Threat Database Trojans Trojan.Ransomlock.Q

Trojan.Ransomlock.Q

By JubileeX in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 18
First Seen: September 28, 2012
OS(es) Affected: Windows

Trojan.Ransomlock.Q is a Trojan that locks the desktop of the compromised PC and makes the computer unusable. Trojan.Ransomlock.Q demands a ransom from the victim to be paid via a certain payment system to unlock the PC. While being executed, Trojan.Ransomlock.Q creates several

infected files and registry entries including one particular entry that enables it to load automatically whenever you turn your computer on. Trojan.Ransomlock.Q finds out the geographical location of the infected computer and illustrates an image specific to a certain location.

Aliases

14 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Suspicious file
Kaspersky UDS:DangerousObject.Multi.Generic
Panda Trj/Dtcontx.A
AVG Generic31.RQU
Fortinet W32/LockScreen.AQC!tr
Ikarus Win32.Rootkit
GData Win32:Rootkit-gen
AhnLab-V3 Trojan/Win32.Ransomlock
AntiVir TR/LockScreen.CS
DrWeb Trojan.DownLoader7.49132
Sophos Troj/Ransom-MR
Avast Win32:Rootkit-gen [Rtk]
Symantec Trojan.Ransomlock.Q
McAfee Artemis!303D4A6E8B39

SpyHunter Detects & Remove Trojan.Ransomlock.Q

File System Details

Trojan.Ransomlock.Q may create the following file(s):
# File Name MD5 Detections
1. skype.dat 303d4a6e8b39143e5ced87c4f244b607 11
2. AltShell.dat 990f5f3274ee543ad80f6ed1f074e415 7
3. %UserProfile%\Application Data\msconfig.dat
4. %UserProfile%\Application Data\msconfig.ini

Registry Details

Trojan.Ransomlock.Q may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "explorer.exe,%UserProfile%\Application Data\msconfig.dat"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo

Trending

Most Viewed

Loading...