Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.MulDrop21.64458

Added to the Dr.Web virus database: 2023-05-08

Virus description added:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %APPDATA%\microsoft\windows\start menu\programs\startup\zk.lnk
Modifies file system
Creates the following files
  • <Current directory>\vpnup.bat
  • <Current directory>\restart.bat
  • nul
Substitutes the following files
  • <Current directory>\restart.bat
Network activity
UDP
  • DNS ASK zd##.74315.com
Miscellaneous
Creates and executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\Restart.bat' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c .\vpnup.bat
  • '%WINDIR%\syswow64\route.exe' add 97.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 96.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 95.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 94.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 93.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 92.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 91.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 90.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 89.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 88.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 87.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 86.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 85.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 99.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 98.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 82.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 81.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 80.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 79.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 78.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 77.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 76.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 75.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 74.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 73.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 72.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 71.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 70.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 84.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 31.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 100.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 131.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 130.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 129.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 128.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 127.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 126.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 125.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 124.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 123.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 122.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 120.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 119.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 118.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 117.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 116.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 115.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 114.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 113.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 112.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 111.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 110.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 109.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 108.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 107.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 106.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 105.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 104.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 103.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 102.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 69.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 83.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 68.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 67.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 66.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 14.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 28.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\Restart.bat
  • '%WINDIR%\syswow64\route.exe' add 27.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 26.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 25.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 24.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 23.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 22.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 21.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 20.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 19.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 17.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 16.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 12.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 2
  • '%WINDIR%\syswow64\route.exe' add 11.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 9.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 8.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 7.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 6.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 5.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 4.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 2.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 1.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\ipconfig.exe' /flushdns
  • '%WINDIR%\syswow64\findstr.exe' "\<0.0.0.0\>"
  • '%WINDIR%\syswow64\route.exe' print
  • '%WINDIR%\syswow64\cmd.exe' /c route print | findstr "\<0.0.0.0\>"
  • '%WINDIR%\syswow64\route.exe' add 132.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 101.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 30.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 33.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 29.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 65.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 64.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 63.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 62.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 61.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 60.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 59.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 58.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 57.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 56.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 55.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 53.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 51.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 50.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 49.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 48.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 47.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 46.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 45.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 44.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 42.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 41.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 40.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 39.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 38.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 37.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 36.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 34.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 32.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5
  • '%WINDIR%\syswow64\route.exe' add 133.0.0.0 mask 255.0.0.0 10.0.15.1 metric 5

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android