Showing posts with label how to remove. Show all posts
Showing posts with label how to remove. Show all posts

Monday, July 8, 2019

Malware Removal 101: Eris Ransomware

Just any other ransomware, Eris ransomware is easy to remove, the only problem is the decryption of your files since no decrypter is available to date.

I didn't test numerous antivirus, just two.  Kaspersky Cloud Security and 360 Total Security Essentials.

Ransomware running in memory








Kaspersky Cloud Security

  • Quick Scan terminated and deleted the malware




360 Total Security Essentials

  • Malware is detected and deleted as soon as 360 TSE is enabled.


Note:  There are no changes created by Eris in the Startup folder nor in HKLM/HKCU\...\Run.  I have to point this out because majority of removal instructions I've seen are just using templates without having an actual ransomware sample to work with.  They give instructions to find entries (keys) made by the malware in the registry.

Startup entries while ransomware is active
 
You can use any antivirus/antimalware as long as it's updated and can detect Eris.

Saturday, September 3, 2016

How to remove ramnit



Type of file: exefile
Description: Random filename
Location: Startup Folder
Size: 101872 b
MD5: F3873258A4258A6761DC54D47463182F

What it does:

  • Starts with Windows
  • Infects exe, dll and html files
  • Worm spreads via the default web browser
  • Create 4 shortcuts on external drives
  • Create copies of itself at the RECYCLER folder on external drives

Manual removal instructions

These instructions are specific to this variant of Ramnit.


1.  Terminate the malware process using Taskman or Taskkill


    TASKKILL /F /IM FIREFOX.EXE*

* Replace filename with your default web browser


2.  Delete the worm located at the Startup folder.  Filename is random.exe.


3.  Delete all shortcuts and RECYCLER folder on external drives.



4.  Scan with an updated antivirus.




Note:  DO NOT SCAN while malware is active in memory.
          Do not use Smadav (Very low detection with high False Positive)


To GOD be the glory!


All content ("Information") contained in this report is the copyrighted work of WinXPert: Virus and Malware Removal.

The Information is provided on an "as is" basis. WinXPert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, WinXPert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2016 WinXPert. All rights reserved. All other trademarks are the sole property of their respective owners.