Preview the new CCleaner Browser
The fast, private and secure browser for Windows, from the makers of CCleaner
Download
|  | 
| Rufus with settings used in creating a bootable Windows 10 installer | 
|  | 
| Ransomware running in memory | 
|  | 
| Startup entries while ransomware is active | 
|  | 
| Ransomware Readme | 
|  | 
| Documents encrypted by Eris Ransomware | 
|  | 
| Original document filesize is reduced to zero byte after encryption | 
|  | 
| Encrypted document | 
|  | 
| Folder used by worm with denied Full control | 
| Keys added: | 
| HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Associations HKU\S-1-5-21-628660338-905938160-2927024020-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Associations HKU\S-1-5-21-628660338-905938160-2927024020-1000\Software\Unzip | 
| Values added: | 
| HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\EnableFileTracing: 0x00000000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\EnableConsoleTracing: 0x00000000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\FileTracingMask: 0xFFFF0000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\ConsoleTracingMask: 0xFFFF0000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\MaxFileSize: 0x00100000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\FileDirectory: "%windir%\tracing" HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\EnableFileTracing: 0x00000000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\EnableConsoleTracing: 0x00000000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\FileTracingMask: 0xFFFF0000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\ConsoleTracingMask: 0xFFFF0000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\MaxFileSize: 0x00100000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\FileDirectory: "%windir%\tracing" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Associations\LowRiskFileTypes: ".exe" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Ggle Updater: "C:\Users\Arnel\AppData\Roaming\Arnel\app.exe" | 
| Files added: | 
| C:\Users\Arnel\AppData\Roaming\Arnel\7za.exe C:\Users\Arnel\AppData\Roaming\Arnel\app.exe C:\Users\Arnel\AppData\Roaming\Arnel\background.js C:\Users\Arnel\AppData\Roaming\Arnel\config.json C:\Users\Arnel\AppData\Roaming\Arnel\files.7z C:\Users\Arnel\AppData\Roaming\Arnel\manifest.json C:\Users\Arnel\AppData\Roaming\Arnel\update-x64.exe C:\Users\Arnel\AppData\Roaming\Arnel\update-x86.exe | 
| Folders added: | 
| C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2LXBY3LA C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2YQU29T2 C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5KFJB9OR C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZL3SUC12 C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized C:\Users\Arnel\AppData\Local\Temp\Low C:\Users\Arnel\AppData\Roaming\Arnel |