マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.DownLoader11.27313

Added to the Dr.Web virus database: 2014-08-14

Virus description added:

Technical Information

Malicious functions:
Creates and executes the following:
  • '%PROGRAM_FILES%\Java\jre6\zipper.exe' "%PROGRAM_FILES%\Java\jre6\core.zip" "%PROGRAM_FILES%\Java\jre6\" "%TEMP%\java_install.log"
  • '%TEMP%\jre-6u35-windows-i586.exe' /s /L %WINDIR%\Errors\fdsk\ftsd-java-setup.log
Executes the following:
  • '<SYSTEM32>\msiexec.exe' -Embedding 339663DC51222E8186C1DD0C49002476
  • '<SYSTEM32>\msiexec.exe' -Embedding E9F8C227CF85B2270EF4A4562AA799B2 M Global\MSI0000
  • '<SYSTEM32>\msiexec.exe' /V
  • '<SYSTEM32>\cscript.exe' "%TEMP%\Javauninstall.vbs"
  • '<SYSTEM32>\msiexec.exe' /i "%APPDATA%\Sun\Java\jre1.6.0_35\jre1.6.0_35.msi" /L %WINDIR%\Errors\fdsk\ftsd-java-setup.log /qn
Modifies file system :
Creates the following files:
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Maputo
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Maseru
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Malabo
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Lubumbashi
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Lusaka
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Mbabane
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Ndjamena
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Niamey
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Nairobi
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Mogadishu
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Monrovia
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Luanda
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Juba
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Kampala
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Johannesburg
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Gaborone
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Harare
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Khartoum
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Libreville
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Lome
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Lagos
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Kigali
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Kinshasa
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Nouakchott
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\La_Rioja
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Mendoza
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Jujuy
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Catamarca
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Cordoba
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Rio_Gallegos
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Tucuman
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Ushuaia
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\San_Luis
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Salta
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\San_Juan
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Argentina\Buenos_Aires
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Tripoli
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Tunis
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Sao_Tome
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Ouagadougou
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Porto-Novo
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Windhoek
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Antigua
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Araguaina
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Anguilla
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Adak
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Anchorage
  • %PROGRAM_FILES%\Java\jre6\lib\security\blacklist
  • %PROGRAM_FILES%\Java\jre6\lib\security\cacerts
  • %PROGRAM_FILES%\Java\jre6\lib\rt.pack
  • %PROGRAM_FILES%\Java\jre6\lib\psfontj2d.properties
  • %PROGRAM_FILES%\Java\jre6\lib\resources.jar
  • %PROGRAM_FILES%\Java\jre6\lib\security\java.policy
  • %PROGRAM_FILES%\Java\jre6\lib\security\US_export_policy.jar
  • %PROGRAM_FILES%\Java\jre6\lib\servicetag\jdk_header.png
  • %PROGRAM_FILES%\Java\jre6\lib\security\local_policy.jar
  • %PROGRAM_FILES%\Java\jre6\lib\security\java.security
  • %PROGRAM_FILES%\Java\jre6\lib\security\javaws.policy
  • %PROGRAM_FILES%\Java\jre6\lib\psfont.properties.ja
  • %PROGRAM_FILES%\Java\jre6\lib\management\jmxremote.access
  • %PROGRAM_FILES%\Java\jre6\lib\management\jmxremote.password.template
  • %PROGRAM_FILES%\Java\jre6\lib\logging.properties
  • %PROGRAM_FILES%\Java\jre6\lib\jsse.pack
  • %PROGRAM_FILES%\Java\jre6\lib\jvm.hprof.txt
  • %PROGRAM_FILES%\Java\jre6\lib\management\management.properties
  • %PROGRAM_FILES%\Java\jre6\lib\net.properties
  • %PROGRAM_FILES%\Java\jre6\lib\plugin.pack
  • %PROGRAM_FILES%\Java\jre6\lib\meta-index
  • %PROGRAM_FILES%\Java\jre6\lib\management\snmp.acl.template
  • %PROGRAM_FILES%\Java\jre6\lib\management-agent.jar
  • %PROGRAM_FILES%\Java\jre6\lib\sound.properties
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Ceuta
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Conakry
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Casablanca
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Bujumbura
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Cairo
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Dakar
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\El_Aaiun
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Freetown
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Douala
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Dar_es_Salaam
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Djibouti
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Brazzaville
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Addis_Ababa
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Algiers
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Accra
  • %PROGRAM_FILES%\Java\jre6\lib\tzmappings
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Abidjan
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Asmara
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Bissau
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Blantyre
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Banjul
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Bamako
  • %PROGRAM_FILES%\Java\jre6\lib\zi\Africa\Bangui
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Aruba
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Maceio
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Managua
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Los_Angeles
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\La_Paz
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Lima
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Manaus
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Menominee
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Merida
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Mazatlan
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Martinique
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Matamoros
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Kentucky\Monticello
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Indiana\Vevay
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Indiana\Vincennes
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Indiana\Tell_City
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Indiana\Marengo
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Indiana\Petersburg
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Indiana\Winamac
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Juneau
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Kentucky\Louisville
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Jamaica
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Inuvik
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Iqaluit
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Metlakatla
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Ojinaga
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Panama
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\North_Dakota\New_Salem
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\North_Dakota\Beulah
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\North_Dakota\Center
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Pangnirtung
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Porto_Velho
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Port_of_Spain
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Port-au-Prince
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Paramaribo
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Phoenix
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Noronha
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Monterrey
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Montevideo
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Moncton
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Mexico_City
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Miquelon
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Montreal
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Nipigon
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Nome
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\New_York
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Montserrat
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Nassau
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Cayenne
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Cayman
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Caracas
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Campo_Grande
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Cancun
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Chicago
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Cuiaba
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Curacao
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Creston
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Chihuahua
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Costa_Rica
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Cambridge_Bay
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Bahia_Banderas
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Barbados
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Bahia
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Asuncion
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Atikokan
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Belem
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Bogota
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Boise
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Boa_Vista
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Belize
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Blanc-Sablon
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Danmarkshavn
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Guatemala
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Guayaquil
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Guadeloupe
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Grand_Turk
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Grenada
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Guyana
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Indiana\Indianapolis
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Indiana\Knox
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Hermosillo
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Halifax
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Havana
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Goose_Bay
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Detroit
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Dominica
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Denver
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Dawson
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Dawson_Creek
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Edmonton
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Glace_Bay
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Godthab
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Fortaleza
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\Eirunepe
  • %PROGRAM_FILES%\Java\jre6\lib\zi\America\El_Salvador
  • %PROGRAM_FILES%\Java\jre6\bin\java-rmi.exe
  • %PROGRAM_FILES%\Java\jre6\bin\java.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jaas_nt.dll
  • %PROGRAM_FILES%\Java\jre6\bin\j2pcsc.dll
  • %PROGRAM_FILES%\Java\jre6\bin\j2pkcs11.dll
  • %PROGRAM_FILES%\Java\jre6\bin\java.exe
  • %PROGRAM_FILES%\Java\jre6\bin\javaws.exe
  • %PROGRAM_FILES%\Java\jre6\bin\java_crw_demo.dll
  • %PROGRAM_FILES%\Java\jre6\bin\javaw.exe
  • %PROGRAM_FILES%\Java\jre6\bin\javacpl.cpl
  • %PROGRAM_FILES%\Java\jre6\bin\javacpl.exe
  • %PROGRAM_FILES%\Java\jre6\bin\ioser12.dll
  • %PROGRAM_FILES%\Java\jre6\bin\dtplugin\npdeployJava1.dll
  • %PROGRAM_FILES%\Java\jre6\bin\dt_shmem.dll
  • %PROGRAM_FILES%\Java\jre6\bin\dtplugin\deployJava1.dll
  • %PROGRAM_FILES%\Java\jre6\bin\dcpr.dll
  • %PROGRAM_FILES%\Java\jre6\bin\deploy.dll
  • %PROGRAM_FILES%\Java\jre6\bin\dt_socket.dll
  • %PROGRAM_FILES%\Java\jre6\bin\hprof.dll
  • %PROGRAM_FILES%\Java\jre6\bin\instrument.dll
  • %PROGRAM_FILES%\Java\jre6\bin\hpi.dll
  • %PROGRAM_FILES%\Java\jre6\bin\eula.dll
  • %PROGRAM_FILES%\Java\jre6\bin\fontmanager.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jawt.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jqs.exe
  • %PROGRAM_FILES%\Java\jre6\bin\jqsnotify.exe
  • %PROGRAM_FILES%\Java\jre6\bin\jpishare.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jpinscp.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jpioji.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jsound.dll
  • %PROGRAM_FILES%\Java\jre6\bin\klist.exe
  • %PROGRAM_FILES%\Java\jre6\bin\ktab.exe
  • %PROGRAM_FILES%\Java\jre6\bin\kinit.exe
  • %PROGRAM_FILES%\Java\jre6\bin\jsoundds.dll
  • %PROGRAM_FILES%\Java\jre6\bin\keytool.exe
  • %PROGRAM_FILES%\Java\jre6\bin\jpiexp.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jkernel.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jli.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jdwp.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jbroker.exe
  • %PROGRAM_FILES%\Java\jre6\bin\JdbcOdbc.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jp2iexp.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jpeg.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jpicom.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jp2ssv.dll
  • %PROGRAM_FILES%\Java\jre6\bin\jp2launcher.exe
  • %PROGRAM_FILES%\Java\jre6\bin\jp2native.dll
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
  • %WINDIR%\Errors\fdsk\ftsd-java-setup.log
  • %WINDIR%\Installer\3784e.msi
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
  • %WINDIR%\Installer\MSIB.tmp
  • %WINDIR%\Installer\MSIC.tmp
  • %TEMP%\Cab9.tmp
  • %TEMP%\Cab5.tmp
  • %TEMP%\Cab7.tmp
  • %APPDATA%\Sun\Java\jre1.6.0_35\jre1.6.0_35.msi
  • %TEMP%\aut2.tmp
  • %TEMP%\Javauninstall.vbs
  • %TEMP%\6u35install.bat
  • %WINDIR%\Errors\fdsk\Java6u35Full_X86.log
  • %TEMP%\aut1.tmp
  • %TEMP%\aut3.tmp
  • %TEMP%\jusched.log
  • %APPDATA%\Sun\Java\jre1.6.0_35\Data1.cab
  • %TEMP%\JavaUpdateBlocker.exe
  • %TEMP%\jre-6u35-windows-i586.exe
  • %TEMP%\aut4.tmp
  • %WINDIR%\Installer\MSID.tmp
  • %PROGRAM_FILES%\Java\jre6\README.txt
  • %PROGRAM_FILES%\Java\jre6\THIRDPARTYLICENSEREADME.txt
  • %PROGRAM_FILES%\Java\jre6\LICENSE
  • %TEMP%\java_install.log
  • %PROGRAM_FILES%\Java\jre6\COPYRIGHT
  • %PROGRAM_FILES%\Java\jre6\Welcome.html
  • %PROGRAM_FILES%\Java\jre6\bin\client\Xusage.txt
  • %PROGRAM_FILES%\Java\jre6\bin\cmm.dll
  • %PROGRAM_FILES%\Java\jre6\bin\client\jvm.dll
  • %PROGRAM_FILES%\Java\jre6\bin\awt.dll
  • %PROGRAM_FILES%\Java\jre6\bin\axbridge.dll
  • %TEMP%\java_install_reg.log
  • %WINDIR%\Installer\MSI11.tmp
  • %WINDIR%\Installer\MSI12.tmp
  • %WINDIR%\Installer\MSI10.tmp
  • %WINDIR%\Installer\MSIE.tmp
  • %WINDIR%\Installer\MSIF.tmp
  • %WINDIR%\Installer\MSI13.tmp
  • %PROGRAM_FILES%\Java\jre6\core.zip
  • %PROGRAM_FILES%\Java\jre6\bin\regutils.dll
  • %PROGRAM_FILES%\Java\jre6\zipper.exe
  • %WINDIR%\Installer\MSI14.tmp
  • C:\Config.Msi\37851.rbs
  • %PROGRAM_FILES%\Java\jre6\bin\management.dll
  • %PROGRAM_FILES%\Java\jre6\lib\ext\dnsns.jar
  • %PROGRAM_FILES%\Java\jre6\lib\ext\localedata.pack
  • %PROGRAM_FILES%\Java\jre6\lib\deploy.pack
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_zh_TW.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\splash.gif
  • %PROGRAM_FILES%\Java\jre6\lib\ext\meta-index
  • %PROGRAM_FILES%\Java\jre6\lib\flavormap.properties
  • %PROGRAM_FILES%\Java\jre6\lib\fontconfig.98.bfc
  • %PROGRAM_FILES%\Java\jre6\lib\ext\sunpkcs11.jar
  • %PROGRAM_FILES%\Java\jre6\lib\ext\sunjce_provider.jar
  • %PROGRAM_FILES%\Java\jre6\lib\ext\sunmscapi.jar
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_zh_HK.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_es.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_fr.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_de.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\lzma.dll
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_it.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_sv.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_zh_CN.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_pt_BR.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_ja.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\messages_ko.properties
  • %PROGRAM_FILES%\Java\jre6\lib\fontconfig.98.properties.src
  • %PROGRAM_FILES%\Java\jre6\lib\images\cursors\win32_CopyDrop32x32.gif
  • %PROGRAM_FILES%\Java\jre6\lib\images\cursors\win32_CopyNoDrop32x32.gif
  • %PROGRAM_FILES%\Java\jre6\lib\images\cursors\invalid32x32.gif
  • %PROGRAM_FILES%\Java\jre6\lib\im\thaiim.jar
  • %PROGRAM_FILES%\Java\jre6\lib\images\cursors\cursors.properties
  • %PROGRAM_FILES%\Java\jre6\lib\images\cursors\win32_LinkDrop32x32.gif
  • %PROGRAM_FILES%\Java\jre6\lib\javaws.pack
  • %PROGRAM_FILES%\Java\jre6\lib\jce.jar
  • %PROGRAM_FILES%\Java\jre6\lib\images\cursors\win32_MoveNoDrop32x32.gif
  • %PROGRAM_FILES%\Java\jre6\lib\images\cursors\win32_LinkNoDrop32x32.gif
  • %PROGRAM_FILES%\Java\jre6\lib\images\cursors\win32_MoveDrop32x32.gif
  • %PROGRAM_FILES%\Java\jre6\lib\im\indicim.jar
  • %PROGRAM_FILES%\Java\jre6\lib\fonts\LucidaBrightDemiItalic.ttf
  • %PROGRAM_FILES%\Java\jre6\lib\fonts\LucidaBrightItalic.ttf
  • %PROGRAM_FILES%\Java\jre6\lib\fonts\LucidaBrightDemiBold.ttf
  • %PROGRAM_FILES%\Java\jre6\lib\fontconfig.bfc
  • %PROGRAM_FILES%\Java\jre6\lib\fontconfig.properties.src
  • %PROGRAM_FILES%\Java\jre6\lib\fonts\LucidaBrightRegular.ttf
  • %PROGRAM_FILES%\Java\jre6\lib\fonts\LucidaTypewriterRegular.ttf
  • %PROGRAM_FILES%\Java\jre6\lib\i386\jvm.cfg
  • %PROGRAM_FILES%\Java\jre6\lib\fonts\LucidaTypewriterBold.ttf
  • %PROGRAM_FILES%\Java\jre6\lib\fonts\LucidaSansDemiBold.ttf
  • %PROGRAM_FILES%\Java\jre6\lib\fonts\LucidaSansRegular.ttf
  • %PROGRAM_FILES%\Java\jre6\bin\rmiregistry.exe
  • %PROGRAM_FILES%\Java\jre6\bin\servertool.exe
  • %PROGRAM_FILES%\Java\jre6\bin\rmid.exe
  • %PROGRAM_FILES%\Java\jre6\bin\policytool.exe
  • %PROGRAM_FILES%\Java\jre6\bin\rmi.dll
  • %PROGRAM_FILES%\Java\jre6\bin\splashscreen.dll
  • %PROGRAM_FILES%\Java\jre6\bin\tnameserv.exe
  • %PROGRAM_FILES%\Java\jre6\bin\unicows.dll
  • %PROGRAM_FILES%\Java\jre6\bin\sunmscapi.dll
  • %PROGRAM_FILES%\Java\jre6\bin\ssv.dll
  • %PROGRAM_FILES%\Java\jre6\bin\ssvagent.exe
  • %PROGRAM_FILES%\Java\jre6\bin\plugin2\npjp2.dll
  • %PROGRAM_FILES%\Java\jre6\bin\net.dll
  • %PROGRAM_FILES%\Java\jre6\bin\nio.dll
  • %PROGRAM_FILES%\Java\jre6\bin\msvcrt.dll
  • %PROGRAM_FILES%\Java\jre6\bin\mlib_image.dll
  • %PROGRAM_FILES%\Java\jre6\bin\msvcr71.dll
  • %PROGRAM_FILES%\Java\jre6\bin\npjpi160_35.dll
  • %PROGRAM_FILES%\Java\jre6\bin\pack200.exe
  • %PROGRAM_FILES%\Java\jre6\bin\plugin2\msvcr71.dll
  • %PROGRAM_FILES%\Java\jre6\bin\orbd.exe
  • %PROGRAM_FILES%\Java\jre6\bin\npoji610.dll
  • %PROGRAM_FILES%\Java\jre6\bin\npt.dll
  • %PROGRAM_FILES%\Java\jre6\bin\unpack.dll
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\ffjcext.zip
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\jqs\ff\chrome\content\overlay.js
  • %PROGRAM_FILES%\Java\jre6\lib\content-types.properties
  • %PROGRAM_FILES%\Java\jre6\lib\cmm\PYCC.pf
  • %PROGRAM_FILES%\Java\jre6\lib\cmm\sRGB.pf
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\jqs\ff\chrome\content\overlay.xul
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\jqs\jqs.conf
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\jqs\jqsmessages.properties
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\jqs\ff\chrome.manifest
  • %PROGRAM_FILES%\Java\jre6\lib\deploy\jqs\ff\install.rdf
  • %PROGRAM_FILES%\Java\jre6\lib\cmm\LINEAR_RGB.pf
  • %PROGRAM_FILES%\Java\jre6\bin\wsdetect.dll
  • %PROGRAM_FILES%\Java\jre6\bin\zip.dll
  • %PROGRAM_FILES%\Java\jre6\bin\w2k_lsa_auth.dll
  • %PROGRAM_FILES%\Java\jre6\bin\unpack200.exe
  • %PROGRAM_FILES%\Java\jre6\bin\verify.dll
  • %PROGRAM_FILES%\Java\jre6\lib\audio\soundbank.gm
  • %PROGRAM_FILES%\Java\jre6\lib\cmm\CIEXYZ.pf
  • %PROGRAM_FILES%\Java\jre6\lib\cmm\GRAY.pf
  • %PROGRAM_FILES%\Java\jre6\lib\classlist
  • %PROGRAM_FILES%\Java\jre6\lib\calendars.properties
  • %PROGRAM_FILES%\Java\jre6\lib\charsets.pack
Deletes the following files:
  • %WINDIR%\Installer\MSIF.tmp
  • %WINDIR%\Installer\MSI10.tmp
  • %WINDIR%\Installer\MSID.tmp
  • %WINDIR%\Installer\MSIE.tmp
  • %WINDIR%\Installer\MSI13.tmp
  • %WINDIR%\Installer\MSI14.tmp
  • %WINDIR%\Installer\MSI11.tmp
  • %WINDIR%\Installer\MSI12.tmp
  • %TEMP%\aut3.tmp
  • %TEMP%\aut4.tmp
  • %TEMP%\aut1.tmp
  • %TEMP%\aut2.tmp
  • %TEMP%\Cab9.tmp
  • %WINDIR%\Installer\MSIB.tmp
  • %TEMP%\Cab5.tmp
  • %TEMP%\Cab7.tmp
Network activity:
Connects to:
  • 'www.download.windowsupdate.com':80
  • 'wp#d':80
  • 'ja####-esd.sun.com':80
TCP:
HTTP GET requests:
  • www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
  • www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • ja####-esd.sun.com/update/1.6.0/1.6.0_35-b10.xml
  • wp#d/wpad.dat
UDP:
  • DNS ASK www.download.windowsupdate.com
  • DNS ASK wp#d
  • DNS ASK ja####-esd.sun.com
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: '(null)'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android