Threat Database Trojans Trojan.Ransomlock.AA

Trojan.Ransomlock.AA

By Domesticus in Trojans

Threat Scorecard

Ranking: 16,445
Threat Level: 90 % (High)
Infected Computers: 97
First Seen: November 30, 2012
Last Seen: August 8, 2023
OS(es) Affected: Windows

Trojan.Ransomlock.AA is a Trojan that is used by scammers to distribute ransomware applications to vulnerable computers. Trojan.Ransomlock.AA blocks the desktop and keyboard of the targeted PC and does not allow the computer owner using it. Trojan.Ransomlock.AA then asks the victim to pay a fine to restore access to it. While being run, Trojan.Ransomlock.AA copies itself to the specific locations. Trojan.Ransomlock.AA creates the certain registry entry so that it can load automatically when you start Windows. Trojan.Ransomlock.AA also modifies the certain registry entry to guarantee its automatic loading at each Windows start-up. Trojan.Ransomlock.AA shows a bogus warning message urging the PC user to pay a ransom to unlock the compromised PC. Trojan.Ransomlock.AA also connects to the specific remote location.

File System Details

Trojan.Ransomlock.AA may create the following file(s):
# File Name Detections
1. %UserProfile%\Local Settings\Application Data\[THREAT FILE NAME].exe
2. %UserProfile%\Application Data\[THREAT FILE NAME].exe

Registry Details

Trojan.Ransomlock.AA may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe, %SystemDrive%\Documents and Settings\All Users\Application Data\[THREAT FILE NAME].exe"
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\"AutoRun" =

Trending

Most Viewed

Loading...