rkhunter wrote:@Maxstar Sure that this is ransom?
So far as I looked are these files dropped by the ransom infection, In many cases you will see the same files with extensions like *.cmd *.pif *.exe *.cmd *.com *.scr in an F3 line in HijackThis.
http://www.pcwebplus.nl/phpbb/viewtopic ... 741#p24741
There are many topics with problems now, and I advised some people to upload the quarantained files of MBAM so I can use this on my own machine to decrypt them with MBAM to get a loader.
Code: Select allFiles Detected: 3
C:\Users\User\AppData\Roaming\0.2644139947080457h7i.exe (Trojan.Agent.TKH) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Roaming\0.4427793733083154.exe (Trojan.Agent.TKH) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Temp\0.4427793733083154.exe (Trojan.Agent.TKH) -> Quarantined and deleted successfully.
The weird thing is that some GEMA (german) versions will show a Dutch or Belgium version of the 'fake-police' ransom, so it looks like there is a check on IP to show the right variant of it.
For now I don't catch the used files or get a full sample of these version.