Home Malware Programs Trojans Ransom!cp


Posted: July 26, 2010

Ransom!cp is a malicious Trojan virus created by cyber-criminals to install and initiate other versions of malicious programs on the victim's PC. Ransom!cp is included in a list of programs which will run automatically when the operating system starts. This makes it very difficult to manually detect and remove Ransom!cp. A spyware removal tool should be used to safely detect and remove Ransom!cp before it is able to cause additional damages to the affected system.


Trojan-Ransom.Win32.XBlocker VirTool:Win32/Obfuscator.DO Win32/Kryptik.EIF

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\skaioejiesfjoee.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions: 0x00000001[HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools: 0x00000001[HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Run\][HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\]HKEY..\..\..\..{RegistryKeys}"sdr8gdrgdrgke49orkgsjkjfjhsd" = "%UserProfile%\Desktop\SETUP.EXE"