Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.DownLoader7.50702

Добавлен в вирусную базу Dr.Web: 2013-01-06

Описание добавлено:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winvsp' = '<SYSTEM32>\winvsp.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vspmem' = '<SYSTEM32>\vspmem.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wmcsp' = '<SYSTEM32>\wmcsp.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svcvsp' = '<SYSTEM32>\svcvsp.exe'
Creates the following services
  • [<HKLM>\System\CurrentControlSet\Services\winvsp] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\winvsp] 'ImagePath' = '"%PROGRAMDATA%\wmcsp.exe"'
Infects the following executable files
  • <Drive name for removable media>:\chromesetup.exe
  • %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\rcx20a7.tmp
  • %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\vcredist_x86.exe
  • %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\rcx1d52.tmp
  • %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\vcredist_x64.exe
  • %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\rcx17da.tmp
  • %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\vc_redist.x86.exe
  • %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\rcx1343.tmp
  • %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
  • %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\rcxeac.tmp
  • %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
  • %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\rcxa53.tmp
  • %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\vcredist_x64.exe
  • %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\rcx5ad.tmp
  • %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\vcredist_x64.exe
  • %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\rcx16a.tmp
  • %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe
  • %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\vcredist_x64.exe
  • C:\totalcmd\totalcmd64.exe
  • %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\rcx29c5.tmp
  • C:\totalcmd\rcx46ac.tmp
  • C:\totalcmd\tcusbrun.exe
  • C:\totalcmd\rcx43c9.tmp
  • C:\totalcmd\tcunin64.exe
  • C:\totalcmd\rcx4137.tmp
  • C:\totalcmd\tcmdx32.exe
  • C:\totalcmd\rcx3e53.tmp
  • C:\totalcmd\tcmadm64.exe
  • C:\totalcmd\noclose64.exe
  • %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\rcx377a.tmp
  • %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
  • %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\rcx32f2.tmp
  • %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
  • %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\rcx2e5c.tmp
  • %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\vc_redist.x64.exe
  • %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
  • %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\rcx253d.tmp
  • %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\rcxfcc1.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc06c.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxbdeb.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\ose.exe
  • C:\far2\rcxb95a.tmp
  • C:\far2\far.exe
  • <Drive name for removable media>:\rcx9812.tmp
  • <Drive name for removable media>:\dotnetfx45_full_setup.exe
  • <Drive name for removable media>:\rcx95ba.tmp
  • <Drive name for removable media>:\wrar520.exe
  • <Drive name for removable media>:\rcx92b2.tmp
  • <Drive name for removable media>:\calc.exe
  • <Drive name for removable media>:\rcx8f9a.tmp
  • <Drive name for removable media>:\notepad.exe
  • <Drive name for removable media>:\rcx8cd1.tmp
  • <Drive name for removable media>:\winmine.exe
  • <Drive name for removable media>:\rcx8aeb.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\rcxf839.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc557.tmp
  • %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\vcredist_x64.exe
  • %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\rcxf393.tmp
  • %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
  • %PROGRAMDATA%\oracle\java\javapath\rcxef1c.tmp
  • %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • %PROGRAMDATA%\oracle\java\javapath\rcxebe2.tmp
  • %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • %PROGRAMDATA%\oracle\java\javapath\rcxe992.tmp
  • %PROGRAMDATA%\oracle\java\javapath\java.exe
  • %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcxe45c.tmp
  • %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\setup.exe
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf21.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc81f.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dwtrig20.exe
  • %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
  • C:\totalcmd\rcx491d.tmp
Creates the following files on removable media
  • <Drive name for removable media>:\chromesetup.exe
  • <Drive name for removable media>:\rcx903f.tmp
  • <Drive name for removable media>:\rcx9050.tmp
  • <Drive name for removable media>:\calc.exe
  • <Drive name for removable media>:\rcx92b2.tmp
  • <Drive name for removable media>:\rcx92c3.tmp
  • <Drive name for removable media>:\rcx92d3.tmp
  • <Drive name for removable media>:\rcx92e4.tmp
  • <Drive name for removable media>:\rcx92f4.tmp
  • <Drive name for removable media>:\rcx9305.tmp
  • <Drive name for removable media>:\rcx9316.tmp
  • <Drive name for removable media>:\rcx8cf3.tmp
  • <Drive name for removable media>:\rcx9326.tmp
  • <Drive name for removable media>:\rcx9348.tmp
  • <Drive name for removable media>:\wrar520.exe
  • <Drive name for removable media>:\rcx95ba.tmp
  • <Drive name for removable media>:\rcx95da.tmp
  • <Drive name for removable media>:\rcx95ea.tmp
  • <Drive name for removable media>:\rcx95fb.tmp
  • <Drive name for removable media>:\rcx960c.tmp
  • <Drive name for removable media>:\dotnetfx45_full_setup.exe
  • <Drive name for removable media>:\rcx9812.tmp
  • <Drive name for removable media>:\rcx9823.tmp
  • <Drive name for removable media>:\rcx902d.tmp
  • <Drive name for removable media>:\rcx903e.tmp
  • <Drive name for removable media>:\rcx901d.tmp
  • <Drive name for removable media>:\rcx8ffc.tmp
  • <Drive name for removable media>:\rcx8ffb.tmp
  • <Drive name for removable media>:\rcx8afb.tmp
  • <Drive name for removable media>:\rcx8afc.tmp
  • <Drive name for removable media>:\rcx8b0d.tmp
  • <Drive name for removable media>:\rcx8b0e.tmp
  • <Drive name for removable media>:\rcx8b1e.tmp
  • <Drive name for removable media>:\rcx8b2f.tmp
  • <Drive name for removable media>:\rcx8b40.tmp
  • <Drive name for removable media>:\winmine.exe
  • <Drive name for removable media>:\rcx8cd1.tmp
  • <Drive name for removable media>:\rcx8ce1.tmp
  • <Drive name for removable media>:\rcx9833.tmp
  • <Drive name for removable media>:\rcx9337.tmp
  • <Drive name for removable media>:\rcx8ce2.tmp
  • <Drive name for removable media>:\rcx8d04.tmp
  • <Drive name for removable media>:\rcx8d15.tmp
  • <Drive name for removable media>:\rcx8d16.tmp
  • <Drive name for removable media>:\rcx8d27.tmp
  • <Drive name for removable media>:\rcx8d37.tmp
  • <Drive name for removable media>:\notepad.exe
  • <Drive name for removable media>:\rcx8f9a.tmp
  • <Drive name for removable media>:\rcx8fca.tmp
  • <Drive name for removable media>:\rcx8fda.tmp
  • <Drive name for removable media>:\rcx8feb.tmp
  • <Drive name for removable media>:\rcx8aeb.tmp
  • <Drive name for removable media>:\rcx8d03.tmp
  • <Drive name for removable media>:\rcx9853.tmp
Malicious functions
To complicate detection of its presence in the operating system,
forces the system hide from view:
  • hidden files
Modifies file system
Creates the following files
  • <SYSTEM32>\winvsp.exe
  • %PROGRAMDATA%\oracle\java\javapath\rcxec36.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec25.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec24.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec14.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec03.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxebf2.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxebe2.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec57.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec47.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxea39.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxea29.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxea18.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxea07.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxe9f7.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxe9f6.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxe9e5.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxea4b.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxe9b3.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec68.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxefe5.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxefd4.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxefc4.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxefb3.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxefa2.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxefa1.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxef91.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxef80.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxef6f.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxef5f.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxef4e.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxef3e.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxef1d.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxef1c.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec9b.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec8a.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec79.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxe9d5.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxea3a.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxe9c4.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxe9a3.tmp
  • %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\rcxf3a4.tmp
  • %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\rcxf393.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc579.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc568.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc557.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc0e2.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc0d1.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc0c1.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc0b0.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc09f.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc08f.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc07e.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc06d.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc06c.tmp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxbdeb.tmp
  • C:\far2\rcxba33.tmp
  • C:\far2\rcxba22.tmp
  • C:\far2\rcxba11.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc57a.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxec78.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc58b.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc59c.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc5ad.tmp
  • %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcxe48e.tmp
  • %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcxe47d.tmp
  • %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcxe46d.tmp
  • %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcxe45c.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdfd7.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdfb6.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdfa6.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf95.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf85.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf74.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf63.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf53.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf42.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf31.tmp
  • %PROGRAMDATA%\adobe\arm\s\10428\rcxdf21.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc81f.tmp
  • %PROGRAMDATA%\oracle\java\javapath\rcxe992.tmp
  • %HOMEPATH%\documents\wmcsp.exe
  • %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\rcxf3c4.tmp
  • C:\totalcmd\rcx43ea.tmp
  • C:\totalcmd\rcx43d9.tmp
  • C:\totalcmd\rcx43c9.tmp
  • C:\totalcmd\rcx419a.tmp
  • C:\totalcmd\rcx4189.tmp
  • C:\totalcmd\rcx4179.tmp
  • C:\totalcmd\rcx4158.tmp
  • C:\totalcmd\rcx4148.tmp
  • C:\totalcmd\rcx4137.tmp
  • C:\totalcmd\rcx3ec5.tmp
  • C:\totalcmd\rcx3eb4.tmp
  • C:\totalcmd\rcx3ea4.tmp
  • C:\totalcmd\rcx3e93.tmp
  • C:\totalcmd\rcx3e73.tmp
  • C:\totalcmd\rcx3e53.tmp
  • %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\rcx378b.tmp
  • %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\rcx378a.tmp
  • C:\totalcmd\rcx43fa.tmp
  • %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\rcx377a.tmp
  • C:\far2\rcxba10.tmp
  • %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\rcx3314.tmp
  • C:\users\all users\vspmem.exe
  • C:\users\all users\vspconsole.exe
  • C:\users\all users\svcvsp.exe
  • C:\users\all users\dvm.exe
  • C:\totalcmd\rcx49a1.tmp
  • C:\totalcmd\rcx4990.tmp
  • C:\totalcmd\rcx497f.tmp
  • C:\totalcmd\rcx496f.tmp
  • C:\totalcmd\rcx494f.tmp
  • C:\totalcmd\rcx493e.tmp
  • C:\totalcmd\rcx492d.tmp
  • C:\totalcmd\rcx491d.tmp
  • C:\totalcmd\rcx46f0.tmp
  • C:\totalcmd\rcx46ef.tmp
  • C:\totalcmd\rcx46df.tmp
  • C:\totalcmd\rcx46ce.tmp
  • C:\totalcmd\rcx46be.tmp
  • C:\totalcmd\rcx46ac.tmp
  • C:\totalcmd\rcx441b.tmp
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc58a.tmp
  • %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\rcx32f2.tmp
  • %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\rcx17da.tmp
  • %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\rcxebc.tmp
  • %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\rcxeac.tmp
  • %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\rcxa75.tmp
  • %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\rcxa54.tmp
  • %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\rcxa53.tmp
  • %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\rcx5de.tmp
  • %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\rcx5be.tmp
  • %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\rcx5ad.tmp
  • %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\rcx18b.tmp
  • %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\rcx17b.tmp
  • %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\rcx16a.tmp
  • %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\rcxfcf2.tmp
  • %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\rcxfcd1.tmp
  • %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\rcxfcc1.tmp
  • %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\rcxf85b.tmp
  • %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\rcxf84a.tmp
  • %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\rcx1343.tmp
  • %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\rcx3303.tmp
  • %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\rcxf839.tmp
  • %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\rcxecd.tmp
  • %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\rcx2e8c.tmp
  • %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\rcx2e7c.tmp
  • %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\rcx2e5c.tmp
  • %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\rcx29e6.tmp
  • %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\rcx29d5.tmp
  • %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\rcx29c5.tmp
  • %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\rcx255f.tmp
  • %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\rcx254e.tmp
  • %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\rcx253d.tmp
  • %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\rcx20c8.tmp
  • %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\rcx20b7.tmp
  • %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\rcx20a7.tmp
  • %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\rcx1e3e.tmp
  • %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\rcx1e2e.tmp
  • %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\rcx1d52.tmp
  • %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\rcx17fb.tmp
  • %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\rcx17ea.tmp
  • %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\rcx1364.tmp
  • %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\rcx1353.tmp
  • C:\far2\rcxba00.tmp
  • C:\far2\rcxb9ef.tmp
  • C:\far2\rcxb9ee.tmp
  • %WINDIR%\rcx6563.tmp
  • %ProgramFiles%\rcx661a.tmp
  • %ProgramFiles%\rcx660a.tmp
  • %ProgramFiles%\winvsp.exe
  • %WINDIR%\rcx65f9.tmp
  • %WINDIR%\rcx65e9.tmp
  • %WINDIR%\rcx65d8.tmp
  • %WINDIR%\vspmng.exe
  • %WINDIR%\rcx65c7.tmp
  • %WINDIR%\rcx65b7.tmp
  • %WINDIR%\rcx65b6.tmp
  • %WINDIR%\dvm.exe
  • %WINDIR%\rcx6595.tmp
  • %WINDIR%\rcx6585.tmp
  • %WINDIR%\rcx6584.tmp
  • %WINDIR%\vspconsole.exe
  • %WINDIR%\rcx6573.tmp
  • <SYSTEM32>\dvm.exe
  • %ProgramFiles%\rcx663b.tmp
  • %ProgramFiles%\rcx664b.tmp
  • %ProgramFiles%\wmcsp.exe
  • %ProgramFiles%\rcx666c.tmp
  • %PROGRAMDATA%\rcx6722.tmp
  • %PROGRAMDATA%\rcx6712.tmp
  • %PROGRAMDATA%\winvsp.exe
  • %ProgramFiles%\rcx6701.tmp
  • %ProgramFiles%\rcx66f1.tmp
  • %ProgramFiles%\vspmng.exe
  • %ProgramFiles%\rcx66e0.tmp
  • %ProgramFiles%\rcx66cf.tmp
  • %ProgramFiles%\dvm.exe
  • %ProgramFiles%\rcx66bf.tmp
  • %ProgramFiles%\rcx66ae.tmp
  • %ProgramFiles%\vspconsole.exe
  • %ProgramFiles%\rcx669d.tmp
  • %ProgramFiles%\rcx668d.tmp
  • %ProgramFiles%\svcvsp.exe
  • %ProgramFiles%\rcx666d.tmp
  • %PROGRAMDATA%\vspmem.exe
  • C:\users\all users\vspmng.exe
  • %PROGRAMDATA%\rcx6733.tmp
  • %WINDIR%\rcx6541.tmp
  • <SYSTEM32>\rcx63b3.tmp
  • <SYSTEM32>\vspconsole.exe
  • <SYSTEM32>\rcx6416.tmp
  • <SYSTEM32>\rcx6415.tmp
  • <SYSTEM32>\rcx6404.tmp
  • <SYSTEM32>\svcvsp.exe
  • <SYSTEM32>\rcx63f4.tmp
  • <SYSTEM32>\rcx63e3.tmp
  • <SYSTEM32>\wmcsp.exe
  • <SYSTEM32>\rcx6447.tmp
  • <SYSTEM32>\rcx63a3.tmp
  • <SYSTEM32>\rcx6382.tmp
  • <SYSTEM32>\rcx6381.tmp
  • <SYSTEM32>\vspmem.exe
  • <SYSTEM32>\rcx6371.tmp
  • <SYSTEM32>\rcx6331.tmp
  • <SYSTEM32>\rcx6330.tmp
  • %WINDIR%\svcvsp.exe
  • %WINDIR%\rcx6552.tmp
  • <SYSTEM32>\rcx6458.tmp
  • <SYSTEM32>\rcx6469.tmp
  • <SYSTEM32>\rcx6436.tmp
  • %WINDIR%\rcx6531.tmp
  • %WINDIR%\rcx6520.tmp
  • %WINDIR%\wmcsp.exe
  • %WINDIR%\rcx650f.tmp
  • %WINDIR%\rcx64ff.tmp
  • %WINDIR%\rcx64ee.tmp
  • %WINDIR%\vspmem.exe
  • %WINDIR%\rcx64de.tmp
  • %WINDIR%\rcx64dd.tmp
  • %WINDIR%\rcx64cc.tmp
  • %WINDIR%\winvsp.exe
  • <SYSTEM32>\rcx64ac.tmp
  • <SYSTEM32>\rcx649b.tmp
  • <SYSTEM32>\rcx648a.tmp
  • <SYSTEM32>\vspmng.exe
  • <SYSTEM32>\rcx647a.tmp
  • <SYSTEM32>\rcx6459.tmp
  • C:\totalcmd\rcx46ad.tmp
  • %PROGRAMDATA%\rcx6734.tmp
  • %PROGRAMDATA%\rcx6755.tmp
  • <SYSTEM32>\rcx7aa4.tmp
  • <SYSTEM32>\rcx7a84.tmp
  • <SYSTEM32>\rcx7a73.tmp
  • <SYSTEM32>\rcx7a63.tmp
  • <SYSTEM32>\rcx7a43.tmp
  • C:\rcx6a0a.tmp
  • C:\rcx69f9.tmp
  • C:\vspmng.exe
  • C:\rcx69e8.tmp
  • C:\rcx69d8.tmp
  • C:\dvm.exe
  • C:\rcx69c7.tmp
  • C:\rcx69b6.tmp
  • C:\vspconsole.exe
  • C:\rcx69a6.tmp
  • C:\rcx69a5.tmp
  • C:\svcvsp.exe
  • %PROGRAMDATA%\wmcsp.exe
  • C:\rcx6994.tmp
  • C:\rcx6984.tmp
  • %WINDIR%\rcx7af6.tmp
  • <SYSTEM32>\rcx7ab5.tmp
  • C:\far2\rcxb9de.tmp
  • C:\far2\rcxb9cd.tmp
  • C:\far2\rcxb9bc.tmp
  • C:\far2\rcxb9ac.tmp
  • C:\far2\rcxb99b.tmp
  • C:\far2\rcxb97b.tmp
  • C:\far2\rcxb96a.tmp
  • C:\far2\rcxb95a.tmp
  • <Current directory>\rcxb4f1.tmp
  • <Current directory>\rcxb4d1.tmp
  • <Current directory>\rcxb4c0.tmp
  • %WINDIR%\rcx7b59.tmp
  • %WINDIR%\rcx7b49.tmp
  • %WINDIR%\rcx7b28.tmp
  • %WINDIR%\rcx7b18.tmp
  • %WINDIR%\rcx7b07.tmp
  • %WINDIR%\rcx7ad6.tmp
  • %PROGRAMDATA%\rcx6745.tmp
  • <SYSTEM32>\rcx7ac6.tmp
  • %ProgramFiles%\vspmem.exe
  • %HOMEPATH%\documents\rcx683b.tmp
  • %HOMEPATH%\documents\vspmem.exe
  • %HOMEPATH%\documents\rcx682a.tmp
  • %HOMEPATH%\documents\rcx67fb.tmp
  • %HOMEPATH%\documents\winvsp.exe
  • %PROGRAMDATA%\rcx67ea.tmp
  • %PROGRAMDATA%\rcx67d9.tmp
  • %PROGRAMDATA%\vspmng.exe
  • %PROGRAMDATA%\rcx67b9.tmp
  • %PROGRAMDATA%\rcx67a8.tmp
  • %PROGRAMDATA%\dvm.exe
  • %PROGRAMDATA%\rcx67a7.tmp
  • %PROGRAMDATA%\rcx6797.tmp
  • %PROGRAMDATA%\vspconsole.exe
  • %PROGRAMDATA%\rcx6786.tmp
  • %PROGRAMDATA%\rcx6776.tmp
  • %PROGRAMDATA%\svcvsp.exe
  • C:\rcx6953.tmp
  • C:\wmcsp.exe
  • C:\rcx6963.tmp
  • %HOMEPATH%\documents\rcx687d.tmp
  • %HOMEPATH%\documents\rcx684c.tmp
  • C:\vspmem.exe
  • C:\rcx6942.tmp
  • C:\rcx6931.tmp
  • C:\winvsp.exe
  • %HOMEPATH%\documents\rcx6921.tmp
  • %HOMEPATH%\documents\rcx6910.tmp
  • %HOMEPATH%\documents\vspmng.exe
  • %HOMEPATH%\documents\rcx6900.tmp
  • %HOMEPATH%\documents\rcx68df.tmp
  • %HOMEPATH%\documents\dvm.exe
  • %HOMEPATH%\documents\rcx68cf.tmp
  • %HOMEPATH%\documents\rcx68be.tmp
  • %HOMEPATH%\documents\vspconsole.exe
  • %HOMEPATH%\documents\rcx68bd.tmp
  • %HOMEPATH%\documents\rcx689d.tmp
  • %HOMEPATH%\documents\svcvsp.exe
  • %HOMEPATH%\documents\rcx686c.tmp
  • C:\users\all users\winvsp.exe
Sets the 'hidden' attribute to the following files
  • <SYSTEM32>\winvsp.exe
  • %PROGRAMDATA%\svcvsp.exe
  • %PROGRAMDATA%\vspconsole.exe
  • %PROGRAMDATA%\dvm.exe
  • %PROGRAMDATA%\vspmng.exe
  • %HOMEPATH%\documents\winvsp.exe
  • %HOMEPATH%\documents\vspmem.exe
  • %HOMEPATH%\documents\wmcsp.exe
  • %WINDIR%\svcvsp.exe
  • %HOMEPATH%\documents\svcvsp.exe
  • %HOMEPATH%\documents\dvm.exe
  • %HOMEPATH%\documents\vspmng.exe
  • C:\winvsp.exe
  • C:\vspmem.exe
  • C:\wmcsp.exe
  • C:\svcvsp.exe
  • C:\vspconsole.exe
  • %PROGRAMDATA%\vspmem.exe
  • %PROGRAMDATA%\wmcsp.exe
  • %PROGRAMDATA%\winvsp.exe
  • %ProgramFiles%\vspmng.exe
  • %ProgramFiles%\dvm.exe
  • <SYSTEM32>\wmcsp.exe
  • <SYSTEM32>\svcvsp.exe
  • <SYSTEM32>\vspconsole.exe
  • <SYSTEM32>\dvm.exe
  • <SYSTEM32>\vspmng.exe
  • %WINDIR%\winvsp.exe
  • %WINDIR%\vspmem.exe
  • C:\dvm.exe
  • %HOMEPATH%\documents\vspconsole.exe
  • %WINDIR%\wmcsp.exe
  • %WINDIR%\dvm.exe
  • %WINDIR%\vspmng.exe
  • %ProgramFiles%\winvsp.exe
  • %ProgramFiles%\vspmem.exe
  • %ProgramFiles%\wmcsp.exe
  • %ProgramFiles%\svcvsp.exe
  • %ProgramFiles%\vspconsole.exe
  • <SYSTEM32>\vspmem.exe
  • %WINDIR%\vspconsole.exe
  • C:\vspmng.exe
Moves the following files
  • from <SYSTEM32>\rcx6330.tmp to <SYSTEM32>\winvsp.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxea3a.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxea4b.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxebf2.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec03.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec14.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec24.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec25.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec36.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec47.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec57.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec68.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec78.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec79.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec8a.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxec9b.tmp to %PROGRAMDATA%\oracle\java\javapath\javaw.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxef1d.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxef3e.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxef4e.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxef5f.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxef6f.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxef80.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxef91.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxefa1.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxefa2.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxefb3.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxefc4.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxefd4.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxefe5.tmp to %PROGRAMDATA%\oracle\java\javapath\javaws.exe
  • from %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\rcxf3a4.tmp to %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxea39.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\rcxf3c4.tmp to %PROGRAMDATA%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxea29.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxea07.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc0d1.tmp to C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • from C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc0e2.tmp to C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • from C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc568.tmp to C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • from C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc579.tmp to C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • from C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc57a.tmp to C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • from C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc58a.tmp to C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • from C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc58b.tmp to C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • from C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc59c.tmp to C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • from C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\rcxc5ad.tmp to C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdf31.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdf42.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdf53.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdf63.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdf74.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdf85.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdf95.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdfa6.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdfb6.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\arm\s\10428\rcxdfd7.tmp to %PROGRAMDATA%\adobe\arm\s\10428\adobearmhelper.exe
  • from %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcxe46d.tmp to %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\setup.exe
  • from %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcxe47d.tmp to %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\setup.exe
  • from %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\rcxe48e.tmp to %PROGRAMDATA%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\setup.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxe9a3.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxe9b3.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxe9c4.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxe9d5.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxe9e5.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxe9f6.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxe9f7.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\oracle\java\javapath\rcxea18.tmp to %PROGRAMDATA%\oracle\java\javapath\java.exe
  • from %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\rcxf84a.tmp to %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\rcxf85b.tmp to %PROGRAMDATA%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\rcxfcd1.tmp to %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
  • from C:\totalcmd\rcx4189.tmp to C:\totalcmd\tcmdx32.exe
  • from C:\totalcmd\rcx419a.tmp to C:\totalcmd\tcmdx32.exe
  • from C:\totalcmd\rcx43d9.tmp to C:\totalcmd\tcunin64.exe
  • from C:\totalcmd\rcx43ea.tmp to C:\totalcmd\tcunin64.exe
  • from C:\totalcmd\rcx43fa.tmp to C:\totalcmd\tcunin64.exe
  • from C:\totalcmd\rcx441b.tmp to C:\totalcmd\tcunin64.exe
  • from C:\totalcmd\rcx46ad.tmp to C:\totalcmd\tcusbrun.exe
  • from C:\totalcmd\rcx46be.tmp to C:\totalcmd\tcusbrun.exe
  • from C:\totalcmd\rcx46ce.tmp to C:\totalcmd\tcusbrun.exe
  • from C:\totalcmd\rcx46df.tmp to C:\totalcmd\tcusbrun.exe
  • from C:\totalcmd\rcx46ef.tmp to C:\totalcmd\tcusbrun.exe
  • from C:\totalcmd\rcx46f0.tmp to C:\totalcmd\tcusbrun.exe
  • from C:\totalcmd\rcx492d.tmp to C:\totalcmd\totalcmd64.exe
  • from %APPDATA%\icqm\icq.exe to %APPDATA%\icqm\icq
  • from C:\totalcmd\rcx493e.tmp to C:\totalcmd\totalcmd64.exe
  • from C:\totalcmd\rcx496f.tmp to C:\totalcmd\totalcmd64.exe
  • from C:\totalcmd\rcx497f.tmp to C:\totalcmd\totalcmd64.exe
  • from C:\totalcmd\rcx4990.tmp to C:\totalcmd\totalcmd64.exe
  • from C:\totalcmd\rcx49a1.tmp to C:\totalcmd\totalcmd64.exe
  • from C:\users\all users\dvm.exe to C:\users\all users\dvm
  • from C:\users\all users\svcvsp.exe to C:\users\all users\svcvsp
  • from C:\users\all users\vspconsole.exe to C:\users\all users\vspconsole
  • from C:\users\all users\vspmem.exe to C:\users\all users\vspmem
  • from C:\users\all users\vspmng.exe to C:\users\all users\vspmng
  • from C:\users\all users\winvsp.exe to C:\users\all users\winvsp
  • from %TEMP%\mirc741.exe to %TEMP%\mirc741
  • from %TEMP%\ose00000.exe to %TEMP%\ose00000
  • from %TEMP%\ose00001.exe to %TEMP%\ose00001
  • from C:\totalcmd\rcx4158.tmp to C:\totalcmd\tcmdx32.exe
  • from C:\totalcmd\rcx4179.tmp to C:\totalcmd\tcmdx32.exe
  • from C:\totalcmd\rcx4148.tmp to C:\totalcmd\tcmdx32.exe
  • from C:\totalcmd\rcx3ec5.tmp to C:\totalcmd\tcmadm64.exe
  • from C:\totalcmd\rcx3eb4.tmp to C:\totalcmd\tcmadm64.exe
  • from %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\rcx17b.tmp to %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\rcx18b.tmp to %PROGRAMDATA%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\rcx5be.tmp to %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\rcx5de.tmp to %PROGRAMDATA%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\rcxa54.tmp to %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\rcxa75.tmp to %PROGRAMDATA%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\rcxebc.tmp to %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\rcxecd.tmp to %PROGRAMDATA%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\rcx1353.tmp to %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\rcx1364.tmp to %PROGRAMDATA%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\rcx17ea.tmp to %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\vc_redist.x86.exe
  • from %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\rcx17fb.tmp to %PROGRAMDATA%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\vc_redist.x86.exe
  • from %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\rcx1e2e.tmp to %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\vcredist_x64.exe
  • from C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc0c1.tmp to C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • from %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\rcx20b7.tmp to %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\rcx1e3e.tmp to %PROGRAMDATA%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\rcx254e.tmp to %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\rcx255f.tmp to %PROGRAMDATA%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\rcx29d5.tmp to %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\rcx29e6.tmp to %PROGRAMDATA%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\vcredist_x64.exe
  • from %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\rcx2e7c.tmp to %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\vc_redist.x64.exe
  • from %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\rcx2e8c.tmp to %PROGRAMDATA%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\vc_redist.x64.exe
  • from %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\rcx3303.tmp to %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\rcx3314.tmp to %PROGRAMDATA%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\rcx378a.tmp to %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\rcx378b.tmp to %PROGRAMDATA%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
  • from C:\totalcmd\rcx3e73.tmp to C:\totalcmd\tcmadm64.exe
  • from C:\totalcmd\rcx3e93.tmp to C:\totalcmd\tcmadm64.exe
  • from C:\totalcmd\rcx3ea4.tmp to C:\totalcmd\tcmadm64.exe
  • from %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\rcxfcf2.tmp to %PROGRAMDATA%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
  • from %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\rcx20c8.tmp to %PROGRAMDATA%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\vcredist_x86.exe
  • from C:\totalcmd\rcx494f.tmp to C:\totalcmd\totalcmd64.exe
  • from C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc0b0.tmp to C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • from C:\far2\rcxb99b.tmp to C:\far2\far.exe
  • from %WINDIR%\rcx6585.tmp to %WINDIR%\vspconsole.exe
  • from %WINDIR%\rcx6595.tmp to %WINDIR%\vspconsole.exe
  • from %WINDIR%\rcx65b6.tmp to %WINDIR%\dvm.exe
  • from %WINDIR%\rcx65b7.tmp to %WINDIR%\dvm.exe
  • from %WINDIR%\rcx65c7.tmp to %WINDIR%\dvm.exe
  • from %WINDIR%\rcx65d8.tmp to %WINDIR%\vspmng.exe
  • from %WINDIR%\rcx65e9.tmp to %WINDIR%\vspmng.exe
  • from %WINDIR%\rcx65f9.tmp to %WINDIR%\vspmng.exe
  • from %ProgramFiles%\rcx660a.tmp to %ProgramFiles%\winvsp.exe
  • from %ProgramFiles%\rcx661a.tmp to %ProgramFiles%\winvsp.exe
  • from %ProgramFiles%\rcx663b.tmp to %ProgramFiles%\vspmem.exe
  • from %ProgramFiles%\rcx664b.tmp to %ProgramFiles%\vspmem.exe
  • from %ProgramFiles%\rcx666c.tmp to %ProgramFiles%\wmcsp.exe
  • from %ProgramFiles%\rcx666d.tmp to %ProgramFiles%\wmcsp.exe
  • from %ProgramFiles%\rcx668d.tmp to %ProgramFiles%\svcvsp.exe
  • from %ProgramFiles%\rcx669d.tmp to %ProgramFiles%\svcvsp.exe
  • from %ProgramFiles%\rcx66ae.tmp to %ProgramFiles%\vspconsole.exe
  • from %ProgramFiles%\rcx66bf.tmp to %ProgramFiles%\vspconsole.exe
  • from %ProgramFiles%\rcx66cf.tmp to %ProgramFiles%\dvm.exe
  • from %ProgramFiles%\rcx66e0.tmp to %ProgramFiles%\dvm.exe
  • from %ProgramFiles%\rcx66f1.tmp to %ProgramFiles%\vspmng.exe
  • from %ProgramFiles%\rcx6701.tmp to %ProgramFiles%\vspmng.exe
  • from %PROGRAMDATA%\rcx6712.tmp to %PROGRAMDATA%\winvsp.exe
  • from %PROGRAMDATA%\rcx6722.tmp to %PROGRAMDATA%\winvsp.exe
  • from %PROGRAMDATA%\rcx6733.tmp to %PROGRAMDATA%\vspmem.exe
  • from %PROGRAMDATA%\rcx6734.tmp to %PROGRAMDATA%\vspmem.exe
  • from %PROGRAMDATA%\rcx6745.tmp to %PROGRAMDATA%\wmcsp.exe
  • from %PROGRAMDATA%\rcx6755.tmp to %PROGRAMDATA%\wmcsp.exe
  • from %PROGRAMDATA%\rcx6776.tmp to %PROGRAMDATA%\svcvsp.exe
  • from %WINDIR%\rcx6584.tmp to %WINDIR%\vspconsole.exe
  • from %PROGRAMDATA%\rcx6786.tmp to %PROGRAMDATA%\svcvsp.exe
  • from %WINDIR%\rcx6573.tmp to %WINDIR%\svcvsp.exe
  • from %WINDIR%\rcx6552.tmp to %WINDIR%\svcvsp.exe
  • from <SYSTEM32>\rcx6331.tmp to <SYSTEM32>\winvsp.exe
  • from <SYSTEM32>\rcx6371.tmp to <SYSTEM32>\winvsp.exe
  • from <SYSTEM32>\rcx6381.tmp to <SYSTEM32>\vspmem.exe
  • from <SYSTEM32>\rcx6382.tmp to <SYSTEM32>\vspmem.exe
  • from <SYSTEM32>\rcx63a3.tmp to <SYSTEM32>\vspmem.exe
  • from <SYSTEM32>\rcx63b3.tmp to <SYSTEM32>\wmcsp.exe
  • from <SYSTEM32>\rcx63e3.tmp to <SYSTEM32>\wmcsp.exe
  • from <SYSTEM32>\rcx63f4.tmp to <SYSTEM32>\wmcsp.exe
  • from <SYSTEM32>\rcx6404.tmp to <SYSTEM32>\svcvsp.exe
  • from <SYSTEM32>\rcx6415.tmp to <SYSTEM32>\svcvsp.exe
  • from <SYSTEM32>\rcx6416.tmp to <SYSTEM32>\svcvsp.exe
  • from <SYSTEM32>\rcx6436.tmp to <SYSTEM32>\vspconsole.exe
  • from <SYSTEM32>\rcx6447.tmp to <SYSTEM32>\vspconsole.exe
  • from <SYSTEM32>\rcx6458.tmp to <SYSTEM32>\vspconsole.exe
  • from <SYSTEM32>\rcx6459.tmp to <SYSTEM32>\dvm.exe
  • from <SYSTEM32>\rcx6469.tmp to <SYSTEM32>\dvm.exe
  • from <SYSTEM32>\rcx647a.tmp to <SYSTEM32>\dvm.exe
  • from <SYSTEM32>\rcx648a.tmp to <SYSTEM32>\vspmng.exe
  • from <SYSTEM32>\rcx649b.tmp to <SYSTEM32>\vspmng.exe
  • from <SYSTEM32>\rcx64ac.tmp to <SYSTEM32>\vspmng.exe
  • from %WINDIR%\rcx64cc.tmp to %WINDIR%\winvsp.exe
  • from %WINDIR%\rcx64dd.tmp to %WINDIR%\winvsp.exe
  • from %WINDIR%\rcx64de.tmp to %WINDIR%\winvsp.exe
  • from %WINDIR%\rcx64ee.tmp to %WINDIR%\vspmem.exe
  • from %WINDIR%\rcx64ff.tmp to %WINDIR%\vspmem.exe
  • from %WINDIR%\rcx650f.tmp to %WINDIR%\vspmem.exe
  • from %WINDIR%\rcx6520.tmp to %WINDIR%\wmcsp.exe
  • from %WINDIR%\rcx6531.tmp to %WINDIR%\wmcsp.exe
  • from %WINDIR%\rcx6541.tmp to %WINDIR%\wmcsp.exe
  • from %WINDIR%\rcx6563.tmp to %WINDIR%\svcvsp.exe
  • from %PROGRAMDATA%\rcx6797.tmp to %PROGRAMDATA%\vspconsole.exe
  • from %PROGRAMDATA%\rcx67a7.tmp to %PROGRAMDATA%\vspconsole.exe
  • from %PROGRAMDATA%\rcx67a8.tmp to %PROGRAMDATA%\dvm.exe
  • from <SYSTEM32>\rcx7aa4.tmp to <SYSTEM32>\vspconsole.exe
  • from <SYSTEM32>\rcx7ab5.tmp to <SYSTEM32>\dvm.exe
  • from <SYSTEM32>\rcx7ac6.tmp to <SYSTEM32>\vspmng.exe
  • from %WINDIR%\rcx7ad6.tmp to %WINDIR%\winvsp.exe
  • from %WINDIR%\rcx7af6.tmp to %WINDIR%\vspmem.exe
  • from %WINDIR%\rcx7b07.tmp to %WINDIR%\wmcsp.exe
  • from %WINDIR%\rcx7b18.tmp to %WINDIR%\svcvsp.exe
  • from %WINDIR%\rcx7b28.tmp to %WINDIR%\vspconsole.exe
  • from %WINDIR%\rcx7b49.tmp to %WINDIR%\dvm.exe
  • from %WINDIR%\rcx7b59.tmp to %WINDIR%\vspmng.exe
  • from <Current directory>\rcxb4d1.tmp to <Full path to file>
  • from <Current directory>\rcxb4f1.tmp to <Full path to file>
  • from C:\far2\rcxb96a.tmp to C:\far2\far.exe
  • from C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc08f.tmp to C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • from C:\far2\rcxb97b.tmp to C:\far2\far.exe
  • from C:\far2\rcxb9ac.tmp to C:\far2\far.exe
  • from C:\far2\rcxb9bc.tmp to C:\far2\far.exe
  • from C:\far2\rcxb9cd.tmp to C:\far2\far.exe
  • from C:\far2\rcxb9de.tmp to C:\far2\far.exe
  • from C:\far2\rcxb9ee.tmp to C:\far2\far.exe
  • from C:\far2\rcxb9ef.tmp to C:\far2\far.exe
  • from C:\far2\rcxba00.tmp to C:\far2\far.exe
  • from C:\far2\rcxba10.tmp to C:\far2\far.exe
  • from C:\far2\rcxba11.tmp to C:\far2\far.exe
  • from C:\far2\rcxba22.tmp to C:\far2\far.exe
  • from C:\far2\rcxba33.tmp to C:\far2\far.exe
  • from C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc06d.tmp to C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • from C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc07e.tmp to C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • from <SYSTEM32>\rcx7a73.tmp to <SYSTEM32>\wmcsp.exe
  • from <SYSTEM32>\rcx7a84.tmp to <SYSTEM32>\svcvsp.exe
  • from <SYSTEM32>\rcx7a63.tmp to <SYSTEM32>\vspmem.exe
  • from <SYSTEM32>\rcx7a43.tmp to <SYSTEM32>\winvsp.exe
  • from C:\rcx6a0a.tmp to C:\vspmng.exe
  • from %PROGRAMDATA%\rcx67d9.tmp to %PROGRAMDATA%\vspmng.exe
  • from %PROGRAMDATA%\rcx67ea.tmp to %PROGRAMDATA%\vspmng.exe
  • from %HOMEPATH%\documents\rcx67fb.tmp to %HOMEPATH%\documents\winvsp.exe
  • from %HOMEPATH%\documents\rcx682a.tmp to %HOMEPATH%\documents\winvsp.exe
  • from %HOMEPATH%\documents\rcx683b.tmp to %HOMEPATH%\documents\vspmem.exe
  • from %HOMEPATH%\documents\rcx684c.tmp to %HOMEPATH%\documents\vspmem.exe
  • from %HOMEPATH%\documents\rcx686c.tmp to %HOMEPATH%\documents\wmcsp.exe
  • from %HOMEPATH%\documents\rcx687d.tmp to %HOMEPATH%\documents\wmcsp.exe
  • from %HOMEPATH%\documents\rcx689d.tmp to %HOMEPATH%\documents\svcvsp.exe
  • from %HOMEPATH%\documents\rcx68bd.tmp to %HOMEPATH%\documents\svcvsp.exe
  • from %HOMEPATH%\documents\rcx68be.tmp to %HOMEPATH%\documents\vspconsole.exe
  • from %HOMEPATH%\documents\rcx68cf.tmp to %HOMEPATH%\documents\vspconsole.exe
  • from %HOMEPATH%\documents\rcx68df.tmp to %HOMEPATH%\documents\dvm.exe
  • from C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\rcxc09f.tmp to C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • from %HOMEPATH%\documents\rcx6910.tmp to %HOMEPATH%\documents\vspmng.exe
  • from %HOMEPATH%\documents\rcx6900.tmp to %HOMEPATH%\documents\dvm.exe
  • from C:\rcx6931.tmp to C:\winvsp.exe
  • from C:\rcx6942.tmp to C:\winvsp.exe
  • from C:\rcx6953.tmp to C:\vspmem.exe
  • from C:\rcx6963.tmp to C:\vspmem.exe
  • from C:\rcx6984.tmp to C:\wmcsp.exe
  • from C:\rcx6994.tmp to C:\wmcsp.exe
  • from C:\rcx69a5.tmp to C:\svcvsp.exe
  • from C:\rcx69a6.tmp to C:\svcvsp.exe
  • from C:\rcx69b6.tmp to C:\vspconsole.exe
  • from C:\rcx69c7.tmp to C:\vspconsole.exe
  • from C:\rcx69d8.tmp to C:\dvm.exe
  • from C:\rcx69e8.tmp to C:\dvm.exe
  • from C:\rcx69f9.tmp to C:\vspmng.exe
  • from %PROGRAMDATA%\rcx67b9.tmp to %PROGRAMDATA%\dvm.exe
  • from %HOMEPATH%\documents\rcx6921.tmp to %HOMEPATH%\documents\vspmng.exe
  • from %APPDATA%\icqm\icqsetup.exe to %APPDATA%\icqm\icqsetup
Substitutes the following executable files
  • <Drive name for removable media>:\chromesetup.exe
  • %PROGRAMDATA%\Package Cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\vcredist_x64.exe
  • %PROGRAMDATA%\Package Cache\{51adbf11-493f-431c-a862-967a0fae2944}\vcredist_x64.exe
  • %PROGRAMDATA%\Package Cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
  • %PROGRAMDATA%\Package Cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
  • %PROGRAMDATA%\Package Cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\VC_redist.x86.exe
  • %PROGRAMDATA%\Package Cache\{a2199617-3609-410f-a8e8-e8806c73545b}\vcredist_x64.exe
  • %PROGRAMDATA%\Package Cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\vcredist_x86.exe
  • %PROGRAMDATA%\Package Cache\{dde2682b-961a-41ea-8d44-6005991b7947}\vcredist_x64.exe
  • C:\totalcmd\TcUsbRun.exe
  • %PROGRAMDATA%\Package Cache\{e46eca4f-393b-40df-9f49-076faf788d83}\VC_redist.x64.exe
  • %PROGRAMDATA%\Package Cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
  • %PROGRAMDATA%\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
  • C:\totalcmd\NOCLOSE64.EXE
  • C:\totalcmd\TCMADM64.EXE
  • C:\totalcmd\TCMDX32.EXE
  • C:\totalcmd\TCUNIN64.EXE
  • %PROGRAMDATA%\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
  • %PROGRAMDATA%\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe
  • %PROGRAMDATA%\Package Cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
  • C:\MSOCache\All Users\{90140000-0011-0000-1000-0000000FF1CE}-C\ose.exe
  • <Drive name for removable media>:\winmine.exe
  • <Drive name for removable media>:\notepad.exe
  • <Drive name for removable media>:\calc.exe
  • <Drive name for removable media>:\wrar520.exe
  • <Drive name for removable media>:\dotnetfx45_full_setup.exe
  • <Full path to file>
  • C:\Far2\Far.exe
  • C:\MSOCache\All Users\{90140000-0011-0000-1000-0000000FF1CE}-C\setup.exe
  • %PROGRAMDATA%\Package Cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
  • C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\DW20.EXE
  • C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\dwtrig20.exe
  • %PROGRAMDATA%\Adobe\ARM\S\10428\AdobeARMHelper.exe
  • %PROGRAMDATA%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exe
  • %PROGRAMDATA%\Oracle\Java\javapath\java.exe
  • %PROGRAMDATA%\Oracle\Java\javapath\javaw.exe
  • %PROGRAMDATA%\Oracle\Java\javapath\javaws.exe
  • %PROGRAMDATA%\Package Cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\vcredist_x64.exe
  • C:\totalcmd\TOTALCMD64.EXE
Moves itself
  • from <Full path to file> to <PATH_SAMPLE>
Network activity
Connects to
  • '<LOCALNET>.89.1':445
  • '<LOCALNET>.89.1':139
Miscellaneous
Searches for the following windows
  • ClassName: 'MouseZ' WindowName: 'Magellan MSWHEEL'
Creates and executes the following
  • '%PROGRAMDATA%\wmcsp.exe'
  • '%PROGRAMDATA%\wmcsp.exe' rg
  • '%PROGRAMDATA%\wmcsp.exe' ws 1172 winvsp
  • 'C:\dvm.exe' wm 1148

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке