TROJ_RIMECUD.XDR
Windows
Threat Type:
Trojan
Destructiveness:
No
Encrypted:
In the wild::
Yes
OVERVIEW
Elimina archivos para impedir la ejecución correcta de programas y aplicaciones.
TECHNICAL DETAILS
Otras modificaciones del sistema
Elimina los archivos siguientes:
- À_þ_CHAR(0x07)_TÕ_CHAR(0x07)_Á¨_CHAR(0x07)_[þ2C3â'âÝʨ
- ÜF#_ßGyìÜá_v_þä_ÕG(GÞG×Gó«5 o&_CHAR(0x06)_#_qÜä_§ßG?ü¡v_þkÕ?é¡ä_Õª²ä_òv_q_CHAR(0x1C)_Þä_Õòv_þûóû
- 9C^_CHAR(0x19)_+ê_CHAR(0x04)__CHAR(0x12)_ÜÝøðÉÊ_CHAR(0x03)_êoj«âæ2÷ª_CHAR(0x1C)__CHAR(0x12)_xâv_CHAR(0x03)_»P)~#ë`_CHAR(0x12)_÷øA_CHAR(0x07)_ÔMv(:4ÉâêÇ_CHAR(0x0E)_ÃêM+M2XbY«22\#ë`_CHAR(0x12)_÷ø iëîY«2%ÆïûöHR%_CHAR(0x04)_ÌÚ2Mv«Â¦_CHAR(0x05)_Pè?×3æò9=XêM.5êÜáζc_CHAR(0x01)__CHAR(0x1B)_ø=XêRs«Â_CHAR(0x12)__CHAR(0x0B)_d¼«Z3æ2÷#_CHAR(0x01)_õðÉ̸_CHAR(0x1C)_«âê\Ç_CHAR(0x0F)_c_CHAR(0x01)_´ø=X_(¥«4?~9jý=x_CHAR(0x04)_ä~ºM2MRvd1Ý+_CHAR(0x1B)_qa½_CHAR(0x16)__CHAR(0x12)__CHAR(0x04)_+_CHAR(0x0F)_¶6cØ2pèi×3æÝ9ô=Xê;v(ÈÉÅ«
- Âp9CÕicwf4°c_CHAR(0x0F)_ý¼×#\Tþj2\`ûâÝÂÈ Mv½{ê9M¹ +_CHAR(0x13)__CHAR(0x07)_¾!__CHAR(0x17)_~«_CHAR(0x04)_voµ&v×ù½¦_CHAR(0x04)_+T_CHAR(0x02)_Cð)'J$_CHAR(0x14)_oj_CHAR(0x1B)_¸=´¨(2T_CHAR(0x02)_C5¶ð:µ&v_u¥×_CHAR(0x04)_É_CHAR(0x13)_Õ¾oê[桸_ß_CHAR(0x12)__CHAR(0x04)_+Mê~+_CHAR(0x0C)__CHAR(0x07)_ס_CHAR(0x04)_Õ_CHAR(0x1F)__CHAR(0x12)_çw´ge×oØ«+ÌM¥æ2%É÷jéRoèojËB#BµÕQH~G_CHAR(0x04)_+䢦ϪU°#BÝ_CHAR(0x1F)_;=o_CHAR(0x13)_X2±¦oj2_CHAR(0x19)_iÝí;M¬2Mv_CHAR(0x0F)_4ªp:§¡=xç,EÉ¢_CHAR(0x01)_oy$_CHAR(0x1F)_t
- ÜáΫþâæ2ñ¤´ÉêXvWôA_CHAR(0x0F)_àÍÛ_CHAR(0x12)_Hc_CHAR(0x01)_=X=X_(äÉÊ@voµè3÷3æ2¡_CHAR(0x19)_HôSXð²À]T_CHAR(0x16)_3êö`_CHAR(0x0B)__CHAR(0x12)_÷ø=oгå½ùðþ6_CHAR(0x1B)__CHAR(0x03)_×3ì×_CHAR(0x04)__CHAR(0x12)_ÜøðÉ2üZâê_CHAR(0x06)_2-Ô_CHAR(0x04)_ÉÜÀøðÉÚ×_CHAR(0x03)_B_CHAR(0x03)_\_CHAR(0x12)_=×ø=XÝ_CHAR(0x07)_±iË2÷*_CHAR(0x0C)_èo66ê_CHAR(0x04)__CHAR(0x12)_Ü÷øðÉ2SÌ(°K\_CHAR(0x12)_ë_CHAR(0x1C)_¾9®+M2XbG«2AoàQ[_CHAR(0x12)_H/\»öRM2ëcÞ«2Ü:êzjêäµÖÉêXð)IJð8«â¶Ýcp_CHAR(0x08)_×ø=1BúÉêUg´ê«þâæ2ä_CHAR(0x1D)_¹1¬+Öã
- 2:÷¾5¨N
- ??????????????????????????????????????
- ???????????????????????????????????????????????????????????????????????????????????????????????????????????????? ???????????????????????????????????????????????????????????????????????????????????????????8????????????????????????????????????????????????????????
- _CHAR(0x14)_]ð2:}£*ª_CHAR(0x03)_o¬e_CHAR(0x19)_içWÜÆ·Évj«(#\US9CMÊHíaø¥Çä©ðù鱪_CHAR(0x03)_#ø\=®_CHAR(0x13)__CHAR(0x04)_ _CHAR(0x06)_÷Mð_CHAR(0x0F)_eJ²_CHAR(0x03)_«â¦¡\_CHAR(0x04)_Õw_CHAR(0x13)_6 ê®ö¶(á'_CHAR(0x1B)_¶=C÷¨s1¢2vof4ª_CHAR(0x12)_/ø×}Ýîõ+Mõ¾U¾M·¦Ï[µ2ÕiÝjáñ_CHAR(0x03)_M_CHAR(0x0F)_=d(êk¼E´_CHAR(0x12)_Hèw_CHAR(0x04)__CHAR(0x16)_î_CHAR(0x1F)_eø²Ïv zö¢_sç'Xw´gX2_CHAR(0x15)_«oj2âæ2¨sð3_CHAR(0x02)_'(ê4U«+'_CHAR(0x19)_içæ_CHAR(0x0C)_å4°ö_CHAR(0x17)_p_CHAR(0x01)_vê÷ÝX2fö¶_CHAR(0x1C)_}ø¾¶ê+åHÔöÝíÆ
- ????????????????????????????????????????????????????????????????????????????????????????????????????????????+???????????????????????¦????????????????????????????£?????????(???????????????????£?????????????????????????????????????????????????????????????????????
- ???????????????????????????£?????????????????????u???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????¬???????????????????????????????????????????????????????????????????
- è
- ??????????????????
- ³?³?³?³?³?³?³?³?³?³?Ç?Ç?Ç?Ç?Ç?Ç
- ????????????????????????????????????????????????????????????????????????????h???F?????
- ±¥ Sz¾_CHAR(0x16)_`±À¾0?_CHAR(0x14)_?ú
- è
- ÔÃ_CHAR(0x1A)_@ÅeI\#¾)øq_CHAR(0x0B)_:nsæsÂJ_CHAR(0x16)_ù_CHAR(0x17)__CHAR(0x03)_ºø(V_CHAR(0x04)_A(26r_CHAR(0x15)_çâ8._CHAR(0x06)_3¯Aÿʧr3MvR#e_CHAR(0x0E)_£z_Qô_CHAR(0x14)_~åM_CHAR(0x05)_'ùf_CHAR(0x0E)_Q&èEÖ]Ï~¤Ð¹gøaµ9ûÂÅ©H2²þÉ^º»æGM©@Y®vêßÑÚ6_CHAR(0x10)_xØpQôÝåM_CHAR(0x05)_'ùf_CHAR(0x0E)_Q&èEÖ]ÏM¤°_i8(Ìð%\M×ÔH%_CHAR(0x17)_t¥Ksè÷à¬òÅK÷[_CHAR(0x12)_3jùõjW/_CHAR(0x03)_MÇ2yTo}¥YÒÇ¢Z:E¯_CHAR(0x06)_Ìáª_CHAR(0x07)_åË÷[_CHAR(0x12)_øu_CHAR(0x0E)__CHAR(0x16)__CHAR(0x13)__CHAR(0x04)_2`M_CHAR(0x1B)__CHAR(0x12)_yToGøÕæ¶CêÖ_CHAR(0x1C)_
- ?
- ????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????L???????????????????t?????????t??????????????????????????????????????????????????
- ??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????-?????????
- ¸\`ì¥g,L¬_cº\e1j_CHAR(0x03)_ÕiãæålðcêXgT4ª~_CHAR(0x12)__CHAR(0x10)_2²j¾.÷Íç½22ðÉÄI_CHAR(0x03)_êêf¸3(c÷ÍXwÚg_CHAR(0x03)_Mª£_CHAR(0x12)_×3èwêÁûXw2g_CHAR(0x03)_Mª£â˾ÕÀê6°î®_CHAR(0x07)_vÉ$¥·ñâê_CHAR(0x19)_iÝó_CHAR(0x16)_º+:_ñö}_CHAR(0x18)_4ªÌÔÌ_CHAR(0x19)_iðW_CHAR(0x1F)_¨sÚT_CHAR(0x02)_@g54ªP2_CHAR(0x19)_iÉêµlG· jé¿#\S~9ÂHêäsÚT:´(rðs(9'_CHAR(0x19)__CHAR(0x12)__CHAR(0x1C)_~äõÚ Ä«j±_CHAR(0x15)_oj2_CHAR(0x19)_iTcê;_CHAR(0x1D)_w_CHAR(0x1C)_'ë¼+Ú×L_CHAR(0x03)_¼Pø_CHAR(0x10)_ÖÏêÊ&T_CHAR(0x02)_R2%áX.
- ?????????????????????????????????????
- N_CHAR(0x19)_ìN^Ñ(N_CHAR(0x19)_ì^UßËßRÕé{X777_CHAR(0x02)_&Ú:7_öAäl
- ?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
- ???7
- ?????????????????????????????????????????????????????????????????????????????????????????????????????????¬???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????_CHAR(0x08)_???????
- ?????????????????????????????????????????_???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????£??????????????????????????????????????????????????????????????????i????????????????????
- N^N^N^N^N^N^N^^^
- ????????
- ???????????????????l?????????????????????????
- ·@ÂÒºÚjH_CHAR(0x04)_MêðæÎçAï]r_CHAR(0x0F)_ÐVÖg´_CHAR(0x1F)_i_CHAR(0x0C)_ôÑʹÔFKÜ5÷_CHAR(0x01)_à-IG}+_CHAR(0x03)_e_CHAR(0x18)_ó¿ûÞÍÄEtB©õ§ _CHAR(0x1D)_(×y_CHAR(0x17)_sUË_CHAR(0x06)_xY&o)¼R¢w:_CHAR(0x02)_£7%%_CHAR(0x16)__CHAR(0x16)_WW
- ???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????+??????????????????????????????????????»???????????????????????????????????????»?????????
- ??
- ??????????????????????????????????????????????????????????????????????????????????)?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????´??????????????????_?????????????????????????????????
Elimina las carpetas siguientes:
- _CHAR(0x14)_z¾S¯±L¾Sz±W L?z±SLz±*L_CHAR(0x14)_#`#¤¸
- °_CHAR(0x12)_EJUCcåïÔÚkjÜ.öç_CHAR(0x16)_ŧêËÊsè_CHAR(0x18)_[Ð]ñ/øê-_CHAR(0x12)_oà(q_CHAR(0x04)_ì§¼çM¼bzo_CHAR(0x03)_óÌåH:×VB_CHAR(0x18)_Mó_CHAR(0x1D)_F_CHAR(0x16)_Vi_CHAR(0x18)__CHAR(0x16)_Öe~_CHAR(0x0C)_iG!ÝsLX½T~ö@ó³ KÎ_CHAR(0x18)__CHAR(0x0F)_óÛkwLVMMÍjX$+esYo°(ªðÍ×XÐ_CHAR(0x06)_yUDС;êáLÐ'7ýο(å&o KÎ_CHAR(0x18)__CHAR(0x0F)_ów:Mnýο(å&o KÎ_CHAR(0x18)__CHAR(0x0F)_óÛk¢L2Î_CHAR(0x18)_ðÛAX$©'µÉÒ3L_CHAR(0x12)__CHAR(0x03)__CHAR(0x1D)__CHAR(0x05)_sU~Ùö_CHAR(0x16)_¨oAêðo_CHAR(0x1B)_[HÚ+M2_CHAR(0x04)_v( j+j2\uÎê_CHAR(0x04)_+éOMv_CHAR(0x03)_÷êø_CHAR(0x13)_j2
- è~M2Mµiê¦Ï\_CHAR(0x14)_ _CHAR(0x05)_´(êäsM3'¥ê¦Ï\_CHAR(0x14)_ ?J(êäsM3'ÑNê¦Ï\_CHAR(0x14)_ °¦êäsM3'¿£_CHAR(0x02)_ê¦Ï\_CHAR(0x14)_ zÎêäsM3'_CHAR(0x03)_âiê¦Ï\_CHAR(0x14)__CHAR(0x12)__CHAR(0x13)__CHAR(0x12)_H°ý_CHAR(0x04)_+T_CHAR(0x02)_'ÖRý:oµøsÈ_CHAR(0x12)_ê_CHAR(0x04)_Å2Mg_CHAR(0x13)__CHAR(0x16)_¶üoj2~oH%ÆáÅ_CHAR(0x07)_äMv(:{9PÇ_CHAR(0x0E)__CHAR(0x1C)_ê7KM2ë¼=oj_CHAR(0x16)_._CHAR(0x12)_HcwðL½b2MvúÅêÜá¥V_CHAR(0x13)_^Hê§_CHAR(0x1A)_+M__CHAR(0x17)_p_CHAR(0x10)_üo_CHAR(0x12)_F\_CHAR(0x12)_=xè~M2MãÂê¦Ï\_CHAR(0x14)__CHAR(0x12)_ä_CHAR(0x12)_Hi_CHAR(0x04)_+T_CHAR(0x02)_'Ö5Áê`2\#BÌÝ
- l
- t½Ô/¸o6Ì^Åwv§²v0ßo¤Ù¾_CHAR(0x06)_5_©î¶m**ùÑAå bqÓXÍ._CHAR(0x04)_ [ÜQDKÌßS_CHAR(0x05)_Õ9½)Í_CHAR(0x0C)_È ÷aH_CHAR(0x03)_Mý~5kã_CHAR(0x14)_G2\ÆjêÕ@+M8Mv(Áçj2/ùH ½_CHAR(0x04)_+?gMvÖwêСj2äNHÔ{_CHAR(0x04)_+qMv(oð[zH2s¼j0°M+)Ý_CHAR(0x04)_v¬jð_CHAR(0x1E)_íH2{jÞM+_CHAR(0x15)__CHAR(0x04)_vSð_CHAR(0x16)_Ùº2ÒïÚ@_CHAR(0x06)_ê+Øðv_CHAR(0x08)_P_CHAR(0x04)_ÊEÚ2^ôºOßð+()vQ¶Îº_CHAR(0x1C)_Â2Ú?Ò_CHAR(0x1C)_úæ+WgvպβõÂ2Ò9ëæ+¿sv
- 77
SOLUTION
Step 1
Los usuarios de Windows ME y XP, antes de llevar a cabo cualquier exploración, deben comprobar que tienen desactivada la opción Restaurar sistema para permitir la exploración completa del equipo.
Step 2
Explorar el equipo con su producto de Trend Micro para eliminar los archivos detectados como TROJ_RIMECUD.XDR En caso de que el producto de Trend Micro ya haya limpiado, eliminado o puesto en cuarentena los archivos detectados, no serán necesarios más pasos. Puede optar simplemente por eliminar los archivos en cuarentena. Consulte esta página de Base de conocimientos para obtener más información.
Did this description help? Tell us how we did.