Home Malware Programs Trojans Trojan-Ransom.Win32.BlueScreen.gc

Trojan-Ransom.Win32.BlueScreen.gc

Posted: April 7, 2011

Trojan-Ransom.Win32.BlueScreen.gc is a trojan infection that runs secretly and enables remote access to the targeted computer system. Trojan-Ransom.Win32.BlueScreen.gc will inform you that your computer is at risk and then you need to purchase the allegedly legal security program to repair your PC issues. But, in fact, Trojan-Ransom.Win32.BlueScreen.gc starts a malicious program file downloaded from the web in order to steal your money. Trojan-Ransom.Win32.BlueScreen.gc may also cover a browser helper, which is usually downloaded under the pretense of another object that they actually would want to have.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\lowsec\local.ds
    2 %System%\lowsec\user.ds
    3 %System%\lowsec\user.ds.lll
    4 %System%\sdra64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_USERS\.DEFAULT\Software\Microsoft\Protected Storage System ProviderHKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]AppData = Cookies = Cache = History =[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]HKEY..\..\..\..{RegistryKeys}ProxyEnable = 0x00000000UID = "%ComputerName%_00019CB8"Userinit ={3039636B-5F3D-6C64-6675-696870667265} = F7 09 F2 0D{33373039-3132-3864-6B30-303233343434} = 47 09 F2 0D
Loading...