TrojanSpy.Win32.RISEPRO.C

 Analysis by: John Rainier Navato

 ALIASES:

Trojan.GenericKD.72158805 (BITDEFENDER)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan Spy

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Dropped by other malware, Downloaded from the Internet

This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It does not have any file infection routine.

It does not have any propagation routine.

It does not have any backdoor routine.

It gathers certain information on the affected computer.

It connects to certain websites to send and receive information.

  TECHNICAL DETAILS

File Size:

849,408 bytes

File Type:

, EXE

Memory Resident:

Yes

Initial Samples Received Date:

05 Apr 2024

Payload:

Connects to URLs/IPs, Collects system information, Steals information

Arrival Details

This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Infection Points

This Trojan Spy does not have any file infection routine.

Installation

This Trojan Spy drops a copy of itself in the following folders using different file names:

  • %All Users Profile%\MPGPH131\MPGPH131.exe
  • %AppDataLocal%\RageMP131\RageMP131.exe

(Note: %All Users Profile% is the common user's profile folder, which is usually C:\Documents and Settings\All Users on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\ProgramData on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit). . %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

It drops the following files:

  • %User Temp%\adobe{12 Random Characters}\Autofill\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\CC\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\Cookies\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\Downloads\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\Google Accounts\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\information.txt → contains gathered system information
  • %User Temp%\adobe{12 Random Characters}\passwords.txt → contains gathered passwords
  • %User Temp%\adobe{12 Random Characters}\Plugins\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\screenshot.png → screenshot of current display
  • %User Temp%\adobe{12 Random Characters}\Wallets\{Web Browser Name}_Default.txt
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Cookies
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}History
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Login Data
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Web Data
  • %User Temp%\rage131MP.tmp
  • %User Temp%\{23 Random Characters}.zip → Contains all gathered information, deleted afterwards

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

It adds the following processes:

  • schtasks /create /f /RU "{Username}" /tr "%All Users Profile%\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
  • schtasks /create /f /RU "{Username}" /tr "%All Users Profile%\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST

(Note: %All Users Profile% is the common user's profile folder, which is usually C:\Documents and Settings\All Users on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\ProgramData on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit). )

It creates the following folders:

  • %All Users Profile%\MPGPH131
  • %AppDataLocal%\RageMP131
  • %User Temp%\adobe{12 Random Characters}
  • %User Temp%\adobe{12 Random Characters}\Autofill
  • %User Temp%\adobe{12 Random Characters}\CC
  • %User Temp%\adobe{12 Random Characters}\Cookies
  • %User Temp%\adobe{12 Random Characters}\Downloads
  • %User Temp%\adobe{12 Random Characters}\FTP
  • %User Temp%\adobe{12 Random Characters}\FTP\FileZilla
  • %User Temp%\adobe{12 Random Characters}\FTP\TotalCommander
  • %User Temp%\adobe{12 Random Characters}\Games
  • %User Temp%\adobe{12 Random Characters}\Games\Battle.net
  • %User Temp%\adobe{12 Random Characters}\Games\FeatherClient
  • %User Temp%\adobe{12 Random Characters}\Games\Growtopia
  • %User Temp%\adobe{12 Random Characters}\Games\LunarClient
  • %User Temp%\adobe{12 Random Characters}\Games\Minecraft
  • %User Temp%\adobe{12 Random Characters}\Games\Steam
  • %User Temp%\adobe{12 Random Characters}\Games\TLauncher
  • %User Temp%\adobe{12 Random Characters}\Google Accounts
  • %User Temp%\adobe{12 Random Characters}\Messengers
  • %User Temp%\adobe{12 Random Characters}\Messengers\Element
  • %User Temp%\adobe{12 Random Characters}\Messengers\ICQ
  • %User Temp%\adobe{12 Random Characters}\Messengers\Pidgin
  • %User Temp%\adobe{12 Random Characters}\Messengers\Signal
  • %User Temp%\adobe{12 Random Characters}\Messengers\Skype
  • %User Temp%\adobe{12 Random Characters}\Messengers\Tox
  • %User Temp%\adobe{12 Random Characters}\Plugins
  • %User Temp%\adobe{12 Random Characters}\VPN
  • %User Temp%\adobe{12 Random Characters}\VPN\OpenVPN Connect
  • %User Temp%\adobe{12 Random Characters}\Wallets
  • %User Temp%\heidi{12 Random Characters}
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Cookies
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}History
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Login Data
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Login Data For Account
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Web Data

(Note: %All Users Profile% is the common user's profile folder, which is usually C:\Documents and Settings\All Users on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\ProgramData on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit). . %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

Autostart Technique

This Trojan Spy adds the following registry entries to enable its automatic execution at every system startup:

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
RageMP131 = %AppDataLocal%\RageMP131\RageMP131.exe

Propagation

This Trojan Spy does not have any propagation routine.

Backdoor Routine

This Trojan Spy does not have any backdoor routine.

Information Theft

This Trojan Spy gathers the following information on the affected computer:

  • System Information:
    • Malwre Build Number
    • Machine ID
    • GUID
    • HWID
    • Current Execution Path
    • Working Directory
    • IP Address
    • Location
    • OS Version
    • Computer Name
    • User Name
    • Display Resolution
    • Language
    • Current Time
  • Hardware Information:
    • Processor
    • CPU Count
    • RAM Amount
    • Video Card
  • List of Running Processes
  • List of Installed Applications
  • Screenshot of Current Display

Other Details

This Trojan Spy connects to the following URL(s) to get the affected system's IP address:

  • https://a{BLOCKED}yip.com/
  • https://a{BLOCKED}.ipify.org/?format=json
  • https://www.{BLOCKED}ind.com/en/locate-my-ip-address

It connects to the following website to send and receive information:

  • tcp://{BLOCKED}.{BLOCKED}.132.74:58709

It does the following:

  • It connects to the following URLs to get the affected system's location:
    • https://d{BLOCKED}.com/demo/home.php?s={IP Address of Affected Machine}
    • https://i{BLOCKED}fo.io/widget/demo/{IP Address of Affected Machine}
    • https://www.{BLOCKED}ind.com/geoip/v2.1/city/me
  • It terminates itself if the country code of the IP address location is any of the following:
    • RU
    • KZ
    • BY
    • AM
    • UZ
    • MD
    • KG
    • TJ
    • UA
    • AZ
  • It exfiltrates browser data (e.g. autofills, browsing history, cookies, download history, credentials/passwords, credit card data, browser extensions) from the following web browsers:
    • 360Browser
    • 7Star
    • Amigo
    • Atom
    • Black Hawk
    • Brave
    • CentBrowser
    • Chedot
    • Chrome
    • Chrome (x86)
    • ChromePlus
    • Chromium
    • Chromodo
    • Citrio
    • CocCoc
    • Comodo Dragon
    • Comodo Ice Dragon
    • Coowon
    • CryptoTab
    • Cyberfox
    • Edge
    • Elements Browser
    • Epic Privacy Browser
    • Firefox
    • Iridium
    • K-Melon
    • Kometa
    • liebao
    • Maxthon3
    • NetboxBrowser
    • Nichrome
    • Opera
    • Opera GX
    • Orbitum
    • Pale Moon
    • QIP SURF
    • SeaMonkey
    • Sleipnir5
    • Sputnik
    • Torch
    • UCozMedia
    • Uran
    • Vivaldi
    • Waterfox
    • Yandex
  • It exfiltrates data found on the following applications:
    • Discord
    • DiscordCanary
    • DiscordPTB
    • DiscordDevelopment
    • NVIDIA GeForce Experience
    • OpenVPN Connect
    • Telegram Desktop
  • It exfiltrates data on the following crypto wallets:
    • Anoncoin
    • Armory
    • Atomic
    • BBQCoin
    • Bitcoin
    • Coinomi
    • Daedalus Mainnet
    • DashCore
    • devcoin
    • digitalcoin
    • Dogecoin
    • ElectronCash
    • Electrum
    • Electrum-LTC
    • Ethereum
    • Exodus
    • Florincoin
    • Franko
    • Freicoin
    • GoldCoin (GLD)
    • Guarda
    • Infinitecoin
    • IOCoin
    • Ixcoin
    • Ledger Live
    • Liberty Jaxx
    • Litecoin
    • Megacoin
    • Mincoin
    • Monero
    • Namecoin
    • Primecoin
    • Reddcoin
    • Terracoin
    • WalletWasabi
    • YACoin
    • Zcash
  • It exfiltrates the following browser wallet extensions and 2FA appilications:
    • Authenticator
      • bhghoamapcdpbohphigoooaddinpkbai
    • Metamask
      • nkbihfbeogaeaoehlefnkodbefgpgknn
    • Jaxx Liberty Extension
      • cjelfplplebdjjenllpjcblmjkfcffne
    • iWallet
      • kncchdigobghenbbaddojjnnaogfppfj
    • BitAppWallet
      • fihkakfobkmkjojpchpfgcmhfjnmnfpi
    • SaturnWallet
      • nkddgncdjgjfcddamfgcmfnlhccnimig
    • Guildwallet
      • nanjmdknhkinifnkgdcggcfnhdaammmj
    • MewCX
      • nlbmnnijcnlegkjjpcfjclmcfggfefdm
    • Wombat
      • amkmjjmmflddogmhpjloimipbofnfjih
    • CloverWallet
      • nhnkbkgjikgcigadomkphalanndcapjk
    • NeoLine
      • cphhlgmgameodnhkjdmkpanlelnlohao
    • RoninWallet
      • fnjhmkhhmkbjkkabndcnnogagogbneec
    • LiqualityWallet
      • kpfopkelmapcoipemfendmdcghnegimn
    • EQUALWallet
      • blnieiiffboillknjnepogjhkgnoapac
    • Guarda
      • hpglfhgfnhbgpjdenjgmdgoeiappafln
    • Coinbase
      • hnfanknocfeofbddgcijnmhnfnkdnaad
    • NiftyWallet
      • jbdaocneiiinmjbjlgalhcelgbejmnid
    • Yoroi
      • ffnbelfdoeiohenkjibnmadjiehjhajb
    • BinanceChainWallet
      • fhbohimaelbohpjbbldcngcnapndodjp
    • TronLink
      • ibnejdfjmmkpcnlpebklmnkoeoihofec
    • Phantom
      • bfnaelmomeimhlpmgjnjophhpkkoljpa
    • Oxygen
      • fhilaheimglignddkjgofkcbgekhenbh
    • PaliWallet
      • mgffkfbidihjpoaomajlbgchddlicgpn
    • Bolt X
      • aodkkagnadcbobfpggfnjeongemjbjca
    • ForboleX
      • fmblappgoiilbgafhjklehhfifbdocee
    • XDEFI Wallet
      • hmeobnfnfcmdkdcmlblgagmfpfboieaf
    • Maiar DeFi Wallet
      • dngmlblcodfobpdpecaadgfbcggfjfnm
    • KardiaChain
      • pdadjkfkgcafgbceimcpbkalnfnepbnk
    • coin98
      • aeachknmefphepccionboohckonoeemg
    • Terra
      • aiifbnbfobpmeekipheeijimdpnlpgpp
    • Harmony
      • fnnegphlobjdpkhecapkijjdkgcjhkib
    • Nami
      • lpfcbjknijpeeillifnkikgncikgfhdo
    • Exodus_E
      • aholpfdialjgjfhomihkjbmgjidlcdno
    • MathWallet
      • afbcbjpbpfadlkmhmclhkeeodmamcflc
    • Keplr
      • dmkamcknogkgcdfhhbddcghachkejeap
    • Sollet
      • fhmfendgdocmcbmfikdcogofphimnkno
    • AuroWallet
      • cnmamaachppnkjgnildpdmkaakejnhae
    • PolymeshWallet
      • jojhfeoedkpkglbfimdfabpdfjaoolaf
    • ICONex
      • flpiciilemghbmfalicajoolhkkenfel
    • EVER Wallet
      • cgeeodpfagjceefieflmdfphplkenlfk
    • Rabby
      • acmacodkjbdgmoleebolmdjonilkdbch
    • BraveWallet
      • odbfpeeihdkbihmopkbjmoonfanlbfcl
    • WavesKeeper
      • lpilbniiabackdjcionkobglmddfbcjo
    • Solflare
      • bhhhlbepdkbapadjdnnojkbgioiodbic
    • CyanoWallet
      • dkdedlpgdmmkkfjabffeganieamfklkm
    • KHC
      • hcflpincpppdclinealmandijcmnkbgn
    • TezBox
      • mnfifefkajgofkcjkemidiaecocnkjeh
    • Temple
      • ookjlbkiijinhpmnjffcofjonbfbgaoc
    • Goby
      • jnkelfanjkeadonecabehalmbgpfodjm
    • Braavos wallet
      • jnlgamecbpmbajjfhmmmlhejkemejdma
    • Eth and Polk Web3 Wallet
      • kkpllkodjeloidieedojogacfhpaihoh
    • OKX Wallet
      • mcohilncbfahbmgdjkbpemcciiolgcge
    • Sender Wallet
      • epapihdplajcdnnkdeiahlgigofloibg
    • Hashpack
      • gjagmgiddbbciopjhllkdnddhcglnemk
    • Eternl
      • kmhcihpebfmpgmihbkipmjlmmioameka
    • GeroWallet
      • bgpipimickeadkjlklgciifhnalhdjhe
    • Pontem Aptos Wallet
      • phkbamefinggmakgklpkljjmgibohnba
    • Petra Aptos Wallet
      • ejjladinnckdgjemekebdpeokbikhfci
    • Opera Wallet
      • gojhcdgcpbpfigcaejpfhfegekdgiblk
    • EMartian Aptos Wallet
      • efbglgofoippbgcjepnhiblaibcnclgk
    • Finnie
      • cjmkndjhnagcfbpiemnkdpomccnjblmj
    • Leap Terra Wallet
      • aijcbedoijmgnlmjeegjaglmepbmpkpi
    • Trust Wallet
      • egjidjbpglichdcondbcbdnbeeppgdph
    • Magic Eden Wallet
      • mkpegjkblkkefacfnmkajcjmabijhclg
    • Backpack
      • aflkmfhebedbjioipglgcbcmnbpgliof
    • MetaMask Edge
      • ejbalbakoplchlghecdalmeeeajnimhm
    • Venom
      • ojggmchlghnjlapmfbnjholfjkiidbch
    • Sui
      • opcgpfmipidbgpenhmajoajpbobppdil
    • Fewcha
      • ebfidpplhabeedpnhjnobghokpiioolj
    • Core
      • agoakfejjabomempkjlepdflaleeobhb
    • Tokenpocket
      • mfgccjchihfkkindfppnaooecgfneiii
    • Safepal
      • lgmpcpglpngdoalbgeoldeajfclnhafa
    • Kaikas
      • jblndlipeogpafnldhgmapagcccfchpi
    • XMR.PT
      • eigblbgjknlfbajkfhopmcojidlgcehm
    • Goblin Wallet
      • ghpilmjholiicaobfjdkefcogmgaabif
    • EOS Authenticator
      • oeljdldpnmdbchonielidgobddffflal
    • GAuth Authenticator
      • ilgcnhelpchnceeipipijaljkblbcobl
    • Trezor Password Manager
      • imloifkgjagghnncjkhggdhalmcnfklk
    • MYKI
      • bmikpgodpkclnkgmnpphehdgcimmided
    • Splikity
      • jhfjfclepacoldmjmkmdlmganfaalklb
    • CommonKey
      • chgfefjpcobfbnpmiokfjjaglahmnded
    • Zoho Vault
      • igkpcodhieompeloncfnbekccinhapdb
    • Norton Password Manager
      • admmjipmmciaobhojoghlmleefbicajg
    • Avira Password Manager
      • caljgklbbfbcjjanaijlacgncafpegll
  • It exfiltrates user credentials found on the following email clients:
    • Outlook
    • Thunderbird
  • It exfiltrates user credentials found on the following gaming applications:
    • Battle.net
    • FeatherCLient
    • Growtopia
    • LunarClient
    • Minecraft
    • Steam
    • TLauncher
  • It exfiltrates user credentials found on the following messaging clients:
    • Element
    • ICQ
    • Pidgin
    • Skype
    • Tox
  • It exfiltrates user data found on the following FTP clients:
    • FileZilla
    • TotalCommander

It adds the following scheduled tasks:

    • Name: MPGPH131 HR
    • Trigger: 1 hour after scheduled task creation (After triggered, repeat every1 hour indefinitely)
    • Action: %All Users Profile%\MPGPH131\MPGPH131.exe
    • Name: MPGPH131 LG
    • Trigger: At log on of any user
    • Action: %All Users Profile%\MPGPH131\MPGPH131.exe

(Note: %All Users Profile% is the common user's profile folder, which is usually C:\Documents and Settings\All Users on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\ProgramData on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit). )

NOTES:

It does not exploit any vulnerability.

  SOLUTION

Minimum Scan Engine:

9.800

FIRST VSAPI PATTERN FILE:

19.272.04

FIRST VSAPI PATTERN DATE:

11 Apr 2024

VSAPI OPR PATTERN File:

19.273.00

VSAPI OPR PATTERN Date:

12 Apr 2024

Step 1

Trend Micro Predictive Machine Learning detects and blocks malware at the first sign of its existence, before it executes on your system. When enabled, your Trend Micro product detects this malware under the following machine learning name:

    • Troj.Win32.TRX.XXPE50FFF079

Step 2

Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.

Step 3

Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.

Step 4

Restart in Safe Mode

[ Learn More ]

Step 5

Deleting Scheduled Tasks while in Safe Mode

  1. Still in safe mode, the following {Task Name}-{Task to be run} listed should be used in the steps identified below:
    • Task name: MPGPH131 HR
    • Task to be run: %All Users Profile%\MPGPH131\MPGPH131.exe
    • Task name: MPGPH131 LG
    • Task to be run: %All Users Profile%\MPGPH131\MPGPH131.exe
  2. For Windows 7 and Server 2008 (R2) users, click Start>Computer.
    • For Windows 8, 8.1, 10, and Server 2012 users, right-click on the lower left corner of the screen, then click File Explorer.
  3. In the Search Computer/This PC input box, type:
    • %System%\Tasks\{Task Name}
  4. Once located, select the file then press SHIFT+DELETE to delete it.
  5. Open Registry Editor. To do this:
    • For Windows 7 and Server 2008 (R2) users, click the Start button, type regedit in the Search input field, and press Enter.
    • For Windows 8, 8.1, 10, and Server 2012 (R2) users, right-click on the lower left corner of the screen, click Run, type regedit in the text box
  6. In the left panel of the Registry Editor window, double-click the following:
    • HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows NT>CurrentVersion>Schedule>TaskCache>Tree>{Task Name}
  7. Locate the created entry and take note of the registry value's data:
    • ID={Task Data}
  8. After taking note of the data, delete the registry key:
    • HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows NT>CurrentVersion>Schedule>TaskCache>Tree>{Task Name}
  9. In the left panel of the Registry Editor window, double-click the following:
    • HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows NT>CurrentVersion>Schedule>TaskCache>Tasks
  10. Still in the left panel, locate and delete the registry key with the same name as the located Task Data in step #6:
    • ={Task Data}
  11. Close Registry Editor.

Step 6

Delete this registry value

[ Learn More ]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • RageMP131 = %AppDataLocal%\RageMP131\RageMP131.exe

Step 7

Search and delete these files

[ Learn More ]
There may be some files that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.
  • %User Temp%\adobe{12 Random Characters}\Autofill\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\CC\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\Cookies\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\Downloads\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\Google Accounts\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\information.txt
  • %User Temp%\adobe{12 Random Characters}\passwords.txt
  • %User Temp%\adobe{12 Random Characters}\Plugins\{Web Browser Name}_Default.txt
  • %User Temp%\adobe{12 Random Characters}\screenshot.png
  • %User Temp%\adobe{12 Random Characters}\Wallets\{Web Browser Name}_Default.txt
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Cookies
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}History
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Login Data
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Web Data
  • %User Temp%\rage131MP.tmp
  • %User Temp%\{23 Random Characters}.zip

Step 8

Search and delete these folders

[ Learn More ]
Please make sure you check the Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden folders in the search result.  
  • %All Users Profile%\MPGPH131
  • %AppDataLocal%\RageMP131
  • %User Temp%\adobe{12 Random Characters}\Autofill
  • %User Temp%\adobe{12 Random Characters}\CC
  • %User Temp%\adobe{12 Random Characters}\Cookies
  • %User Temp%\adobe{12 Random Characters}\Downloads
  • %User Temp%\adobe{12 Random Characters}\FTP\FileZilla
  • %User Temp%\adobe{12 Random Characters}\FTP\TotalCommander
  • %User Temp%\adobe{12 Random Characters}\FTP
  • %User Temp%\adobe{12 Random Characters}\Games\Battle.net
  • %User Temp%\adobe{12 Random Characters}\Games\FeatherClient
  • %User Temp%\adobe{12 Random Characters}\Games\Growtopia
  • %User Temp%\adobe{12 Random Characters}\Games\LunarClient
  • %User Temp%\adobe{12 Random Characters}\Games\Minecraft
  • %User Temp%\adobe{12 Random Characters}\Games\Steam
  • %User Temp%\adobe{12 Random Characters}\Games\TLauncher
  • %User Temp%\adobe{12 Random Characters}\Games
  • %User Temp%\adobe{12 Random Characters}\Google Accounts
  • %User Temp%\adobe{12 Random Characters}\Messengers\Element
  • %User Temp%\adobe{12 Random Characters}\Messengers\ICQ
  • %User Temp%\adobe{12 Random Characters}\Messengers\Pidgin
  • %User Temp%\adobe{12 Random Characters}\Messengers\Signal
  • %User Temp%\adobe{12 Random Characters}\Messengers\Skype
  • %User Temp%\adobe{12 Random Characters}\Messengers\Tox
  • %User Temp%\adobe{12 Random Characters}\Messengers
  • %User Temp%\adobe{12 Random Characters}\Plugins
  • %User Temp%\adobe{12 Random Characters}\VPN\OpenVPN Connect
  • %User Temp%\adobe{12 Random Characters}\VPN
  • %User Temp%\adobe{12 Random Characters}\Wallets
  • %User Temp%\adobe{12 Random Characters}
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Cookies
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}History
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Login Data
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Login Data For Account
  • %User Temp%\heidi{12 Random Characters}\{12 Random Characters}Web Data
  • %User Temp%\heidi{12 Random Characters}

Step 9

Restart in normal mode and scan your computer with your Trend Micro product for files detected as TrojanSpy.Win32.RISEPRO.C. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.


Did this description help? Tell us how we did.