Threat Database Trojans Trojan.Ransomlock.T

Trojan.Ransomlock.T

By ESGI Advisor in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 98
First Seen: October 4, 2012
Last Seen: September 29, 2022
OS(es) Affected: Windows

Trojan.Ransomlock.T is a Trojan that is used by cybercriminals to spread the Police Service of Nothern Ireland ransomware to the targeted PCs. Trojan.Ransomlock.T locks the infected computer and does not let the PC user to use the machine. Trojan.Ransomlock.T asks the victim to pay the so-called fine to unlock the computer. While being run, Trojan.Ransomlock.T copies itself to the specificlocation of the affected computer system. Trojan.Ransomlock.T creates the particular registry entry, which allows it to load automatically whenever you start Windows. Trojan.Ransomlock.T also creates the particular registry entry in order to involve itself into the list of programs authorized by the Windows firewall. After the computer is locked, Trojan.Ransomlock.T illustrates a bogus warning, which blames PC users of the violation of the certain copyright law and asks to make an online transaction of $200 via a MoneyPak.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Trj/Agent.MIZ
DrWeb Trojan.DownLoader7.55048
Sophos Troj/DotNet-B
CAT-QuickHeal Trojan.Genome.airjn.cw3
Fortinet W32/Small.PNV!tr
Ikarus Trojan-Downloader.Agent
AhnLab-V3 Trojan/Win32.Genome
Microsoft Trojan:MSIL/Wantia.A
Comodo TrojWare.Win32.Trojan.Svchost
Kaspersky Trojan.Win32.Genome.airjn
eSafe Win32.Trojan
K7AntiVirus Trojan
McAfee Downloader.a!c2c
Panda Trj/CI.A
AVG Downloader.Agent2.BHQG

SpyHunter Detects & Remove Trojan.Ransomlock.T

File System Details

Trojan.Ransomlock.T may create the following file(s):
# File Name MD5 Detections
1. svchost.exe dc5e6611ff13b4321095098400d586e8 51
2. %UserProfile%\Application Data\system\[THREAT FILE NAME].exe
3. %SystemDrive%\RECYCLER\find_me.tmp
4. %UserProfile%\Application Data\rt1.png

Registry Details

Trojan.Ransomlock.T may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Update" = "%UserProfile%\Application Data\system\[THREAT FILE NAME].exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe, %UserProfile%\Application Data\system\[THREAT FILE NAME].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\"Update" = "%UserProfile%\Application Data\system\[THREAT FILE NAME].exe"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%UserProfile%\Application Data\system\[THREAT FILE NAME].exe" = "%UserProfile%\Application Data\system\[THREAT FILE NAME].

Trending

Most Viewed

Loading...