Possibly Infected By P2HHR.bat And MGT_reg32.dll.vbs

  1. All encrypted files are renamed to form {USERID}{random_hash} with .locky extension.
  2. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
  4. Edited by Kin869, 13 May 2009 - 01:18 AM.
  5. How to stay safe As always, don’t open suspicious attachments (e.g. .doc, .xls, and .zip files) Disable Microsoft Office macros by default and never enable macros in strange/unknown attachments that you
  6. Persistence After its execution, the Locky binary is copied to the %TEMP% directory and renamed to svchost.exe, to make it difficult for people to find and delete.

Javascript Disabled Detected You currently have javascript disabled. It compresses files in .rar format which is not currently blocked by Google. We therefore predict new ransomware families will emerge this year.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2ba40a1-74f3-42bd-f434-12345a2c8953} (Trojan.Ertfor) -> Delete on reboot.

