Preview the new CCleaner Browser
The fast, private and secure browser for Windows, from the makers of CCleaner
Download
Rufus with settings used in creating a bootable Windows 10 installer |
Ransomware running in memory |
Startup entries while ransomware is active |
Ransomware Readme |
Documents encrypted by Eris Ransomware |
Original document filesize is reduced to zero byte after encryption |
Encrypted document |
Folder used by worm with denied Full control |
Keys added: |
HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Associations HKU\S-1-5-21-628660338-905938160-2927024020-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Associations HKU\S-1-5-21-628660338-905938160-2927024020-1000\Software\Unzip |
Values added: |
HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\EnableFileTracing: 0x00000000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\EnableConsoleTracing: 0x00000000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\FileTracingMask: 0xFFFF0000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\ConsoleTracingMask: 0xFFFF0000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\MaxFileSize: 0x00100000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASAPI32\FileDirectory: "%windir%\tracing" HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\EnableFileTracing: 0x00000000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\EnableConsoleTracing: 0x00000000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\FileTracingMask: 0xFFFF0000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\ConsoleTracingMask: 0xFFFF0000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\MaxFileSize: 0x00100000 HKLM\SOFTWARE\Microsoft\Tracing\play_29732727_RASMANCS\FileDirectory: "%windir%\tracing" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Associations\LowRiskFileTypes: ".exe" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Ggle Updater: "C:\Users\Arnel\AppData\Roaming\Arnel\app.exe" |
Files added: |
C:\Users\Arnel\AppData\Roaming\Arnel\7za.exe C:\Users\Arnel\AppData\Roaming\Arnel\app.exe C:\Users\Arnel\AppData\Roaming\Arnel\background.js C:\Users\Arnel\AppData\Roaming\Arnel\config.json C:\Users\Arnel\AppData\Roaming\Arnel\files.7z C:\Users\Arnel\AppData\Roaming\Arnel\manifest.json C:\Users\Arnel\AppData\Roaming\Arnel\update-x64.exe C:\Users\Arnel\AppData\Roaming\Arnel\update-x86.exe |
Folders added: |
C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2LXBY3LA C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2YQU29T2 C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5KFJB9OR C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZL3SUC12 C:\Users\Arnel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized C:\Users\Arnel\AppData\Local\Temp\Low C:\Users\Arnel\AppData\Roaming\Arnel |