Remove Trojan.Ransomlock.C


Other payload of Trojan.Ransomlock.C are as follows:

The Trojan will display a Windows Security Alert in Russian language that asked user to pay for the unlock key.

It will modify Windows Registry entries to disable Safe Mode:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop\SafeMode
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot

1 thought on “Remove Trojan.Ransomlock.C”

Leave a Comment