BrowserMe is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 12/12/2015.
– It belongs to a family of ransomwares.
– A ransomware is a malicious program that takes hostage certain personal data of the user.
– A polluteware is a software that pollutes storage and/or the Base of registers.
– It installs as a process launched at startup of the system (RP),
– It settled in the Base of registers to be launched each time with the system (O4),
– It creates additional folders (O43),
O4 – HKCU\..\Run: [santa_svc] C:\Users\Coolman\AppData\Roaming\nainyacroic.exe
O4 – HKCU\..\Run: [meryHmas] C:\Users\Coolman\AppData\Roaming\uvubeskhf2.exe
O4 – HKUS\S-1-5-21-3800208651-3344468394-2534425987-1000\..\Run: [santa_svc] C:\Users\Coolman\AppData\Roaming\nainyacroic.exe
O4 – HKUS\S-1-5-21-3800208651-3344468394-2534425987-1000\..\Run: [BrowserMe] . (…) — C:\Users\Coolman\AppData\Roaming\BrowserMe\ChromeUpdate.exe
O4 – HKUS\S-1-5-21-3800208651-3344468394-2534425987-1000\..\Run: [meryHmas] C:\Users\Coolman\AppData\Roaming\uvubeskhf2.exe
O43 – CFD: 27/12/2015 – [] D — C:\Users\Coolman\AppData\Roaming\BrowserMe
C:\Users\Coolman\AppData\Roaming\nainyacroic.exe
C:\Users\Coolman\AppData\Roaming\BrowserMe
C:\Users\Coolman\AppData\Roaming\BrowserMe\ChromeUpdate.exe
C:\Users\Coolman\AppData\Roaming\uvubeskhf2.exe[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:BrowserMe[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:santa_svc[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:meryHmas
TR/Crypt.Xpack.274950 8.3.2.2 [Avira AntiVirus] Win32:Malware-gen 2014.9-151019 [avast!] Trojan.Encoder.514 9.0.1.0292 [Dr.Web] Trojan.Generic.15009167 8.15.10.19.01 [Emsisoft Anti-Malware] Win32/Kryptik.DWUO (variant) 9.12382 [ESET NOD32] Trojan.GenericKD.2725257 11.2015-19-10_2 [F-Secure] Trojan-Ransom.Win32.Cryptodef 14.0.0.1255 [Kaspersky] Ransom.CryptoWall v2015.10.19.01 [Malwarebytes] RDN/Ransom 5600.6608 [McAfee] Ransom:Win32/Crowti.A 1.1.12101.0 [Microsoft Security Essentials]
– Remove software in Windows Configuration Panel,
– Remove with ZHPcleaner
– Diagnose with ZHPDiag
Leave A Comment
You must be logged in to post a comment.