[uanog] New virus attack

Sergey Smitienko hunter at comsys.com.ua
Tue Jul 4 20:59:54 EEST 2017


А что за антивирус ??

On 04.07.17 18:24, Vasiliy P. Melnik wrote:
> Кто поднял медок всем привет - я так понимаю после ребута диск пошифруется
>
> C:\medoc\03359658\ZvitPublishedObjects.dlla variant of MSIL/TeleDoor.A 
> trojancleaned by deleting
> C:\Program Files\KMSpico\AutoPico.exea variant of 
> MSIL/HackTool.IdleKMS.E potentially unsafe applicationcleaned by deleting
> C:\Program Files\KMSpico\KMSELDI.exeMSIL/HackTool.IdleKMS.I 
> potentially unsafe applicationcleaned by deleting
> C:\Program Files\KMSpico\Service_KMS.exea variant of 
> MSIL/HackTool.IdleKMS.E potentially unsafe applicationcleaned by 
> deleting (after the next restart)
> C:\Windows\SECOH-QAD.dllWin64/HackKMS.D potentially unsafe 
> applicationcleaned by deleting
> C:\Windows\SECOH-QAD.exeWin64/HackKMS.C potentially unsafe 
> applicationcleaned by deleting
> ${DisksMBR}Win32/Diskcoder.C trojanunable to clean
>
>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.uanog.kiev.ua/pipermail/uanog/attachments/20170704/d03548ab/attachment.html>


More information about the uanog mailing list