Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.DownLoader26.46965

Добавлен в вирусную базу Dr.Web: 2018-05-22

Описание добавлено:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32461' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1933' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8531' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32602' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6432' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26154' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32752' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24055' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30653' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21955' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24205' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11159' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13408' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4711' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11309' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2611' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '512' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9210' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10630' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4032' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29446' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3277' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27347' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1178' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16550' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7853' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14451' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12352' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5389' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3654' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10253' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25626' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8230' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14829' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6131' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12730' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24583' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31181' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22483' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16941' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23540' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14842' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21440' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12743' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4045' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10644' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1946' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8545' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32615' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6445' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30516' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21818' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28417' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19040' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27738' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25639' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3668' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29082' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29837' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20384' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11687' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18285' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9587' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16186' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7488' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5754' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5376' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29460' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3290' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27360' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1191' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25261' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16564' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23162' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14087' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19391' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8581' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16173' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31231' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5062' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29132' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2963' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27033' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '863' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24934' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31532' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22835' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29433' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20736' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12038' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18636' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9939' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16537' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31910' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7840' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7161' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '562' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32651' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6482' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30552' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4383' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28453' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2284' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26354' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24255' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31546' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30854' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22156' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13458' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20057' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11359' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17958' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9260' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5740' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29811' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3641' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30867' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22169' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28768' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20070' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26669' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17971' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24569' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15872' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22470' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13773' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20371' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11673' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18272' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9574' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '198' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8896' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6797' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2297' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27712' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10995' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1542' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25612' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16915' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14816' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30188' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4019' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19719' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7475' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25990' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17292' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23891' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15193' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21792' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13094' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4396' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28089' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '185' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26317' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28945' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25225' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16527' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7829' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14428' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5730' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12329' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3631' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10230' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1532' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25602' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32201' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23503' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21404' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4008' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10607' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8508' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1909' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18626' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27324' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26645' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17947' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24546' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15848' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22447' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13749' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5051' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2952' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9036' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9551' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '853' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24923' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31522' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5353' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29423' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20725' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32578' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23880' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30479' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26359' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17662' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24260' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15563' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22161' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13464' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20062' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11364' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17963' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9265' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '568' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7166' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13841' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20440' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28459' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4388' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2289' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11338' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21781' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8610' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28380' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19682' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10984' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13234' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4536' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11135' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11650' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2575' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15711' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9263' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28984' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2815' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26885' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '716' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16088' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2437' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5566' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24218' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30843' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9751' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1054' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7652' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31722' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5629' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12228' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3530' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10129' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1431' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11260' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2562' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9161' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '463' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24533' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31132' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29033' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22434' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3153' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11850' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15521' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22119' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13421' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4724' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11322' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31044' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4874' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2775' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28744' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26845' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18148' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24746' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16049' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22647' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13950' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5252' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20335' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26934' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18236' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27990' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19292' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10594' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17193' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8495' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15094' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21768' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13070' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19669' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10971' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17570' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8872' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15471' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6773' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30089' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23490' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21391' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32188' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9538' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25589' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16137' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7439' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14038' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5340' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12641' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20712' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17620' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4674' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12165' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18764' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10066' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16665' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7967' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10217' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1519' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27311' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17279' = '<Full path to file>'
Malicious functions:
To bypass firewall, removes or modifies the following registry keys:
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
Modifies file system:
Creates the following files:
  • C:\lsass.exe
  • <Full path to file>
Network activity:
Connects to:
  • '19#.#9.79.85':3128
  • '24.#.120.140':3128
  • '18#.#5.40.40':3128
  • '19#.#74.95.251':3128
  • '70.##7.109.173':3128
  • '70.##2.226.4':3128
  • '18#.#2.133.87':3128
  • '22#.#49.77.169':3128
  • '20#.#.222.212':3128
  • '89.##.63.223':3128
  • '69.##4.10.225':3128
  • '74.##1.8.168':3128
  • '80.##2.240.210':3128
  • '71.##8.88.204':3128
  • '19#.#50.79.216':3128
  • '24.##6.70.130':3128
  • '65.##.127.73':3128
  • '67.##.183.115':3128
  • '67.##.249.135':3128
  • '21#.#31.114.204':3128
  • '69.#07.0.14':3128
  • '75.##5.154.235':3128
  • '98.##4.149.92':3128
  • '82.##5.24.20':3128
  • '85.##9.84.108':3128
  • '72.##0.114.96':3128
  • '20#.#49.82.170':3128
  • '88.##6.160.30':3128
  • '20#.#.51.195':3128
  • '18#.#.50.202':3128
  • '76.##0.14.58':3128
  • '24.##6.142.175':3128
  • '76.##4.39.199':3128
  • '24.##.232.175':3128
  • '98.##9.144.177':3128
  • '68.##.116.243':3128
  • '19#.#5.38.161':3128
  • '68.##.198.131':3128
  • '68.##.236.201':3128
  • '98.##2.138.52':3128
  • '24.##.105.235':3128
  • '98.##1.105.24':3128
  • '20#.#49.92.113':3128
  • '24.##5.158.124':3128
  • '72.##9.183.24':3128
  • '84.##0.253.96':3128
  • '98.#5.78.68':3128
  • '20#.#.139.228':3128
  • '72.##7.95.146':3128
  • '14#.#08.165.167':3128
  • '76.##4.155.68':3128
  • '18#.#3.70.175':3128
  • '67.#2.3.13':3128
  • '76.##1.133.208':3128
  • '85.#5.59.77':3128
  • '79.##6.58.126':3128
  • '81.##5.59.143':3128
  • '24.##6.44.58':3128
  • '81.##6.251.158':3128
  • '24.#.12.235':3128
  • '88.##7.97.168':3128
  • '68.##4.155.132':3128
  • '88.##6.140.63':3128
  • '12#.#3.130.144':3128
  • '98.##0.218.227':3128
  • '59.##.210.230':3128
  • '18#.1.3.65':3128
  • '99.##.229.242':3128
  • '19#.#9.52.138':3128
  • '68.##0.137.202':3128
  • '69.##2.221.110':3128
  • '17#.#0.100.79':3128
  • '70.##1.253.221':3128
  • '69.##9.68.163':3128
  • '19#.#47.62.253':3128
  • '82.##.37.247':3128
  • '76.##2.118.22':3128
  • '17#.#01.154.221':3128
  • '87.##6.197.233':3128
  • '19#.#05.17.14':3128
  • '97.#2.49.58':3128
  • '12#.#36.124.56':3128
  • '98.##8.235.143':3128
  • '77.#9.88.2':3128
  • '67.##1.237.165':3128
  • '87.##6.75.219':3128
  • '24.##3.76.97':3128
  • '76.##.223.90':3128
  • '66.##.104.157':3128
  • '68.##2.35.71':3128
  • '18#.#05.144.150':3128
  • '68.##6.155.196':3128
  • '83.##0.36.147':3128
  • '89.##.98.154':3128
  • '18#.#9.145.181':3128
  • '95.##.112.250':3128
  • '24.##.122.78':3128
  • '69.##6.213.245':3128
  • '20#.#3.11.76':3128
  • '11#.#5.143.191':3128
  • '70.##7.48.38':3128
  • '21##.tpd':80
  • '19#.#60.104.194':3128
  • '19#.#45.40.206':3128
  • '76#.tpd':80
  • '21#.#31.135.235':3128
  • '88.##5.124.142':3128
  • '11#.#93.99.156':3128
  • '19#.#05.151.230':3128
  • '75.##.139.21':3128
  • '12#.#44.227.211':3128
  • '94.##6.154.173':3128
  • '20#.#98.142.133':3128
  • '12#.#37.105.17':3128
  • '64.##5.142.140':3128
  • '76.##9.59.198':3128
  • '18#.#0.120.139':3128
  • '20#.#33.61.29':3128
  • '67.##0.203.199':3128
  • '20#.#09.47.228':3128
  • '75.##.206.12':3128
  • '24.##8.8.189':3128
  • '20#.#55.158.93':3128
  • '75.##.31.100':3128
  • '70.##6.126.114':3128
  • '12#.#73.70.80':3128
  • '11#.#02.33.238':3128
  • '68.#3.42.60':3128
  • '62.##1.92.44':3128
  • '16#.#32.242.201':3128
  • '24.##5.158.82':3128
  • '89.##.27.131':3128
  • '65.##0.146.33':3128
  • '18#.#3.165.6':3128
  • '72.##8.219.233':3128
  • '68.##.42.179':3128
  • '71.##9.76.103':3128
  • '76.##.112.96':3128
  • '98.##3.163.223':3128
  • '12#.#25.98.144':3128
  • '22#.#6.16.176':3128
  • '11#.#6.90.191':3128
  • '96.##.158.65':3128
  • '98.##1.78.135':3128
  • '24.##3.45.96':3128
  • '20#.#46.213.28':3128
  • '89.##.94.130':3128
  • '21#.#27.18.198':3128
  • '72.##6.65.161':3128
  • '99.##7.130.17':3128
  • '72.##4.6.237':3128
  • '21#.#53.155.189':3128
  • '75.##9.230.124':3128
  • '68.##6.88.185':3128
  • '61.##.214.57':3128
  • '24.##6.214.145':3128
  • '24.##8.74.91':3128
  • '68.#0.45.63':3128
  • '64.##.73.136':3128
  • '18#.#1.146.222':3128
  • '12#.#9.152.99':3128
  • '20#.#.191.135':3128
  • '18#.#8.229.150':3128
  • '99.##5.68.251':3128
  • '18#.#5.146.44':3128
  • '76.##9.50.75':3128
  • '76.##1.167.44':3128
  • '68.#.163.214':3128
  • '20#.#9.209.58':3128
  • '21#.#47.65.166':3128
  • '18#.#5.181.51':3128
  • '18#.#09.32.126':3128
  • '21#.#47.92.236':3128
  • '20#.#25.109.65':3128
  • '22#.#0.46.241':3128
  • '24.##2.206.140':3128
  • '67.##4.228.190':3128
  • '20#.#38.240.62':3128
  • '76.##5.31.127':3128
  • '24.##4.60.115':3128
  • '20#.#.109.61':3128
  • '12#.#.145.188':3128
  • '72.#08.73.9':3128
  • '78.##.210.31':3128
  • '11#.#1.106.177':3128
  • '21#.#27.18.101':3128
  • '76.##.23.229':3128
  • '76.##.15.188':3128
  • '80.##6.242.104':3128
  • '12#.#41.151.14':3128
  • '24.##0.93.198':3128
  • '98.##6.195.108':3128
  • '12#.#.145.238':3128
  • '91.#8.46.66':3128
  • '67.##7.179.152':3128
  • '22#.#08.73.180':3128
  • '20#.#80.140.151':3128
  • '75.##7.108.116':3128
  • '17#.#1.85.154':3128
  • '24.##.126.237':3128
  • '12#.#44.250.77':3128
  • '99.##9.53.157':3128
  • '98.#27.77.5':3128
  • '80.##.139.153':3128
  • '98.##9.69.85':3128
  • '19#.#99.17.97':3128
  • '20#.#3.32.104':3128
  • '20#.#2.201.205':3128
  • '76.##3.82.87':3128
  • '19#.#4.225.104':3128
  • '66.##8.245.98':3128
  • '18#.#8.82.126':3128
  • '24.##9.121.0':3128
  • '96.##.227.51':3128
  • '24.##7.39.108':3128
  • '18#.#6.10.33':3128
  • '76.##5.208.51':3128
  • '76.##5.211.200':3128
  • '24.##.53.160':3128
  • '20#.#.210.202':3128
  • '92.##.226.31':3128
  • '84.##6.9.119':3128
  • '11#.#62.8.13':3128
  • '75.#0.1.65':3128
  • '67.##7.62.51':3128
  • '20#.#2.137.93':3128
  • '68.##5.30.247':3128
  • '76.##.99.173':3128
  • '20#.#44.7.234':3128
  • '79.##9.203.38':3128
  • '20#.#49.89.202':3128
  • '20#.#2.188.171':3128
  • '20#.#20.222.72':3128
  • '12#.#67.227.207':3128
  • '84.##.74.199':3128
  • '99.#1.38.34':3128
  • '67.##2.56.188':3128
  • '20#.#15.115.117':3128
  • '76.##8.29.165':3128
  • '69.##3.126.92':3128
  • '21#.#19.181.123':3128
  • '70.#61.5.54':3128
  • '68.#2.49.69':3128
  • '18#.#8.61.88':3128
  • '65.##5.145.141':3128
  • '21#.#7.128.4':3128
  • '20#.#1.95.200':3128
  • '20#.#73.147.106':3128
  • '76.##.34.161':3128
  • '69.##9.80.49':3128
  • '70.##8.186.155':3128
  • '89.##6.209.121':3128
  • '95.##4.88.118':3128
  • '67.##2.55.202':3128
  • '83.#6.92.79':3128
  • '19#.#5.28.140':3128
  • '98.##2.36.90':3128
  • '24.#.101.173':3128
  • '19#.#5.52.192':3128
  • '19#.#09.3.94':3128
  • '72.##6.217.93':3128
  • '68.##.136.70':3128
  • '11#.#62.7.98':3128
  • '76.##2.13.246':3128
  • '98.#0.65.78':3128
  • '75.##2.12.31':3128
  • '86.##6.14.42':3128
  • '76.##9.141.49':3128
  • '19#.#40.185.213':3128
  • '74.##7.192.48':3128
  • '18#.#.49.186':3128
  • '24.#.146.212':3128
  • '69.##3.197.73':3128
  • '24.#90.1.4':3128
  • '98.##3.255.13':3128
  • '20#.#8.45.56':3128
  • '21#.#48.255.97':3128
  • '69.##9.49.85':3128
  • '77.##.84.156':3128
  • '59.##.11.201':3128
  • '98.##2.15.128':3128
  • '21#.#53.159.69':3128
  • '20#.#31.255.34':3128
  • '69.##2.83.44':3128
  • '69.##6.117.205':3128
  • '18#.#20.26.162':3128
  • '76.##8.249.78':3128
  • '85.##9.253.227':3128
  • '98.##0.208.194':3128
  • '18#.#7.218.94':3128
  • '78.##.131.149':3128
  • '18#.#5.186.6':3128
  • '12#.#6.17.73':3128
  • '12#.#32.144.128':3128
  • '99.##4.8.183':3128
  • '88.##7.188.31':3128
  • '97.##.24.152':3128
  • '20#.#0.90.48':3128
  • '24.##1.155.22':3128
  • '24.#.128.210':3128
  • '98.##8.146.0':3128
  • '76.##.179.145':3128
  • '12#.#dtdtp173':0
TCP:
HTTP POST requests:
  • http://19#.#9.79.85/+13318.html
  • http://76.##2.118.22/+13318.html
  • http://75.##.206.12/+13318.html
  • http://24.##8.8.189/+13318.html
  • http://20#.#55.158.93/+13318.html
  • http://75.##.31.100/+13318.html
  • http://70.##6.126.114/+13318.html
  • http://68.#3.42.60/+13318.html
  • http://62.##1.92.44/+13318.html
  • http://16#.#32.242.201/+13318.html
  • http://18#.#9.145.181/+13318.html
  • http://12#.#73.70.80/+13318.html
  • http://89.##.27.131/+13318.html
  • http://67.##.249.135/+13318.html
  • http://69.#07.0.14/+13318.html
  • http://75.##5.154.235/+13318.html
  • http://98.##4.149.92/+13318.html
  • http://82.##5.24.20/+13318.html
  • http://65.##.127.73/+13318.html
  • http://11#.#02.33.238/+13318.html
  • http://98.##3.163.223/+13318.html
  • http://21#.#27.18.198/+13318.html
  • http://89.##.94.130/+13318.html
  • http://12#.#25.98.144/+13318.html
  • http://22#.#6.16.176/+13318.html
  • http://11#.#6.90.191/+13318.html
  • http://96.##.158.65/+13318.html
  • http://24.##3.45.96/+13318.html
  • http://98.##1.78.135/+13318.html
  • http://20#.#46.213.28/+13318.html
  • http://85.##9.84.108/+13318.html
  • http://72.##0.114.96/+13318.html
  • http://67.##0.203.199/+13318.html
  • http://18#.#3.165.6/+13318.html
  • http://19#.#47.62.253/+13318.html
  • http://64.##5.142.140/+13318.html
  • http://24.##5.158.82/+13318.html
  • http://76.##9.59.198/+13318.html
  • http://18#.#0.120.139/+13318.html
  • http://20#.#33.61.29/+13318.html
  • http://72.##6.65.161/+13318.html
  • http://20#.#09.47.228/+13318.html
  • http://20#.#49.82.170/+13318.html
  • http://88.##6.160.30/+13318.html
  • http://76.##.112.96/+13318.html
  • http://88.##7.97.168/+13318.html
  • http://19#.#50.79.216/+13318.html
  • http://24.##6.70.130/+13318.html
  • http://68.##.116.243/+13318.html
  • http://68.##.198.131/+13318.html
  • http://69.##9.68.163/+13318.html
  • http://81.##5.59.143/+13318.html
  • http://74.##1.8.168/+13318.html
  • http://81.##6.251.158/+13318.html
  • http://24.#.12.235/+13318.html
  • http://99.##.229.242/+13318.html
  • http://68.##4.155.132/+13318.html
  • http://88.##6.140.63/+13318.html
  • http://12#.#3.130.144/+13318.html
  • http://98.##0.218.227/+13318.html
  • http://59.##.210.230/+13318.html
  • http://18#.1.3.65/+13318.html
  • http://80.##2.240.210/+13318.html
  • http://68.##0.137.202/+13318.html
  • http://89.##.63.223/+13318.html
  • http://22#.#49.77.169/+13318.html
  • http://20#.#.51.195/+13318.html
  • http://69.##4.10.225/+13318.html
  • http://18#.#.50.202/+13318.html
  • http://76.##0.14.58/+13318.html
  • http://24.##6.142.175/+13318.html
  • http://76.##4.39.199/+13318.html
  • http://24.##.232.175/+13318.html
  • http://98.##9.144.177/+13318.html
  • http://20#.#.222.212/+13318.html
  • http://21#.#31.114.204/+13318.html
  • http://19#.#5.38.161/+13318.html
  • http://71.##8.88.204/+13318.html
  • http://24.#.120.140/+13318.html
  • http://18#.#5.40.40/+13318.html
  • http://19#.#74.95.251/+13318.html
  • http://70.##7.109.173/+13318.html
  • http://70.##2.226.4/+13318.html
  • http://18#.#2.133.87/+13318.html
  • http://67.##.183.115/+13318.html
  • http://19#.#9.52.138/+13318.html
  • http://71.##9.76.103/+13318.html
  • http://69.##3.126.92/+24542.html
  • http://99.##4.8.183/+24542.html
  • http://68.#0.45.63/+24542.html
  • http://20#.#49.92.113/+24542.html
  • http://68.##.198.131/+24542.html
  • http://98.##0.218.227/+24542.html
  • http://98.##3.163.223/+24542.html
  • http://19#.#5.28.140/+24542.html
  • http://98.##2.138.52/+24542.html
  • http://64.##.73.136/+24542.html
  • http://19#.#5.52.192/+24542.html
  • http://20#.#46.213.28/+24542.html
  • http://89.##6.209.121/+24542.html
  • http://88.##6.160.30/+24542.html
  • http://75.##.31.100/+24542.html
  • http://20#.#15.115.117/+24542.html
  • http://18#.#7.218.94/+24542.html
  • http://94.##6.154.173/+24542.html
  • http://98.##3.255.13/+24542.html
  • http://79.##9.203.38/+24542.html
  • http://75.##2.12.31/+24542.html
  • http://18#.#5.40.40/+24542.html
  • http://59.##.210.230/+24542.html
  • http://72.##7.95.146/+24542.html
  • http://61.##.214.57/+24542.html
  • http://67.##1.237.165/+24542.html
  • http://70.##6.126.114/+24542.html
  • http://72.##6.217.93/+24542.html
  • http://98.##1.78.135/+24542.html
  • http://18#.#9.145.181/+24542.html
  • http://20#.#2.188.171/+24542.html
  • http://67.##.183.115/+24542.html
  • http://72.##6.65.161/+24542.html
  • http://71.##8.88.204/+24542.html
  • http://19#.#4.225.104/+24542.html
  • http://12#.#36.124.56/+24542.html
  • http://74.##7.192.48/+24542.html
  • http://76.##5.208.51/+24542.html
  • http://12#.#25.98.144/+24542.html
  • http://99.#1.38.34/+24542.html
  • http://76.##.34.161/+24542.html
  • http://87.##6.75.219/+24542.html
  • http://68.##.42.179/+24542.html
  • http://69.##3.126.92/+13318.html
  • http://17#.#1.85.154/+24542.html
  • http://99.##.229.242/+24542.html
  • http://76.##8.29.165/+24542.html
  • http://12#.#41.151.14/+24542.html
  • http://68.##.136.70/+24542.html
  • http://67.##7.62.51/+24542.html
  • http://66.##.104.157/+24542.html
  • http://21#.#31.114.204/+24542.html
  • http://84.##.74.199/+24542.html
  • http://67.##2.56.188/+24542.html
  • http://68.##.42.179/+13318.html
  • http://68.##2.35.71/+13318.html
  • http://18#.#05.144.150/+13318.html
  • http://68.##6.155.196/+13318.html
  • http://94.##6.154.173/+13318.html
  • http://12#.#37.105.17/+13318.html
  • http://72.##8.219.233/+13318.html
  • http://99.##7.130.17/+13318.html
  • http://24.#.146.212/+24542.html
  • http://65.##0.146.33/+13318.html
  • http://69.##9.49.85/+24542.html
  • http://20#.#2.201.205/+24542.html
  • http://12#.#3.130.144/+24542.html
  • http://76.##9.50.75/+24542.html
  • http://99.##9.53.157/+24542.html
  • http://24.##3.45.96/+24542.html
  • http://68.##2.35.71/+24542.html
  • http://22#.#0.46.241/+24542.html
  • http://71.##9.76.103/+24542.html
  • http://19#.#50.79.216/+24542.html
  • http://68.##6.88.185/+24542.html
  • http://76.##.223.90/+24542.html
  • http://18#.#8.82.126/+24542.html
  • http://24.##.126.237/+24542.html
  • http://19#.#09.3.94/+24542.html
  • http://98.#0.65.78/+24542.html
  • http://19#.#47.62.253/+24542.html
  • http://21#.#48.255.97/+24542.html
  • http://76.##9.141.49/+24542.html
  • http://24.#.101.173/+24542.html
  • http://24.##3.76.97/+24542.html
  • http://69.##2.221.110/+13318.html
  • http://17#.#0.100.79/+13318.html
  • http://70.##1.253.221/+13318.html
  • http://11#.#1.106.177/+13318.html
  • http://21#.#27.18.101/+13318.html
  • http://76.##.23.229/+13318.html
  • http://18#.#09.32.126/+13318.html
  • http://21#.#47.65.166/+13318.html
  • http://80.##6.242.104/+13318.html
  • http://20#.#9.209.58/+13318.html
  • http://68.##6.88.185/+13318.html
  • http://24.##6.214.145/+13318.html
  • http://20#.#.109.61/+13318.html
  • http://24.##8.74.91/+13318.html
  • http://68.#0.45.63/+13318.html
  • http://64.##.73.136/+13318.html
  • http://18#.#1.146.222/+13318.html
  • http://18#.#8.229.150/+13318.html
  • http://99.##5.68.251/+13318.html
  • http://72.#08.73.9/+13318.html
  • http://61.##.214.57/+13318.html
  • http://24.#90.1.4/+13318.html
  • http://24.##4.60.115/+13318.html
  • http://20#.#8.45.56/+13318.html
  • http://21#.#48.255.97/+13318.html
  • http://77.##.84.156/+13318.html
  • http://69.##9.49.85/+13318.html
  • http://59.##.11.201/+13318.html
  • http://20#.#44.7.234/+13318.html
  • http://98.##2.15.128/+13318.html
  • http://84.##6.9.119/+13318.html
  • http://21#.#53.159.69/+13318.html
  • http://12#.#.145.188/+13318.html
  • http://18#.#5.181.51/+13318.html
  • http://21#.#47.92.236/+13318.html
  • http://20#.#25.109.65/+13318.html
  • http://22#.#0.46.241/+13318.html
  • http://67.##4.228.190/+13318.html
  • http://20#.#38.240.62/+13318.html
  • http://76.##5.31.127/+13318.html
  • http://20#.#1.95.200/+13318.html
  • http://20#.#.191.135/+13318.html
  • http://24.##2.206.140/+13318.html
  • http://76.##5.211.200/+13318.html
  • http://92.##.226.31/+13318.html
  • http://20#.#2.201.205/+13318.html
  • http://98.##3.255.13/+13318.html
  • http://20#.#3.32.104/+13318.html
  • http://91.#8.46.66/+13318.html
  • http://12#.#.145.238/+13318.html
  • http://98.##6.195.108/+13318.html
  • http://67.##7.179.152/+13318.html
  • http://22#.#08.73.180/+13318.html
  • http://19#.#4.225.104/+13318.html
  • http://67.##7.62.51/+13318.html
  • http://75.##7.108.116/+13318.html
  • http://24.##.126.237/+13318.html
  • http://98.##9.69.85/+13318.html
  • http://12#.#44.250.77/+13318.html
  • http://99.##9.53.157/+13318.html
  • http://98.#27.77.5/+13318.html
  • http://80.##.139.153/+13318.html
  • http://19#.#99.17.97/+13318.html
  • http://20#.#80.140.151/+13318.html
  • http://17#.#1.85.154/+13318.html
  • http://69.##2.83.44/+13318.html
  • http://20#.#.210.202/+13318.html
  • http://24.##7.39.108/+13318.html
  • http://68.#.163.214/+13318.html
  • http://12#.#9.152.99/+13318.html
  • http://76.##9.50.75/+13318.html
  • http://18#.#5.146.44/+13318.html
  • http://76.##1.167.44/+13318.html
  • http://12#.#41.151.14/+13318.html
  • http://76.##3.82.87/+13318.html
  • http://66.##8.245.98/+13318.html
  • http://75.#0.1.65/+13318.html
  • http://11#.#62.8.13/+13318.html
  • http://24.##0.93.198/+13318.html
  • http://76.##5.208.51/+13318.html
  • http://20#.#2.137.93/+13318.html
  • http://24.##9.121.0/+13318.html
  • http://18#.#8.82.126/+13318.html
  • http://96.##.227.51/+13318.html
  • http://18#.#6.10.33/+13318.html
  • http://24.##.53.160/+13318.html
  • http://76.##.15.188/+13318.html
  • http://78.##.210.31/+13318.html
  • http://69.##3.197.73/+13318.html
  • http://98.#0.65.78/+13318.html
  • http://19#.#5.28.140/+13318.html
  • http://76.##.99.173/+13318.html
  • http://69.##9.80.49/+13318.html
  • http://70.##8.186.155/+13318.html
  • http://89.##6.209.121/+13318.html
  • http://95.##4.88.118/+13318.html
  • http://67.##2.55.202/+13318.html
  • http://83.#6.92.79/+13318.html
  • http://24.#.146.212/+13318.html
  • http://21#.#53.155.189/+13318.html
  • http://75.##9.230.124/+13318.html
  • http://19#.#5.52.192/+13318.html
  • http://19#.#09.3.94/+13318.html
  • http://72.##6.217.93/+13318.html
  • http://68.##.136.70/+13318.html
  • http://11#.#62.7.98/+13318.html
  • http://20#.#73.147.106/+13318.html
  • http://21#.#7.128.4/+13318.html
  • http://24.#.101.173/+13318.html
  • http://98.##2.36.90/+13318.html
  • http://76.##.34.161/+13318.html
  • http://72.##9.183.24/+13318.html
  • http://24.##5.158.124/+13318.html
  • http://79.##6.58.126/+13318.html
  • http://68.##.236.201/+13318.html
  • http://85.#5.59.77/+13318.html
  • http://98.##2.138.52/+13318.html
  • http://24.##.105.235/+13318.html
  • http://98.##1.105.24/+13318.html
  • http://20#.#49.92.113/+13318.html
  • http://24.##6.44.58/+13318.html
  • http://20#.#98.142.133/+13318.html
  • http://76.##1.133.208/+13318.html
  • http://98.#5.78.68/+13318.html
  • http://20#.#.139.228/+13318.html
  • http://72.##7.95.146/+13318.html
  • http://18#.#3.70.175/+13318.html
  • http://14#.#08.165.167/+13318.html
  • http://76.##4.155.68/+13318.html
  • http://67.#2.3.13/+13318.html
  • http://84.##0.253.96/+13318.html
  • http://98.##8.235.143/+24542.html
  • http://76#.tpd./d/.184:. 00000039.+dd31http://199.24542.55770884.ttp://76t.tpd./d/.184:. 00000039.+dd31http://199.24542.55 ��|� via 76#.tpd
  • http://79.##9.203.38/+13318.html
  • http://18#.#.49.186/+13318.html
  • http://18#.#5.186.6/+13318.html
  • http://12#.#6.17.73/+13318.html
  • http://12#.#32.144.128/+13318.html
  • http://88.##7.188.31/+13318.html
  • http://97.##.24.152/+13318.html
  • http://76.##9.141.49/+13318.html
  • http://20#.#0.90.48/+13318.html
  • http://65.##5.145.141/+13318.html
  • http://78.##.131.149/+13318.html
  • http://24.#.128.210/+13318.html
  • http://98.##8.146.0/+13318.html
  • http://18#.#20.26.162/+13318.html
  • http://68.##5.30.247/+13318.html
  • http://86.##6.14.42/+13318.html
  • http://20#.#31.255.34/+13318.html
  • http://19#.#40.185.213/+13318.html
  • http://74.##7.192.48/+13318.html
  • http://24.##1.155.22/+13318.html
  • http://70.#61.5.54/+13318.html
  • http://18#.#7.218.94/+13318.html
  • http://76.##8.249.78/+13318.html
  • http://98.##0.208.194/+13318.html
  • http://20#.#49.89.202/+13318.html
  • http://20#.#2.188.171/+13318.html
  • http://20#.#20.222.72/+13318.html
  • http://12#.#67.227.207/+13318.html
  • http://20#.#15.115.117/+13318.html
  • http://84.##.74.199/+13318.html
  • http://99.#1.38.34/+13318.html
  • http://85.##9.253.227/+13318.html
  • http://67.##2.56.188/+13318.html
  • http://99.##4.8.183/+13318.html
  • http://21#.#19.181.123/+13318.html
  • http://68.#2.49.69/+13318.html
  • http://18#.#8.61.88/+13318.html
  • http://76.##2.13.246/+13318.html
  • http://75.##2.12.31/+13318.html
  • http://76.##.179.145/+13318.html
  • http://69.##6.117.205/+13318.html
  • http://76.##8.29.165/+13318.html
  • http://21##.tpd./d/.227:. 00000018.+dd31http://101.24542.15924996.:.html8211t.tpd./d/.227:. 00000018.+dd31http://101.24542.159249 ��|� via 21##.tpd
UDP:
  • DNS ASK 76#.tpd
  • DNS ASK 21##.tpd
  • DNS ASK 12#.#dtdtp173
Miscellaneous:
Creates and executes the following:
  • 'C:\lsass.exe' exe <Full path to file>
  • '<Full path to file>' force

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке