Threat Database Trojans Trojan.Ransomserv

Trojan.Ransomserv

By Domesticus in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 6
First Seen: July 9, 2013
Last Seen: October 18, 2020
OS(es) Affected: Windows

Trojan.Ransomserv is a Trojan that encrypts files and opens a back door on the compromised PC. Once run, Trojan.Ransomserv may create the folder named 'C:\ProgramData'. Trojan.Ransomserv aims at terminating all non-operating system services running on the targeted PC. Trojan.Ransomserv then disables 'AutoRun'. Trojan.Ransomserv deletes the contents of the Windows Startup folder. Trojan.Ransomserv then deletes all entries in the registry subkeys. Trojan.Ransomserv then aims to encrypt files detected on the infected computer. After the files are encrypted, Trojan.Ransomserv shows a ransom message with the headline 'Warning! Access to your computer is limited. Your files have been encrypted'. The victim is then asked to pay $4000 US as a fine for the key to decrypt the files. Trojan.Ransomserv may also open a back door, which enables cybercriminals to obtain remote unauthorized access and control over the victimized PC.

Trending

Most Viewed

Loading...