Home Malware Programs Trojans Trojan.Ransomlock.H

Trojan.Ransomlock.H

Posted: July 13, 2011

Trojan.Ransomlock.H is a ransomware Trojan that locks your computer and refuses to let you use it until you've followed Trojan.Ransomlock.H's ransoming instructions. The instructions may involve texting a premium number or sending money directly to criminals through various services. Trojan.Ransomlock.H's Russian origins may make it confusing to non-Russian speakers, but all you need to know about Trojan.Ransomlock.H is that getting rid of Trojan.Ransomlock.H should be your highest priority. High-quality threat-removal software and strategies that bypass Trojan.Ransomlock.H's automatic startup will allow you to delete Trojan.Ransomlock.H and resume normal use of your computer.

Trojan.Ransomlock.H, the Ransom Attack from Russian

Trojan.Ransomlock.H may use malicious websites to infect your computer. Disabling scripts for risky websites, keeping your software up to date and avoiding suspicious file downloads may help to reduce your exposure to Trojan.Ransomlock.H attack vectors. As a Russian-based program, Trojan.Ransomlock.H may be especially prolific in malicious Russian websites and in files that are seeded from Russia, so you may wish to take a little extra care in those areas. However, overall distribution of Trojan.Ransomlock.H currently is reported to be quite low.

As a threat that was first seen in 2011, Trojan.Ransomlock.H is also a new menace and should be guarded against with full updates for all relevant software, especially with regards to your anti-virus software. If you're using anti-virus protection with threat definitions from prior to July 2011, you could be more vulnerable to being hurt by a Trojan.Ransomlock.H infection.

Trojan.Ransomlock.H, like all Trojans, tries to infect your PC without letting you know about it, until it's ready to attack. Trojan.Ransomlock.H's attack is also extremely difficult to overlook – the first thing you'll see is your entire computer locked up and displaying a garish yellow-on-brown error message. Deciphering this ransom message may be beyond your abilities, since the entire text is in Russian. However, figuring out the exact ransom that Trojan.Ransomlock.H wants you to pay is self-destructive, in any case.

Unlocking Your PC from Trojan.Ransomlock.H's Substantial Grip

Since all versions of Windows are vulnerable to being attacked by Trojan.Ransomlock.H's lockup scheme, knowing how to undo Trojan.Ransomlock.H's attack with minimal harm is essential. Although Trojan.Ransomlock.H may make it appear as though all major system functions are disabled, you can still access Windows and delete Trojan.Ransomlock.H with patient application of good anti-virus strategies.

Even though Trojan.Ransomlock.H will use Registry exploits to start up by default and lock Windows, Safe Mode may allow you to skirt around Trojan.Ransomlock.H's startup routine. Even if Safe Mode fails, another boot option, such as booting your computer from an external device, will let you access your PC and use the right software to remove Trojan.Ransomlock.H.

Trying to remove Trojan.Ransomlock.H manually isn't recommended unless you're a computer expert with no other choices available. For most circumstances, using strong anti-virus software is best for deleting Trojan.Ransomlock.H and restoring your PC to perfect health.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CurrentFolder%\[RANDOM NUMERIC CHARACTERS].bat
    2 %Temp%\[RANDOM ALPHANUMERIC CHARACTERS].tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[TEN RANDOM NUMBERS]" = "%UserProfile%\[TEN RANDOM NUMBERS].exe"
Loading...