Home Malware Programs Trojans Trojan.Ransomlock.W

Trojan.Ransomlock.W

Posted: October 4, 2012

Threat Metric

Ranking: 19,264
Threat Level: 9/10
Infected PCs: 981
First Seen: October 4, 2012
Last Seen: March 8, 2025
OS(es) Affected: Windows

Trojan.Ransomlock.W is a Trojan that downloads and installs the Politie Federal Computer Crime Unit Ransomware on the victimized PCs. Trojan.Ransomlock.W locks the desktop of the targeted computer and makes the PC unusable. Trojan.Ransomlock.W demands a supposed ransom from the PC owner to be paid receive an unlock code. While being run, Trojan.Ransomlock.W copies itself to the certain location of the compromised PC. Trojan.Ransomlock.W creates the specific registry entry so that it can initiate automatically whenever you boot up Windows. Once Trojan.Ransomlock.W has locked the computer, it shows a misleading notification on the screen, which accuses computer users of breaching the certain copyright law and asks them to pay the so-called fine of $200 via a Ukash or MoneyPak to evade prosecution and restore access to the blocked computer.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\KB[EIGHT RANDOM DIGITS].exe File name: %UserProfile%\Application Data\KB[EIGHT RANDOM DIGITS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"KB[EIGHT RANDOM DIGITS].exe" = "%UserProfile%\Application Data\KB[EIGHT RANDOM DIGITS].exe"
Loading...