.ru/xxx_video.exe
hxxp://elzachabalakhnovgshch.narod2.ru/xxx_video.exe
hxxp://veronikauemagazinerga.narod2.ru/xxx_video.exe
hxxp://leonidyueenotineyu.narod2.ru/xxx_video.exe
hxxp://raisakykapitonovsshch.narod2.ru/xxx_video.exe
hxxp://oksanaerlashkinchb.narod2.ru/xxx_video.exe
hxxp://mariyakhkhblinovlb.narod2.ru/xxx_video.exe
hxxp://alangtdemenkovzl.narod2.ru/xxx_video.exe
hxxp://stellappkolomiytsevyo.narod2.ru/xxx_video.exe
hxxp://anfisayrlagutovakh.narod2.ru/xxx_video.exe
hxxp://ninatikramovai.narod2.ru/xxx_video.exe
hxxp://alisaudbaltabevbl.narod2.ru/xxx_video.exe
hxxp://angelinaeevakhrushevym.narod2.ru/xxx_video.exe
hxxp://margaritakhnbagroviyu.narod2.ru/xxx_video.exe
hxxp://azariynnbarsovzhshch.narod2.ru/xxx_video.exe
hxxp://aristarkhefmarkelovep.narod2.ru/xxx_video.exe
hxxp://yuriyshakuzkineg.narod2.ru/xxx_video.exe
hxxp://zinaidakhlzubarevoch.narod2.ru/xxx_video.exe
hxxp://petrzpkuzmichg.narod2.ru/xxx_video.exe
hxxp://olegyatlevkinzh.narod2.ru/xxx_video.exe
hxxp://valeriyashebabatoch.narod2.ru/xxx_video.exe
hxxp://timurzpkalmykovmi.narod2.ru/xxx_video.exe
hxxp://vyacheslavushchglobazh.narod2.ru/xxx_video.exe
hxxp://anastasiyayblobanrv.narod2.ru/xxx_video.exe
hxxp://ivangykoryavinmu.narod2.ru/xxx_video.exe
hxxp://adolfdenabokinyuu.narod2.ru/xxx_video.exe
hxxp://alisayuivoronkovyy.narod2.ru/xxx_video.exe
hxxp://antonshchbesfamilnovzk.narod2.ru/xxx_video.exe
hxxp://milenaesdurkinbsh.narod2.ru/xxx_video.exe
hxxp://vladimiroyaburkinyum.narod2.ru/xxx_video.exe
hxxp://fainaommikhalevsy.narod2.ru/xxx_video.exe
hxxp://sofyaechbutylinyshch.narod2.ru/xxx_video.exe
hxxp://makareebesfamilnovyab.narod2.ru/xxx_video.exe
hxxp://efimyskostinop.narod2.ru/xxx_video.exe
hxxp://antonmboldaevoo.narod2.ru/xxx_video.exe
hxxp://antoninatbbershovgi.narod2.ru/xxx_video.exe
hxxp://adamzavaluevtse.narod2.ru/xxx_video.exe
hxxp://adakhukanalinfo.narod2.ru/xxx_video.exe
hxxp://anzheyyuedagintst.narod2.ru/xxx_video.exe
hxxp://vitaliygkdemchenkogs.narod2.ru/xxx_video.exe
hxxp://eduardzhgzhurovfu.narod2.ru/xxx_video.exe
hxxp://vyacheslavpygachevyae.narod2.ru/xxx_video.exe
hxxp://daryaykarginya.narod2.ru/xxx_video.exe
hxxp://vitaliymtslapinel.narod2.ru/xxx_video.exe
hxxp://nikitatzallenoviyu.narod2.ru/xxx_video.exe
hxxp://susannayzhbarentsevuzh.narod2.ru/xxx_video.exe
hxxp://karinafmamelintl.narod2.ru/xxx_video.exe
hxxp://vladimirbsvalievpe.narod2.ru/xxx_video.exe
hxxp://valentinalykuzminykhkh.narod2.ru/xxx_video.exe
hxxp://konstantinbdkruteleve.narod2.ru/xxx_video.exe
hxxp://rimmafbanrepzy.narod2.ru/xxx_video.exe
hxxp://adolfkyuignatkovichp.narod2.ru/xxx_video.exe
hxxp://tracenin.narod.ru/xxx_video.exe
hxxp://susannafdegtinshr.narod2.ru/xxx_video.exe
hxxp://andreyshchpburyakovt.narod2.ru/xxx_video.exe
hxxp://albinapdvorobevyaa.narod2.ru/xxx_video.exe
hxxp://semenstnovikovzhkh.narod2.ru/xxx_video.exe
hxxp://valeriyaankatkiner.narod2.ru/xxx_video.exe
hxxp://petrtchignatevzd.narod2.ru/xxx_video.exe
hxxp://alevtinaulepikhovkhg.narod2.ru/xxx_video.exe
hxxp://ivettasfgorelovishch.narod2.ru/xxx_video.exe
hxxp://karinaeshchlachkovzhv.narod2.ru/xxx_video.exe
hxxp://prokhorshzmilekhintts.narod2.ru/xxx_video.exe
hxxp://alinazhmerokhinyl.narod2.ru/xxx_video.exe
hxxp://daryayarkuptsovshts.narod2.ru/xxx_video.exe
hxxp://olgaazignatenkovfl.narod2.ru/xxx_video.exe
hxxp://denisbfzhelezkinfkh.narod2.ru/xxx_video.exe
hxxp://semenspkaravaevev.narod2.ru/xxx_video.exe
hxxp://mariyapvmalakhovmy.narod2.ru/xxx_video.exe
hxxp://susannayukhmyshkinde.narod2.ru/xxx_video.exe
hxxp://gennadiybgistominfa.narod2.ru/xxx_video.exe
hxxp://elzalklomadurovlts.narod2.ru/xxx_video.exe
And the only difference inside Winlock is tel numbers (string array, number selects randomly) and unblock code they have on board.
Winlock packed with UPX and protected by some crappy VB cryptor.
Ring0 - the source of inspiration