マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.MulDrop8.32921

Added to the Dr.Web virus database: 2018-07-30

Virus description added:

Technical Information

Modifies file system:
Creates the following files:
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Arabic.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\GWfilt64.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\MaxxAudioAPO20.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\MBAPO32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\MBAPO64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\MBPPCn64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\MBppld64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\MBWrp64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RAVCpl64.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RCoInst64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtCOM64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RTCOMDLL.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\APOPCH.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\FMAPO64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtkApi64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtkCfg.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtkCfg64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RTKVHD64.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtlCPAPI.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtlCPAPI64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtlUpd64.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RTPCEE64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtPgEx64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\SkyTel.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\slcshp64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\slgeq64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtkAPO64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RtkAudioService64.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\AERTSr64.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\AERTAR64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\AERTAC64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\MBWrp32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RTCOMDLL.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtHDVCpl.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtkAPO.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtkApoApi.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtkAudioService.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtkCfg.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtkCoInst.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtkPgExt.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RTKVHDA.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtlCPAPI.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RtlUpd.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\MBppld32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RTPCEE32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\slcshp32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\slgeq32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\slh36032.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\slInit32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\sltshd32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\sluapo32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\SRSHP360.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\SRSTSHD.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\SRSTSXT.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\SRSWOW.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\vncutil.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\WavesLib.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\SkyTel.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\slh36064.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\slInit64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\sltshd64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\sluapo64.dll
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp2.tmp\temp.000
  • %APPDATA%\Microsoft\Protect\CREDHIST
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\bc54eb7b13d5ec1ea733cc462bd83b84_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %TEMP%\igd6.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp5.tmp\temp.000
  • %TEMP%\_se7.tmp
  • %TEMP%\isp4.tmp\temp.000
  • %TEMP%\iss1.tmp\setup.isn
  • %TEMP%\skin8ad1.rra
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iKe8.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\Dot9.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\ctoA.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iscB.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iusC.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\IsPD.tmp
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\IsProBE.tlb
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\iKernel.rgs
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\ObjE.tmp
  • %TEMP%\1f8f.rra
  • %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\setu2452.rra
  • %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\lice24a0.rra
  • %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\core24de.rra
  • %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\Font24fe.rra
  • %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\Stri252d.rra
  • %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\isrt254c.rra
  • %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\defa25aa.rra
  • %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\_IsR25d8.rra
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\set3.tmp
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\vncutil64.exe
  • %TEMP%\iss1.tmp\setup.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\vncutil.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\SRSHP64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\SRSTSH64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\SRSTSX64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\SRSWOW64.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\vncutil64.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\Alcmtr.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\AlcWzrd.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\AMBFilt.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\AMBFt64.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\CPLUtl64.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\MicCal.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\Monfilt.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\Monft64.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RCoInst64XP.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RTCOMDLL.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RTHDCPL.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RtkAudioService.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RtkAudioService64.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RtkCoInstXP.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RTKHDA64.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RTKHDAUD.sys
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RtlCPAPI.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RTLCPL.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RtlUpd.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RtlUpd64.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\SkyTel.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\SoundMan.exe
  • %WINDIR%\RtlE350b.rra
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\MBPPCn32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\MBAPO32.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\MaxxAudioEQ.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\setup.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\setup.inx
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\setup.isn
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\setup.iss
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\setup.log
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Slovak.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Spanish.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Swedish.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Swedish_.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\TChinese.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Thai.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\SChinese.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\setup.ibt
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Turkish.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDA861A.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDACPC.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDADELL.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDAGB.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDAGW.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDAHPNB.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDALC.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDALC2.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDALC3.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDAMSI.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDARt.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\USetup.iss
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\hda32.cat
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Russian.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Portuguese.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Polish_.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\AsusSetup_Vista.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\AsusSetup_XP.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Brazil.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Config\RTHDAEQ0.dat
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Czech.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Danish.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Danish_.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\data1.cab
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\data1.hdr
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\data2.cab
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Dutch.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\engine32.cab
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\AsusSetup.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\English.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Finnish_.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\French.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\German.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Greek.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Hungarian.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Italian.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Japanese.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Korean.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\layout.bin
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Norwegian.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Norwegian_.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Polish.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Finnish.ini
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDARt9.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDASRSP.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\HDAToshiba.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\RTSndMgr.cpl
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDX01.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDX104D.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDX861A.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDXApple.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDXCPC.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDXHP880.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDXHPNB.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDXLC.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDXLC2.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDXRT.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDXSamsu.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RTKHDA64.CAT
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\RTSndMgr.cpl
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\AsusSetup.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\ChCfg.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\MSHDQFE\Win2K3\us\kb888111srvrtm.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\MSHDQFE\Win2K_XP\us\kb888111w2ksp4.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\MSHDQFE\Win2K_XP\us\kb888111xpsp1.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\MSHDQFE\Win2K_XP\us\kb888111xpsp2.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\RtlExUpd.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Setup.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\AERTACap.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\AERTARen.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\AERTSrv.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\APOPCH.exe
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\FMAPO.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\MaxxAudioAPO.dll
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDX.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDARt.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDASamsu.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDALC2.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\hda64.cat
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDX861A.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXCPC.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXDELL.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXGB.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXGW.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXHPNB.INF
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXLC.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXLC2.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXLC3.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXMSI.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXRT.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXRT9.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXSRSP.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\HDXToshiba.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista64\RTSnMg64.cpl
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\ALSndMgr.cpl
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDA.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDA01.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDA104D.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDA32.cat
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDA861A.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDAApple.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDACPC.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDAHP880.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDAHPNB.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\WDM\HDALC.inf
  • %TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Vista\MaxxAudioAPO20.dll
  • %WINDIR%\HideWin.exe
Deletes the following files:
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\set3.tmp
  • %TEMP%\igd6.tmp
  • %TEMP%\_se7.tmp
  • %TEMP%\skin8ad1.rra
  • %CommonProgramFiles%\InstallShield\Professional\RunTime\IsPD.tmp
Moves the following files:
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp2.tmp\temp.000 to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp2.tmp\setup.dll
  • from %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\defa25aa.rra to %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\default.pal
  • from %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\isrt254c.rra to %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\isrt.dll
  • from %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\Stri252d.rra to %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\StringTable-0009-English.ips
  • from %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\Font24fe.rra to %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\FontData.ini
  • from %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\core24de.rra to %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\corecomp.ini
  • from %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\lice24a0.rra to %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\license.txt
  • from %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\setu2452.rra to %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\setup.inx
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\ObjE.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\Objectps.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iusC.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iscB.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\ctoA.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\Dot9.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iKe8.tmp to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
  • from %TEMP%\isp4.tmp\temp.000 to %TEMP%\isp4.tmp\_Setup.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp5.tmp\IGdi.dll to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp5.tmp\temp.000 to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp5.tmp\IGdi.dll
  • from %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\isp2.tmp\setup.dll to %CommonProgramFiles%\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
  • from %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\_IsR25d8.rra to %TEMP%\{F4C80279-E1D6-4932-803A-A4F2499FF7C9}\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\_IsRes.dll
  • from %WINDIR%\RtlE350b.rra to %WINDIR%\RtlExUpd.dll
Miscellaneous:
Creates and executes the following:
  • '%TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Setup.exe'
  • '%TEMP%\7zS04BB4332\RealtekALC888_Audio_V51005798\Setup.exe' -deleter

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android