Home Malware Programs Trojans Trojan.Ransomlock.S

Trojan.Ransomlock.S

Posted: October 3, 2012

Threat Metric

Ranking: 6,411
Threat Level: 9/10
Infected PCs: 164
First Seen: October 3, 2012
Last Seen: October 16, 2023
OS(es) Affected: Windows

Trojan.Ransomlock.S is a Trojan that locks the desktop of the affected computer and makes the PC unusable. Trojan.Ransomlock.S demands the affected PC user to pay the supposed ransom to unlock the machine. Once executed, Trojan.Ransomlock.S copies itself to the certain location of the compromised PC. Trojan.Ransomlock.S creates the specific registry entry so that it can run automatically every time you start Windows. After the PC is locked, Trojan.Ransomlock.S displays a fake warning message on the screen notifying victims that they have breached the certain copyright law and asks to make a money transfer of $200 via a MoneyPak payment system.

Aliases

Trj/CI.A [Panda]Agent_r.BPD [AVG]W32/Kryptik.AMPM!tr [Fortinet]Worm.Win32.Cridex [Ikarus]Trojan/Win32.PornoAsset [AhnLab-V3]Heuristic.BehavesLike.Win32.Suspicious-BAY.K [McAfee-GW-Edition]TR/Graftor.4485979 [AntiVir]TrojWare.Win32.Kryptik.NEGB [Comodo]Mal/ZboCheMan-D [Sophos]Trojan-Ransom.Win32.PornoAsset.afhx [Kaspersky]Win32:Kryptik-KGB [Trj] [Avast]Trojan.Ransomlock.S [Symantec]W32/Falab.F18.gen!Eldorado [F-Prot]Trojan [K7AntiVirus]PWS-Zbot.gen.als [McAfee]
More aliases (27)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%CurrentFolder%\[THREAT FILE NAME].exe File name: %CurrentFolder%\[THREAT FILE NAME].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"GoogleChrome" = "%CurrentFolder%\[THREAT FILE NAME].exe"
Loading...