Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.Encoder.30941

Added to the Dr.Web virus database: 2020-02-03

Virus description added:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %APPDATA%\microsoft\windows\start menu\programs\startup\runtime broker.exe
  • %APPDATA%\microsoft\windows\start menu\programs\startup\wannascream.hta
Malicious functions
Reads files which store third party applications passwords
  • %HOMEPATH%\desktop\13.jpg
  • %HOMEPATH%\desktop\tree_view.htm
  • %HOMEPATH%\desktop\testee.cer
  • %HOMEPATH%\desktop\testcertificate.cer
  • %HOMEPATH%\desktop\split.avi
  • %HOMEPATH%\desktop\sdksampleunprivdeveloper.cer
  • %HOMEPATH%\desktop\region-north-karelia.jpg
  • %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
  • %HOMEPATH%\desktop\delete.avi
  • %HOMEPATH%\desktop\dashborder_120.bmp
  • %HOMEPATH%\desktop\correct.avi
  • %HOMEPATH%\desktop\contoso_1.cer
  • %HOMEPATH%\desktop\trivial-merge.htm
  • %HOMEPATH%\desktop\contoso.cer
  • %HOMEPATH%\desktop\browse.htm
  • %HOMEPATH%\desktop\api-hashmap.html
  • %HOMEPATH%\desktop\adhd_and_obesity.docx
  • %HOMEPATH%\desktop\adadsi.html
  • %HOMEPATH%\desktop\about.html
  • %HOMEPATH%\desktop\4f0bf7ff71f28.jpg
  • %HOMEPATH%\desktop\4f0bf7ff71f28.jpeg
  • %HOMEPATH%\desktop\3.jpg
  • %HOMEPATH%\desktop\210252809.jpg
  • %HOMEPATH%\desktop\2.jpg
  • %HOMEPATH%\desktop\168.jpg
  • %HOMEPATH%\desktop\coffee.bmp
  • %HOMEPATH%\desktop\weeklysheet1215.doc
Modifies file system
Creates the following files
  • %HOMEPATH%\desktop\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\dp0qcmsh\info.txt
  • %APPDATA%\adobe\acrobat\dc\security\crlcache\info.txt
  • %APPDATA%\adobe\acrobat\dc\security\info.txt
  • %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~\info.txt
  • %LOCALAPPDATA%\adobe\acrobat\dc\cache\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\safebrowsing\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\3v2zgiw9\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\info.txt
  • %APPDATA%\icq-profile\update\info.txt
  • %APPDATA%\adobe\acrobat\dc\preferences\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\offlinecache\info.txt
  • %TEMP%\info.txt
  • %LOCALAPPDATA%\microsoft\feeds\feeds for united states~\info.txt
  • %LOCALAPPDATA%\steam\htmlcache\info.txt
  • %LOCALAPPDATA%\microsoft\feeds\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\webslices~\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\info.txt
  • %APPDATA%\microsoft\internet explorer\quick launch\info.txt
  • %LOCALAPPDATA%\microsoft\media player\info.txt
  • %APPDATA%\microsoft\document building blocks\1033\14\info.txt
  • %APPDATA%\microsoft\dbgclr\7.1\info.txt
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\info.txt
  • %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\info.txt
  • %APPDATA%\macromedia\flash player\#sharedobjects\gr8by44n\kiks.yandex.ru\info.txt
  • %APPDATA%\mirc\info.txt
  • %APPDATA%\mail.ru\agent\info.txt
  • %APPDATA%\icqm\icq\database\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\w37zlxnl\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\p4p79gg0\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\evw7z7yu\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\g32ifqhj\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\recovery\high\active\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\1ilya49m\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\e6k79x6b\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\info.txt
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\info.txt
  • %LOCALAPPDATA%\opera software\opera stable\cache\info.txt
  • %APPDATA%\ghisler\info.txt
  • %LOCALAPPDATA%\adobe\color\info.txt
  • %LOCALAPPDATA%low\adobe\acrobat\dc\info.txt
  • %LOCALAPPDATA%\adobe\acrobat\dc\info.txt
  • %LOCALAPPDATA%\applicationhistory\info.txt
  • %HOMEPATH%\contacts\info.txt
  • %LOCALAPPDATA%\info.txt
  • %HOMEPATH%\videos\info.txt
  • %HOMEPATH%\pictures\info.txt
  • %HOMEPATH%\downloads\info.txt
  • %LOCALAPPDATA%\microsoft\windows\history\info.txt
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012016081820160819\info.txt
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012015112320151124\info.txt
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\info.txt
  • %HOMEPATH%\music\info.txt
  • %HOMEPATH%\documents\info.txt
  • %LOCALAPPDATA%low\microsoft\internet explorer\services\info.txt
  • %LOCALAPPDATA%low\oracle\java\au\info.txt
  • %APPDATA%\adobe\acrobat\dc\jscache\info.txt
  • %APPDATA%\adobe\acrobat\dc\info.txt
  • %LOCALAPPDATA%\microsoft\feeds\info.txt
  • %APPDATA%\icqm\info.txt
  • %APPDATA%\icq-profile\base\info.txt
  • %LOCALAPPDATA%low\sun\java\jre1.8.0_45_x64\info.txt
  • %LOCALAPPDATA%\adobe\color\profiles\info.txt
  • %APPDATA%\icq-profile\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\info.txt
  • %LOCALAPPDATA%\microsoft\device metadata\info.txt
  • %LOCALAPPDATA%\msfree inc\info.txt
  • %LOCALAPPDATA%\google\chrome\user data\info.txt
  • %LOCALAPPDATA%\microsoft\dbgclr\7.1\info.txt
  • %APPDATA%\adobe\logtransport2\info.txt
  • %APPDATA%\adobe\flash player\nativecache\info.txt
  • %LOCALAPPDATA%low\sun\java\deployment\info.txt
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\info.txt
  • %APPDATA%\microsoft\mmc\info.txt
Moves the following files
  • from %APPDATA%\ghisler\wincmd.ini to %APPDATA%\ghisler\wincmd.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\bookmarksextras to %APPDATA%\opera software\opera stable\bookmarksextras-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\dll\mailrusputnik.exe to %APPDATA%\icqm\icq\dll\mailrusputnik.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\update\languages.aff to %APPDATA%\mra\update\languages.aff-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\qip 2012.lnk to %APPDATA%\microsoft\internet explorer\quick launch\qip 2012.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_amd64_20151216210341_000_vcruntimeminimum_x64.log to %TEMP%\dd_vcredist_amd64_20151216210341_000_vcruntimeminimum_x64.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\magentsetup.exe to %APPDATA%\mail.ru\agent\magentsetup.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\publisher building blocks\contentstore.xml to %APPDATA%\microsoft\publisher building blocks\contentstore.xml-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\addons.json to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\addons.json-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\bookmarks.bak to %APPDATA%\opera software\opera stable\bookmarks.bak-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\chrome.dll to %APPDATA%\qipguard\chrome.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\dll\altergeo.msi to %APPDATA%\icqm\icq\dll\altergeo.msi-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\base\opt.dbs to %APPDATA%\mra\base\opt.dbs-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk to %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\mozilla thunderbird.lnk to %APPDATA%\microsoft\internet explorer\quick launch\mozilla thunderbird.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\bookmarks to %APPDATA%\opera software\opera stable\bookmarks-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\cache to %APPDATA%\qipguard\cache-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\crash reports\installtime20150415140819 to %APPDATA%\mozilla\firefox\crash reports\installtime20150415140819-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_uz.csv to %APPDATA%\icqm\icq\database\citylist_uz.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\base\mra.dbs to %APPDATA%\mra\base\mra.dbs-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\mail.ru agent.lnk to %APPDATA%\microsoft\internet explorer\quick launch\mail.ru agent.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\scripts\popups.ini to %APPDATA%\mirc\scripts\popups.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_setuputility.txt to %TEMP%\dd_setuputility.txt-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\magent.exe to %APPDATA%\mail.ru\agent\magent.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_ua.csv to %APPDATA%\icqm\icq\database\citylist_ua.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\scripts\aliases.ini to %APPDATA%\mirc\scripts\aliases.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\installerlang.xml to %APPDATA%\mra\installerlang.xml-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_amd64_20151216210341.log to %TEMP%\dd_vcredist_amd64_20151216210341.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\msdn\7.0\objbrow.dat to %APPDATA%\microsoft\msdn\7.0\objbrow.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\qipguard.exe to %APPDATA%\qipguard\qipguard.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\sqlite3.dll to %APPDATA%\qipguard\sqlite3.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_x86_20151216210157_001_vcruntimeadditional_x86.log to %TEMP%\dd_vcredist_x86_20151216210157_001_vcruntimeadditional_x86.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\cookies-journal to %APPDATA%\opera software\opera stable\cookies-journal-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\vplog.dat to %APPDATA%\mail.ru\agent\vplog.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\fonts\segoesc.ttf to %APPDATA%\icqm\icq\fonts\segoesc.ttf-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\telegram desktop\log.txt to %APPDATA%\telegram desktop\log.txt-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\cookies to %APPDATA%\opera software\opera stable\cookies-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\uproof\excludedictionaryen0809.lex to %APPDATA%\microsoft\uproof\excludedictionaryen0809.lex-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_x86_20151216210157_000_vcruntimeminimum_x86.log to %TEMP%\dd_vcredist_x86_20151216210157_000_vcruntimeminimum_x86.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk to %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\vivo.dll to %APPDATA%\mail.ru\agent\vivo.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\compatibility.ini to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\compatibility.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\update\languages.hash to %APPDATA%\mra\update\languages.hash-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\templates\normal.dotm to %APPDATA%\microsoft\templates\normal.dotm-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\blocklist.xml to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\blocklist.xml-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\certificate revocation lists to %APPDATA%\opera software\opera stable\certificate revocation lists-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\uproof\excludedictionaryen0409.lex to %APPDATA%\microsoft\uproof\excludedictionaryen0409.lex-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_x86_20151216210157.log to %TEMP%\dd_vcredist_x86_20151216210157.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\winamp.lnk to %APPDATA%\microsoft\internet explorer\quick launch\winamp.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\sciter32.dll to %APPDATA%\mail.ru\agent\sciter32.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\dll\mousephone.dll to %APPDATA%\icqm\icq\dll\mousephone.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\update\languages.dict to %APPDATA%\mra\update\languages.dict-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\browser.js to %APPDATA%\opera software\opera stable\browser.js-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\qipguard_upd.exe to %APPDATA%\qipguard\qipguard_upd.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_amd64_20151216210341_001_vcruntimeadditional_x64.log to %TEMP%\dd_vcredist_amd64_20151216210341_001_vcruntimeadditional_x64.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk to %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\mrainplaceviewer.dll to %APPDATA%\mail.ru\agent\mrainplaceviewer.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\dll\mratag.dll to %APPDATA%\icqm\icq\dll\mratag.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt to %TEMP%\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_tr.csv to %APPDATA%\icqm\icq\database\citylist_tr.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#yastatic.net\settings.sol to %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#yastatic.net\settings.sol-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\update\vvlog.dat to %APPDATA%\icq-profile\update\vvlog.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icqsetup.exe to %APPDATA%\icqm\icqsetup.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\aspnetsetup_00000.log to %TEMP%\aspnetsetup_00000.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\aspnetsetup.log to %TEMP%\aspnetsetup.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata to %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\update\languages.hash to %APPDATA%\icq-profile\update\languages.hash-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\adobesfx.log to %TEMP%\adobesfx.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\update\languages.dict to %APPDATA%\icq-profile\update\languages.dict-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat to %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\libvoip_x86.dll to %APPDATA%\icqm\libvoip_x86.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq.exe to %APPDATA%\icqm\icq.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\update\languages.aff to %APPDATA%\icq-profile\update\languages.aff-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\preferences\autofilldefaults.dat to %APPDATA%\adobe\acrobat\dc\preferences\autofilldefaults.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\adobearm.log to %TEMP%\adobearm.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\jscache\globsettings to %APPDATA%\adobe\acrobat\dc\jscache\globsettings-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\opt.dbs-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\jscache\globdata to %APPDATA%\adobe\acrobat\dc\jscache\globdata-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\mra.dbs-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\installerlang.xml to %APPDATA%\icq-profile\installerlang.xml-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav to %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\logtransport2\logtransport2.cfg to %APPDATA%\adobe\logtransport2\logtransport2.cfg-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\flash player\nativecache\nativecache.directory to %APPDATA%\adobe\flash player\nativecache\nativecache.directory-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\tmdocs.sav to %APPDATA%\adobe\acrobat\dc\tmdocs.sav-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\adobearm_notlocked.log to %TEMP%\adobearm_notlocked.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cprogram files (x86)opera29.0.1795.47opera_autoupdate.download.lock to %TEMP%\cprogram files (x86)opera29.0.1795.47opera_autoupdate.download.lock-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\aspnetsetup_00001.log to %TEMP%\aspnetsetup_00001.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\mrainplaceviewer.dll to %APPDATA%\icqm\mrainplaceviewer.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#kiks.yandex.ru\settings.sol to %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#kiks.yandex.ru\settings.sol-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\document building blocks\1033\14\built-in building blocks.dotx to %APPDATA%\microsoft\document building blocks\1033\14\built-in building blocks.dotx-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\office\mso1033.acl to %APPDATA%\microsoft\office\mso1033.acl-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_ru.csv to %APPDATA%\icqm\icq\database\citylist_ru.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\profiles.ini to %APPDATA%\mozilla\firefox\profiles.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\icq.lnk to %APPDATA%\microsoft\internet explorer\quick launch\icq.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\network\connections\pbk\_hiddenpbk\rasphone.pbk to %APPDATA%\microsoft\network\connections\pbk\_hiddenpbk\rasphone.pbk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvrf2a3.tmp.cvr to %TEMP%\cvrf2a3.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk to %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\urls.ini to %APPDATA%\mirc\urls.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvreaf2.tmp.cvr to %TEMP%\cvreaf2.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\servers.ini to %APPDATA%\mirc\servers.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_kz.csv to %APPDATA%\icqm\icq\database\citylist_kz.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\mmc\taskschd to %APPDATA%\microsoft\mmc\taskschd-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\dbgclr\7.1\objbrow.dat to %APPDATA%\microsoft\dbgclr\7.1\objbrow.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cprogram files (x86)opera29.0.1795.47opera_autoupdate.metrics.lock to %TEMP%\cprogram files (x86)opera29.0.1795.47opera_autoupdate.metrics.lock-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\settings.sol to %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\settings.sol-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvrde7f.tmp.cvr to %TEMP%\cvrde7f.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\macromedia\flash player\#sharedobjects\gr8by44n\kiks.yandex.ru\fuid01.sol to %APPDATA%\macromedia\flash player\#sharedobjects\gr8by44n\kiks.yandex.ru\fuid01.sol-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\mirc.ini to %APPDATA%\mirc\mirc.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\libvoip_x86.dll to %APPDATA%\mail.ru\agent\libvoip_x86.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_en.csv to %APPDATA%\icqm\icq\database\citylist_en.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvrc867.tmp.cvr to %TEMP%\cvrc867.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\vplog.dat to %APPDATA%\icqm\vplog.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvrbada.tmp.cvr to %TEMP%\cvrbada.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\vivo.dll to %APPDATA%\icqm\vivo.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvr6b9c.tmp.cvr to %TEMP%\cvr6b9c.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\sciter32.dll to %APPDATA%\icqm\sciter32.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\startmenu\icq.lnk to %APPDATA%\microsoft\internet explorer\quick launch\user pinned\startmenu\icq.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\update\vvlog.dat to %APPDATA%\mra\update\vvlog.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
Modifies user data files (Trojan.Encoder).
Network activity
TCP
HTTP GET requests
  • http://ic###azip.com/
  • http://re#######ata.merehosting.com/db
  • http://re#######ata.merehosting.com/db/
UDP
  • DNS ASK ic###azip.com
  • DNS ASK re#######ata.merehosting.com

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android