| N/A | |
| PE32 executable (DLL) (GUI) Intel 80386, for MS Windows | 146432 |
| N/A | |
| 84bc71e20048279ea324e1cfb936eef0 | |
| 6ef94b1ff5b7b580cd7cf850aae93504ddb3ec53 | |
| 450dfcdc8dc58fcb557287ee81fade754a6bb2df2b377d9a541a973d9eb01c7a | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| winlogon | |
| 143 kB | |
| Intel 386 or later, and compatibles | |
| Windows NT 32-bit | |
| 16384 | |
| 5.0 | |
| 0x46b0 | |
| 0x003f | |
| 9.0 | |
| N/A | |
| N/A | |
| 5.1.2600.5512 (xpsp.080413-2113) | |
| 129024 | |
| Программа входа в систему Windows NT | |
| 5.1.2600.5512 | |
| Операционная система Microsoft® Windows® | |
| Корпорация Майкрософт2 | |
| application/octet-stream | |
| Unicode | |
| Russian | |
| 5.1.2600.5512 | |
| Win32 DLL | |
| WINLOGON.EXE | |
| © Корпорация Майкрософт2. Все права защищены. | |
| Windows GUI | |
| Executable application | |
| 0.0 | |
| (none) | |
| 5.0 | |
| 5.1.2600.5512 | |
| Source: |

| AVG | Crypt.BWHW |
| AhnLab-V3 | Trojan/Win32.Ransom |
| AntiVir | TR/Kazy.170128.3 |
| Avast | Win32:Kryptik-LRN [Trj] |
| BitDefender | Gen:Variant.Kazy.170128 |
| Comodo | TrojWare.Win32.Kryptik.BAEB |
| DrWeb | Trojan.Winlock.8541 |
| ESET-NOD32 | a variant of Win32/Kryptik.BAEB |
| Emsisoft | Gen:Variant.Kazy.170128 (B) |
| F-Secure | Gen:Variant.Kazy.170128 |
| Fortinet | W32/Reveton.R!tr |
| GData | Gen:Variant.Kazy.170128 |
| Ikarus | Trojan.Win32.Reveton |
| Kaspersky | Trojan-Ransom.Win32.Foreign.caxl |
| Kingsoft | Win32.Troj.Undef.(kcloud) |
| Malwarebytes | Trojan.FakeMS |
| McAfee | Ransom-FBUM!84BC71E20048 |
| McAfee-GW-Edition | Ransom-FBUM!84BC71E20048 |
| MicroWorld-eScan | Gen:Variant.Kazy.170128 |
| Microsoft | Trojan:Win32/Reveton.R |
| Norman | Kryptik.CBDQ |
| PCTools | Trojan.Ransomlock |
| Panda | Generic Malware |
| Rising | Trojan.Agent!53EA |
| Sophos | Mal/Ransom-AH |
| Symantec | Trojan.Ransomlock!g50 |
| VIPRE | Trojan.Win32.Generic!BT |