Saturday, June 26, 2010

Trojan.Ransomware

This trojan displays an invasive Window and blocks software execution. It copies itself in %TEMP% and register at:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit



To get rid of it, try one of these 2 serial codes:
75633922
ZV3232P


Run MBAM to remove the infection.