Home Malware Programs Malware Ransom.ZAAC

Ransom.ZAAC

Posted: February 29, 2012

Threat Metric

Threat Level: 1/10
Infected PCs: 92
First Seen: February 29, 2012
OS(es) Affected: Windows

Ransom.ZAAC is a malware threat and part of a ransomware scam pretending to be from the Italian Police. Ransom.ZAAC is attacking website visitors who speak Italian. When Italian PC users log into websites hijacked with the JavaScript associated with Ransom.ZAAC, it shows fake 'authorized flag' reports alerting illegal activity has been identified in connection with child abuse pornography and that illegal spam emails are also being sent from the user's computer.

The fake message goes on to say that it has become necessary to lock the PC so that no further illegal content would be delivered. The fabricated message declares that the computer can, however, be unlocked for which the PC user needs to pay the amount of 100EUR during the next 24 hours. When Ransom.ZAAC is executed, it blocks the computer from operating. Ransom.ZAAC deactivates the Task Manager and hijacks the Windows Registry. Ransom.ZAAC modifies the Windows Registry, so that it can run every time you start your PC. Although affected PC users pay the fine, the problem isn't solved because they will receive a useless unlocking key. It is strongly advised to scan your PC and remove Ransom.ZAAC by using genuine security software.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\vasja
Loading...