Threat Database Trojans Trojan.Ransomlock.Y

Trojan.Ransomlock.Y

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 8
First Seen: October 10, 2012
Last Seen: April 21, 2022
OS(es) Affected: Windows

Trojan.Ransomlock.Y is a Trojan that is a component of the FBI Green Dot Moneypak Virus. Trojan.Ransomlock.Y locks targeted computer and does not allow PC owners to use. Trojan.Ransomlock.Y then demands a ransom from the PC user to be paid to unlock it. When run, Trojan.Ransomlock.Y creates the specific file on the infected PC. Trojan.Ransomlock.Y creates the specific registry entry so that it can launch automatically whenever you boot up Windows. Trojan.Ransomlock.Y can also create several other registry entries. Trojan.Ransomlock.Y deletes the particular registry entries to disable Safe Mode Boot. Trojan.Ransomlock.Y can terminate itself, remove its run key, and delete the MP3 file. Trojan.Ransomlock.Y repeatably plays the 1.mp3 audio recording stating 'FBI warning: Your computer is blocked for violation of federal law', displays details about the ransom in a fake pop-up notification and offers a way for the PC user to pay a so-called fine to unlock the affected computer.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Trj/WL.A
Fortinet W32/Agent.AB!tr
F-Prot W32/Trojan2.NURT
CAT-QuickHeal Trojan.Agent.uyaj.cw7
Fortinet W32/Zbot.DHN!tr
Ikarus Trojan.Signed
AhnLab-V3 Trojan/Win32.Zbot
AntiVir TR/Crypt.ZPACK.Gen8
Symantec Trojan.Gen
CAT-QuickHeal Trojan.Agent.uyre
Panda Trj/Genetic.gen
Sophos Mal/Ransom-AB
BitDefender Trojan.Generic.KDZ.353
McAfee PWS-Zbot.gen.aqt
CAT-QuickHeal Trojan.Tobfy

SpyHunter Detects & Remove Trojan.Ransomlock.Y

File System Details

Trojan.Ransomlock.Y may create the following file(s):
# File Name MD5 Detections
1. 013aeaed16db.exe b8daa3f9f1d2aef78d95aa9467a84ba3 1
2. 013b338e80e6.exe b691a8959141ec493287d4bd171a2643 1
3. 013b41f1fd3c.exe 4be9beb19245028606f2647fe7df33fa 1
4. 013b42455bee.exe 8fd1760a1b92e96a4ec4d1f12ce890f5 1
5. 013b4629c367.exe f641382a6ebb664642dba2bec3c3af63 1
6. 013b525322ba.exe 454c042cb640f9d7df1da5e049a78b2e 1
7. [TROJAN PATH]/1.mp3

Registry Details

Trojan.Ransomlock.Y may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\mini
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\net
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft Updater"="[TROJAN PATH AND FILENAME]"

Trending

Most Viewed

Loading...