Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Encoder.30941

Added to the Dr.Web virus database: 2020-02-03

Virus description added:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %APPDATA%\microsoft\windows\start menu\programs\startup\runtime broker.exe
  • %APPDATA%\microsoft\windows\start menu\programs\startup\wannascream.hta
Malicious functions
Reads files which store third party applications passwords
  • %HOMEPATH%\desktop\13.jpg
  • %HOMEPATH%\desktop\tree_view.htm
  • %HOMEPATH%\desktop\testee.cer
  • %HOMEPATH%\desktop\testcertificate.cer
  • %HOMEPATH%\desktop\split.avi
  • %HOMEPATH%\desktop\sdksampleunprivdeveloper.cer
  • %HOMEPATH%\desktop\region-north-karelia.jpg
  • %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
  • %HOMEPATH%\desktop\delete.avi
  • %HOMEPATH%\desktop\dashborder_120.bmp
  • %HOMEPATH%\desktop\correct.avi
  • %HOMEPATH%\desktop\contoso_1.cer
  • %HOMEPATH%\desktop\trivial-merge.htm
  • %HOMEPATH%\desktop\contoso.cer
  • %HOMEPATH%\desktop\browse.htm
  • %HOMEPATH%\desktop\api-hashmap.html
  • %HOMEPATH%\desktop\adhd_and_obesity.docx
  • %HOMEPATH%\desktop\adadsi.html
  • %HOMEPATH%\desktop\about.html
  • %HOMEPATH%\desktop\4f0bf7ff71f28.jpg
  • %HOMEPATH%\desktop\4f0bf7ff71f28.jpeg
  • %HOMEPATH%\desktop\3.jpg
  • %HOMEPATH%\desktop\210252809.jpg
  • %HOMEPATH%\desktop\2.jpg
  • %HOMEPATH%\desktop\168.jpg
  • %HOMEPATH%\desktop\coffee.bmp
  • %HOMEPATH%\desktop\weeklysheet1215.doc
Modifies file system
Creates the following files
  • %HOMEPATH%\desktop\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\dp0qcmsh\info.txt
  • %APPDATA%\adobe\acrobat\dc\security\crlcache\info.txt
  • %APPDATA%\adobe\acrobat\dc\security\info.txt
  • %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~\info.txt
  • %LOCALAPPDATA%\adobe\acrobat\dc\cache\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\safebrowsing\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\3v2zgiw9\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\info.txt
  • %APPDATA%\icq-profile\update\info.txt
  • %APPDATA%\adobe\acrobat\dc\preferences\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\offlinecache\info.txt
  • %TEMP%\info.txt
  • %LOCALAPPDATA%\microsoft\feeds\feeds for united states~\info.txt
  • %LOCALAPPDATA%\steam\htmlcache\info.txt
  • %LOCALAPPDATA%\microsoft\feeds\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\webslices~\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\info.txt
  • %APPDATA%\microsoft\internet explorer\quick launch\info.txt
  • %LOCALAPPDATA%\microsoft\media player\info.txt
  • %APPDATA%\microsoft\document building blocks\1033\14\info.txt
  • %APPDATA%\microsoft\dbgclr\7.1\info.txt
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\info.txt
  • %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\info.txt
  • %APPDATA%\macromedia\flash player\#sharedobjects\gr8by44n\kiks.yandex.ru\info.txt
  • %APPDATA%\mirc\info.txt
  • %APPDATA%\mail.ru\agent\info.txt
  • %APPDATA%\icqm\icq\database\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\w37zlxnl\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\p4p79gg0\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\evw7z7yu\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\g32ifqhj\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\recovery\high\active\info.txt
  • %LOCALAPPDATA%\microsoft\internet explorer\domstore\1ilya49m\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\e6k79x6b\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\info.txt
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\info.txt
  • %LOCALAPPDATA%\opera software\opera stable\cache\info.txt
  • %APPDATA%\ghisler\info.txt
  • %LOCALAPPDATA%\adobe\color\info.txt
  • %LOCALAPPDATA%low\adobe\acrobat\dc\info.txt
  • %LOCALAPPDATA%\adobe\acrobat\dc\info.txt
  • %LOCALAPPDATA%\applicationhistory\info.txt
  • %HOMEPATH%\contacts\info.txt
  • %LOCALAPPDATA%\info.txt
  • %HOMEPATH%\videos\info.txt
  • %HOMEPATH%\pictures\info.txt
  • %HOMEPATH%\downloads\info.txt
  • %LOCALAPPDATA%\microsoft\windows\history\info.txt
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012016081820160819\info.txt
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012015112320151124\info.txt
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\info.txt
  • %HOMEPATH%\music\info.txt
  • %HOMEPATH%\documents\info.txt
  • %LOCALAPPDATA%low\microsoft\internet explorer\services\info.txt
  • %LOCALAPPDATA%low\oracle\java\au\info.txt
  • %APPDATA%\adobe\acrobat\dc\jscache\info.txt
  • %APPDATA%\adobe\acrobat\dc\info.txt
  • %LOCALAPPDATA%\microsoft\feeds\info.txt
  • %APPDATA%\icqm\info.txt
  • %APPDATA%\icq-profile\base\info.txt
  • %LOCALAPPDATA%low\sun\java\jre1.8.0_45_x64\info.txt
  • %LOCALAPPDATA%\adobe\color\profiles\info.txt
  • %APPDATA%\icq-profile\info.txt
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\info.txt
  • %LOCALAPPDATA%\microsoft\device metadata\info.txt
  • %LOCALAPPDATA%\msfree inc\info.txt
  • %LOCALAPPDATA%\google\chrome\user data\info.txt
  • %LOCALAPPDATA%\microsoft\dbgclr\7.1\info.txt
  • %APPDATA%\adobe\logtransport2\info.txt
  • %APPDATA%\adobe\flash player\nativecache\info.txt
  • %LOCALAPPDATA%low\sun\java\deployment\info.txt
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\info.txt
  • %LOCALAPPDATA%\microsoft\feeds cache\info.txt
  • %APPDATA%\microsoft\mmc\info.txt
Moves the following files
  • from %APPDATA%\ghisler\wincmd.ini to %APPDATA%\ghisler\wincmd.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\bookmarksextras to %APPDATA%\opera software\opera stable\bookmarksextras-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\dll\mailrusputnik.exe to %APPDATA%\icqm\icq\dll\mailrusputnik.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\update\languages.aff to %APPDATA%\mra\update\languages.aff-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\qip 2012.lnk to %APPDATA%\microsoft\internet explorer\quick launch\qip 2012.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_amd64_20151216210341_000_vcruntimeminimum_x64.log to %TEMP%\dd_vcredist_amd64_20151216210341_000_vcruntimeminimum_x64.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\magentsetup.exe to %APPDATA%\mail.ru\agent\magentsetup.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\publisher building blocks\contentstore.xml to %APPDATA%\microsoft\publisher building blocks\contentstore.xml-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\addons.json to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\addons.json-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\bookmarks.bak to %APPDATA%\opera software\opera stable\bookmarks.bak-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\chrome.dll to %APPDATA%\qipguard\chrome.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\dll\altergeo.msi to %APPDATA%\icqm\icq\dll\altergeo.msi-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\base\opt.dbs to %APPDATA%\mra\base\opt.dbs-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk to %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\mozilla thunderbird.lnk to %APPDATA%\microsoft\internet explorer\quick launch\mozilla thunderbird.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\bookmarks to %APPDATA%\opera software\opera stable\bookmarks-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\cache to %APPDATA%\qipguard\cache-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\crash reports\installtime20150415140819 to %APPDATA%\mozilla\firefox\crash reports\installtime20150415140819-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_uz.csv to %APPDATA%\icqm\icq\database\citylist_uz.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\base\mra.dbs to %APPDATA%\mra\base\mra.dbs-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\mail.ru agent.lnk to %APPDATA%\microsoft\internet explorer\quick launch\mail.ru agent.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\scripts\popups.ini to %APPDATA%\mirc\scripts\popups.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_setuputility.txt to %TEMP%\dd_setuputility.txt-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\magent.exe to %APPDATA%\mail.ru\agent\magent.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_ua.csv to %APPDATA%\icqm\icq\database\citylist_ua.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\scripts\aliases.ini to %APPDATA%\mirc\scripts\aliases.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\installerlang.xml to %APPDATA%\mra\installerlang.xml-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_amd64_20151216210341.log to %TEMP%\dd_vcredist_amd64_20151216210341.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\msdn\7.0\objbrow.dat to %APPDATA%\microsoft\msdn\7.0\objbrow.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\qipguard.exe to %APPDATA%\qipguard\qipguard.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\sqlite3.dll to %APPDATA%\qipguard\sqlite3.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_x86_20151216210157_001_vcruntimeadditional_x86.log to %TEMP%\dd_vcredist_x86_20151216210157_001_vcruntimeadditional_x86.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\cookies-journal to %APPDATA%\opera software\opera stable\cookies-journal-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\vplog.dat to %APPDATA%\mail.ru\agent\vplog.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\fonts\segoesc.ttf to %APPDATA%\icqm\icq\fonts\segoesc.ttf-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\telegram desktop\log.txt to %APPDATA%\telegram desktop\log.txt-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\cookies to %APPDATA%\opera software\opera stable\cookies-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\uproof\excludedictionaryen0809.lex to %APPDATA%\microsoft\uproof\excludedictionaryen0809.lex-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_x86_20151216210157_000_vcruntimeminimum_x86.log to %TEMP%\dd_vcredist_x86_20151216210157_000_vcruntimeminimum_x86.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk to %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\vivo.dll to %APPDATA%\mail.ru\agent\vivo.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\compatibility.ini to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\compatibility.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\update\languages.hash to %APPDATA%\mra\update\languages.hash-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\templates\normal.dotm to %APPDATA%\microsoft\templates\normal.dotm-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\blocklist.xml to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\blocklist.xml-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\certificate revocation lists to %APPDATA%\opera software\opera stable\certificate revocation lists-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\uproof\excludedictionaryen0409.lex to %APPDATA%\microsoft\uproof\excludedictionaryen0409.lex-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_x86_20151216210157.log to %TEMP%\dd_vcredist_x86_20151216210157.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\winamp.lnk to %APPDATA%\microsoft\internet explorer\quick launch\winamp.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\sciter32.dll to %APPDATA%\mail.ru\agent\sciter32.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\dll\mousephone.dll to %APPDATA%\icqm\icq\dll\mousephone.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\update\languages.dict to %APPDATA%\mra\update\languages.dict-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\opera software\opera stable\browser.js to %APPDATA%\opera software\opera stable\browser.js-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\qipguard\qipguard_upd.exe to %APPDATA%\qipguard\qipguard_upd.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_vcredist_amd64_20151216210341_001_vcruntimeadditional_x64.log to %TEMP%\dd_vcredist_amd64_20151216210341_001_vcruntimeadditional_x64.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk to %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\mrainplaceviewer.dll to %APPDATA%\mail.ru\agent\mrainplaceviewer.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\dll\mratag.dll to %APPDATA%\icqm\icq\dll\mratag.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt to %TEMP%\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_tr.csv to %APPDATA%\icqm\icq\database\citylist_tr.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#yastatic.net\settings.sol to %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#yastatic.net\settings.sol-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\update\vvlog.dat to %APPDATA%\icq-profile\update\vvlog.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icqsetup.exe to %APPDATA%\icqm\icqsetup.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\aspnetsetup_00000.log to %TEMP%\aspnetsetup_00000.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\aspnetsetup.log to %TEMP%\aspnetsetup.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata to %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\update\languages.hash to %APPDATA%\icq-profile\update\languages.hash-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\adobesfx.log to %TEMP%\adobesfx.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\update\languages.dict to %APPDATA%\icq-profile\update\languages.dict-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat to %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\libvoip_x86.dll to %APPDATA%\icqm\libvoip_x86.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq.exe to %APPDATA%\icqm\icq.exe-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\update\languages.aff to %APPDATA%\icq-profile\update\languages.aff-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\preferences\autofilldefaults.dat to %APPDATA%\adobe\acrobat\dc\preferences\autofilldefaults.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\adobearm.log to %TEMP%\adobearm.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\jscache\globsettings to %APPDATA%\adobe\acrobat\dc\jscache\globsettings-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\opt.dbs-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\jscache\globdata to %APPDATA%\adobe\acrobat\dc\jscache\globdata-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\mra.dbs-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icq-profile\installerlang.xml to %APPDATA%\icq-profile\installerlang.xml-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav to %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\logtransport2\logtransport2.cfg to %APPDATA%\adobe\logtransport2\logtransport2.cfg-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\flash player\nativecache\nativecache.directory to %APPDATA%\adobe\flash player\nativecache\nativecache.directory-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\adobe\acrobat\dc\tmdocs.sav to %APPDATA%\adobe\acrobat\dc\tmdocs.sav-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\adobearm_notlocked.log to %TEMP%\adobearm_notlocked.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cprogram files (x86)opera29.0.1795.47opera_autoupdate.download.lock to %TEMP%\cprogram files (x86)opera29.0.1795.47opera_autoupdate.download.lock-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\aspnetsetup_00001.log to %TEMP%\aspnetsetup_00001.log-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\mrainplaceviewer.dll to %APPDATA%\icqm\mrainplaceviewer.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#kiks.yandex.ru\settings.sol to %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#kiks.yandex.ru\settings.sol-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\document building blocks\1033\14\built-in building blocks.dotx to %APPDATA%\microsoft\document building blocks\1033\14\built-in building blocks.dotx-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\office\mso1033.acl to %APPDATA%\microsoft\office\mso1033.acl-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_ru.csv to %APPDATA%\icqm\icq\database\citylist_ru.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mozilla\firefox\profiles.ini to %APPDATA%\mozilla\firefox\profiles.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\icq.lnk to %APPDATA%\microsoft\internet explorer\quick launch\icq.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\network\connections\pbk\_hiddenpbk\rasphone.pbk to %APPDATA%\microsoft\network\connections\pbk\_hiddenpbk\rasphone.pbk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvrf2a3.tmp.cvr to %TEMP%\cvrf2a3.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk to %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\urls.ini to %APPDATA%\mirc\urls.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvreaf2.tmp.cvr to %TEMP%\cvreaf2.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\servers.ini to %APPDATA%\mirc\servers.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_kz.csv to %APPDATA%\icqm\icq\database\citylist_kz.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\mmc\taskschd to %APPDATA%\microsoft\mmc\taskschd-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\dbgclr\7.1\objbrow.dat to %APPDATA%\microsoft\dbgclr\7.1\objbrow.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cprogram files (x86)opera29.0.1795.47opera_autoupdate.metrics.lock to %TEMP%\cprogram files (x86)opera29.0.1795.47opera_autoupdate.metrics.lock-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\settings.sol to %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\settings.sol-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvrde7f.tmp.cvr to %TEMP%\cvrde7f.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\macromedia\flash player\#sharedobjects\gr8by44n\kiks.yandex.ru\fuid01.sol to %APPDATA%\macromedia\flash player\#sharedobjects\gr8by44n\kiks.yandex.ru\fuid01.sol-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mirc\mirc.ini to %APPDATA%\mirc\mirc.ini-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mail.ru\agent\libvoip_x86.dll to %APPDATA%\mail.ru\agent\libvoip_x86.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\icq\database\citylist_en.csv to %APPDATA%\icqm\icq\database\citylist_en.csv-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvrc867.tmp.cvr to %TEMP%\cvrc867.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\vplog.dat to %APPDATA%\icqm\vplog.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvrbada.tmp.cvr to %TEMP%\cvrbada.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\vivo.dll to %APPDATA%\icqm\vivo.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %TEMP%\cvr6b9c.tmp.cvr to %TEMP%\cvr6b9c.tmp.cvr-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\icqm\sciter32.dll to %APPDATA%\icqm\sciter32.dll-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\startmenu\icq.lnk to %APPDATA%\microsoft\internet explorer\quick launch\user pinned\startmenu\icq.lnk-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
  • from %APPDATA%\mra\update\vvlog.dat to %APPDATA%\mra\update\vvlog.dat-id.[1f6ca2b1].email=[decryptharma24@cock.li].harma
Modifies user data files (Trojan.Encoder).
Network activity
TCP
HTTP GET requests
  • http://ic###azip.com/
  • http://re#######ata.merehosting.com/db
  • http://re#######ata.merehosting.com/db/
UDP
  • DNS ASK ic###azip.com
  • DNS ASK re#######ata.merehosting.com

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android