Home Malware Programs Trojans Trojan.Ransomlock.U

Trojan.Ransomlock.U

Posted: October 4, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 62
First Seen: October 4, 2012
OS(es) Affected: Windows

Trojan.Ransomlock.U is a Trojan that is used to spread the Sur votre ordinateur est infecte French Ransomware to the hacked computers. Trojan.Ransomlock.U locks the desktop of the corrupted machine and makes the computer system unusable. Trojan.Ransomlock.U demands a supposed ransom from the affected computer owner to be paid to unlock the computer system. While being activated, Trojan.Ransomlock.U copies itself to the certain location of the infected computer. Trojan.Ransomlock.U creates the specific registry entry so that it can load automatically whenever you boot up Windows. Once the PC is locked, Trojan.Ransomlock.U shows a deceptive alert on the screen, which accuses PC users of violating the certain copyright law and asks them to pay the so-called fine of $200 via a Ukash or MoneyPak payment system to avoid prosecution and regain access to the computer.

Aliases

Trj/CI.A [Panda]Downloader.Generic13.LNX [AVG]Trojan-Downloader.Win32.Andromeda [Ikarus]Trojan/Win32.Downloader [AhnLab-V3]TrojanDownloader:Win32/Karagany.L [Microsoft]Rkit/Agent.101376.2 [AntiVir]Win32:Karagany-MC [Trj] [Avast]Suspicious file [Panda]W32/Zbot.MZ!tr [Fortinet]Win32:Rootkit-gen [GData]Trojan.PWS.Panda.2958 [DrWeb]TrojWare.Win32.Trojan.Agent.Gen [Comodo]Trojan-Downloader.Win32.Andromeda.nu [Kaspersky]Win32:Rootkit-gen [Rtk] [Avast]Trojan.Ransomlock.U [Symantec]
More aliases (23)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\Microsoft\Windows\2753\TSErrRedir.exe File name: TSErrRedir.exe
Size: 101.37 KB (101376 bytes)
MD5: 2d1c12d1af36bb650f707012c7bb78c0
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Microsoft\Windows\2753
Group: Malware file
Last Updated: October 12, 2012
Loading...