マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話

03-6550-8770

Profile

Trojan.Siggen15.13676

Added to the Dr.Web virus database: 2021-09-10

Virus description added:

Technical Information

Malicious functions
To complicate detection of its presence in the operating system,
forces the system hide from view:
  • hidden files
  • file extensions
blocks execution of the following system utilities:
  • Windows Task Manager (Taskmgr)
  • Registry Editor (RegEdit)
  • Windows Defender
blocks the following features:
  • User Account Control (UAC)
modifies the following system settings:
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMorePrograms' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMyMusic' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoUserNameInStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoCommonGroups' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSecurityTab' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoThemesTab' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoChangeStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFavoritesMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRecentDocsMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoLogOff' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoActiveDesktop' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFileMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayContextMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewContextMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMFUprogramsList' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDrives' = '03FFFFFF'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuPinnedList' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayItemsDisplay' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFind' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoControlPanel' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetTaskbar' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetFolders' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMHelp' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'StartMenuLogoff' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMMyDocs' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMMyPictures' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSaveSettings' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuSubFolders' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoNetHood' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoAddPrinter' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDeletePrinter' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSimpleStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewOnDrive' = '03FFFFFF'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'DisallowRun' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoUserNameInStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoCommonGroups' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSecurityTab' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoThemesTab' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoChangeStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFavoritesMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewOnDrive' = '03FFFFFF'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRecentDocsMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoActiveDesktop' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFileMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayContextMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewContextMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDrives' = '03FFFFFF'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMorePrograms' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMyMusic' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMFUprogramsList' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuPinnedList' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSimpleStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoControlPanel' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetTaskbar' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetFolders' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMHelp' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMMyDocs' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'StartMenuLogoff' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSaveSettings' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuSubFolders' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoNetHood' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoAddPrinter' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDeletePrinter' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayItemsDisplay' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFind' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMMyPictures' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoLogOff' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'DisallowRun' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRecentDocsMenu' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMorePrograms' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMyMusic' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoUserNameInStartMenu' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoCommonGroups' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSecurityTab' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoThemesTab' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoChangeStartMenu' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFavoritesMenu' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRecentDocsMenu' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoLogOff' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoActiveDesktop' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFileMenu' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayContextMenu' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewContextMenu' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMFUprogramsList' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDrives' = '03FFFFFF'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuPinnedList' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayItemsDisplay' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFind' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoControlPanel' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetTaskbar' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetFolders' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMHelp' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'StartMenuLogoff' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMMyDocs' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMMyPictures' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSaveSettings' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuSubFolders' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoNetHood' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoAddPrinter' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDeletePrinter' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSimpleStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewOnDrive' = '03FFFFFF'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewOnDrive' = '03FFFFFF'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMyMusic' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoUserNameInStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoCommonGroups' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSecurityTab' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoThemesTab' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoChangeStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDrives' = '03FFFFFF'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFavoritesMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoLogOff' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoActiveDesktop' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFileMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayContextMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewContextMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMFUprogramsList' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuMorePrograms' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuPinnedList' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSimpleStartMenu' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoTrayItemsDisplay' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoControlPanel' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetTaskbar' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSetFolders' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMHelp' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'DisallowRun' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'DisallowRun' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'StartMenuLogoff' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSaveSettings' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuSubFolders' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoNetHood' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoAddPrinter' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDeletePrinter' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMMyDocs' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFind' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMMyPictures' = '00000001'
  • Hides taskbar notifications
Executes the following
  • '%WINDIR%\syswow64\taskkill.exe' /f /im edge.exe
  • '%WINDIR%\syswow64\taskkill.exe' /f /im mmc.exe
  • '%WINDIR%\syswow64\taskkill.exe' /f /im taskmgr.exe
  • '%WINDIR%\syswow64\taskkill.exe' /f /im processhacker.exe
  • '%WINDIR%\syswow64\taskkill.exe' /f /im processexplorer.exe
  • '%WINDIR%\syswow64\taskkill.exe' /f /im iexplore.exe
  • '%WINDIR%\syswow64\taskkill.exe' /f /im chrome.exe
  • '%WINDIR%\syswow64\taskkill.exe' /f /im powershell.exe
Terminates or attempts to terminate
the following user processes:
  • iexplore.exe
Modifies settings of Windows Internet Explorer
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Attachments] 'SaveZoneInformation' = '00000001'
  • [\REGISTRY\USER\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Attachments] 'SaveZoneInformation' = '00000001'
  • [\REGISTRY\USER\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Attachments] 'SaveZoneInformation' = '00000001'
  • [\REGISTRY\USER\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Attachments] 'SaveZoneInformation' = '00000001'
Modifies file system
Creates the following files
  • %WINDIR%\syswow64\temp\shutdowncounter.txt
Sets the 'hidden' attribute to the following files
  • %WINDIR%\syswow64\temp\shutdowncounter.txt
Deletes the following files
  • %WINDIR%\syswow64\windowspowershell\v1.0\certificate.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\examples\profile.ps1
  • %WINDIR%\syswow64\windowspowershell\v1.0\wsman.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\types.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\registry.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\pwrshsip.dll
  • %WINDIR%\syswow64\windowspowershell\v1.0\pwrshmsg.dll
  • %WINDIR%\syswow64\windowspowershell\v1.0\pspluginwkr.dll
  • %WINDIR%\syswow64\windowspowershell\v1.0\psevents.dll
  • %WINDIR%\syswow64\windowspowershell\v1.0\modules\psdiagnostics\psdiagnostics.psd1
  • %WINDIR%\syswow64\windowspowershell\v1.0\powershell_ise.exe
  • %WINDIR%\syswow64\windowspowershell\v1.0\powershellcore.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe
  • %WINDIR%\syswow64\windowspowershell\v1.0\help.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\getevent.types.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\filesystem.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\dotnettypes.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\diagnostics.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\compiledcomposition.microsoft.powershell.gpowershell.dll
  • %WINDIR%\syswow64\windowspowershell\v1.0\powershelltrace.format.ps1xml
  • %WINDIR%\syswow64\windowspowershell\v1.0\modules\psdiagnostics\psdiagnostics.psm1
Miscellaneous
Searches for the following windows
  • ClassName: '' WindowName: ''
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c rd /s /q <SYSTEM32>\Temp
  • '%WINDIR%\syswow64\cmd.exe' /c del /f /q <SYSTEM32>\bcdboot.exe
  • '%WINDIR%\syswow64\cmd.exe' /c del /f /q <SYSTEM32>\bcdedit.exe
  • '%WINDIR%\syswow64\cmd.exe' /c del /f /q <SYSTEM32>\bootsect.exe
  • '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im powershell.exe
  • '%WINDIR%\syswow64\cmd.exe' /c takeown /F "%ProgramFiles%\WindowsPowerShell" /R /D Y
  • '%WINDIR%\syswow64\takeown.exe' /F "%ProgramFiles%\WindowsPowerShell" /R /D Y
  • '%WINDIR%\syswow64\cmd.exe' /c icacls "%ProgramFiles%\WindowsPowerShell" /grant %Username%:F
  • '%WINDIR%\syswow64\icacls.exe' "%ProgramFiles%\WindowsPowerShell" /grant user:F
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%ProgramFiles%\WindowsPowerShell"
  • '%WINDIR%\syswow64\cmd.exe' /c icacls <SYSTEM32>\bootsect.exe /grant %Username%:F
  • '%WINDIR%\syswow64\icacls.exe' <SYSTEM32>\bootsect.exe /grant user:F
  • '%WINDIR%\syswow64\cmd.exe' /c rd /s /q "%ProgramFiles%\WindowsPowerShell"
  • '%WINDIR%\syswow64\cmd.exe' /c icacls "<SYSTEM32>\WindowsPowerShell\v1.0" /grant %Username%:F
  • '%WINDIR%\syswow64\icacls.exe' "<SYSTEM32>\WindowsPowerShell\v1.0" /grant user:F
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "<SYSTEM32>\WindowsPowerShell\v1.0"
  • '%WINDIR%\syswow64\cmd.exe' /c rd /s /q "<SYSTEM32>\WindowsPowerShell\v1.0"
  • '%WINDIR%\syswow64\cmd.exe' /c assoc .vbs=
  • '%WINDIR%\syswow64\cmd.exe' /c assoc .bat=
  • '%WINDIR%\syswow64\cmd.exe' /c assoc .inf=
  • '%WINDIR%\syswow64\cmd.exe' /c assoc .ps1=
  • '%WINDIR%\syswow64\cmd.exe' /c assoc .cmd=
  • '%WINDIR%\syswow64\cmd.exe' /c takeown /F "<SYSTEM32>\WindowsPowerShell\v1.0" /R /D Y
  • '%WINDIR%\syswow64\takeown.exe' /F "<SYSTEM32>\WindowsPowerShell\v1.0" /R /D Y
  • '%WINDIR%\syswow64\icacls.exe' <SYSTEM32>\bcdedit.exe /grant user:F
  • '%WINDIR%\syswow64\cmd.exe' /c icacls <SYSTEM32>\bcdedit.exe /grant %Username%:F
  • '%WINDIR%\syswow64\icacls.exe' <SYSTEM32>\bcdboot.exe /grant user:F
  • '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im mmc.exe
  • '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im taskmgr.exe
  • '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im processhacker.exe
  • '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im processexplorer.exe
  • '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im iexplore.exe
  • '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im chrome.exe
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%appdata%\Microsoft\Windows\Start Menu\Programs\*"
  • '%WINDIR%\syswow64\cmd.exe' /c attrib +r +s +h <SYSTEM32>\Temp
  • '%WINDIR%\syswow64\attrib.exe' +r +s +h <SYSTEM32>\Temp
  • '%WINDIR%\syswow64\cmd.exe' /c for /r <SYSTEM32>\Temp\ %i in (*.*) do attrib +r +s +h %i
  • '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im edge.exe
  • '%WINDIR%\syswow64\attrib.exe' +r +s +h <SYSTEM32>\Temp\shutdowncounter.txt
  • '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\Temp /R /D Y
  • '%WINDIR%\syswow64\cmd.exe' /c icacls <SYSTEM32>\Temp /deny Everyone:(DE,WO,AS,GW,WD,AD,WEA,DC,WA) /T /C /Q
  • '%WINDIR%\syswow64\icacls.exe' <SYSTEM32>\Temp /deny Everyone:(DE,WO,AS,GW,WD,AD,WEA,DC,WA) /T /C /Q
  • '%WINDIR%\syswow64\cmd.exe' /c takeown /f <SYSTEM32>\bcdboot.exe
  • '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\bcdboot.exe
  • '%WINDIR%\syswow64\cmd.exe' /c takeown /f <SYSTEM32>\bcdedit.exe
  • '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\bcdedit.exe
  • '%WINDIR%\syswow64\cmd.exe' /c takeown /f <SYSTEM32>\bootsect.exe
  • '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\bootsect.exe
  • '%WINDIR%\syswow64\cmd.exe' /c icacls <SYSTEM32>\bcdboot.exe /grant %Username%:F
  • '%WINDIR%\syswow64\cmd.exe' /c takeown /f <SYSTEM32>\Temp /R /D Y
  • '%WINDIR%\syswow64\cmd.exe' /c assoc .reg=
  • '%WINDIR%\syswow64\cmd.exe' /c pause

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android