Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Start::
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-2949773067-2822248895-1452439868-1001\...\MountPoints2: E - "E:\Autorun.exe"
HKU\S-1-5-21-2949773067-2822248895-1452439868-1001\...\MountPoints2: {ab07eca7-fc8a-11e9-825d-c45444983a5d} - "E:\HiSuiteDownLoader.exe"
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {EC7C5DBC-0D60-4523-8029-4E474C8573CE} - System32\Tasks\Microsoft\Windows\Windows Error Reporting\SystemInfo => C:\Users\Tahir\AppData\Roaming\\systemdiag\\sysinfo.exe <==== ATTENTION
S2 csxzdmbr; C:\Windows\SysWOW64\csxzdmbr\vvwhcdbj.exe [X]
S3 BS_Flash64; \??\C:\Program Files (x86)\Tseries BIOS Update\Award\BS_Flash64.sys [X]
2020-05-26 02:51 - 2020-05-26 02:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2020-05-22 16:40 - 2020-05-27 21:14 - 000000000 ____D C:\Windows\system32\Tasks\AVAST Software
2020-05-26 02:17 - 2020-05-22 02:58 - 000338104 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe
2020-05-22 05:42 - 2020-05-22 05:42 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\k1a4cuw2lvz
2020-05-22 05:42 - 2020-05-22 05:42 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\00vitirhday
2020-05-22 03:30 - 2020-05-22 03:30 - 000000000 ____D C:\Users\Tahir\AppData\Local\AVG Netherlands BV
2020-05-22 03:15 - 2020-05-22 03:15 - 000000000 _____ C:\Users\Tahir\AppData\Roaming\unp217921376.tmp
2020-05-22 03:08 - 2020-05-22 03:08 - 000000000 ___HD C:\$AV_AVG
2020-05-22 03:03 - 2020-05-22 03:26 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\AVG
2020-05-22 03:03 - 2020-05-22 03:03 - 000000000 ____D C:\Users\Tahir\AppData\Local\CEF
2020-05-22 03:03 - 2020-05-22 03:03 - 000000000 ____D C:\Users\Tahir\AppData\Local\Avg
2020-05-22 02:58 - 2020-05-22 03:32 - 000000000 ____D C:\Users\Tahir\AppData\Local\CrashDumps
2020-05-22 02:32 - 2020-05-28 19:54 - 000000000 ____D C:\ProgramData\AVG
2020-05-22 02:29 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\uiokljg4rxn
2020-05-22 02:29 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\fm0uhc53qtw
2020-05-22 00:58 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\uhxw5y1wlvf
2020-05-22 00:58 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\hnt4cj5rdnd
2020-05-22 00:38 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\qr1fyt4lap2
2020-05-22 00:38 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\i1vcwvkmwcf
2020-05-22 00:18 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\xdjedv0wrx0
2020-05-22 00:18 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\mu2la35bpek
2020-05-22 00:02 - 2020-05-22 00:02 - 000000000 ____D C:\ProgramData\318994591972699
2020-05-21 23:58 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\m2fmoudsz2r
2020-05-21 23:58 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\jmsvswgiqfw
2020-05-21 23:54 - 2020-05-22 07:01 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\0a3b49011685
2020-05-21 23:38 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\wplib5cpq0n
2020-05-21 23:38 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\1cgg04ruwrq
2020-05-21 23:19 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\5mukjzzivzf
2020-05-21 23:18 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\zgagzlzn0cs
2020-05-21 23:12 - 2020-05-21 23:12 - 000000000 ____D C:\ProgramData\6OA8NIP44JDYZUNFQNWK20M4M
2020-05-21 23:10 - 2020-05-22 03:13 - 000000000 ____D C:\Users\Tahir\AppData\Roaming\f50bok4qitv
2020-05-21 23:09 - 2020-05-22 03:04 - 000000000 ____D C:\Windows\SysWOW64\csxzdmbr
2020-05-09 16:11 - 2020-05-21 23:11 - 000000000 ____D C:\748a6fab61a9eae989cac36f37
2020-05-09 00:39 - 2020-05-21 23:11 - 000000000 ____D C:\041280efeb2daba66f80b9eee7
2020-05-08 22:39 - 2020-05-21 23:11 - 000000000 ____D C:\4c6b791e4ff7073d3c8ebec4e7
2020-05-01 15:08 - 2020-05-21 23:11 - 000000000 ____D C:\3559c24885af98ea1ff3b008d37c
2020-04-30 19:47 - 2020-05-21 23:11 - 000000000 ____D C:\d3d51fa1a4933e05dcdeb6af
FCheck: C:\Windows\system32\w32tm.dll [2020-05-20] <==== ATTENTION (zero byte File/Folder)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
EmptyTemp:
End::
Source: How to remove Covm Ransomware - virus removal stepsAs explained in the "_readme.txt" ransom note, victims can encrypt their files with a decryption tool and unique key that can be purchased either for $980 or $490. Their price depends on how fast victims contact Covm's developers which can be done by writing an email to helpmanager@mail.ch or restoremanager@firemail.cc address. An email has to include the assigned ID. It is stated that it is impossible to decrypt data encrypted by Covm without tools that can be purchased only from its developers. Unfortunately, it is true. It is common that victims do not receive decryption tools even if they had paid for them. Therefore, cyber criminals cannot be trusted. In such cases the only way to recover files without risking to lose any money is to restore them from a created backup. It is worthwhile to mention that files that were not encrypted by installed ransomware can be protected from being encrypted later by uninstalling it. Although, files that are already encrypted remain encrypted even after its uninstallation.
Has Sysnative Forums helped you? Please consider donating to help us support the site!