Trojan.Ransomlock.W is a Trojan that corrupts the vulnerable computers by the Politie Federal Computer Crime Unit Ransomware. Trojan.Ransomlock.W locks the desktop of the compromised PC and does not allow victims to use the computer. Trojan.Ransomlock.W demands a ransom from the victim to be paid via a Ukash or MoneyPak to unlock the PC. While being executed, Trojan.Ransomlock.W creates several infected files and registry entries including one particular entry that enales it to load automatically whenever you turn your computer on. When the PC is locked by the Trojan.Ransomlock.W, it illustrates a a tricky warning message on the screen, which blames computer users for performing illegal actions and asks them to pay a supposed ransom of of $200 via a Ukash or MoneyPak to restore the locked PC.
How Can You Detect Trojan.Ransomlock.W?
Download SpyHunter’s Detection Scanner
to Detect Trojan.Ransomlock.W.
Trojan.Ransomlock.W Removal Details
Trojan.Ransomlock.W has typically the following processes in memory:
- %UserProfile%\Application Data\KB[EIGHT RANDOM DIGITS].exe
Trojan.Ransomlock.W creates the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”KB[EIGHT RANDOM DIGITS].exe” = “%UserProfile%\Application Data\KB[EIGHT RANDOM DIGITS].exe”