Threat Database Trojans Trojan.Ransomlock.U

Trojan.Ransomlock.U

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 1
First Seen: October 4, 2012
OS(es) Affected: Windows

Trojan.Ransomlock.U is a Trojan that infects compromised PCs with the Sur votre ordinateur est infecte French Ransomware. Trojan.Ransomlock.U locks the desktop of the corrupted machine and does not enable the victim to use it until the so-called fine is paid in order to receive an unlock code. Trojan.Ransomlock.U will stop all the applications running on a computer and completely disable the keyboard and mouse. While being activated, Trojan.Ransomlock.U creates the certain registry entry so that it launches automatically whenever you start Windows. Once Trojan.Ransomlock.U has locked the PC, it displays a bogus notification on the screen, which blames computer users for performing illegitmate actions on the computer and demands a ransom of $200 to be paid via a Ukash or MoneyPak to restore the PC.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Trj/CI.A
AVG Downloader.Generic13.LNX
Ikarus Trojan-Downloader.Win32.Andromeda
AhnLab-V3 Trojan/Win32.Downloader
Microsoft TrojanDownloader:Win32/Karagany.L
AntiVir Rkit/Agent.101376.2
Avast Win32:Karagany-MC [Trj]
Panda Suspicious file
Fortinet W32/Zbot.MZ!tr
GData Win32:Rootkit-gen
DrWeb Trojan.PWS.Panda.2958
Comodo TrojWare.Win32.Trojan.Agent.Gen
Kaspersky Trojan-Downloader.Win32.Andromeda.nu
Avast Win32:Rootkit-gen [Rtk]
Symantec Trojan.Ransomlock.U

SpyHunter Detects & Remove Trojan.Ransomlock.U

File System Details

Trojan.Ransomlock.U may create the following file(s):
# File Name MD5 Detections
1. TSErrRedir.exe 2d1c12d1af36bb650f707012c7bb78c0 1
2. %UserProfile%\Application Data\Microsoft\Windows\53\TSErrRedir.exe
3. %UserProfile%\Application Data\658645053
4. %UserProfile%\Application Data\Microsoft\Windows\53\2742203d

Registry Details

Trojan.Ransomlock.U may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"TSErrRedir" = "%UserProfile%\Application Data\Microsoft\Windows\53\TSErrRedir.exe"

Trending

Most Viewed

Loading...