from <LS_APPDATA>\Microsoft\Windows\RCXB.tmp to <LS_APPDATA>\Microsoft\Windows\rsvp.exe
from <LS_APPDATA>\Microsoft\RCXA.tmp to <LS_APPDATA>\Microsoft\clipsrv.exe
from %WINDIR%\RCX9.tmp to %WINDIR%\spoolsv.exe
from <DRIVERS>\RCXC.tmp to <DRIVERS>\mstsc.exe
from <LS_APPDATA>\Microsoft\RCXF.tmp to <LS_APPDATA>\Microsoft\winlogon.exe
from %WINDIR%\RCXE.tmp to %WINDIR%\esentutl.exe
from %WINDIR%\RCXD.tmp to %WINDIR%\logman.exe
from %WINDIR%\RCX8.tmp to %WINDIR%\esentutl.exe
from %APPDATA%\Microsoft\RCX3.tmp to %APPDATA%\Microsoft\rsvp.exe
from %APPDATA%\Microsoft\RCX2.tmp to %APPDATA%\Microsoft\sessmgr.exe
from <LS_APPDATA>\Microsoft\Windows\RCX1.tmp to <LS_APPDATA>\Microsoft\Windows\logman.exe
from <LS_APPDATA>\Microsoft\Windows\RCX4.tmp to <LS_APPDATA>\Microsoft\Windows\rsvp.exe
from %APPDATA%\RCX7.tmp to %APPDATA%\sessmgr.exe
from <LS_APPDATA>\RCX6.tmp to <LS_APPDATA>\sessmgr.exe
from <DRIVERS>\RCX5.tmp to <DRIVERS>\mstsc.exe
Network activity:
Connects to:
'www.ms###csi.com':80
TCP:
HTTP GET requests:
www.ms###csi.com/ncsi.txt
UDP:
DNS ASK www.ms###csi.com
DNS ASK dn#.##ftncsi.com
DNS ASK ly###s-db.org
Miscellaneous:
Searches for the following windows:
ClassName: 'Indicator' WindowName: ''
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more