Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
moga cuf gosesam = I can bloom bossom in blulgarian
Its weird like a semi gibberish
Pakogeni - packaged?
logetoca - logic, computer
sedetare - romanian, latin based lang?
tepehod - tepe - warm? hod - to move? (steam?)
99.9% sure its a virus.
And its probably new. or your just REALLY unlucky. and its rare.
https://pastebin.com/UhtpGpmT
I'm not certain if my posting this is allowed or not, so apologies if I'm breaking a rule by putting that up here.
It doesn't have one, it's just referred to as "File".
The escaped code is the real stuff, for example:
%46%75%6E%63%74%69%6F%6E%20%57%72%69%74%65%52%65%67%28%52%65%67%50%61%74%68%2C%20%56%61%6C%75%65%2C%20%52%65%67%54%79%70%65%29%3A%4F%6E%20%45%72%
Means...
Function WriteReg(RegPath, Value, RegType):On Er%
It's a function for writing into your Windows registry and adding itself to your Windows startup.
It creates: %53%63%72%69%70%74%43%6F%6E%74%72%6F%6C
Which is "ScriptControl"
Using: %56%42%53%63%72%69%70%74
Which is "VBScript" (Visual Basic programming language)
Then creates a folder: C:\Users\User\AppData\Roaming\500D7A~1\synhelpe%
With a file: Rifalegab.Exec
and Executes WScript.Shell (a run commend upon it)
Then there's more random comment filler at the end.
Thanks for telling me about that folder, I just checked it out and found something called synhelper.exe. Checked it out online, and it turns out it's associated with some kind of ransomware?
Thank god I removed it before anything happened, ransomware sucks big time.
You are correct.
"syntphelper.exe" is a SynTPHelper Application belonging to Synaptics Pointing Device Driver from Synaptics, Inc.
"synhelper.exe" is a faked malware posing as that, one which is commonly known as "Cerber Ransomware". This slowly encrypts your entire hard drive files over time and demands payment to get them decrypted. It uses AES-265 and RSA encryption method, making it impossible to decrypt at this time without the key from them.
Check your document files .DOC, etc, and ensure none have double extentions. If you notice this, consider running a Windows system restore if available to roll back.
Suggest you check your entire system with Spybot or similar anti-malware:
https://www.safer-networking.org/mirrors24/