マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話

03-6550-8770

Profile

Trojan.DownLoader49.37860

Added to the Dr.Web virus database: 2026-04-05

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'by.edn.cloud-sign.agent' = '"%APPDATA%\cloud-sign-agent\agent.exe" '
Modifies file system
Creates the following files
  • %APPDATA%\cloud-sign-agent\agent.exe
  • nul
  • %APPDATA%\cloud-sign-agent\agent.new
  • %APPDATA%\cloud-sign-agent\agent.exe.old
  • %APPDATA%\cloud-sign-agent\avjceprov\avjavaseckit.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avjutils.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avldapcertstore.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avlog.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avoids.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avscimport.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avtsc.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avwss4j.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avxmlsecurity.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avpass.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avtkncsp.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avtkncspwrapper.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avtoken.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avuniversaljni.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.10
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.10.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.10.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.3
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.3.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.6
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.6.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.1176.2.3.6.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.0.34.101.45.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.0.2.1.28147.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.1.3.1.1.1.3
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.1.3.1.1.2.3
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.2.112.1.3.1.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.105.10
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.105.10.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.105.10.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.4.30
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.4.30.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.4.30.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.7.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.7.2.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.7.2.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.7.3
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.7.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.7.5.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\params\1.3.6.1.4.1.12656.7.5.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\pkcs11wrapper.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avc.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avcext.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avcryptokibign.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win32\avcryptokibignmt.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avpass.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avtkncsp.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avtkncspwrapper.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avtoken.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avuniversaljni.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.10
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.10.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.10.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.3
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.3.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.6
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.6.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.1176.2.3.6.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.0.34.101.45.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.0.2.1.28147.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.1.3.1.1.1.3
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.1.3.1.1.2.3
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.2.112.1.3.1.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.105.10
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.105.10.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.105.10.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.4.30
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.4.30.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.4.30.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.7.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.7.2.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.7.2.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.7.3
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.7.3.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.7.5.1
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\params\1.3.6.1.4.1.12656.7.5.2
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\pkcs11wrapper.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avc.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avcext.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avcryptokibign.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\win64\avcryptokibignmt.dll
  • %APPDATA%\cloud-sign-agent\avjceprov\avjavasecprov-shared.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avjavasecprovintf.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avjceprovlib-avbign-shared.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avjceprovlib-avtoken-shared.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avkeytool.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avocspclient.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avpkitools.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avstores.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\avtlsjava-bign.jar
  • %APPDATA%\cloud-sign-agent\avjceprov\version.properties
  • %APPDATA%\cloud-sign-agent\avjceprov\sha1
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\java.exe
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\javaw.exe
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\keytool.exe
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\java.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\jimage.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\jli.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\msvcp120.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\msvcr120.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\net.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\nio.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\verify.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\zip.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\client\jvm.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\bin\server\jvm.dll
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\release
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\client\xusage.txt
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\security\blacklisted.certs
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\security\cacerts
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\security\default.policy
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\security\public_suffix_list.dat
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\modules
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\classlist
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\jrt-fs.jar
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\jvm.cfg
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\jvm.lib
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\server\xusage.txt
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\tzdb.dat
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\tzmappings
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\lib\main.jar
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\logging.properties
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\net.properties
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\security\java.policy
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\security\java.security
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\security\policy\limited\default_local.policy
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\security\policy\limited\default_us_export.policy
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\security\policy\limited\exempt_local.policy
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\security\policy\unlimited\default_local.policy
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\security\policy\unlimited\default_us_export.policy
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\conf\security\policy\readme.txt
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.security.sasl\assembly_exception
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.security.sasl\license
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.security.sasl\additional_license_info
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.naming\assembly_exception
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.naming\license
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.naming\additional_license_info
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\public_suffix.md
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\c-libutl.md
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\zlib.md
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\cldr.md
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\asm.md
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\assembly_exception
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\aes.md
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\license
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\unicode.md
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\icu.md
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.base\additional_license_info
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.logging\assembly_exception
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.logging\license
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\legal\java.logging\additional_license_info
  • %APPDATA%\cloud-sign-agent\cryptoj-agent\version.txt
  • %TEMP%\hsperfdata_user\2964
  • %APPDATA%\cloud-sign-agent\agent-ui\license.electron.txt
  • %APPDATA%\cloud-sign-agent\agent-ui\licenses.chromium.html
  • %APPDATA%\cloud-sign-agent\agent-ui\agent-ui.exe
  • %APPDATA%\cloud-sign-agent\agent-ui\chrome_100_percent.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\chrome_200_percent.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\d3dcompiler_47.dll
  • %APPDATA%\cloud-sign-agent\agent-ui\ffmpeg.dll
  • %APPDATA%\cloud-sign-agent\agent-ui\icudtl.dat
  • %APPDATA%\cloud-sign-agent\agent-ui\libegl.dll
  • %APPDATA%\cloud-sign-agent\agent-ui\libglesv2.dll
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\am.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ar.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\bg.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\bn.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ca.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\cs.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\da.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\de.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\el.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\en-gb.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\en-us.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\es-419.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\es.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\et.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\fa.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\fi.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\fil.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\fr.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\gu.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\he.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\hi.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\hr.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\hu.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\id.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\it.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ja.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\kn.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ko.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\lt.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\lv.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ml.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\mr.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ms.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\nb.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\nl.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\pl.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\pt-br.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\pt-pt.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ro.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ru.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\sk.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\sl.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\sr.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\sv.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\sw.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\ta.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\te.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\th.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\tr.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\uk.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\vi.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\zh-cn.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\locales\zh-tw.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\resources.pak
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\.prettierrc
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\license
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\index.js
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\lib\checkgrowl.js
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\lib\utils.js
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\notifiers\balloon.js
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\notifiers\growl.js
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\notifiers\notificationcenter.js
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\notifiers\notifysend.js
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\notifiers\toaster.js
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\package.json
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\mac.noindex\terminal-notifier.app\contents\info.plist
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\mac.noindex\terminal-notifier.app\contents\macos\terminal-notifier
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\mac.noindex\terminal-notifier.app\contents\pkginfo
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\mac.noindex\terminal-notifier.app\contents\resources\terminal.icns
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\mac.noindex\terminal-notifier.app\contents\resources\en.lproj\credits.rtf
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\mac.noindex\terminal-notifier.app\contents\resources\en.lproj\infoplist.strings
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\mac.noindex\terminal-notifier.app\contents\resources\en.lproj\mainmenu.nib
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\notifu\license
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\notifu\notifu.exe
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\notifu\notifu64.exe
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\snoretoast\license
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\snoretoast\snoretoast-x64.exe
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\snoretoast\snoretoast-x86.exe
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\app.asar.unpacked\node_modules\node-notifier\vendor\terminal-notifier-license
  • %APPDATA%\cloud-sign-agent\agent-ui\resources\img\tray.ico
  • %APPDATA%\cloud-sign-agent\agent-ui\snapshot_blob.bin
  • %APPDATA%\cloud-sign-agent\agent-ui\swiftshader\libegl.dll
  • %APPDATA%\cloud-sign-agent\agent-ui\swiftshader\libglesv2.dll
  • %APPDATA%\cloud-sign-agent\agent-ui\v8_context_snapshot.bin
  • %APPDATA%\cloud-sign-agent\agent-ui\vk_swiftshader.dll
  • %APPDATA%\cloud-sign-agent\agent-ui\vk_swiftshader_icd.json
  • %APPDATA%\cloud-sign-agent\agent-ui\vulkan-1.dll
  • %APPDATA%\cloud-sign-agent\agent-ui\version.txt
  • %APPDATA%\cloud-sign-agent\agent-ui\dictionaries\en-us-9-0.bdic
Deletes following files that it created itself
  • %APPDATA%\cloud-sign-agent\agent.new
Network activity
Connects to
  • 'st###.edn.by':443
  • 'localhost':49708
  • 're####ctor.gvt1.com':443
  • 'r6########5onuxaxjvh-n8vs.gvt1.com':443
  • 'localhost':49704
TCP
HTTP GET requests
  • http://12#.#.0.1:49704/
Other
  • 'st###.edn.by':443
  • 'localhost':49708
  • 'localhost':49709
  • 're####ctor.gvt1.com':443
  • 'r6########5onuxaxjvh-n8vs.gvt1.com':443
  • 'localhost':49713
UDP
  • DNS ASK st###.edn.by
  • DNS ASK re####ctor.gvt1.com
  • DNS ASK r6########5onuxaxjvh-n8vs.gvt1.com
Miscellaneous
Creates and executes the following
  • '%APPDATA%\cloud-sign-agent\agent.exe'
  • '%APPDATA%\cloud-sign-agent\agent.new'
  • '%APPDATA%\cloud-sign-agent\cryptoj-agent\bin\java.exe' -Xms64m -Xmx512m -Dfile.encoding=utf-8 -cp lib\main.jar;%APPDATA%\cloud-sign-agent\avjceprov\* by.edn.cryptoj.agent.Main
  • '%APPDATA%\cloud-sign-agent\agent-ui\agent-ui.exe' --port=49704 --no-sandbox
  • '%APPDATA%\cloud-sign-agent\agent-ui\agent-ui.exe' --type=gpu-process --field-trial-handle=1728,11877455588246692934,14039688590555438027,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --no-san...
  • '%APPDATA%\cloud-sign-agent\agent-ui\agent-ui.exe' --type=utility --field-trial-handle=1728,11877455588246692934,14039688590555438027,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=en-US...
  • '%APPDATA%\cloud-sign-agent\agent-ui\agent-ui.exe' --type=renderer --no-sandbox --field-trial-handle=1728,11877455588246692934,14039688590555438027,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProces...
Executes the following
  • '%APPDATA%\cloud-sign-agent\cryptoj-agent\bin\java.exe' -Xms64m -Xmx512m -Dfile.encoding=utf-8 -cp lib\main.jar;%APPDATA%\cloud-sign-agent\avjceprov\* by.edn.cryptoj.agent.Main' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android