Home Malware Programs Trojans Trojan.Ransomserv

Trojan.Ransomserv

Posted: July 9, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 14
First Seen: July 9, 2013
Last Seen: October 18, 2020
OS(es) Affected: Windows

Trojan.Ransomserv is a Trojan that encrypts files and opens a back door on the affected computer. When Trojan.Ransomserv is executed, it may create the folder called 'C:\ProgramData'. Trojan.Ransomserv strives to terminate all non-operating system services running on the targeted computer. Trojan.Ransomserv then disables 'AutoRun'. Next, Trojan.Ransomserv deletes the contents of the Windows Startup folder. Trojan.Ransomserv then deletes all entries in the registry subkeys. Trojan.Ransomserv then strives to encrypt files found on the corrupted PC. After the files are encrypted, Trojan.Ransomserv displays a ransom message with the headline 'Warning! Access to your computer is limited. Your files have been encrypted'. The target computer user is then requested by Trojan.Ransomserv to pay $4000 US as a ransom for the key to decrypt the files. Trojan.Ransomserv may also open a back door, which allows attackers to gain full remote access and control to the victimized computer.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunHKEY_CURRENT_USER\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Loading...