Quantcast
Channel: Malware Analysis and Removal
Viewing all articles
Browse latest Browse all 28

WindowsSecurity (Ransom Trojan) - 04.13.2012 - Analysis and Removal

$
0
0
Creates this registry value: HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell points to the malicious that was run. Creates a bad value under this key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Look for a value similar to: "S112106111" which points to the malicious file that was run. Main objective is to delete the one malicious file you ran. For example I ran a

Viewing all articles
Browse latest Browse all 28

Trending Articles