Attempting to disable Windows Defender

Attempting to disable Windows Defender

4 years ago
Anonymous $6AJGTL-6_8

https://www.bleepingcomputer.com/news/security/clop-ransomware-tries-to-disable-windows-defender-malwarebytes/

In order to successfully encrypt a victim's data, the Clop CryptoMix Ransomware is now attempting to disable Windows Defender as well as remove the Microsoft Security Essentials and Malwarebytes' standalone Anti-Ransomware programs.

Clop is a variant of the CryptoMix Ransomware, that uses the Clop extension and signs its CIopReadMe.txt ransom note with "Dont Worry C|0P".  Due to this, the ransomware has become known as Clop Ransomware, which is how we will refer to it in this article.