マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話

03-6550-8770

Profile

Trojan.Siggen14.20015

Added to the Dr.Web virus database: 2021-07-02

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\Software\Classes\3XEfile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\Software\Classes\.exe] '' = 'exefile'
  • [<HKLM>\Software\Classes\exefile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\Software\Classes\.com] '' = 'comfile'
  • [<HKLM>\Software\Classes\comfile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\Software\Classes\.bat] '' = 'batfile'
  • [<HKLM>\Software\Classes\.cmd] '' = 'cmdfile'
  • [<HKLM>\Software\Classes\.pif] '' = 'piffile'
  • [<HKLM>\Software\Classes\batfile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\Software\Classes\cmdfile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\Software\Classes\piffile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\Software\Classes\telnet\shell\open\command] '' = '"<SYSTEM32>\rundll32.exe" "<SYSTEM32>\url.dll",TelnetProtocolHandler %l'
  • [<HKLM>\software\Wow6432Node\microsoft\windows nt\currentversion\winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,'
Sets the following service settings
  • [<HKLM>\SYSTEM\CurrentControlSet\services\AFD] 'Start' = '00000001'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\tdx] 'Start' = '00000001'
  • [<HKLM>\System\CurrentControlSet\Services\W32Time] 'ImagePath' = '<SYSTEM32>\svchost.exe -k LocalService'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\Wdf01000] 'ImagePath' = 'system32\drivers\Wdf01000.sys'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\Wdf01000] 'Start' = '00000000'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\WinDefend] 'ImagePath' = '<SYSTEM32>\svchost.exe -k secsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\WinDefend] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\Spooler] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\tdx] 'ImagePath' = 'system32\DRIVERS\tdx.sys'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\WinDefend\Parameters] 'ServiceDll' = '%ProgramFiles%\Windows Defender\mpsvc.dll'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\Winmgmt] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\ws2ifsl] 'Start' = '00000001'
  • [<HKLM>\System\CurrentControlSet\Services\wscsvc] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\wscsvc] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\System\CurrentControlSet\Services\wscsvc] 'ImagePath' = '<SYSTEM32>\svchost.exe -k LocalServiceNetworkRestricted'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\wuauserv] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\WinHttpAutoProxySvc] 'ImagePath' = '<SYSTEM32>\svchost.exe -k LocalService'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\Winmgmt] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\Schedule] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\seclogon] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\seclogon] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\AsyncMac] 'ImagePath' = 'system32\DRIVERS\asyncmac.sys'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\BITS] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\BridgeMP] 'ImagePath' = 'system32\DRIVERS\bridge.sys'
  • [<HKLM>\System\CurrentControlSet\Services\Browser] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\COMSysApp] 'ImagePath' = '<SYSTEM32>\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\CryptSvc] 'ImagePath' = '<SYSTEM32>\svchost.exe -k NetworkService'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\CryptSvc] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\AppMgmt] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\lanmanserver] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\System\CurrentControlSet\Services\lmhosts] 'ImagePath' = '<SYSTEM32>\svchost.exe -k LocalServiceNetworkRestricted'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\nsi] 'ImagePath' = '<SYSTEM32>\svchost.exe -k LocalService'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\nsi] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\PcaSvc] 'ImagePath' = '<SYSTEM32>\svchost.exe -k LocalSystemNetworkRestricted'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\PcaSvc] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\PolicyAgent] 'ImagePath' = '<SYSTEM32>\svchost.exe -k NetworkServiceNetworkRestricted'
  • [<HKLM>\SYSTEM\CurrentControlSet\services\RemoteAccess] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\wuauserv] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\PROCEXP113] 'ImagePath' = '<DRIVERS>\PROCEXP113.SYS'
Creates the following services
  • 'PROCEXP113' <DRIVERS>\PROCEXP113.SYS
Malicious functions
To complicate detection of its presence in the operating system,
blocks the following features:
  • System Restore (SR)
Modifies file system
Creates the following files
  • %TEMP%\7zipsfx.000\combofix_19.11.4.1.exe
  • C:\32788r22fwjfw\license\unxutilsdist.com
  • %WINDIR%\erdnt\hiv-backup\security
  • %WINDIR%\erdnt\hiv-backup\default
  • %WINDIR%\erdnt\hiv-backup\software
  • %WINDIR%\erdnt\hiv-backup\erdnt.con
  • %WINDIR%\erdnt\hiv-backup\system
  • %WINDIR%\erdnt\hiv-backup\erdnt.inf
  • %WINDIR%\erdnt\hiv-backup\bcd
  • %TEMP%\nsx760b.tmp\nsisdl.dll
  • C:\32788r22fwjfw\license\streamtools.zip
  • C:\32788r22fwjfw\license\pv_5_2_2.zip
  • C:\32788r22fwjfw\license\ncmd.cfxxe
  • C:\32788r22fwjfw\license\mtee.txt
  • C:\32788r22fwjfw\license\iexplore.exe
  • C:\32788r22fwjfw\license\firefox.exe
  • C:\32788r22fwjfw\license\dumphive-license.txt
  • C:\32788r22fwjfw\license\zip - license.txt
  • %WINDIR%\erdnt\hiv-backup\sam
  • C:\32788r22fwjfw\license\unxutilsdist.pif
  • %WINDIR%\erdnt\hiv-backup\users\00000002\ntuser.dat
  • %WINDIR%\erdnt\hiv-backup\users\00000003\ntuser.dat
  • C:\32788r22fwjfw\w7.mac
  • C:\32788r22fwjfw\nolaunch.dat
  • C:\32788r22fwjfw\setpath_n.cmd
  • C:\32788r22fwjfw\temppath.bat
  • C:\32788r22fwjfw\cmd.3xe
  • %TEMP%\nsx760b.tmp\execcmd.dll
  • C:\32788r22fwjfw\rar_sfx.cmd
  • C:\32788r22fwjfw\en-us\cmd.3xe.mui
  • %TEMP%\nsx760b.tmp\nsexec.dll
  • C:\32788r22fwjfw\vista.krl
  • C:\32788r22fwjfw\vun.dat
  • C:\32788r22fwjfw\w6432.dat
  • C:\32788r22fwjfw\desktop.ini
  • %WINDIR%\erdnt\hiv-backup\erdntdos.loc
  • %WINDIR%\erdnt\hiv-backup\erdntwin.loc
  • %WINDIR%\erdnt\hiv-backup\erdnt.exe
  • %WINDIR%\erdnt\hiv-backup\users\00000004\usrclass.dat
  • %WINDIR%\erdnt\hiv-backup\users\00000001\ntuser.dat
  • C:\32788r22fwjfw\license\unxutilsdist.html
  • C:\32788r22fwjfw\license\fi - license.txt
  • C:\32788r22fwjfw\license\extract.txt
  • C:\32788r22fwjfw\svchost.w7.x64.dat
  • C:\32788r22fwjfw\svchost.vista.dat
  • C:\32788r22fwjfw\svchost.dat
  • C:\32788r22fwjfw\svc_wht.dat
  • C:\32788r22fwjfw\srizbi.md5
  • C:\32788r22fwjfw\sqlite3.3xe
  • C:\32788r22fwjfw\setpath.3xe
  • C:\32788r22fwjfw\sed.3xe
  • C:\32788r22fwjfw\safeboot.def.vista.dat
  • C:\32788r22fwjfw\safeboot.def.dat
  • C:\32788r22fwjfw\safeboot.dat
  • C:\32788r22fwjfw\s0rt.3xe
  • C:\32788r22fwjfw\run2.sed
  • C:\32788r22fwjfw\rogues.dat
  • C:\32788r22fwjfw\rmbr.3xe
  • C:\32788r22fwjfw\restore_pt.vbs
  • C:\32788r22fwjfw\region.dat
  • C:\32788r22fwjfw\svchost.vista.x64.dat
  • C:\32788r22fwjfw\svchost.w8.dat
  • C:\32788r22fwjfw\en-us\iexplore.exe
  • C:\32788r22fwjfw\swreg.3xe
  • C:\32788r22fwjfw\license\curl - license.txt
  • C:\32788r22fwjfw\svchost.w8.x64.dat
  • C:\32788r22fwjfw\zip.3xe
  • C:\32788r22fwjfw\zhsvc.dat
  • C:\32788r22fwjfw\zdomain.dat
  • C:\32788r22fwjfw\xpreg.dat
  • C:\32788r22fwjfw\xpmcode.dat
  • C:\32788r22fwjfw\w8reg.dat
  • C:\32788r22fwjfw\pv.com
  • C:\32788r22fwjfw\w7reg.dat
  • C:\32788r22fwjfw\w7mcode.dat
  • C:\32788r22fwjfw\vistareg.dat
  • C:\32788r22fwjfw\vistamcode.dat
  • C:\32788r22fwjfw\toolbar.sed
  • C:\32788r22fwjfw\tail.3xe
  • C:\32788r22fwjfw\system_ini.dat
  • C:\32788r22fwjfw\swxcacls.3xe
  • C:\32788r22fwjfw\swsc.3xe
  • C:\32788r22fwjfw\pnp296_00
  • C:\32788r22fwjfw\svchost.w7.dat
  • C:\32788r22fwjfw\disclaimed.dat
  • C:\32788r22fwjfw\pv.txt
  • C:\combofix_19.11.4.1\cf13968.3xe
  • C:\combofix_19.11.4.1\en-us\route.3xe.mui
  • C:\combofix_19.11.4.1\en-us\regt.3xe.mui
  • C:\combofix_19.11.4.1\en-us\ping.3xe.mui
  • C:\combofix_19.11.4.1\en-us\iexplore.exe
  • C:\combofix_19.11.4.1\en-us\cscript.3xe.mui
  • C:\combofix_19.11.4.1\en-us\cmd.3xe.mui
  • C:\combofix_19.11.4.1\en-us\cf13968.3xe.mui
  • C:\combofix_19.11.4.1\en-us\attrib.3xe.mui
  • C:\32788r22fwjfw\license\sfs.bat
  • C:\32788r22fwjfw\license\sf.exe
  • C:\32788r22fwjfw\license\readme.txt
  • C:\32788r22fwjfw\license\ls.exe
  • C:\32788r22fwjfw\license\ds.exe
  • C:\32788r22fwjfw\license\cs.exe
  • C:\32788r22fwjfw\license\rs.bat
  • C:\32788r22fwjfw\license\fs.bat
  • C:\32788r22fwjfw\dirname00
  • C:\32788r22fwjfw\dirname01
  • C:\start_.cmd
  • C:\32788r22fwjfw\start_dat
  • C:\combofix_19.11.4.1\mirrors00
  • C:\combofix_19.11.4.1\n_\3809
  • C:\combofix_19.11.4.1\n_\29144
  • C:\combofix_19.11.4.1\n_\31793
  • C:\combofix_19.11.4.1\n_\pingtest
  • C:\combofix_19.11.4.1\n_\169
  • C:\combofix_19.11.4.1\n_\16117
  • C:\combofix_19.11.4.1\foreignwht
  • C:\combofix_19.11.4.1\n_\12820
  • C:\32788r22fwjfw\avwhite
  • C:\qoobox\quarantine\catchme.log
  • C:\combofix_19.11.4.1\erunt.dat
  • C:\combofix_19.11.4.1\kmd.dat
  • C:\combofix_19.11.4.1\n_\7111
  • C:\combofix_19.11.4.1\desktop.ini
  • C:\combofix_19.11.4.1\ccs.bat
  • C:\combofix_19.11.4.1\vista.krl
  • C:\combofix_19.11.4.1\n_\4919
  • C:\32788r22fwjfw\filename
  • C:\32788r22fwjfw\avblack
  • C:\32788r22fwjfw\update-cf.cmd
  • C:\32788r22fwjfw\pev.exe
  • C:\32788r22fwjfw\nircmdb.exe
  • C:\32788r22fwjfw\en-us\cf13968.3xe.mui
  • C:\32788r22fwjfw\muisubst.dat
  • C:\32788r22fwjfw\cmdmui00
  • C:\32788r22fwjfw\en-us\regt.3xe.mui
  • C:\32788r22fwjfw\en-us\route.3xe.mui
  • C:\32788r22fwjfw\en-us\ping.3xe.mui
  • C:\32788r22fwjfw\en-us\cscript.3xe.mui
  • C:\32788r22fwjfw\en-us\attrib.3xe.mui
  • C:\32788r22fwjfw\mui
  • C:\32788r22fwjfw\mui00
  • C:\32788r22fwjfw\n_\30075
  • %TEMP%\nsx760b.tmp\nsprocess.dll
  • C:\32788r22fwjfw\curver
  • C:\32788r22fwjfw\vercf.bat
  • C:\32788r22fwjfw\set.txt
  • C:\32788r22fwjfw\n_\19557
  • C:\32788r22fwjfw\nlscodepageacp00
  • C:\32788r22fwjfw\msname00
  • C:\32788r22fwjfw\oldsfxname00
  • C:\32788r22fwjfw\userinit00
  • C:\32788r22fwjfw\route.3xe
  • C:\32788r22fwjfw\ping.3xe
  • C:\32788r22fwjfw\cscript.3xe
  • C:\32788r22fwjfw\attrib.3xe
  • C:\32788r22fwjfw\sfx.cmd
  • C:\32788r22fwjfw\temp01
  • C:\32788r22fwjfw\set00
  • C:\32788r22fwjfw\winnt00
  • %WINDIR%\temp\udde55e.tmp
  • C:\32788r22fwjfw\pv.exe
  • C:\32788r22fwjfw\mdcheck00.dat
  • C:\32788r22fwjfw\temp00
  • <DRIVERS>\procexp113.sys
  • C:\32788r22fwjfw\handle64.exe
  • C:\32788r22fwjfw\nlslanguagedefault
  • C:\32788r22fwjfw\nlslanguage00
  • C:\32788r22fwjfw\chcp.bat
  • C:\32788r22fwjfw\mdcheck0a.dat
  • C:\32788r22fwjfw\powp.dat
  • C:\32788r22fwjfw\pevb.3xe
  • C:\32788r22fwjfw\pev.3xe
  • C:\32788r22fwjfw\find3m.bat
  • C:\32788r22fwjfw\list-c.bat
  • C:\32788r22fwjfw\list-b.bat
  • C:\32788r22fwjfw\lang.bat
  • C:\32788r22fwjfw\ksvchost.vbs
  • C:\32788r22fwjfw\kill-all.cmd
  • C:\32788r22fwjfw\knetsvcs.vbs
  • C:\32788r22fwjfw\install-rc.cmd
  • C:\32788r22fwjfw\imefile.dat
  • C:\32788r22fwjfw\gethive.cmd
  • C:\32788r22fwjfw\fin.dat
  • C:\32788r22fwjfw\filekill.3xe
  • C:\32788r22fwjfw\favoritesfile.cfx
  • C:\32788r22fwjfw\favoritefolder.cfx
  • C:\32788r22fwjfw\fkmgen.cmd
  • C:\32788r22fwjfw\fixlsp64.cmd
  • C:\32788r22fwjfw\fixlsp.bat
  • C:\32788r22fwjfw\localappdatafile.cfx
  • C:\32788r22fwjfw\list.bat
  • C:\32788r22fwjfw\localservice.dat
  • C:\32788r22fwjfw\fd-sv.cmd
  • C:\32788r22fwjfw\nirscript.dat
  • C:\32788r22fwjfw\nircmdc.3xe
  • C:\32788r22fwjfw\nircmd.chm
  • C:\32788r22fwjfw\nircmd.3xe
  • C:\32788r22fwjfw\networkservice.dat
  • C:\32788r22fwjfw\nt-os.cmd
  • C:\32788r22fwjfw\nd_64.bat
  • C:\32788r22fwjfw\nd_.bat
  • C:\32788r22fwjfw\moveit.bat
  • C:\32788r22fwjfw\pv.3xe
  • C:\32788r22fwjfw\mzchanged.dat
  • C:\32788r22fwjfw\mdwht.dat
  • C:\32788r22fwjfw\localsystemnetworkrestricted.dat
  • C:\32788r22fwjfw\localsettingsfolder.cfx
  • C:\32788r22fwjfw\localsettingsfile.cfx
  • C:\32788r22fwjfw\localservicenetworkrestricted.dat
  • C:\32788r22fwjfw\localappdatafolder.cfx
  • C:\32788r22fwjfw\osid.vbs
  • C:\32788r22fwjfw\exe.reg
  • C:\32788r22fwjfw\erunt.loc
  • C:\32788r22fwjfw\bfe.dat
  • C:\32788r22fwjfw\assoc.cmd
  • C:\32788r22fwjfw\appdatafolder.cfx
  • C:\32788r22fwjfw\appdatafile.cfx
  • C:\32788r22fwjfw\activedrv.vbs
  • C:\32788r22fwjfw\awf.cmd
  • C:\32788r22fwjfw\023w8.dat
  • C:\32788r22fwjfw\023w7.dat
  • C:\32788r22fwjfw\023v.dat
  • C:\32788r22fwjfw\023.dat
  • %TEMP%\nsx760b.tmp\banner.dll
  • %TEMP%\nsx760b.tmp\userinfo.dll
  • %TEMP%\nsx760b.tmp\vista.krl
  • %TEMP%\nsx760b.tmp\w7.mac
  • %TEMP%\nsx760b.tmp\system.dll
  • %TEMP%\nsh75fa.tmp
  • C:\32788r22fwjfw\boot-rk.cmd
  • C:\32788r22fwjfw\boot.bat
  • C:\32788r22fwjfw\bootdrv.vbs
  • C:\32788r22fwjfw\auto-rc.cmd
  • C:\32788r22fwjfw\cf-script.cmd
  • C:\32788r22fwjfw\erdntwin.loc
  • C:\32788r22fwjfw\erunt.3xe
  • C:\32788r22fwjfw\erdntdos.loc
  • C:\32788r22fwjfw\erdnt.e_e
  • C:\32788r22fwjfw\drvrun.vbs
  • C:\32788r22fwjfw\dnl.dat
  • C:\32788r22fwjfw\desktopfile.cfx
  • C:\32788r22fwjfw\delclsid64.bat
  • C:\32788r22fwjfw\p.cmd
  • C:\32788r22fwjfw\mpssvc.dat
  • C:\32788r22fwjfw\delclsid.bat
  • C:\32788r22fwjfw\cregc.cmd
  • C:\32788r22fwjfw\creg.dat
  • C:\32788r22fwjfw\create.cmd
  • C:\32788r22fwjfw\combobatch.bat
  • C:\32788r22fwjfw\combofix-download.3xe
  • C:\32788r22fwjfw\combo-fix.sys
  • C:\32788r22fwjfw\catch-sub.cmd
  • C:\32788r22fwjfw\dpf.str
  • C:\32788r22fwjfw\cregc.dat
  • C:\32788r22fwjfw\list-d.bat
  • C:\32788r22fwjfw\personalfile.cfx
  • C:\32788r22fwjfw\hidec.3xe
  • C:\32788r22fwjfw\hwid.pif
  • C:\32788r22fwjfw\handle.3xe
  • C:\32788r22fwjfw\gsar.3xe
  • C:\32788r22fwjfw\grep.3xe
  • C:\32788r22fwjfw\fl0.bat
  • C:\32788r22fwjfw\firefox.exe
  • C:\32788r22fwjfw\files.pif
  • C:\32788r22fwjfw\ffext.pif
  • C:\32788r22fwjfw\ffdefstr.dll
  • C:\32788r22fwjfw\extract.3xe
  • C:\32788r22fwjfw\embedded.sed
  • C:\32788r22fwjfw\dumphive.3xe
  • C:\32788r22fwjfw\ddsdo.sed
  • C:\32788r22fwjfw\dd.3xe
  • C:\32788r22fwjfw\clsid.c
  • C:\32788r22fwjfw\catchme.3xe
  • C:\32788r22fwjfw\c.bat
  • C:\32788r22fwjfw\iexplore.exe
  • C:\32788r22fwjfw\image001.gif
  • C:\32788r22fwjfw\pausep.3xe
  • C:\32788r22fwjfw\md5sum00.pif
  • C:\32788r22fwjfw\mtee.3xe
  • C:\32788r22fwjfw\nir.pif
  • C:\32788r22fwjfw\netsvc.xp.dat
  • C:\32788r22fwjfw\netsvc.vista.dat
  • C:\32788r22fwjfw\netsvc.dat
  • C:\32788r22fwjfw\netsvc.bad.dat
  • C:\32788r22fwjfw\ndis_combofix.dat
  • C:\32788r22fwjfw\ncmd.com
  • C:\32788r22fwjfw\history.bat
  • C:\32788r22fwjfw\badclsid.c
  • C:\32788r22fwjfw\personalfolder.cfx
  • C:\32788r22fwjfw\mbr.chk
  • C:\32788r22fwjfw\mbr.3xe
  • C:\32788r22fwjfw\lnkread.vbs
  • C:\32788r22fwjfw\katch.cmd
  • C:\32788r22fwjfw\iphlpsvc.w8.dat
  • C:\32788r22fwjfw\iphlpsvc.w7.dat
  • C:\32788r22fwjfw\iphlpsvc.vista.dat
  • C:\32788r22fwjfw\md5sum.pif
  • C:\combofix_19.11.4.1\n_\19953
  • C:\combofix_19.11.4.1\mirrors
  • C:\32788r22fwjfw\asp.str
  • C:\32788r22fwjfw\srestore.cmd
  • C:\32788r22fwjfw\rust.str
  • C:\32788r22fwjfw\rkey.cmd
  • C:\32788r22fwjfw\regscan64.cmd
  • C:\32788r22fwjfw\regscan.cmd
  • C:\32788r22fwjfw\regdo.sed
  • C:\32788r22fwjfw\rnullfix64.3xe
  • C:\32788r22fwjfw\regdacl.sed
  • C:\32788r22fwjfw\rclink.dat
  • C:\32788r22fwjfw\purity.dat
  • C:\32788r22fwjfw\programsfolder.cfx
  • C:\32788r22fwjfw\programsfile.cfx
  • C:\32788r22fwjfw\profilesfolder.cfx
  • C:\32788r22fwjfw\profilesfile.cfx
  • C:\32788r22fwjfw\prep.inf
  • C:\32788r22fwjfw\policies.dat
  • C:\32788r22fwjfw\safeboot.def.w8.dat
  • C:\32788r22fwjfw\setenvmt.bat
  • C:\32788r22fwjfw\safeboot.def.w7.dat
  • C:\32788r22fwjfw\shaccess.dat
  • C:\32788r22fwjfw\appinit.bad
  • C:\32788r22fwjfw\snapshot.cmd
  • C:\32788r22fwjfw\xpsboot.reg
  • C:\32788r22fwjfw\wmi_rem.vbs
  • C:\32788r22fwjfw\vwintemp.dacl
  • C:\32788r22fwjfw\vipev.dat
  • C:\32788r22fwjfw\vinfo2
  • C:\32788r22fwjfw\vinfo
  • C:\32788r22fwjfw\vinfo3
  • C:\32788r22fwjfw\av.vbs
  • C:\32788r22fwjfw\av.cmd
  • C:\32788r22fwjfw\undow7_xp.dat
  • C:\32788r22fwjfw\templatesfolder.cfx
  • C:\32788r22fwjfw\templatesfile.cfx
  • C:\32788r22fwjfw\svcdrv.vbs
  • C:\32788r22fwjfw\suppscan.cmd
  • C:\32788r22fwjfw\startupfile.cfx
  • C:\32788r22fwjfw\startmenufolder.cfx
  • C:\32788r22fwjfw\startmenufile.cfx
  • C:\32788r22fwjfw\vbr.pif
  • C:\combofix_19.11.4.1\n_\13772
Deletes the following files
  • C:\32788r22fwjfw\nirscript.dat
  • C:\32788r22fwjfw\temp01
  • C:\32788r22fwjfw\msname00
  • C:\32788r22fwjfw\avwhite
  • C:\32788r22fwjfw\avblack
  • C:\32788r22fwjfw\filename
  • C:\32788r22fwjfw\dirname00
  • C:\32788r22fwjfw\dirname01
  • C:\32788r22fwjfw\oldsfxname00
  • C:\32788r22fwjfw\nolaunch.dat
  • C:\32788r22fwjfw\firefox.exe
  • C:\32788r22fwjfw\undow7_xp.dat
  • C:\32788r22fwjfw\en-us\iexplore.exe
  • C:\32788r22fwjfw\license\cs.exe
  • C:\32788r22fwjfw\license\ds.exe
  • C:\32788r22fwjfw\license\extract.txt
  • C:\32788r22fwjfw\license\firefox.exe
  • C:\32788r22fwjfw\license\fs.bat
  • C:\32788r22fwjfw\license\iexplore.exe
  • C:\32788r22fwjfw\license\ls.exe
  • C:\32788r22fwjfw\license\mtee.txt
  • C:\32788r22fwjfw\license\ncmd.cfxxe
  • C:\32788r22fwjfw\license\pv_5_2_2.zip
  • C:\32788r22fwjfw\license\readme.txt
  • C:\32788r22fwjfw\license\rs.bat
  • C:\32788r22fwjfw\license\sfs.bat
  • C:\32788r22fwjfw\n_\19557
  • C:\32788r22fwjfw\n_\30075
  • C:\start_.cmd
  • C:\combofix_19.11.4.1\p.cmd
  • C:\32788r22fwjfw\set00
  • C:\combofix_19.11.4.1\cmd.3xe
  • C:\32788r22fwjfw\userinit00
  • C:\32788r22fwjfw\nircmd.chm
  • C:\32788r22fwjfw\temppath.bat
  • C:\32788r22fwjfw\pnp296_00
  • C:\32788r22fwjfw\winnt00
  • %WINDIR%\temp\udde55e.tmp
  • C:\32788r22fwjfw\curver
  • %TEMP%\nsx760b.tmp\banner.dll
  • %TEMP%\nsx760b.tmp\execcmd.dll
  • %TEMP%\nsx760b.tmp\nsexec.dll
  • %TEMP%\nsx760b.tmp\nsisdl.dll
  • %TEMP%\nsx760b.tmp\nsprocess.dll
  • %TEMP%\nsx760b.tmp\system.dll
  • %TEMP%\nsx760b.tmp\userinfo.dll
  • %TEMP%\nsx760b.tmp\vista.krl
  • %TEMP%\nsx760b.tmp\w7.mac
  • %TEMP%\7zipsfx.000\combofix_19.11.4.1.exe
  • C:\32788r22fwjfw\mui00
  • C:\32788r22fwjfw\cmdmui00
  • C:\32788r22fwjfw\muisubst.dat
  • C:\32788r22fwjfw\md5sum00.pif
  • C:\32788r22fwjfw\ksvchost.vbs
  • C:\32788r22fwjfw\pv.txt
  • C:\32788r22fwjfw\nlscodepageacp00
  • C:\32788r22fwjfw\nlslanguage00
  • <DRIVERS>\procexp113.sys
  • C:\32788r22fwjfw\handle64.exe
  • C:\32788r22fwjfw\temp00
  • C:\32788r22fwjfw\mdcheck00.dat
  • C:\32788r22fwjfw\mdcheck0a.dat
  • C:\32788r22fwjfw\dnl.dat
  • C:\32788r22fwjfw\set.txt
  • C:\combofix_19.11.4.1\mirrors00
Moves the following files
  • from C:\32788r22fwjfw\pv.exe to C:\32788r22fwjfw\pv.3xe
  • from C:\32788r22fwjfw\pv.com to C:\combofix_19.11.4.1\pv.com
  • from C:\32788r22fwjfw\rar_sfx.cmd to C:\combofix_19.11.4.1\rar_sfx.cmd
  • from C:\32788r22fwjfw\rclink.dat to C:\combofix_19.11.4.1\rclink.dat
  • from C:\32788r22fwjfw\regdacl.sed to C:\combofix_19.11.4.1\regdacl.sed
  • from C:\32788r22fwjfw\regdo.sed to C:\combofix_19.11.4.1\regdo.sed
  • from C:\32788r22fwjfw\region.dat to C:\combofix_19.11.4.1\region.dat
  • from C:\32788r22fwjfw\regscan.cmd to C:\combofix_19.11.4.1\regscan.cmd
  • from C:\32788r22fwjfw\regscan64.cmd to C:\combofix_19.11.4.1\regscan64.cmd
  • from C:\32788r22fwjfw\restore_pt.vbs to C:\combofix_19.11.4.1\restore_pt.vbs
  • from C:\32788r22fwjfw\rkey.cmd to C:\combofix_19.11.4.1\rkey.cmd
  • from C:\32788r22fwjfw\p.cmd to C:\combofix_19.11.4.1\p.cmd
  • from C:\32788r22fwjfw\rmbr.3xe to C:\combofix_19.11.4.1\rmbr.3xe
  • from C:\32788r22fwjfw\rogues.dat to C:\combofix_19.11.4.1\rogues.dat
  • from C:\32788r22fwjfw\route.3xe to C:\combofix_19.11.4.1\route.3xe
  • from C:\32788r22fwjfw\run2.sed to C:\combofix_19.11.4.1\run2.sed
  • from C:\32788r22fwjfw\rust.str to C:\combofix_19.11.4.1\rust.str
  • from C:\32788r22fwjfw\s0rt.3xe to C:\combofix_19.11.4.1\s0rt.3xe
  • from C:\32788r22fwjfw\safeboot.dat to C:\combofix_19.11.4.1\safeboot.dat
  • from C:\32788r22fwjfw\safeboot.def.dat to C:\combofix_19.11.4.1\safeboot.def.dat
  • from C:\32788r22fwjfw\safeboot.def.vista.dat to C:\combofix_19.11.4.1\safeboot.def.vista.dat
  • from C:\32788r22fwjfw\safeboot.def.w7.dat to C:\combofix_19.11.4.1\safeboot.def.w7.dat
  • from C:\32788r22fwjfw\safeboot.def.w8.dat to C:\combofix_19.11.4.1\safeboot.def.w8.dat
  • from C:\32788r22fwjfw\purity.dat to C:\combofix_19.11.4.1\purity.dat
  • from C:\32788r22fwjfw\pv.3xe to C:\combofix_19.11.4.1\pv.3xe
  • from C:\32788r22fwjfw\programsfolder.cfx to C:\combofix_19.11.4.1\programsfolder.cfx
  • from C:\32788r22fwjfw\programsfile.cfx to C:\combofix_19.11.4.1\programsfile.cfx
  • from C:\32788r22fwjfw\profilesfolder.cfx to C:\combofix_19.11.4.1\profilesfolder.cfx
  • from C:\32788r22fwjfw\netsvc.dat to C:\combofix_19.11.4.1\netsvc.dat
  • from C:\32788r22fwjfw\netsvc.vista.dat to C:\combofix_19.11.4.1\netsvc.vista.dat
  • from C:\32788r22fwjfw\netsvc.xp.dat to C:\combofix_19.11.4.1\netsvc.xp.dat
  • from C:\32788r22fwjfw\networkservice.dat to C:\combofix_19.11.4.1\networkservice.dat
  • from C:\32788r22fwjfw\nircmd.3xe to C:\combofix_19.11.4.1\nircmd.3xe
  • from C:\32788r22fwjfw\nircmdb.exe to C:\combofix_19.11.4.1\nircmdb.exe
  • from C:\32788r22fwjfw\nircmdc.3xe to C:\combofix_19.11.4.1\nircmdc.3xe
  • from C:\32788r22fwjfw\nirkmd.3xe to C:\combofix_19.11.4.1\nirkmd.3xe
  • from C:\32788r22fwjfw\nlslanguagedefault to C:\combofix_19.11.4.1\nlslanguagedefault
  • from C:\32788r22fwjfw\nt-os.cmd to C:\combofix_19.11.4.1\nt-os.cmd
  • from C:\32788r22fwjfw\sed.3xe to C:\combofix_19.11.4.1\sed.3xe
  • from C:\32788r22fwjfw\rnullfix64.3xe to C:\combofix_19.11.4.1\rnullfix64.3xe
  • from C:\32788r22fwjfw\osid.vbs to C:\combofix_19.11.4.1\osid.vbs
  • from C:\32788r22fwjfw\personalfile.cfx to C:\combofix_19.11.4.1\personalfile.cfx
  • from C:\32788r22fwjfw\personalfolder.cfx to C:\combofix_19.11.4.1\personalfolder.cfx
  • from C:\32788r22fwjfw\pev.3xe to C:\combofix_19.11.4.1\pev.3xe
  • from C:\32788r22fwjfw\pev.exe to C:\combofix_19.11.4.1\pev.exe
  • from C:\32788r22fwjfw\pevb.3xe to C:\combofix_19.11.4.1\pevb.3xe
  • from C:\32788r22fwjfw\ping.3xe to C:\combofix_19.11.4.1\ping.3xe
  • from C:\32788r22fwjfw\policies.dat to C:\combofix_19.11.4.1\policies.dat
  • from C:\32788r22fwjfw\powp.dat to C:\combofix_19.11.4.1\powp.dat
  • from C:\32788r22fwjfw\prep.inf to C:\combofix_19.11.4.1\prep.inf
  • from C:\32788r22fwjfw\profilesfile.cfx to C:\combofix_19.11.4.1\profilesfile.cfx
  • from C:\32788r22fwjfw\netsvc.bad.dat to C:\combofix_19.11.4.1\netsvc.bad.dat
  • from C:\32788r22fwjfw\pausep.3xe to C:\combofix_19.11.4.1\pausep.3xe
  • from C:\32788r22fwjfw\svcdrv.vbs to C:\combofix_19.11.4.1\svcdrv.vbs
  • from C:\32788r22fwjfw\zhsvc.dat to C:\combofix_19.11.4.1\zhsvc.dat
  • from C:\32788r22fwjfw\setpath_n.cmd to C:\combofix_19.11.4.1\setpath_n.cmd
  • from C:\32788r22fwjfw\update-cf.cmd to C:\combofix_19.11.4.1\update-cf.cmd
  • from C:\32788r22fwjfw\vbr.pif to C:\combofix_19.11.4.1\vbr.pif
  • from C:\32788r22fwjfw\vercf.bat to C:\combofix_19.11.4.1\vercf.bat
  • from C:\32788r22fwjfw\vinfo to C:\combofix_19.11.4.1\vinfo
  • from C:\32788r22fwjfw\vinfo2 to C:\combofix_19.11.4.1\vinfo2
  • from C:\32788r22fwjfw\vinfo3 to C:\combofix_19.11.4.1\vinfo3
  • from C:\32788r22fwjfw\vipev.dat to C:\combofix_19.11.4.1\vipev.dat
  • from C:\32788r22fwjfw\vista.krl to C:\combofix_19.11.4.1\vista.krl
  • from C:\32788r22fwjfw\vistamcode.dat to C:\combofix_19.11.4.1\vistamcode.dat
  • from C:\32788r22fwjfw\vistareg.dat to C:\combofix_19.11.4.1\vistareg.dat
  • from C:\32788r22fwjfw\setenvmt.bat to C:\combofix_19.11.4.1\setenvmt.bat
  • from C:\32788r22fwjfw\vun.dat to C:\combofix_19.11.4.1\vun.dat
  • from C:\32788r22fwjfw\w6432.dat to C:\combofix_19.11.4.1\w6432.dat
  • from C:\32788r22fwjfw\w7.mac to C:\combofix_19.11.4.1\w7.mac
  • from C:\32788r22fwjfw\w7mcode.dat to C:\combofix_19.11.4.1\w7mcode.dat
  • from C:\32788r22fwjfw\w7reg.dat to C:\combofix_19.11.4.1\w7reg.dat
  • from C:\32788r22fwjfw\w8reg.dat to C:\combofix_19.11.4.1\w8reg.dat
  • from C:\32788r22fwjfw\wmi_rem.vbs to C:\combofix_19.11.4.1\wmi_rem.vbs
  • from C:\32788r22fwjfw\xpmcode.dat to C:\combofix_19.11.4.1\xpmcode.dat
  • from C:\32788r22fwjfw\xpreg.dat to C:\combofix_19.11.4.1\xpreg.dat
  • from C:\32788r22fwjfw\xpsboot.reg to C:\combofix_19.11.4.1\xpsboot.reg
  • from C:\32788r22fwjfw\zdomain.dat to C:\combofix_19.11.4.1\zdomain.dat
  • from C:\32788r22fwjfw\templatesfolder.cfx to C:\combofix_19.11.4.1\templatesfolder.cfx
  • from C:\32788r22fwjfw\toolbar.sed to C:\combofix_19.11.4.1\toolbar.sed
  • from C:\32788r22fwjfw\templatesfile.cfx to C:\combofix_19.11.4.1\templatesfile.cfx
  • from C:\32788r22fwjfw\tail.3xe to C:\combofix_19.11.4.1\tail.3xe
  • from C:\32788r22fwjfw\system_ini.dat to C:\combofix_19.11.4.1\system_ini.dat
  • from C:\32788r22fwjfw\sfx.cmd to C:\combofix_19.11.4.1\sfx.cmd
  • from C:\32788r22fwjfw\shaccess.dat to C:\combofix_19.11.4.1\shaccess.dat
  • from C:\32788r22fwjfw\snapshot.cmd to C:\combofix_19.11.4.1\snapshot.cmd
  • from C:\32788r22fwjfw\sqlite3.3xe to C:\combofix_19.11.4.1\sqlite3.3xe
  • from C:\32788r22fwjfw\srestore.cmd to C:\combofix_19.11.4.1\srestore.cmd
  • from C:\32788r22fwjfw\srizbi.md5 to C:\combofix_19.11.4.1\srizbi.md5
  • from C:\32788r22fwjfw\startmenufile.cfx to C:\combofix_19.11.4.1\startmenufile.cfx
  • from C:\32788r22fwjfw\startmenufolder.cfx to C:\combofix_19.11.4.1\startmenufolder.cfx
  • from C:\32788r22fwjfw\startupfile.cfx to C:\combofix_19.11.4.1\startupfile.cfx
  • from C:\32788r22fwjfw\start_dat to C:\combofix_19.11.4.1\start_dat
  • from C:\32788r22fwjfw\setpath.3xe to C:\combofix_19.11.4.1\setpath.3xe
  • from C:\32788r22fwjfw\nd_64.bat to C:\combofix_19.11.4.1\nd_64.bat
  • from C:\32788r22fwjfw\suppscan.cmd to C:\combofix_19.11.4.1\suppscan.cmd
  • from C:\32788r22fwjfw\svchost.vista.dat to C:\combofix_19.11.4.1\svchost.vista.dat
  • from C:\32788r22fwjfw\svchost.vista.x64.dat to C:\combofix_19.11.4.1\svchost.vista.x64.dat
  • from C:\32788r22fwjfw\svchost.w7.dat to C:\combofix_19.11.4.1\svchost.w7.dat
  • from C:\32788r22fwjfw\svchost.w7.x64.dat to C:\combofix_19.11.4.1\svchost.w7.x64.dat
  • from C:\32788r22fwjfw\svchost.w8.dat to C:\combofix_19.11.4.1\svchost.w8.dat
  • from C:\32788r22fwjfw\svchost.w8.x64.dat to C:\combofix_19.11.4.1\svchost.w8.x64.dat
  • from C:\32788r22fwjfw\svc_wht.dat to C:\combofix_19.11.4.1\svc_wht.dat
  • from C:\32788r22fwjfw\swreg.3xe to C:\combofix_19.11.4.1\swreg.3xe
  • from C:\32788r22fwjfw\swsc.3xe to C:\combofix_19.11.4.1\swsc.3xe
  • from C:\32788r22fwjfw\swxcacls.3xe to C:\combofix_19.11.4.1\swxcacls.3xe
  • from C:\32788r22fwjfw\sf.exe to C:\combofix_19.11.4.1\sf.exe
  • from C:\32788r22fwjfw\svchost.dat to C:\combofix_19.11.4.1\svchost.dat
  • from C:\32788r22fwjfw\vwintemp.dacl to C:\combofix_19.11.4.1\vwintemp.dacl
  • from C:\32788r22fwjfw\nd_.bat to C:\combofix_19.11.4.1\nd_.bat
  • from C:\32788r22fwjfw\localsettingsfolder.cfx to C:\combofix_19.11.4.1\localsettingsfolder.cfx
  • from C:\32788r22fwjfw\combo-fix.sys to C:\combofix_19.11.4.1\combo-fix.sys
  • from C:\32788r22fwjfw\combobatch.bat to C:\combofix_19.11.4.1\combobatch.bat
  • from C:\32788r22fwjfw\combofix-download.3xe to C:\combofix_19.11.4.1\combofix-download.3xe
  • from C:\32788r22fwjfw\create.cmd to C:\combofix_19.11.4.1\create.cmd
  • from C:\32788r22fwjfw\creg.dat to C:\combofix_19.11.4.1\creg.dat
  • from C:\32788r22fwjfw\cregc.cmd to C:\combofix_19.11.4.1\cregc.cmd
  • from C:\32788r22fwjfw\cregc.dat to C:\combofix_19.11.4.1\cregc.dat
  • from C:\32788r22fwjfw\cscript.3xe to C:\combofix_19.11.4.1\cscript.3xe
  • from C:\32788r22fwjfw\dd.3xe to C:\combofix_19.11.4.1\dd.3xe
  • from C:\32788r22fwjfw\ddsdo.sed to C:\combofix_19.11.4.1\ddsdo.sed
  • from C:\32788r22fwjfw\attrib.3xe to C:\combofix_19.11.4.1\attrib.3xe
  • from C:\32788r22fwjfw\delclsid.bat to C:\combofix_19.11.4.1\delclsid.bat
  • from C:\32788r22fwjfw\desktop.ini to C:\combofix_19.11.4.1\desktop.ini
  • from C:\32788r22fwjfw\desktopfile.cfx to C:\combofix_19.11.4.1\desktopfile.cfx
  • from C:\32788r22fwjfw\disclaimed.dat to C:\combofix_19.11.4.1\disclaimed.dat
  • from C:\32788r22fwjfw\dpf.str to C:\combofix_19.11.4.1\dpf.str
  • from C:\32788r22fwjfw\drvrun.vbs to C:\combofix_19.11.4.1\drvrun.vbs
  • from C:\32788r22fwjfw\dumphive.3xe to C:\combofix_19.11.4.1\dumphive.3xe
  • from C:\32788r22fwjfw\embedded.sed to C:\combofix_19.11.4.1\embedded.sed
  • from C:\32788r22fwjfw\erdnt.e_e to C:\combofix_19.11.4.1\erdnt.e_e
  • from C:\32788r22fwjfw\erdntdos.loc to C:\combofix_19.11.4.1\erdntdos.loc
  • from C:\32788r22fwjfw\erdntwin.loc to C:\combofix_19.11.4.1\erdntwin.loc
  • from C:\32788r22fwjfw\clsid.c to C:\combofix_19.11.4.1\clsid.c
  • from C:\32788r22fwjfw\cmd.3xe to C:\combofix_19.11.4.1\cmd.3xe
  • from C:\32788r22fwjfw\chcp.bat to C:\combofix_19.11.4.1\chcp.bat
  • from C:\32788r22fwjfw\cf-script.cmd to C:\combofix_19.11.4.1\cf-script.cmd
  • from C:\32788r22fwjfw\catchme.3xe to C:\combofix_19.11.4.1\catchme.3xe
  • from C:\32788r22fwjfw\license\sf.exe to C:\32788r22fwjfw\sf.exe
  • from C:\32788r22fwjfw\023.dat to C:\combofix_19.11.4.1\023.dat
  • from C:\32788r22fwjfw\023v.dat to C:\combofix_19.11.4.1\023v.dat
  • from C:\32788r22fwjfw\023w7.dat to C:\combofix_19.11.4.1\023w7.dat
  • from C:\32788r22fwjfw\023w8.dat to C:\combofix_19.11.4.1\023w8.dat
  • from C:\32788r22fwjfw\activedrv.vbs to C:\combofix_19.11.4.1\activedrv.vbs
  • from C:\32788r22fwjfw\appdatafile.cfx to C:\combofix_19.11.4.1\appdatafile.cfx
  • from C:\32788r22fwjfw\appdatafolder.cfx to C:\combofix_19.11.4.1\appdatafolder.cfx
  • from C:\32788r22fwjfw\appinit.bad to C:\combofix_19.11.4.1\appinit.bad
  • from C:\32788r22fwjfw\asp.str to C:\combofix_19.11.4.1\asp.str
  • from C:\32788r22fwjfw\erunt.3xe to C:\combofix_19.11.4.1\erunt.3xe
  • from C:\32788r22fwjfw\delclsid64.bat to C:\combofix_19.11.4.1\delclsid64.bat
  • from C:\32788r22fwjfw\assoc.cmd to C:\combofix_19.11.4.1\assoc.cmd
  • from C:\32788r22fwjfw\av.cmd to C:\combofix_19.11.4.1\av.cmd
  • from C:\32788r22fwjfw\av.vbs to C:\combofix_19.11.4.1\av.vbs
  • from C:\32788r22fwjfw\awf.cmd to C:\combofix_19.11.4.1\awf.cmd
  • from C:\32788r22fwjfw\badclsid.c to C:\combofix_19.11.4.1\badclsid.c
  • from C:\32788r22fwjfw\bfe.dat to C:\combofix_19.11.4.1\bfe.dat
  • from C:\32788r22fwjfw\boot-rk.cmd to C:\combofix_19.11.4.1\boot-rk.cmd
  • from C:\32788r22fwjfw\boot.bat to C:\combofix_19.11.4.1\boot.bat
  • from C:\32788r22fwjfw\bootdrv.vbs to C:\combofix_19.11.4.1\bootdrv.vbs
  • from C:\32788r22fwjfw\c.bat to C:\combofix_19.11.4.1\c.bat
  • from C:\32788r22fwjfw\catch-sub.cmd to C:\combofix_19.11.4.1\catch-sub.cmd
  • from C:\32788r22fwjfw\nir.pif to C:\32788r22fwjfw\nirkmd.3xe
  • from C:\32788r22fwjfw\auto-rc.cmd to C:\combofix_19.11.4.1\auto-rc.cmd
  • from C:\32788r22fwjfw\gethive.cmd to C:\combofix_19.11.4.1\gethive.cmd
  • from C:\32788r22fwjfw\ncmd.com to C:\combofix_19.11.4.1\ncmd.com
  • from C:\32788r22fwjfw\extract.3xe to C:\combofix_19.11.4.1\extract.3xe
  • from C:\32788r22fwjfw\lang.bat to C:\combofix_19.11.4.1\lang.bat
  • from C:\32788r22fwjfw\list-b.bat to C:\combofix_19.11.4.1\list-b.bat
  • from C:\32788r22fwjfw\list-c.bat to C:\combofix_19.11.4.1\list-c.bat
  • from C:\32788r22fwjfw\list-d.bat to C:\combofix_19.11.4.1\list-d.bat
  • from C:\32788r22fwjfw\list.bat to C:\combofix_19.11.4.1\list.bat
  • from C:\32788r22fwjfw\lnkread.vbs to C:\combofix_19.11.4.1\lnkread.vbs
  • from C:\32788r22fwjfw\localappdatafile.cfx to C:\combofix_19.11.4.1\localappdatafile.cfx
  • from C:\32788r22fwjfw\localappdatafolder.cfx to C:\combofix_19.11.4.1\localappdatafolder.cfx
  • from C:\32788r22fwjfw\localservice.dat to C:\combofix_19.11.4.1\localservice.dat
  • from C:\32788r22fwjfw\localservicenetworkrestricted.dat to C:\combofix_19.11.4.1\localservicenetworkrestricted.dat
  • from C:\32788r22fwjfw\erunt.loc to C:\combofix_19.11.4.1\erunt.loc
  • from C:\32788r22fwjfw\localsettingsfile.cfx to C:\combofix_19.11.4.1\localsettingsfile.cfx
  • from C:\32788r22fwjfw\localsystemnetworkrestricted.dat to C:\combofix_19.11.4.1\localsystemnetworkrestricted.dat
  • from C:\32788r22fwjfw\mbr.3xe to C:\combofix_19.11.4.1\mbr.3xe
  • from C:\32788r22fwjfw\mbr.chk to C:\combofix_19.11.4.1\mbr.chk
  • from C:\32788r22fwjfw\md5sum.pif to C:\combofix_19.11.4.1\md5sum.pif
  • from C:\32788r22fwjfw\mdwht.dat to C:\combofix_19.11.4.1\mdwht.dat
  • from C:\32788r22fwjfw\moveit.bat to C:\combofix_19.11.4.1\moveit.bat
  • from C:\32788r22fwjfw\mpssvc.dat to C:\combofix_19.11.4.1\mpssvc.dat
  • from C:\32788r22fwjfw\mtee.3xe to C:\combofix_19.11.4.1\mtee.3xe
  • from C:\32788r22fwjfw\mui to C:\combofix_19.11.4.1\mui
  • from C:\32788r22fwjfw\mzchanged.dat to C:\combofix_19.11.4.1\mzchanged.dat
  • from C:\32788r22fwjfw\kill-all.cmd to C:\combofix_19.11.4.1\kill-all.cmd
  • from C:\32788r22fwjfw\knetsvcs.vbs to C:\combofix_19.11.4.1\knetsvcs.vbs
  • from C:\32788r22fwjfw\katch.cmd to C:\combofix_19.11.4.1\katch.cmd
  • from C:\32788r22fwjfw\iphlpsvc.w8.dat to C:\combofix_19.11.4.1\iphlpsvc.w8.dat
  • from C:\32788r22fwjfw\iphlpsvc.w7.dat to C:\combofix_19.11.4.1\iphlpsvc.w7.dat
  • from C:\32788r22fwjfw\favoritesfile.cfx to C:\combofix_19.11.4.1\favoritesfile.cfx
  • from C:\32788r22fwjfw\fd-sv.cmd to C:\combofix_19.11.4.1\fd-sv.cmd
  • from C:\32788r22fwjfw\ffdefstr.dll to C:\combofix_19.11.4.1\ffdefstr.dll
  • from C:\32788r22fwjfw\ffext.pif to C:\combofix_19.11.4.1\ffext.pif
  • from C:\32788r22fwjfw\filekill.3xe to C:\combofix_19.11.4.1\filekill.3xe
  • from C:\32788r22fwjfw\files.pif to C:\combofix_19.11.4.1\files.pif
  • from C:\32788r22fwjfw\fin.dat to C:\combofix_19.11.4.1\fin.dat
  • from C:\32788r22fwjfw\find3m.bat to C:\combofix_19.11.4.1\find3m.bat
  • from C:\32788r22fwjfw\fixlsp.bat to C:\combofix_19.11.4.1\fixlsp.bat
  • from C:\32788r22fwjfw\fixlsp64.cmd to C:\combofix_19.11.4.1\fixlsp64.cmd
  • from C:\32788r22fwjfw\exe.reg to C:\combofix_19.11.4.1\exe.reg
  • from C:\32788r22fwjfw\ndis_combofix.dat to C:\combofix_19.11.4.1\ndis_combofix.dat
  • from C:\32788r22fwjfw\fkmgen.cmd to C:\combofix_19.11.4.1\fkmgen.cmd
  • from C:\32788r22fwjfw\gsar.3xe to C:\combofix_19.11.4.1\gsar.3xe
  • from C:\32788r22fwjfw\handle.3xe to C:\combofix_19.11.4.1\handle.3xe
  • from C:\32788r22fwjfw\hidec.3xe to C:\combofix_19.11.4.1\hidec.3xe
  • from C:\32788r22fwjfw\history.bat to C:\combofix_19.11.4.1\history.bat
  • from C:\32788r22fwjfw\hwid.pif to C:\combofix_19.11.4.1\hwid.pif
  • from C:\32788r22fwjfw\iexplore.exe to C:\combofix_19.11.4.1\iexplore.exe
  • from C:\32788r22fwjfw\image001.gif to C:\combofix_19.11.4.1\image001.gif
  • from C:\32788r22fwjfw\imefile.dat to C:\combofix_19.11.4.1\imefile.dat
  • from C:\32788r22fwjfw\install-rc.cmd to C:\combofix_19.11.4.1\install-rc.cmd
  • from C:\32788r22fwjfw\iphlpsvc.vista.dat to C:\combofix_19.11.4.1\iphlpsvc.vista.dat
  • from C:\32788r22fwjfw\favoritefolder.cfx to C:\combofix_19.11.4.1\favoritefolder.cfx
  • from C:\32788r22fwjfw\grep.3xe to C:\combofix_19.11.4.1\grep.3xe
  • from C:\32788r22fwjfw\zip.3xe to C:\combofix_19.11.4.1\zip.3xe
Substitutes the following files
  • C:\32788r22fwjfw\temp00
Network activity
Connects to
  • 'do######.bleepingcomputer.com':80
  • '20#.#3.120.24':80
  • '69.#.236.82':80
UDP
  • DNS ASK do######.bleepingcomputer.com
  • DNS ASK co###ndiate.net
  • DNS ASK google.com
Miscellaneous
Searches for the following windows
  • ClassName: 'RegEdit_RegEdit' WindowName: ''
Creates and executes the following
  • '%TEMP%\7zipsfx.000\combofix_19.11.4.1.exe' /S /NCRC
  • 'C:\32788r22fwjfw\pev.3xe' -tf -tpmz -t!o C:\$RECYCLE.bin\*000*.? -preg"\\U\\[^\\]*\..$"
  • 'C:\32788r22fwjfw\attrib.3xe' +R "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe"
  • 'C:\32788r22fwjfw\grep.3xe' "=.*[a-z]" sfx.cmd
  • 'C:\32788r22fwjfw\grep.3xe' -Eisq "=.\/NoMbr| .\/NoMbr. | .\/NoMbr.$" sfx.cmd
  • 'C:\32788r22fwjfw\grep.3xe' -Eisq "\\CFScript[^:\/\\]*$" sfx.cmd
  • 'C:\32788r22fwjfw\grep.3xe' -Ei "\\NoMbr\.....$" MSName00
  • 'C:\32788r22fwjfw\grep.3xe' -Ei "\\iexplore\.exe.$" MSName00
  • 'C:\32788r22fwjfw\grep.3xe' -Fsf AVBlack resident.txt
  • 'C:\32788r22fwjfw\grep.3xe' -Fivf AVWhite resident.txt
  • 'C:\32788r22fwjfw\grep.3xe' -E "^(AV|SP): .*\*Enabled/"
  • 'C:\32788r22fwjfw\pev.3xe' -k * -preg"\\((ntvdm|teatimer[^\\]*|ad-watch[^\\]*|SZServer|StopZilla[^\\]*|userinit|procmon|txp1atform|SonndMan|ANDRE|TOLO|jalang|jalangkung|jantungan|DOSEN|C3W3K4MPUS)\.exe)$"
  • 'C:\32788r22fwjfw\grep.3xe' -Fx "REGEDIT4" Fin.dat
  • 'C:\32788r22fwjfw\grep.3xe' -ix "FileName=[-[:alnum:]@_.]*" FileName
  • 'C:\32788r22fwjfw\grep.3xe' -ivx ComboFix DirName00
  • 'C:\32788r22fwjfw\nircmd.3xe' CMDWAIT 9000 EXEC HIDE PEV -k CSCRIPT.3XE
  • 'C:\32788r22fwjfw\swxcacls.3xe' C:\$RECYCLE.bin\* /GA:F /S /Q
  • 'C:\32788r22fwjfw\sed.3xe' -r "/.*\\CF@C([1-9][0-9])M([1-9])\.....$/I!d; s//\1\t\2/" MSName00
  • 'C:\32788r22fwjfw\cscript.3xe' //NOLOGO //E:VBSCRIPT //B //T:08 av.vbs
  • 'C:\32788r22fwjfw\grep.3xe' -Ei "\\uninstall\.....$" MSName00
  • 'C:\32788r22fwjfw\pev.3xe' -tx50000 -tf -files:files.pif -c:##5#b#f# -output:mdCheck00.dat
  • 'C:\32788r22fwjfw\grep.3xe' -vs "^!" mdCheck00.dat
  • 'C:\32788r22fwjfw\grep.3xe' -Fvf md5sum.pif mdCheck0a.dat
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "hklm\software\microsoft\windows\currentversion\app paths\combofix.exe" /ve
  • 'C:\32788r22fwjfw\swreg.3xe' ADD "hklm\software\microsoft\windows\currentversion\app paths\combofix.exe" /ve /d "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe"
  • 'C:\32788r22fwjfw\grep.3xe' -Ei "\\(wscntfy|winlogon|wininit|nvsvc|lsm|lsass|iexplore|svchost|spoolsv|smss|slsvc|services|explorer|ctfmon|csrss|alg)\.....$" MSName00
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "hklm\software\microsoft\windows nt\currentversion\winlogon" /v Userinit
  • 'C:\32788r22fwjfw\grep.3xe' -Fisqx "ComboFix_19.11.4.1" DirName01
  • 'C:\32788r22fwjfw\swreg.3xe' ADD "hklm\software\microsoft\windows nt\currentversion\winlogon" /v Userinit /d "<SYSTEM32>\userinit.exe,"
  • 'C:\32788r22fwjfw\sed.3xe' -r "/./!d; /^\x22/!{s/\x22(\S+)\x22/\1/; s_\s+(/\S+)\s+_ \x22\1\x22 _g; s_\s+(/\S+)\s+_ \x22\1\x22 _g; s_\x22\s+(/\S*)$_\x22 \x22\1\x22_; s_^(/\S+)\s+_\x22\1\x22 _; }" temp00
  • 'C:\combofix_19.11.4.1\swreg.3xe' QUERY "HKCU\Console_combofixbackup"
  • 'C:\32788r22fwjfw\swxcacls.3xe' %WINDIR%\SysNative\ATTRIB.exe /P /GA:F /GS:F /GU:X /GP:X /I ENABLE /Q
  • 'C:\32788r22fwjfw\swxcacls.3xe' %WINDIR%\SysNative\CSCRIPT.exe /P /GA:F /GS:F /GU:X /GP:X /I ENABLE /Q
  • 'C:\32788r22fwjfw\swxcacls.3xe' %WINDIR%\SysNative\PING.exe /P /GA:F /GS:F /GU:X /GP:X /I ENABLE /Q
  • 'C:\32788r22fwjfw\grep.3xe' -Fi "<SYSTEM32>\userinit.exe" Userinit00
  • 'C:\32788r22fwjfw\swxcacls.3xe' %WINDIR%\SysNative\ROUTE.exe /P /GA:F /GS:F /GU:X /GP:X /I ENABLE /Q
  • 'C:\32788r22fwjfw\sed.3xe' -r "/SfxCmd=/I!d; s///; s/\s*$//; s/^(\x22[^\x22]*\x22|[^\x22]\S*) *//; s/(\x22[^\x22]*\x22)/\n\1\n/g" SET00
  • 'C:\32788r22fwjfw\grep.3xe' -E "^[5-9]$|.."
  • 'C:\32788r22fwjfw\sed.3xe' -r ":a; $!N;s/\n *\x22/ \x22/;ta; s/./@SET SfxCmd=&/; s/^(@SET SfxCmd=)([^\x22]\S*)$/\1\x22\2\x22/" temp01
  • 'C:\combofix_19.11.4.1\sed.3xe' -R "1,3d; /[4-9]\S{7}\s*\d* .:\\|\\detoured.dll$/Id; /.*(.:\\.*)/I!d; s//\1/" ForeignC00
  • 'C:\combofix_19.11.4.1\swreg.3xe' DELETE HKLM\Software\Swearware /V "CF_Update"
  • 'C:\combofix_19.11.4.1\pev.3xe' -rtf -dg365 .\md5sum.pif
  • 'C:\combofix_19.11.4.1\pv.3xe' -d2000 -xa PING.3XE
  • 'C:\combofix_19.11.4.1\pv.3xe' -m PING.3XE
  • 'C:\combofix_19.11.4.1\sed.3xe' -R "1,3d; /((10|4)00000|[4-9]\S{7})\s*\d* .:\\/d; /C:\\Windows\\SysWow64\\(xpsp2res|Normaliz|urlmon|odbcint|imon)\.dll/Id; /\)|\\/I!d; s/.*(.:\\)/\1/" pingtest00
  • 'C:\combofix_19.11.4.1\grep.3xe' -Fixf ForeignWht pingtest01
  • 'C:\combofix_19.11.4.1\hidec.3xe' PING -n 1 -w 250 127.0.0.1
  • 'C:\combofix_19.11.4.1\ping.3xe' -n 2 -w 500 google.com
  • 'C:\combofix_19.11.4.1\swreg.3xe' QUERY "HKLM\SOFTWARE\swearware\Backup\Winsock2"
  • 'C:\combofix_19.11.4.1\swreg.3xe' ACL "HKLM\SOFTWARE\swearware" /RESET
  • 'C:\combofix_19.11.4.1\swreg.3xe' COPY "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2" "HKLM\SOFTWARE\swearware\Backup\Winsock2" /s
  • 'C:\combofix_19.11.4.1\combofix-download.3xe' -s --connect-timeout 5 -A "cfcurl/7.15.3 (i586-pc-mingw32msvc) libcurl/7.15.3 zlib/1.2.2" -H "Host: download.bleepingcomputer.com" http://20#.#3.120.24/sUBs/version.txt
  • 'C:\combofix_19.11.4.1\grep.3xe' "^[0-9][0-9].* [0-9]"
  • 'C:\combofix_19.11.4.1\combofix-download.3xe' -s --connect-timeout 5 -A "cfcurl/7.15.3 (i586-pc-mingw32msvc) libcurl/7.15.3 zlib/1.2.2" -H "Host: www.co####diate.net" http://69.#.236.82/sUBs/ComboFix.exe/version.txt
  • 'C:\combofix_19.11.4.1\pev.3xe' -k PING.3XE
  • 'C:\combofix_19.11.4.1\swreg.3xe' QUERY HKLM\Software\Swearware /V "CF_Update"
  • 'C:\32788r22fwjfw\pev.3xe' -rtf -s=0 "%WINDIR%\erdnt\Hiv-backup\*"
  • 'C:\combofix_19.11.4.1\swreg.3xe' QUERY HKLM\Software\Swearware /v 44617465204572726F72
  • 'C:\32788r22fwjfw\swreg.3xe' ADD "HKLM\Software\Swearware" /V LastDir /D "C:\ComboFix_19.11.4.1"
  • 'C:\combofix_19.11.4.1\swxcacls.3xe' PV.3XE /P /GE:F /Q
  • 'C:\32788r22fwjfw\pev.3xe' -k SWSC.3XE
  • 'C:\32788r22fwjfw\pev.3xe' UZIP "License\streamtools.zip" License
  • 'C:\32788r22fwjfw\hidec.3xe' "C:\ComboFix_19.11.4.1\CF13968.3XE" /F:OFF /D /C C:\Start_.cmd
  • 'C:\32788r22fwjfw\pev.3xe' WAIT 2000
  • 'C:\combofix_19.11.4.1\cf13968.3xe' /F:OFF /D /C C:\Start_.cmd
  • 'C:\combofix_19.11.4.1\cf13968.3xe' /k c.bat
  • 'C:\32788r22fwjfw\grep.3xe' -Eisq "=.\/uninstall| .\/uninstall. | .\/uninstall.$" sfx.cmd
  • 'C:\combofix_19.11.4.1\pev.3xe' RIMPORT EXE.reg
  • 'C:\combofix_19.11.4.1\sed.3xe' -r "/.* /!d; s//00/; s/^[0-9]*(...) .*/@SET ControlSet=ControlSet\1\nSET CS000=HKEY_LOCAL_MACHINE\\system\\ControlSet\1\\Services/"
  • 'C:\combofix_19.11.4.1\attrib.3xe' +S "C:\ComboFix_19.11.4.1"
  • 'C:\combofix_19.11.4.1\grep.3xe' -sqx "REGEDIT4" Fin.dat
  • 'C:\combofix_19.11.4.1\attrib.3xe' +R *.3XE
  • 'C:\combofix_19.11.4.1\nircmdc.3xe' EXEC SHOW "C:\ComboFix_19.11.4.1\CF13968.3XE" /C " ECHO.&&ECHO.-------- ~%CurrDate.yyyy-MM-dd% - ~%CurrTime.HH:mm:ss% -------------&&ECHO."
  • 'C:\combofix_19.11.4.1\swreg.3xe' ADD "HKLM\Software\Swearware" /v 44617465204572726F72 /d "idk"
  • 'C:\combofix_19.11.4.1\grep.3xe' -Fixvf ForeignWht ForeignC01
  • 'C:\combofix_19.11.4.1\swreg.3xe' QUERY "hklm\system\select" /v "current"
  • 'C:\combofix_19.11.4.1\cf13968.3xe' /C " ECHO.&&ECHO.-------- 2021-07-01 - 18:30:22 -------------&&ECHO."
  • 'C:\32788r22fwjfw\grep.3xe' -sq . mdCheck01.dat
  • 'C:\combofix_19.11.4.1\grep.3xe' -isq "09$" NlsLanguageDefault
  • 'C:\32788r22fwjfw\handle64.exe' -p System
  • 'C:\32788r22fwjfw\grep.3xe' -Fic "%WINDIR%\SysWow64\drivers\volsnap.sys" temp00
  • 'C:\32788r22fwjfw\pev.3xe' -tx40000 -t!g -rtf -tpmz -c##y#b#z# \Services.exe
  • 'C:\32788r22fwjfw\sed.3xe' -r "/(0x0.*)\t\1/d"
  • 'C:\32788r22fwjfw\grep.3xe' .
  • 'C:\32788r22fwjfw\pev.3xe' -tf -tpmz -t!o %WINDIR%\Installer\*000*.? -preg"C:\\Windows\\Installer\\\{[^\\]*\}\\U\\[^\\]*\..$"
  • 'C:\32788r22fwjfw\license\iexplore.exe' -rk { "%ProgramFiles(x86)%\*" OR "%CommonProgramFiles(x86)%\*" } not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }
  • 'C:\combofix_19.11.4.1\pv.3xe' -m CF13968.3XE
  • 'C:\32788r22fwjfw\setpath.3xe'
  • 'C:\32788r22fwjfw\hidec.3xe' %WINDIR%\Sysnative\cmd.exe /c REGEDIT.EXE /S C:\32788R22FWJFW\W7Reg.dat
  • 'C:\32788r22fwjfw\cmd.3xe' /C C:\32788R22FWJFW\p.cmd
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_{79007602-0CDB-4405-9DBF-1257BB3226ED}\0000\Control" /v ActiveService
  • 'C:\32788r22fwjfw\rmbr.3xe' -u
  • 'C:\32788r22fwjfw\grep.3xe' -Eix "HKEY_.*\\root\\\*PNP[^\\]*" PNP296_00
  • 'C:\32788r22fwjfw\nircmd.3xe' WIN CLOSE CLASS "#32770"
  • 'C:\32788r22fwjfw\grep.3xe' -sq . ZAFldr00.dat
  • 'C:\32788r22fwjfw\grep.3xe' -Fsq "STATE : 4 RUNNING"
  • 'C:\combofix_19.11.4.1\grep.3xe' -Eisq "=.\/uninstall.| .\/uninstall. | .\/uninstall.$" sfx.cmd
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "HKLM\System\Currentcontrolset\Control\ProductOptions" /v ProductType
  • 'C:\32788r22fwjfw\grep.3xe' -isq "ProductType.*WinNT" WinNT00
  • 'C:\32788r22fwjfw\swreg.3xe' ACL "HKLM\SOFTWARE\Microsoft\Command Processor" /RESET /Q
  • 'C:\32788r22fwjfw\erunt.3xe' "%WINDIR%\erdnt\Hiv-backup" SYSREG CURUSER OTHERUSERS /NOCONFIRMDELETE
  • 'C:\32788r22fwjfw\pev.3xe' RIMPORT C:\32788R22FWJFW\EXE.reg
  • 'C:\32788r22fwjfw\en-us\iexplore.exe' /w C:\32788R22FWJFW\PEV.3XE RIMPORT C:\32788R22FWJFW\EXE.reg
  • 'C:\32788r22fwjfw\iexplore.exe' Script C:\32788R22FWJFW\Nirscript.dat
  • 'C:\32788r22fwjfw\license\iexplore.exe' -s450000-1400000 -t!k -t!o -t!g -k C:\*.exe and not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }
  • 'C:\32788r22fwjfw\license\iexplore.exe' -k { "%ALLUSERSPROFILE%\*" or "%HOMEPATH%\*" } not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }
  • 'C:\32788r22fwjfw\hidec.3xe' C:\32788R22FWJFW\cmd.3XE /C C:\32788R22FWJFW\p.cmd
  • 'C:\32788r22fwjfw\swreg.3xe' ACL "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32" /RESET /Q
  • 'C:\32788r22fwjfw\license\iexplore.exe' -loadline:C:\32788R22FWJFW\License\UnxUtilsDist.pif and not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }
  • 'C:\32788r22fwjfw\license\iexplore.exe' -loadline:C:\32788R22FWJFW\License\UnxUtilsDist.com and not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }
  • 'C:\32788r22fwjfw\swxcacls.3xe' "<SYSTEM32>\cmd.exe" /P /GA:F /GS:F /GU:X /GP:X /I ENABLE /Q
  • 'C:\32788r22fwjfw\gsar.3xe' -if -s\:000M:000i:000c:000r:000o -r\:001M:000i:000c:000r:000o "<SYSTEM32>\cmd.exe" cmd.3XE
  • 'C:\32788r22fwjfw\swreg.3xe' ACL "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32" /DA:R /Q
  • 'C:\32788r22fwjfw\swreg.3xe' ACL "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /RESET /Q
  • 'C:\32788r22fwjfw\swsc.3xe' QUERY BFE
  • 'C:\32788r22fwjfw\license\iexplore.exe' -k "%TEMP%\*" not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }
  • 'C:\32788r22fwjfw\pev.3xe' -c##g# "<SYSTEM32>\kernel32.dll"
  • 'C:\32788r22fwjfw\handle.3xe' -p System
  • 'C:\32788r22fwjfw\grep.3xe' -isq "processorArchitecture=.amd64." "%WINDIR%\SysNative\csrss.exe"
  • 'C:\32788r22fwjfw\hidec.3xe' SWSC START CryptSvc
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "HKCU\Console_combofixbackup"
  • 'C:\32788r22fwjfw\swreg.3xe' COPY "HKCU\Console" "HKCU\Console_combofixbackup" /s
  • 'C:\32788r22fwjfw\pev.3xe' -rtd %WINDIR%\Sysnative
  • 'C:\32788r22fwjfw\swreg.3xe' ADD "HKCU\Console" /V "InsertMode" /T REG_DWORD /D 1
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "HKLM\SYSTEM\CurrentControlSet\Enum\Root"
  • 'C:\32788r22fwjfw\pev.3xe' UZIP License\pv_5_2_2.zip .\
  • 'C:\32788r22fwjfw\swreg.3xe' ADD HKCU\Console /V CodePage /T REG_DWORD /D "1252"
  • 'C:\32788r22fwjfw\swreg.3xe' ADD HKU\S-1-5-18\Console /V CodePage /T REG_DWORD /D "1252"
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY HKLM\System\CurrentControlSet\Control\NLS\Language /V Default
  • 'C:\32788r22fwjfw\sed.3xe' "/.* /!d; s///" NlsLanguage00
  • 'C:\32788r22fwjfw\grep.3xe' -isq "09$" NlsLanguageDefault
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY hklm\system\currentcontrolset\enum\root\system
  • 'C:\32788r22fwjfw\swsc.3xe' DELETE MBR
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "HKLM\SYSTEM\CurrentControlSet\Control\Nls\CodePage" /V ACP
  • 'C:\32788r22fwjfw\sed.3xe' -r "/.* (.:\\[^\\]*)$/!d; s//\1/"
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "HKLM\Software\Swearware" /V LastDir
  • 'C:\32788r22fwjfw\swreg.3xe' ADD "HKCU\Console" /v "QuickEdit" /T REG_DWORD /D 0
  • 'C:\32788r22fwjfw\pev.3xe' -limit1 -rtf -sasize "C:\32788R22FWJFW\en-US\*.3XE.mui"
  • 'C:\32788r22fwjfw\nircmd.3xe' CMDWAIT 6000 EXEC HIDE PEV -k CSCRIPT.exe
  • '%WINDIR%\syswow64\cscript.exe' //NOLOGO //E:VBSCRIPT //B //T:05 "C:\32788R22FWJFW\ksvchost.vbs"
  • 'C:\32788r22fwjfw\pev.3xe' -k NIRCMD.3XE
  • 'C:\32788r22fwjfw\sed.3xe' "/.* /!d; s//@CHCP.com /" NlsCodePageACP00
  • 'C:\32788r22fwjfw\swreg.3xe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys /D Driver
  • 'C:\32788r22fwjfw\swreg.3xe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys /D Driver
  • 'C:\32788r22fwjfw\grep.3xe' -Fsqix en-US MUI
  • 'C:\32788r22fwjfw\swreg.3xe' ACL "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" /RESET /Q
  • 'C:\32788r22fwjfw\swreg.3xe' DELETE HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option
  • 'C:\32788r22fwjfw\sed.3xe' -r "/.* /!d; s///; s/(\\0)*$//; s/\\0/\n/g" MUI00
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "HKCU\Control Panel\International" /v LocaleName
  • 'C:\32788r22fwjfw\swreg.3xe' QUERY "HKCU\Control Panel\Desktop\MuiCached" /v "MachinePreferredUILanguages"
  • 'C:\32788r22fwjfw\swreg.3xe' ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted" /V "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" /T REG_DWORD /D 1
  • 'C:\32788r22fwjfw\swreg.3xe' ACL "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" /RO:F /RA:F /Q
  • 'C:\32788r22fwjfw\sed.3xe' -r -n "G; s/\n/&&/; /^([ -~]*\n).*\n\1/d; s/\n//; h; P"
  • 'C:\32788r22fwjfw\pev.3xe' -outputtemp00 -rtf -c:##5# .\* and { License.exe or 32788R22FWJFW.exe or WinNT.exe or N_.exe }
  • 'C:\combofix_19.11.4.1\nircmdb.exe' QBOXCOMTOP "Current date is ~%CurrDate.yyyy-MM-dd%. ComboFix has expired~n~nClick 'Yes' to run in REDUCED FUNCTIONALITY mode~n~nClick 'No' to exit" "Version_19-11-04.01" "" FILLDELETE ABORTB
  • 'C:\combofix_19.11.4.1\cf13968.3xe' /F:OFF /D /C C:\Start_.cmd' (with hidden window)
  • '%WINDIR%\syswow64\ping.exe' -n 1 -w 250 127.0.0.1' (with hidden window)
  • 'C:\32788r22fwjfw\license\iexplore.exe' -loadline:C:\32788R22FWJFW\License\UnxUtilsDist.pif and not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }' (with hidden window)
  • 'C:\32788r22fwjfw\license\iexplore.exe' -s450000-1400000 -t!k -t!o -t!g -k C:\*.exe and not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }' (with hidden window)
  • 'C:\32788r22fwjfw\pev.3xe' RIMPORT C:\32788R22FWJFW\EXE.reg' (with hidden window)
  • 'C:\32788r22fwjfw\license\iexplore.exe' -loadline:C:\32788R22FWJFW\License\UnxUtilsDist.com and not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }' (with hidden window)
  • 'C:\32788r22fwjfw\license\iexplore.exe' -k "%TEMP%\*" not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /C %WINDIR%\SysNative\cmd.exe /c C:\32788R22FWJFW\fl0.bat' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c REGEDIT.EXE /S C:\32788R22FWJFW\W7Reg.dat' (with hidden window)
  • 'C:\32788r22fwjfw\license\iexplore.exe' -k { "%ALLUSERSPROFILE%\*" or "%HOMEPATH%\*" } not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }' (with hidden window)
  • 'C:\32788r22fwjfw\cmd.3xe' /C C:\32788R22FWJFW\p.cmd' (with hidden window)
  • 'C:\32788r22fwjfw\license\iexplore.exe' -rk { "%ProgramFiles(x86)%\*" OR "%CommonProgramFiles(x86)%\*" } not { "%TEMP%\7ZipSfx.000\ComboFix_19.11.4.1.exe" or C:\32788R22FWJFW\* }' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /C %WINDIR%\SysNative\cmd.exe /c C:\32788R22FWJFW\fl0.bat
  • '<SYSTEM32>\cmd.exe' /c C:\32788R22FWJFW\fl0.bat
  • '<SYSTEM32>\cmd.exe' /c REGEDIT.EXE /S C:\32788R22FWJFW\W7Reg.dat
  • '%WINDIR%\regedit.exe' /S C:\32788R22FWJFW\W7Reg.dat
  • '%WINDIR%\syswow64\findstr.exe' -B "6.1.760" CurVer
  • '%WINDIR%\syswow64\chcp.com' 1252
  • '<SYSTEM32>\attrib.exe' -H -S "C:\32788R22FWJFW\*"
  • '<SYSTEM32>\chcp.com' 1252
  • '%WINDIR%\syswow64\ping.exe' -n 1 -w 250 127.0.0.1
  • '<SYSTEM32>\sort.exe' /M 65536 Mirrors00 /O Mirrors

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android