マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.KillProc.55849

Added to the Dr.Web virus database: 2018-05-09

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] '"C:\DOCUME~1\%USERNAME%\LOCALS~1\Temp\ir_ext_temp_0\AutoPlay\Docs\Dos Facebook.bat"' = '"%TEMP%\ir_ext_temp_0\AutoPlay\Docs\Dos Faceb...
Modifies file system:
Creates the following files:
  • %WINDIR%\JkX.bat
  • %HOMEPATH%\Desktop\15436.virus
  • %HOMEPATH%\Desktop\27144.virus
  • %HOMEPATH%\Desktop\8710.virus
  • %HOMEPATH%\Desktop\29099.virus
  • %HOMEPATH%\Desktop\28764.virus
  • %HOMEPATH%\Desktop\18149.virus
  • %HOMEPATH%\Desktop\4754.virus
  • %HOMEPATH%\Desktop\9748.virus
  • %HOMEPATH%\Desktop\6981.virus
  • %HOMEPATH%\Desktop\1962.virus
  • %HOMEPATH%\Desktop\24217.virus
  • %HOMEPATH%\Desktop\10199.virus
  • %HOMEPATH%\Desktop\2351.virus
  • %HOMEPATH%\Desktop\23499.virus
  • %HOMEPATH%\Desktop\19431.virus
  • %HOMEPATH%\Desktop\1272.virus
  • %HOMEPATH%\Desktop\21807.virus
  • %HOMEPATH%\Desktop\23244.virus
  • %HOMEPATH%\Desktop\21078.virus
  • %HOMEPATH%\Desktop\28699.virus
  • %HOMEPATH%\Desktop\14710.virus
  • %HOMEPATH%\Desktop\27380.virus
  • %HOMEPATH%\Desktop\7121.virus
  • %HOMEPATH%\Desktop\1606.virus
  • %HOMEPATH%\Desktop\23847.virus
  • %HOMEPATH%\Desktop\18643.virus
  • %HOMEPATH%\Desktop\23246.virus
  • %HOMEPATH%\Desktop\21005.virus
  • %HOMEPATH%\Desktop\659.virus
  • %HOMEPATH%\Desktop\17828.virus
  • %HOMEPATH%\Desktop\5635.virus
  • %HOMEPATH%\Desktop\4212.virus
  • %HOMEPATH%\Desktop\1191.virus
  • %HOMEPATH%\Desktop\16442.virus
  • %HOMEPATH%\Desktop\7506.virus
  • %HOMEPATH%\Desktop\15006.virus
  • %HOMEPATH%\Desktop\3076.virus
  • %HOMEPATH%\Desktop\4874.virus
  • %HOMEPATH%\Desktop\10675.virus
  • %HOMEPATH%\Desktop\22864.virus
  • %HOMEPATH%\Desktop\1489.virus
  • %HOMEPATH%\Desktop\23360.virus
  • %HOMEPATH%\Desktop\20205.virus
  • %HOMEPATH%\Desktop\18710.virus
  • %HOMEPATH%\Desktop\29547.virus
  • %HOMEPATH%\Desktop\27392.virus
  • %HOMEPATH%\Desktop\5491.virus
  • %HOMEPATH%\Desktop\11274.virus
  • %HOMEPATH%\Desktop\26141.virus
  • %HOMEPATH%\Desktop\12302.virus
  • %HOMEPATH%\Desktop\28503.virus
  • %HOMEPATH%\Desktop\24491.virus
  • %HOMEPATH%\Desktop\3727.virus
  • %HOMEPATH%\Desktop\2957.virus
  • %HOMEPATH%\Desktop\17395.virus
  • %HOMEPATH%\Desktop\27159.virus
  • %HOMEPATH%\Desktop\21679.virus
  • %HOMEPATH%\Desktop\1608.virus
  • %HOMEPATH%\Desktop\12696.virus
  • %HOMEPATH%\Desktop\14425.virus
  • %HOMEPATH%\Desktop\13335.virus
  • %HOMEPATH%\Desktop\3590.virus
  • %HOMEPATH%\Desktop\2276.virus
  • %HOMEPATH%\Desktop\29987.virus
  • %HOMEPATH%\Desktop\24327.virus
  • %HOMEPATH%\Desktop\30168.virus
  • %HOMEPATH%\Desktop\6078.virus
  • %HOMEPATH%\Desktop\10147.virus
  • %HOMEPATH%\Desktop\1407.virus
  • %HOMEPATH%\Desktop\1461.virus
  • %HOMEPATH%\Desktop\32155.virus
  • %HOMEPATH%\Desktop\15801.virus
  • %HOMEPATH%\Desktop\16154.virus
  • %HOMEPATH%\Desktop\6065.virus
  • %HOMEPATH%\Desktop\15824.virus
  • %HOMEPATH%\Desktop\18214.virus
  • %HOMEPATH%\Desktop\6041.virus
  • %HOMEPATH%\Desktop\19114.virus
  • %HOMEPATH%\Desktop\24182.virus
  • %HOMEPATH%\Desktop\24897.virus
  • %HOMEPATH%\Desktop\18467.virus
  • %HOMEPATH%\Desktop\11889.virus
  • %HOMEPATH%\Desktop\30934.virus
  • %HOMEPATH%\Desktop\28320.virus
  • %HOMEPATH%\Desktop\1359.virus
  • %HOMEPATH%\Desktop\7682.virus
  • %HOMEPATH%\Desktop\12399.virus
  • %HOMEPATH%\Desktop\22831.virus
  • %HOMEPATH%\Desktop\15967.virus
  • %HOMEPATH%\Desktop\19322.virus
  • %HOMEPATH%\Desktop\30011.virus
  • %HOMEPATH%\Desktop\27289.virus
  • %HOMEPATH%\Desktop\28125.virus
  • %HOMEPATH%\Desktop\17948.virus
  • %HOMEPATH%\Desktop\30306.virus
  • %HOMEPATH%\Desktop\6091.virus
  • %HOMEPATH%\Desktop\6066.virus
  • %HOMEPATH%\Desktop\31426.virus
  • %HOMEPATH%\Desktop\21566.virus
  • %HOMEPATH%\Desktop\24642.virus
  • %HOMEPATH%\Desktop\21153.virus
  • %HOMEPATH%\Desktop\13615.virus
  • %HOMEPATH%\Desktop\6080.virus
  • %HOMEPATH%\Desktop\8054.virus
  • %HOMEPATH%\Desktop\1749.virus
  • %HOMEPATH%\Desktop\29267.virus
  • %HOMEPATH%\Desktop\16749.virus
  • %HOMEPATH%\Desktop\16805.virus
  • %HOMEPATH%\Desktop\9963.virus
  • %HOMEPATH%\Desktop\4705.virus
  • %HOMEPATH%\Desktop\25573.virus
  • %HOMEPATH%\Desktop\12162.virus
  • %HOMEPATH%\Desktop\31607.virus
  • %HOMEPATH%\Desktop\12972.virus
  • %HOMEPATH%\Desktop\28145.virus
  • %HOMEPATH%\Desktop\15404.virus
  • %HOMEPATH%\Desktop\2876.virus
  • %HOMEPATH%\Desktop\18240.virus
  • %HOMEPATH%\Desktop\25896.virus
  • %HOMEPATH%\Desktop\7411.virus
  • %HOMEPATH%\Desktop\6950.virus
  • %HOMEPATH%\Desktop\16458.virus
  • %HOMEPATH%\Desktop\9207.virus
  • %HOMEPATH%\Desktop\14182.virus
  • %HOMEPATH%\Desktop\1957.virus
  • %HOMEPATH%\Desktop\12317.virus
  • %HOMEPATH%\Desktop\407.virus
  • %HOMEPATH%\Desktop\11669.virus
  • %HOMEPATH%\Desktop\8546.virus
  • %HOMEPATH%\Desktop\22058.virus
  • %HOMEPATH%\Desktop\2356.virus
  • %HOMEPATH%\Desktop\3420.virus
  • %HOMEPATH%\Desktop\22115.virus
  • %HOMEPATH%\Desktop\17796.virus
  • %HOMEPATH%\Desktop\28877.virus
  • %HOMEPATH%\Desktop\14469.virus
  • %HOMEPATH%\Desktop\1577.virus
  • %HOMEPATH%\Desktop\11980.virus
  • %HOMEPATH%\Desktop\21979.virus
  • %HOMEPATH%\Desktop\31112.virus
  • %HOMEPATH%\Desktop\25798.virus
  • %HOMEPATH%\Desktop\15766.virus
  • %HOMEPATH%\Desktop\3526.virus
  • %HOMEPATH%\Desktop\30599.virus
  • %HOMEPATH%\Desktop\23215.virus
  • %HOMEPATH%\Desktop\22380.virus
  • %HOMEPATH%\Desktop\6377.virus
  • %HOMEPATH%\Desktop\20302.virus
  • %HOMEPATH%\Desktop\26455.virus
  • %HOMEPATH%\Desktop\9430.virus
  • %HOMEPATH%\Desktop\28016.virus
  • %HOMEPATH%\Desktop\10112.virus
  • %HOMEPATH%\Desktop\8868.virus
  • %HOMEPATH%\Desktop\21416.virus
  • %HOMEPATH%\Desktop\31854.virus
  • %HOMEPATH%\Desktop\20038.virus
  • %HOMEPATH%\Desktop\12839.virus
  • %HOMEPATH%\Desktop\12040.virus
  • %HOMEPATH%\Desktop\3315.virus
  • %HOMEPATH%\Desktop\22750.virus
  • %HOMEPATH%\Desktop\4804.virus
  • %HOMEPATH%\Desktop\9654.virus
  • %HOMEPATH%\Desktop\21539.virus
  • %HOMEPATH%\Desktop\20653.virus
  • %HOMEPATH%\Desktop\16117.virus
  • %HOMEPATH%\Desktop\4912.virus
  • %HOMEPATH%\Desktop\28048.virus
  • %HOMEPATH%\Desktop\7537.virus
  • %HOMEPATH%\Desktop\2881.virus
  • %HOMEPATH%\Desktop\5399.virus
  • %HOMEPATH%\Desktop\17014.virus
  • %HOMEPATH%\Desktop\21626.virus
  • %HOMEPATH%\Desktop\2617.virus
  • %HOMEPATH%\Desktop\3959.virus
  • %HOMEPATH%\Desktop\21954.virus
  • %HOMEPATH%\Desktop\21094.virus
  • %HOMEPATH%\Desktop\8374.virus
  • %HOMEPATH%\Desktop\2375.virus
  • %HOMEPATH%\Desktop\8296.virus
  • %HOMEPATH%\Desktop\1452.virus
  • %HOMEPATH%\Desktop\32088.virus
  • %HOMEPATH%\Desktop\10915.virus
  • %HOMEPATH%\Desktop\27876.virus
  • %HOMEPATH%\Desktop\20610.virus
  • %HOMEPATH%\Desktop\4461.virus
  • %HOMEPATH%\Desktop\10186.virus
  • %HOMEPATH%\Desktop\14447.virus
  • %HOMEPATH%\Desktop\29682.virus
  • %HOMEPATH%\Desktop\7489.virus
  • %HOMEPATH%\Desktop\7770.virus
  • %HOMEPATH%\Desktop\9087.virus
  • %HOMEPATH%\Desktop\28387.virus
  • %HOMEPATH%\Desktop\2532.virus
  • %HOMEPATH%\Desktop\14213.virus
  • %HOMEPATH%\Desktop\2620.virus
  • %HOMEPATH%\Desktop\8244.virus
  • %HOMEPATH%\Desktop\5384.virus
  • %HOMEPATH%\Desktop\18486.virus
  • %HOMEPATH%\Desktop\22956.virus
  • %HOMEPATH%\Desktop\32368.virus
  • %HOMEPATH%\Desktop\2157.virus
  • %HOMEPATH%\Desktop\17350.virus
  • %HOMEPATH%\Desktop\29873.virus
  • %HOMEPATH%\Desktop\16539.virus
  • %HOMEPATH%\Desktop\22863.virus
  • %HOMEPATH%\Desktop\12642.virus
  • %HOMEPATH%\Desktop\13850.virus
  • %HOMEPATH%\Desktop\9976.virus
  • %HOMEPATH%\Desktop\30125.virus
  • %HOMEPATH%\Desktop\18175.virus
  • %HOMEPATH%\Desktop\24756.virus
  • %HOMEPATH%\Desktop\10206.virus
  • %HOMEPATH%\Desktop\25366.virus
  • %HOMEPATH%\Desktop\18729.virus
  • %HOMEPATH%\Desktop\21431.virus
  • %HOMEPATH%\Desktop\31828.virus
  • %HOMEPATH%\Desktop\2334.virus
  • %HOMEPATH%\Desktop\6580.virus
  • %HOMEPATH%\Desktop\14386.virus
  • %HOMEPATH%\Desktop\18578.virus
  • %HOMEPATH%\Desktop\17050.virus
  • %HOMEPATH%\Desktop\2556.virus
  • %HOMEPATH%\Desktop\12366.virus
  • %HOMEPATH%\Desktop\5280.virus
  • %HOMEPATH%\Desktop\24908.virus
  • %HOMEPATH%\Desktop\14799.virus
  • %HOMEPATH%\Desktop\2477.virus
  • %HOMEPATH%\Desktop\3781.virus
  • %HOMEPATH%\Desktop\15109.virus
  • %HOMEPATH%\Desktop\14863.virus
  • %HOMEPATH%\Desktop\11210.virus
  • %HOMEPATH%\Desktop\24947.virus
  • %HOMEPATH%\Desktop\22574.virus
  • %HOMEPATH%\Desktop\20583.virus
  • %HOMEPATH%\Desktop\8834.virus
  • %HOMEPATH%\Desktop\32470.virus
  • %HOMEPATH%\Desktop\31966.virus
  • %HOMEPATH%\Desktop\22383.virus
  • %HOMEPATH%\Desktop\21434.virus
  • %HOMEPATH%\Desktop\12591.virus
  • %HOMEPATH%\Desktop\9411.virus
  • %HOMEPATH%\Desktop\27560.virus
  • %HOMEPATH%\Desktop\21105.virus
  • %HOMEPATH%\Desktop\32454.virus
  • %HOMEPATH%\Desktop\15204.virus
  • %HOMEPATH%\Desktop\31643.virus
  • %HOMEPATH%\Desktop\11447.virus
  • %HOMEPATH%\Desktop\14931.virus
  • %HOMEPATH%\Desktop\21838.virus
  • %HOMEPATH%\Desktop\17648.virus
  • %HOMEPATH%\Desktop\12717.virus
  • %HOMEPATH%\Desktop\1269.virus
  • %HOMEPATH%\Desktop\17469.virus
  • %HOMEPATH%\Desktop\19320.virus
  • %HOMEPATH%\Desktop\711.virus
  • %HOMEPATH%\Desktop\14670.virus
  • %HOMEPATH%\Desktop\4514.virus
  • %HOMEPATH%\Desktop\12819.virus
  • %HOMEPATH%\Desktop\2161.virus
  • %HOMEPATH%\Desktop\20062.virus
  • %HOMEPATH%\Desktop\9652.virus
  • %HOMEPATH%\Desktop\13170.virus
  • %HOMEPATH%\Desktop\28204.virus
  • %HOMEPATH%\Desktop\3384.virus
  • %HOMEPATH%\Desktop\14009.virus
  • %HOMEPATH%\Desktop\7811.virus
  • %HOMEPATH%\Desktop\21548.virus
  • %HOMEPATH%\Desktop\17921.virus
  • %HOMEPATH%\Desktop\11485.virus
  • %HOMEPATH%\Desktop\19716.virus
  • %HOMEPATH%\Desktop\19184.virus
  • %HOMEPATH%\Desktop\13220.virus
  • %HOMEPATH%\Desktop\4315.virus
  • %HOMEPATH%\Desktop\23266.virus
  • %HOMEPATH%\Desktop\6752.virus
  • %HOMEPATH%\Desktop\22382.virus
  • %HOMEPATH%\Desktop\4430.virus
  • %HOMEPATH%\Desktop\22338.virus
  • %HOMEPATH%\Desktop\22790.virus
  • %HOMEPATH%\Desktop\12362.virus
  • %HOMEPATH%\Desktop\12027.virus
  • %HOMEPATH%\Desktop\24776.virus
  • %HOMEPATH%\Desktop\15767.virus
  • %HOMEPATH%\Desktop\18807.virus
  • %HOMEPATH%\Desktop\28141.virus
  • %HOMEPATH%\Desktop\3294.virus
  • %HOMEPATH%\Desktop\1256.virus
  • %HOMEPATH%\Desktop\9159.virus
  • %HOMEPATH%\Desktop\11628.virus
  • %HOMEPATH%\Desktop\4346.virus
  • %HOMEPATH%\Desktop\29781.virus
  • %HOMEPATH%\Desktop\11179.virus
  • %HOMEPATH%\Desktop\11354.virus
  • %HOMEPATH%\Desktop\6159.virus
  • %HOMEPATH%\Desktop\3174.virus
  • %HOMEPATH%\Desktop\15384.virus
  • %HOMEPATH%\Desktop\13227.virus
  • %HOMEPATH%\Desktop\1358.virus
  • %HOMEPATH%\Desktop\29109.virus
  • %HOMEPATH%\Desktop\5834.virus
  • %HOMEPATH%\Desktop\12076.virus
  • %HOMEPATH%\Desktop\25839.virus
  • %HOMEPATH%\Desktop\14568.virus
  • %HOMEPATH%\Desktop\26414.virus
  • %HOMEPATH%\Desktop\6721.virus
  • %HOMEPATH%\Desktop\11712.virus
  • %HOMEPATH%\Desktop\2152.virus
  • %HOMEPATH%\Desktop\7888.virus
  • %HOMEPATH%\Desktop\3006.virus
  • %HOMEPATH%\Desktop\12137.virus
  • %HOMEPATH%\Desktop\1419.virus
  • %HOMEPATH%\Desktop\23063.virus
  • %HOMEPATH%\Desktop\5689.virus
  • %HOMEPATH%\Desktop\28749.virus
  • %HOMEPATH%\Desktop\23506.virus
  • %HOMEPATH%\Desktop\11047.virus
  • %HOMEPATH%\Desktop\7861.virus
  • %HOMEPATH%\Desktop\5.virus
  • %HOMEPATH%\Desktop\26422.virus
  • %HOMEPATH%\Desktop\32458.virus
  • %WINDIR%\Dos FB By Ahmed.exe
  • %HOMEPATH%\Desktop\28672.virus
  • %HOMEPATH%\Desktop\16281.virus
  • %HOMEPATH%\Desktop\31498.virus
  • %HOMEPATH%\Desktop\11993.virus
  • %HOMEPATH%\Desktop\17835.virus
  • %HOMEPATH%\Desktop\15443.virus
  • %HOMEPATH%\Desktop\14917.virus
  • %HOMEPATH%\Desktop\31004.virus
  • %HOMEPATH%\Desktop\19084.virus
  • %HOMEPATH%\Desktop\4904.virus
  • %HOMEPATH%\Desktop\26779.virus
  • %HOMEPATH%\Desktop\16517.virus
  • %HOMEPATH%\Desktop\24088.virus
  • %HOMEPATH%\Desktop\17351.virus
  • %HOMEPATH%\Desktop\24042.virus
  • %HOMEPATH%\Desktop\12190.virus
  • %HOMEPATH%\Desktop\29480.virus
  • %HOMEPATH%\Desktop\25552.virus
  • %HOMEPATH%\Desktop\29954.virus
  • %HOMEPATH%\Desktop\20131.virus
  • %HOMEPATH%\Desktop\17360.virus
  • %HOMEPATH%\Desktop\8119.virus
  • %HOMEPATH%\Desktop\9471.virus
  • %HOMEPATH%\Desktop\18421.virus
  • %HOMEPATH%\Desktop\17841.virus
  • %HOMEPATH%\Desktop\4020.virus
  • %HOMEPATH%\Desktop\23874.virus
  • %HOMEPATH%\Desktop\4504.virus
  • %HOMEPATH%\Desktop\5281.virus
  • %HOMEPATH%\Desktop\13737.virus
  • %HOMEPATH%\Desktop\31439.virus
  • %HOMEPATH%\Desktop\4226.virus
  • %HOMEPATH%\Desktop\18078.virus
  • %HOMEPATH%\Desktop\11905.virus
  • %HOMEPATH%\Desktop\19313.virus
  • %HOMEPATH%\Desktop\6846.virus
  • %HOMEPATH%\Desktop\2919.virus
  • %HOMEPATH%\Desktop\24214.virus
  • %HOMEPATH%\Desktop\20552.virus
  • %HOMEPATH%\Desktop\15318.virus
  • %HOMEPATH%\Desktop\25236.virus
  • %HOMEPATH%\Desktop\15350.virus
  • %HOMEPATH%\Desktop\25693.virus
  • %HOMEPATH%\Desktop\29591.virus
  • %HOMEPATH%\Desktop\26567.virus
  • %HOMEPATH%\Desktop\16307.virus
  • %HOMEPATH%\Desktop\11807.virus
  • %HOMEPATH%\Desktop\23257.virus
  • %HOMEPATH%\Desktop\32338.virus
  • %HOMEPATH%\Desktop\15013.virus
  • %HOMEPATH%\Desktop\6779.virus
  • %HOMEPATH%\Desktop\19278.virus
  • %HOMEPATH%\Desktop\9879.virus
  • %HOMEPATH%\Desktop\18268.virus
  • %HOMEPATH%\Desktop\788.virus
  • %HOMEPATH%\Desktop\31399.virus
  • %HOMEPATH%\Desktop\27942.virus
  • %HOMEPATH%\Desktop\10537.virus
  • %HOMEPATH%\Desktop\25277.virus
  • %HOMEPATH%\Desktop\31275.virus
  • %HOMEPATH%\Desktop\10933.virus
  • %HOMEPATH%\Desktop\28980.virus
  • %HOMEPATH%\Desktop\3357.virus
  • %HOMEPATH%\Desktop\20408.virus
  • %HOMEPATH%\Desktop\12976.virus
  • %HOMEPATH%\Desktop\23040.virus
  • %HOMEPATH%\Desktop\11050.virus
  • %HOMEPATH%\Desktop\17473.virus
  • %HOMEPATH%\Desktop\21039.virus
  • %HOMEPATH%\Desktop\6382.virus
  • %WINDIR%\Code Dos FB.exe
  • %HOMEPATH%\Desktop\19152.virus
  • %HOMEPATH%\Desktop\22012.virus
  • %HOMEPATH%\Desktop\25420.virus
  • %HOMEPATH%\Desktop\15186.virus
  • %HOMEPATH%\Desktop\10799.virus
  • %HOMEPATH%\Desktop\13364.virus
  • %HOMEPATH%\Desktop\12554.virus
  • %HOMEPATH%\Desktop\3783.virus
  • %HOMEPATH%\Desktop\330.virus
  • %WINDIR%\Dos Fb.bat
  • %HOMEPATH%\Desktop\30076.virus
  • %HOMEPATH%\Desktop\29442.virus
  • %HOMEPATH%\Desktop\18609.virus
  • %HOMEPATH%\Desktop\8968.virus
  • %HOMEPATH%\Desktop\6097.virus
  • %HOMEPATH%\Desktop\4345.virus
  • %HOMEPATH%\Desktop\12838.virus
  • %HOMEPATH%\Desktop\16035.virus
  • %HOMEPATH%\Desktop\24191.virus
  • %HOMEPATH%\Desktop\255.virus
  • %HOMEPATH%\Desktop\28844.virus
  • %HOMEPATH%\Desktop\24758.virus
  • %HOMEPATH%\Desktop\31699.virus
  • %HOMEPATH%\Desktop\26895.virus
  • %HOMEPATH%\Desktop\8067.virus
  • %HOMEPATH%\Desktop\5153.virus
  • %HOMEPATH%\Desktop\23907.virus
  • %HOMEPATH%\Desktop\32037.virus
  • %HOMEPATH%\Desktop\20179.virus
  • %HOMEPATH%\Desktop\19303.virus
  • %HOMEPATH%\Desktop\6284.virus
  • %HOMEPATH%\Desktop\21879.virus
  • %HOMEPATH%\Desktop\1487.virus
  • %HOMEPATH%\Desktop\12902.virus
  • %HOMEPATH%\Desktop\31109.virus
  • %HOMEPATH%\Desktop\4730.virus
  • %HOMEPATH%\Desktop\21064.virus
  • %HOMEPATH%\Desktop\29880.virus
  • %HOMEPATH%\Desktop\32699.virus
  • %HOMEPATH%\Desktop\16492.virus
  • %HOMEPATH%\Desktop\14693.virus
  • %HOMEPATH%\Desktop\28521.virus
  • %HOMEPATH%\Desktop\1343.virus
  • %HOMEPATH%\Desktop\10227.virus
  • %HOMEPATH%\Desktop\2935.virus
  • %HOMEPATH%\Desktop\29190.virus
  • %HOMEPATH%\Desktop\18902.virus
  • %HOMEPATH%\Desktop\2669.virus
  • %HOMEPATH%\Desktop\1671.virus
  • %HOMEPATH%\Desktop\1043.virus
  • %HOMEPATH%\Desktop\28688.virus
  • %HOMEPATH%\Desktop\21009.virus
  • %HOMEPATH%\Desktop\12172.virus
  • %HOMEPATH%\Desktop\2143.virus
  • %HOMEPATH%\Desktop\11962.virus
  • %HOMEPATH%\Desktop\16143.virus
  • %HOMEPATH%\Desktop\16288.virus
  • %HOMEPATH%\Desktop\6872.virus
  • %HOMEPATH%\Desktop\7275.virus
  • %HOMEPATH%\Desktop\20505.virus
  • %HOMEPATH%\Desktop\14118.virus
  • %HOMEPATH%\Desktop\1212.virus
  • %HOMEPATH%\Desktop\30743.virus
  • %HOMEPATH%\Desktop\26969.virus
  • %HOMEPATH%\Desktop\30950.virus
  • %HOMEPATH%\Desktop\2725.virus
  • %HOMEPATH%\Desktop\7762.virus
  • %TEMP%\ir_ext_temp_0\lua5.1.dll
  • %HOMEPATH%\Desktop\16193.virus
  • %HOMEPATH%\Desktop\27660.virus
  • %TEMP%\ir_ext_temp_0\lua51.dll
  • %HOMEPATH%\Desktop\16121.virus
  • %HOMEPATH%\Desktop\4023.virus
  • %HOMEPATH%\Desktop\5611.virus
  • %HOMEPATH%\Desktop\3226.virus
  • %HOMEPATH%\Desktop\31341.virus
  • %HOMEPATH%\Desktop\26074.virus
  • %HOMEPATH%\Desktop\4934.virus
  • %HOMEPATH%\Desktop\18377.virus
  • %TEMP%\ir_ext_temp_0\tunisia.ico
  • %HOMEPATH%\Desktop\12996.virus
  • %HOMEPATH%\Desktop\18810.virus
  • %HOMEPATH%\Desktop\361.virus
  • %HOMEPATH%\Desktop\28489.virus
  • %HOMEPATH%\Desktop\26776.virus
  • %HOMEPATH%\Desktop\3227.virus
  • %HOMEPATH%\Desktop\22799.virus
  • %HOMEPATH%\Desktop\9295.virus
  • %HOMEPATH%\Desktop\32410.virus
  • %HOMEPATH%\Desktop\17681.virus
  • %HOMEPATH%\Desktop\19782.virus
  • %HOMEPATH%\Desktop\29973.virus
  • %HOMEPATH%\Desktop\7457.virus
  • %HOMEPATH%\Desktop\23043.virus
  • %HOMEPATH%\Desktop\24575.virus
  • %HOMEPATH%\Desktop\5958.virus
  • %HOMEPATH%\Desktop\30268.virus
  • %HOMEPATH%\Desktop\11261.virus
  • %HOMEPATH%\Desktop\10894.virus
  • %HOMEPATH%\Desktop\10752.virus
  • %HOMEPATH%\Desktop\2177.virus
  • %HOMEPATH%\Desktop\26794.virus
  • %HOMEPATH%\Desktop\32102.virus
  • %HOMEPATH%\Desktop\15931.virus
  • %HOMEPATH%\Desktop\19990.virus
  • %HOMEPATH%\Desktop\26920.virus
  • %HOMEPATH%\Desktop\31933.virus
  • %HOMEPATH%\Desktop\283.virus
  • %HOMEPATH%\Desktop\30172.virus
  • %HOMEPATH%\Desktop\5973.virus
  • %HOMEPATH%\Desktop\26188.virus
  • %HOMEPATH%\Desktop\12330.virus
  • %HOMEPATH%\Desktop\29361.virus
  • %HOMEPATH%\Desktop\25492.virus
  • %HOMEPATH%\Desktop\6001.virus
  • %HOMEPATH%\Desktop\22861.virus
  • %HOMEPATH%\Desktop\7491.virus
  • %HOMEPATH%\Desktop\23932.virus
  • %HOMEPATH%\Desktop\3721.virus
  • %HOMEPATH%\Desktop\27902.virus
  • %HOMEPATH%\Desktop\16957.virus
  • %HOMEPATH%\Desktop\17862.virus
  • %HOMEPATH%\Desktop\13036.virus
  • %HOMEPATH%\Desktop\21273.virus
  • %HOMEPATH%\Desktop\17169.virus
  • %TEMP%\ir_ext_temp_0\AutoPlay\Audio\Click1.ogg
  • %HOMEPATH%\Desktop\27115.virus
  • %HOMEPATH%\Desktop\8437.virus
  • %HOMEPATH%\Desktop\9712.virus
  • %HOMEPATH%\Desktop\124.virus
  • %HOMEPATH%\Desktop\22057.virus
  • %TEMP%\ir_ext_temp_0\AutoPlay\Audio\High1.ogg
  • %HOMEPATH%\Desktop\30400.virus
  • %HOMEPATH%\Desktop\2535.virus
  • %HOMEPATH%\Desktop\21837.virus
  • %HOMEPATH%\Desktop\20893.virus
  • %HOMEPATH%\Desktop\20856.virus
  • %HOMEPATH%\Desktop\25743.virus
  • %HOMEPATH%\Desktop\18096.virus
  • %HOMEPATH%\Desktop\31553.virus
  • %HOMEPATH%\Desktop\29022.virus
  • %HOMEPATH%\Desktop\21771.virus
  • %HOMEPATH%\Desktop\12733.virus
  • %HOMEPATH%\Desktop\10541.virus
  • %HOMEPATH%\Desktop\6997.virus
  • %HOMEPATH%\Desktop\15367.virus
  • %HOMEPATH%\Desktop\812.virus
  • %HOMEPATH%\Desktop\29272.virus
  • %HOMEPATH%\Desktop\9799.virus
  • %HOMEPATH%\Desktop\26873.virus
  • %HOMEPATH%\Desktop\12037.virus
  • %HOMEPATH%\Desktop\7648.virus
  • %HOMEPATH%\Desktop\16431.virus
  • %HOMEPATH%\Desktop\6851.virus
  • %HOMEPATH%\Desktop\14441.virus
  • %HOMEPATH%\Desktop\21576.virus
  • %HOMEPATH%\Desktop\29305.virus
  • %HOMEPATH%\Desktop\4331.virus
  • %HOMEPATH%\Desktop\21038.virus
  • %HOMEPATH%\Desktop\15178.virus
  • %TEMP%\ir_ext_temp_0\autorun.exe
  • %HOMEPATH%\Desktop\19858.virus
  • %HOMEPATH%\Desktop\7327.virus
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\f.png
  • %HOMEPATH%\Desktop\1915.virus
  • %HOMEPATH%\Desktop\19545.virus
  • %HOMEPATH%\Desktop\10412.virus
  • %HOMEPATH%\Desktop\3439.virus
  • %HOMEPATH%\Desktop\14523.virus
  • %HOMEPATH%\Desktop\31604.virus
  • %HOMEPATH%\Desktop\14821.virus
  • %HOMEPATH%\Desktop\20511.virus
  • %HOMEPATH%\Desktop\24332.virus
  • %HOMEPATH%\Desktop\22335.virus
  • %HOMEPATH%\Desktop\11481.virus
  • %HOMEPATH%\Desktop\23414.virus
  • %HOMEPATH%\Desktop\29539.virus
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\Dos Facebook.bat
  • %HOMEPATH%\Desktop\24985.virus
  • %HOMEPATH%\Desktop\7970.virus
  • %HOMEPATH%\Desktop\30280.virus
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\fhe.bat
  • %HOMEPATH%\Desktop\1037.virus
  • %HOMEPATH%\Desktop\10053.virus
  • %HOMEPATH%\Desktop\3005.virus
  • %HOMEPATH%\Desktop\8055.virus
  • %TEMP%\ir_ext_temp_0\AutoPlay\Icons\tunisia.ico
  • %HOMEPATH%\Desktop\14674.virus
  • %HOMEPATH%\Desktop\27021.virus
  • %HOMEPATH%\Desktop\8133.virus
  • %HOMEPATH%\Desktop\21103.virus
  • %HOMEPATH%\Desktop\12698.virus
  • %TEMP%\ir_ext_temp_0\AutoPlay\autorun.cdd
  • %HOMEPATH%\Desktop\27035.virus
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: 'Windows Task Manager'
Creates and executes the following:
  • '%WINDIR%\Code Dos FB.exe'
  • '%WINDIR%\Dos FB By Ahmed.exe'
  • '%TEMP%\ir_ext_temp_0\autorun.exe' "SFXSOURCE:%WINDIR%\Dos FB By Ahmed.exe"
Executes the following:
  • '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\JkX.bat" "
  • '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\Dos Fb.bat" "
  • '<SYSTEM32>\cmd.exe'
  • '%WINDIR%\explorer.exe'
  • '<SYSTEM32>\calc.exe'
  • '<SYSTEM32>\taskmgr.exe'
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\ir_ext_temp_0\AutoPlay\Docs\Dos Facebook.bat" "
  • '<SYSTEM32>\cmd.exe' /c "%TEMP%\ir_ext_temp_0\AutoPlay\Docs\Dos Facebook.bat"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android