SeHTF
Chào mừng các bạn ghé thăm Se 2nt
Để dễ dàng trong việc tham khảo ý kiến mọi người thì các bạn cần đọc thông tin về nội quy cũng như là phải có một tài khoản cá nhân trên 4rum. Mong rằng sau một ngày làm việc căng thẳng thì Se2nt sẽ là điểm đến cho các bạn cùng giải toả stress nhé.
Nếu các bạn có vấn đề gì có thể liên hệ qua Yahoo : anhlinh01678914801 và TV để được tư vấn và hỗ trợ.

Join the forum, it's quick and easy

SeHTF
Chào mừng các bạn ghé thăm Se 2nt
Để dễ dàng trong việc tham khảo ý kiến mọi người thì các bạn cần đọc thông tin về nội quy cũng như là phải có một tài khoản cá nhân trên 4rum. Mong rằng sau một ngày làm việc căng thẳng thì Se2nt sẽ là điểm đến cho các bạn cùng giải toả stress nhé.
Nếu các bạn có vấn đề gì có thể liên hệ qua Yahoo : anhlinh01678914801 và TV để được tư vấn và hỗ trợ.
SeHTF
Bạn có muốn phản ứng với tin nhắn này? Vui lòng đăng ký diễn đàn trong một vài cú nhấp chuột hoặc đăng nhập để tiếp tục.
Đăng Nhập

Quên mật khẩu

Tìm kiếm
 
 

Display results as :
 


Rechercher Advanced Search

Top posting users this month
No user

Thống Kê
Hiện có 1 người đang truy cập Diễn Đàn, gồm: 0 Thành viên, 0 Thành viên ẩn danh và 1 Khách viếng thăm

Không

Số người truy cập cùng lúc nhiều nhất là 58 người, vào ngày Wed Aug 02, 2017 7:50 pm

How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala

Go down

23072010

Bài gửi 

How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Empty How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala




How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Vir_solutionsHow to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala

In this section you will find recommendations how to fight malicious programs which cannot be disinfected by Kaspersky Lab's products. In order to disinfect/remove malicious programs you may have to modify the system registry or use an additional utility. If you failed to find the necessary information or you find these recommendations too complicated or inadequate, please send a request to the Technical Support service via the [You must be registered and logged in to see this link.].

How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala

ID Article: 3043 Other languages: [You must be registered and logged in to see this link.]
How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Views 134 How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Modify 2010 Apr 16 18:32How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Print [You must be registered and logged in to see this link.]



Malware belonging to the family Trojan-Ransom.Win32.Digitala (Get Accelerator, Digital Access, Get Access, Download Manager v1.34) compromises systems to demand a ransom. Malware belonging to the family Trojan-Ransom.Win32.Digitala blocks access to the Internet and displays a message about breach of a license agreement. The message contains a demand to send a SMS with a certain code to a certain number in order to unblock access to the Internet.

The family Trojan-Ransom.Win32.Digitala has several types of blockers:

  • Digital Access
  • Get Accelerator
  • Get Access
  • Download Manager v1.34
  • Ilite Net Accelerator

It is highly probable that the invader will be displaying messages in Cyrillic!

Please find the examples below:




  • Digital Access
    How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_1


  • Get Accelerator
    How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_2




  • Get Access
    How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_3




  • Download Manager v1.34
    How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_4




Signs of infection



  • This malware can penetrate computers either through user's actions or silently:

    • This malware can penetrate user computers through user's actions. For example, a user can initiate installation of an allegedly legal program claiming to be Digital Access. When such “disguised” program is run, it displays a license agreement. By agreeing with this license agreement, the user allow to infect the system.

      How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_5


      How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_6
    • It can also invade without user's participation with aid of other malicious programs (Get Access) by self-downloading and performing a silent installation.

  • It will then display a message demanding to send a SMS in order to receive an activation code which would permit to activate the installed software.
  • The message may be displayed immediately or within 6 hours.

    How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_7
  • Within 5 minutes after displaying that message, the malware will force a PC reboot and block access to the Internet.
  • It will create a new folder named {ffffffff-F03B-4b40-A3D0-F62E04DD1C09} in the system registry (path HKEY_LOCAL_MACHINE->SOFTWARE->Microsoft->Windows->Current Version->Uninstall) containing uninstaller path.
  • The value of the variable "UninstallString" is srored in the field Data.

    How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_8


How this malicios program invades a system:

  • installation of a hidden service (its file can be found in C:WindowsSystem32);
  • installation of a rootkit to hide its files (its file can be found in C:WindowsSystem32). A rootkit is a program or a suite of programs designed to obscure the fact that a system has been compromised.
  • deletes its installer;
  • sends a report (about installation, activation, and deactivation) to the owner's server;
  • if there is no network or network has a specific configuration, the malicious program fails to install in the system, outputs an error and deletes its installer.


How to receive a copy of the malicious program on an infected system:

  • open the command line console:



    • in Windows XP: go to Start > Run, type in cmd and press Enter;
    • in Windows Vista / 7: type cmd in the Start Menu box area and press Enter;



  • type the following command in the command line prompt: copy (without quotes). For example:

    copy%systemroot%Installerffffffff-F03B-4b40-A3D0-F62E04DD1C09userinit.exe

    How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_8


  • virus copy will be saved in the current folder.


How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Info1It is necessary to submit a query to the Technical Suuport Service by filling the [You must be registered and logged in to see this link.] having attached a copy of the virus to the query.


Destructive effects:


  • consumes a great amount of space on the desktop
  • disables Internet access (certain versions)


How to desactivate the malicious program:

  • Start the uninstaller



    • in Windows XP: go to Start > Run, type in the value of the variable "UninstallString" and press Enter;


    • in Windows Vista / 7: type cmd in the Start Menu box area and press Enter, type in the value of the variable "UninstallString" and press Enter.
      How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_9



  • A dialog box will be displayed (within a few seconds) prompting to confirm uninstallation.

    How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_10

    Since the dialog box is obstacled with a window asking for "ransom", you should do the following:

    • open Windows Task Manager (press Ctrl+Alt+Del simultaneously)
    • open the menu Options and check the option Always on Top
      How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_11
    • right-click the taskUninstallation(the one referring to the malicious program) and select Maximize.

      How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala 3043_12




  • Click Yes in the Uninstallation dialog box.
  • Reboot the PC.


Alternative method of disinfection


There is also a utility named Digita_Cure.exe which serves for elimination of malware belonging to the family Trojan-Ransom.Win32.Digitala (Get Accelerator, Digital Access, Get Access, Download Manager v1.34).

The utility works under x86 versions of Windows OS: 2000, XP, 2003, Vista, 2008, 7.

x64 versions of Windows OS are immune to malware belonging to the family Trojan-Ransom.Win32.Digitala.

Disinfection of an infected system:



  1. Download the archive [You must be registered and logged in to see this link.] and extract it into a folder using an archiver program (WinZip, for example).
  2. Execute the file Digita_Cure.exe. The utility Digita_Cure.exe has a graphical user interface.
  3. Reboot the computer after the utility work is over.
  4. Update Kaspersky Anti-Virus databases and run a full system scan.

The utility does the following:

  1. It stops an active infection by scanning system memory for a running malicious program and removes it from the memory.
  2. Deletes the trojan program from the system by stopping its service, removing it from autorun, etc.
  3. Clears file system of passive malware.
Admin
Admin
Chủ Tịch Se S2T
Chủ Tịch Se S2T

Nam Con Giáp : Scorpio
Tuổi giáp Trung Hoa : Horse
Tổng số bài gửi : 1481
Điểm Se S2T : 88055
Sinh Nhật : 03/11/1990
Tham gia ngày : 27/08/2009
Tuổi : 33
Đến từ : Đồng Há»›i City
Sở thích : Máy tính, Soft, AV....
Tính hài hước : Bình thường

Huy chương
Sức mạnh:
How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Left_bar_bleue100/100How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Empty_bar_bleue  (100/100)
Điểm SeS2T:
How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Left_bar_bleue50/50How to deal with malware belonging to the family Trojan-Ransom.Win32.Digitala Empty_bar_bleue  (50/50)

Về Đầu Trang Go down

Share this post on: reddit

 
Permissions in this forum:
Bạn không có quyền trả lời bài viết