Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.DownLoader36.30192

Added to the Dr.Web virus database: 2020-12-23

Virus description added:

Technical Information

Malicious functions
Injects code into
the following user processes:
  • jjsploit v5.exe
Modifies file system
Creates the following files
  • %TEMP%\nss29cf.tmp\system.dll
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resizehorizontal.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\smallicons.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\securityicons_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\securityicons.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\searchprev.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\searchnext.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\smallicons_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resourcestimegraphicon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resourceplainicon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resourcejsicon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resourcedocumenticonsmall.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resourcedocumenticon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resourcecssicon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resizevertical_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resourceplainiconsmall.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resizevertical.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\toolbarresizervertical.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\touchcursor.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\layers\layers_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\js_app.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\js_app.html
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\javascript_metadata\javascript_metadata_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\integration_test_runner.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\integration_test_runner.html
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\inspector.html
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\inspectorbackendcommands.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\inspector.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\inline_editor\inline_editor_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\whatsnew.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\treeoutlinetriangles_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\treeoutlinetriangles.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\touchcursor_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\speech.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resizehorizontal_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resizediagonal_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\resizediagonal.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\breakpointconditional.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\chromedisabledselect_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\chromedisabledselect.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\checker.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\breakpoint_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\breakpointconditional_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\chromeleft.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\chromemiddle.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\chromeright.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\accelerometer-top.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\accelerometer-right.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\accelerometer-left.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\accelerometer-front.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\accelerometer-bottom.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\audits_logo.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\chromeselect.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\profilesmallicon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\errorwave.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\radiodot.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\mediumicons_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\profileicon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\profilegroupicon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\popoverarrows.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\nodeicon.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\navigationcontrols_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\navigationcontrols.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\mediumicons.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\chromeselect_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\largeicons_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\largeicons.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\ic_warning_black_18dp.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\ic_info_black_18dp.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\errorwave_2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\accelerometer-back.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\images\breakpoint.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\layers_test_runner\layers_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\perf_ui\perf_ui_module.js
  • %APPDATA%\jjsploitv5\code cache\js\index
  • %TEMP%\8e42f5a3-e006-4ef6-8a02-8ff0e376abda.tmp.node
  • %APPDATA%\jjv5conf.json
  • %HOMEPATH%\desktop\jjsploit v5.lnk
  • %TEMP%\nss29cf.tmp\winshell.dll
  • %APPDATA%\microsoft\windows\start menu\programs\jjsploit v5.lnk
  • %LOCALAPPDATA%\programs\jjsploitv5\jjsploit v5.exe
  • %LOCALAPPDATA%\programs\jjsploitv5\uninstall jjsploit v5.exe
  • %LOCALAPPDATA%\programs\jjsploitv5\vkicd_mock_icd.dll
  • %LOCALAPPDATA%\programs\jjsploitv5\swiftshader\libglesv2.dll
  • %LOCALAPPDATA%\programs\jjsploitv5\swiftshader\libegl.dll
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\exploit-main.dll
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\elevate.exe
  • %LOCALAPPDATA%\programs\jjsploitv5\libglesv2.dll
  • %LOCALAPPDATA%\jjsploitv5-updater\installer.exe
  • %LOCALAPPDATA%\programs\jjsploitv5\libegl.dll
  • %APPDATA%\jjsploitv5\code cache\js\index-dir\temp-index
  • %APPDATA%\jjsploitv5\manifest-000002
  • %APPDATA%\jjsploitv5\cache\data_1
  • %APPDATA%\jjsploitv5\cache\data_0
  • %APPDATA%\jjsploitv5\cache\index
  • %APPDATA%\jjsploitv5\cookies
  • %APPDATA%\jjsploitv5\cookies-journal
  • %APPDATA%\jjsploitv5\log
  • %APPDATA%\jjsploitv5\000001.dbtmp
  • %APPDATA%\jjsploitv5\manifest-000001
  • %APPDATA%\jjsploitv5\gpucache\data_3
  • %APPDATA%\jjsploitv5\gpucache\data_2
  • %APPDATA%\jjsploitv5\gpucache\data_1
  • %APPDATA%\jjsploitv5\gpucache\data_0
  • %APPDATA%\jjsploitv5\gpucache\index
  • %APPDATA%\jjsploitv5\5f345865-d2a0-4a0c-96b7-dc708b16b18f.tmp
  • %APPDATA%\jjsploitv5\000002.dbtmp
  • %LOCALAPPDATA%\programs\jjsploitv5\ffmpeg.dll
  • %LOCALAPPDATA%\programs\jjsploitv5\v8_context_snapshot.bin
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-vertical-default-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\product_registry_impl\product_registry_impl_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\sdk_test_runner\sdk_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\resources\resources_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\quick_open\quick_open_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\protocol_monitor\protocol_monitor_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\profiler\profiler_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\settings\settings_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\security\security_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\security_test_runner\security_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\performance_monitor\performance_monitor_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\object_ui\object_ui_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\node_app.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\node_app.html
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\network_test_runner\network_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\performance_test_runner\performance_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\shell.js
  • %LOCALAPPDATA%\programs\jjsploitv5\snapshot_blob.bin
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\layer_viewer\layer_viewer_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\search\search_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\workspace_diff\workspace_diff_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\worker_app.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\worker_app.html
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\toolbox.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\toolbox.html
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\timeline_model\timeline_model_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\timeline\timeline_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\text_editor\text_editor_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\tests.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\supportedcssproperties.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\source_frame\source_frame_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\sources_test_runner\sources_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\sources\sources_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\snippets\snippets_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\network\network_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\help\help_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\heap_snapshot_worker\heap_snapshot_worker_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\heap_snapshot_worker.js
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\nl.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ru.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ro.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\pt-pt.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\pt-br.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\pl.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\sr.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\sl.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\kn.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\mr.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ml.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\lv.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\lt.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ko.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ms.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\nb.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\sw.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ja.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\.htaccess
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\electron.asar
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\app.asar
  • %LOCALAPPDATA%\programs\jjsploitv5\resources.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\natives_blob.bin
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\sv.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\accessibility\accessibility_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\zh-tw.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\uk.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\tr.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\th.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\te.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ta.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\zh-cn.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\vi.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\it.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\id.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\bn.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ar.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\am.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\licenses.chromium.html
  • %LOCALAPPDATA%\programs\jjsploitv5\license.electron.txt
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\ca.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\icudtl.dat
  • %LOCALAPPDATA%\programs\jjsploitv5\chrome_100_percent.pak
  • %TEMP%\nss29cf.tmp\nsis7z.dll
  • %TEMP%\nss29cf.tmp\app-32.7z
  • %TEMP%\nss29cf.tmp\nsprocess.dll
  • %TEMP%\nss29cf.tmp\spiderbanner.dll
  • %TEMP%\nss29cf.tmp\stdutils.dll
  • %LOCALAPPDATA%\programs\jjsploitv5\chrome_200_percent.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\cs.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\da.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\bg.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\de.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\hr.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\fa.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\hi.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\he.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\gu.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\fr.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\fil.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\fi.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\et.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\hu.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\es.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\es-419.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\en-us.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\en-gb.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\el.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\accessibility\ariaproperties.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\accessibility_test_runner\accessibility_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\locales\sk.pak
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\animation\animation_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-vertical-navigation-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-horizontal-navigation-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-vertical-navigation-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-vertical-keyboard-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-vertical-keyboard-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-vertical-default-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-vertical-default-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\iphone5-landscape.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\ipad-landscape.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\ipad-portrait.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-horizontal-keyboard-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-horizontal-default-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-horizontal-default-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-vertical-navigation-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-vertical-navigation-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-horizontal-keyboard-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\iphone5-portrait.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\heap_snapshot_model\heap_snapshot_model_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-vertical-keyboard-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\application_test_runner\application_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\heap_profiler_test_runner\heap_profiler_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\har_importer\har_importer_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\formatter_worker.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\formatter\formatter_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\extensions_test_runner\extensions_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\event_listeners\event_listeners_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\nexus6p-portrait.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\nexus6p-landscape.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\nexus5x-portrait.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\nexus5x-landscape.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\iphone6plus-portrait.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\iphone6plus-landscape.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\iphone6-portrait.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\iphone6-landscape.svg
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5x-horizontal-navigation-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\d3dcompiler_47.dll
  • %APPDATA%\jjsploitv5\cache\data_2
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-vertical-default-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\cookie_table\cookie_table_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\console_test_runner\console_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\console\console_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\color_picker\color_picker_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\cm_modes\cm_modes_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\coverage_test_runner\coverage_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\cm\cm_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\browser_debugger\browser_debugger_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\bindings_test_runner\bindings_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\audits2_worker\audits2_worker_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\audits2_worker.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\audits2_test_runner\audits2_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\audits2\audits2_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\changes\changes_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\cpu_profiler_test_runner\cpu_profiler_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\coverage\coverage_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\data_grid\data_grid_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-horizontal-navigation-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\elements\elements_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-horizontal-navigation-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-horizontal-keyboard-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-horizontal-keyboard-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-horizontal-default-2x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-horizontal-default-1x.png
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\elements_test_runner\elements_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\diff\diff_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\data_grid_test_runner\data_grid_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\devtools_extension_api.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\devtools_compatibility.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\devtools_app.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\devtools_app.html
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\device_mode_test_runner\device_mode_test_runner_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\devices\devices_module.js
  • %LOCALAPPDATA%\programs\jjsploitv5\resources\inspector\emulated_devices\google-nexus-5-vertical-keyboard-1x.png
  • %APPDATA%\jjsploitv5\cache\data_3
Deletes the following files
  • %TEMP%\nss29cf.tmp\app-32.7z
  • %TEMP%\nss29cf.tmp\nsis7z.dll
  • %TEMP%\nss29cf.tmp\nsprocess.dll
  • %TEMP%\nss29cf.tmp\spiderbanner.dll
  • %TEMP%\nss29cf.tmp\stdutils.dll
  • %TEMP%\nss29cf.tmp\system.dll
  • %TEMP%\nss29cf.tmp\winshell.dll
  • %APPDATA%\jjsploitv5\current~rf12c8ab.tmp
  • %APPDATA%\jjsploitv5\manifest-000001
  • %APPDATA%\jjsploitv5\network persistent state~rf14231a.tmp
Moves the following files
  • from %APPDATA%\jjsploitv5\code cache\js\index-dir\temp-index to %APPDATA%\jjsploitv5\code cache\js\index-dir\the-real-index
  • from %APPDATA%\jjsploitv5\000001.dbtmp to %APPDATA%\jjsploitv5\current
  • from %APPDATA%\jjsploitv5\5f345865-d2a0-4a0c-96b7-dc708b16b18f.tmp to %APPDATA%\jjsploitv5\network persistent state
  • from %APPDATA%\jjsploitv5\000002.dbtmp to %APPDATA%\jjsploitv5\current
  • from %APPDATA%\jjsploitv5\current to %APPDATA%\jjsploitv5\current~rf12c8ab.tmp
  • from %APPDATA%\jjsploitv5\network persistent state to %APPDATA%\jjsploitv5\network persistent state~rf14231a.tmp
Substitutes the following files
  • %APPDATA%\jjsploitv5\current
Network activity
TCP
  • 'fo###.#oogleapis.com':443
  • 'fo###.gstatic.com':443
  • 'go#####analytics.com':443
  • 'cd#.##aredevs.net':443
  • 'cd#.##scordapp.com':443
  • 'yo##ube.com':443
  • 'i.##img.com':443
UDP
  • DNS ASK fo###.#oogleapis.com
  • DNS ASK fo###.gstatic.com
  • DNS ASK cd#.##aredevs.net
  • DNS ASK go#####analytics.com
  • DNS ASK cd#.##scordapp.com
  • DNS ASK yo##ube.com
  • DNS ASK microsoft.com
  • DNS ASK i.##img.com
Miscellaneous
Searches for the following windows
  • ClassName: '#32770' WindowName: ''
  • ClassName: 'DDEMLMom' WindowName: ''
  • ClassName: 'IEFrame' WindowName: ''
  • ClassName: 'Static' WindowName: ''
  • ClassName: 'MS_AutodialMonitor' WindowName: ''
  • ClassName: 'MS_WebCheckMonitor' WindowName: ''
Creates and executes the following
  • '%LOCALAPPDATA%\programs\jjsploitv5\jjsploit v5.exe'
  • '%LOCALAPPDATA%\programs\jjsploitv5\jjsploit v5.exe' --type=gpu-process --disable-features=SpareRendererForSitePerProcess --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAA...
  • '%LOCALAPPDATA%\programs\jjsploitv5\jjsploit v5.exe' --type=renderer --disable-features=SpareRendererForSitePerProcess --service-pipe-token=15803181725934175735 --lang=en-US --app-path="%LOCALAPPDATA%\Programs\jjsploitv5\resources\app.asar" --no-...
  • '%LOCALAPPDATA%\programs\jjsploitv5\jjsploit v5.exe' --type=gpu-process --disable-features=SpareRendererForSitePerProcess --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIA...
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c start "" "%LOCALAPPDATA%\Programs\jjsploitv5\resources\jjsploit_installer.exe"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android