Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[REQUEST] ThinkPad E15 Gen 2 - BIOS Upda...
Last Post: Ronin314Clear
Today 06:19 PM
» Replies: 0
» Views: 12
[REQUEST] Asus Zenbook (UM535QE) Bios M...
Last Post: Bravo6
Today 03:41 AM
» Replies: 0
» Views: 194
OptiPlex 360 380 760 780 960 Xeon LGA 77...
Last Post: LoFabio
Today 03:38 AM
» Replies: 265
» Views: 330618
[REQUEST] Asus G614JV BIOS Unlock
Last Post: Mrgraysky
Today 01:02 AM
» Replies: 0
» Views: 128
[REQUEST] HP Compaq nx6120 WiFi Whitelis...
Last Post: Maxinator500
Yesterday 09:24 PM
» Replies: 1
» Views: 203
[REQUEST] Acer Nitro 5 AN517-52 BIOS Unl...
Last Post: Dudu2002
Yesterday 03:50 AM
» Replies: 24
» Views: 10541
[REQUEST] Acer Nitro ANV15-51 BIOS Unloc...
Last Post: Dudu2002
Yesterday 01:14 AM
» Replies: 3
» Views: 197
[REQUEST] Lenovo Yoga S940-14IIL (BQCNxx...
Last Post: Dudu2002
07-15-2025 03:09 AM
» Replies: 1
» Views: 371
[REQUEST] Lenovo G400S (7BCNxxWW) Whitel...
Last Post: helrobsil
07-14-2025 09:10 PM
» Replies: 217
» Views: 112452
[REQUEST] Lenovo Ideapad S510p (89CNxxWW...
Last Post: Dudu2002
07-14-2025 12:04 PM
» Replies: 181
» Views: 92052
[REQUEST] GA-8I865GME-775-RH (rev. 3.9) ...
Last Post: DeathBringer
07-14-2025 01:48 AM
» Replies: 3
» Views: 631
i7 2860QM how to raise power limit?
Last Post: DeathBringer
07-13-2025 07:43 AM
» Replies: 12
» Views: 891
[REQUEST] Dell Wyse 3040: CSM enable for...
Last Post: mm400
07-13-2025 05:58 AM
» Replies: 1
» Views: 810
[REQUEST] Acer TravelMate 5760(G,Z) BIOS...
Last Post: quibic
07-12-2025 01:03 AM
» Replies: 49
» Views: 26883
Asus P8Z77-M RT-d Unlock
Last Post: cbaldwin1
07-11-2025 04:21 PM
» Replies: 0
» Views: 561
[REQUEST] Lenovo Yoga 530-14ARR (8MCNxxW...
Last Post: Dudu2002
07-11-2025 02:04 PM
» Replies: 4
» Views: 3267
[REQUEST] Gigabyte GA-X99P-SLI BIOS with...
Last Post: DKisCRUSHIN
07-11-2025 09:50 AM
» Replies: 0
» Views: 579
Acer Aspire 5920G - Requesting Modded BI...
Last Post: EbrahimSiami
07-10-2025 02:56 PM
» Replies: 1
» Views: 535
Acer A517-51G-58S5 - Complete BIOS image...
Last Post: Humboldt
07-10-2025 01:07 PM
» Replies: 2
» Views: 643
Lenovo Yoga Pro 7 14ASP9 Bios Unlock
Last Post: Dudu2002
07-10-2025 03:02 AM
» Replies: 3
» Views: 661

Acer 5750 Pc Hack..
#1
Hello, I have an acer 5750~g series i5 2nd generation laptop about 1.5 months ago (RIGJ) (MOIA) Under Swrtifi with EXTENSION Infected with Virus and changed all my memory its Extension Revert Extension but I can't open my files, photos and videos. Please I'm waiting for support. Thank you Recep from Turkey
find
quote
#2
Is this virus requesting payment?
find
quote
#3
yes i have come across the possibility of ransom virus researches
find
quote
#4
Also, whenever I turn on my laptop and change the hdd, it doesn't work. They make a connection, what should I do?
find
quote
#5
(12-26-2021, 01:07 AM)recep03500 Wrote: yes
If you want to recover data, follow what this virus asks for.
find
quote
#6
? ???
find
quote
#7
What is this virus called?
find
quote
#8
txt formatında açıklamasını atabilirim istersen
find
quote
#9
File Information
Size553KSHA-1c32b61c45986dc968a5f171d3908529f696fbd5fMD58d73e53c7ea2fe803c7d6f1d5033a94fCRC-32b039e34aFile typeapplication/x-ms-dos-executableFirst seen2011-04-20
Runtime Analysis
Copies Itself To
c:\Documents and Settings\test user\Local Settings\Temp\ircbsbot.exe
Dropped Files
c:\Documents and Settings\test user\Local Settings\Temp\data.dat
Size32SHA-1a63834dcdb4c35d355adff7bb74e707a6aff5a18MD5b631415fa89b240b97137ec5667af007CRC-328365a11eFile typeapplication/octet-streamFirst seen2011-04-20
Registry Keys Created
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
winlogonC:\DOCUME~1\support\LOCALS~1\Temp\ircbsbot.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
winlogonC:\DOCUME~1\support\LOCALS~1\Temp\ircbsbot.exe
HKCU\Software\VB and VBA Program Settings\INSTALL\DATE
NT4CULVUBIApril 20, 2011
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
DoNotAllowExceptions0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
c:\test_item.exec:\test_item.exe:*:Enabled:Windows Messanger
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run
winlogonC:\DOCUME~1\support\LOCALS~1\Temp\ircbsbot.exe
Processes Created
c:\windows\system32\cmd.exe
c:\windows\system32\reg.exe
DNS Requests
eastncballer.dyndns.info

https://ibb.co/MGygQp8
find
quote
#10
(12-26-2021, 03:00 AM)recep03500 Wrote: ircbsbot.exe
There is no information on the search for the file name on the net and, accordingly, there are no existing solutions. When activated, this virus establishes remote communication with the attacker's computer, so it can assume that the virus can either encrypt and allow to see your private files, but that doesn't matter.
Could you send me a downliad link to this file IN PRIVATE MESSAGES? For safety.
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)