Trojan.Ransomlock.U is a Trojan that infects compromised PCs with the Sur votre ordinateur est infecte French Ransomware. Trojan.Ransomlock.U locks the desktop of the corrupted machine and does not enable the victim to use it until the so-called fine is paid in order to receive an unlock code. Trojan.Ransomlock.U will stop all the applications running on a computer and completely disable the keyboard and mouse. While being activated, Trojan.Ransomlock.U creates the certain registry entry so that it launches automatically whenever you start Windows. Once Trojan.Ransomlock.U has locked the PC, it displays a bogus notification on the screen, which blames computer users for performing illegitmate actions on the computer and demands a ransom of $200 to be paid via a Ukash or MoneyPak to restore the PC.
How Can You Detect Trojan.Ransomlock.U?
Download SpyHunter’s Detection Scanner
to Detect Trojan.Ransomlock.U.
Trojan.Ransomlock.U Removal Details
Trojan.Ransomlock.U has typically the following processes in memory:
- %UserProfile%\Application Data\Microsoft\Windows\53\TSErrRedir.exe
Trojan.Ransomlock.U creates the following files in the system:
- %UserProfile%\Application Data\658645053
- %UserProfile%\Application Data\Microsoft\Windows\53\2742203d
Trojan.Ransomlock.U creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”TSErrRedir” = “%UserProfile%\Application Data\Microsoft\Windows\53\TSErrRedir.exe”