What is Win32/Rodpicom.B infection?
In this article you will discover concerning the meaning of Win32/Rodpicom.B as well as its adverse influence on your computer system. Such ransomware are a kind of malware that is specified by online scams to demand paying the ransom by a victim.
In the majority of the situations, Win32/Rodpicom.B infection will instruct its victims to initiate funds move for the function of neutralizing the changes that the Trojan infection has introduced to the victim’s tool.
Win32/Rodpicom.B Summary
These alterations can be as follows:
- The binary likely contains encrypted or compressed data. In this case, encryption is a way of hiding virus’ code from antiviruses and virus’ analysts.
- Anomalous binary characteristics. This is a way of hiding virus’ code from antiviruses and virus’ analysts.
- Ciphering the records situated on the victim’s hard drive — so the sufferer can no longer use the information;
- Preventing regular accessibility to the victim’s workstation;
Win32/Rodpicom.B
One of the most normal networks through which Win32/Rodpicom.B Ransomware are injected are:
- By ways of phishing emails;
- As a repercussion of user winding up on a resource that hosts a destructive software program;
As soon as the Trojan is successfully injected, it will either cipher the data on the victim’s computer or stop the tool from operating in an appropriate fashion – while also putting a ransom money note that points out the demand for the targets to impact the settlement for the function of decrypting the files or restoring the file system back to the first problem. In a lot of instances, the ransom money note will certainly turn up when the customer restarts the PC after the system has already been damaged.
Win32/Rodpicom.B circulation channels.
In numerous edges of the world, Win32/Rodpicom.B expands by jumps and also bounds. Nevertheless, the ransom notes and tricks of extorting the ransom money quantity may differ relying on certain local (regional) settings. The ransom notes as well as methods of extorting the ransom money quantity may vary depending on specific neighborhood (local) settings.
For instance:
Faulty alerts concerning unlicensed software program.
In certain locations, the Trojans commonly wrongfully report having actually detected some unlicensed applications made it possible for on the victim’s tool. The alert then requires the individual to pay the ransom.
Faulty statements regarding unlawful content.
In countries where software application piracy is less popular, this method is not as reliable for the cyber scams. Alternatively, the Win32/Rodpicom.B popup alert may incorrectly declare to be deriving from a law enforcement establishment as well as will report having located kid pornography or other illegal data on the device.
Win32/Rodpicom.B popup alert may falsely claim to be obtaining from a legislation enforcement establishment and also will report having situated youngster porn or other prohibited information on the gadget. The alert will likewise contain a requirement for the user to pay the ransom money.
Technical details
File Info:
crc32: AA4BC4A7md5: 7f002f4a98747c5dee03c468feaafcd2name: 7F002F4A98747C5DEE03C468FEAAFCD2.mlwsha1: 04ee748a930b27e2d4f46ebe0c7258442c21b299sha256: 18456a5a5e04f94b71cd0df82b426637ba43bad1be3095038ca769cfa41930e8sha512: 87c08eadbe6ff33de5dcf2451d8a61cfe1d4e180693835da512b06b3de2c41ddf60c2cac60cf2f2f7933564bc81d9dc3161c5d3fa322c06a399b4cebd4a0c9fdssdeep: 1536:FhaFOqOCHZLyjHGnXSv9X7+LHdg5KqxR9pGEGiXzxeRb0PIBMl8:FhapOC5G18HUKqxRlXzQFfU8type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS WindowsVersion Info:
0: [No Data]
Win32/Rodpicom.B also known as:
| GridinSoft | Trojan.Ransom.Gen |
| Bkav | W32.AIDetect.malware2 |
| K7AntiVirus | Trojan ( 0040f1d41 ) |
| Elastic | malicious (high confidence) |
| DrWeb | Trojan.Siggen4.27293 |
| Cynet | Malicious () |
| ALYac | Worm.Generic.394648 |
| Cylance | Unsafe |
| Zillya | Trojan.Yakes.Win32.6814 |
| Sangfor | Trojan.Win32.Save.a |
| CrowdStrike | win/malicious_confidence_80% (D) |
| Alibaba | Worm:Win32/Rodpicom.abe30cbe |
| K7GW | Trojan ( 0040f1d41 ) |
| Cybereason | malicious.a98747 |
| Symantec | Trojan.Ransomlock!g8 |
| ESET-NOD32 | Win32/Rodpicom.B |
| APEX | Malicious |
| TotalDefense | Win32/Ransom.ATQ |
| Avast | Sf:Crypt-EX [Trj] |
| ClamAV | Win.Ransomware.Yakes-9828437-0 |
| Kaspersky | HEUR:Trojan.Win32.Generic |
| BitDefender | Worm.Generic.394648 |
| NANO-Antivirus | Virus.Win32.Gen-Crypt.ccnc |
| ViRobot | Trojan.Win32.A.Yakes.75776.D |
| MicroWorld-eScan | Worm.Generic.394648 |
| Tencent | Malware.Win32.Gencirc.10b9ac6e |
| Ad-Aware | Worm.Generic.394648 |
| Sophos | Mal/Generic-R + Troj/Ransom-LO |
| Comodo | Malware@#2ris228igit72 |
| VIPRE | Worm.Win32.Dorkbot.i (v) |
| TrendMicro | TROJ_RANSOM.SMO7 |
| McAfee-GW-Edition | BehavesLike.Win32.Generic.lh |
| FireEye | Generic.mg.7f002f4a98747c5d |
| Emsisoft | Worm.Generic.394648 (B) |
| SentinelOne | Static AI – Suspicious PE |
| Jiangmin | Trojan/Yakes.hpo |
| Webroot | W32.Rogue.Gen |
| Microsoft | Worm:Win32/Dorkbot.AM |
| Arcabit | Worm.Generic.D60598 |
| AegisLab | Trojan.Win32.Generic.4!c |
| GData | Worm.Generic.394648 |
| AhnLab-V3 | Trojan/Win32.Ransomlock.R42488 |
| Acronis | suspicious |
| McAfee | Ransom-ABD.gen.a |
| MAX | malware (ai score=100) |
| VBA32 | BScope.Malware-Cryptor.Oop |
| Panda | Trj/Genetic.gen |
| TrendMicro-HouseCall | TROJ_RANSOM.SMO7 |
| Rising | Worm.Rodpicom!8.2510 (CLOUD) |
| Ikarus | Trojan.Win32.Yakes |
| MaxSecure | Trojan.Malware.7164915.susgen |
| Fortinet | W32/Kryptik.4C06!tr |
| AVG | Sf:Crypt-EX [Trj] |
| Qihoo-360 | Win32/Worm.Generic.HgAASQ8A |