マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.MulDrop8.20665

Added to the Dr.Web virus database: 2018-05-04

Virus description added:

Technical Information

Modifies file system:
Creates the following files:
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\AzMixerSel.ini
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\MBTHX32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\MBppld64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\MBPPCn64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\mbfilt64.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\MBAPO64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\MBAPO32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\MBTHX64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\MaxxAudioAPO20.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\FMAPO64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\APOPCH.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\AERTSr64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\AERTAR64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\AERTAC64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\WavesLib.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\GWfilt64.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtkAPO64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtPgEx64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RAVCpl64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtlUpd64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtlCPAPI64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtlCPAPI.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RTKVHD64.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtkCfg64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtkCfg.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\vncutil.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtkAudioService64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtkApi64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RTCOMDLL.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RtCOM64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RP3DHT64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RP3DAA64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RCoInst64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\MBWrp64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RAVBg64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SRSWOW.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtlCPAPI.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtkCoInst.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtkCfg.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtkAudioService.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtkApoApi.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtkAPO.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtHDVCpl.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtkPgExt.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtHDVBg.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RP3DHT32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RP3DAA32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\MBWrp32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\MBTHX32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\MBppld32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\MBPPCn32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RTCOMDLL.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\slcshp32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SRSTSHD.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RtlUpd.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SRSHP360.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\sluapo32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\sltshd32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\slmaxv32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\slInit32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\slh36032.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SRSTSXT.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\slgeq32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SkyTel.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SFFXSAPO.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SFFXProc.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SFFXHAPO.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SFFXDAPO.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\SFFXComm.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RTKVHDA.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RTCOMDLL.dll
  • %WINDIR%\RtlEe4f7.rra
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SFHAPO64.dll
  • %TEMP%\skin289c.rra
  • %TEMP%\iss1.tmp\setup.isn
  • %TEMP%\isp4.tmp\temp.000
  • %TEMP%\_se7.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp5.tmp\temp.000
  • %TEMP%\igd6.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iKe8.tmp
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\4eb2c4658e59854cf811e43010321300_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp2.tmp\temp.000
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\set3.tmp
  • %TEMP%\iss1.tmp\setup.ini
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\vncutil64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\vncutil.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\SoundMan.exe
  • %APPDATA%\Microsoft\Protect\CREDHIST
  • %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\setucefe.rra
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SFDAPO64.dll
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iscB.tmp
  • %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\_IsRd111.rra
  • %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\defad0e2.rra
  • %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\isrtd065.rra
  • %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\Strid027.rra
  • %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\Fontcfe8.rra
  • %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\corecfaa.rra
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\SkyTel.exe
  • %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\licecf6b.rra
  • %TEMP%\c9de.rra
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\ObjE.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\iKernel.rgs
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\IsProBE.tlb
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\IsPD.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iusC.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\Dot9.tmp
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\mbfilt32.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RtlUpd64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\AlcWzrd.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SRSWOW64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SRSTSX64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SRSTSH64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SRSHP64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\sluapo64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\sltshd64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\vncutil64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\slmaxv64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\slh36064.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\slgeq64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\slcshp64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SkyTel.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SFSAPO64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SFProc64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\slInit64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\SFComm64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RTLCPL.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\AMBFilt.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RtlCPAPI.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RTKHDAUD.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RTKHDA64.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RtkCoInstXP.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RtkAudioService64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RtkAudioService.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RtlUpd.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RTHDCPL.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RCoInst64XP.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\Monft64.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\Monfilt.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\MicCal.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\CPLUtl64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\AMBFt64.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\Alcmtr.exe
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\ctoA.tmp
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\MBAPO32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K\RtkUpd.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\hda64.cat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RTSndMgr.cpl
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\RCORES.dat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDAWU.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDAToshiba.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDATHX.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDX861A.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDASRSS.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDASRSA.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDARt9.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDARt.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDAPrmAu.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDALC3.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDALC2.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDASRSD.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXLC3.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXToshiba.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXDELL.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXTHX.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXSRSS.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXSRSD.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXSRSA.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXRT9.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXRT.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDALC.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXPrmAu.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXLC2.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXLC.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXHPNB.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXHPAI2.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXHPAI1.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXGW.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXCPC.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXCR.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDAHPNB.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K\rthdmi32.cat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\HDXATI64.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\rthdmi32.cat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\HDAATI.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\engine32.cab
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\data2.cab
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\data1.hdr
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\rthdmi64.cat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\data1.cab
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\RtHdatEx.dat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\RTEQEX2.dat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\RTEQEX1.dat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\RTEQEX0.dat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\RtDefLvl.ini
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\RTConvEQ.dat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\rtkhdaud.dat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\setup.iss
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDAHPAI1.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K64\HDXATI64.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDAGW.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDADELL.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDACR.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDACPC.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDA861A.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\hda32.cat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\HDAHPAI2.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\USetup.iss
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\setup.isn
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\setup.inx
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\setup.ini
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\setup.ibt
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\layout.bin
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K64\rthdmi64.cat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K\HDAATI.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXHPAIO.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\MaxxAudioAPO20.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RTSnMg64.cpl
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\RtkUpd64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\RtkHDM64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\RtHDMIVX.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\RHDMEx64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\RHCoInst64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\RH3DHT64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K\RHCoInstXP.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista64\RH3DAA64.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\RtkHDMI.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\RtHDMIV.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\RHDMIExt.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\RHCoInst.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\RH3DHT32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\RH3DAA32.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\Vista\RtkUpd.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\RtlExUpd.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\RCORES64.dat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K64\RHCoInst64XP.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\MaxxAudioAPO.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\FMAPO.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\APOPCH.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\AERTSrv.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\AERTARen.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\AERTACap.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Config\AzMixerSel.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Setup.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\MSHDQFE\Win2K_XP\us\kb888111xpsp2.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\MSHDQFE\Win2K_XP\us\kb888111xpsp1.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\MSHDQFE\Win2K_XP\us\kb888111w2ksp4.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\MSHDQFE\Win2K3\us\kb888111srvrtm.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K64\RtkUpd64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K64\RtkHDMIX.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\HDMI\XP2K\RtkHDMI.sys
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista\MaxxAudioEQ.dll
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\ChCfg.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDASRSA.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDALC2.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDALC.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDAHPNB.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDAHPAIO.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDAHP880.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDACPC.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDARt.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDAApple.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDA861A.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDA32.cat
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDA104D.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDA01.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDA.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\ALSndMgr.cpl
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDAAcer.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Vista64\HDXWU.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\AP\RtkDSR32.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDX.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RTSndMgr.cpl
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\RTKHDA64.CAT
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXSamsu.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXRT.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXLC2.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXLC.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\AP\RtkDSR64.exe
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXHPNB.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXHP880.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXCPC.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDXApple.inf
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDX861A.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDX104D.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDX01.INF
  • %TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\WDM\HDASamsu.inf
  • %WINDIR%\HideWin.exe
Deletes the following files:
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\set3.tmp
  • %TEMP%\igd6.tmp
  • %TEMP%\_se7.tmp
  • %TEMP%\skin289c.rra
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\IsPD.tmp
Moves the following files:
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp2.tmp\temp.000 to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp2.tmp\setup.dll
  • from %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\defad0e2.rra to %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\default.pal
  • from %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\isrtd065.rra to %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\isrt.dll
  • from %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\Strid027.rra to %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\StringTable-0009-English.ips
  • from %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\Fontcfe8.rra to %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\FontData.ini
  • from %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\corecfaa.rra to %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\corecomp.ini
  • from %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\licecf6b.rra to %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\license.txt
  • from %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\setucefe.rra to %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\setup.inx
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\ObjE.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\Objectps.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iusC.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iscB.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\ctoA.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\Dot9.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iKe8.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
  • from %TEMP%\isp4.tmp\temp.000 to %TEMP%\isp4.tmp\_Setup.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp5.tmp\IGdi.dll to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp5.tmp\temp.000 to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp5.tmp\IGdi.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp2.tmp\setup.dll to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
  • from %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\_IsRd111.rra to %TEMP%\{8B9A5407-3FFE-4224-BCDB-B480980FDF34}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\_IsRes.dll
  • from %WINDIR%\RtlEe4f7.rra to %WINDIR%\RtlExUpd.dll
Miscellaneous:
Creates and executes the following:
  • '%TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Setup.exe'
  • '%TEMP%\7zS44BE68E1\Audio_Realtek_6.0.1.5904_Win7x86x64\Setup.exe' -deleter

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android