Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
OptiPlex 360 380 760 780 960 Xeon LGA 77...
Last Post: LoFabio
Today 02:49 PM
» Replies: 263
» Views: 329767
[REQUEST] Acer Nitro 5 AN517-52 BIOS Unl...
Last Post: Dudu2002
Today 03:50 AM
» Replies: 24
» Views: 10464
[REQUEST] Acer Nitro ANV15-51 BIOS Unloc...
Last Post: Dudu2002
Today 01:14 AM
» Replies: 3
» Views: 168
[REQUEST] Lenovo Yoga S940-14IIL (BQCNxx...
Last Post: Dudu2002
Yesterday 03:09 AM
» Replies: 1
» Views: 287
[REQUEST] Lenovo G400S (7BCNxxWW) Whitel...
Last Post: helrobsil
07-14-2025 09:10 PM
» Replies: 217
» Views: 112009
[REQUEST] Lenovo Ideapad S510p (89CNxxWW...
Last Post: Dudu2002
07-14-2025 12:04 PM
» Replies: 181
» Views: 91907
[REQUEST] GA-8I865GME-775-RH (rev. 3.9) ...
Last Post: DeathBringer
07-14-2025 01:48 AM
» Replies: 3
» Views: 521
i7 2860QM how to raise power limit?
Last Post: DeathBringer
07-13-2025 07:43 AM
» Replies: 12
» Views: 857
[REQUEST] Dell Wyse 3040: CSM enable for...
Last Post: mm400
07-13-2025 05:58 AM
» Replies: 1
» Views: 787
[REQUEST] Acer TravelMate 5760(G,Z) BIOS...
Last Post: quibic
07-12-2025 01:03 AM
» Replies: 49
» Views: 26806
Asus P8Z77-M RT-d Unlock
Last Post: cbaldwin1
07-11-2025 04:21 PM
» Replies: 0
» Views: 478
[REQUEST] Lenovo Yoga 530-14ARR (8MCNxxW...
Last Post: Dudu2002
07-11-2025 02:04 PM
» Replies: 4
» Views: 3247
[REQUEST] Gigabyte GA-X99P-SLI BIOS with...
Last Post: DKisCRUSHIN
07-11-2025 09:50 AM
» Replies: 0
» Views: 481
Acer Aspire 5920G - Requesting Modded BI...
Last Post: EbrahimSiami
07-10-2025 02:56 PM
» Replies: 1
» Views: 522
Acer A517-51G-58S5 - Complete BIOS image...
Last Post: Humboldt
07-10-2025 01:07 PM
» Replies: 2
» Views: 537
Lenovo Yoga Pro 7 14ASP9 Bios Unlock
Last Post: Dudu2002
07-10-2025 03:02 AM
» Replies: 3
» Views: 609
[RESOLVED] Help! BIOS for Asus GL503VS R...
Last Post: AmosNZ
07-10-2025 12:09 AM
» Replies: 5
» Views: 3077
[REQUEST] Acer Predator Helios 500 PH517...
Last Post: TeckToe
07-09-2025 11:29 PM
» Replies: 4
» Views: 1551
Gigabyte G6X 9MG insydeH2O IOS Unlock
Last Post: Zzhheennyyaa
07-09-2025 04:37 PM
» Replies: 2
» Views: 661
[SOLVED] Lenovo IdeaPad 510-15ISK - BIOS...
Last Post: outsydeh2o
07-09-2025 09:39 AM
» Replies: 1
» Views: 658

Acer 5750 Pc Hack..
#1
Hello, I have an acer 5750~g series i5 2nd generation laptop about 1.5 months ago (RIGJ) (MOIA) Under Swrtifi with EXTENSION Infected with Virus and changed all my memory its Extension Revert Extension but I can't open my files, photos and videos. Please I'm waiting for support. Thank you Recep from Turkey
find
quote
#2
Is this virus requesting payment?
find
quote
#3
yes i have come across the possibility of ransom virus researches
find
quote
#4
Also, whenever I turn on my laptop and change the hdd, it doesn't work. They make a connection, what should I do?
find
quote
#5
(12-26-2021, 01:07 AM)recep03500 Wrote: yes
If you want to recover data, follow what this virus asks for.
find
quote
#6
? ???
find
quote
#7
What is this virus called?
find
quote
#8
txt formatında açıklamasını atabilirim istersen
find
quote
#9
File Information
Size553KSHA-1c32b61c45986dc968a5f171d3908529f696fbd5fMD58d73e53c7ea2fe803c7d6f1d5033a94fCRC-32b039e34aFile typeapplication/x-ms-dos-executableFirst seen2011-04-20
Runtime Analysis
Copies Itself To
c:\Documents and Settings\test user\Local Settings\Temp\ircbsbot.exe
Dropped Files
c:\Documents and Settings\test user\Local Settings\Temp\data.dat
Size32SHA-1a63834dcdb4c35d355adff7bb74e707a6aff5a18MD5b631415fa89b240b97137ec5667af007CRC-328365a11eFile typeapplication/octet-streamFirst seen2011-04-20
Registry Keys Created
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
winlogonC:\DOCUME~1\support\LOCALS~1\Temp\ircbsbot.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
winlogonC:\DOCUME~1\support\LOCALS~1\Temp\ircbsbot.exe
HKCU\Software\VB and VBA Program Settings\INSTALL\DATE
NT4CULVUBIApril 20, 2011
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
DoNotAllowExceptions0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
c:\test_item.exec:\test_item.exe:*:Enabled:Windows Messanger
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run
winlogonC:\DOCUME~1\support\LOCALS~1\Temp\ircbsbot.exe
Processes Created
c:\windows\system32\cmd.exe
c:\windows\system32\reg.exe
DNS Requests
eastncballer.dyndns.info

https://ibb.co/MGygQp8
find
quote
#10
(12-26-2021, 03:00 AM)recep03500 Wrote: ircbsbot.exe
There is no information on the search for the file name on the net and, accordingly, there are no existing solutions. When activated, this virus establishes remote communication with the attacker's computer, so it can assume that the virus can either encrypt and allow to see your private files, but that doesn't matter.
Could you send me a downliad link to this file IN PRIVATE MESSAGES? For safety.
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)