Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

What the HEX?


  • Please log in to reply

#1
adqjohn

adqjohn

    Member

  • Member
  • PipPip
  • 42 posts
Hi guys and gals. I have isolated a nasty little file named winwow32. I have veiwed the contents and while I can't read much of it, some of the text mentions "my sk0r Days P2P worm copywrite sk0r alias Cyzbik". Seems to be ransomeware, "if you want files back contact..." I copied the file from another computer and have been very careful not to execute on mine. I used my Filelyzer to explore a bit and now I have a question concerning Hex strings. In the string list (quite long) there are a couple that stick out like:
skOr Days 00001E78 00000000 00000000 00007635
skOr Days P2P 00001A64 736B3072 20446179 73205032
What the heck do these mean and are what is the significance of ones like this?

Signed,
Hex Dummy
  • 0

Advertisements


#2
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
Please follow the procedures outlined here: Malware Removal Guide

You will need a PC which can connect to the internet

Run all the programmes as advised then post a current Hijack This Log in a new topic in the Malware Forum

For the purpose of accurate malware analysis, Hijack This Logs are only dealt with in the Malware Forum. Posting them anywhere else will result in a delayed response

If you are unable to run any of the programmes, please ask for advice in the Malware Forum
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP