VSDSRV32.EXE is Trojan Ransom.Foreign

June 16, 2012 by NightWatcher
Filed under: Malware 
: Solved!

Fix it immediately:

Ransom Screen Locker VSDSRV32.EXE is a malicious program.
VSDSRV32.EXE blocks user access to a computer that it infects.
VSDSRV32.EXE demands a ransom paid for unlocking the computer.

Malware Analysis of VSDSRV32.EXE
Full path on a computer: %AppData%\vsdsrv32.exe

Detected by RegRun Warrior:

VSDSRV32.EXE
Default location: %AppData%\vsdsrv32.exe

Removal Results: Success
Number of reboot: 1

VSDSRV32.EXE is known as:

Trojan.Ransom.Foreign, Trojan.Injector

VSDSRV32.EXE hash:

  • MD5: ac8bcfb1b918207caf4c68d30a6fc408
How to quickly detect VSDSRV32.EXE presence?

Registry:
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\vsdsrv: “”%AppData%\vsdsrv32.exe”"
Files:
  • %AppData%\vsdsrv32.exe


Recommended: UnHackMe anti-rootkit and anti-malware

Premium software: RegRun Security Suite (Good choice for removal and protection)

Written by

Malware Hunter.

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.