Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.StartPage1.58180

Добавлен в вирусную базу Dr.Web: 2019-10-06

Описание добавлено:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • <SYSTEM32>\tasks\10879
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\startup\desktop.ini
Creates the following services
  • [<HKLM>\system\currentcontrolset\services\TermService\parameters] 'ServiceDLL' = '%WINDIR%\help\tmp5211.dat'
  • [<HKLM>\System\CurrentControlSet\Services\TermService] 'Start' = '00000002'
Changes the following executable system files
  • <SYSTEM32>\unregmp2.exe
Malicious functions
To complicate detection of its presence in the operating system,
forces the system hide from view:
  • hidden files
  • file extensions
Modifies settings of Windows Internet Explorer
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnOnPost' = '{01,00,00,00}'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'PMDisplayName' = 'Internet [Protected Mode]'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'Description' = 'This zone contains all Web sites you haven't...
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'Icon' = 'inetcpl.cpl#001313'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'LowIcon' = 'inetcpl.cpl#005425'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'CurrentLevel' = '00011500'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'Flags' = '00000001'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '' = ''
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'DisplayName' = 'Restricted sites'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'PMDisplayName' = 'Restricted sites [Protected Mode]'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'Description' = 'This zone contains Web sites that could pote...
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'Icon' = 'inetcpl.cpl#00004481'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'LowIcon' = 'inetcpl.cpl#005426'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'CurrentLevel' = '00012000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'Flags' = '00000003'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1200' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2007' = '00010000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1200' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1200' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1200' = '00000003'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1400' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1400' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1400' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000003'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'DisplayName' = 'Computer'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'PMDisplayName' = 'Computer [Protected Mode]'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonZoneCrossing' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '2007' = '00000003'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2007' = '00010000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2007' = '00010000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'DisplayName' = 'Internet'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1200' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '' = ''
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'CurrentLevel' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{AEBA21FA-782A-4A90-978D-B72164C80120}' = '{1a,37,61,59,23,5...
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A10' = '00000001'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{A8A88C49-5EB2-4990-A1A2-0876022C854F}' = '{1a,37,61,59,23,5...
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '{AEBA21FA-782A-4A90-978D-B72164C80120}' = '{1a,37,61,59,23,5...
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1A10' = '00000003'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '{A8A88C49-5EB2-4990-A1A2-0876022C854F}' = '{1a,37,61,59,23,5...
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '' = ''
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'DisplayName' = 'My Computer'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'PMDisplayName' = 'My Computer [Protected Mode]'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'Description' = 'Your computer'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'Icon' = 'shell32.dll#0016'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'LowIcon' = 'inetcpl.cpl#005422'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] 'Flags' = '00000021'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'CurrentLevel' = '00011000'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '' = ''
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] 'DisplayName' = 'Local intranet'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] 'PMDisplayName' = 'Local intranet [Protected Mode]'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] 'Description' = 'This zone contains all Web sites that are on...
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] 'Icon' = 'shell32.dll#0018'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] 'LowIcon' = 'inetcpl.cpl#005423'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] 'CurrentLevel' = '00010500'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] 'Flags' = '00000143'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '' = ''
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'DisplayName' = 'Trusted sites'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'PMDisplayName' = 'Trusted sites [Protected Mode]'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'Description' = 'This zone contains Web sites that you trust ...
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'Icon' = 'inetcpl.cpl#00004480'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'LowIcon' = 'inetcpl.cpl#005424'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] 'Flags' = '00000047'
  • [\REGISTRY\USER\S-1-5-21-1960123792-2022915161-3775307078-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2007' = '00000003'
Sets a new unauthorized home page for Windows Internet Explorer.
Modifies file system
Creates the following files
  • %TEMP%\nsdf2d4.tmp\blowfish.dll
  • C:\users\supportaccount\appdata\roaming\microsoft\internet explorer\quick launch\google chrome.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\google chrome.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\internet explorer (no add-ons).lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\internet explorer.lnk
  • C:\users\supportaccount\appdata\local\microsoft\internet explorer\brndlog.txt
  • C:\users\supportaccount\favorites\microsoft websites\ie site on microsoft.com.url
  • C:\users\supportaccount\favorites\microsoft websites\ie add-on site.url
  • C:\users\supportaccount\favorites\microsoft websites\microsoft at home.url
  • C:\users\supportaccount\favorites\microsoft websites\microsoft at work.url
  • C:\users\supportaccount\favorites\msn websites\msn.url
  • C:\users\supportaccount\favorites\msn websites\msn sports.url
  • C:\users\supportaccount\favorites\msn websites\msnbc news.url
  • C:\users\supportaccount\favorites\msn websites\msn money.url
  • C:\users\supportaccount\links\downloads.lnk
  • C:\users\supportaccount\appdata\local\temp\chrome_installer.log
  • C:\users\supportaccount\favorites\msn websites\msn entertainment.url
  • C:\users\supportaccount\favorites\msn websites\msn autos.url
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\arub9k7q\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\khvi1oht\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0h0tlwd3\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\index.dat
  • C:\users\supportaccount\appdata\local\microsoft\windows\history\history.ie5\desktop.ini
  • C:\users\supportaccount\links\recentplaces.lnk
  • C:\users\supportaccount\appdata\local\microsoft\windows\history\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\desktop.ini
  • C:\users\supportaccount\favorites\links\desktop.ini
  • C:\users\supportaccount\favorites\microsoft websites\microsoft store.url
  • C:\users\supportaccount\favorites\windows live\get windows live.url
  • C:\users\supportaccount\favorites\windows live\windows live gallery.url
  • C:\users\supportaccount\favorites\windows live\windows live spaces.url
  • C:\users\supportaccount\favorites\windows live\windows live mail.url
  • C:\users\supportaccount\links\desktop.lnk
  • C:\users\supportaccount\searches\everywhere.search-ms
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\cookies\index.dat
  • C:\users\supportaccount\appdata\local\microsoft\windows media\12.0\wmsdkns.dtd
  • C:\users\supportaccount\appdata\local\microsoft\windows media\12.0\wmsdkns.xml.bak
  • C:\users\supportaccount\appdata\local\microsoft\windows media\12.0\wmsdknsd.xml
  • C:\users\supportaccount\appdata\local\microsoft\media player\currentdatabase_372.wmdb
  • C:\users\supportaccount\appdata\local\microsoft\media player\localmls_3.wmdb
  • C:\users\supportaccount\videos\desktop.ini
  • C:\users\supportaccount\pictures\desktop.ini
  • C:\users\supportaccount\desktop\desktop.ini
  • C:\users\supportaccount\favorites\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\desktop.ini
  • C:\users\supportaccount\music\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\desktop.ini
  • C:\users\supportaccount\documents\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\documents.library-ms
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\desktop.ini
  • C:\users\supportaccount\searches\indexed locations.search-ms
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\administrative tools\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\videos.library-ms
  • C:\users\supportaccount\saved games\desktop.ini
  • C:\users\supportaccount\links\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\~usic.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\music.library-ms
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\~ideos.tmp
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\90xm8vtd\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\12_all_video.wpl
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\pictures.library-ms
  • C:\users\supportaccount\downloads\desktop.ini
  • C:\users\supportaccount\searches\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\recent\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\~ocuments.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\~ictures.tmp
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\greenbubbles.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows\history\history.ie5\index.dat
  • C:\users\supportaccount\appdata\local\microsoft\feeds\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\webslices~\web slice gallery~.feed-ms
  • C:\users\supportaccount\appdata\local\temp\~dfc8ddd30cd93dd6b9.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfd978cabb9cefa1ea.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfd77692f7f2aa1f87.tmp
  • C:\users\supportaccount\appdata\local\temp\~df150e7b6ddcf03f43.tmp
  • C:\users\supportaccount\appdata\local\temp\www436f.tmp
  • C:\users\supportaccount\appdata\local\temp\www437f.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi47e3.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi4842.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi4872.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi48c1.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi495e.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\recent\automaticdestinations\1b4dd67f29cb1962.automaticdestinations-ms
  • C:\users\supportaccount\appdata\local\microsoft\windows\explorer\thumbcache_32.db
  • C:\users\supportaccount\appdata\local\microsoft\windows\explorer\thumbcache_96.db
  • C:\users\supportaccount\appdata\local\microsoft\windows\explorer\thumbcache_256.db
  • C:\users\supportaccount\appdata\local\microsoft\windows\explorer\thumbcache_1024.db
  • C:\users\supportaccount\appdata\local\temp\~dfa1a74f4e032ce1de.tmp
  • C:\users\supportaccount\appdata\local\temp\~df92a98de310ef42b7.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfb28d1008edf492c9.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfe067331b84150fea.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfa2249a6c6b243534.tmp
  • C:\users\supportaccount\appdata\local\temp\~df8808e709d9603653.tmp
  • C:\users\supportaccount\appdata\local\temp\~df3cceb61297405b9c.tmp
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\11_all_pictures.wpl
  • C:\users\supportaccount\appdata\local\temp\~dfde2b376afd4a4b19.tmp
  • C:\users\supportaccount\appdata\local\temp\~df6f81b8c468ab4e2f.tmp
  • C:\users\supportaccount\appdata\local\temp\~df1b941ea9a8534de4.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfcd5db9e9025dc550.tmp
  • C:\users\supportaccount\appdata\local\microsoft\windows\explorer\thumbcache_idx.db
  • C:\users\supportaccount\appdata\local\microsoft\windows\explorer\thumbcache_sr.db
  • C:\users\supportaccount\appdata\local\temp\~df4ad80c00d47575d6.tmp
  • C:\users\supportaccount\appdata\local\temp\~df56b8d2f27f2b82f7.tmp
  • C:\users\supportaccount\appdata\local\microsoft\windows media\12.0\wmsdkns.xml
  • C:\users\supportaccount\appdata\local\temp\~df0c9411dceec68724.tmp
  • C:\users\supportaccount\appdata\local\temp\~df08821e5cb2511e6b.tmp
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\y8pzz1b4\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\u2vijt9e\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\z73a4iqj\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\eewb0kpr\desktop.ini
  • C:\users\supportaccount\appdata\local\temp\~df3b48e4d54ae387d2.tmp
  • C:\users\supportaccount\appdata\local\temp\~df94ddcf956afe12c9.tmp
  • C:\users\supportaccount\appdata\local\microsoft\feeds\microsoft feeds~\microsoft at home~.feed-ms
  • C:\users\supportaccount\appdata\local\temp\~df1205057bbb648138.tmp
  • C:\users\supportaccount\appdata\local\temp\~df04f524c559dc962a.tmp
  • C:\users\supportaccount\appdata\local\microsoft\feeds\feedsstore.feedsdb-ms
  • C:\users\supportaccount\appdata\local\temp\~df5b5c18a7acee7788.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfba891c72b8a39261.tmp
  • C:\users\supportaccount\appdata\local\temp\~df33f98ffd1b590be8.tmp
  • C:\users\supportaccount\appdata\local\temp\~df4fabbea6468b64a3.tmp
  • C:\users\supportaccount\appdata\local\temp\~df4516db9342d84674.tmp
  • C:\users\supportaccount\appdata\local\temp\~dff53de17eade9f59b.tmp
  • C:\users\supportaccount\appdata\local\temp\~df939d4bd3493da657.tmp
  • C:\users\supportaccount\appdata\local\temp\~dff1e242803c3cd11e.tmp
  • C:\users\supportaccount\appdata\local\microsoft\feeds\microsoft feeds~\msnbc news~.feed-ms
  • C:\users\supportaccount\appdata\local\temp\~dfd9dad3cfdfb32884.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfb33c7867e1bf87b9.tmp
  • C:\users\supportaccount\favorites\links\web slice gallery.url
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\ietldcache\index.dat
  • C:\users\supportaccount\appdata\local\temp\~df5dd9df044efebb6e.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfff6a74f4c9b23fa5.tmp
  • C:\users\supportaccount\appdata\local\microsoft\feeds\microsoft feeds~\microsoft at work~.feed-ms
  • C:\users\supportaccount\appdata\local\temp\~dff050c0b34fd1605b.tmp
  • C:\users\supportaccount\appdata\local\temp\~dfa09d279c5b3d4807.tmp
  • C:\users\supportaccount\appdata\local\temp\~df8b8867f4f99c29ea.tmp
  • C:\users\supportaccount\appdata\local\temp\~df674d17bc636ae945.tmp
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\index.dat
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\10_all_music.wpl
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\09_music_played_the_most.wpl
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\08_video_rated_at_4_or_5_stars.wpl
  • C:\users\supportaccount\appdata\local\microsoft\windows\usrclass.dat
  • C:\users\supportaccount\ntuser.dat.log1
  • C:\users\supportaccount\ntuser.pol
  • \device\termdd
  • C:\users\supportaccount\appdata\local\microsoft\windows\explorer\explorerstartuplog.etl
  • C:\users\supportaccount\appdata\local\temp\rgic824.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic864.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic8a3.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic8f2.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic932.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic9df.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\themes\transcodedwallpaper.jpg
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1006\desktop.ini
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1006\desktop.ini
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete2c1.tmp
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\edb.log
  • <SYSTEM32>\spool\drivers\x64\3\new\tsprint-pipelineconfig.xml
  • C:\users\supportaccount\contacts\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\edbres00002.jrs
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\edbres00001.jrs
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\edbtmp.log
  • C:\users\supportaccount\appdata\local\temp\supportaccount.bmp
  • C:\users\supportaccount\contacts\supportaccount.contact
  • C:\users\supportaccount\appdata\local\microsoft\windows\usrclass.dat.log1
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\windows explorer.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\sendto\fax recipient.lnk
  • <SYSTEM32>\spool\drivers\x64\3\new\tsprint.dll
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete351.tmp
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete312.tmp
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete2f1.tmp
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete2d1.tmp
  • <SYSTEM32>\spool\drivers\x64\3\new\tsprint-datafile.dat
  • C:\users\supportaccount\appdata\local\temp\~df3ea81abebe49125b.tmp
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\tmp.edb
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.ini
  • %TEMP%\cvmmydqftn458743cvmmydqftn.ps1
  • %TEMP%\nsdf2d4.tmp\system.dll
  • %WINDIR%\help\tmp5211.dat
  • %WINDIR%\help\tmp5212.dat
  • %WINDIR%\help\tmp5213.dat
  • <SYSTEM32>\rfxvmt.dll
  • <SYSTEM32>\microsoft\protect\s-1-5-20\f4fb4893-638a-4bcd-a534-5b37fa4b283b
  • <SYSTEM32>\microsoft\protect\s-1-5-20\preferred
  • %PROGRAMDATA%\microsoft\crypto\rsa\machinekeys\f686aace6942fb7f7ceb231212eef4a4_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • C:\users\supportaccount\ntuser.dat
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\maintenance\help.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\maintenance\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\private character editor.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\desktop.ini
  • %TEMP%\chadshfsd323.txt
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\computer.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\control panel.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\on-screen keyboard.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\narrator.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\magnify.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\sendto\mail recipient.mapimail
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\run.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\ease of access.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\sendto\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\command prompt.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\internet explorer\quick launch\window switcher.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\internet explorer\quick launch\shows desktop.lnk
  • C:\users\supportaccount\appdata\roaming\microsoft\internet explorer\quick launch\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\sendto\desktop (create shortcut).desklink
  • C:\users\supportaccount\appdata\local\temp\~df52de5a7cb77947e5.tmp
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\edb.chk
  • C:\users\supportaccount\appdata\roaming\microsoft\protect\s-1-5-21-1960123792-2022915161-3775307078-1006\86be87a1-eb15-4be0-8c08-2aa21c6addb5
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\peacock.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\pine_lumber.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\pretty_peacock.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\psychedelic.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\roses.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\roses.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\sand_paper.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\seyes.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\shades of blue.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\shadesofblue.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\shorthand.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\small_news.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\soft blue.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\softblue.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\stars.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\stars.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\stucco.gif
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\orangecircles.jpg
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\07_tv_recorded_in_the_last_week.wpl
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\06_pictures_rated_4_or_5_stars.wpl
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\05_pictures_taken_in_the_last_month.wpl
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\04_music_played_in_the_last_month.wpl
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\03_music_rated_at_4_or_5_stars.wpl
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\peacock.htm
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\02_music_added_in_the_last_month.wpl
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\windowsmail.msmessagestore
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\wrinkled_paper.gif
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\white_chocolate.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\to_do_list.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\tiki.gif
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\tanspecks.jpg
  • C:\users\supportaccount\appdata\local\microsoft\media player\sync playlists\en-us\001116e0\01_music_auto_rated_at_5_stars.wpl
  • C:\users\supportaccount\appdata\roaming\microsoft\protect\credhist
  • C:\users\supportaccount\appdata\local\temp\wmsetup.log
  • C:\users\supportaccount\ntuser.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\protect\s-1-5-21-1960123792-2022915161-3775307078-1006\preferred
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\backup\temp\windowsmail.msmessagestore
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\windowsmail.pat
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\backup\temp\edb00001.log
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\backup\temp\windowsmail.pat
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\account{c2835ef5-da55-4a8f-bfcc-0dbcac05e787}.oeaccount
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\account{7f032ae1-3bd8-45da-91fa-0190e30affc2}.oeaccount
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\account{e2563802-5569-4bae-951f-5ca2208d227c}.oeaccount
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\oeold.xml
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\bears.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\bears.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\blue_gradient.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\cave_drawings.gif
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\connectivity.gif
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\dotted_lines.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\garden.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\notebook.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\month_calendar.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\monet.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\memo.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\handprints.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\hand prints.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\orange circles.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\grid_(inch).wmf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\music.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\green bubbles.htm
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\graph.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\genko_2.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\genko_1.emf
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\garden.jpg
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\stationery\grid_(cm).wmf
  • C:\users\supportaccount\appdata\local\temp\~df4753f669d58fc8ed.tmp
Sets the 'hidden' attribute to the following files
  • C:\users\supportaccount\ntuser.dat
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\desktop.ini
  • C:\users\supportaccount\favorites\links\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0h0tlwd3\desktop.ini
  • C:\users\supportaccount\links\desktop.ini
  • C:\users\supportaccount\saved games\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\khvi1oht\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\history\history.ie5\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\y8pzz1b4\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\u2vijt9e\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\z73a4iqj\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\arub9k7q\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\<INETFILES>\content.ie5\90xm8vtd\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\administrative tools\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\startup\desktop.ini
  • C:\users\supportaccount\downloads\desktop.ini
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1006\desktop.ini
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1006\desktop.ini
  • C:\users\supportaccount\contacts\desktop.ini
  • C:\users\supportaccount\videos\desktop.ini
  • C:\users\supportaccount\pictures\desktop.ini
  • C:\users\supportaccount\desktop\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\usrclass.dat
  • C:\users\supportaccount\favorites\desktop.ini
  • C:\users\supportaccount\music\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\desktop.ini
  • C:\users\supportaccount\documents\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\recent\desktop.ini
  • C:\users\supportaccount\searches\desktop.ini
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\feeds cache\eewb0kpr\desktop.ini
  • C:\users\supportaccount\appdata\local\microsoft\windows\history\desktop.ini
Deletes the following files
  • %TEMP%\nsdf2d4.tmp\blowfish.dll
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\videos.library-ms~rf116ffd.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\music.library-ms~rf116fed.tmp
  • C:\users\supportaccount\appdata\local\microsoft\media player\localmls_3.wmdb
  • C:\users\supportaccount\appdata\local\temp\rgi495e.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi48c1.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi4872.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi4842.tmp
  • C:\users\supportaccount\appdata\local\temp\rgi47e3.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\start menu\programs\internet explorer.lnk
  • C:\users\supportaccount\appdata\local\temp\www437f.tmp
  • C:\users\supportaccount\appdata\local\temp\www436f.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\music.library-ms~rf11276b.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\videos.library-ms~rf11273c.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\pictures.library-ms~rf1126ee.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\documents.library-ms~rf11700c.tmp
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\documents.library-ms~rf112690.tmp
  • C:\users\supportaccount\appdata\local\microsoft\windows media\12.0\wmsdkns.xml.bak
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\xpssvcs.dll
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\tsprint.dll
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\tsprint-pipelineconfig.xml
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\tsprint-datafile.dat
  • <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\mxdwdrv.dll
  • C:\users\supportaccount\appdata\local\temp\rgic9df.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic932.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic8f2.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic8a3.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic864.tmp
  • C:\users\supportaccount\appdata\local\temp\rgic824.tmp
  • %TEMP%\chadshfsd323.txt
  • %TEMP%\nsdf2d4.tmp\system.dll
  • C:\users\supportaccount\appdata\local\microsoft\windows media\12.0\wmsdknsd.xml
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\pictures.library-ms~rf11704b.tmp
Moves the following files
  • from <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete2c1.tmp to <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\tsprint.dll
  • from C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\videos.library-ms to C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\videos.library-ms~rf116ffd.tmp
  • from C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\music.library-ms to C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\music.library-ms~rf116fed.tmp
  • from C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\music.library-ms to C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\music.library-ms~rf11276b.tmp
  • from C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\videos.library-ms to C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\videos.library-ms~rf11273c.tmp
  • from C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\pictures.library-ms to C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\pictures.library-ms~rf1126ee.tmp
  • from C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\documents.library-ms to C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\documents.library-ms~rf112690.tmp
  • from C:\users\supportaccount\appdata\local\microsoft\windows mail\edb.log to C:\users\supportaccount\appdata\local\microsoft\windows mail\edb00001.log
  • from C:\users\supportaccount\appdata\local\microsoft\windows mail\edbtmp.log to C:\users\supportaccount\appdata\local\microsoft\windows mail\edb.log
  • from <SYSTEM32>\spool\drivers\x64\3\new\tsprint-pipelineconfig.xml to <SYSTEM32>\spool\drivers\x64\3\tsprint-pipelineconfig.xml
  • from <SYSTEM32>\spool\drivers\x64\3\new\tsprint-datafile.dat to <SYSTEM32>\spool\drivers\x64\3\tsprint-datafile.dat
  • from <SYSTEM32>\spool\drivers\x64\3\new\tsprint.dll to <SYSTEM32>\spool\drivers\x64\3\tsprint.dll
  • from <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete351.tmp to <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\xpssvcs.dll
  • from <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete312.tmp to <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\mxdwdrv.dll
  • from <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete2f1.tmp to <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\tsprint-datafile.dat
  • from <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\sete2d1.tmp to <SYSTEM32>\spool\drivers\x64\{657c0d7c-4b38-4c43-bd7f-1a615e136da6}\tsprint-pipelineconfig.xml
  • from C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\documents.library-ms to C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\documents.library-ms~rf11700c.tmp
  • from C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\pictures.library-ms to C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\pictures.library-ms~rf11704b.tmp
Substitutes the following files
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\edbtmp.log
  • C:\users\supportaccount\appdata\local\microsoft\windows mail\edb.log
  • C:\users\supportaccount\appdata\local\microsoft\windows media\12.0\wmsdkns.xml.bak
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\documents.library-ms
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\pictures.library-ms
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\videos.library-ms
  • C:\users\supportaccount\appdata\roaming\microsoft\windows\libraries\music.library-ms
Deletes itself.
Network activity
UDP
  • DNS ASK af####daslfo3d3.xyz
Miscellaneous
Searches for the following windows
  • ClassName: 'CicLoaderWndClass' WindowName: ''
  • ClassName: 'Progman' WindowName: ''
  • ClassName: 'Proxy Desktop' WindowName: ''
  • ClassName: 'PersonalizationThemeChangeListener' WindowName: ''
  • ClassName: 'SystemTray_Main' WindowName: ''
  • ClassName: 'OutlookExpressHiddenWindow' WindowName: ''
Creates and executes the following
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ep bypass -f %TEMP%\CVMMYDQFTN458743CVMMYDQFTN.ps1
  • '<SYSTEM32>\cmd.exe' /c powershell -ep bypass -f %TEMP%\CVMMYDQFTN458743CVMMYDQFTN.ps1' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C net.exe user supportaccount asfggees /del' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C net.exe user supportaccount QkwtUk7T /add' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C net.exe LOCALGROUP "Remote Desktop Users" supportaccount /ADD' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C net.exe LOCALGROUP "Remote Desktop Users" scuinqjzl$ /ADD' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C net.exe LOCALGROUP "Administrators" supportaccount /ADD' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C net.exe user supportaccount QkwtUk7T' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C schtasks /create /tn 10879 /tr "powershell -nop -ep bypass -f %WINDIR%\help\84577.ps1" /ru system /sc hourly /mo 1' (with hidden window)
  • '<SYSTEM32>\userinit.exe' ' (with hidden window)
  • '%WINDIR%\syswow64\rundll32.exe' advpack.dll,LaunchINFSectionEx <SYSTEM32>\ieuinit.inf,Install,,36' (with hidden window)
  • '<SYSTEM32>\rundll32.exe' advpack.dll,LaunchINFSectionEx <SYSTEM32>\ieuinit.inf,Install,,36' (with hidden window)
Executes the following
  • '<SYSTEM32>\cmd.exe' /c powershell -ep bypass -f %TEMP%\CVMMYDQFTN458743CVMMYDQFTN.ps1
  • '<SYSTEM32>\cmd.exe' /C schtasks /create /tn 10879 /tr "powershell -nop -ep bypass -f %WINDIR%\help\84577.ps1" /ru system /sc hourly /mo 1
  • '<SYSTEM32>\schtasks.exe' /create /tn 10879 /tr "powershell -nop -ep bypass -f %WINDIR%\help\84577.ps1" /ru system /sc hourly /mo 1
  • '<SYSTEM32>\smss.exe' 00000000 0000003c
  • '<SYSTEM32>\csrss.exe' ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitializa...
  • '<SYSTEM32>\winlogon.exe'
  • '<SYSTEM32>\rdpclip.exe'
  • '<SYSTEM32>\userinit.exe'
  • '%WINDIR%\explorer.exe'
  • '%WINDIR%\syswow64\ie4uinit.exe' -BaseSettings
  • '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
  • '%WINDIR%\syswow64\rundll32.exe' advpack.dll,LaunchINFSectionEx <SYSTEM32>\ieuinit.inf,Install,,36
  • '<SYSTEM32>\regsvr32.exe' /s /n /i:/UserInstall <SYSTEM32>\themeui.dll
  • '<SYSTEM32>\rundll32.exe' uxtheme.dll,#64 %WINDIR%\resources\Themes\Aero\Aero.msstyles?NormalColor?NormalSize
  • '%ProgramFiles%\windows mail\winmail.exe' OCInstallUserConfigOE
  • '%ProgramFiles%\windows sidebar\sidebar.exe' /autoRun
  • '<SYSTEM32>\unregmp2.exe' /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
  • '<SYSTEM32>\regsvr32.exe' /s /n /i:U shell32.dll
  • '%WINDIR%\syswow64\rundll32.exe' %WINDIR%\SysWOW64\mscories.dll,Install
  • '%ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\installer\chrmstp.exe' --configure-user-settings --verbose-logging --system-level --multi-install --chrome
  • '%WINDIR%\syswow64\ie4uinit.exe' -UserIconConfig
  • '%WINDIR%\syswow64\ie4uinit.exe' -ClearIconCache
  • '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
  • '<SYSTEM32>\ie4uinit.exe' -BaseSettings
  • '<SYSTEM32>\rundll32.exe' advpack.dll,LaunchINFSectionEx <SYSTEM32>\ieuinit.inf,Install,,36
  • '<SYSTEM32>\rundll32.exe' <SYSTEM32>\mscories.dll,Install
  • '<SYSTEM32>\ie4uinit.exe' -UserIconConfig
  • '<SYSTEM32>\ie4uinit.exe' -ClearIconCache
  • '<SYSTEM32>\rundll32.exe' "<SYSTEM32>\iedkcs32.dll",BrandIEActiveSetup SIGNUP
  • '<SYSTEM32>\net1.exe' user supportaccount QkwtUk7T
  • '%ProgramFiles(x86)%\windows mail\winmail.exe' OCInstallUserConfigOE
  • '<SYSTEM32>\net.exe' user supportaccount QkwtUk7T
  • '<SYSTEM32>\cmd.exe' /c del %temp%\*.ps1 /f
  • '<SYSTEM32>\takeown.exe' /A /F rfxvmt.dll
  • '<SYSTEM32>\icacls.exe' rfxvmt.dll /inheritance:d
  • '<SYSTEM32>\icacls.exe' rfxvmt.dll /setowner "NT SERVICE\TrustedInstaller"
  • '<SYSTEM32>\icacls.exe' rfxvmt.dll /grant "NT SERVICE\TrustedInstaller:F"
  • '<SYSTEM32>\icacls.exe' rfxvmt.dll /remove "NT AUTHORITY\SYSTEM"
  • '<SYSTEM32>\icacls.exe' rfxvmt.dll /grant "NT AUTHORITY\SYSTEM:RX"
  • '<SYSTEM32>\icacls.exe' rfxvmt.dll /remove BUILTIN\Administrators
  • '<SYSTEM32>\icacls.exe' rfxvmt.dll /grant BUILTIN\Administrators:RX
  • '<SYSTEM32>\reg.exe' ADD "HKLM\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v PortNumber /t REG_DWORD /d 0x1C21 /f
  • '<SYSTEM32>\reg.exe' add HKLM\system\currentcontrolset\services\TermService\parameters /v ServiceDLL /t REG_EXPAND_SZ /d %WINDIR%\help\tmp5211.dat /f
  • '<SYSTEM32>\net.exe' localgroup Administrators "NT AUTHORITY\NETWORK SERVICE" /add
  • '<SYSTEM32>\net1.exe' localgroup Administrators "NT AUTHORITY\NETWORK SERVICE" /add
  • '<SYSTEM32>\cmd.exe' /C net.exe user supportaccount asfggees /del
  • '<SYSTEM32>\cmd.exe' /c del %temp%\*.txt /f
  • '<SYSTEM32>\net1.exe' LOCALGROUP "Administrators" supportaccount /ADD
  • '<SYSTEM32>\net.exe' user supportaccount asfggees /del
  • '<SYSTEM32>\net1.exe' user supportaccount asfggees /del
  • '<SYSTEM32>\cmd.exe' /C net.exe user supportaccount QkwtUk7T /add
  • '<SYSTEM32>\net.exe' user supportaccount QkwtUk7T /add
  • '<SYSTEM32>\net1.exe' user supportaccount QkwtUk7T /add
  • '<SYSTEM32>\cmd.exe' /C net.exe LOCALGROUP "Remote Desktop Users" supportaccount /ADD
  • '<SYSTEM32>\net.exe' LOCALGROUP "Remote Desktop Users" supportaccount /ADD
  • '<SYSTEM32>\net1.exe' LOCALGROUP "Remote Desktop Users" supportaccount /ADD
  • '<SYSTEM32>\cmd.exe' /C net.exe LOCALGROUP "Remote Desktop Users" scuinqjzl$ /ADD
  • '<SYSTEM32>\net.exe' LOCALGROUP "Remote Desktop Users" scuinqjzl$ /ADD
  • '<SYSTEM32>\net1.exe' LOCALGROUP "Remote Desktop Users" scuinqjzl$ /ADD
  • '<SYSTEM32>\cmd.exe' /C net.exe LOCALGROUP "Administrators" supportaccount /ADD
  • '<SYSTEM32>\net.exe' LOCALGROUP "Administrators" supportaccount /ADD
  • '<SYSTEM32>\cmd.exe' /C net.exe user supportaccount QkwtUk7T
  • '<SYSTEM32>\mctadmin.exe'

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке