Threat Database Trojans Trojan.Ransomlock.O

Trojan.Ransomlock.O

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 1
First Seen: May 21, 2012
Last Seen: July 31, 2020
OS(es) Affected: Windows

Trojan.Ransomlock.O is a Trojan that locks the desktop of the targeted computer and makes the computer unusable. Trojan.Ransomlock.O shows a pop-up message and demands ransom from the victim to unlock the PC. When the PC is locked with the ransom notification, Trojan.Ransomlock.O ends some processes on the compromised PC. When Trojan.Ransomlock.O is executed, it copies itself to the specific location. Trojan.Ransomlock.O then creates the specific registry entry so that it can run every time you start Windows. Trojan.Ransomlock.O connects to a remote location that is constructed from three components. Trojan.Ransomlock.O downloads commands from the remote location, which permit remote attackers to conduct harmful actions on the affected PC system such as delete files, distribute and illustrate a ransom alert, download updates and submit a PIN code. Select a genuine security application to get rid of Trojan.Ransomlock.O.

File System Details

Trojan.Ransomlock.O may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\froot\froot.exe

Registry Details

Trojan.Ransomlock.O may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Free" = "%UserProfile%\Application Data\froot\froot.exe -b"

Trending

Most Viewed

Loading...