Ransom!cp
Ransom!cp Description
Ransom!cp is a dangerous Trojan. Ransom!cp is able to download additional malware from a remote server and install it on a compromised PC. Ransom!cp is designed to hold a compromised PC hostage by blocking internet access, disabling Windows functions and closing opened applications. Ransom!cp is a computer threat that should be removed upon detection.
Type: Trojans
Aliases: Trojan-Ransom.Win32.XBlocker VirTool:Win32/Obfuscator.DO Win32/Kryptik.EIF.
How Can You Detect Ransom!cp?
Ransom!cp creates the following registry entries:
- [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\]
- “sdr8gdrgdrgke49orkgsjkjfjhsd” = “%UserProfile%\Desktop\SETUP.EXE”
- [HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools: 0x00000001
- [HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Run\]
- [HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions: 0x00000001
Important Article Disclaimer
This entry was posted on 07/26/10 and is filed under Trojans.
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Ransom!cp 










