Windows defender shows CryptoExtortBTC.A - Virus, Trojan, Spyware, and Malware Removal Help
Common Information
Type Value
UUID e9369077-a6b9-4c62-bef9-7e7d5d9da097
Fingerprint 37540a22fe8e8ec7
Analysis status DONE
Considered CTI value 1
Text language
Published March 8, 2023, 7:48 a.m.
Added to db March 8, 2023, 4:23 p.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline Windows defender shows CryptoExtortBTC.A
Title Windows defender shows CryptoExtortBTC.A - Virus, Trojan, Spyware, and Malware Removal Help
Detected Hints/Tags/Attributes 83/2/278
Attributes
Details Type #Events CTI Value
Details File 1
c:\windows\system32\dtsgaincompensatordll64.dll
Details File 1
c:\windows\system32\hifidax2apipcll.dll
Details File 1
c:\windows\system32\hmapo.dll
Details File 1
c:\windows\system32\hmclarifi.dll
Details File 1
c:\windows\system32\dtsgfxapo64.dll
Details File 1
c:\windows\system32\dtslfxapo64.dll
Details File 1
c:\windows\system32\dtsgfxapons64.dll
Details File 1
c:\windows\system32\hmhvs.dll
Details File 1
c:\windows\system32\hmeq_voice.dll
Details File 1
c:\windows\system32\hmeq.dll
Details File 1
c:\windows\system32\hmlimiter.dll
Details File 3
c:\windows\system32\rtpgex64.dll
Details File 1
c:\windows\system32\dolbydax2apov201.dll
Details File 3
c:\windows\system32\ddpd64a.dll
Details File 1
c:\windows\system32\ddpd64af3.dll
Details File 1
c:\windows\system32\dax3apoprop.dll
Details File 1
c:\windows\system32\dax3apov251.dll
Details File 1
c:\windows\system32\ddpo64af3.dll
Details File 3
c:\windows\system32\ddpo64a.dll
Details File 1
c:\windows\system32\ddpa64f3.dll
Details File 3
c:\windows\system32\ddpa64.dll
Details File 1
c:\windows\system32\slprp64.dll
Details File 3
c:\windows\system32\r4eep64a.dll
Details File 3
c:\windows\system32\ddpp64a.dll
Details File 1
c:\windows\system32\ddpp64af3.dll
Details File 3
c:\windows\system32\rcoinstii64.dll
Details File 3
c:\windows\system32\dolbydax2apoprop.dll
Details File 1
c:\windows\system32\hmui.dll
Details File 3
c:\windows\system32\hifidax2api.dll
Details File 1
c:\windows\system32\harmanaudiointerface.dll
Details File 3
c:\windows\system32\coneqmsapoguilibrary.dll
Details File 1
c:\windows\system32\acpiservicevna64.dll
Details File 1
c:\windows\system32\audiolibvc.dll
Details File 1
c:\users\you have\downloads\addition.txt
Details File 1
c:\users\you have\downloads\frst.txt
Details File 1
c:\users\masz\downloads\frst64english.exe
Details File 1
c:\users\has\downloads\esetonlinescanner.exe
Details File 1
c:\users\has\downloads\sophosscanandclean_x64.exe
Details File 1
c:\programdata\sophos 2023-03-06 10:04 - 2023-03-06 10:04 - 000004032 _____ c:\windows\system32\tasks\postponedevicesetuptoast_s-1-5-21-1905558373-745742369-245519911-1001_8 2023-03-02 07:18 - 2023-03-02 07:18 - 000057890 _____ c:\users\has\downloads\fv_2023-03-02_07_17_41.pdf
Details File 1
c:\users\has\downloads\fv_2023-03-02_07_17_14.pdf
Details File 1
c:\users\has\downloads\fv_2023-03-02_07_15_55.pdf
Details File 1
c:\users\has\downloads\fv_2023-03-02_07_16_19.pdf
Details File 1
c:\users\your\downloads\fv_2023-02-17_09_48_21.pdf
Details File 1
c:\users\you have\intelgraphicsprofiles 2023-03-08 13:45 - 2020-10-22 14:29 - 001767980 _____ c:\windows\system32\perfstringbackup.ini
Details File 1
c:\windows\system32\perfh015.dat
Details File 1
c:\windows\system32\perfc015.dat
Details File 1
c:\windows\inf 2023-03-08 13:38 - 2020-10-22 14:38 - 000000006 ____h c:\windows\tasks\sa.dat
Details File 38
c:\dumpstack.log
Details File 2
c:\windows\syswow64\abbakconfig.dat
Details File 1
c:\windows\syswow64\winsevr.dat
Details File 1
c:\windows\system32\config\bbi 2023-03-08 12:58 - 2018-10-25 06:48 - 000000000 ____d c:\users\you\appdata\local\d3dscache 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ___rd c:\windows\immersivecontrolpanel 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ____d c:\windows\systemresources 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ____d c:\windows\system32\oobe 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ____d c:\windows\bcastdvr 2023-03-08 12:57 - 2019-12-07 10:14 - 000000000 ____d c:\windows\appreadiness 2023-03-08 12:52 - 2019-12-07 10:03 - 000000000 ____d c:\windows\cbstemp 2023-03-08 12:41 - 2017-07-17 08:10 - 000000000 ____d c:\windows\syswow64\rtcom 2023-03-08 11:50 - 2019-12-07 16:10 - 000000000 ____d c:\windows\system32\fxstmp 2023-03-08 11:50 - 2018-03-05 07:50 - 000000000 ____d c:\users\your\desktop\scan invoices 2023-03-08 11:43 - 2014-12-16 13:08 - 000000000 ____d c:\users\your\appdata\roaming\macrobase 2023-03-08 09:43 - 2017-06-07 07:14 - 000000000 ____d c:\programdata\aomeibr 2023-03-08 09:20 - 2017-06-07 07:14 - 000001024 ____h c:\systag.bin
Details File 1
c:\program files\windowsapps 2023-03-08 06:53 - 2020-10-22 14:38 - 000003566 _____ c:\windows\system32\tasks\microsoftedgeupdatetaskmachineua 2023-03-08 06:53 - 2020-10-22 14:38 - 000003442 _____ c:\windows\system32\tasks\microsoftedgeupdatetaskmachinecore 2023-03-07 08:59 - 2014-12-16 12:11 - 000187392 _____ c:\users\your\desktop\mail list.xls
Details File 59
c:\windows\system32\mrt.exe
Details File 1
c:\users\your\desktop\order zec.xls
Details File 1
c:\users\masz\desktop\sm attachment to rebates.xlsx
Details File 24
c:\windows\system32\fntcache.dat
Details File 54
c:\windows\syswow64\printconfig.dll
Details File 86
frst.txt
Details File 70
onedrivesetup.exe
Details File 8
c:\program files\windowsapps\microsoft.bin
Details File 18
c:\program files\windowsapps\microsoft.mpeg
Details File 4
c:\windows\system32\ole32.dll
Details File 38
x64.dll
Details File 9
c:\windows\system32\igfxdtcm.dll
Details File 1
vcomp.dll
Details File 3
c:\program files\microsoft office 15\root\vfs\programfilesx64\microsoft office\office15\ochelper.dll
Details File 3
c:\program files\microsoft office 15\root\vfs\programfilesx64\microsoft office\office15\grooveex.dll
Details File 3
c:\program files\microsoft office 15\root\office15\msosb.dll
Details File 24
c:\windows\web\wallpaper\windows\img0.jpg
Details File 1
c:\macrologic\system\jterm\miscw\jrew\bin\javaw.exe
Details File 1
c:\macrologic\system\jterm\ miscw\jrew\bin\javaw.exe
Details File 1
c:\windows\syswow64\javaw.exe
Details File 2
c:\program files\microsoft office 15\root\office15\outlook.exe
Details File 1
c:\merit\system\jterm\miscw\jrew\bin\javaw.exe
Details File 1
c:\merit\system\jterm\ miscw\jrew\bin\javaw.exe
Details File 87
skype.exe
Details File 76
msedgewebview2.exe
Details File 92
c:\windows\system32\svchost.exe
Details File 63
thunderbird.exe
Details File 1
c:\users\has\appdata\local\temp\ehdrv.sys
Details File 1
c:\users\you\appdata\roaming\10130.vbs
Details File 1
c:\users\have\appdata\roaming\1194.vbs
Details File 1
c:\users\have\appdata\roaming\1752.vbs
Details File 1
c:\users\have\appdata\roaming\1896.vbs
Details File 1
c:\users\have\appdata\roaming\9435.vbs
Details File 1
c:\users\have\appdata\roaming\9572.vbs
Details File 1
c:\users\you have\appdata\roaming\9784.vbs
Details File 1
c:\users\has\downloads\frst64.exe
Details File 1
c:\users\you have\appdata\roaming\9572.vbs
Details File 1
c:\users\you have\appdata\roaming\9435.vbs
Details File 1
c:\users\you have\appdata\roaming\1896.vbs
Details File 1
c:\users\you have\appdata\roaming\1752.vbs
Details File 1
com-1.pl
Details File 3
zaplata.jpeg
Details File 2
jpeg.exe
Details File 1
datils.zip
Details File 1
zubby.exe
Details File 1
detail.zip
Details File 1
zaplata_112020.jpeg
Details File 91
addition.txt
Details sha1 1
a1909296681c7acefe45687d3a64758c8659bf46
Details IPv4 1
156.17.24.240
Details IPv4 295
8.8.8.8
Details IPv4 63
8.8.4.4
Details IPv4 1
32.0.0.89
Details IPv4 2
1.31.8.1
Details IPv4 8
3.70.0.0
Details IPv4 6
8.91.0.0
Details IPv4 4
1.19.0.0
Details IPv4 619
0.0.0.0
Details IPv4 1
102.8.0.0
Details IPv4 3
10.1.1.38
Details Microsoft Patch Numbers 21
KB5001716
Details Url 1
https://www.google.pl
Details Url 1
https://www.garneczki.pl
Details Url 1
https://go.microsoft.com/fwlink/?linkid=37020&name=trojandownloader
Details Url 2
https://go.microsoft.com/fwlink/?linkid=37020&name=trojan:win32
Details Url 2
https://go.microsoft.com/fwlink/?linkid=37020&name
Details Windows Registry Key 68
HKLM\...\Run
Details Windows Registry Key 50
HKLM-x32\...\Run
Details Windows Registry Key 19
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Details Windows Registry Key 1
HKU\S-1-5-21-1905558373-745742369-245519911-1001\...\Run
Details Windows Registry Key 1
HKLM\...\Print\Monitors\423SeriesPCL-8
Details Windows Registry Key 1
HKLM\...\Print\Monitors\Panasonic
Details Windows Registry Key 1
HKLM\...\Print\Monitors\PDF-XChange5-ABBYY-FR
Details Windows Registry Key 1
HKU\S-1-5-21-1905558373-745742369-245519911-1001
Details Windows Registry Key 77
HKLM-x32
Details Windows Registry Key 18
HKLM-x32\...\Adobe
Details Windows Registry Key 1
HKLM-x32\...\MP
Details Windows Registry Key 1
HKLM-x32\...\e-Declarations.A1909296681C7ACEFE45687D3A64758C8659BF46.1
Details Windows Registry Key 6
HKLM\...\IrfanView64
Details Windows Registry Key 1
HKLM-x32\...\jTerm
Details Windows Registry Key 1
HKLM-x32\...\Macrologic
Details Windows Registry Key 68
HKLM-x32\...\Microsoft
Details Windows Registry Key 1
HKLM\...\HomeBusinessRetail
Details Windows Registry Key 1
HKU\S-1-5-21-1905558373-745742369-245519911-1001\...\OneDriveSetup.exe
Details Windows Registry Key 10
HKLM\...\Microsoft
Details Windows Registry Key 2
HKLM-x32\...\MozillaMaintenanceService
Details Windows Registry Key 5
HKLM-x32\...\Mozilla
Details Windows Registry Key 1
HKU\S-1-5-21-1905558373-745742369-245519911-1001\...\Opera
Details Windows Registry Key 3
HKLM-x32\...\WinLiveSuite
Details Windows Registry Key 19
HKLM-x32\...\InstallShield_
Details Windows Registry Key 1
HKU\S-1-5-21-1905558373-745742369-245519911-1001_Classes\CLSID
Details Windows Registry Key 41
HKLM\System\CurrentControlSet\Control\Session
Details Windows Registry Key 1
HKU\S-1-5-21-1905558373-745742369-245519911-1001\Control
Details Windows Registry Key 98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Details Windows Registry Key 42
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Details Windows Registry Key 30
HKLM\...\StartupApproved\Run32
Details Domain 285
microsoft.net
Details Domain 4
www.google.pl
Details Domain 1
www.garneczki.pl
Details Domain 368
microsoft.com
Details Domain 8
intel-webapi.intel.com
Details Domain 87
regid.1991-06.com.microsoft
Details Domain 9
king.com
Details Domain 50
microsoft.photos
Details Domain 64
go.microsoft.com
Details Domain 1
datils.zip
Details Domain 1
detail.zip
Details Domain 1
agenttesla.sm
Details File 1260
explorer.exe
Details File 128
msedge.exe
Details File 15
c:\program files\realtek\audio\hda\rtkngui64.exe
Details File 7
c:\windows\system32\igfxtray.exe
Details File 8
c:\windows\system32\igfxem.exe
Details File 8
c:\windows\system32\igfxhk.exe
Details File 1
dmwakeup.exe
Details File 1
pccmfsdm.exe
Details File 306
services.exe
Details File 1
networklicenseserver.exe
Details File 38
armsvc.exe
Details File 3
abservice.exe
Details File 41
jhi_service.exe
Details File 26
lms.exe
Details File 4
c:\program files\intel\icls client\heciserver.exe
Details File 9
c:\windows\system32\igfxcuiservice.exe
Details File 3
c:\program files\microsoft office 15\clientx64\officeclicktorun.exe
Details File 27
presentationfontcache.exe
Details File 198
msmpeng.exe
Details File 87
nissrv.exe
Details File 1
lmsrvnt.exe
Details File 1
trapmnnt.exe
Details File 1122
svchost.exe
Details File 12
cortana.exe
Details File 27
phoneexperiencehost.exe
Details File 23
c:\windows\system32\mousocoreworker.exe
Details File 67
c:\windows\system32\smartscreen.exe
Details File 14
c:\windows\syswow64\dllhost.exe
Details File 21
tiworker.exe
Details File 1
kmpcfax.exe
Details File 1
mfssecprt.exe
Details File 1
c:\windows\system32\koayfj_l.dll
Details File 1
c:\windows\system32\panewm64.dll
Details File 1
c:\windows\system32\zdglic36.dll
Details File 1
c:\windows\system32\pcmfsfxlmon.dll
Details File 1
c:\windows\system32\pxc50pmaf.dll
Details File 1
c:\users\masz\appdata\roaming\microsoft\windows\start menu\programs\startup\x.vbs
Details File 3
c:\program files\microsoft office 15\clientx64\officec2rclient.exe
Details File 1
c:\windows\browserchoice\browserchoice.exe
Details File 1
c:\windows\system32\autoworkplace.exe
Details File 42
adobearm.exe
Details File 99
c:\windows\explorer.exe
Details File 6
google.pl
Details File 1
garneczki.pl
Details File 6
npctrl.dll
Details File 19
c:\program files\adobe\acrobat dc\acrobat\air\nppdf32.dll
Details File 8
npintelwebapiipt.dll
Details File 8
npintelwebapiupdater.dll
Details File 3
c:\program files\microsoft office 15\root\office15\npspwrap.dll
Details File 3
npwlpg.dll
Details File 2
c:\windows\system32\ambakdrv.sys
Details File 2
c:\windows\system32\ammntdrv.sys
Details File 2
c:\windows\system32\amwrtdrv.sys
Details File 26
c:\windows\system32\drivers\btha2dp.sys
Details File 22
c:\windows\system32\drivers\bthhfenum.sys
Details File 39
mpksldrv.sys
Details File 70
c:\windows\system32\drivers\wd\wdboot.sys
Details File 70
c:\windows\system32\drivers\wd\wdfilter.sys
Details File 70
c:\windows\system32\drivers\wd\wdnisdrv.sys
Details File 1
c:\windows\system32\yamahaae2.dll
Details File 1
c:\windows\system32\yamahaae.dll
Details File 1
c:\windows\system32\slcnt64.dll
Details File 1
c:\windows\system32\sltech64.dll
Details File 1
c:\windows\system32\srrptr64.dll
Details File 1
c:\windows\system32\tosade.dll
Details File 1
c:\windows\system32\tossaeapo64.dll
Details File 1
c:\windows\system32\sl3apo64.dll
Details File 1
c:\windows\system32\tadefxapo264.dll
Details File 1
c:\windows\system32\tosasfapo64.dll
Details File 1
c:\windows\system32\tossaemapo64.dll
Details File 1
c:\windows\system32\srstsx64.dll
Details File 1
c:\windows\system32\srapo64.dll
Details File 1
c:\windows\system32\toseaeapo64.dll
Details File 1
c:\windows\system32\srcom64.dll
Details File 1
c:\windows\syswow64\srcom.dll
Details File 1
c:\windows\system32\srcom.dll
Details File 1
c:\windows\system32\srstsh64.dll
Details File 1
c:\windows\system32\srshp64.dll
Details File 1
c:\windows\system32\srswow64.dll
Details File 1
c:\windows\system32\tadefxapo.dll
Details File 1
c:\windows\system32\tepeqapo64.dll
Details File 1
c:\windows\system32\sehdhf64.dll
Details File 1
c:\windows\system32\sfss_apo.dll
Details File 1
c:\windows\syswow64\sehdhf32.dll
Details File 1
c:\windows\system32\secomn64.dll
Details File 1
c:\windows\system32\sehdra64.dll
Details File 1
c:\windows\syswow64\secomn32.dll
Details File 1
c:\windows\system32\seapo64.dll
Details File 3
c:\windows\system32\rtlcpapi64.dll
Details File 1
c:\windows\system32\sfnhk64.dll
Details File 1
c:\windows\system32\sfcom64.dll
Details File 1
c:\windows\system32\sfapo64.dll
Details File 1
c:\windows\syswow64\sfcom.dll
Details File 3
c:\windows\system32\rltkapo64.dll
Details File 1
c:\windows\syswow64\rltkapo.dll
Details File 5
c:\windows\system32\rtcom64.dll
Details File 3
c:\windows\system32\rtdataproc64.dll
Details File 3
c:\windows\system32\r4eed64a.dll
Details File 1
c:\windows\system32\rteep64a.dll
Details File 1
c:\windows\system32\rp3daa64.dll
Details File 1
c:\windows\system32\rp3dht64.dll
Details File 1
c:\windows\system32\rteed64a.dll
Details File 3
c:\windows\system32\r4eel64a.dll
Details File 3
c:\windows\system32\r4eea64a.dll
Details File 1
c:\windows\system32\rteel64a.dll
Details File 1
c:\windows\system32\rteeg64a.dll
Details File 3
c:\windows\system32\r4eeg64a.dll
Details File 3
c:\windows\system32\dolbydax2apov211.dll
Details File 1
c:\windows\system32\dtss2speakerdll64.dll
Details File 1
c:\windows\system32\dtss2headphonedll64.dll
Details File 1
c:\windows\system32\dtsboostdll64.dll
Details File 1
c:\windows\system32\dolbydax2apovlldp.dll
Details File 1
c:\windows\system32\dtsbassenhancementdll64.dll
Details File 1
c:\windows\system32\dtssymmetrydll64.dll
Details File 1
c:\windows\system32\dtsvoiceclaritydll64.dll
Details File 1
c:\windows\system32\icesoundapo64.dll
Details File 1
c:\windows\system32\dtsneopcdll64.dll
Details File 1
c:\windows\system32\dtslimiterdll64.dll