Trojan:Win32/Ransom.FL is a ransomware Trojan that targets PC users in several countries that include Germany and France. Trojan:Win32/Ransom.FL displays a window that shields the entire desktop of the compromised PC and demands payment for the alleged possession of illegitimate material. Trojan:Win32/Ransom.FL displays a full-screen image that hides all other windows, making the computer effectively unusable. The image is a fake warning message that pretends to come from a legitimate institution such as the German ‘Bundespolizei’ or the French ‘Gendarmerie Nationale’. Trojan:Win32/Ransom.FL makes system changes on the affected computer system. It demands the payment of an alleged fine; however, even if the PC user pays, the computer is still left unusable. Get rid of Trojan:Win32/Ransom.FL immediately after detection.
PSW.Generic9.AYND [AVG]W32/Blocker.GOS!tr [Fortinet]Hoax.Blocker.gos [VBA32]TR/Offend.KD.491802.1 [AntiVir]Trojan.PWS.YTR [BitDefender]Trojan-Ransom.Win32.Blocker.gos [Kaspersky]Win32.PWS.Zbot.Ma [eSafe]Win32:MalOb-IF [Cryp] [Avast]TROJ_SPNR.11LO11 [TrendMicro-HouseCall]W32/Suspicious_Gen2.UMQNE [Norman]
More aliases (240)
Trojan:Win32/Ransom.FL Automatic Detection Tool (Recommended)
Is your PC infected with Trojan:Win32/Ransom.FL? To safely & quickly detect Trojan:Win32/Ransom.FL, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Trojan:Win32/Ransom.FL What happens if Trojan:Win32/Ransom.FL does not let you open SpyHunter or blocks the Internet?
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 %WINDIR%\ Explorer.exe 665 2 %USERPROFILE%\ Application Data\ 4qowy47c.exe 665 3 %USERPROFILE%\ Application Data\ pvtv11n1.exe 527 4 %USERPROFILE%\ Application Data\ wltngl8u.exe 321 5 %USERPROFILE%\ Application Data\ zxrtgshv.exe 300 6 %WINDIR%\ services32.exe 225 7 %APPDATA%\ c2qjcylz.exe 54 8 %USERPROFILE%\ AppData\ Roaming\ o9a7e2y0.exe 16 9 %APPDATA%\ yhz3kf8s.exe 12 10 %USERPROFILE%\ Application Data\ esofra45.exe 12 11 %AppData%\ehxgckss4ws4jfi2.dat N/A 12 \twexx32.dll N/A
Posted: December 20, 2011 | By SpywareRemove
Threat Level: 8/10
Rate this article:
Detection Count: 248