මේක ransomware එකක්ද, නැත්තන් worm එකක්ද?

Heshan Daminda

Well-known member
  • Mar 13, 2009
    46,197
    1
    101,010
    113
    34
    Kalutara
    මෙන්න මේක මොකක්ද? ගුගල් සර්ච් කරද්දී ආවේ නම් මේක worm එකක් කියල, Rasith.A කියල worm එකක්ලු. මේකට වින්ඩෝස් නොගහ අයින් කරන්න පුළුවන් විදිහක් තියේද? ඩෙස්ක්ටොප් එකට ලොග් වෙන්න දෙන්නේ නෑ. මගේ මැසිමක් නෙමෙයි ගෙවල් ළඟ එකෙක්ගේ, ඌ කිව්වේ නම් අවුලක් නෑ වින්ඩෝස් ගහන්න කියල. හැබැයි කලිනුත් මේකම ඇවිල්ල වින්ඩෝස් ගැහුවලු ෆෝමැට් කරලා. ආයේ වින්ඩෝස් ගහල ආයේ ආවොත් කියලයි සැක. :baffled: :baffled: :baffled:

    https://www.virusradar.com/en/Win32_Rasith/detail

    1595262387779.png
     
    • Like
    Reactions: kinkon

    charitha2011

    Well-known member
  • Jan 25, 2011
    16,464
    1
    32,157
    113
    - උඩරට -
    ඕක ෆුල් ෆෝමැට් කරපන්..
    හොද අප්ඩේට් කරන්න පුලුවන් වයිරස් ගාඩ් එකක් දා ගනින්. Avira , Kaspersky , MacAfee වගේ..
    ඊට පස්සේ අනිත් සොෆ්ට්වෙයාර් ටික ඉන්ස්ටෝල් කරපන්..
    උබේ පෙන් ඩ්‍රයිව් එකක හරි ඕක ඇති හංගිලා ඒකයි ඒ...
     
    Last edited:
    • Like
    Reactions: Heshan Daminda

    Heshan Daminda

    Well-known member
  • Mar 13, 2009
    46,197
    1
    101,010
    113
    34
    Kalutara
    ඕක ෆුල් ෆෝමැට් කරපන්..
    හොද අප්ඩේට් කරන්න පුලුවන් වයිරස් ගාඩ් එකක් දා ගනින්. Avira , Kaspersky , MacAfee වගේ..
    ඊට පස්සේ අනිත් සොෆ්ට්වෙයාර් ටික ඉන්ස්ටෝල් කරපන්..
    උබේ පෙන් ඩ්‍රයිව් එකක හරි ඕක ඇති හංගිලා ඒකයි ඒ...
    ඕක බූට් ස්කෑන් එකක් දෙන්න බැරිද බන් ?
    මම දැන් සේෆ් මොඩ් එකෙන් බූට් කරලා රීස්ටෝ කරන ගමන්. මේකෙන් වැඩක් වෙයිද?
     

    charitha2011

    Well-known member
  • Jan 25, 2011
    16,464
    1
    32,157
    113
    - උඩරට -
    මම දැන් සේෆ් මොඩ් එකෙන් බූට් කරලා රීස්ටෝ කරන ගමන්. මේකෙන් වැඩක් වෙයිද?


    Infection Channel:
    Dropped by other malware, Downloaded from the Internet, Via physical/removable drives
    This worm arrives via removable drives. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

    It drops an AUTORUN.INF file to automatically execute the copies it drops when a user accesses the drives of an affected system.

    It steals system information.


    Arrival Details

    This worm arrives via removable drives.

    It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

    SOLUTION


    Step 1

    Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.


    Step 2

    Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.


    Step 3

    Restart in Safe Mode


    Step 4

    Search and delete AUTORUN.INF files created by WORM_RASITH.A that contain these strings

    [AutoRun]
    action=Open
    shell\execute=kabe.bat
    shell\explore\command=kabe.bat
    USEAUTOPLAY=1
    shell\Open\command=kabe.bat
    shell\Autorun\command=kabe.bat
    shell\Search\command=kabe.bat


    Step 5


    Search and delete this file

    [ Learn More ]
    There may be some files that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.
    • %User Startup%\msfold.exe
    • %User Temp%\sajith_and_rasini.db
    • %User Temp%\i_love_you_rasini.db

    Step 6

    Restart in normal mode and scan your computer with Your Antivirus Guard


    More Infomation
     
    • Love
    Reactions: Heshan Daminda

    Dr.Amdan

    Well-known member
  • Sep 26, 2015
    26,412
    1
    28,508
    113
    ෆයිබර් අරන් වෙච්ච දෙයක් මූට.. දෙහි ටිකක් වත් කපහන්.
     
    • Angry
    Reactions: Heshan Daminda

    K_ZONE

    Well-known member
  • May 28, 2009
    5,172
    4,083
    113
    invoke db "Injected Memory"
    :D මමත් ඉස්කොලේ කාලේ කරපු හුජ්ජ වැඩ මතක් උනා, :D

    INI:
    Autorun file
    
    [autorun]
    open=MaHasona.exe
    Icon=MaHasona.exe,0
    shellexecute=MaHasona.exe
    shell\Explore\command=MaHasona.exe
    shell\Open\command=MaHasona.exe
    shell=Explore
    By K_ZONE

    තාමත් සමහරු පාරෙ හම්බ වෙලා බැනලා යනවා :(
     
    Last edited:

    comx

    Well-known member
  • Jun 11, 2015
    2,504
    1,078
    113
    srilanka
    bootable pen ekak hadala lazesoft windows recovery danna free eka atakota oka hari yai.... ita passa Avast virus software eka danna dina 30k free
     
    • Love
    Reactions: Heshan Daminda

    laknath123

    Well-known member
  • Jun 23, 2007
    18,233
    3,061
    113
    click here
    :D මමත් ඉස්කොලේ කාලේ කරපු හුජ්ජ වැඩ මතක් උනා, :D

    INI:
    Autorun file
    
    [autorun]
    open=MaHasona.exe
    Icon=MaHasona.exe,0
    shellexecute=MaHasona.exe
    shell\Explore\command=MaHasona.exe
    shell\Open\command=MaHasona.exe
    shell=Explore
    By K_ZONE

    තාමත් සමහරු පාරෙ හම්බ වෙලා බැනලා යනවා :(
    මහසෝන එක හැදුවේ තෝද ? නොදකිං ඒ කාගේ ඕක අයින් කරන්න කරපු කට්ට.....
     
    • Haha
    Reactions: Heshan Daminda

    Heshan Daminda

    Well-known member
  • Mar 13, 2009
    46,197
    1
    101,010
    113
    34
    Kalutara
    අඩෝ මම restore කළා ලැප් එක. දැන් ඌ කලින් දාපු පාස්වර්ඩ් එකක් අහනව. ඒක දාපු එකාටත් මතක නෑ. ගහන ගහන එක වැරදියි. පාස්වර්ඩ් රීසෙට් දුන්නම usb pen එකක් ගහන්න කියනව. පෙන් එකක් නෑ මේ වෙලාවේ, කොහොමද පෙන් එකක් නැතුව reset කරන්නේ password එක?
     

    imhotep

    Well-known member
  • Mar 29, 2017
    14,861
    8
    35,448
    113
    අඩෝ මම restore කළා ලැප් එක. දැන් ඌ කලින් දාපු පාස්වර්ඩ් එකක් අහනව. ඒක දාපු එකාටත් මතක නෑ. ගහන ගහන එක වැරදියි. පාස්වර්ඩ් රීසෙට් දුන්නම usb pen එකක් ගහන්න කියනව. පෙන් එකක් නෑ මේ වෙලාවේ, කොහොමද පෙන් එකක් නැතුව reset කරන්නේ password එක?
    There are many free password reset utilities... Boot off from a USB and just blank the password.
    Check the Lazesoft site https://www.lazesoft.com/forgot-windows-admin-password-recovery-freeware.html
    or use the "Offline NT Password & Registry Editor"
     
    • Like
    Reactions: Heshan Daminda

    HSW

    Well-known member
  • Nov 18, 2016
    3,475
    1
    519
    113
    ඕක නම් මොකක්ද දන්නෙ නෑ. ඉන්දියන් කාරයො ඔය වගේ messages එවල සුද්දන්ව රවට්ටල සල්ලි ගන්න scams නම් තියෙනවා.
     
    • Sad
    Reactions: Heshan Daminda