Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Carberp.2686

Added to the Dr.Web virus database: 2021-02-27

Virus description added:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • <SYSTEM32>\tasks\nvngxupdatecheckdaily_{78821544-1544-1544-1544-788215441544}
Malicious functions
Injects code into
the following system processes:
  • %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
the following user processes:
  • ibffwrs
Terminates or attempts to terminate
the following system processes:
  • %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
Reads files which store third party applications passwords
  • %LOCALAPPDATA%\google\chrome\user data\default\login data
  • %LOCALAPPDATA%\google\chrome\user data\default\web data
  • %LOCALAPPDATA%\google\chrome\user data\default\cookies
  • %APPDATA%\opera software\opera stable\login data
Modifies file system
Creates the following files
  • %TEMP%\4dd3.tmp
  • %TEMP%\tmp2977.tmp
  • %TEMP%\tmp2976.tmp
  • %TEMP%\tmp2975.tmp
  • %TEMP%\tmp2974.tmp
  • %TEMP%\tmp2963.tmp
  • %TEMP%\tmp2962.tmp
  • %TEMP%\tmp2961.tmp
  • %TEMP%\tmp2960.tmp
  • %TEMP%\tmp2978.tmp
  • %TEMP%\tmp295f.tmp
  • %TEMP%\tmp294e.tmp
  • %TEMP%\tmp294d.tmp
  • %TEMP%\tmp294c.tmp
  • %TEMP%\tmp294b.tmp
  • %TEMP%\tmp293a.tmp
  • %TEMP%\tmp2939.tmp
  • %TEMP%\tmp2938.tmp
  • %TEMP%\tmp2937.tmp
  • %TEMP%\tmp294f.tmp
  • %TEMP%\tmp2989.tmp
  • %TEMP%\tmp298a.tmp
  • %TEMP%\tmp298b.tmp
  • %TEMP%\tmp5f66.tmp
  • %TEMP%\tmp5f55.tmp
  • %TEMP%\tmp5f54.tmp
  • %TEMP%\tmp5f53.tmp
  • %TEMP%\tmp5f43.tmp
  • %TEMP%\tmp5f42.tmp
  • %TEMP%\tmp5f41.tmp
  • %TEMP%\tmp5f21.tmp
  • %TEMP%\tmp5f20.tmp
  • %TEMP%\tmp29d3.tmp
  • %TEMP%\tmp29d2.tmp
  • %TEMP%\tmp29c1.tmp
  • %TEMP%\tmp29b1.tmp
  • %TEMP%\tmp29a0.tmp
  • %TEMP%\tmp299f.tmp
  • %TEMP%\tmp299e.tmp
  • %TEMP%\tmp299d.tmp
  • %TEMP%\tmp299c.tmp
  • %TEMP%\tmp298c.tmp
  • %TEMP%\tmp2936.tmp
  • %TEMP%\tmp284d.tmp
  • %TEMP%\tmp2926.tmp
  • %TEMP%\tmp2924.tmp
  • %TEMP%\tmp28ae.tmp
  • %TEMP%\tmp28ad.tmp
  • %TEMP%\tmp28ac.tmp
  • %TEMP%\tmp28ab.tmp
  • %TEMP%\tmp28aa.tmp
  • %TEMP%\tmp2899.tmp
  • %TEMP%\tmp2898.tmp
  • %TEMP%\tmp2897.tmp
  • %TEMP%\tmp28bf.tmp
  • %TEMP%\tmp2896.tmp
  • %TEMP%\tmp2885.tmp
  • %TEMP%\tmp2884.tmp
  • %TEMP%\tmp2873.tmp
  • %TEMP%\tmp2872.tmp
  • %TEMP%\tmp2871.tmp
  • %TEMP%\tmp2870.tmp
  • %TEMP%\tmp2860.tmp
  • %TEMP%\tmp285f.tmp
  • %TEMP%\tmp2886.tmp
  • %TEMP%\tmp28c0.tmp
  • %TEMP%\tmp28c1.tmp
  • %TEMP%\tmp28d1.tmp
  • %TEMP%\tmp2923.tmp
  • %TEMP%\tmp2922.tmp
  • %TEMP%\tmp2911.tmp
  • %TEMP%\tmp2910.tmp
  • %TEMP%\tmp290f.tmp
  • %TEMP%\tmp290e.tmp
  • %TEMP%\tmp290d.tmp
  • %TEMP%\tmp28fc.tmp
  • %TEMP%\tmp28fb.tmp
  • %TEMP%\tmp28fa.tmp
  • %TEMP%\tmp28f9.tmp
  • %TEMP%\tmp28f8.tmp
  • %TEMP%\tmp28e8.tmp
  • %TEMP%\tmp28e7.tmp
  • %TEMP%\tmp28e6.tmp
  • %TEMP%\tmp28e5.tmp
  • %TEMP%\tmp28d4.tmp
  • %TEMP%\tmp28d3.tmp
  • %TEMP%\tmp28d2.tmp
  • %TEMP%\tmp2925.tmp
  • %TEMP%\tmp284e.tmp
  • %TEMP%\tmp5f67.tmp
  • %TEMP%\tmp5fb0.tmp
  • %TEMP%\tmp60d0.tmp
  • %TEMP%\tmp60cf.tmp
  • %TEMP%\tmp60ce.tmp
  • %TEMP%\tmp60be.tmp
  • %TEMP%\tmp60bd.tmp
  • %TEMP%\tmp60ac.tmp
  • %TEMP%\tmp60ab.tmp
  • %TEMP%\tmp609b.tmp
  • %TEMP%\tmp60e2.tmp
  • %TEMP%\tmp60d1.tmp
  • %TEMP%\tmp6098.tmp
  • %TEMP%\tmp6097.tmp
  • %TEMP%\tmp6086.tmp
  • %TEMP%\tmp6085.tmp
  • %TEMP%\tmp6084.tmp
  • %TEMP%\tmp6083.tmp
  • %TEMP%\tmp6082.tmp
  • %TEMP%\tmp6071.tmp
  • %TEMP%\tmp609a.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mozmapi32.dll
  • %TEMP%\tmp60e3.tmp
  • %TEMP%\tmp6164.tmp
  • %TEMP%\tmp6154.tmp
  • %TEMP%\tmp6143.tmp
  • %TEMP%\tmp6142.tmp
  • %TEMP%\tmp6141.tmp
  • %TEMP%\tmp6130.tmp
  • %TEMP%\tmp612f.tmp
  • %TEMP%\tmp612e.tmp
  • %TEMP%\tmp611e.tmp
  • %TEMP%\tmp611d.tmp
  • %TEMP%\tmp611c.tmp
  • %TEMP%\tmp611b.tmp
  • %TEMP%\tmp610a.tmp
  • %TEMP%\tmp6109.tmp
  • %TEMP%\tmp6108.tmp
  • %TEMP%\tmp6107.tmp
  • %TEMP%\tmp60f7.tmp
  • %TEMP%\tmp60f6.tmp
  • %TEMP%\tmp60f5.tmp
  • %TEMP%\tmp6070.tmp
  • %TEMP%\tmp6099.tmp
  • %TEMP%\tmp5f69.tmp
  • %TEMP%\tmp5f68.tmp
  • %TEMP%\tmp605e.tmp
  • %TEMP%\tmp5fb1.tmp
  • %TEMP%\tmp5fd8.tmp
  • %TEMP%\tmp5fd7.tmp
  • %TEMP%\tmp5fd6.tmp
  • %TEMP%\tmp5fc5.tmp
  • %TEMP%\tmp5fc4.tmp
  • %TEMP%\tmp5fc3.tmp
  • %TEMP%\tmp5fb2.tmp
  • %TEMP%\tmp5feb.tmp
  • %TEMP%\tmp5fe9.tmp
  • %TEMP%\tmp5fea.tmp
  • %TEMP%\tmp5f9f.tmp
  • %TEMP%\tmp5f8e.tmp
  • %TEMP%\tmp5f8d.tmp
  • %TEMP%\tmp5f8c.tmp
  • %TEMP%\tmp5f7c.tmp
  • %TEMP%\tmp5f7b.tmp
  • %TEMP%\tmp5f7a.tmp
  • %TEMP%\tmp5fa0.tmp
  • %TEMP%\tmp5fec.tmp
  • %TEMP%\tmp605d.tmp
  • %TEMP%\tmp606e.tmp
  • %TEMP%\tmp5fd9.tmp
  • %TEMP%\tmp605c.tmp
  • %TEMP%\tmp605b.tmp
  • %TEMP%\tmp605a.tmp
  • %TEMP%\tmp6049.tmp
  • %TEMP%\tmp6048.tmp
  • %TEMP%\tmp6047.tmp
  • %TEMP%\tmp6037.tmp
  • %TEMP%\tmp6036.tmp
  • %TEMP%\tmp6035.tmp
  • %TEMP%\tmp6024.tmp
  • %TEMP%\tmp6023.tmp
  • %TEMP%\tmp6022.tmp
  • %TEMP%\tmp6021.tmp
  • %TEMP%\tmp6010.tmp
  • %TEMP%\tmp600f.tmp
  • %TEMP%\tmp5fff.tmp
  • %TEMP%\tmp5ffe.tmp
  • %TEMP%\tmp5ffd.tmp
  • %TEMP%\tmp606f.tmp
  • %TEMP%\tmp284c.tmp
  • %TEMP%\tmp284b.tmp
  • %TEMP%\tmp283a.tmp
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-environment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-convert-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-conio-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-util-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-timezone-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-sysinfo-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-profile-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-1.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processenvironment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-namedpipe-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssckbi.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nss3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-locale-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-math-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-multibyte-l1-1-0.dll
  • %LOCALAPPDATA%low\8prvaj3jy-shm
  • %LOCALAPPDATA%low\8prvaj3jy
  • %LOCALAPPDATA%low\fraqbc8ws-shm
  • %LOCALAPPDATA%low\fraqbc8ws
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-memory-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-localization-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-libraryloader-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-interlocked-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-handle-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l2-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-utility-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-time-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-stdio-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-runtime-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-process-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-private-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\msvcp140.dll
  • %LOCALAPPDATA%low\firefox_urls.txt
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozglue.dll
  • %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol
  • %LOCALAPPDATA%low\bbsqwy6yhk
  • %LOCALAPPDATA%low\gxix4a2dre
  • %LOCALAPPDATA%low\exuieaoeii
  • %LOCALAPPDATA%low\3solbph71y
  • %LOCALAPPDATA%low\x3cf3ednhm
  • %LOCALAPPDATA%low\rqf69azbla
  • %LOCALAPPDATA%low\rywtiizs2t
  • %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\3ccd5499-87a8-4b10-a215-608888dd3b55.vsch
  • %LOCALAPPDATA%low\1xvpfvjcrg
  • %TEMP%\a45d.tmp.exe
  • %LOCALAPPDATA%low\sqlite3.dll
  • %TEMP%\9cce.tmp.exe
  • %TEMP%\93b9.tmp.exe
  • %TEMP%\7d4b.tmp.exe
  • %TEMP%\6a85.tmp.exe
  • %APPDATA%\jshjugb
  • %APPDATA%\ibffwrs
  • %LOCALAPPDATA%low\fraqbc8wsa
  • %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\2f1a6504-0641-44cf-8bb5-3612d865f2e5.vsch
  • %LOCALAPPDATA%\microsoft\vault\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\policy.vpol
  • %ALLUSERSPROFILE%\q5x2y1x5x5x2y1x5x5\vttrhgpopeyg.vtt
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\libegl.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\lgpllibs.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldif60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldap60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ia2marshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\freebl3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\breakpadinjector.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblemarshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblehandler.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\vcruntime140.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ucrtbase.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\softokn3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\qipcap.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\prldap60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssdbm3.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ar8pj3hc8rg2st.zip
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ih7oe4ur9pw5zj0o.zip
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32.dll
  • %LOCALAPPDATA%low\nd58z0xsk
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-filesystem-l1-1-0.dll
  • %LOCALAPPDATA%low\nd58z0xsk-shm
  • %LOCALAPPDATA%low\gxwdinksg
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-handle-l1-1-0.dll
  • %LOCALAPPDATA%low\rtooaierq-shm
  • %LOCALAPPDATA%low\rtooaierq
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-memory-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-localization-l1-2-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-libraryloader-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-interlocked-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\vab8ercbu-shm
  • %LOCALAPPDATA%low\gxwdinksg-shm
  • %LOCALAPPDATA%low\vab8ercbu
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-utility-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-time-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-string-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-stdio-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-runtime-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-process-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-private-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-file-l1-2-0.dll
  • %LOCALAPPDATA%low\5xoapqambwg.zip
  • %TEMP%\tmp2839.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-multibyte-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-locale-l1-1-0.dll
  • %TEMP%\tmp2838.tmp
  • %TEMP%\tmp2837.tmp
  • %TEMP%\tmp2827.tmp
  • %TEMP%\tmp2826.tmp
  • %TEMP%\tmp2825.tmp
  • %TEMP%\tmp2814.tmp
  • %TEMP%\tmp2813.tmp
  • %TEMP%\tmp2812.tmp
  • %TEMP%\tmp2802.tmp
  • %TEMP%\tmp2801.tmp
  • %TEMP%\tmp2800.tmp
  • %TEMP%\tmp27ef.tmp
  • %TEMP%\tmp27ee.tmp
  • %TEMP%\tmp27ed.tmp
  • %TEMP%\tmp27dc.tmp
  • %TEMP%\tmp27ad.tmp
  • %TEMP%\tmp27ac.tmp
  • nul
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-file-l2-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-math-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\kt2ay1ko2
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\accessiblehandler.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\libegl.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\lgpllibs.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ldif60.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ldap60.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ia2marshal.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\freebl3.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\breakpadinjector.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\accessiblemarshal.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\vcruntime140.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mapiproxy_inuse.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ucrtbase.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\softokn3.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\qipcap.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\prldap60.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\nssdbm3.dll
  • %LOCALAPPDATA%low\3ozw5hpum0p.zip
  • %LOCALAPPDATA%low\machineinfo.txt
  • %LOCALAPPDATA%low\kt2ay1ko2-shm
  • %TEMP%\tmp6184.tmp
  • %TEMP%\tmp60e4.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mozglue.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\msvcp140.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mapiproxy.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-filesystem-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-environment-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-convert-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-conio-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-util-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-timezone-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-sysinfo-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-synch-l1-2-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-synch-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-string-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-profile-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-processthreads-l1-1-1.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-processthreads-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-processenvironment-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-namedpipe-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\nssckbi.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\nss3.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mozmapi32_inuse.dll
  • %TEMP%\tmp6185.tmp
Sets the 'hidden' attribute to the following files
  • %APPDATA%\ibffwrs
  • %APPDATA%\jshjugb
Deletes the following files
  • %TEMP%\4dd3.tmp
  • %TEMP%\tmp2872.tmp
  • %TEMP%\tmp2884.tmp
  • %TEMP%\tmp2886.tmp
  • %TEMP%\tmp2897.tmp
  • %TEMP%\tmp2899.tmp
  • %TEMP%\tmp28ab.tmp
  • %TEMP%\tmp28ad.tmp
  • %TEMP%\tmp28bf.tmp
  • %TEMP%\tmp28c1.tmp
  • %TEMP%\tmp28d2.tmp
  • %TEMP%\tmp28d4.tmp
  • %TEMP%\tmp28e6.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\nssdbm3.dll
  • %TEMP%\tmp28e8.tmp
  • %TEMP%\tmp28fb.tmp
  • %TEMP%\tmp290d.tmp
  • %TEMP%\tmp290f.tmp
  • %TEMP%\tmp2911.tmp
  • %TEMP%\tmp2923.tmp
  • %TEMP%\tmp2925.tmp
  • %TEMP%\tmp2936.tmp
  • %TEMP%\tmp2938.tmp
  • %TEMP%\tmp293a.tmp
  • %TEMP%\tmp294c.tmp
  • %TEMP%\tmp294e.tmp
  • %TEMP%\tmp295f.tmp
  • %TEMP%\tmp285f.tmp
  • %TEMP%\tmp2870.tmp
  • %TEMP%\tmp284d.tmp
  • %TEMP%\tmp284b.tmp
  • %TEMP%\tmp2839.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ia2marshal.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ldap60.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ldif60.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\lgpllibs.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\libegl.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mapiproxy.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mapiproxy_inuse.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mozglue.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mozmapi32.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\mozmapi32_inuse.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\msvcp140.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\nss3.dll
  • %TEMP%\tmp2961.tmp
  • %TEMP%\tmp28f9.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\nssckbi.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\qipcap.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\softokn3.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ucrtbase.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\vcruntime140.dll
  • %TEMP%\tmp27ad.tmp
  • %TEMP%\tmp27ed.tmp
  • %TEMP%\tmp27ef.tmp
  • %TEMP%\tmp2801.tmp
  • %TEMP%\tmp2812.tmp
  • %TEMP%\tmp2814.tmp
  • %TEMP%\tmp2826.tmp
  • %TEMP%\tmp2837.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\freebl3.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\prldap60.dll
  • %TEMP%\tmp2963.tmp
  • %TEMP%\tmp2975.tmp
  • %TEMP%\tmp2977.tmp
  • %TEMP%\tmp6037.tmp
  • %TEMP%\tmp6048.tmp
  • %TEMP%\tmp605a.tmp
  • %TEMP%\tmp605c.tmp
  • %TEMP%\tmp605e.tmp
  • %TEMP%\tmp606f.tmp
  • %TEMP%\tmp6071.tmp
  • %TEMP%\tmp6083.tmp
  • %TEMP%\tmp6085.tmp
  • %TEMP%\tmp6097.tmp
  • %TEMP%\tmp6099.tmp
  • %TEMP%\tmp609b.tmp
  • %TEMP%\tmp60ac.tmp
  • %TEMP%\tmp60cf.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\breakpadinjector.dll
  • %TEMP%\tmp60d1.tmp
  • %TEMP%\tmp60e3.tmp
  • %TEMP%\tmp60f5.tmp
  • %TEMP%\tmp60f7.tmp
  • %TEMP%\tmp6108.tmp
  • %TEMP%\tmp610a.tmp
  • %TEMP%\tmp611c.tmp
  • %TEMP%\tmp611e.tmp
  • %TEMP%\tmp612f.tmp
  • %TEMP%\tmp6141.tmp
  • %TEMP%\tmp6143.tmp
  • %TEMP%\tmp6154.tmp
  • %TEMP%\tmp6164.tmp
  • %TEMP%\tmp6035.tmp
  • %TEMP%\tmp5f67.tmp
  • %TEMP%\tmp6023.tmp
  • %TEMP%\tmp5f55.tmp
  • %TEMP%\tmp2989.tmp
  • %TEMP%\tmp298b.tmp
  • %TEMP%\tmp299c.tmp
  • %TEMP%\tmp299e.tmp
  • %TEMP%\tmp29a0.tmp
  • %TEMP%\tmp29b1.tmp
  • %TEMP%\tmp29c1.tmp
  • %TEMP%\tmp29d2.tmp
  • %TEMP%\tmp29d3.tmp
  • %TEMP%\9cce.tmp.exe
  • %TEMP%\tmp5f21.tmp
  • %TEMP%\tmp5f42.tmp
  • %TEMP%\tmp5f53.tmp
  • %TEMP%\tmp6184.tmp
  • %TEMP%\tmp600f.tmp
  • %TEMP%\tmp5f69.tmp
  • %TEMP%\tmp5f7b.tmp
  • %TEMP%\tmp5f8c.tmp
  • %TEMP%\tmp5f8e.tmp
  • %TEMP%\tmp5fa0.tmp
  • %TEMP%\tmp5fb1.tmp
  • %TEMP%\tmp5fc3.tmp
  • %TEMP%\tmp5fc5.tmp
  • %TEMP%\tmp5fd7.tmp
  • %TEMP%\tmp5fd9.tmp
  • %TEMP%\tmp5fea.tmp
  • %TEMP%\tmp5fec.tmp
  • %TEMP%\tmp5ffe.tmp
  • %TEMP%\tmp6021.tmp
  • %TEMP%\tmp60be.tmp
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-utility-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-sysinfo-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processenvironment-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-processthreads-l1-1-1.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-profile-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-synch-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-sysinfo-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-timezone-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-util-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-conio-l1-1-0.dll
  • %LOCALAPPDATA%low\8prvaj3jy
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-convert-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-filesystem-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-locale-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-math-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-multibyte-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-private-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-process-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-runtime-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-stdio-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-string-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-time-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-utility-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-memory-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-namedpipe-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-localization-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-libraryloader-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-interlocked-l1-1-0.dll
  • %LOCALAPPDATA%low\1xvpfvjcrg
  • %LOCALAPPDATA%low\rywtiizs2t
  • %LOCALAPPDATA%low\rqf69azbla
  • %LOCALAPPDATA%low\x3cf3ednhm
  • %LOCALAPPDATA%low\3solbph71y
  • %LOCALAPPDATA%low\exuieaoeii
  • %LOCALAPPDATA%low\gxix4a2dre
  • %LOCALAPPDATA%low\bbsqwy6yhk
  • %ALLUSERSPROFILE%\q5x2y1x5x5x2y1x5x5\vttrhgpopeyg.vtt
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ih7oe4ur9pw5zj0o.zip
  • %LOCALAPPDATA%low\fraqbc8ws-shm
  • %LOCALAPPDATA%low\fraqbc8ws
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\breakpadinjector.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-crt-environment-l1-1-0.dll
  • %LOCALAPPDATA%low\8prvaj3jy-shm
  • %LOCALAPPDATA%low\nd58z0xsk
  • %LOCALAPPDATA%low\kt2ay1ko2-shm
  • %LOCALAPPDATA%low\kt2ay1ko2
  • %LOCALAPPDATA%low\3ozw5hpum0p.zip
  • %LOCALAPPDATA%low\firefox_urls.txt
  • %LOCALAPPDATA%low\machineinfo.txt
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblehandler.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\accessiblemarshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-file-l2-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-handle-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\api-ms-win-core-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\fraqbc8wsa
  • %LOCALAPPDATA%low\nd58z0xsk-shm
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\freebl3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ia2marshal.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldap60.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-interlocked-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-libraryloader-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-localization-l1-2-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-memory-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-namedpipe-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-processenvironment-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-processthreads-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-processthreads-l1-1-1.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-profile-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-string-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-synch-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-synch-l1-2-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-timezone-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-time-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-util-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-conio-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-convert-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-environment-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-filesystem-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-locale-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-math-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-multibyte-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-private-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-process-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-runtime-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-stdio-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-heap-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\softokn3.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-handle-l1-1-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\qipcap.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ldif60.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\lgpllibs.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\libegl.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mapiproxy_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozglue.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\mozmapi32_inuse.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\msvcp140.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nss3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssckbi.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\nssdbm3.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\prldap60.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-crt-string-l1-1-0.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-file-l1-2-0.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\ucrtbase.dll
  • %LOCALAPPDATA%low\pf2qc1gg7yh8hi1o\vcruntime140.dll
  • %LOCALAPPDATA%low\sqlite3.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\ar8pj3hc8rg2st.zip
  • %LOCALAPPDATA%low\rtooaierq-shm
  • %LOCALAPPDATA%low\rtooaierq
  • %LOCALAPPDATA%low\gxwdinksg-shm
  • %LOCALAPPDATA%low\gxwdinksg
  • %LOCALAPPDATA%low\vab8ercbu-shm
  • %LOCALAPPDATA%low\vab8ercbu
  • %LOCALAPPDATA%low\5xoapqambwg.zip
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\accessiblehandler.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\accessiblemarshal.dll
  • %LOCALAPPDATA%low\ee8sf0yg2eq6ft7\api-ms-win-core-file-l2-1-0.dll
  • %TEMP%\tmp6185.tmp
Substitutes the following files
  • %TEMP%\4dd3.tmp
  • %ALLUSERSPROFILE%\q5x2y1x5x5x2y1x5x5\vttrhgpopeyg.vtt
  • %LOCALAPPDATA%low\fraqbc8wsa
  • %LOCALAPPDATA%low\1xvpfvjcrg
  • %LOCALAPPDATA%low\rywtiizs2t
  • %LOCALAPPDATA%low\rqf69azbla
  • %LOCALAPPDATA%low\x3cf3ednhm
  • %LOCALAPPDATA%low\3solbph71y
  • %LOCALAPPDATA%low\exuieaoeii
  • %LOCALAPPDATA%low\gxix4a2dre
  • %LOCALAPPDATA%low\bbsqwy6yhk
  • %LOCALAPPDATA%low\fraqbc8ws
  • %LOCALAPPDATA%low\fraqbc8ws-shm
  • %LOCALAPPDATA%low\firefox_urls.txt
  • %LOCALAPPDATA%low\machineinfo.txt
Deletes itself.
Network activity
Connects to
  • '1p##.oradza.ru':443
  • 'pa#####gmercedes.top':443
  • 'te##te.in':443
  • '45.#4.13.58':3214
  • '18#.#12.131.241':80
  • '80.##.245.80':80
  • 'ma###ash22.com':80
  • 'ma###ash22.com':443
  • 'zc#.##denther.ru':443
  • 'ap#.ip.sb':443
  • 'wh###.iana.org':43
  • 'WH###.RIPE.NET':43
TCP
HTTP GET requests
  • http://10############6831-service1002012510022020.space/raccon.exe
HTTP POST requests
  • http://10###########lder1002002131-service1002.space/
  • http://10##########older33417-01242510022020.space/
  • http://10############6831-service1002012510022020.space/
  • http://80.##.245.80/log/
  • http://45.##.13.58:3214/ via 45.#4.13.58
  • http://rh##mnes.cf/
  • '1p##.oradza.ru':443
  • 'te##te.in':443
  • 'pa#####gmercedes.top':443
  • 'ma###ash22.com':443
  • 'ap#.ip.sb':443
  • 'wh###.iana.org':43
  • 'WH###.RIPE.NET':43
  • UDP
    • DNS ASK 10###########lder1002002131-service1002.space
    • DNS ASK wh###.iana.org
    • DNS ASK ap#.ip.sb
    • DNS ASK zc#.##denther.ru
    • DNS ASK ma###ash22.com
    • DNS ASK pa#####gmercedes.top
    • DNS ASK te##te.in
    • DNS ASK WH###.RIPE.NET
    • DNS ASK 1p##.oradza.ru
    • DNS ASK 10############5831-service1002012510022020.space
    • DNS ASK 10##########older33417-01242510022020.space
    • DNS ASK 10###########lder1002002531-service1002.space
    • DNS ASK 10###########lder1002002431-service1002.space
    • DNS ASK 10##########older3100231-service1002.space
    • DNS ASK 10###########lder1002002231-service1002.space
    • DNS ASK 10############6831-service1002012510022020.space
    • DNS ASK rh##mnes.cf
    Miscellaneous
    Creates and executes the following
    • '%TEMP%\6a85.tmp.exe'
    • '%APPDATA%\ibffwrs'
    • '%TEMP%\7d4b.tmp.exe'
    • '%TEMP%\93b9.tmp.exe'
    • '%TEMP%\9cce.tmp.exe'
    • '%TEMP%\a45d.tmp.exe'
    • '%APPDATA%\ibffwrs' ' (with hidden window)
    Executes the following
    • '<SYSTEM32>\taskeng.exe' {3DE543AE-F15C-4437-9330-AAB406D7FA28} S-1-5-21-1960123792-2022915161-3775307078-1001:gomacp\user:Interactive:[1]
    • '%WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe'
    • '%WINDIR%\syswow64\cmd.exe' /C timeout /T 10 /NOBREAK > Nul & Del /f /q "%TEMP%\9CCE.tmp.exe"
    • '%WINDIR%\syswow64\timeout.exe' /T 10 /NOBREAK

    Curing recommendations

    1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
    2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
    Download Dr.Web

    Download by serial number

    Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

    After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

    Download Dr.Web

    Download by serial number

    1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
    2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
      • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
      • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
      • Switch off your device and turn it on as normal.

    Find out more about Dr.Web for Android