マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.DownLoader11.17381

Added to the Dr.Web virus database: 2014-06-17

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'd764ac0c30c9530b6f2941d5590f880a' = '"%TEMP%\service.exe" ..'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'd764ac0c30c9530b6f2941d5590f880a' = '"%TEMP%\service.exe" ..'
Creates or modifies the following files:
  • %HOMEPATH%\Start Menu\Programs\Startup\d764ac0c30c9530b6f2941d5590f880a.exe
Malicious functions:
To bypass firewall, removes or modifies the following registry keys:
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\service.exe' = '%TEMP%\service.exe:*:Enabled:service.exe'
Creates and executes the following:
  • '%TEMP%\service.exe'
  • '%TEMP%\ir_ext_temp_0\autorun.exe' "SFXSOURCE:%TEMP%\bein.exe"
  • '%TEMP%\bein.exe'
  • '%TEMP%\vlc1.exe'
Executes the following:
  • '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\service.exe" "service.exe" ENABLE
Modifies file system :
Creates the following files:
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\jpcntx.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\jisfreq.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\hebrewprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\langbulgarianmodel.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\langhebrewmodel.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\langgreekmodel.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\langcyrillicmodel.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\gb2312prober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\euckrfreq.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\eucjpprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\escsm.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\euckrprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\gb2312freq.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\euctwprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\euctwfreq.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\langhungarianmodel.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\utf8prober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\universaldetector.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\_collections.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\contrib\ntlmpool.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\contrib\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\connectionpool.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\sjisprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\mbcharsetprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\latin1prober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\langthaimodel.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\mbcsgroupprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\sbcsgroupprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\sbcharsetprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\mbcssm.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\escprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\adapters.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\EGG-INFO\top_level.txt
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\api.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\certs.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\cacert.pem
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\auth.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\EGG-INFO\SOURCES.txt
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\python27.dll
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\pyexpat.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\paste.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\regex2.dll
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\EGG-INFO\PKG-INFO
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\EGG-INFO\not-zip-safe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\EGG-INFO\dependency_links.txt
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\compat.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\charsetprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\charsetgroupprober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\chardistribution.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\codingstatemachine.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\cp949prober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\constants.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\compat.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\big5prober.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\hooks.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\exceptions.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\cookies.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\models.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\big5freq.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\charade\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd13.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd12.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd11.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd14.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\Panel-025.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\Panel-005.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd15.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd10.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd05.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd04.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd03.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd06.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd09.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd08.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd07.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\sky_sport4.png
  • %TEMP%\ir_ext_temp_0\autorun.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\Untitled-2_1.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\Untitled-2.png
  • %TEMP%\ir_ext_temp_0\beIN_Sport_logo.ico
  • %TEMP%\_ir_tmpfnt_1\Segoe UI.TFT
  • %TEMP%\ir_ext_temp_0\lua51.dll
  • %TEMP%\ir_ext_temp_0\lua5.1.dll
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\Untitled-1.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\sky_sports1.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\sky_sports_news.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\sky_sports_news.jpg
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\sky_sports2.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\unnamed.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\sky_uk_sports_f1.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\sky_sports3.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd02.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\util.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\response.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\request.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\sessions.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\utils.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\structures.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\status_codes.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\poolmanager.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\filepost.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\exceptions.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\contrib\pyopenssl.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\packages\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\packages\ssl_match_hostname\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\packages\six.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\requests-1.2.3-py2.7.egg\requests\packages\urllib3\packages\ordered_dict.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\rtmpdump.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\bt_sport_1.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\bein_play_color_overwhite11.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\Bar-Vertical-016.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\bt_sport_2.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\hd01.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\EGC7zWB.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Images\eaH7MZT.png
  • %TEMP%\ir_ext_temp_0\AutoPlay\Icons\beIN_Sport_logo.ico
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\setuptools-0.6c11-py2.7.egg
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\select.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\sed.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\SKYLIST.ini
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\wget.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\unicodedata.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\tid.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\cut.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\curl.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\bz2.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\grep.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\libintl3.dll
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\libiconv2.dll
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\jsclist.ini
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\beinlist.ini
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\_ctypes.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\9_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\9.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\_elementtree.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\_ssl.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\_socket.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\_hashlib.pyd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\library.zip
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\buffers.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\EGG-INFO\top_level.txt
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\cache.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\logger.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\exceptions.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\compat.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\EGG-INFO\SOURCES.txt
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\EGG-INFO\dependency_links.txt
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\list.inf
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\EGG-INFO\entry_points.txt
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\EGG-INFO\requires.txt
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\EGG-INFO\PKG-INFO
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\EGG-INFO\not-zip-safe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\8_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\10.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\1_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\10_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\13.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\12.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\11.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Buttons\1040_0001.btn
  • %TEMP%\aut2.tmp
  • %TEMP%\bein.exe
  • %TEMP%\aut1.tmp
  • %TEMP%\vlc1.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\autorun.cdd
  • %TEMP%\ir_ext_temp_0\AutoPlay\Audio\High1.ogg
  • %TEMP%\ir_ext_temp_0\AutoPlay\Audio\Click1.ogg
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\14.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\6_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\6.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\5_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\7.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\8.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\7_2.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\7_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\5.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\2_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\2.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\15.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\3.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\4_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\4.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\3_1.bat
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\session.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\yycast.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\youtube.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\hls.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\hds.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\akamaihd.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\weeb.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\stream.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\owncast.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\ongamenet.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\streamingvideoprovider.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\veetle.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\ustreamtv.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\svtplay.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\http.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer_cli\console.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer_cli\compat.pyc
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer_cli\constants.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer_cli\utils.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer_cli\output.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer_cli\main.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer_cli\argparser.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\streamprocess.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\stream.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\rtmpdump.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\stream\wrappers.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer_cli\__init__.pyc
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\utils.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\oldlivestream.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\packet.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\ordereddict.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\flv.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\tag.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\pbs.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\util.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\types.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\f4v.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\__init__.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\options.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\amf.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\error.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\compat.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\packages\flashmedia\box.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugin.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\ilive.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\gomtv.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\freedocast.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\justintv.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\mips.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\livestream.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\livestation.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\filmon.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\azubutv.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\alieztv.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\__init__.pyc
  • %TEMP%\service.exe
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\euronews.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\dailymotion.pyc
  • %TEMP%\ir_ext_temp_0\AutoPlay\Docs\data\livestreamer-1.5.2-py2.7.egg\livestreamer\plugins\cast3d.pyc
Deletes the following files:
  • %TEMP%\aut2.tmp
  • %TEMP%\aut1.tmp
Moves the following files:
  • from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
  • from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
Network activity:
Connects to:
  • 'el######ouakaz23.no-ip.biz':2300
UDP:
  • DNS ASK el######ouakaz23.no-ip.biz
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: '(null)'
  • ClassName: 'Indicator' WindowName: '(null)'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android