マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.MulDrop5.5042

Added to the Dr.Web virus database: 2013-12-11

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Gl64564A29026' = '%HOMEPATH%\Sp26068Q16984\lsass.exe'
Malicious functions:
Creates and executes the following:
  • '%HOMEPATH%\Sp26068Q16984\lsass.exe'
Modifies file system :
Creates the following files:
  • %HOMEPATH%\Sp26068Q16984\12279.JSE
  • %HOMEPATH%\Sp26068Q16984\63990.EJU
  • %HOMEPATH%\Sp26068Q16984\J50310X69144.ACR
  • %HOMEPATH%\Sp26068Q16984\Y67033E42883.OFT
  • %HOMEPATH%\Sp26068Q16984\H31221Y52803.NOK
  • %HOMEPATH%\Sp26068Q16984\89366.HYD
  • %HOMEPATH%\Sp26068Q16984\57537.ZKS
  • %HOMEPATH%\Sp26068Q16984\J36419D92062.IDD
  • %HOMEPATH%\Sp26068Q16984\13922.AAC
  • %HOMEPATH%\Sp26068Q16984\I53540S84107.VHN
  • %HOMEPATH%\Sp26068Q16984\O25303G8880.LEF
  • %HOMEPATH%\Sp26068Q16984\16884.PEN
  • %HOMEPATH%\Sp26068Q16984\A68017S98537.HSX
  • %HOMEPATH%\Sp26068Q16984\78886.ITD
  • %HOMEPATH%\Sp26068Q16984\X47091Q9667.MTH
  • %HOMEPATH%\Sp26068Q16984\A80286U42779.HHF
  • %HOMEPATH%\Sp26068Q16984\K72153Y82251.EUW
  • %HOMEPATH%\Sp26068Q16984\J84335L65171.FCC
  • %HOMEPATH%\Sp26068Q16984\A57813Z29500.ECM
  • %HOMEPATH%\Sp26068Q16984\85050.WLA
  • %HOMEPATH%\Sp26068Q16984\56378.EKG
  • %HOMEPATH%\Sp26068Q16984\Q57155Q88886.ESL
  • %HOMEPATH%\Sp26068Q16984\99225.TIO
  • %HOMEPATH%\Sp26068Q16984\W54513W95050.HBL
  • %HOMEPATH%\Sp26068Q16984\Z42225X62399.EKU
  • %HOMEPATH%\Sp26068Q16984\20100.YDQ
  • %HOMEPATH%\Sp26068Q16984\91435.GJJ
  • %HOMEPATH%\Sp26068Q16984\16806.PCF
  • %HOMEPATH%\Sp26068Q16984\Z40309N31637.URD
  • %HOMEPATH%\Sp26068Q16984\B79452J22950.WBI
  • %HOMEPATH%\Sp26068Q16984\Y91011A46745.BBK
  • %HOMEPATH%\Sp26068Q16984\F76390B20304.JDD
  • %HOMEPATH%\Sp26068Q16984\54782.MRC
  • %HOMEPATH%\Sp26068Q16984\B70570Z54858.ADR
  • %HOMEPATH%\Sp26068Q16984\10519.AVD
  • %HOMEPATH%\Sp26068Q16984\44639.XFI
  • %HOMEPATH%\Sp26068Q16984\59477.BCP
  • %HOMEPATH%\Sp26068Q16984\E66192J22198.PGP
  • %HOMEPATH%\Sp26068Q16984\56483.RLM
  • %HOMEPATH%\Sp26068Q16984\I86271Y33362.PQH
  • %HOMEPATH%\Sp26068Q16984\29674.EYX
  • %HOMEPATH%\Sp26068Q16984\F20072K8889.AOI
  • %HOMEPATH%\Sp26068Q16984\T82411K71401.URB
  • %HOMEPATH%\Sp26068Q16984\M46664G5092.ILL
  • %HOMEPATH%\Sp26068Q16984\C48893J85975.BHK
  • %HOMEPATH%\Sp26068Q16984\W28133A52793.MTA
  • %HOMEPATH%\Sp26068Q16984\J56185E40391.KSD
  • %HOMEPATH%\Sp26068Q16984\M55852R81951.PSS
  • %HOMEPATH%\Sp26068Q16984\A13228N31190.LJP
  • %HOMEPATH%\Sp26068Q16984\61303.REV
  • %HOMEPATH%\Sp26068Q16984\R83216N52777.MYN
  • %HOMEPATH%\Sp26068Q16984\75323.QYL
  • %HOMEPATH%\Sp26068Q16984\36796.WZQ
  • %HOMEPATH%\Sp26068Q16984\T20338C85341.QNX
  • %HOMEPATH%\Sp26068Q16984\P51035F63323.VNQ
  • %HOMEPATH%\Sp26068Q16984\M58431C86306.IFD
  • %HOMEPATH%\Sp26068Q16984\L42843F80422.LFO
  • %HOMEPATH%\Sp26068Q16984\91639.KZB
  • %HOMEPATH%\Sp26068Q16984\O68482G82941.UEM
  • %HOMEPATH%\Sp26068Q16984\I36037R47064.LID
  • %HOMEPATH%\Sp26068Q16984\W80299H41412.DVJ
  • %HOMEPATH%\Sp26068Q16984\Q15586L41099.XQB
  • %HOMEPATH%\Sp26068Q16984\O6432M62145.OXO
  • %HOMEPATH%\Sp26068Q16984\A41112L1414.ODD
  • %HOMEPATH%\Sp26068Q16984\68203.FSU
  • %HOMEPATH%\Sp26068Q16984\N76428T76117.DYL
  • %HOMEPATH%\Sp26068Q16984\G39192K25698.OPD
  • %HOMEPATH%\Sp26068Q16984\P87418Y25441.QVN
  • %HOMEPATH%\Sp26068Q16984\X22238G47406.UHS
  • %HOMEPATH%\Sp26068Q16984\G21249D61285.CIL
  • %HOMEPATH%\Sp26068Q16984\71844.VGA
  • %HOMEPATH%\Sp26068Q16984\53106.PMN
  • %HOMEPATH%\Sp26068Q16984\P85736D16208.EWY
  • %HOMEPATH%\Sp26068Q16984\E75297L76243.HKL
  • %HOMEPATH%\Sp26068Q16984\12210.KRU
  • %HOMEPATH%\Sp26068Q16984\S92792L18334.RPF
  • %HOMEPATH%\Sp26068Q16984\D59905W50989.KCQ
  • %HOMEPATH%\Sp26068Q16984\69421.IVY
  • %HOMEPATH%\Sp26068Q16984\Z51347A85053.FVG
  • %HOMEPATH%\Sp26068Q16984\O51925F79534.STN
  • %HOMEPATH%\Sp26068Q16984\89919.PIB
  • %HOMEPATH%\Sp26068Q16984\19059.ZBF
  • %HOMEPATH%\Sp26068Q16984\I79319N19630.OXJ
  • %HOMEPATH%\Sp26068Q16984\78612.UZX
  • %HOMEPATH%\Sp26068Q16984\S68867F64537.VWO
  • %HOMEPATH%\Sp26068Q16984\48289.HUQ
  • %HOMEPATH%\Sp26068Q16984\J52030E25539.KNL
  • %HOMEPATH%\Sp26068Q16984\40522.VZS
  • %HOMEPATH%\Sp26068Q16984\53974.GTN
  • %HOMEPATH%\Sp26068Q16984\35066.LHV
  • %HOMEPATH%\Sp26068Q16984\U18080M27749.GJV
  • %HOMEPATH%\Sp26068Q16984\G21036B42970.HEK
  • %HOMEPATH%\Sp26068Q16984\Z50034F81838.RCE
  • %HOMEPATH%\Sp26068Q16984\83376.SFT
  • %HOMEPATH%\Sp26068Q16984\X92373J65634.ISR
  • %HOMEPATH%\Sp26068Q16984\26653.WXB
  • %HOMEPATH%\Sp26068Q16984\4396.NFS
  • %HOMEPATH%\Sp26068Q16984\25449.VHC
  • %HOMEPATH%\Sp26068Q16984\68037.KMK
  • %HOMEPATH%\Sp26068Q16984\K26574Y82788.DMO
  • %HOMEPATH%\Sp26068Q16984\Q62061J64832.LEB
  • %HOMEPATH%\Sp26068Q16984\29413.MJO
  • %HOMEPATH%\Sp26068Q16984\88174.GGJ
  • %HOMEPATH%\Sp26068Q16984\K4312M94942.QCI
  • %HOMEPATH%\Sp26068Q16984\45619.VAX
  • %HOMEPATH%\Sp26068Q16984\M30896M87252.OBA
  • %HOMEPATH%\Sp26068Q16984\12364.KCJ
  • %HOMEPATH%\Sp26068Q16984\81159.YAL
  • %HOMEPATH%\Sp26068Q16984\9213.GTL
  • %HOMEPATH%\Sp26068Q16984\R27940Z56502.QNW
  • %HOMEPATH%\Sp26068Q16984\V97851W33697.IJF
  • %HOMEPATH%\Sp26068Q16984\Y47044X9559.XQH
  • %HOMEPATH%\Sp26068Q16984\R89363E84307.DQP
  • %HOMEPATH%\Sp26068Q16984\H97959V43545.TZL
  • %HOMEPATH%\Sp26068Q16984\W5654W42818.TKI
  • %HOMEPATH%\Sp26068Q16984\Q73376P53817.WPH
  • %HOMEPATH%\Sp26068Q16984\R36527R97861.BVW
  • %HOMEPATH%\Sp26068Q16984\94488.MIW
  • %HOMEPATH%\Sp26068Q16984\8585.BTL
  • %HOMEPATH%\Sp26068Q16984\71710.FXH
  • %HOMEPATH%\Sp26068Q16984\58167.MAN
  • %HOMEPATH%\Sp26068Q16984\98681.WKO
  • %HOMEPATH%\Sp26068Q16984\28309.DJH
  • %HOMEPATH%\Sp26068Q16984\91299.NCU
  • %HOMEPATH%\Sp26068Q16984\10010.SOF
  • %HOMEPATH%\Sp26068Q16984\E58256H59173.MGO
  • %HOMEPATH%\Sp26068Q16984\19619.BDU
  • %HOMEPATH%\Sp26068Q16984\M46542P44652.ADG
  • %HOMEPATH%\Sp26068Q16984\11215.YHL
  • %HOMEPATH%\Sp26068Q16984\Z57544D3543.NJB
  • %HOMEPATH%\Sp26068Q16984\I62609D17422.ZGD
  • %HOMEPATH%\Sp26068Q16984\64607.AUZ
  • %HOMEPATH%\Sp26068Q16984\57554.TAU
  • %HOMEPATH%\Sp26068Q16984\K19751E16545.SFH
  • %HOMEPATH%\Sp26068Q16984\60101.ONW
  • %HOMEPATH%\Sp26068Q16984\74728.BST
  • %HOMEPATH%\Sp26068Q16984\42818.OWP
  • %HOMEPATH%\Sp26068Q16984\W14469B88681.DMF
  • %HOMEPATH%\Sp26068Q16984\66790.BST
  • %HOMEPATH%\Sp26068Q16984\I58320T89138.JYB
  • %HOMEPATH%\Sp26068Q16984\68129.BFS
  • %HOMEPATH%\Sp26068Q16984\O34197L2410.JIY
  • %HOMEPATH%\Sp26068Q16984\66602.SEA
  • %HOMEPATH%\Sp26068Q16984\S65630C98546.GUB
  • %HOMEPATH%\Sp26068Q16984\28009.SPB
  • %HOMEPATH%\Sp26068Q16984\67767.KGO
  • %HOMEPATH%\Sp26068Q16984\T23020X63940.UAT
  • %HOMEPATH%\Sp26068Q16984\67422.IZR
  • %HOMEPATH%\Sp26068Q16984\D87479J12603.EAJ
  • %HOMEPATH%\Sp26068Q16984\11877.ZED
  • %HOMEPATH%\Sp26068Q16984\94939.IKK
  • %HOMEPATH%\Sp26068Q16984\P32439A7373.KDY
  • %HOMEPATH%\Sp26068Q16984\O62487Z76947.AKF
  • %HOMEPATH%\Sp26068Q16984\65565.ONW
  • %HOMEPATH%\Sp26068Q16984\L89179P84202.XKM
  • %HOMEPATH%\Sp26068Q16984\L55064T29938.MQC
  • %HOMEPATH%\Sp26068Q16984\C82614X12887.FJN
  • %HOMEPATH%\Sp26068Q16984\Z28838V55685.CEA
  • %HOMEPATH%\Sp26068Q16984\56486.DQJ
  • %HOMEPATH%\Sp26068Q16984\42332.PND
  • %HOMEPATH%\Sp26068Q16984\25250.QUY
  • %HOMEPATH%\Sp26068Q16984\Y85675I63426.ZXL
  • %HOMEPATH%\Sp26068Q16984\P13976C50267.JNF
  • %HOMEPATH%\Sp26068Q16984\67529.ESL
  • %HOMEPATH%\Sp26068Q16984\Z18595N92749.EKH
  • %HOMEPATH%\Sp26068Q16984\58535.PYS
  • %HOMEPATH%\Sp26068Q16984\G86160P95416.FUS
  • %HOMEPATH%\Ls76914K58974.txt
  • %TEMP%\aut1.tmp
  • %HOMEPATH%\Ky58341C31176.YI5
  • C:\lsass.exe
  • %HOMEPATH%\Sp26068Q16984\T26298X45775.FVY
  • %HOMEPATH%\Sp26068Q16984\31004.ECU
  • %HOMEPATH%\Sp26068Q16984\MB.MGO
  • %HOMEPATH%\Sp26068Q16984\G14863F94762.UON
  • %HOMEPATH%\Sp26068Q16984\N91379F24377.QDW
  • %HOMEPATH%\Sp26068Q16984\72441.JIF
  • %HOMEPATH%\Sp26068Q16984\Q13416D6778.FZF
  • %HOMEPATH%\Sp26068Q16984\14183.NPQ
  • %HOMEPATH%\Sp26068Q16984\T92651W24026.NTI
  • %HOMEPATH%\Sp26068Q16984\S14587Q38713.VRV
  • %HOMEPATH%\Sp26068Q16984\R51362Y8055.YLW
  • %HOMEPATH%\Sp26068Q16984\4504.LPU
  • %HOMEPATH%\Sp26068Q16984\Q37241W9923.KHK
  • %HOMEPATH%\Sp26068Q16984\36233.LJT
  • %HOMEPATH%\Sp26068Q16984\R9027A84255.NBS
  • %HOMEPATH%\Sp26068Q16984\F84504V81255.NWB
  • %HOMEPATH%\Sp26068Q16984\Z95791C34159.BOO
  • %HOMEPATH%\Sp26068Q16984\G98377V76591.PBI
  • %HOMEPATH%\Sp26068Q16984\97858.QMM
  • %HOMEPATH%\Sp26068Q16984\G74120Q25983.FWH
  • %HOMEPATH%\Sp26068Q16984\28847.VEW
  • %HOMEPATH%\Sp26068Q16984\A34822B64509.OAQ
  • %HOMEPATH%\Sp26068Q16984\O31522B64546.JTA
  • %HOMEPATH%\Sp26068Q16984\98712.MAO
  • %HOMEPATH%\Sp26068Q16984\40617.WRR
  • %HOMEPATH%\Sp26068Q16984\24294.BAP
  • %HOMEPATH%\Sp26068Q16984\I85572U55951.JYE
  • %HOMEPATH%\Sp26068Q16984\15778.HFT
  • %HOMEPATH%\Sp26068Q16984\G57920Y27440.UUU
  • %HOMEPATH%\Sp26068Q16984\P31252H83395.USK
  • %HOMEPATH%\Sp26068Q16984\N46812Q22843.TNM
  • %HOMEPATH%\Sp26068Q16984\B46692M92921.LDM
  • %HOMEPATH%\Sp26068Q16984\U22472P40251.OSL
  • %HOMEPATH%\Sp26068Q16984\18266.UXC
  • %HOMEPATH%\Sp26068Q16984\15776.QXG
  • %HOMEPATH%\Sp26068Q16984\94396.DDR
  • %HOMEPATH%\Sp26068Q16984\48182.NZY
  • %HOMEPATH%\Sp26068Q16984\77123.NFT
  • %HOMEPATH%\Sp26068Q16984\C29171H51459.MQJ
  • %HOMEPATH%\Sp26068Q16984\93076.DZD
  • %HOMEPATH%\Sp26068Q16984\88579.CVU
  • %HOMEPATH%\Sp26068Q16984\58662.DWY
  • %HOMEPATH%\Sp26068Q16984\S79220W88240.JSI
  • %HOMEPATH%\Sp26068Q16984\H17434W79003.JJB
  • %HOMEPATH%\Sp26068Q16984\U56554Z61413.YRK
  • %HOMEPATH%\Sp26068Q16984\53069.BSR
  • %HOMEPATH%\Sp26068Q16984\D44880D25770.SKC
  • %HOMEPATH%\Sp26068Q16984\J40321X67003.QJQ
  • %HOMEPATH%\Sp26068Q16984\8876.DRS
  • %HOMEPATH%\Sp26068Q16984\Y27455S1808.TWH
  • %HOMEPATH%\Sp26068Q16984\G58273R1557.ISG
  • %HOMEPATH%\Sp26068Q16984\38869.OCT
  • %HOMEPATH%\Sp26068Q16984\W23266G27474.LIH
  • %HOMEPATH%\Sp26068Q16984\44949.BJV
  • %HOMEPATH%\Sp26068Q16984\N59274I67151.CJM
  • %HOMEPATH%\Sp26068Q16984\10968.FGC
  • %HOMEPATH%\Sp26068Q16984\21531.CMO
  • %HOMEPATH%\Sp26068Q16984\P46579L20549.NXL
  • %HOMEPATH%\Sp26068Q16984\60496.RWO
  • %HOMEPATH%\Sp26068Q16984\33523.WAR
  • %HOMEPATH%\Sp26068Q16984\36442.GVN
  • %HOMEPATH%\Sp26068Q16984\94808.KXB
  • %HOMEPATH%\Sp26068Q16984\63248.YPZ
  • %HOMEPATH%\Sp26068Q16984\49776.EEU
  • %HOMEPATH%\Sp26068Q16984\R59943W81546.ZFJ
  • %HOMEPATH%\Sp26068Q16984\G41040A60596.OPU
  • %HOMEPATH%\Sp26068Q16984\M92545L6171.QFQ
  • %HOMEPATH%\Sp26068Q16984\6827.SBQ
  • %HOMEPATH%\Sp26068Q16984\19673.HCF
  • %HOMEPATH%\Sp26068Q16984\21248.FRW
  • %HOMEPATH%\Sp26068Q16984\69800.TNJ
  • %HOMEPATH%\Sp26068Q16984\85346.RRX
  • %HOMEPATH%\Sp26068Q16984\10475.LOR
  • %HOMEPATH%\Sp26068Q16984\60544.EWL
  • %HOMEPATH%\Sp26068Q16984\K96713K61369.SMH
  • %HOMEPATH%\Sp26068Q16984\X44230V5113.PAP
  • %HOMEPATH%\Sp26068Q16984\P97163P77579.LII
  • %HOMEPATH%\Sp26068Q16984\31617.LRO
  • %HOMEPATH%\Sp26068Q16984\N48637X97563.PJO
  • %HOMEPATH%\Sp26068Q16984\U55171V80604.YPN
  • %HOMEPATH%\Sp26068Q16984\83182.JTN
  • %HOMEPATH%\Sp26068Q16984\H45073J25100.KPC
  • %HOMEPATH%\Sp26068Q16984\W60128H48869.WCO
  • %HOMEPATH%\Sp26068Q16984\25183.CDW
  • %HOMEPATH%\Sp26068Q16984\M59820Z85549.MRM
  • %HOMEPATH%\Sp26068Q16984\59335.JSZ
  • %HOMEPATH%\Sp26068Q16984\4359.BSO
  • %HOMEPATH%\Sp26068Q16984\R93834Y91603.UWI
  • %HOMEPATH%\Sp26068Q16984\80916.BNT
  • %HOMEPATH%\Sp26068Q16984\T49005T91687.SHX
  • %HOMEPATH%\Sp26068Q16984\W47867T64103.HQW
  • %HOMEPATH%\Sp26068Q16984\S95502O12229.OWE
  • %HOMEPATH%\Sp26068Q16984\35809.UJD
  • %HOMEPATH%\Sp26068Q16984\B50490I72585.PBO
  • %HOMEPATH%\Sp26068Q16984\V78365Q58769.DFU
  • %HOMEPATH%\Sp26068Q16984\L35751M89195.KSQ
  • %HOMEPATH%\Sp26068Q16984\R58862Y96397.IOI
  • %HOMEPATH%\Sp26068Q16984\G52127G85373.NAN
  • %HOMEPATH%\Sp26068Q16984\47802.JPD
  • %HOMEPATH%\Sp26068Q16984\17267.VTX
  • %HOMEPATH%\Sp26068Q16984\D95089S76871.EHQ
  • %HOMEPATH%\Sp26068Q16984\96027.ASU
  • %HOMEPATH%\Sp26068Q16984\W24308I46372.VQG
  • %HOMEPATH%\Sp26068Q16984\58945.UAZ
  • %HOMEPATH%\Sp26068Q16984\36089.OED
  • %HOMEPATH%\Sp26068Q16984\H89185T84930.UWL
  • %HOMEPATH%\Sp26068Q16984\Q74764P71746.WHJ
  • %HOMEPATH%\Sp26068Q16984\18219.LUP
  • %HOMEPATH%\Sp26068Q16984\68097.RPJ
  • %HOMEPATH%\Sp26068Q16984\62816.JDH
  • %HOMEPATH%\Sp26068Q16984\O95783T88525.AFG
  • %HOMEPATH%\Sp26068Q16984\78438.CNV
  • %HOMEPATH%\Sp26068Q16984\48230.TOB
  • %HOMEPATH%\Sp26068Q16984\6281.ARS
  • %HOMEPATH%\Sp26068Q16984\42506.LGK
  • %HOMEPATH%\Sp26068Q16984\F3315T67558.MOZ
  • %HOMEPATH%\Sp26068Q16984\A82662B71063.CFX
  • %HOMEPATH%\Sp26068Q16984\X9959W27670.EMV
  • %HOMEPATH%\Sp26068Q16984\T40581P98261.TUL
  • %HOMEPATH%\Sp26068Q16984\36393.NLU
  • %HOMEPATH%\Sp26068Q16984\77071.PNK
  • %HOMEPATH%\Sp26068Q16984\69283.KBK
  • %HOMEPATH%\Sp26068Q16984\51080.BAA
  • %HOMEPATH%\Sp26068Q16984\55393.ONY
  • %HOMEPATH%\Sp26068Q16984\O23989R42457.YDZ
  • %HOMEPATH%\Sp26068Q16984\U73008S32527.JZT
  • %HOMEPATH%\Sp26068Q16984\E68332X71966.ZLW
  • %HOMEPATH%\Sp26068Q16984\75883.WYD
  • %HOMEPATH%\Sp26068Q16984\T77388J92573.FFJ
  • %HOMEPATH%\Sp26068Q16984\P5545T30179.YYZ
  • %HOMEPATH%\Sp26068Q16984\9558.YVM
  • %HOMEPATH%\Sp26068Q16984\75273.TCZ
  • %HOMEPATH%\Sp26068Q16984\33961.PXN
  • %HOMEPATH%\Sp26068Q16984\51520.ELH
  • %HOMEPATH%\Sp26068Q16984\31133.YLH
  • %HOMEPATH%\Sp26068Q16984\Y31755C75672.IWR
  • %HOMEPATH%\Sp26068Q16984\25889.IDI
  • %HOMEPATH%\Sp26068Q16984\N34732E48764.FWR
  • %HOMEPATH%\Sp26068Q16984\21304.QCD
  • %HOMEPATH%\Sp26068Q16984\92533.LRS
  • %HOMEPATH%\Sp26068Q16984\79856.XHP
  • %HOMEPATH%\Sp26068Q16984\L71645K74024.GNM
  • %HOMEPATH%\Sp26068Q16984\I4628L47336.SXC
  • %HOMEPATH%\Sp26068Q16984\5115.GER
  • %HOMEPATH%\Sp26068Q16984\H72658D36076.BCD
  • %HOMEPATH%\Sp26068Q16984\54488.AZX
  • %HOMEPATH%\Sp26068Q16984\F14355H92506.OSF
  • %HOMEPATH%\Sp26068Q16984\R88308O28540.XDR
  • %HOMEPATH%\Sp26068Q16984\I51541C43742.PVA
  • %HOMEPATH%\Sp26068Q16984\A35233X3712.FOF
  • %HOMEPATH%\Sp26068Q16984\H8854D9921.CBV
  • %HOMEPATH%\Sp26068Q16984\H59899G65285.TWS
  • %HOMEPATH%\Sp26068Q16984\N53305E56142.NZA
  • %HOMEPATH%\Sp26068Q16984\42350.OZV
  • %HOMEPATH%\Sp26068Q16984\D46782T16590.QDT
  • %HOMEPATH%\Sp26068Q16984\2075.LRO
  • %HOMEPATH%\Sp26068Q16984\66516.GKP
  • %HOMEPATH%\Sp26068Q16984\B40853U59563.GZO
  • %HOMEPATH%\Sp26068Q16984\44230.KJG
  • %HOMEPATH%\Sp26068Q16984\1716.CWZ
  • %HOMEPATH%\Sp26068Q16984\W52484V83392.RKG
  • %HOMEPATH%\Sp26068Q16984\B16304R39226.JOE
  • %HOMEPATH%\Sp26068Q16984\78288.QEX
  • %HOMEPATH%\Sp26068Q16984\W21645D41097.MIV
  • %HOMEPATH%\Sp26068Q16984\8488.PJX
  • %HOMEPATH%\Sp26068Q16984\I51709O26997.TKL
  • %HOMEPATH%\Sp26068Q16984\43683.ZVL
  • %HOMEPATH%\Sp26068Q16984\I20909N32678.ACT
  • %HOMEPATH%\Sp26068Q16984\lsass.exe
  • %HOMEPATH%\Sp26068Q16984\20718.GOC
  • %HOMEPATH%\Sp26068Q16984\O38981Q31778.VMQ
  • %HOMEPATH%\Sp26068Q16984\Z14093U99194.RDI
  • %HOMEPATH%\Sp26068Q16984\59980.SKM
  • %HOMEPATH%\Sp26068Q16984\G61050P45198.WQF
  • %HOMEPATH%\Sp26068Q16984\74728.NBW
  • %HOMEPATH%\Sp26068Q16984\G63744M14246.HXT
  • %HOMEPATH%\Sp26068Q16984\H63308Y18753.ZJY
  • %HOMEPATH%\Sp26068Q16984\79979.TXY
  • %HOMEPATH%\Sp26068Q16984\T89938S59207.ZTI
  • %HOMEPATH%\Sp26068Q16984\80434.QVW
  • %HOMEPATH%\Sp26068Q16984\17384.KKC
  • %HOMEPATH%\Sp26068Q16984\Z8077F73782.ZFR
  • %HOMEPATH%\Sp26068Q16984\S72012K5542.WRK
  • %HOMEPATH%\Sp26068Q16984\54604.JDW
  • %HOMEPATH%\Sp26068Q16984\S70092U69179.DND
  • %HOMEPATH%\Sp26068Q16984\20371.SPS
  • %HOMEPATH%\Sp26068Q16984\C2175B71223.ZYT
  • %HOMEPATH%\Sp26068Q16984\63863.HMB
  • %HOMEPATH%\Sp26068Q16984\X55224Y32952.FZZ
  • %HOMEPATH%\Sp26068Q16984\23596.CNO
  • %HOMEPATH%\Sp26068Q16984\73665.PRJ
  • %HOMEPATH%\Sp26068Q16984\Z99583X55620.TQH
  • %HOMEPATH%\Sp26068Q16984\G15538R34955.QYL
  • %HOMEPATH%\Sp26068Q16984\29540.KLJ
  • %HOMEPATH%\Sp26068Q16984\27469.IMP
  • %HOMEPATH%\Sp26068Q16984\70304.HRT
  • %HOMEPATH%\Sp26068Q16984\52325.EUP
  • %HOMEPATH%\Sp26068Q16984\Q52524Q23349.SSJ
  • %HOMEPATH%\Sp26068Q16984\P97248H92499.YLA
  • %HOMEPATH%\Sp26068Q16984\96666.JYK
  • %HOMEPATH%\Sp26068Q16984\23099.UVZ
  • %HOMEPATH%\Sp26068Q16984\U89103E22192.KLZ
  • %HOMEPATH%\Sp26068Q16984\16292.GRV
  • %HOMEPATH%\Sp26068Q16984\O72872O22715.GAS
  • %HOMEPATH%\Sp26068Q16984\69779.HYU
  • %HOMEPATH%\Sp26068Q16984\64995.NMY
  • %HOMEPATH%\Sp26068Q16984\A18664I3810.NRE
  • %HOMEPATH%\Sp26068Q16984\31199.MAM
  • %HOMEPATH%\Sp26068Q16984\X30606G83663.DNV
  • %HOMEPATH%\Sp26068Q16984\N13947H49578.QMW
  • %HOMEPATH%\Sp26068Q16984\P74748L75087.XND
  • %HOMEPATH%\Sp26068Q16984\O59094E75280.IUP
  • %HOMEPATH%\Sp26068Q16984\5444.OBR
  • %HOMEPATH%\Sp26068Q16984\O58474K67313.HNO
  • %HOMEPATH%\Sp26068Q16984\Z66707C30823.WGQ
  • %HOMEPATH%\Sp26068Q16984\I75339A48400.CGO
  • %HOMEPATH%\Sp26068Q16984\85160.OBZ
  • %HOMEPATH%\Sp26068Q16984\62093.ZHG
  • %HOMEPATH%\Sp26068Q16984\D73056C68104.BEU
  • %HOMEPATH%\Sp26068Q16984\E16698G59224.AHD
  • %HOMEPATH%\Sp26068Q16984\M98014M35277.GHQ
  • %HOMEPATH%\Sp26068Q16984\13820.QOT
  • %HOMEPATH%\Sp26068Q16984\U64005S36012.YNU
  • %HOMEPATH%\Sp26068Q16984\80158.WEE
  • %HOMEPATH%\Sp26068Q16984\10061.DQD
  • %HOMEPATH%\Sp26068Q16984\3446.BSP
  • %HOMEPATH%\Sp26068Q16984\P43906C37423.DJC
  • %HOMEPATH%\Sp26068Q16984\A35928M89062.WVK
  • %HOMEPATH%\Sp26068Q16984\16783.AVE
  • %HOMEPATH%\Sp26068Q16984\3199.FYJ
  • %HOMEPATH%\Sp26068Q16984\6612.XLS
  • %HOMEPATH%\Sp26068Q16984\92393.HJR
  • %HOMEPATH%\Sp26068Q16984\92570.AZR
  • %HOMEPATH%\Sp26068Q16984\26942.SWY
  • %HOMEPATH%\Sp26068Q16984\29100.JFP
  • %HOMEPATH%\Sp26068Q16984\92650.RIG
  • %HOMEPATH%\Sp26068Q16984\A96503G83306.MCW
  • %HOMEPATH%\Sp26068Q16984\A36516A65814.IUA
  • %HOMEPATH%\Sp26068Q16984\V27166L81166.CYO
  • %HOMEPATH%\Sp26068Q16984\13313.NUF
  • %HOMEPATH%\Sp26068Q16984\L29879B21608.ALW
  • %HOMEPATH%\Sp26068Q16984\G86270G75605.EZO
  • %HOMEPATH%\Sp26068Q16984\14068.AJT
  • %HOMEPATH%\Sp26068Q16984\5130.DRC
  • %HOMEPATH%\Sp26068Q16984\71569.GMT
  • %HOMEPATH%\Sp26068Q16984\10784.AYU
  • %HOMEPATH%\Sp26068Q16984\75202.HFO
  • %HOMEPATH%\Sp26068Q16984\55293.GZH
  • %HOMEPATH%\Sp26068Q16984\Z78535H25289.RWL
  • %HOMEPATH%\Sp26068Q16984\61729.WAG
  • %HOMEPATH%\Sp26068Q16984\N54142X43171.ONL
  • %HOMEPATH%\Sp26068Q16984\97832.OAF
  • %HOMEPATH%\Sp26068Q16984\35837.AHF
  • %HOMEPATH%\Sp26068Q16984\4965.RWG
  • %HOMEPATH%\Sp26068Q16984\N81327E81848.BFN
  • %HOMEPATH%\Sp26068Q16984\87616.NDX
  • %HOMEPATH%\Sp26068Q16984\H47120K40195.KEP
  • %HOMEPATH%\Sp26068Q16984\40283.JYQ
  • %HOMEPATH%\Sp26068Q16984\54304.HQM
  • %HOMEPATH%\Sp26068Q16984\68718.FPG
  • %HOMEPATH%\Sp26068Q16984\U92775Z94126.GCC
  • %HOMEPATH%\Sp26068Q16984\A45279F73148.XPM
  • %HOMEPATH%\Sp26068Q16984\59491.IUC
  • %HOMEPATH%\Sp26068Q16984\1879.QPM
  • %HOMEPATH%\Sp26068Q16984\K98066M1232.GET
  • %HOMEPATH%\Sp26068Q16984\94246.SOZ
  • %HOMEPATH%\Sp26068Q16984\Q1871D82621.UMF
  • %HOMEPATH%\Sp26068Q16984\O54607N12880.BPP
  • %HOMEPATH%\Sp26068Q16984\20817.VGT
  • %HOMEPATH%\Sp26068Q16984\39074.HSF
  • %HOMEPATH%\Sp26068Q16984\34407.SPM
  • %HOMEPATH%\Sp26068Q16984\1558.RLH
  • %HOMEPATH%\Sp26068Q16984\58097.EIM
  • %HOMEPATH%\Sp26068Q16984\Z94829W30132.UCI
  • %HOMEPATH%\Sp26068Q16984\19456.HBB
  • %HOMEPATH%\Sp26068Q16984\93109.VVJ
  • %HOMEPATH%\Sp26068Q16984\J43467O24926.YFU
  • %HOMEPATH%\Sp26068Q16984\B66190W78316.RXP
  • %HOMEPATH%\Sp26068Q16984\69362.LJX
  • %HOMEPATH%\Sp26068Q16984\K16202W53140.TYO
  • %HOMEPATH%\Sp26068Q16984\82657.VIQ
  • %HOMEPATH%\Sp26068Q16984\21684.MLB
  • %HOMEPATH%\Sp26068Q16984\11943.FLW
  • %HOMEPATH%\Sp26068Q16984\Q41241G22322.RCN
  • %HOMEPATH%\Sp26068Q16984\20723.AYT
  • %HOMEPATH%\Sp26068Q16984\40464.XYC
  • %HOMEPATH%\Sp26068Q16984\K63498T90941.JMA
  • %HOMEPATH%\Sp26068Q16984\D27095K83533.AHO
  • %HOMEPATH%\Sp26068Q16984\11205.MCT
  • %HOMEPATH%\Sp26068Q16984\S5252M33914.SGR
  • %HOMEPATH%\Sp26068Q16984\76019.EUK
  • %HOMEPATH%\Sp26068Q16984\13895.NJX
  • %HOMEPATH%\Sp26068Q16984\63631.HDC
  • %HOMEPATH%\Sp26068Q16984\75004.OOG
  • %HOMEPATH%\Sp26068Q16984\B62984F75932.MAL
  • %HOMEPATH%\Sp26068Q16984\U83013O72200.YLW
  • %HOMEPATH%\Sp26068Q16984\11472.YWW
  • %HOMEPATH%\Sp26068Q16984\I53679Q43806.OCT
  • %HOMEPATH%\Sp26068Q16984\25827.AHG
  • %HOMEPATH%\Sp26068Q16984\76620.YYP
  • %HOMEPATH%\Sp26068Q16984\49165.WPD
  • %HOMEPATH%\Sp26068Q16984\26506.AKJ
  • %HOMEPATH%\Sp26068Q16984\65956.USL
  • %HOMEPATH%\Sp26068Q16984\66541.KWG
  • %HOMEPATH%\Sp26068Q16984\T61215B82129.BSQ
  • %HOMEPATH%\Sp26068Q16984\86797.EPC
  • %HOMEPATH%\Sp26068Q16984\U64932N66428.EWV
  • %HOMEPATH%\Sp26068Q16984\B90958X91424.AFZ
  • %HOMEPATH%\Sp26068Q16984\82559.BEU
  • %HOMEPATH%\Sp26068Q16984\T29114W46810.OBY
  • %HOMEPATH%\Sp26068Q16984\31086.JQE
  • %HOMEPATH%\Sp26068Q16984\J68181T63411.NTX
  • %HOMEPATH%\Sp26068Q16984\93036.SKA
  • %HOMEPATH%\Sp26068Q16984\78740.AQR
  • %HOMEPATH%\Sp26068Q16984\6314.QRQ
  • %HOMEPATH%\Sp26068Q16984\29839.KXD
  • %HOMEPATH%\Sp26068Q16984\C76667Q12937.WFH
  • %HOMEPATH%\Sp26068Q16984\99039.JXH
  • %HOMEPATH%\Sp26068Q16984\83342.VRM
  • %HOMEPATH%\Sp26068Q16984\T26886U78583.NSK
  • %HOMEPATH%\Sp26068Q16984\48801.CRH
  • %HOMEPATH%\Sp26068Q16984\32138.UBK
  • %HOMEPATH%\Sp26068Q16984\T49071Q89917.NVL
  • %HOMEPATH%\Sp26068Q16984\78645.CMK
  • %HOMEPATH%\Sp26068Q16984\44022.LRK
  • %HOMEPATH%\Sp26068Q16984\6571.NOW
  • %HOMEPATH%\Sp26068Q16984\74178.AJT
  • %HOMEPATH%\Sp26068Q16984\7402.JUL
  • %HOMEPATH%\Sp26068Q16984\J72942X14021.RJK
  • %HOMEPATH%\Sp26068Q16984\I27558N30442.MPS
  • %HOMEPATH%\Sp26068Q16984\57058.LGF
  • %HOMEPATH%\Sp26068Q16984\62568.FFJ
  • %HOMEPATH%\Sp26068Q16984\U29900S5343.TSQ
  • %HOMEPATH%\Sp26068Q16984\79896.VGL
  • %HOMEPATH%\Sp26068Q16984\R3346U44491.DDM
  • %HOMEPATH%\Sp26068Q16984\X40225A51036.BFH
  • %HOMEPATH%\Sp26068Q16984\F65667K56691.KBW
  • %HOMEPATH%\Sp26068Q16984\W68013C36980.KLK
Sets the 'hidden' attribute to the following files:
  • %HOMEPATH%\Ky58341C31176.YI5
  • %HOMEPATH%\Ls76914K58974.txt
Deletes the following files:
  • %TEMP%\aut1.tmp
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Indicator' WindowName: '(null)'
  • ClassName: 'Shell_TrayWnd' WindowName: '(null)'
  • ClassName: 'EDIT' WindowName: '(null)'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android