Need help? Ask the community or hire an expert.
Go to Avira Answers
??:TR/Ransom.Foreign.abna
????:14/02/2013
??:?????
????:?
????????????????
??/????????????
?? / ????????????
????:?
VDF ??:7.11.61.26 - 14 Şubat 2013 Perşembe
IVDF ??:7.11.61.26 - 14 Şubat 2013 Perşembe

 ???? ????:
   • ?????????


??:
   •  Kaspersky: Trojan-Ransom.Win32.Foreign.abna
     Avast: MSIL:LockScreen-Q
   •  Grisoft: PSW.Agent.BASM
   •  VirusBuster: Trojan.Foreign!IMuNi5yt0b4
   •  Eset: MSIL/PSW.Stealock.A trojan
     Norman: Trojan W32/Stealock.A


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003
    Windows Vista
    Windows Server 2008
    Windows 7


???:
   • ??????
   • Pricetrap ?? - ????????????


?????????????:


 ?? ???????????:
   • %HOME%\Application Data\Windows Authentication\Windows Authentication.exe

 ??? ????????????????????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Windows Authentication"="%HOME%\\Application Data\\Windows Authentication\\Windows Authentication.exe"



?????????????:

–  [HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
   • "4EFCED9C6BDD0C985CA3C7D253063C5BE6FC620C"=-
   • "4EF2E6670AC9B5091FE06BE0E5483EAAD6BA32D9"=-
   • "4C95A9902ABE0777CED18D6ACCC3372D2748381E"=-
   • "4BA7B9DDD68788E12FF852E1A024204BF286A8F6"=-
   • "4B421F7515F6AE8A6ECEF97F6982A400A4D9224E"=-
   • "47AFB915CDA26D82467B97FA42914468726138DD"=-
   • "4463C531D7CCC1006794612BB656D3BF8257846F"=-
   • "43F9B110D5BAFD48225231B0D0082B372FEF9A54"=-
   • "43DDB1FFF3B49B73831407F6BC8B975023D07C50"=-
   • "40E78C1D523D1CD9954FAC1A1AB3BD3CBAA15BFC"=-
   • "4072BA31FEC351438480F62E6CB95508461EAB2F"=-
   • "3F85F2BB4A62B0B58BE1614ABB0D4631B4BEF8BA"=-
   • "394FF6850B06BE52E51856CC10E180E882B385CC"=-
   • "36863563FD5128C7BEA6F005CFE9B43668086CCE"=-
   • "317A2AD07F2B335EF5A1C34E4B57E8B7D8F1FCA6"=-
   • "2F173F7DE99667AFA57AF80AA2D1B12FAC830338"=-
   • "284F55C41A1A7A3F8328D4C262FB376ED6096F24"=-
   • "273EE12457FDC4F90C55E82B56167F62F532E547"=-
   • "24BA6D6C8A5B5837A48DB5FAE919EA675C94D217"=-
   • "24A40A1F573643A67F0A4B0749F6A22BF28ABB6B"=-
   • "23E594945195F2414803B4D564D2A3A3F5D88B8C"=-
   • "216B2A29E62A00CE820146D8244141B92511B279"=-
   • "209900B63D955728140CD13622D8C687A4EB0085"=-
   • "1F55E8839BAC30728BE7108EDE7B0BB0D3298224"=-
   • "1331F48A5DA8E01DAACA1BB0C17044ACFEF755BB"=-
   • "0B77BEBBCB7AA24705DECC0FBD6A02FC7ABD9B52"=-
   • "049811056AFE9FD0F5BE01685AACE6A5D1C4454C"=-
   • "0483ED3399AC3608058722EDBC5E4600E3BEF9D7"=-
   • "00EA522C8A9C06AA3ECCE0B4FA6CDC21D92E8099"=-
   • "0048F8D37B153F6EA2798C323EF4F318A5624A9E"=-
   • "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"=-



?????????:

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   4EFCED9C6BDD0C985CA3C7D253063C5BE6FC620C]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   4EF2E6670AC9B5091FE06BE0E5483EAAD6BA32D9]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   4C95A9902ABE0777CED18D6ACCC3372D2748381E]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   4BA7B9DDD68788E12FF852E1A024204BF286A8F6]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   4B421F7515F6AE8A6ECEF97F6982A400A4D9224E]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   47AFB915CDA26D82467B97FA42914468726138DD]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   4463C531D7CCC1006794612BB656D3BF8257846F]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   43F9B110D5BAFD48225231B0D0082B372FEF9A54]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   43DDB1FFF3B49B73831407F6BC8B975023D07C50]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   40E78C1D523D1CD9954FAC1A1AB3BD3CBAA15BFC]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   4072BA31FEC351438480F62E6CB95508461EAB2F]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   3F85F2BB4A62B0B58BE1614ABB0D4631B4BEF8BA]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   394FF6850B06BE52E51856CC10E180E882B385CC]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   36863563FD5128C7BEA6F005CFE9B43668086CCE]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   317A2AD07F2B335EF5A1C34E4B57E8B7D8F1FCA6]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   2F173F7DE99667AFA57AF80AA2D1B12FAC830338]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   284F55C41A1A7A3F8328D4C262FB376ED6096F24]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   273EE12457FDC4F90C55E82B56167F62F532E547]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   24BA6D6C8A5B5837A48DB5FAE919EA675C94D217]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   24A40A1F573643A67F0A4B0749F6A22BF28ABB6B]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   23E594945195F2414803B4D564D2A3A3F5D88B8C]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   216B2A29E62A00CE820146D8244141B92511B279]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   209900B63D955728140CD13622D8C687A4EB0085]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   1F55E8839BAC30728BE7108EDE7B0BB0D3298224]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   1331F48A5DA8E01DAACA1BB0C17044ACFEF755BB]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   0B77BEBBCB7AA24705DECC0FBD6A02FC7ABD9B52]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   049811056AFE9FD0F5BE01685AACE6A5D1C4454C]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   0483ED3399AC3608058722EDBC5E4600E3BEF9D7]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   00EA522C8A9C06AA3ECCE0B4FA6CDC21D92E8099]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   0048F8D37B153F6EA2798C323EF4F318A5624A9E]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43]
   ??:
   • "Blob"=%?????%

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\
   0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43]
   ??:
   • "Blob"=%?????%

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\
   Winlogon]
   ??:
   • "ParseAutoexec"="1"

Açıklamayı yerleştiren Alexander Bauer tarihinde 25 Şubat 2013 Pazartesi
Açıklamayı güncelleyen: Sven Carlsen tarihinde 25 Şubat 2013 Pazartesi

Geri . . . .
https:// Bu pencere güvenlik amacıyla şifrelenmiştir.