マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.Carberp.2675

Added to the Dr.Web virus database: 2021-02-25

Virus description added:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • <SYSTEM32>\tasks\nvngxupdatecheckdaily_{78821544-1544-1544-1544-788215441544}
Malicious functions
Injects code into
the following system processes:
  • %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
the following user processes:
  • iexplore.exe
Hooks functions
in browsers
  • firefox.exe process, nss3.dll module
  • iexplore.exe process, wininet.dll module
Searches for registry branches where third party applications store passwords
  • [<HKCU>\Software\Martin Prikryl]
  • [<HKLM>\Software\Wow6432Node\Martin Prikryl]
Reads files which store third party applications passwords
  • %LOCALAPPDATA%\google\chrome\user data\default\login data
  • %LOCALAPPDATA%\google\chrome\user data\default\web data
  • %LOCALAPPDATA%\google\chrome\user data\default\cookies
  • %APPDATA%\opera software\opera stable\login data
  • %APPDATA%\mozilla\firefox\profiles.ini
  • %APPDATA%\thunderbird\profiles.ini
  • %ProgramFiles(x86)%\steam\config\config.vdf
  • %ProgramFiles(x86)%\steam\config\dialogconfig.vdf
  • %HOMEPATH%\desktop\cveuropeo.doc
  • %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
  • %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
  • %HOMEPATH%\desktop\ovp25012015.doc
  • %HOMEPATH%\desktop\thlps_keeper_mayer_1965.docx
Modifies file system
Creates the following files
  • %TEMP%\4dd3.tmp
  • %TEMP%\tmp9aa.tmp
  • %TEMP%\tmp9a9.tmp
  • %TEMP%\tmp9a8.tmp
  • %TEMP%\tmp998.tmp
  • %TEMP%\tmp997.tmp
  • %TEMP%\tmp996.tmp
  • %TEMP%\tmp995.tmp
  • %TEMP%\tmp984.tmp
  • %TEMP%\tmp983.tmp
  • %TEMP%\tmp982.tmp
  • %TEMP%\tmp981.tmp
  • %TEMP%\tmp980.tmp
  • %TEMP%\tmp96f.tmp
  • %TEMP%\tmp9ab.tmp
  • %TEMP%\tmp96e.tmp
  • %TEMP%\tmp96c.tmp
  • %TEMP%\tmp96b.tmp
  • %TEMP%\tmp95b.tmp
  • %TEMP%\tmp95a.tmp
  • %TEMP%\tmp959.tmp
  • %TEMP%\tmp958.tmp
  • %TEMP%\tmp947.tmp
  • %TEMP%\tmp937.tmp
  • %TEMP%\tmp936.tmp
  • %TEMP%\tmp935.tmp
  • %TEMP%\tmp924.tmp
  • %TEMP%\tmp923.tmp
  • %TEMP%\tmp922.tmp
  • %TEMP%\tmp96d.tmp
  • %TEMP%\tmp9bc.tmp
  • %TEMP%\tmp9bd.tmp
  • %TEMP%\tmp9be.tmp
  • %TEMP%\tmpa67.tmp
  • %TEMP%\tmpa66.tmp
  • %TEMP%\tmpa65.tmp
  • %TEMP%\tmpa64.tmp
  • %TEMP%\tmpa54.tmp
  • %TEMP%\tmpa53.tmp
  • %TEMP%\tmpa52.tmp
  • %TEMP%\tmpa51.tmp
  • %TEMP%\tmpa50.tmp
  • %TEMP%\tmpa3f.tmp
  • %TEMP%\tmpa3e.tmp
  • %TEMP%\tmpa3d.tmp
  • %TEMP%\tmpa3c.tmp
  • %TEMP%\tmpa3b.tmp
  • %TEMP%\tmpa3a.tmp
  • %TEMP%\tmpa29.tmp
  • %TEMP%\tmpa28.tmp
  • %TEMP%\tmpa27.tmp
  • %TEMP%\tmpa26.tmp
  • %TEMP%\tmpa25.tmp
  • %TEMP%\tmpa15.tmp
  • %TEMP%\tmpa14.tmp
  • %TEMP%\tmpa13.tmp
  • %TEMP%\tmpa12.tmp
  • %TEMP%\tmpa01.tmp
  • %TEMP%\tmpa00.tmp
  • %TEMP%\tmp9ff.tmp
  • %TEMP%\tmp9c0.tmp
  • %TEMP%\tmp9bf.tmp
  • %TEMP%\tmp911.tmp
  • %TEMP%\tmpa68.tmp
  • %TEMP%\tmp910.tmp
  • %TEMP%\tmp90e.tmp
  • %TEMP%\tmpfc65.tmp
  • %TEMP%\tmpfc55.tmp
  • %TEMP%\tmpfc54.tmp
  • %TEMP%\tmpfc53.tmp
  • %TEMP%\tmpfc52.tmp
  • %TEMP%\tmpfc51.tmp
  • %TEMP%\tmpfc50.tmp
  • %TEMP%\tmpfc3f.tmp
  • %TEMP%\tmpfc3e.tmp
  • %TEMP%\tmpfc3d.tmp
  • %TEMP%\tmpfc3c.tmp
  • %TEMP%\tmpfc3b.tmp
  • %TEMP%\tmpfc2a.tmp
  • %TEMP%\tmpfc66.tmp
  • %TEMP%\tmpfc29.tmp
  • %TEMP%\tmpfc27.tmp
  • %TEMP%\tmpfc26.tmp
  • %TEMP%\tmpfc25.tmp
  • %TEMP%\tmpfc15.tmp
  • %TEMP%\tmpfc14.tmp
  • %TEMP%\tmpfc13.tmp
  • %TEMP%\tmpfc12.tmp
  • %TEMP%\tmpfc11.tmp
  • %TEMP%\tmpfc10.tmp
  • %TEMP%\tmpfbff.tmp
  • %TEMP%\tmpfbef.tmp
  • %TEMP%\tmpfbee.tmp
  • %TEMP%\tmpfbed.tmp
  • %TEMP%\tmpfc28.tmp
  • %TEMP%\tmpfc67.tmp
  • %TEMP%\tmpfc68.tmp
  • %TEMP%\tmpfc69.tmp
  • %TEMP%\tmp8fe.tmp
  • %TEMP%\tmp8fd.tmp
  • %TEMP%\tmp8fc.tmp
  • %TEMP%\tmp8fb.tmp
  • %TEMP%\tmp8ea.tmp
  • %TEMP%\tmp8e9.tmp
  • %TEMP%\tmp8e8.tmp
  • %TEMP%\tmp8e7.tmp
  • %TEMP%\tmp8c7.tmp
  • %TEMP%\tmp8a7.tmp
  • %TEMP%\tmpfcca.tmp
  • %TEMP%\tmpfcc9.tmp
  • %TEMP%\tmpfcb9.tmp
  • %TEMP%\tmpfcb8.tmp
  • %TEMP%\tmpfca7.tmp
  • %TEMP%\tmpfca6.tmp
  • %TEMP%\tmpfca5.tmp
  • %TEMP%\tmpfca4.tmp
  • %TEMP%\tmpfc93.tmp
  • %TEMP%\tmpfc92.tmp
  • %TEMP%\tmpfc91.tmp
  • %TEMP%\tmpfc90.tmp
  • %TEMP%\tmpfc80.tmp
  • %TEMP%\tmpfc7f.tmp
  • %TEMP%\tmpfc7e.tmp
  • %TEMP%\tmpfc7d.tmp
  • %TEMP%\tmpfc7c.tmp
  • %TEMP%\tmpfc7b.tmp
  • %TEMP%\tmpfc6a.tmp
  • %TEMP%\tmp90f.tmp
  • %TEMP%\tmp2a2e.tmp
  • %TEMP%\tmp2b48.tmp
  • %TEMP%\tmpa7b.tmp
  • %TEMP%\tmp2ab9.tmp
  • %TEMP%\tmp2ab8.tmp
  • %TEMP%\tmp2ab7.tmp
  • %TEMP%\tmp2aa6.tmp
  • %TEMP%\tmp2aa5.tmp
  • %TEMP%\tmp2aa4.tmp
  • %TEMP%\tmp2aa3.tmp
  • %TEMP%\tmp2aa2.tmp
  • %TEMP%\tmp2aa1.tmp
  • %TEMP%\tmp2a91.tmp
  • %TEMP%\tmp2a90.tmp
  • %TEMP%\tmp2a8f.tmp
  • %TEMP%\tmp2a8e.tmp
  • %TEMP%\tmp2aba.tmp
  • %TEMP%\tmp2a8d.tmp
  • %TEMP%\tmp2a7b.tmp
  • %TEMP%\tmp2a7a.tmp
  • %TEMP%\tmp2a79.tmp
  • %TEMP%\tmp2a69.tmp
  • %TEMP%\tmp2a68.tmp
  • %TEMP%\tmp2a67.tmp
  • %TEMP%\tmp2a66.tmp
  • %TEMP%\tmp2a55.tmp
  • %TEMP%\tmp2a54.tmp
  • %TEMP%\tmp2a43.tmp
  • %TEMP%\tmp2a42.tmp
  • %TEMP%\tmp2a41.tmp
  • %TEMP%\tmp2a40.tmp
  • %TEMP%\tmp2a8c.tmp
  • %TEMP%\tmp2abb.tmp
  • %TEMP%\tmp2abc.tmp
  • %TEMP%\tmp2abd.tmp
  • %TEMP%\tmp2b38.tmp
  • %TEMP%\tmp2b37.tmp
  • %TEMP%\tmp2b26.tmp
  • %TEMP%\tmp2b25.tmp
  • %TEMP%\tmp2b24.tmp
  • %TEMP%\tmp2b23.tmp
  • %TEMP%\tmp2b22.tmp
  • %TEMP%\tmp2b21.tmp
  • %TEMP%\tmp2b20.tmp
  • %TEMP%\tmp2b0f.tmp
  • %TEMP%\tmp2b0e.tmp
  • %TEMP%\tmp2b0d.tmp
  • %TEMP%\tmp2b0c.tmp
  • %TEMP%\tmp2b0b.tmp
  • %TEMP%\tmp2afb.tmp
  • %TEMP%\tmp2afa.tmp
  • %TEMP%\tmp2af9.tmp
  • %TEMP%\tmp2af8.tmp
  • %TEMP%\tmp2af7.tmp
  • %TEMP%\tmp2ae6.tmp
  • %TEMP%\tmp2ae5.tmp
  • %TEMP%\tmp2ae4.tmp
  • %TEMP%\tmp2ad4.tmp
  • %TEMP%\tmp2ad3.tmp
  • %TEMP%\tmp2ad2.tmp
  • %TEMP%\tmp2ad1.tmp
  • %TEMP%\tmp2ad0.tmp
  • %TEMP%\tmp2acf.tmp
  • %TEMP%\tmp2ace.tmp
  • %TEMP%\tmp2a3f.tmp
  • %TEMP%\tmpfbec.tmp
  • %TEMP%\tmp2a2f.tmp
  • %TEMP%\tmp2a2d.tmp
  • %LOCALAPPDATA%low\ldijnhaoxxl.zip
  • %LOCALAPPDATA%low\jzbyid9nv-shm
  • %LOCALAPPDATA%low\jzbyid9nv
  • %LOCALAPPDATA%low\ezadnlqug-shm
  • %LOCALAPPDATA%low\ezadnlqug
  • %LOCALAPPDATA%low\3qsy7ppgl-shm
  • %LOCALAPPDATA%low\3qsy7ppgl
  • %TEMP%\tmpaed.tmp
  • %TEMP%\tmpaec.tmp
  • %TEMP%\tmpadc.tmp
  • %TEMP%\tmpacb.tmp
  • %TEMP%\tmpaca.tmp
  • %TEMP%\tmpaba.tmp
  • %TEMP%\tmp2960.tmp
  • %TEMP%\tmpab9.tmp
  • %TEMP%\tmpab7.tmp
  • %TEMP%\tmpaa6.tmp
  • %TEMP%\tmpaa5.tmp
  • %TEMP%\tmpaa4.tmp
  • %TEMP%\tmpaa3.tmp
  • %TEMP%\tmpaa2.tmp
  • %TEMP%\tmpa91.tmp
  • %TEMP%\tmpa90.tmp
  • %TEMP%\tmpa8f.tmp
  • %TEMP%\tmpa7f.tmp
  • %TEMP%\tmpa7e.tmp
  • %TEMP%\tmpa7d.tmp
  • %TEMP%\tmpa7c.tmp
  • %TEMP%\tmpab8.tmp
  • %TEMP%\tmp2971.tmp
  • %TEMP%\tmp2981.tmp
  • %TEMP%\tmp2982.tmp
  • %TEMP%\tmp2a2c.tmp
  • %TEMP%\tmp2a2b.tmp
  • %TEMP%\tmp2a1a.tmp
  • %TEMP%\tmp2a19.tmp
  • %TEMP%\tmp2a18.tmp
  • %TEMP%\tmp2a17.tmp
  • %TEMP%\tmp2a16.tmp
  • %TEMP%\tmp2a15.tmp
  • %TEMP%\tmp2a05.tmp
  • %TEMP%\tmp2a04.tmp
  • %TEMP%\tmp29e3.tmp
  • %TEMP%\tmp29e2.tmp
  • %TEMP%\tmp29e1.tmp
  • %TEMP%\tmp29e0.tmp
  • %TEMP%\tmp29df.tmp
  • %TEMP%\tmp29cf.tmp
  • %TEMP%\tmp29be.tmp
  • %TEMP%\tmp29bd.tmp
  • %TEMP%\tmp29bc.tmp
  • %TEMP%\tmp29bb.tmp
  • %TEMP%\tmp29ab.tmp
  • %TEMP%\tmp29aa.tmp
  • %TEMP%\tmp29a9.tmp
  • %TEMP%\tmp29a8.tmp
  • %TEMP%\tmp2997.tmp
  • %TEMP%\tmp2996.tmp
  • %TEMP%\tmp2995.tmp
  • %TEMP%\tmp2994.tmp
  • %TEMP%\tmp2983.tmp
  • %TEMP%\tmpa69.tmp
  • %TEMP%\tmpa7a.tmp
  • %TEMP%\tmpfbeb.tmp
  • %TEMP%\tmpe215.tmp
  • %TEMP%\acd8.tmp.exe
  • %TEMP%\a0f5.tmp.exe
  • %LOCALAPPDATA%low\oliv4efysbj.zip
  • %LOCALAPPDATA%low\machineinfo.txt
  • %TEMP%\7c63.tmp.exe
  • %TEMP%\5562.tmp.exe
  • %LOCALAPPDATA%low\acqlc5anp-shm
  • %LOCALAPPDATA%low\acqlc5anp
  • %LOCALAPPDATA%low\3buaklzls-shm
  • %LOCALAPPDATA%low\3buaklzls
  • %LOCALAPPDATA%low\firefox_urls.txt
  • %LOCALAPPDATA%low\2tdbiyu4p-shm
  • %LOCALAPPDATA%low\2tdbiyu4p
  • %TEMP%\baec.tmp.exe
  • %LOCALAPPDATA%low\fraqbc8ws-shm
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-memory-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-localization-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-libraryloader-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-interlocked-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-handle-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l2-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-utility-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-time-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-stdio-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-runtime-l1-1-0.dll
  • %LOCALAPPDATA%low\fraqbc8ws
  • %ALLUSERSPROFILE%\q6y0s9p7y2y0s9p7y2\modf787xwomm.mod
  • %TEMP%\c00c.tmp.exe
  • %APPDATA%\edgecp\microsoftedgecps.exe
  • %TEMP%\tmpe203.tmp
  • %TEMP%\tmpe202.tmp
  • %TEMP%\tmpe1f1.tmp
  • %TEMP%\tmpe1f0.tmp
  • %TEMP%\tmpe1ef.tmp
  • %TEMP%\tmpe1ee.tmp
  • %TEMP%\tmpe1de.tmp
  • %TEMP%\tmpe1dd.tmp
  • %TEMP%\tmpe1dc.tmp
  • %TEMP%\tmpe1db.tmp
  • %TEMP%\tmpe1ca.tmp
  • %TEMP%\tmpe1c9.tmp
  • %TEMP%\tmpe1c8.tmp
  • %TEMP%\tmpe1a8.tmp
  • %TEMP%\tmpe197.tmp
  • %TEMP%\cb58.tmp-shm
  • %TEMP%\cb58.tmp
  • %TEMP%\cb47.tmp
  • %TEMP%\cb46.tmp
  • %TEMP%\cb45.tmp
  • %TEMP%\cb44.tmp
  • %TEMP%\cb33.tmp
  • %TEMP%\cb32.tmp
  • %TEMP%\cb31.tmp
  • %TEMP%\cb21.tmp
  • %TEMP%\cac2.tmp
  • %TEMP%\ca32.tmp
  • %TEMP%\ca21.tmp-shm
  • %TEMP%\ca21.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-process-l1-1-0.dll
  • %TEMP%\tmpe213.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-private-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-math-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblemarshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblehandler.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\vcruntime140.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ucrtbase.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\softokn3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\qipcap.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\prldap60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssdbm3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ih7oe4ur9pw5zj0o.zip
  • %LOCALAPPDATA%\microsoft\vault\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\policy.vpol
  • %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\2f1a6504-0641-44cf-8bb5-3612d865f2e5.vsch
  • %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\3ccd5499-87a8-4b10-a215-608888dd3b55.vsch
  • %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\breakpadinjector.dll
  • %LOCALAPPDATA%low\bbsqwy6yhk
  • %LOCALAPPDATA%low\exuieaoeii
  • %LOCALAPPDATA%low\3solbph71y
  • %LOCALAPPDATA%low\x3cf3ednhm
  • %LOCALAPPDATA%low\rqf69azbla
  • %LOCALAPPDATA%low\rywtiizs2t
  • %LOCALAPPDATA%low\1xvpfvjcrg
  • %LOCALAPPDATA%low\fraqbc8wsa
  • %LOCALAPPDATA%low\sqlite3.dll
  • %TEMP%\2ebf.tmp.exe
  • %TEMP%\273f.tmp.exe
  • %TEMP%\203c.tmp.exe
  • %APPDATA%\jaicdtr
  • %APPDATA%\frciucs
  • %LOCALAPPDATA%low\gxix4a2dre
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\freebl3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ia2marshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldap60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-locale-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-filesystem-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-environment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-convert-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-conio-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-util-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-timezone-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-sysinfo-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-profile-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-1.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processenvironment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-namedpipe-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssckbi.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nss3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\msvcp140.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozglue.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\libegl.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\lgpllibs.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldif60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-multibyte-l1-1-0.dll
  • %TEMP%\tmpe320.tmp
  • %TEMP%\tmpfbd9.tmp
  • %TEMP%\tmpe226.tmp
  • %TEMP%\tmpfb4a.tmp
  • %TEMP%\tmpfb39.tmp
  • %TEMP%\tmpfb38.tmp
  • %TEMP%\tmpfb37.tmp
  • %TEMP%\tmpfb27.tmp
  • %TEMP%\tmpfb26.tmp
  • %TEMP%\tmpfb25.tmp
  • %TEMP%\tmpfb14.tmp
  • %TEMP%\tmpfb13.tmp
  • %TEMP%\tmpfb12.tmp
  • %TEMP%\tmpfb01.tmp
  • %TEMP%\tmpfae1.tmp
  • %TEMP%\tmpe390.tmp
  • %TEMP%\tmpfb4b.tmp
  • %TEMP%\tmpe37f.tmp
  • %TEMP%\tmpe36e.tmp
  • %TEMP%\tmpe35d.tmp
  • %TEMP%\tmpe35c.tmp
  • %TEMP%\tmpe35b.tmp
  • %TEMP%\tmpe35a.tmp
  • %TEMP%\tmpe359.tmp
  • %TEMP%\tmpe348.tmp
  • %TEMP%\tmpe347.tmp
  • %TEMP%\tmpe346.tmp
  • %TEMP%\tmpe345.tmp
  • %TEMP%\tmpe335.tmp
  • %TEMP%\tmpe334.tmp
  • %TEMP%\tmpe333.tmp
  • %TEMP%\tmpe36f.tmp
  • %TEMP%\tmpfb4c.tmp
  • %TEMP%\tmpfb4d.tmp
  • %TEMP%\tmpfb4e.tmp
  • %TEMP%\tmpfbd8.tmp
  • %TEMP%\tmpfbd7.tmp
  • %TEMP%\tmpfbc6.tmp
  • %TEMP%\tmpfbc5.tmp
  • %TEMP%\tmpfbc4.tmp
  • %TEMP%\tmpfbc3.tmp
  • %TEMP%\tmpfbc2.tmp
  • %TEMP%\tmpfbb2.tmp
  • %TEMP%\tmpfbb1.tmp
  • %TEMP%\tmpfbb0.tmp
  • %TEMP%\tmpfbaf.tmp
  • %TEMP%\tmpfb9e.tmp
  • %TEMP%\tmpfb9d.tmp
  • %TEMP%\tmpfb9c.tmp
  • %TEMP%\tmpfb9b.tmp
  • %TEMP%\tmpfb9a.tmp
  • %TEMP%\tmpfb99.tmp
  • %TEMP%\tmpfb89.tmp
  • %TEMP%\tmpfb88.tmp
  • %TEMP%\tmpfb87.tmp
  • %TEMP%\tmpfb86.tmp
  • %TEMP%\tmpfb85.tmp
  • %TEMP%\tmpfb74.tmp
  • %TEMP%\tmpfb73.tmp
  • %TEMP%\tmpfb72.tmp
  • %TEMP%\tmpfb61.tmp
  • %TEMP%\tmpfb60.tmp
  • %TEMP%\tmpfb5f.tmp
  • %TEMP%\tmpfb5e.tmp
  • %TEMP%\tmpe332.tmp
  • %TEMP%\tmpfbda.tmp
  • %TEMP%\tmpe331.tmp
  • %TEMP%\tmpe31f.tmp
  • %TEMP%\tmpe2a0.tmp
  • %TEMP%\tmpe29f.tmp
  • %TEMP%\tmpe29e.tmp
  • %TEMP%\tmpe29d.tmp
  • %TEMP%\tmpe28c.tmp
  • %TEMP%\tmpe28b.tmp
  • %TEMP%\tmpe27a.tmp
  • %TEMP%\tmpe279.tmp
  • %TEMP%\tmpe278.tmp
  • %TEMP%\tmpe277.tmp
  • %TEMP%\tmpe276.tmp
  • %TEMP%\tmpe266.tmp
  • %TEMP%\tmpe265.tmp
  • %TEMP%\tmpe2a1.tmp
  • %TEMP%\tmpe264.tmp
  • %TEMP%\tmpe262.tmp
  • %TEMP%\tmpe251.tmp
  • %TEMP%\tmpe250.tmp
  • %TEMP%\tmpe24f.tmp
  • %TEMP%\tmpe24e.tmp
  • %TEMP%\tmpe24d.tmp
  • %TEMP%\tmpe23d.tmp
  • %TEMP%\tmpe23c.tmp
  • %TEMP%\tmpe23b.tmp
  • %TEMP%\tmpe23a.tmp
  • %TEMP%\tmpe229.tmp
  • %TEMP%\tmpe228.tmp
  • %TEMP%\tmpe227.tmp
  • %TEMP%\tmpe263.tmp
  • %TEMP%\tmpe2b1.tmp
  • %TEMP%\tmpe2b2.tmp
  • %TEMP%\tmpe2b3.tmp
  • %TEMP%\tmpe31e.tmp
  • %TEMP%\tmpe31d.tmp
  • %TEMP%\tmpe30d.tmp
  • %TEMP%\tmpe30c.tmp
  • %TEMP%\tmpe30b.tmp
  • %TEMP%\tmpe30a.tmp
  • %TEMP%\tmpe309.tmp
  • %TEMP%\tmpe308.tmp
  • %TEMP%\tmpe2f7.tmp
  • %TEMP%\tmpe2f6.tmp
  • %TEMP%\tmpe2f5.tmp
  • %TEMP%\tmpe2f4.tmp
  • %TEMP%\tmpe2f3.tmp
  • %TEMP%\tmpe2f2.tmp
  • %TEMP%\tmpe2f1.tmp
  • %TEMP%\tmpe2e0.tmp
  • %TEMP%\tmpe2df.tmp
  • %TEMP%\tmpe2de.tmp
  • %TEMP%\tmpe2dd.tmp
  • %TEMP%\tmpe2dc.tmp
  • %TEMP%\tmpe2db.tmp
  • %TEMP%\tmpe2cb.tmp
  • %TEMP%\tmpe2ca.tmp
  • %TEMP%\tmpe2c9.tmp
  • %TEMP%\tmpe2c8.tmp
  • %TEMP%\tmpe2c7.tmp
  • %TEMP%\tmpe2c6.tmp
  • %TEMP%\tmpe2b5.tmp
  • %TEMP%\tmpe2b4.tmp
  • %TEMP%\tmpe214.tmp
  • %TEMP%\tmp2b49.tmp
Sets the 'hidden' attribute to the following files
  • %APPDATA%\frciucs
  • %APPDATA%\jaicdtr
Deletes the following files
  • %LOCALAPPDATA%low\fraqbc8wsa
  • %TEMP%\tmp96b.tmp
  • %TEMP%\tmp95a.tmp
  • %TEMP%\tmp958.tmp
  • %TEMP%\tmp937.tmp
  • %TEMP%\tmp935.tmp
  • %TEMP%\tmp923.tmp
  • %TEMP%\tmp911.tmp
  • %TEMP%\tmp90f.tmp
  • %TEMP%\tmp8fe.tmp
  • %TEMP%\tmp8fc.tmp
  • %TEMP%\tmp8ea.tmp
  • %TEMP%\tmp8e8.tmp
  • %TEMP%\tmp8c7.tmp
  • %TEMP%\tmpfcca.tmp
  • %TEMP%\tmpfcc9.tmp
  • %TEMP%\tmpfcb8.tmp
  • %TEMP%\tmpfcb9.tmp
  • %TEMP%\tmp96d.tmp
  • %TEMP%\tmp96f.tmp
  • %TEMP%\tmpa3b.tmp
  • %TEMP%\tmpa29.tmp
  • %TEMP%\tmpa27.tmp
  • %TEMP%\tmpa25.tmp
  • %TEMP%\tmpa14.tmp
  • %TEMP%\tmpa12.tmp
  • %TEMP%\tmpa00.tmp
  • %TEMP%\tmp9be.tmp
  • %TEMP%\tmpfca5.tmp
  • %TEMP%\tmp9bc.tmp
  • %TEMP%\tmp9aa.tmp
  • %TEMP%\tmp9a8.tmp
  • %TEMP%\tmp997.tmp
  • %TEMP%\tmp995.tmp
  • %TEMP%\tmp983.tmp
  • %TEMP%\tmp981.tmp
  • %TEMP%\tmpfca7.tmp
  • %TEMP%\tmpfc93.tmp
  • %TEMP%\tmpa3f.tmp
  • %TEMP%\tmpfc10.tmp
  • %TEMP%\tmpfbeb.tmp
  • %TEMP%\tmpfbd9.tmp
  • %TEMP%\tmpfbd7.tmp
  • %TEMP%\tmpfbc5.tmp
  • %TEMP%\tmpfbc3.tmp
  • %TEMP%\tmpfbb2.tmp
  • %TEMP%\tmpfbb0.tmp
  • %TEMP%\tmpfb9e.tmp
  • %TEMP%\tmpfb9c.tmp
  • %TEMP%\tmpfb9a.tmp
  • %TEMP%\tmpfb89.tmp
  • %TEMP%\tmpfb87.tmp
  • %TEMP%\tmpfb85.tmp
  • %TEMP%\tmpfb73.tmp
  • %TEMP%\tmpfc12.tmp
  • %TEMP%\tmpfc14.tmp
  • %TEMP%\tmpfc91.tmp
  • %TEMP%\tmpfc53.tmp
  • %TEMP%\tmpfc55.tmp
  • %TEMP%\tmpfc80.tmp
  • %TEMP%\tmpfc7e.tmp
  • %TEMP%\tmpfc7c.tmp
  • %TEMP%\tmpfc6a.tmp
  • %TEMP%\tmpfc68.tmp
  • %TEMP%\tmpfc66.tmp
  • %TEMP%\tmp9c0.tmp
  • %TEMP%\tmpa3d.tmp
  • %TEMP%\tmpfbed.tmp
  • %TEMP%\tmpfc3f.tmp
  • %TEMP%\tmpfc3d.tmp
  • %TEMP%\tmpfc3b.tmp
  • %TEMP%\tmpfc29.tmp
  • %TEMP%\tmpfc27.tmp
  • %TEMP%\tmpfc25.tmp
  • %TEMP%\tmpfc51.tmp
  • %TEMP%\tmpe229.tmp
  • %TEMP%\tmpa51.tmp
  • %TEMP%\tmp2aa4.tmp
  • %TEMP%\tmp2aa2.tmp
  • %TEMP%\tmp2a91.tmp
  • %TEMP%\tmp2a8f.tmp
  • %TEMP%\tmp2a8d.tmp
  • %TEMP%\tmp2a7b.tmp
  • %TEMP%\tmp2a79.tmp
  • %TEMP%\tmp2a68.tmp
  • %TEMP%\tmp2a66.tmp
  • %TEMP%\tmp2a54.tmp
  • %TEMP%\tmp2a42.tmp
  • %TEMP%\tmp2a40.tmp
  • %TEMP%\tmp2a2f.tmp
  • %TEMP%\tmp2a2d.tmp
  • %TEMP%\tmp2a2b.tmp
  • %TEMP%\tmp2aa6.tmp
  • %TEMP%\tmp2ab8.tmp
  • %TEMP%\tmp2aba.tmp
  • %TEMP%\tmp2abc.tmp
  • %TEMP%\tmp2b38.tmp
  • %TEMP%\tmp2b37.tmp
  • %TEMP%\tmp2b26.tmp
  • %TEMP%\tmp2b24.tmp
  • %TEMP%\tmp2b22.tmp
  • %TEMP%\tmp2b20.tmp
  • %TEMP%\tmp2b0e.tmp
  • %TEMP%\tmp2a19.tmp
  • %TEMP%\tmpfb61.tmp
  • %TEMP%\tmp2af9.tmp
  • %TEMP%\tmp2af7.tmp
  • %TEMP%\tmp2ae5.tmp
  • %TEMP%\tmp2ad4.tmp
  • %TEMP%\tmp2ad2.tmp
  • %TEMP%\tmp2ad0.tmp
  • %TEMP%\tmp2ace.tmp
  • %TEMP%\tmp2afb.tmp
  • %TEMP%\tmp2a17.tmp
  • %TEMP%\tmpfbef.tmp
  • %TEMP%\tmp2a04.tmp
  • %TEMP%\tmp2996.tmp
  • %TEMP%\tmpacb.tmp
  • %TEMP%\tmpaca.tmp
  • %TEMP%\tmpab9.tmp
  • %TEMP%\tmpab7.tmp
  • %TEMP%\tmpaa5.tmp
  • %TEMP%\tmpaa3.tmp
  • %TEMP%\tmpa91.tmp
  • %TEMP%\tmpa8f.tmp
  • %TEMP%\tmpa7e.tmp
  • %TEMP%\tmpa7c.tmp
  • %TEMP%\tmpa7a.tmp
  • %TEMP%\tmpa68.tmp
  • %TEMP%\tmpa66.tmp
  • %TEMP%\tmpa64.tmp
  • %TEMP%\tmpaec.tmp
  • %TEMP%\tmpaed.tmp
  • %LOCALAPPDATA%low\3qsy7ppgl-shm
  • %LOCALAPPDATA%low\3qsy7ppgl
  • %TEMP%\tmp29e2.tmp
  • %TEMP%\tmp29e0.tmp
  • %TEMP%\tmp29cf.tmp
  • %TEMP%\tmp29bd.tmp
  • %TEMP%\tmp29bb.tmp
  • %TEMP%\tmp29aa.tmp
  • %TEMP%\tmp29a8.tmp
  • %TEMP%\tmp2a15.tmp
  • %TEMP%\tmpa53.tmp
  • %TEMP%\tmp2982.tmp
  • %TEMP%\tmp2971.tmp
  • %LOCALAPPDATA%low\ldijnhaoxxl.zip
  • %LOCALAPPDATA%low\jzbyid9nv
  • %LOCALAPPDATA%low\jzbyid9nv-shm
  • %LOCALAPPDATA%low\ezadnlqug
  • %LOCALAPPDATA%low\ezadnlqug-shm
  • %TEMP%\tmp2994.tmp
  • %TEMP%\tmpadc.tmp
  • %TEMP%\tmpfb5f.tmp
  • %TEMP%\tmpfb4e.tmp
  • %TEMP%\tmpfb4c.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-time-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-runtime-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-process-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-private-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-multibyte-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-math-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-locale-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-filesystem-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-environment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-convert-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-conio-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-util-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-timezone-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-sysinfo-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-utility-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\breakpadinjector.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\prldap60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozglue.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssdbm3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssckbi.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nss3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\msvcp140.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-interlocked-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\libegl.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\lgpllibs.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldif60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldap60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ia2marshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\freebl3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy.dll
  • %TEMP%\tmp2b48.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\qipcap.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %LOCALAPPDATA%low\3buaklzls-shm
  • %LOCALAPPDATA%low\2tdbiyu4p
  • %LOCALAPPDATA%low\2tdbiyu4p-shm
  • %LOCALAPPDATA%low\fraqbc8ws
  • %LOCALAPPDATA%low\fraqbc8ws-shm
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ih7oe4ur9pw5zj0o.zip
  • %LOCALAPPDATA%low\bbsqwy6yhk
  • %LOCALAPPDATA%low\gxix4a2dre
  • %LOCALAPPDATA%low\exuieaoeii
  • %LOCALAPPDATA%low\3solbph71y
  • %LOCALAPPDATA%low\x3cf3ednhm
  • %LOCALAPPDATA%low\rqf69azbla
  • %LOCALAPPDATA%low\rywtiizs2t
  • %LOCALAPPDATA%low\1xvpfvjcrg
  • %LOCALAPPDATA%low\acqlc5anp-shm
  • %LOCALAPPDATA%low\acqlc5anp
  • %LOCALAPPDATA%low\3buaklzls
  • %LOCALAPPDATA%low\oliv4efysbj.zip
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-profile-l1-1-0.dll
  • %LOCALAPPDATA%low\firefox_urls.txt
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-1.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processenvironment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-namedpipe-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-memory-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-localization-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-handle-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l2-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblemarshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblehandler.dll
  • %LOCALAPPDATA%low\machineinfo.txt
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-libraryloader-l1-1-0.dll
  • %TEMP%\tmp2b0c.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\softokn3.dll
  • %LOCALAPPDATA%low\sqlite3.dll
  • %TEMP%\tmpe30d.tmp
  • %TEMP%\tmpe30b.tmp
  • %TEMP%\tmpe309.tmp
  • %TEMP%\tmpe2f7.tmp
  • %TEMP%\tmpe2f5.tmp
  • %TEMP%\tmpe2f3.tmp
  • %TEMP%\tmpe2f1.tmp
  • %TEMP%\tmpe2df.tmp
  • %TEMP%\tmpe2dd.tmp
  • %TEMP%\tmpe2db.tmp
  • %TEMP%\tmpe2ca.tmp
  • %TEMP%\tmpe2c8.tmp
  • %TEMP%\tmpe2c6.tmp
  • %TEMP%\tmpe2b4.tmp
  • %TEMP%\tmpe2b2.tmp
  • %TEMP%\tmpe31e.tmp
  • %TEMP%\tmpe320.tmp
  • %TEMP%\tmpe332.tmp
  • %TEMP%\tmpe334.tmp
  • %TEMP%\tmpe29f.tmp
  • %TEMP%\tmpfb4a.tmp
  • %TEMP%\tmpfb38.tmp
  • %TEMP%\tmpfb27.tmp
  • %TEMP%\tmpfb25.tmp
  • %TEMP%\tmpfb13.tmp
  • %TEMP%\tmpfb01.tmp
  • %TEMP%\tmpe2a1.tmp
  • %TEMP%\tmpe390.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ucrtbase.dll
  • %TEMP%\tmpe36e.tmp
  • %TEMP%\tmpe35d.tmp
  • %TEMP%\tmpe35b.tmp
  • %TEMP%\tmpe359.tmp
  • %TEMP%\tmpe347.tmp
  • %TEMP%\tmpe345.tmp
  • %TEMP%\tmpe37f.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\vcruntime140.dll
  • %TEMP%\tmpe36f.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-stdio-l1-1-0.dll
  • %TEMP%\cb58.tmp
  • %TEMP%\cb58.tmp-shm
  • %TEMP%\cb47.tmp
  • %TEMP%\cb46.tmp
  • %TEMP%\cb45.tmp
  • %TEMP%\cb44.tmp
  • %TEMP%\cb33.tmp
  • %TEMP%\cb32.tmp
  • %TEMP%\cb31.tmp
  • %TEMP%\cb21.tmp
  • %TEMP%\cac2.tmp
  • %TEMP%\ca32.tmp
  • %TEMP%\ca21.tmp
  • %TEMP%\ca21.tmp-shm
  • %ALLUSERSPROFILE%\q6y0s9p7y2y0s9p7y2\modf787xwomm.mod
  • %TEMP%\tmpe1a8.tmp
  • %TEMP%\tmpe1c9.tmp
  • %TEMP%\tmpe1db.tmp
  • %TEMP%\tmpe1dd.tmp
  • %TEMP%\tmpe28b.tmp
  • %TEMP%\tmpe277.tmp
  • %TEMP%\tmpe266.tmp
  • %TEMP%\tmpe264.tmp
  • %TEMP%\tmpe262.tmp
  • %TEMP%\tmpe250.tmp
  • %TEMP%\tmpe24e.tmp
  • %TEMP%\tmpe29d.tmp
  • %TEMP%\tmpe23d.tmp
  • %TEMP%\tmpe279.tmp
  • %TEMP%\tmpe227.tmp
  • %TEMP%\tmpe215.tmp
  • %TEMP%\tmpe213.tmp
  • %TEMP%\tmpe202.tmp
  • %TEMP%\tmpe1f0.tmp
  • %TEMP%\tmpe1ee.tmp
  • %TEMP%\tmpe23b.tmp
  • %TEMP%\tmp2b49.tmp
Substitutes the following files
  • %ALLUSERSPROFILE%\q6y0s9p7y2y0s9p7y2\modf787xwomm.mod
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-locale-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-filesystem-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-environment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-convert-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-conio-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-multibyte-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-math-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-sysinfo-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-profile-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-util-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblehandler.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-private-l1-1-0.dll
  • %LOCALAPPDATA%low\fraqbc8ws-shm
  • %LOCALAPPDATA%low\fraqbc8ws
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-memory-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-localization-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-libraryloader-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-interlocked-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-handle-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l2-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-utility-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-time-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-stdio-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-runtime-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-1.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-timezone-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processenvironment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-namedpipe-l1-1-0.dll
  • %LOCALAPPDATA%low\exuieaoeii
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\qipcap.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\prldap60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssdbm3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ih7oe4ur9pw5zj0o.zip
  • %LOCALAPPDATA%low\bbsqwy6yhk
  • %LOCALAPPDATA%low\gxix4a2dre
  • %LOCALAPPDATA%low\3solbph71y
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ucrtbase.dll
  • %LOCALAPPDATA%low\x3cf3ednhm
  • %LOCALAPPDATA%low\rqf69azbla
  • %LOCALAPPDATA%low\rywtiizs2t
  • %LOCALAPPDATA%low\1xvpfvjcrg
  • %LOCALAPPDATA%low\fraqbc8wsa
  • %LOCALAPPDATA%low\sqlite3.dll
  • %LOCALAPPDATA%low\firefox_urls.txt
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-process-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\vcruntime140.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\breakpadinjector.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\softokn3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssckbi.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nss3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\msvcp140.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozglue.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\libegl.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\lgpllibs.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldif60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldap60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ia2marshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\freebl3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblemarshal.dll
  • %LOCALAPPDATA%low\machineinfo.txt
Deletes itself.
Network activity
Connects to
  • 'si####salabim.top':443
  • 'a.###ganfor.ru':443
  • '80.##.245.80':80
  • 'sk#.#huua.ru':443
  • '17#.#0.40.83':81
  • '94.##3.94.198':3214
  • 'te##te.in':443
  • 'ap#.ip.sb':443
  • '10############6831-service1002012510022020.space':80
  • 'wh###.iana.org':43
  • 'WH###.RIPE.NET':43
  • '18#.#93.88.150':80
  • '35.##4.31.241':3214
  • '3x##.oradza.ru':443
  • 'co##ris.xyz':80
TCP
HTTP GET requests
  • http://10############6831-service1002012510022020.space/raccon.exe
  • http://10############6831-service1002012510022020.space/reestr.exe
HTTP POST requests
  • http://10###########lder1002002131-service1002.space/
  • http://10##########older33417-01242510022020.space/
  • http://80.##.245.80/log/
  • http://10############6831-service1002012510022020.space/
  • http://94.###.94.198:3214/ via 94.##3.94.198
  • http://17#.#0.40.83:81/ via 17#.#0.40.83
  • http://35.###.31.241:3214/ via 35.##4.31.241
  • http://co##ris.xyz/
  • 'te##te.in':443
  • 'si####salabim.top':443
  • 'a.###ganfor.ru':443
  • 'ap#.ip.sb':443
  • 'wh###.iana.org':43
  • 'WH###.RIPE.NET':43
  • UDP
    • DNS ASK 10###########lder1002002131-service1002.space
    • DNS ASK WH###.RIPE.NET
    • DNS ASK wh###.iana.org
    • DNS ASK ap#.ip.sb
    • DNS ASK sk#.#huua.ru
    • DNS ASK a.###ganfor.ru
    • DNS ASK si####salabim.top
    • DNS ASK 3x##.oradza.ru
    • DNS ASK te##te.in
    • DNS ASK 10############5831-service1002012510022020.space
    • DNS ASK 10##########older33417-01242510022020.space
    • DNS ASK 10###########lder1002002531-service1002.space
    • DNS ASK 10###########lder1002002431-service1002.space
    • DNS ASK 10##########older3100231-service1002.space
    • DNS ASK 10###########lder1002002231-service1002.space
    • DNS ASK 10############6831-service1002012510022020.space
    • DNS ASK co##ris.xyz
    Miscellaneous
    Creates and executes the following
    • '%TEMP%\203c.tmp.exe'
    • '%TEMP%\273f.tmp.exe'
    • '%TEMP%\2ebf.tmp.exe'
    • '%TEMP%\5562.tmp.exe'
    • '%TEMP%\7c63.tmp.exe'
    • '%TEMP%\a0f5.tmp.exe'
    • '%TEMP%\acd8.tmp.exe'
    • '%TEMP%\baec.tmp.exe'
    • '%TEMP%\c00c.tmp.exe'
    • '%APPDATA%\edgecp\microsoftedgecps.exe'
    • '%APPDATA%\edgecp\microsoftedgecps.exe' ' (with hidden window)
    • '%WINDIR%\syswow64\wbem\wmic.exe' /Node:localhost /Namespace:\\root\SecurityCenter2 path AntiVirusProduct get DisplayName /FORMAT:List' (with hidden window)
    Executes the following
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe'
    • '%WINDIR%\syswow64\explorer.exe'
    • '%WINDIR%\explorer.exe'
    • '%WINDIR%\syswow64\wbem\wmic.exe' /Node:localhost /Namespace:\\root\SecurityCenter2 path AntiVirusProduct get DisplayName /FORMAT:List

    Curing recommendations

    1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
    2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
    Download Dr.Web

    Download by serial number

    Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

    After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

    Download Dr.Web

    Download by serial number

    1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
    2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
      • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
      • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
      • Switch off your device and turn it on as normal.

    Find out more about Dr.Web for Android