Saturday, June 19, 2010

Trojan.Ransomware

This trojan is hidden behind an Adobe Flash Installer.



When executed, it is making a copy of itself in %ALLUSERSPROFILE% and displays an invasive message box in Russian.



To get rid of it, try these 2 serial codes (alternately if needed):
35676549
28527548




To get rid of it, try these serial codes (alternately if needed):
49752406
62907349

or
83675124
29645732


Run MBAM to remove the infection.