Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.DownLoader26.47425

Добавлен в вирусную базу Dr.Web: 2018-05-25

Описание добавлено:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '817' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7541' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29140' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30858' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22133' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14810' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31027' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27255' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18027' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24980' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7763' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25885' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '89' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18211' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1735' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19857' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27403' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5211' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21503' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5281' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16694' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28678' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17898' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6377' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18064' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28494' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10390' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23331' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5005' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20021' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3692' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18338' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13456' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17914' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9187' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2102' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17158' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10404' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17139' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24111' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4139' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27754' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15716' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '108' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23722' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16400' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7246' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32691' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16215' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8892' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11130' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32506' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24315' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23353' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10867' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6857' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8503' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20450' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5989' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10149' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20948' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22594' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7948' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26070' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23870' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2641' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '440' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3917' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1625' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3936' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21466' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19562' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8763' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32377' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24685' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23926' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14957' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13440' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23149' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22779' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26255' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9205' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18008' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7302' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29271' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8189' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20117' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4879' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26497' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11851' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22816' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15494' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3456' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1440' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13810' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30287' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16826' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14550' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30102' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13625' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22428' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7782' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24074' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25719' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20833' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11074' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27365' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30842' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31375' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32487' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8688' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12164' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26274' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4675' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11462' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18785' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17860' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20098' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26829' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26848' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31453' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9854' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1199' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24813' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25406' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23130' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26682' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32155' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26108' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2660' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15697' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27939' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15531' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10722' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18045' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3954' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29400' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31638' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20246' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13885' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11092' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12424' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4898' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19983' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18230' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10907' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3584' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23205' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '497' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3271' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32321' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23168' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15845' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16952' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1714' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18005' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19557' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22152' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5675' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23797' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7321' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25443' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10797' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27089' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12443' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28735' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14089' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27807' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30381' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '880' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15735' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '140' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18876' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20648' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22814' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17785' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6616' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8262' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15585' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9538' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17230' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2585' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17541' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10219' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6763' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28362' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '716' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18839' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1086' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17381' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25055' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32710' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28437' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11961' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30083' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13607' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31729' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17083' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '607' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18729' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2252' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20375' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22020' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '25497' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9020' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30177' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1089' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16249' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13700' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '904' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19026' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2550' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20672' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6026' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22318' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7672' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23964' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9318' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27440' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10964' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21763' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5287' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23409' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6932' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10409' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12055' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8870' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21870' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11647' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8356' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7431' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '14920' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7597' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '16936' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19377' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5249' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6895' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '10001' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4547' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31989' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11500' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20468' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20986' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30324' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22650' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7801' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19914' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17694' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27218' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12757' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32136' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22983' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27791' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27957' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31951' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23760' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13478' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32359' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9280' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31766' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '22613' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27051' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '146' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2697' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6155' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '2823' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8334' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8650' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24942' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24572' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9498' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '8096' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11572' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '13218' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '31340' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32616' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '218' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '21463' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9331' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19855' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '26068' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '4804' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3528' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23296' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3231' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17265' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23184' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '30450' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '15952' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28767' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '23886' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28343' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '19616' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9428' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '20597' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '27124' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '17970' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '6801' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11171' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '24216' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '29528' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '28732' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12532' = '<Full path to file>'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '11703' = '<Full path to file>'
Malicious functions:
To bypass firewall, removes or modifies the following registry keys:
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
Hides the following processes:
  • C:\lsass.exe
Modifies file system:
Creates the following files:
  • C:\lsass.exe
  • <ANALYSETOOLS_DIR>\DumpNet\CmdDotNetDumper.log
  • <Full path to file>
Network activity:
Connects to:
  • '19#.#6.37.211':3128
  • '20#.10.35.7':3128
  • '20#.#71.226.113':3128
  • '19#.#59.193.224':3128
  • '85.##1.119.64':3128
  • '18#.#4.161.235':3128
  • '89.##4.212.6':3128
  • '90.##5.70.240':3128
  • '85.##4.55.133':3128
  • '19#.#7.115.226':3128
  • '79.##7.13.172':3128
  • '70.##6.181.248':3128
  • '78.#0.47.54':3128
  • '84.##0.58.244':3128
  • '68.##1.84.32':3128
  • '82.##4.168.215':3128
  • '93.##3.32.100':3128
  • '71.##5.167.192':3128
  • '20#.#7.11.53':3128
  • '19#.5.30.42':3128
  • '20#.#4.186.248':3128
  • '71.##.89.178':3128
  • '74.#29.93.5':3128
  • '69.##0.54.52':3128
  • '67.##1.33.242':3128
  • '78.##.228.140':3128
  • '19#.#04.130.12':3128
  • '20#.#2.35.195':3128
  • '88.##8.60.110':3128
  • '20#.#9.19.104':3128
  • '91.##9.238.68':3128
  • '12#.#23.111.59':3128
  • '84.##1.203.233':3128
  • '18#.#01.48.178':3128
  • '67.##3.217.124':3128
  • '85.##.46.186':3128
  • '91.##7.152.4':3128
  • '19#.#34.186.228':3128
  • '21#.#53.129.127':3128
  • '19#.#0.36.59':3128
  • '95.##4.54.195':3128
  • '98.##3.127.251':3128
  • '20#.#3.62.109':3128
  • '18#.#4.34.173':3128
  • '60.##3.24.44':3128
  • '19#.#9.172.241':3128
  • '21#.#41.92.224':3128
  • '20#.#.205.176':3128
  • '20#.#61.197.69':3128
  • '18#.#11.123.249':3128
  • '62.##1.92.44':3128
  • '18#.#1.141.37':3128
  • '19#.#81.53.26':3128
  • '20#.#74.221.249':3128
  • '19#.#88.247.213':3128
  • '94.##.68.141':3128
  • '19#.#5.133.107':3128
  • '20#.#10.130.20':3128
  • '75.##8.41.140':3128
  • '82.#6.53.41':3128
  • '12#.#0.98.26':3128
  • '19#.#38.168.49':3128
  • '82.#7.22.50':3128
  • '19#.#9.132.194':3128
  • '84.#0.12.72':3128
  • '20#.#16.154.186':3128
  • '18#.#.119.13':3128
  • '77.##.42.139':3128
  • '20#.#71.108.238':3128
  • '19#.#6.105.61':3128
  • '68.##.192.178':3128
  • '77.##.62.108':3128
  • '86.##2.251.11':3128
  • '18#.#1.13.237':3128
  • '19#.#01.89.213':3128
  • '69.##3.230.173':3128
  • '19#.#20.50.66':3128
  • '70.##.202.16':3128
  • '21#.#30.119.106':3128
  • '20#.#36.232.3':3128
  • '78.#8.79.77':3128
  • '69.##4.161.141':3128
  • '17#.#2.51.109':3128
  • '99.##0.198.167':3128
  • '20#.#33.22.252':3128
  • '20#.#18.191.110':3128
  • '18#.#8.136.25':3128
  • '85.##.116.219':3128
  • '24.##0.184.152':3128
  • '76.##7.188.157':3128
  • '20#.#63.223.205':3128
  • '18#.#8.55.24':3128
  • '19#.#47.61.5':3128
  • '11#.#5.80.135':3128
  • '98.##2.255.92':3128
  • '<LOCALNET>.0.2':80
  • '98.##0.39.21':3128
  • '66.##7.80.100':3128
  • '11#.#46.143.168':3128
  • '19#.#83.136.242':3128
  • '19#.#07.100.113':3128
  • '12#.#42.63.165':3128
  • '41.##1.175.85':3128
  • '84.##2.142.86':3128
  • '79.##.12.118':3128
  • '18#.#8.142.129':3128
  • '20#.#.22.192':3128
  • '82.##7.236.171':3128
  • '18#.#0.163.182':3128
  • '20#.#11.53.77':3128
  • '82.##4.82.17':3128
  • '20#.#8.51.58':3128
  • '81.##0.59.235':3128
  • '98.##7.76.39':3128
  • '20#.#7.9.192':3128
  • '68.##.67.253':3128
  • '89.##.244.57':3128
  • '12#.#7.244.48':3128
  • '24.##9.253.195':3128
  • '89.##.39.184':3128
  • '76.##1.31.129':3128
  • '19#.#2.53.44':3128
  • '84.##.102.56':3128
  • '20#.1.46.64':3128
  • '18#.#11.131.139':3128
  • '86.##.254.223':3128
  • '89.##.251.39':3128
  • '77.##.158.250':3128
  • '19#.#29.93.210':3128
  • '78.##.72.201':3128
  • '78.##.247.68':3128
  • '84.##7.174.56':3128
  • '12#.#2.39.67':3128
  • '24.##.216.247':3128
  • '78.##.51.140':3128
  • '72.##2.239.53':3128
  • '82.##3.47.158':3128
  • '19#.#64.7.219':3128
  • '20#.#2.163.75':3128
  • '19#.#0.28.114':3128
  • '64.##3.161.53':3128
  • '18#.#1.145.92':3128
  • '21#.#0.95.10':3128
  • '20#.#5.24.166':3128
  • '76.##.204.100':3128
  • '70.##0.209.52':3128
  • '59.##.164.239':3128
  • '75.#2.116.5':3128
  • '86.##.24.216':3128
  • '24.##9.150.100':3128
  • '94.##0.96.102':3128
  • '12#.#23.7.106':3128
  • '18#.#8.44.142':3128
  • '20#.#34.132.2':3128
  • '18#.#4.100.76':3128
  • '11#.#5.109.140':3128
  • '99.##5.234.179':3128
  • '19#.#8.25.80':3128
  • '62.##9.129.52':3128
  • '81.#3.185.0':3128
  • '11#.#94.81.221':3128
  • '76.##0.204.36':3128
  • '19#.#00.162.18':3128
  • '20#.#8.71.33':3128
  • '77.##.135.125':3128
  • '20#.#9.228.181':3128
  • '19#.#57.164.57':3128
  • '62.##.207.153':3128
  • '19#.#55.9.58':3128
  • '85.##.88.157':3128
  • '99.##6.185.71':3128
  • '80.##4.12.234':3128
  • '93.##3.26.61':3128
  • '82.##0.153.53':3128
  • '94.##8.80.183':3128
  • '18#.#4.120.86':3128
  • '88.##1.208.60':3128
  • '70.##2.210.222':3128
  • '20#.#07.17.200':3128
  • '18#.#5.126.133':3128
  • '89.##.119.125':3128
  • '21#.#7.23.36':3128
  • '18#.#2.216.195':3128
  • '20#.#88.255.90':3128
  • '67.#2.3.13':3128
  • '18#.#5.2.216':3128
  • '75.##.31.100':3128
  • '85.##1.131.222':0
  • '21#.#54.245.142':3128
  • '20#.#2.102.68':3128
  • '72.#9.73.61':3128
  • '78.##.251.47':3128
  • '20#.#17.106.54':3128
  • '17#.#7.41.37':3128
  • '19#.#25.71.247':3128
  • '61.##.98.165':3128
  • '59.##.64.180':3128
  • '19#.#5.110.25':3128
  • '84.##.205.123':3128
  • '18#.#.228.125':3128
  • '20#.#55.221.50':3128
  • '19#.#58.29.252':3128
  • '89.##3.142.181':3128
  • '70.##0.206.55':3128
  • '78.##.189.82':3128
  • '88.##2.113.235':3128
  • '93.##2.155.128':3128
  • '20#.#17.8.35':3128
  • '71.##3.163.37':3128
  • '24.##0.159.165':3128
  • '84.##2.84.37':3128
  • '20#.#40.192.123':3128
  • '20#.#68.86.38':3128
  • '19#.#4.21.163':3128
  • '18#.#4.128.34':3128
  • '89.#30.7.8':3128
  • '99.##.11.232':3128
  • '21#.#0.230.94':3128
  • '69.##2.132.215':3128
  • '18#.#22.145.83':3128
  • '19#.#15.60.224':3128
  • '78.##9.59.115':3128
  • '85.##5.171.66':3128
  • '68.##.125.83':3128
  • '94.##5.189.157':3128
  • '76.##2.148.20':3128
  • '18#.#69.139.45':3128
  • '20#.#43.58.15':3128
  • '19#.#2.126.170':3128
  • '18#.#20.216.80':3128
  • '78.##.196.53':3128
  • '86.##0.115.204':3128
  • '67.##7.29.188':3128
  • '59.##.211.38':3128
  • '11#.#1.3.132':3128
  • '98.##8.246.2':3128
  • '18#.#8.32.251':3128
  • '85.##2.157.70':3128
  • '68.##3.251.209':3128
  • '84.##6.44.157':3128
  • '20#.#7.5.122':3128
  • '89.#5.85.68':3128
  • '89.##5.183.139':3128
  • '20#.#5.50.254':3128
  • '18#.#2.17.38':3128
  • '85.##.171.68':3128
  • '66.##.42.223':3128
  • '84.##8.183.98':3128
  • '18#.#8.196.221':3128
  • '21#.#2.163.248':3128
  • '18#.#1.74.218':3128
  • '64.##2.113.59':3128
  • '21#.#07.29.216':3128
  • '18#.#5.146.59':3128
  • '67.##2.11.22':3128
  • '19#.#1.194.106':3128
  • '19#.#1.121.71':3128
  • '59.#.100.14':3128
  • '71.#3.3.97':3128
  • '19#.#9.18.108':3128
  • '64.##4.29.29':3128
  • '24.##0.126.55':3128
  • '24.##8.19.107':3128
  • '71.#1.220.0':3128
  • '89.##3.106.237':3128
  • '18#.#6.196.81':3128
  • '68.##.139.191':3128
  • '16#.#46.210.246':3128
  • '70.##3.167.212':3128
  • '70.##8.244.12':3128
  • '18#.#0.98.35':3128
  • '84.##.250.26':3128
  • '84.##.239.237':3128
  • '12#.7.8.42':3128
  • '87.##6.105.67':3128
  • '98.##8.213.217':3128
  • '81.##.151.184':3128
  • '78.#7.6.147':3128
  • '21#.#0.223.161':3128
  • '24.##.175.131':3128
  • '20#.#6.66.14':3128
  • '85.##1.75.88':3128
  • '85.##1.131.222':3128
  • '80.##9.104.84':3128
  • '86.##6.177.75':3128
  • '20#.#7.72.195':3128
  • '11#.#65.154.214':3128
  • '78.##.105.37':3128
  • '90.##8.209.207':3128
  • '20#.#17.110.77':3128
  • '85.##.148.177':3128
  • '12#.#58.105.39':3128
  • '17#.#5.28.229':3128
  • '84.##.16.250':3128
  • '76.##.55.223':3128
  • '82.##1.119.31':3128
  • '68.##4.13.255':3128
  • '92.##.20.214':3128
  • '71.##9.84.249':3128
  • '76.##9.56.111':3128
  • '20#.#9.120.112':3128
  • '94.#2.ttp':0
TCP:
HTTP POST requests:
  • http://19#.#6.37.211/+9217.html
  • http://67.##2.11.22/+9217.html
  • http://18#.#5.146.59/+9217.html
  • http://64.##2.113.59/+9217.html
  • http://21#.#07.29.216/+9217.html
  • http://21#.#07.29.216/+8447.html
  • http://18#.#5.146.59/+8447.html
  • http://18#.#1.74.218/+8447.html
  • http://21#.#2.163.248/+8447.html
  • http://12#.#23.7.106/+8447.html
  • http://72.#9.73.61/+8447.html
  • http://59.##.211.38/+9217.html
  • http://94.##0.96.102/+8447.html
  • http://20#.#.205.176/+8447.html
  • http://21#.#41.92.224/+8447.html
  • http://19#.#9.172.241/+8447.html
  • http://60.##3.24.44/+8447.html
  • http://19#.#00.162.18/+8447.html
  • http://75.##.31.100/+8447.html
  • http://18#.#4.34.173/+8447.html
  • http://89.##3.106.237/+8447.html
  • http://11#.#94.81.221/+8447.html
  • http://68.##.139.191/+8447.html
  • http://19#.#1.121.71/+9217.html
  • http://19#.#1.194.106/+9217.html
  • http://59.#.100.14/+9217.html
  • http://71.#3.3.97/+9217.html
  • http://19#.#9.18.108/+9217.html
  • http://85.##1.75.88/+9217.html
  • http://18#.#2.17.38/+9217.html
  • http://89.##5.183.139/+9217.html
  • http://89.#5.85.68/+9217.html
  • http://20#.#7.5.122/+9217.html
  • http://84.##6.44.157/+9217.html
  • http://68.##3.251.209/+9217.html
  • http://85.##2.157.70/+9217.html
  • http://18#.#8.32.251/+9217.html
  • http://98.##8.246.2/+9217.html
  • http://20#.#3.62.109/+8447.html
  • http://21#.#0.223.161/+8447.html
  • http://11#.#1.3.132/+9217.html
  • http://86.##0.115.204/+9217.html
  • http://78.##.196.53/+9217.html
  • http://19#.#2.126.170/+9217.html
  • http://84.##8.183.98/+9217.html
  • http://18#.#20.216.80/+9217.html
  • http://89.##3.106.237/+9217.html
  • http://24.##8.19.107/+9217.html
  • http://66.##.42.223/+9217.html
  • http://24.##0.126.55/+9217.html
  • http://64.##4.29.29/+9217.html
  • http://85.##.171.68/+9217.html
  • http://67.##7.29.188/+9217.html
  • http://98.##3.127.251/+8447.html
  • http://20#.#40.192.123/+8447.html
  • http://18#.#11.123.249/+8447.html
  • http://20#.#71.108.238/+8447.html
  • http://77.##.42.139/+8447.html
  • http://84.#0.12.72/+8447.html
  • http://89.##5.183.139/+8447.html
  • http://82.#7.22.50/+8447.html
  • http://84.##.250.26/+8447.html
  • http://86.##2.251.11/+8447.html
  • http://75.##8.41.140/+8447.html
  • http://91.##7.152.4/+8447.html
  • http://93.##3.32.100/+8447.html
  • http://76.##0.204.36/+8447.html
  • http://18#.#01.48.178/+8447.html
  • http://85.##1.131.222/+9217.html
  • http://93.##3.26.61/+8447.html
  • http://19#.#38.168.49/+8447.html
  • http://78.#7.6.147/+8447.html
  • http://12#.#0.98.26/+8447.html
  • http://82.#6.53.41/+8447.html
  • http://18#.#.228.125/+8447.html
  • http://70.##2.210.222/+8447.html
  • http://18#.#6.196.81/+8447.html
  • http://18#.#.119.13/+8447.html
  • http://20#.#17.106.54/+8447.html
  • http://69.##2.132.215/+8447.html
  • http://12#.7.8.42/+8447.html
  • http://20#.#61.197.69/+8447.html
  • http://19#.#6.105.61/+8447.html
  • http://62.##1.92.44/+8447.html
  • http://19#.#0.36.59/+8447.html
  • http://18#.#8.196.221/+8447.html
  • http://67.#2.3.13/+8447.html
  • http://94.##8.80.183/+8447.html
  • http://20#.#6.66.14/+8447.html
  • http://19#.#5.110.25/+8447.html
  • http://24.##9.150.100/+8447.html
  • http://19#.#47.61.5/+8447.html
  • http://19#.#81.53.26/+8447.html
  • http://20#.#8.51.58/+8447.html
  • http://18#.#1.141.37/+8447.html
  • http://19#.#4.21.163/+8447.html
  • http://68.##.192.178/+8447.html
  • http://94.##.68.141/+8447.html
  • http://85.##.88.157/+8447.html
  • http://95.##4.54.195/+8447.html
  • http://20#.#07.17.200/+8447.html
  • http://20#.#74.221.249/+8447.html
  • http://85.##1.131.222/+8447.html
  • http://17#.#5.28.229/+8447.html
  • http://19#.#5.133.107/+8447.html
  • http://20#.#10.130.20/+8447.html
  • http://77.##.62.108/+8447.html
  • http://87.##6.105.67/+8447.html
  • http://19#.#2.126.170/+8447.html
  • http://85.##.46.186/+8447.html
  • http://80.##9.104.84/+9217.html
  • http://76.##9.56.111/+9217.html
  • http://18#.#4.128.34/+9217.html
  • http://19#.#4.21.163/+9217.html
  • http://20#.#68.86.38/+9217.html
  • http://20#.#40.192.123/+9217.html
  • http://84.##2.84.37/+9217.html
  • http://20#.#2.102.68/+9217.html
  • http://88.##2.113.235/+9217.html
  • http://18#.#8.44.142/+9217.html
  • http://19#.#57.164.57/+9217.html
  • http://93.##2.155.128/+9217.html
  • http://78.##.251.47/+9217.html
  • http://20#.#9.228.181/+9217.html
  • http://20#.#8.71.33/+9217.html
  • http://11#.#94.81.221/+9217.html
  • http://81.#3.185.0/+9217.html
  • http://62.##9.129.52/+9217.html
  • http://19#.#8.25.80/+9217.html
  • http://99.##5.234.179/+9217.html
  • http://11#.#5.109.140/+9217.html
  • http://20#.#34.132.2/+9217.html
  • http://18#.#4.100.76/+9217.html
  • http://18#.#6.196.81/+9217.html
  • http://99.##.11.232/+9217.html
  • http://89.#30.7.8/+9217.html
  • http://20#.#17.106.54/+9217.html
  • http://21#.#0.230.94/+9217.html
  • http://78.##9.59.115/+9217.html
  • http://78.##.189.82/+9217.html
  • http://89.##3.142.181/+9217.html
  • http://19#.#58.29.252/+9217.html
  • http://20#.#55.221.50/+9217.html
  • http://18#.#.228.125/+9217.html
  • http://19#.#5.110.25/+9217.html
  • http://72.#9.73.61/+9217.html
  • http://59.##.64.180/+9217.html
  • http://61.##.98.165/+9217.html
  • http://19#.#25.71.247/+9217.html
  • http://19#.#55.9.58/+9217.html
  • http://77.##.135.125/+9217.html
  • http://17#.#7.41.37/+9217.html
  • http://20#.#17.8.35/+9217.html
  • http://84.##.205.123/+9217.html
  • http://62.##.207.153/+9217.html
  • http://94.##5.189.157/+9217.html
  • http://71.##3.163.37/+9217.html
  • http://68.##.125.83/+9217.html
  • http://85.##5.171.66/+9217.html
  • http://18#.#22.145.83/+9217.html
  • http://69.##2.132.215/+9217.html
  • http://19#.#15.60.224/+9217.html
  • http://70.##0.206.55/+9217.html
  • http://24.##0.159.165/+9217.html
  • http://99.##6.185.71/+9217.html
  • http://85.##.88.157/+9217.html
  • http://19#.#00.162.18/+9217.html
  • http://84.##.239.237/+9217.html
  • http://87.##6.105.67/+9217.html
  • http://84.##.250.26/+9217.html
  • http://18#.#0.98.35/+9217.html
  • http://70.##8.244.12/+9217.html
  • http://70.##3.167.212/+9217.html
  • http://16#.#46.210.246/+9217.html
  • http://68.##.139.191/+9217.html
  • http://20#.#7.72.195/+9217.html
  • http://20#.#9.120.112/+9217.html
  • http://86.##6.177.75/+9217.html
  • http://18#.#1.13.237/+9217.html
  • http://11#.#65.154.214/+9217.html
  • http://71.##9.84.249/+9217.html
  • http://92.##.20.214/+9217.html
  • http://68.##4.13.255/+9217.html
  • http://82.##1.119.31/+9217.html
  • http://76.##.55.223/+9217.html
  • http://84.##.16.250/+9217.html
  • http://17#.#5.28.229/+9217.html
  • http://12#.#58.105.39/+9217.html
  • http://85.##.148.177/+9217.html
  • http://20#.#17.110.77/+9217.html
  • http://90.##8.209.207/+9217.html
  • http://12#.7.8.42/+9217.html
  • http://21#.#54.245.142/+9217.html
  • http://98.##8.213.217/+9217.html
  • http://20#.#07.17.200/+9217.html
  • http://80.##4.12.234/+9217.html
  • http://18#.#5.2.216/+9217.html
  • http://67.#2.3.13/+9217.html
  • http://20#.#88.255.90/+9217.html
  • http://18#.#2.216.195/+9217.html
  • http://21#.#7.23.36/+9217.html
  • http://89.##.119.125/+9217.html
  • http://18#.#5.126.133/+9217.html
  • http://94.##8.80.183/+9217.html
  • http://93.##3.26.61/+9217.html
  • http://75.##.31.100/+9217.html
  • http://78.##.105.37/+9217.html
  • http://78.#7.6.147/+9217.html
  • http://70.##2.210.222/+9217.html
  • http://88.##1.208.60/+9217.html
  • http://18#.#4.120.86/+9217.html
  • http://18#.#69.139.45/+9217.html
  • http://20#.#5.50.254/+9217.html
  • http://82.##0.153.53/+9217.html
  • http://71.#1.220.0/+9217.html
  • http://20#.#43.58.15/+9217.html
  • http://20#.#6.66.14/+9217.html
  • http://24.##.175.131/+9217.html
  • http://21#.#0.223.161/+9217.html
  • http://81.##.151.184/+9217.html
  • http:/// via <LOCALNET>.0.2
UDP:
  • DNS ASK 94.#2.ttp
Miscellaneous:
Creates and executes the following:
  • 'C:\lsass.exe' exe <Full path to file>
  • '<Full path to file>' force
Executes the following:
  • '%WINDIR%\XXInstall\ps.exe' --pid=2856 --managed --dump-dir="<ANALYSE_DIR>\DUMPS_NET" --log-dir="<ANALYSETOOLS_DIR>\DumpNet"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке