Home Malware Programs Trojans Trojan-Ransom.Cidox

Trojan-Ransom.Cidox

Posted: January 11, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 12
First Seen: October 12, 2011
OS(es) Affected: Windows

Trojan-Ransom.Cidox is a ransomware Trojan-based variant of Trojan.Cidox that locks your computer and requests money before Trojan-Ransom.Cidox will allow you to go about your business. Paying into Trojan-Ransom.Cidox's scam is strongly-discouraged by SpywareRemove.com malware analysts, since the criminals behind Trojan-Ransom.Cidox have no reason to follow through on their word and are very-likely to pocket your cash without unlocking your PC. Moreover, competent anti-malware products are able to remove Trojan-Ransom.Cidox and its accompanying symptoms without forcing you to place money into criminal hands. Because members of the Cidox family have been known to possess rootkit functions, you should be certain to delete all components of a Trojan-Ransom.Cidox infection by scanning your PC as thoroughly as possible.

Trojan-Ransom.Cidox: Not Quite Top Threat of the Year, but Close Enough for Its Purposes

Trojan-Ransom.Cidox was recently-ranked as eighth on a list of the most-harmful PC threats of 2011 by VirusBlokAda, an anti-virus company. Although the distribution numbers of the original Trojan.Cidox PC threat that Trojan-Ransom.Cidox is based on are still low, Trojan-Ransom.Cidox can truly be considered to be a high-level threat to your PC and endangers your computer's security with its mere presence. SpywareRemove.com malware researchers also caution that Trojan-Ransom.Cidox may not be alone, since Trojans from the Cidox family are often installed in multiple components that cooperate to attack your PC. This can include rootkits and PC threats that attack your computer's boot sector so that your PC will load malicious software by default.

Despite the fact that specific worms, rogue security programs and spyware Trojans have ranked higher on the aforementioned list than Trojan-Ransom.Cidox, even Trojan-Ransom.Cidox at position eight still has an enormously-invasive and deadly payload. Like other ransomware Trojans, Trojan-Ransom.Cidox will attempt to block your PC from running most programs and, as Trojan-Ransom.Cidox holds your computer hostage, will insist that you transfer money to Trojan-Ransom.Cidox's criminal partners. However, giving in to the demands of any ransomware Trojan, including Trojan-Ransom.Cidox's, is ultimately self-destructive and a needless waste of your money.

Putting Trojan-Ransom.Cidox at the Bottom of the List for Effective PC Threats

Removing Trojan-Ransom.Cidox should be done with anti-malware scanners that are also capable of detecting and deleted associated PC threats, especially other Trojans from the Cidox family. Due to the high potential of rootkit infestation, you may be required to take extreme measures to provide a safe environment for scanning your PC – such as disabling system backup features temporarily – before your anti-malware software, however competent, can delete all portions of a Trojan-Ransom.Cidox infection. If Trojan-Ransom.Cidox stops you from using software that could remove Trojan-Ransom.Cidox, you should attempt to disable Trojan-Ransom.Cidox beforehand. This can often be accomplished via Safe Mode or by directly-booting into the Command Prompt.

Trojan-Ransom.Cidox may also be identified by other names, such as TR/Drop.Cidox.imza, Trojan.Mayachok.1, Win32:Cidox-M, Trojan-Dropper.Win32.Cidox, Vundo.UWH, BScope.Trojan-Ransom.Cidox.8121 and Trojan.Generic.KD.444100.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\logonbgpack.exe File name: logonbgpack.exe
Size: 139.3 KB (139306 bytes)
MD5: f3c461d316005c5e57783b20ac626f13
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: October 13, 2011
Loading...