マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.DownLoader26.57702

Added to the Dr.Web virus database: 2018-07-14

Virus description added:

Technical Information

Modifies file system:
Creates the following files:
  • %TEMP%\1.tmp\batfile.bat
  • <SYSTEM32>\dllcache\hmmapi.dll.new
  • <SYSTEM32>\dllcache\wmm2filt.dll.new
  • <SYSTEM32>\dllcache\wmm2ext.dll.new
  • <SYSTEM32>\dllcache\wmm2eres.dll.new
  • <SYSTEM32>\dllcache\wmm2ae.dll.new
  • <SYSTEM32>\dllcache\moviemk.exe.new
  • <SYSTEM32>\dllcache\trialoc.dll.new
  • <SYSTEM32>\dllcache\wmm2fxa.dll.new
  • <SYSTEM32>\dllcache\icwutil.dll.new
  • <SYSTEM32>\dllcache\icwhelp.dll.new
  • <SYSTEM32>\dllcache\icwdl.dll.new
  • <SYSTEM32>\dllcache\icwconn.dll.new
  • <SYSTEM32>\dllcache\isignup.exe.new
  • <SYSTEM32>\dllcache\inetwiz.exe.new
  • <SYSTEM32>\dllcache\icwtutor.exe.new
  • <SYSTEM32>\dllcache\icwrmind.exe.new
  • <SYSTEM32>\dllcache\icwres.dll.new
  • <SYSTEM32>\dllcache\icwconn2.exe.new
  • <SYSTEM32>\dllcache\wmm2res.dll.new
  • <SYSTEM32>\dllcache\wmm2res2.dll.new
  • %WINDIR%\regedit.exe.new
  • %WINDIR%\notepad.exe.new
  • %WINDIR%\hh.exe.new
  • <SYSTEM32>\dllcache\hrtz.dll.new
  • <SYSTEM32>\dllcache\cmnresm.dll.new
  • <SYSTEM32>\dllcache\cmnclim.dll.new
  • <SYSTEM32>\dllcache\chkrres.dll.new
  • <SYSTEM32>\dllcache\bckg.dll.new
  • <SYSTEM32>\dllcache\chkr.dll.new
  • <SYSTEM32>\dllcache\bckgres.dll.new
  • <SYSTEM32>\dllcache\zclientm.exe.new
  • <SYSTEM32>\dllcache\shvlzm.exe.new
  • <SYSTEM32>\dllcache\rvsezm.exe.new
  • <SYSTEM32>\dllcache\hrtzzm.exe.new
  • <SYSTEM32>\dllcache\chkrzm.exe.new
  • <SYSTEM32>\dllcache\bckgzm.exe.new
  • <SYSTEM32>\dllcache\wmm2fxb.dll.new
  • <SYSTEM32>\dllcache\icwconn1.exe.new
  • <SYSTEM32>\dllcache\iexplore.exe.new
  • <SYSTEM32>\dllcache\iedw.exe.new
  • %ProgramFiles%\NetMeeting\nmft.dll.new
  • %ProgramFiles%\Outlook Express\setup50.exe.new
  • %ProgramFiles%\Outlook Express\oemig50.exe.new
  • %ProgramFiles%\Outlook Express\msimn.exe.new
  • %ProgramFiles%\NetMeeting\rrcm.dll.new
  • %ProgramFiles%\NetMeeting\nmwb.dll.new
  • %ProgramFiles%\NetMeeting\nmoldwb.dll.new
  • %ProgramFiles%\Outlook Express\wab.exe.new
  • %ProgramFiles%\Outlook Express\wabmig.exe.new
  • %ProgramFiles%\Outlook Express\msoe.dll.new
  • %ProgramFiles%\NetMeeting\nmasnt.dll.new
  • %ProgramFiles%\NetMeeting\nmas.dll.new
  • %ProgramFiles%\NetMeeting\nac.dll.new
  • %ProgramFiles%\NetMeeting\mst123.dll.new
  • %ProgramFiles%\NetMeeting\mst120.dll.new
  • %ProgramFiles%\NetMeeting\h323cc.dll.new
  • %ProgramFiles%\NetMeeting\nmchat.dll.new
  • %ProgramFiles%\Outlook Express\msoeres.dll.new
  • %ProgramFiles%\Windows NT\Accessories\wordpad.exe.new
  • %ProgramFiles%\Outlook Express\oemiglib.dll.new
  • %ProgramFiles%\Windows NT\Pinball\pinball.exe.new
  • %ProgramFiles%\Windows Media Player\mpvis.dll.new
  • %ProgramFiles%\Windows NT\htrn_jis.dll.new
  • %ProgramFiles%\Windows NT\dialer.exe.new
  • %ProgramFiles%\Windows Media Player\wmpns.dll.new
  • %ProgramFiles%\Windows Media Player\wmpband.dll.new
  • %ProgramFiles%\Windows Media Player\npwmsdrm.dll.new
  • %ProgramFiles%\Windows Media Player\npdsplay.dll.new
  • %ProgramFiles%\Windows Media Player\npdrmv2.dll.new
  • %ProgramFiles%\Windows Media Player\custsat.dll.new
  • %ProgramFiles%\Outlook Express\oeimport.dll.new
  • %ProgramFiles%\Windows Media Player\wmplayer.exe.new
  • %ProgramFiles%\Windows Media Player\setup_wm.exe.new
  • %ProgramFiles%\Windows Media Player\mplayer2.exe.new
  • %ProgramFiles%\Windows Media Player\migrate.exe.new
  • %ProgramFiles%\Outlook Express\wabimp.dll.new
  • %ProgramFiles%\Outlook Express\wabfind.dll.new
  • %ProgramFiles%\NetMeeting\dcap32.dll.new
  • %ProgramFiles%\NetMeeting\nmcom.dll.new
  • %WINDIR%\taskman.exe.new
  • <SYSTEM32>\dllcache\rvseres.dll.new
  • <SYSTEM32>\dllcache\npwmsdrm.dll.new
  • <SYSTEM32>\dllcache\npdsplay.dll.new
  • <SYSTEM32>\dllcache\npdrmv2.dll.new
  • <SYSTEM32>\dllcache\mpvis.dll.new
  • <SYSTEM32>\dllcache\custsat.dll.new
  • <SYSTEM32>\dllcache\wmplayer.exe.new
  • <SYSTEM32>\dllcache\setup_wm.exe.new
  • <SYSTEM32>\dllcache\setup50.exe.new
  • <SYSTEM32>\dllcache\mplayer2.exe.new
  • <SYSTEM32>\dllcache\wabimp.dll.new
  • <SYSTEM32>\dllcache\wabfind.dll.new
  • <SYSTEM32>\dllcache\oemiglib.dll.new
  • <SYSTEM32>\dllcache\oeimport.dll.new
  • <SYSTEM32>\dllcache\msoeres.dll.new
  • <SYSTEM32>\dllcache\msoe.dll.new
  • <SYSTEM32>\dllcache\wabmig.exe.new
  • <SYSTEM32>\dllcache\migrate.exe.new
  • <SYSTEM32>\dllcache\wab.exe.new
  • <SYSTEM32>\dllcache\wmpband.dll.new
  • <SYSTEM32>\dllcache\twunk_16.exe.new
  • <SYSTEM32>\dllcache\aclua.dll.new
  • <SYSTEM32>\dllcache\aclayers.dll.new
  • <SYSTEM32>\dllcache\vmmreg32.dll.new
  • <SYSTEM32>\dllcache\twain_32.dll.new
  • <SYSTEM32>\dllcache\twain.dll.new
  • <SYSTEM32>\dllcache\winhlp32.exe.new
  • <SYSTEM32>\dllcache\winhelp.exe.new
  • <SYSTEM32>\dllcache\dialer.exe.new
  • <SYSTEM32>\dllcache\wmpns.dll.new
  • <SYSTEM32>\dllcache\taskman.exe.new
  • <SYSTEM32>\dllcache\regedit.exe.new
  • <SYSTEM32>\dllcache\notepad.exe.new
  • <SYSTEM32>\dllcache\hh.exe.new
  • <SYSTEM32>\dllcache\pinball.exe.new
  • <SYSTEM32>\dllcache\wordpad.exe.new
  • <SYSTEM32>\dllcache\htrn_jis.dll.new
  • <SYSTEM32>\dllcache\twunk_32.exe.new
  • <SYSTEM32>\dllcache\oemig50.exe.new
  • <SYSTEM32>\dllcache\rrcm.dll.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwdl.dll.new
  • <SYSTEM32>\dllcache\shvl.dll.new
  • <SYSTEM32>\dllcache\zeeverm.dll.new
  • %WINDIR%\AppPatch\aclua.dll.new
  • %WINDIR%\AppPatch\aclayers.dll.new
  • <SYSTEM32>\dllcache\zcorem.dll.new
  • <SYSTEM32>\dllcache\uniansi.dll.new
  • <SYSTEM32>\dllcache\shvlres.dll.new
  • <SYSTEM32>\dllcache\zoneclim.dll.new
  • %WINDIR%\AppPatch\acxtrnal.dll.new
  • <SYSTEM32>\dllcache\znetm.dll.new
  • %WINDIR%\vmmreg32.dll.new
  • %WINDIR%\twain_32.dll.new
  • %WINDIR%\twain.dll.new
  • <SYSTEM32>\dllcache\hrtzres.dll.new
  • %WINDIR%\winhlp32.exe.new
  • %WINDIR%\winhelp.exe.new
  • <SYSTEM32>\dllcache\rvse.dll.new
  • <SYSTEM32>\dllcache\zonelibm.dll.new
  • <SYSTEM32>\dllcache\nmwb.dll.new
  • %WINDIR%\twunk_16.exe.new
  • %WINDIR%\AppPatch\acspecfc.dll.new
  • <SYSTEM32>\dllcache\nmoldwb.dll.new
  • <SYSTEM32>\dllcache\nmft.dll.new
  • <SYSTEM32>\dllcache\nmcom.dll.new
  • <SYSTEM32>\dllcache\nmchat.dll.new
  • <SYSTEM32>\dllcache\nmasnt.dll.new
  • <SYSTEM32>\dllcache\nmas.dll.new
  • <SYSTEM32>\dllcache\nac.dll.new
  • <SYSTEM32>\dllcache\mst123.dll.new
  • <SYSTEM32>\dllcache\mst120.dll.new
  • <SYSTEM32>\dllcache\h323cc.dll.new
  • <SYSTEM32>\dllcache\dcap32.dll.new
  • <SYSTEM32>\dllcache\confmrsl.dll.new
  • <SYSTEM32>\dllcache\callcont.dll.new
  • <SYSTEM32>\dllcache\wb32.exe.new
  • <SYSTEM32>\dllcache\conf.exe.new
  • <SYSTEM32>\dllcache\cb32.exe.new
  • %WINDIR%\twunk_32.exe.new
  • %ProgramFiles%\NetMeeting\confmrsl.dll.new
  • %ProgramFiles%\NetMeeting\callcont.dll.new
  • %ProgramFiles%\NetMeeting\wb32.exe.new
  • %CommonProgramFiles%\System\Ole DB\msdatt.dll.new
  • <SYSTEM32>\dllcache\msinfo32.exe.new
  • %CommonProgramFiles%\System\Ole DB\sqlxmlx.dll.new
  • %CommonProgramFiles%\System\Ole DB\oledb32r.dll.new
  • %CommonProgramFiles%\System\Ole DB\oledb32.dll.new
  • %CommonProgramFiles%\System\Ole DB\msxactps.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdaurl.dll.new
  • <SYSTEM32>\dllcache\spcplui.dll.new
  • <SYSTEM32>\dllcache\sapi.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdaer.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdasql.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdasc.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdaps.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdaosp.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdaorar.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdaora.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdasqlr.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdatl3.dll.new
  • <SYSTEM32>\dllcache\vgx.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdaenum.dll.new
  • <SYSTEM32>\dllcache\msadrh15.dll.new
  • <SYSTEM32>\dllcache\msadox.dll.new
  • <SYSTEM32>\dllcache\msador15.dll.new
  • <SYSTEM32>\dllcache\msadomd.dll.new
  • <SYSTEM32>\dllcache\msado15.dll.new
  • <SYSTEM32>\dllcache\msader15.dll.new
  • <SYSTEM32>\dllcache\triedit.dll.new
  • <SYSTEM32>\dllcache\msjro.dll.new
  • <SYSTEM32>\dllcache\wab32res.dll.new
  • <SYSTEM32>\dllcache\spttseng.dll.new
  • <SYSTEM32>\dllcache\spcommon.dll.new
  • <SYSTEM32>\dllcache\mssoapr.dll.new
  • <SYSTEM32>\dllcache\wisc10.dll.new
  • <SYSTEM32>\dllcache\mssoap1.dll.new
  • <SYSTEM32>\dllcache\fp4autl.dll.new
  • <SYSTEM32>\dllcache\wab32.dll.new
  • <SYSTEM32>\dllcache\directdb.dll.new
  • %CommonProgramFiles%\System\Ole DB\msdadc.dll.new
  • %CommonProgramFiles%\System\msadc\msdfmap.dll.new
  • %CommonProgramFiles%\System\wab32.dll.new
  • %CommonProgramFiles%\SpeechEngines\Microsoft\TTS\1033\spttseng.dll.new
  • %CommonProgramFiles%\SpeechEngines\Microsoft\spcommon.dll.new
  • <SYSTEM32>\dllcache\dao360.dll.new
  • %CommonProgramFiles%\MSSoap\Binaries\Resources\1033\mssoapr.dll.new
  • %CommonProgramFiles%\MSSoap\Binaries\wisc10.dll.new
  • %CommonProgramFiles%\System\wab32res.dll.new
  • %CommonProgramFiles%\MSSoap\Binaries\mssoap1.dll.new
  • %CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll.new
  • %CommonProgramFiles%\Microsoft Shared\Triedit\triedit.dll.new
  • %CommonProgramFiles%\Microsoft Shared\Speech\1033\spcplui.dll.new
  • %CommonProgramFiles%\Microsoft Shared\Speech\sapi.dll.new
  • %CommonProgramFiles%\Microsoft Shared\Speech\sapisvr.exe.new
  • %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe.new
  • %CommonProgramFiles%\Microsoft Shared\DAO\dao360.dll.new
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\bin\fp4autl.dll.new
  • %CommonProgramFiles%\System\ado\msader15.dll.new
  • %CommonProgramFiles%\System\ado\msado15.dll.new
  • %CommonProgramFiles%\System\directdb.dll.new
  • %CommonProgramFiles%\System\ado\msadomd.dll.new
  • %CommonProgramFiles%\System\msadc\msdarem.dll.new
  • %CommonProgramFiles%\System\msadc\msadcfr.dll.new
  • %CommonProgramFiles%\System\msadc\msdaprst.dll.new
  • %CommonProgramFiles%\System\msadc\msdaprsr.dll.new
  • %CommonProgramFiles%\System\msadc\msaddsr.dll.new
  • %CommonProgramFiles%\System\msadc\msadds.dll.new
  • %CommonProgramFiles%\System\msadc\msadcs.dll.new
  • %CommonProgramFiles%\System\msadc\msadcor.dll.new
  • %CommonProgramFiles%\System\msadc\msadco.dll.new
  • %CommonProgramFiles%\System\msadc\msadcf.dll.new
  • %CommonProgramFiles%\System\msadc\msdaremr.dll.new
  • %CommonProgramFiles%\System\msadc\msadcer.dll.new
  • %CommonProgramFiles%\System\msadc\msadce.dll.new
  • %CommonProgramFiles%\System\ado\msjro.dll.new
  • %CommonProgramFiles%\System\ado\msadrh15.dll.new
  • %CommonProgramFiles%\System\ado\msadox.dll.new
  • %CommonProgramFiles%\System\ado\msador15.dll.new
  • <SYSTEM32>\dllcache\msadce.dll.new
  • <SYSTEM32>\dllcache\msadcer.dll.new
  • <SYSTEM32>\dllcache\sapisvr.exe.new
  • <SYSTEM32>\dllcache\msadcf.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\shvlzm.exe.new
  • %ProgramFiles%\Movie Maker\wmm2fxb.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\rvsezm.exe.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\hrtzzm.exe.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\chkrzm.exe.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\bckgzm.exe.new
  • %ProgramFiles%\Movie Maker\wmm2res2.dll.new
  • %ProgramFiles%\Movie Maker\wmm2res.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\bckgres.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\zclientm.exe.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\bckg.dll.new
  • %ProgramFiles%\Movie Maker\wmm2ext.dll.new
  • %ProgramFiles%\Movie Maker\wmm2eres.dll.new
  • %ProgramFiles%\Movie Maker\wmm2ae.dll.new
  • %ProgramFiles%\Movie Maker\moviemk.exe.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\trialoc.dll.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwutil.dll.new
  • %ProgramFiles%\Movie Maker\wmm2filt.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\chkr.dll.new
  • %ProgramFiles%\NetMeeting\conf.exe.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwres.dll.new
  • <SYSTEM32>\dllcache\msadcfr.dll.new
  • %ProgramFiles%\NetMeeting\cb32.exe.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\zonelibm.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\zoneclim.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\znetm.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\zeeverm.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\zcorem.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\uniansi.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\shvlres.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\shvl.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\rvseres.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\rvse.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\hrtzres.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\hrtz.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\cmnresm.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\cmnclim.dll.new
  • %ProgramFiles%\MSN Gaming Zone\Windows\chkrres.dll.new
  • %ProgramFiles%\Movie Maker\wmm2fxa.dll.new
  • <SYSTEM32>\dllcache\msimn.exe.new
  • <SYSTEM32>\dllcache\acspecfc.dll.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn.dll.new
  • <SYSTEM32>\dllcache\msdaorar.dll.new
  • <SYSTEM32>\dllcache\msdaora.dll.new
  • <SYSTEM32>\dllcache\msdaer.dll.new
  • <SYSTEM32>\dllcache\msdaenum.dll.new
  • <SYSTEM32>\dllcache\msdadc.dll.new
  • <SYSTEM32>\dllcache\msdfmap.dll.new
  • <SYSTEM32>\dllcache\msdaps.dll.new
  • <SYSTEM32>\dllcache\msdaremr.dll.new
  • <SYSTEM32>\dllcache\msdaprst.dll.new
  • <SYSTEM32>\dllcache\msdaprsr.dll.new
  • <SYSTEM32>\dllcache\msaddsr.dll.new
  • <SYSTEM32>\dllcache\msadds.dll.new
  • <SYSTEM32>\dllcache\msadcs.dll.new
  • <SYSTEM32>\dllcache\msadcor.dll.new
  • <SYSTEM32>\dllcache\msadco.dll.new
  • <SYSTEM32>\dllcache\msdarem.dll.new
  • <SYSTEM32>\dllcache\msdasc.dll.new
  • <SYSTEM32>\dllcache\msdaosp.dll.new
  • <SYSTEM32>\dllcache\msdasql.dll.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exe.new
  • %ProgramFiles%\Internet Explorer\iedw.exe.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exe.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwtutor.exe.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwrmind.exe.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exe.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe.new
  • %ProgramFiles%\Internet Explorer\hmmapi.dll.new
  • %ProgramFiles%\Internet Explorer\iexplore.exe.new
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\fifo.log
  • <SYSTEM32>\dllcache\msdasqlr.dll.new
  • <SYSTEM32>\dllcache\sqlxmlx.dll.new
  • <SYSTEM32>\dllcache\oledb32r.dll.new
  • <SYSTEM32>\dllcache\oledb32.dll.new
  • <SYSTEM32>\dllcache\msxactps.dll.new
  • <SYSTEM32>\dllcache\msdaurl.dll.new
  • <SYSTEM32>\dllcache\msdatt.dll.new
  • <SYSTEM32>\dllcache\msdatl3.dll.new
  • %ProgramFiles%\Internet Explorer\Connection Wizard\icwhelp.dll.new
  • <SYSTEM32>\dllcache\acxtrnal.dll.new
Deletes the following files:
  • <Full path to file>
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v3.5.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
  • %WINDIR%\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
  • %WINDIR%\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
  • %WINDIR%\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
  • %WINDIR%\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
  • %WINDIR%\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
  • %WINDIR%\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
  • %WINDIR%\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
  • %WINDIR%\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.Xml.dll
  • %WINDIR%\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
  • %WINDIR%\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
  • %WINDIR%\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
  • %WINDIR%\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
  • %WINDIR%\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
  • %WINDIR%\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
  • %WINDIR%\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
  • %WINDIR%\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
  • %WINDIR%\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
  • %WINDIR%\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
  • %WINDIR%\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
  • %WINDIR%\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
  • %WINDIR%\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
  • %WINDIR%\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
  • %WINDIR%\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
  • %WINDIR%\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Management.Instrumentation\3.5.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Net\3.5.0.0__b03f5f7f11d50a3a\System.Net.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Entity.Design\3.5.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
  • %WINDIR%\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
  • %WINDIR%\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
  • %WINDIR%\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll
  • %WINDIR%\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
  • %WINDIR%\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
  • %WINDIR%\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
  • %WINDIR%\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
  • %WINDIR%\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
  • %WINDIR%\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
  • %WINDIR%\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
  • %WINDIR%\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msi.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msihnd.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msimsg.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msisip.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.exe
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\updspapi.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.txt
  • %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.exe
  • %WINDIR%\$NtUninstallWIC$\spuninst\updspapi.dll
  • %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.txt
  • %WINDIR%\AppPatch\AcGenral.dll
  • %WINDIR%\AppPatch\AcLayers.dll
  • %WINDIR%\AppPatch\AcLua.dll
  • %WINDIR%\AppPatch\AcSpecfc.dll
  • %WINDIR%\AppPatch\AcXtrnal.dll
  • %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
  • %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
  • %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
  • %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
  • %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\$NtUninstallKB942288-v3$\msiexec.exe
  • %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
  • %WINDIR%\win.ini
  • %WINDIR%\vb.ini
  • %WINDIR%\explorer.exe
  • %WINDIR%\hh.exe
  • %WINDIR%\NOTEPAD.EXE
  • %WINDIR%\regedit.exe
  • %WINDIR%\sfk.exe
  • %WINDIR%\sleep.exe
  • %WINDIR%\TASKMAN.EXE
  • %WINDIR%\twunk_16.exe
  • %WINDIR%\twunk_32.exe
  • %WINDIR%\winhelp.exe
  • %WINDIR%\winhlp32.exe
  • %WINDIR%\twain.dll
  • %WINDIR%\twain_32.dll
  • %WINDIR%\vmmreg32.dll
  • %WINDIR%\OEWABLog.txt
  • %WINDIR%\setuplog.txt
  • %WINDIR%\clock.avi
  • %WINDIR%\nsreg.dat
  • %WINDIR%\control.ini
  • %WINDIR%\desktop.ini
  • %WINDIR%\msdfmap.ini
  • %WINDIR%\ODBCINST.INI
  • %WINDIR%\system.ini
  • %WINDIR%\vbaddin.ini
  • %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
  • %WINDIR%\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
  • %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
  • %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
  • %WINDIR%\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
  • %WINDIR%\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
  • %WINDIR%\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
  • %WINDIR%\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
  • %WINDIR%\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
  • %WINDIR%\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
  • %WINDIR%\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
  • %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
  • %WINDIR%\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
  • %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
  • %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
  • %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
  • %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
  • %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
  • %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
  • %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
  • %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
  • %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
  • %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
  • %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Extensions.Design\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
Substitutes the following files:
  • <SYSTEM32>\dllcache\dao360.dll.new
  • <SYSTEM32>\dllcache\mplayer2.exe.new
  • <SYSTEM32>\dllcache\migrate.exe.new
  • <SYSTEM32>\dllcache\wabimp.dll.new
  • <SYSTEM32>\dllcache\wabfind.dll.new
  • <SYSTEM32>\dllcache\oemiglib.dll.new
  • <SYSTEM32>\dllcache\oeimport.dll.new
  • <SYSTEM32>\dllcache\msoeres.dll.new
  • <SYSTEM32>\dllcache\msoe.dll.new
  • <SYSTEM32>\dllcache\wabmig.exe.new
  • <SYSTEM32>\dllcache\wab.exe.new
  • <SYSTEM32>\dllcache\setup50.exe.new
  • <SYSTEM32>\dllcache\oemig50.exe.new
  • <SYSTEM32>\dllcache\msimn.exe.new
  • <SYSTEM32>\dllcache\sqlxmlx.dll.new
  • <SYSTEM32>\dllcache\oledb32r.dll.new
  • <SYSTEM32>\dllcache\oledb32.dll.new
  • <SYSTEM32>\dllcache\msxactps.dll.new
  • <SYSTEM32>\dllcache\msdaurl.dll.new
  • <SYSTEM32>\dllcache\msdatt.dll.new
  • <SYSTEM32>\dllcache\setup_wm.exe.new
  • <SYSTEM32>\dllcache\wmplayer.exe.new
  • <SYSTEM32>\dllcache\custsat.dll.new
  • <SYSTEM32>\dllcache\mpvis.dll.new
  • <SYSTEM32>\dllcache\vmmreg32.dll.new
  • <SYSTEM32>\dllcache\twain_32.dll.new
  • <SYSTEM32>\dllcache\twain.dll.new
  • <SYSTEM32>\dllcache\winhlp32.exe.new
  • <SYSTEM32>\dllcache\winhelp.exe.new
  • <SYSTEM32>\dllcache\twunk_32.exe.new
  • <SYSTEM32>\dllcache\twunk_16.exe.new
  • <SYSTEM32>\dllcache\taskman.exe.new
  • <SYSTEM32>\dllcache\regedit.exe.new
  • <SYSTEM32>\dllcache\hh.exe.new
  • <SYSTEM32>\dllcache\notepad.exe.new
  • <SYSTEM32>\dllcache\pinball.exe.new
  • <SYSTEM32>\dllcache\wordpad.exe.new
  • <SYSTEM32>\dllcache\htrn_jis.dll.new
  • <SYSTEM32>\dllcache\dialer.exe.new
  • <SYSTEM32>\dllcache\wmpns.dll.new
  • <SYSTEM32>\dllcache\wmpband.dll.new
  • <SYSTEM32>\dllcache\npwmsdrm.dll.new
  • <SYSTEM32>\dllcache\npdsplay.dll.new
  • <SYSTEM32>\dllcache\npdrmv2.dll.new
  • <SYSTEM32>\dllcache\aclayers.dll.new
  • <SYSTEM32>\dllcache\msdatl3.dll.new
  • <SYSTEM32>\dllcache\msdasqlr.dll.new
  • <SYSTEM32>\dllcache\msdasql.dll.new
  • <SYSTEM32>\dllcache\msador15.dll.new
  • <SYSTEM32>\dllcache\msadomd.dll.new
  • <SYSTEM32>\dllcache\msado15.dll.new
  • <SYSTEM32>\dllcache\msader15.dll.new
  • <SYSTEM32>\dllcache\wab32res.dll.new
  • <SYSTEM32>\dllcache\wab32.dll.new
  • <SYSTEM32>\dllcache\directdb.dll.new
  • <SYSTEM32>\dllcache\spttseng.dll.new
  • <SYSTEM32>\dllcache\spcommon.dll.new
  • <SYSTEM32>\dllcache\mssoapr.dll.new
  • <SYSTEM32>\dllcache\wisc10.dll.new
  • <SYSTEM32>\dllcache\mssoap1.dll.new
  • <SYSTEM32>\dllcache\fp4autl.dll.new
  • <SYSTEM32>\dllcache\vgx.dll.new
  • <SYSTEM32>\dllcache\triedit.dll.new
  • <SYSTEM32>\dllcache\spcplui.dll.new
  • <SYSTEM32>\dllcache\sapi.dll.new
  • <SYSTEM32>\dllcache\sapisvr.exe.new
  • <SYSTEM32>\dllcache\msinfo32.exe.new
  • <SYSTEM32>\dllcache\msadox.dll.new
  • <SYSTEM32>\dllcache\msadrh15.dll.new
  • <SYSTEM32>\dllcache\msjro.dll.new
  • <SYSTEM32>\dllcache\msadce.dll.new
  • <SYSTEM32>\dllcache\msdaps.dll.new
  • <SYSTEM32>\dllcache\msdaosp.dll.new
  • <SYSTEM32>\dllcache\msdaorar.dll.new
  • <SYSTEM32>\dllcache\msdaora.dll.new
  • <SYSTEM32>\dllcache\msdaer.dll.new
  • <SYSTEM32>\dllcache\msdaenum.dll.new
  • <SYSTEM32>\dllcache\msdadc.dll.new
  • <SYSTEM32>\dllcache\msdfmap.dll.new
  • <SYSTEM32>\dllcache\msdaremr.dll.new
  • <SYSTEM32>\dllcache\msdaprst.dll.new
  • <SYSTEM32>\dllcache\msdarem.dll.new
  • <SYSTEM32>\dllcache\msdaprsr.dll.new
  • <SYSTEM32>\dllcache\msaddsr.dll.new
  • <SYSTEM32>\dllcache\msadds.dll.new
  • <SYSTEM32>\dllcache\msadcs.dll.new
  • <SYSTEM32>\dllcache\msadcor.dll.new
  • <SYSTEM32>\dllcache\msadco.dll.new
  • <SYSTEM32>\dllcache\msadcfr.dll.new
  • <SYSTEM32>\dllcache\msadcf.dll.new
  • <SYSTEM32>\dllcache\msadcer.dll.new
  • <SYSTEM32>\dllcache\msdasc.dll.new
  • <SYSTEM32>\dllcache\aclua.dll.new
Network activity:
Connects to:
  • 'localhost':1037
  • 'sb#o.ro':80
TCP:
HTTP GET requests:
  • http://www.sb#o.ro/index.php via sb#o.ro
UDP:
  • DNS ASK www.sb#o.ro
Miscellaneous:
Searches for the following windows:
  • ClassName: '' WindowName: ''
  • ClassName: 'MS_AutodialMonitor' WindowName: ''
  • ClassName: 'MS_WebcheckMonitor' WindowName: ''
Executes the following:
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\batfile.bat" "
  • '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' "http://www.sb#o.ro/index.php"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android