Issue
According to the Padvish team, spider malware came to the fore intending to extort money from victims, and it can transmit through portable drives (Flash Drives).
No need to pay the ransom, But this malware will format the system information if it is not removed from the system in time.
Symptoms of spider virus infection
-
The malware displays the following message on your system:
Your system is infected with a spider virus. All your system drives at the end of --- Will be fully formatted. If your system is formatted, even we will not be able to restore your data. Do not try to deceive the program because the spider is smart and indestructible and will format your drive. Avoid connecting any external memory while your system is infected with the spider virus(Flash, Memory, phone, etc.). To deactivate the virus before the deadline, enter the following site and complete the required information. Pay the deactivation fee in the form of a first 10 thousand toman mobile recharge card. If your charger password has been verified by our experts, you will be given a deactivation password. Enter the password in the spider program to get rid of the spider virus forever. Serial: ......... password: ......... Approval Do not touch your system history at all when your system is infected with a virus. In case of any problems entering the site, use a VPN. sign in to the site
-
The malware places the following files on portable drives connected to the system.
-
2.exe
-
NewFolder.exe
-
Telegram_anti filter.exe
-
New.exe
-
New .exe
-
-
It also adds a folder named System on the ProgramData path.
-
It also adds a copy of the malware named system32.exe on the Startup path.
As soon as this malware is executed it displays a message in the system, which announces that the system is infected with spider malware and asks the user to enter the following site and enter the 10 thousand Tomans charging code of one of the mobile phone operators along with the other requested information:
http: //www.spider0101.ezyro [dot] com / spider.html
Then, if the user does not do the job within the time specified by the malware, it will start formatting the victim drives.
Spider virus removal solution
-
Antivirus Padvish detects this malware as Worm.Win32.spider.AP. The easiest way is to install this anti-virus and remove the malware.