マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.Fakealert.47784

Added to the Dr.Web virus database: 2015-02-08

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '<Virus name>.exe' = '<SYSTEM32>\<Virus name>.exe'
Modifies file system :
Creates the following files:
  • %WINDIR%\4251dzwnloader9570.dll
  • <SYSTEM32>\26812sp9mb5tze4.dll
  • <SYSTEM32>\76dc5h9eat110z0.ocx
  • %WINDIR%\988fspyzare3159.cpl
  • %WINDIR%\130015o9z7f1.cpl
  • <SYSTEM32>\e94downloade95z1.ocx
  • <SYSTEM32>\952worz6b95.exe
  • <SYSTEM32>\4964tr5j16z.dll
  • %WINDIR%\269z9spa5b9t518.bin
  • <SYSTEM32>\60zaspyware2795.exe
  • <SYSTEM32>\60acbazkdo5r591.ocx
  • <SYSTEM32>\5f9zs5arse49.bin
  • %WINDIR%\2z529pyware1885.bin
  • %WINDIR%\2970zt95j51.exe
  • <SYSTEM32>\1z5989roj58a.ocx
  • %WINDIR%\3z005ir9578.dll
  • <SYSTEM32>\872zspam9ot505.exe
  • <SYSTEM32>\z9292sp959.cpl
  • %WINDIR%\595zsp9rse3405.dll
  • <SYSTEM32>\4d0c5aczdoor2965.exe
  • %WINDIR%\7f54downl9adez2313.cpl
  • <SYSTEM32>\3ezcsp5ware3953.ocx
  • %WINDIR%\4z19thi5f2590.bin
  • <SYSTEM32>\5009thi9z1542.bin
  • %WINDIR%\6952zparse1423.dll
  • %WINDIR%\2z44a59ware1457.bin
  • <SYSTEM32>\89515zrus327.exe
  • %WINDIR%\59a6szarse935.exe
  • %WINDIR%\55061not-a-z9rus66e.exe
  • %WINDIR%\5930ba9k5oor399z.exe
  • <SYSTEM32>\15516virus90z.exe
  • %WINDIR%\58935zirus704.ocx
  • %WINDIR%\z14sp5119.dll
  • <SYSTEM32>\5b1as5yware29z2.ocx
  • %WINDIR%\z9559spy759.exe
  • %WINDIR%\3a19spy5are1789z.ocx
  • %WINDIR%\29055wor95z0.ocx
  • <SYSTEM32>\z237sp54919.ocx
  • %WINDIR%\5958vir3593z.ocx
  • <SYSTEM32>\51b9spywa5z3065.bin
  • %WINDIR%\2z5495p9mbot96.exe
  • <SYSTEM32>\ze415hrea95659.exe
  • %WINDIR%\d57v9z491.bin
  • %WINDIR%\33z9vir553.dll
  • %WINDIR%\50z2tro9772.cpl
  • <SYSTEM32>\9935spy450z.ocx
  • <SYSTEM32>\58995worm55z.cpl
  • %WINDIR%\7925addware969z.cpl
  • %WINDIR%\25718spzmbo56d9.bin
  • %WINDIR%\1c1zsparse10539.exe
  • %WINDIR%\359dthief76z.ocx
  • %WINDIR%\30572sz5759.dll
  • %WINDIR%\29050t95j60z.dll
  • <SYSTEM32>\1259zorm5149.cpl
  • <SYSTEM32>\4905virzs4cd.dll
  • %WINDIR%\299z3tr5j692.exe
  • %WINDIR%\23137noz-a-vir5s598.dll
  • %WINDIR%\97z52worm6c6.ocx
  • <SYSTEM32>\z375spambot955.dll
  • <SYSTEM32>\3a6z9ir1455.bin
  • <SYSTEM32>\4z39ack5oor2246.exe
  • <SYSTEM32>\e60thr5at90638z.ocx
  • <SYSTEM32>\5720zhacktool58a9.ocx
  • %WINDIR%\32065not-9-vzrus39b.exe
  • <SYSTEM32>\14995no5-a-virus33z.exe
  • <SYSTEM32>\3119459rz6ef.cpl
  • <SYSTEM32>\742559rzat8432.ocx
  • %WINDIR%\542zhre9t12849.dll
  • %WINDIR%\245025pamboz559.cpl
  • %WINDIR%\2954backd9or32z6.exe
  • <SYSTEM32>\z9651spamb9t52a.cpl
  • %WINDIR%\544e9hief135z.exe
  • %WINDIR%\ec5t95zf2496.ocx
  • <SYSTEM32>\4838hzcktool15f9.ocx
  • <SYSTEM32>\5175ad9ware299z.cpl
  • %WINDIR%\13101sp5mbz966c.cpl
  • <SYSTEM32>\301z2h59ktool656.dll
  • %WINDIR%\6z66backdo5r1949.dll
  • %WINDIR%\16z60v9rus54e.dll
  • %WINDIR%\19401troj5z0.exe
  • <SYSTEM32>\163z1t9oj5ff.cpl
  • <SYSTEM32>\59772vizus3d8.ocx
  • %WINDIR%\5153addwarz19459.ocx
  • %WINDIR%\7z05t9r5at25002.exe
  • %WINDIR%\7735z5ckdoor7949.exe
  • %WINDIR%\5df9downlo5dz9203.cpl
  • %WINDIR%\12559zroj359.exe
  • <SYSTEM32>\5350downl9ader2z24.bin
  • <SYSTEM32>\z94v9r5199.exe
  • %WINDIR%\65abv9r3z35.cpl
  • %WINDIR%\6d25vir992z.bin
  • <SYSTEM32>\73zc9te5l42.cpl
  • %WINDIR%\56169troj5z9.exe
  • %WINDIR%\4863downlzade5292.cpl
  • <SYSTEM32>\9ca7addzar52253.cpl
  • <SYSTEM32>\5905vir49z.dll
  • %WINDIR%\3d74st9al755z.cpl
  • %WINDIR%\94b8t5ief13z7.exe
  • %WINDIR%\181529py544z.dll
  • <SYSTEM32>\2cc9vzr5939.bin
  • %WINDIR%\23casparz92275.exe
  • %WINDIR%\2041not-5-virus7ez9.ocx
  • <SYSTEM32>\5931thrzat7941.ocx
  • <SYSTEM32>\z949spy625.ocx
  • %WINDIR%\6dc5s9zal362.exe
  • <SYSTEM32>\28567z95j60a.ocx
  • <SYSTEM32>\26f0z9wnloader625.exe
  • <SYSTEM32>\55910trzj573.cpl
  • <SYSTEM32>\28359s9z598.dll
  • %WINDIR%\4b975teal11z2.ocx
  • %WINDIR%\2720zpa9b5t17b.ocx
  • <SYSTEM32>\4783threatz40905.cpl
  • %WINDIR%\1c5zd9wnloader2503.bin
  • <SYSTEM32>\7z53sp9ware822.dll
  • %WINDIR%\5767trzj49a.exe
  • <SYSTEM32>\1965zpy4f3.bin
  • %WINDIR%\1z992hack5ool36b.dll
  • <SYSTEM32>\2784zv9rus495.dll
  • %WINDIR%\76ffth9ea5z4377.exe
  • <SYSTEM32>\5209spyz23.exe
  • <SYSTEM32>\9z04spars51922.bin
  • %WINDIR%\5986back5ozr395.ocx
  • %WINDIR%\3965worm2ez5.cpl
  • %WINDIR%\10534noz-a-virus981.exe
  • %WINDIR%\7azaste5l729.ocx
  • %WINDIR%\5e9ebaczdoor1045.dll
  • <SYSTEM32>\26446hazk5o9l1e6.dll
  • %WINDIR%\369z59r2612.exe
  • <SYSTEM32>\22989v9rus5z4.cpl
  • <SYSTEM32>\20d9downloadez29055.bin
  • %WINDIR%\fb5st59l785z.exe
  • <SYSTEM32>\6990addzare1579.cpl
  • <SYSTEM32>\692zaddware29835.bin
  • %WINDIR%\23614w9rm5bz.exe
  • <SYSTEM32>\5d5dz9r1986.exe
  • %WINDIR%\545029pyz6.bin
  • %WINDIR%\7deddownl9ader1z45.ocx
  • %WINDIR%\6987ad5wzre2924.bin
  • <SYSTEM32>\5z033troj9dd.ocx
  • %WINDIR%\5999zworm2b3.exe
  • %WINDIR%\z20789roj6e5.dll
  • <SYSTEM32>\986ctzie52377.cpl
  • %WINDIR%\14255t9oj2cz5.exe
  • %WINDIR%\15zv9r522.dll
  • %WINDIR%\59zsp9390.dll
  • <SYSTEM32>\3z5cspar9e2017.cpl
  • <SYSTEM32>\51541s9z199.cpl
  • <SYSTEM32>\1659addware2124z.bin
  • <SYSTEM32>\97743virus1ez5.bin
  • %WINDIR%\4800baz59oor1455.cpl
  • %WINDIR%\29817zot-a-v5rus336.exe
  • <SYSTEM32>\1352zv9rus2f1.exe
  • <SYSTEM32>\z9669pyware5634.ocx
  • %WINDIR%\3089downloader965z.cpl
  • <SYSTEM32>\8528s9y5za.bin
  • %WINDIR%\442f5aczdoor2917.exe
  • <SYSTEM32>\100759a5ktool5z.ocx
  • %WINDIR%\17859spaz59t5a5.exe
  • <SYSTEM32>\1b3395zeat25130.dll
  • <SYSTEM32>\186055zy5909.ocx
  • <SYSTEM32>\4d3c9own5oader1378z.ocx
  • %WINDIR%\958eadzware2814.dll
  • %WINDIR%\23z95spy99.dll
  • %WINDIR%\7z3fthreat27599.ocx
  • <SYSTEM32>\8199zpambot25d.cpl
  • %WINDIR%\ze9ethreat156499.ocx
  • <SYSTEM32>\18279wzr542e.cpl
  • %WINDIR%\9179ztroj458.dll
  • <SYSTEM32>\18e1baczdoor25669.ocx
  • %WINDIR%\5z9fbackdoor200.bin
  • <SYSTEM32>\70529roj1ccz.bin
  • %WINDIR%\9cbcspywa5e62z.bin
  • <SYSTEM32>\559zw9rm75e.exe
  • %WINDIR%\2958downlozder31539.dll
  • <SYSTEM32>\1d5addware902z.dll
  • %WINDIR%\2579thre9t3940z.ocx
  • <SYSTEM32>\1569zackdoor2981.cpl
  • <SYSTEM32>\29968szy5ed.cpl
  • %WINDIR%\1789vir15z55.dll
  • %WINDIR%\16523sp5z69.bin
  • <SYSTEM32>\6249dzwnlo9d5r855.exe
  • <SYSTEM32>\5771thief1z99.bin
  • <SYSTEM32>\4594addwarez299.dll
  • <SYSTEM32>\1z595spamb5t99b.dll
  • <SYSTEM32>\29b85ownlzader3189.ocx
  • %WINDIR%\5dd89aczdoor1249.ocx
  • %WINDIR%\4822spz5bot9ee.dll
  • %WINDIR%\202z9p5222.bin
  • <SYSTEM32>\94zsteal515.bin
  • %WINDIR%\289cste5z678.dll
  • <SYSTEM32>\1073add9arz30525.ocx
  • %WINDIR%\79zw5rm4a8.cpl
  • %WINDIR%\34e6zown5oader3915.cpl
  • <SYSTEM32>\z58dsteal2209.bin
  • <SYSTEM32>\99599vizu5c2.ocx
  • %WINDIR%\10315zr9j5ff.cpl
  • <SYSTEM32>\718asparsz9115.bin
  • <SYSTEM32>\558d9wnloadez5051.ocx
  • <SYSTEM32>\9102worm35z9.exe
  • %WINDIR%\ae1baczdo5r819.cpl
  • <SYSTEM32>\169zspa5bot356.cpl
  • %WINDIR%\49aathiz93156.bin
  • %WINDIR%\30097tr5j520z.ocx
  • <SYSTEM32>\z9a2thief1595.bin
  • %WINDIR%\z8272worm95e.dll
  • %WINDIR%\3b64s5eal9z1.dll
  • %WINDIR%\45bfszeal9695.exe
  • <SYSTEM32>\45z9threat7853.ocx
  • %WINDIR%\dza5hie9553.bin
  • %WINDIR%\1f09ddwa5e2776z.ocx
  • %WINDIR%\209th5ef2689z.exe
  • %WINDIR%\5dz9steal2006.dll
  • %WINDIR%\528szywa9e175.dll
  • %WINDIR%\35099tezl5291.exe
  • %WINDIR%\9515viz1780.bin
  • %WINDIR%\32965pambotz7a9.bin
  • %WINDIR%\94zavir1519.dll
  • <SYSTEM32>\1f16downlo9d5z2326.ocx
  • %WINDIR%\z57downloader1943.bin
  • %WINDIR%\121079pambzt58.bin
  • %WINDIR%\dc25zyw9re1139.exe
  • <SYSTEM32>\78629iz2859.bin
  • <SYSTEM32>\9e53spazse172.dll
  • %WINDIR%\12z585irus1729.exe
  • <SYSTEM32>\6367ha5k9zol69d.bin
  • %WINDIR%\3145thizf439.bin
  • <SYSTEM32>\5e16thre5t1z8609.bin
  • <SYSTEM32>\894vir230z5.bin
  • <SYSTEM32>\29fzdow5loader1102.bin
  • <SYSTEM32>\8625not-a-vi9zsf9.ocx
  • <SYSTEM32>\9545v5zus49.cpl
  • %WINDIR%\6f8c5ir1z999.bin
  • %WINDIR%\15265v9rus63az.exe
  • <SYSTEM32>\25291szy155.exe
  • <SYSTEM32>\469adownloaze510259.exe
  • <SYSTEM32>\49zdsp5rse2081.bin
  • %WINDIR%\19eed9wnlozd5r1335.cpl
  • %WINDIR%\1zf5ad5ware30839.dll
  • <SYSTEM32>\1564spzrse1539.cpl
  • <SYSTEM32>\31598hackt5oz9e0.dll
  • <SYSTEM32>\z5269wo5m299.dll
  • <SYSTEM32>\98d5downlozd5r1840.ocx
  • <SYSTEM32>\91952wozm68c.dll
  • %WINDIR%\3609sp5rse360z.ocx
  • %WINDIR%\816zv5r9s84.dll
  • <SYSTEM32>\125z29py157.cpl
  • %WINDIR%\z5bdownload9r4455.dll
  • %WINDIR%\40z0no59a-virus3de.dll
  • %WINDIR%\52296troj161z.exe
  • <SYSTEM32>\5b9zaddwar95704.ocx
  • <SYSTEM32>\25996spy3bz.bin
  • %WINDIR%\190baddwar514z9.exe
  • %WINDIR%\9z525sp57f.bin
  • <SYSTEM32>\z9745iru96ac.ocx
  • %WINDIR%\5z4fbac5door24739.bin
  • <SYSTEM32>\3594zhreat5956.dll
  • <SYSTEM32>\75z59ddware2867.dll
  • <SYSTEM32>\5590bzc9door326.ocx
  • %WINDIR%\32530zirus249.bin
  • <SYSTEM32>\49e0a9zware540.exe
  • <SYSTEM32>\6944spywarz1395.cpl
  • <SYSTEM32>\57783spamb9t359z.bin
  • %WINDIR%\30a5threa5996z.exe
  • <SYSTEM32>\4251spazse2994.cpl
  • %WINDIR%\12484zpa5bot16f9.ocx
  • <SYSTEM32>\5c7fdzwnloa9er2418.bin
  • <SYSTEM32>\4zbbs59al2678.dll
  • %WINDIR%\28280vir5z8a9.ocx
  • <SYSTEM32>\56f4zhi591610.dll
  • %WINDIR%\59af9parz51097.ocx
  • <SYSTEM32>\485nz9-5-virus35.dll
  • %WINDIR%\192z2not-a-vi5us622.dll
  • %WINDIR%\28dcdownl9a5er21z2.cpl
  • <SYSTEM32>\7z61troj5759.exe
  • <SYSTEM32>\133295rzj18d.ocx
  • %WINDIR%\397espywar52045z.bin
  • %WINDIR%\2553zhief9169.bin
  • %WINDIR%\5b86th5ea9110z3.ocx
  • %WINDIR%\5cd9sp5rsz1705.exe
  • %WINDIR%\95955zpambot2b7.dll
  • <SYSTEM32>\57555hr9zt21745.dll
  • <SYSTEM32>\12702vzrus959.exe
  • %WINDIR%\159zworm71.bin
  • %WINDIR%\65zte5l4509.bin
  • %WINDIR%\9980nzt-a-vir5s9e8.bin
  • %WINDIR%\23z15h9ck5ool39f.dll
  • %WINDIR%\16dad9wnload5rz487.bin
  • <SYSTEM32>\z1079r5j2e2.dll
  • <SYSTEM32>\1z212sp5mbot95c.cpl
  • <SYSTEM32>\39zfdownload5r28649.exe
  • <SYSTEM32>\3096zspy259.exe
  • <SYSTEM32>\653bd9wnload5z2431.ocx
  • <SYSTEM32>\66aazackdo5r2879.dll
  • <SYSTEM32>\6d665t9alz009.dll
  • %WINDIR%\3e6zspyw9r53155.cpl
  • %WINDIR%\39525zpyb5.exe
  • <SYSTEM32>\95073virus7fcz.exe
  • %WINDIR%\15471h9cktzol5ad.exe
  • <SYSTEM32>\494bdownloadzr852.cpl
  • %WINDIR%\5431nzt-a-9i5us4a0.bin
  • <SYSTEM32>\16364n5t-a9vzrus1ce.ocx
  • %WINDIR%\3699spywaze2255.cpl
  • %WINDIR%\z6136not-a-v5r9s54e.exe
  • <SYSTEM32>\2991thr5az5119.exe
  • <SYSTEM32>\45fzste9l5062.ocx
  • <SYSTEM32>\1135z5py9c0.dll
  • %WINDIR%\8bedownloazer91445.cpl
  • <SYSTEM32>\39edspars9z1375.bin
  • %WINDIR%\3207dz5nl9ader1590.cpl
  • %WINDIR%\11060s59mbot46z.ocx
  • %WINDIR%\3208sp9zar52556.dll
  • %WINDIR%\1504zwo5m790.cpl
  • %WINDIR%\96019zorm5a.bin
  • %WINDIR%\315669irus56z5.cpl
  • %WINDIR%\5425steal1945z.cpl
  • <SYSTEM32>\35c0spzw5r9835.cpl
  • %WINDIR%\5z65th5ea910483.ocx
  • %WINDIR%\1965zs5y4c.cpl
  • <SYSTEM32>\2448zt59j575.bin
  • <SYSTEM32>\7978szy517.cpl
  • %WINDIR%\21560zo9m759.exe
  • %WINDIR%\222cspyza9e1435.dll
  • %WINDIR%\7ef9spzrse1524.cpl
  • %WINDIR%\21587worm4zc9.exe
  • <SYSTEM32>\436cspzrse29759.ocx
  • %WINDIR%\3z01do9nlo5der202.exe
  • <SYSTEM32>\23z09sp5125.dll
  • %WINDIR%\51261spz239.cpl
  • <SYSTEM32>\9991zro5590.cpl
  • <SYSTEM32>\297939orm25z.exe
  • <SYSTEM32>\6zd7spywar52569.bin
  • <SYSTEM32>\95zfv5r366.exe
  • %WINDIR%\7738s9arsz2895.dll
  • %WINDIR%\177195pz379.cpl
  • %WINDIR%\25z52worm9fc.cpl
  • %WINDIR%\23277zo9-a-virus145.cpl
  • %WINDIR%\35c8thre9z21533.cpl
  • <SYSTEM32>\3bz1t9reat30225.dll
  • %WINDIR%\5519zhief3995.exe
  • <SYSTEM32>\7z5ethie91250.bin
  • %WINDIR%\9989zacktool7185.ocx
  • <SYSTEM32>\2zbbdownload5r2903.exe
  • %WINDIR%\c65d9wn5oaderz468.dll
  • %WINDIR%\7dc2spazse9853.dll
  • %WINDIR%\z5d6s5yw9re2591.cpl
  • <SYSTEM32>\6e1cthreat9z285.cpl
  • %WINDIR%\9206thrzat4358.ocx
  • %WINDIR%\29975ddwaze155.bin
  • <SYSTEM32>\28581notza-virus5909.dll
  • <SYSTEM32>\4z5adow5loader2965.bin
  • <SYSTEM32>\3361h5cktooz129.ocx
  • %WINDIR%\309zth9ef5803.cpl
  • <SYSTEM32>\59fbbac9dooz3155.ocx
  • <SYSTEM32>\50017spzmbot699.ocx
  • <SYSTEM32>\5685viruz2695.bin
  • %WINDIR%\61z2downlo5de92394.ocx
  • <SYSTEM32>\35z59p5rse2108.dll
  • %WINDIR%\364cspyw95e1z7.bin
  • <SYSTEM32>\26022hac5toz9241.dll
  • %WINDIR%\3z555ownlo9der2259.dll
  • <SYSTEM32>\15239not-a-virusf6z.bin
  • <SYSTEM32>\23074ha9ktozl5e5.dll
  • <SYSTEM32>\5193sp54z1.bin
  • %WINDIR%\4192virus27z5.bin
  • <SYSTEM32>\3d99hief1495z.dll
  • <SYSTEM32>\4z4spa95e2414.dll
  • <SYSTEM32>\51e65i92z04.exe
  • %WINDIR%\9f2cspyw5rez097.ocx
  • %WINDIR%\6252zpy3bb9.exe
  • <SYSTEM32>\z661t9re5t6472.bin
  • <SYSTEM32>\zb27threat265659.ocx
  • <SYSTEM32>\9152addwaze25925.bin
  • %WINDIR%\35708wormz99.cpl
  • <SYSTEM32>\6937spzrse2757.exe
  • %WINDIR%\2a55azdware797.dll
  • <SYSTEM32>\24211sp5zbo93e9.exe
  • <SYSTEM32>\4b53zddware1539.cpl
  • <SYSTEM32>\26915troj19z.exe
  • <SYSTEM32>\90485ot-a-viruz22b.cpl
  • <SYSTEM32>\2915zdd9are1185.bin
  • %WINDIR%\60505rojzda9.ocx
  • <SYSTEM32>\19780w5rz40f.exe
  • %WINDIR%\10317not-a9virus39z5.bin
  • %WINDIR%\95acspzrs5128.dll
  • %WINDIR%\29595sz52d5.exe
  • %WINDIR%\27949wor94z45.ocx
  • <SYSTEM32>\6fc359dwzre757.dll
  • <SYSTEM32>\5bzfspyware2896.cpl
  • <SYSTEM32>\5c0sp5rze995.exe
  • <SYSTEM32>\326395rzat13411.ocx
  • <SYSTEM32>\15920ha9ktozl262.ocx
  • <SYSTEM32>\a0f5ddware984z.ocx
  • <SYSTEM32>\700bviz1959.bin
  • %WINDIR%\7f3b9pzrse2523.exe
  • <SYSTEM32>\29821hac9tool58ez.bin
  • <SYSTEM32>\219zackdo5r2999.exe
  • <SYSTEM32>\z058vir959.dll
  • %WINDIR%\5az859eal1765.bin
  • <SYSTEM32>\9aeba5dware575z.ocx
  • <SYSTEM32>\2899troz4d5.bin
  • %WINDIR%\f93vir5598z.ocx
  • <SYSTEM32>\2dd4tzreat19385.exe
  • %WINDIR%\6457thrz9t4816.ocx
  • <SYSTEM32>\5z4bsteal959.ocx
  • <SYSTEM32>\15522trzj98.exe
  • <SYSTEM32>\2bdzth9ef1035.cpl
  • %WINDIR%\12b5stzal6809.bin
  • %WINDIR%\129z0hackt5ol7bd.cpl
  • <SYSTEM32>\139625roz3479.bin
  • <SYSTEM32>\5740hackt9oz1a75.ocx
  • %WINDIR%\26697hz5ktool5d9.bin
  • <SYSTEM32>\23589hac5zo9l5dc.exe
  • <SYSTEM32>\251z9spy2b9.exe
  • <SYSTEM32>\45a49hreat35727z.ocx
  • %WINDIR%\7f22z5yware943.cpl
  • %WINDIR%\6aazteal3195.dll
  • <SYSTEM32>\79z5sparse196.dll
  • %WINDIR%\12767t9ozf65.exe
  • <SYSTEM32>\57595virus9dz.ocx
  • %WINDIR%\18479tr9z69b5.bin
  • <SYSTEM32>\30254s5azbot599.exe
  • <SYSTEM32>\565zsp5wa9e2761.ocx
  • %WINDIR%\238989z5m79.bin
  • %WINDIR%\7f2d5zckdoor4709.ocx
  • <SYSTEM32>\18212spambo9580z.cpl
  • %WINDIR%\22956noz-a-vir5se7.exe
  • <SYSTEM32>\6a8aaddwa951z63.cpl
  • %WINDIR%\21545zi59s12.ocx
  • %WINDIR%\95z4steal25845.exe
  • <SYSTEM32>\9057haczt9ol426.dll
  • %WINDIR%\15z0s9eal2180.cpl
  • %WINDIR%\59addoznload5r852.dll
  • <SYSTEM32>\3z89spyware5927.dll
  • <SYSTEM32>\71e5zh9ef570.ocx
  • <SYSTEM32>\9951not-a-v5ruszeb.bin
  • %WINDIR%\4c75spyza9e2238.ocx
  • <SYSTEM32>\92373tr5j673z.ocx
  • <SYSTEM32>\966395y7a0z.exe
  • <SYSTEM32>\5876thre9tz36095.ocx
  • <SYSTEM32>\68zcv5r9823.cpl
  • <SYSTEM32>\21dfs5ywaze9545.ocx
  • <SYSTEM32>\19679tzoj755.bin
  • <SYSTEM32>\5647hac9tool6dz.dll
  • %WINDIR%\5956steaz2636.dll
  • <SYSTEM32>\66599z5ware2898.cpl
  • <SYSTEM32>\eaavz99895.cpl
  • <SYSTEM32>\9631spzrse8295.dll
  • %WINDIR%\z1b9v9r2885.bin
  • %WINDIR%\97z9spamb5t981.exe
  • %WINDIR%\8954hz5k9ool640.ocx
  • %WINDIR%\55dadzware1739.exe
  • %WINDIR%\49659zwnloader3074.dll
  • %WINDIR%\1abba9kdozr1665.cpl
  • %WINDIR%\10445szye99.cpl
  • %WINDIR%\6e0cdoznloa5er579.bin
  • <SYSTEM32>\1965thief596z.exe
  • <SYSTEM32>\66dt5zef1009.ocx
  • <SYSTEM32>\1f0atz9ef805.ocx
  • <SYSTEM32>\6354spyware956z.ocx
  • <SYSTEM32>\1147z5reat63299.ocx
  • <SYSTEM32>\c53spywz9e26645.ocx
  • %WINDIR%\275c9ackdooz1287.bin
  • %WINDIR%\19593wzrm55b.exe
  • <SYSTEM32>\z51f9parse2305.dll
  • <SYSTEM32>\4z9daddware753.exe
  • %WINDIR%\911z3spambot7505.bin
  • %WINDIR%\18926spzm9ot295.dll
  • <SYSTEM32>\<Virus name>.exe
  • %WINDIR%\5aadzte9l2784.exe
  • %WINDIR%\4z2b9t5al2695.dll
  • <SYSTEM32>\24z295pam9ot2a5.bin
  • %WINDIR%\79d6s5eal1z889.exe
  • %WINDIR%\35b9zddware2393.cpl
  • <SYSTEM32>\20955szambo56af.ocx
  • <SYSTEM32>\28e5sparsez4579.exe
  • %WINDIR%\989addwa9e275z5.ocx
  • <SYSTEM32>\z765hacktool299.bin
  • <SYSTEM32>\93z9steal2955.cpl
  • %WINDIR%\28649hacztool3f5.cpl
  • %WINDIR%\75b5s9zal1105.cpl
  • <SYSTEM32>\1cebstea5270z9.dll
  • <SYSTEM32>\95fcszeal697.exe
  • %WINDIR%\71299ot-a-virus225z.dll
  • %WINDIR%\4z39do5nloader5099.ocx
  • %WINDIR%\5czfaddware19635.cpl
  • %WINDIR%\7cafazdw5re391.cpl
  • <SYSTEM32>\4955stealz99.bin
  • %WINDIR%\55238wormz59.bin
  • <SYSTEM32>\8790viz5s4599.dll
  • %WINDIR%\695zsteal770.bin
  • <SYSTEM32>\25c9back9ozr1251.ocx
  • %WINDIR%\30z25spy596.exe
  • %WINDIR%\3253zvirus90.dll
  • %WINDIR%\10909z5al.cpl
  • %WINDIR%\19857trzj491.bin
  • <SYSTEM32>\72dz9hi5f788.bin
  • %WINDIR%\19919viruz5d.bin
  • <SYSTEM32>\3343zackt59l321.ocx
  • <SYSTEM32>\30992hacktoz95e6.cpl
  • <SYSTEM32>\6f18down9o5der2z35.cpl
  • <SYSTEM32>\19815not-a-virus5za.cpl
  • %WINDIR%\17940ha5kzoo974b.ocx
  • <SYSTEM32>\26751no95a-zirus719.ocx
  • <SYSTEM32>\7zaf5h9ef2563.exe
  • %WINDIR%\1ez7addw5re9918.exe
  • %WINDIR%\3b57v5r982z.exe
  • <SYSTEM32>\135fszarse21769.exe
  • <SYSTEM32>\z71495y57a.cpl
  • <SYSTEM32>\3729viru9z15.cpl
  • %WINDIR%\z2933sp59c.bin
  • %WINDIR%\5477st9az1684.exe
  • %WINDIR%\z8861troj959.cpl
  • <SYSTEM32>\36f1threa9205z55.exe
  • <SYSTEM32>\7z21thief509.ocx
  • <SYSTEM32>\5865bazkdo9r2971.bin
  • %WINDIR%\z127spywa9e756.exe
  • <SYSTEM32>\63bzthreat16895.exe
  • <SYSTEM32>\259z5acktoo955a.exe
  • %WINDIR%\39z0v9rus55c.exe
  • <SYSTEM32>\49bzthreat3958.cpl
  • %WINDIR%\199z3worm5f.dll
  • %WINDIR%\599athzeat16354.exe
  • <SYSTEM32>\2d9cspyw9ze9675.cpl
  • %WINDIR%\1746zw9r5485.ocx
  • %WINDIR%\11293troj5bz5.cpl
  • <SYSTEM32>\29591t5oj7zc.cpl
  • %WINDIR%\25315not-azv95us3eb.exe
  • %WINDIR%\5eebdownzoad5r3009.cpl
  • <SYSTEM32>\18561zo9m580.bin
  • %WINDIR%\z09baddwar51589.exe
  • <SYSTEM32>\52070noz-a-vi9us79d.exe
  • <SYSTEM32>\4158zteal21945.dll
  • <SYSTEM32>\9694not-a5virus7zf.ocx
  • <SYSTEM32>\49f4doznloade51348.ocx
  • %WINDIR%\3z554spa9bo5419.ocx
  • <SYSTEM32>\2585spambotz49.dll
  • <SYSTEM32>\z9653tro5799.cpl
  • %WINDIR%\98z3tro9557.dll
  • %WINDIR%\7dzespyware52429.dll
  • %WINDIR%\993adzware21095.exe
  • <SYSTEM32>\6e97thr5az31950.bin
  • <SYSTEM32>\1934add9ar5129z.exe
  • %WINDIR%\217z9ackdoor25775.exe
  • <SYSTEM32>\z8059worm7589.ocx
  • %WINDIR%\17cc9hzef2512.exe
  • <SYSTEM32>\6de6s9eal352z.bin
  • %WINDIR%\22a5stezl4559.cpl
  • <SYSTEM32>\993z8sp5mbot627.ocx
  • %WINDIR%\3101hackz59l23c.bin
  • %WINDIR%\3059addwarz9090.bin
  • %WINDIR%\2z7d9hre5t8197.cpl
  • <SYSTEM32>\zd52steal2690.bin
  • %WINDIR%\28335spamb9z35e.exe
  • <SYSTEM32>\za70sparse27795.exe
  • <SYSTEM32>\1c55backdoor199z9.dll
  • %WINDIR%\67abt9i5z1266.bin
  • %WINDIR%\2001zhacktool99c5.ocx
  • %WINDIR%\5cz5vir2951.bin
  • <SYSTEM32>\4956szywar52830.cpl
  • <SYSTEM32>\9552sp918bz.bin
  • <SYSTEM32>\7aaza9dwa5e3183.exe
  • %WINDIR%\29b9spzware13755.dll
  • %WINDIR%\ze9cstea52210.dll
  • <SYSTEM32>\54ffdownloaz95623.cpl
  • %WINDIR%\5901s9y525z.ocx
  • <SYSTEM32>\3dd05zarse2789.dll
  • <SYSTEM32>\29697not-a-v9zus652.cpl
  • %WINDIR%\7259zhreat6537.ocx
  • <SYSTEM32>\9921v5rus362z.cpl
  • <SYSTEM32>\29905sp57z0.dll
  • %WINDIR%\93665spa5bzt497.bin
  • <SYSTEM32>\2095ztroj6b6.ocx
  • %WINDIR%\1090sp5mb9t6d1z.ocx
  • <SYSTEM32>\3c46sz9r5e1100.ocx
  • <SYSTEM32>\76f5dowzlo5der2579.bin
  • %WINDIR%\5bfzsp9ware1801.exe
  • %WINDIR%\z6755virus594.cpl
  • %WINDIR%\1b05back59oz187.bin
  • <SYSTEM32>\3912threz914453.dll
  • %WINDIR%\3349stza51470.cpl
  • <SYSTEM32>\70b5b9ckdooz2860.ocx
  • <SYSTEM32>\9548zacktool595.ocx
  • %WINDIR%\19z5vir1120.dll
  • %WINDIR%\45e29ow5loadez577.dll
  • <SYSTEM32>\53d2t9reat51z55.exe
  • %WINDIR%\31547w5rz195.cpl
  • %WINDIR%\6c985ackdoor105z.exe
  • <SYSTEM32>\917495orz6f3.cpl
  • %WINDIR%\23564sp94z4.ocx
  • %WINDIR%\6z59vir958.bin
  • <SYSTEM32>\4c33spyzare9059.ocx
  • <SYSTEM32>\13f6th9z51746.exe
  • <SYSTEM32>\306eviz55469.ocx
  • %WINDIR%\5d95downloazer2655.exe
  • <SYSTEM32>\61bzth9ef2795.exe
  • %WINDIR%\30d2sp5rsez539.cpl
  • %WINDIR%\49z9spars5965.bin
  • <SYSTEM32>\6ze0add5are9951.ocx
  • <SYSTEM32>\96456tr5j9z.dll
  • %WINDIR%\1f915teal825z.dll
  • %WINDIR%\155adz5a9e3102.bin
  • %WINDIR%\cz5v9r609.exe
  • <SYSTEM32>\7513tro5zde9.exe
  • <SYSTEM32>\7dffzown9oader1154.dll
  • %WINDIR%\3657downloader150z9.dll
  • %WINDIR%\23472vz9us526.exe
  • <SYSTEM32>\26d9tzief7455.ocx
  • <SYSTEM32>\652zspars93062.ocx
  • <SYSTEM32>\9582troj5ze.cpl
  • %WINDIR%\2079spa95zt6e7.cpl
  • <SYSTEM32>\34d5zwnloader9208.bin
  • %WINDIR%\49a45ddwaze1655.ocx
  • <SYSTEM32>\a59thiefz907.cpl
  • %WINDIR%\34d7t9rezt15218.bin
  • %WINDIR%\171spam5ot9az.cpl
  • %WINDIR%\9ez5sparse1655.bin
  • <SYSTEM32>\2z785spy4269.cpl
  • <SYSTEM32>\27972wz5m3129.ocx
  • <SYSTEM32>\78z55py6819.bin
  • %WINDIR%\5zf5thief9452.ocx
  • <SYSTEM32>\z6d49ir5253.dll
  • <SYSTEM32>\4956tr5j59z.bin
  • <SYSTEM32>\25673zot-a-vir9s5e7.exe
  • %WINDIR%\1989zspamb5t675.ocx
  • %WINDIR%\973not5a-virus471z.exe
  • %WINDIR%\5504worm90z.bin
  • <SYSTEM32>\6df15teal9z5.dll
  • <SYSTEM32>\z646troj9d5.bin
  • %WINDIR%\2dfzp9ware2575.dll
  • <SYSTEM32>\465aspzw9re55.ocx
  • <SYSTEM32>\54770wz9m475.ocx
  • <SYSTEM32>\6c95addwarz259.cpl
  • %WINDIR%\zf59thief2124.bin
  • <SYSTEM32>\7c95stealz5689.cpl
  • <SYSTEM32>\773bthi591z69.cpl
  • <SYSTEM32>\5356zspambo95e7.ocx
  • <SYSTEM32>\759asp9waze30295.bin
  • <SYSTEM32>\1194thi5922z8.cpl
  • %WINDIR%\297z9troj5a5.exe
  • <SYSTEM32>\59259zroj55b.cpl
  • <SYSTEM32>\7849th5eat2995z.cpl
  • %WINDIR%\25595zpambot3f9.cpl
  • %WINDIR%\96370sz5379.ocx
  • %WINDIR%\3z953troj562.ocx
  • %WINDIR%\38b0thzeat91215.exe
  • %WINDIR%\5f66adzware297.exe
  • <SYSTEM32>\27z29s5y41f.cpl
  • <SYSTEM32>\37zbspars52977.dll
  • %WINDIR%\1682sz5w9re2934.cpl
  • <SYSTEM32>\15570not59-virzscc.ocx
  • %WINDIR%\z885s95al1730.dll
  • <SYSTEM32>\29538hackt5ol9d2z.exe
  • %WINDIR%\17975trzj599.dll
  • %WINDIR%\50921not-a-virusaz.ocx
  • <SYSTEM32>\29afdownload9rz655.bin
  • %WINDIR%\26d5ad9ware95z.bin
  • %WINDIR%\6637zr5964e.cpl
  • %WINDIR%\2d79baz5door758.bin
  • <SYSTEM32>\31597troj2zb5.exe
  • %WINDIR%\16559troz19c.bin
  • %WINDIR%\8164not-95virus678z.dll
  • <SYSTEM32>\17193not-5zvir9s73d.dll
  • <SYSTEM32>\4506sp9rse2031z.dll
  • %WINDIR%\7bc9down5ozder1756.dll
  • %WINDIR%\9c90thief95z.cpl
  • <SYSTEM32>\3be1downloader95z6.exe
  • %WINDIR%\7ecbaddware2956z.cpl
  • <SYSTEM32>\9801s5z528.dll
  • %WINDIR%\62a4zhreat518929.bin
  • %WINDIR%\41d15ownzoader9488.exe
  • %WINDIR%\1a9fstezl10335.bin
  • <SYSTEM32>\29312spz5be.dll
  • <SYSTEM32>\76azdownlo9d5r2846.ocx
  • <SYSTEM32>\z5eedownloader3259.cpl
  • %WINDIR%\3998w5zm439.bin
  • %WINDIR%\3174threaz54829.ocx
  • <SYSTEM32>\8903no9-z-virus556.dll
  • %WINDIR%\7992backdoor2z55.exe
  • <SYSTEM32>\4z85s95ware1534.ocx
  • <SYSTEM32>\35999a5ztool583.cpl
  • %WINDIR%\6397backdoor19z15.dll
  • <SYSTEM32>\6cz8spa5se2292.exe
  • %WINDIR%\6f97th5ef2943z.ocx
  • %WINDIR%\13599worm32z.cpl
  • <SYSTEM32>\693at5rzat9729.exe
  • %WINDIR%\195759rzs29e.exe
  • <SYSTEM32>\402fa9dwzre75.ocx
  • <SYSTEM32>\7d8dzh5e9952.ocx
  • <SYSTEM32>\6899zownl5ader929.exe
  • <SYSTEM32>\28075hacktoo95z5.cpl
  • <SYSTEM32>\3a5z9pyware3162.cpl
  • <SYSTEM32>\1327spaz9e9375.dll
  • %WINDIR%\50339zrus2ce.bin
  • <SYSTEM32>\25570wo9m50z.exe
  • <SYSTEM32>\578z5hackto9l33f.bin
  • %WINDIR%\39bcthiefz953.exe
  • <SYSTEM32>\34959hi5fz80.exe
  • <SYSTEM32>\41df9h5eaz23131.exe
  • <SYSTEM32>\1916thizf5014.exe
  • %WINDIR%\2e295zr2969.cpl
  • <SYSTEM32>\2ef95hzeat5096.exe
  • <SYSTEM32>\19a759eal7z9.ocx
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'Indicator' WindowName: ''

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android