Threat Database Trojans Trojan-Ransom.Win32.BlueScreen.gc

Trojan-Ransom.Win32.BlueScreen.gc

By GoldSparrow in Trojans

Trojan-Ransom.Win32.BlueScreen.gc is a computer trojan that obtains access to your computer system and puts you in danger. Trojan Ransom.Win32.BlueScreen.gc shows security threats to notify you that your computer is corrupted with malware infections. Trojan Ransom.Win32.BlueScreen.gc takes over all your passwords, pin numbers and personal details before sending this data to corrupt servers. Trojan-Ransom.Win32.BlueScreen.gc acts as a threat to computer security and once it has been detected it has to be terminated immediately before it starts creating chaos on your computer.

File System Details

Trojan-Ransom.Win32.BlueScreen.gc may create the following file(s):
# File Name Detections
1. %System%\sdra64.exe
2. %System%\lowsec\user.ds
3. %System%\lowsec\local.ds
4. %System%\lowsec\user.ds.lll

Registry Details

Trojan-Ransom.Win32.BlueScreen.gc may create the following registry entry or registry entries:
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network]
ProxyEnable = 0x00000000
Userinit =
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
{33373039-3132-3864-6B30-303233343434} = 47 09 F2 0D
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
HKEY_USERS\.DEFAULT\Software\Microsoft\Protected Storage System Provider
{3039636B-5F3D-6C64-6675-696870667265} = F7 09 F2 0D
UID = "%ComputerName%_00019CB8"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]AppData = Cookies = Cache = History =

Trending

Most Viewed

Loading...