Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Siggen22.19846

Added to the Dr.Web virus database: 2023-11-29

Virus description added:

Technical Information

To ensure autorun and distribution
Sets the following service settings
  • [HKLM\system\CurrentControlSet\services\WofAdk] 'Start' = '00000000'
  • [HKLM\System\CurrentControlSet\Services\WofAdk] 'ImagePath' = 'system32\DRIVERS\wofadk.sys'
  • [HKLM\system\CurrentControlSet\services\ImDisk] 'Start' = '00000002'
  • [HKLM\System\CurrentControlSet\Services\Imdisk] 'ImagePath' = '%TEMP%\~6784711813192159767..\tools\imdisk\sys\amd64\imdisk.sys'
Creates the following services
  • 'WofAdk' system32\DRIVERS\wofadk.sys
  • 'Imdisk' %TEMP%\~6784711813192159767..\tools\imdisk\sys\amd64\imdisk.sys
Malicious functions
Terminates or attempts to terminate
the following system processes:
  • <SYSTEM32>\cmd.exe
Registers file system filter
  • [HKLM\system\CurrentControlSet\services\WofAdk] 'Group' = 'FSFilter Compression'
Modifies file system
Creates the following files
  • %TEMP%\~~5074702496660032428.tmp
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\active setup.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\defender.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\defender.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\drvstore_inf.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\edge.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\edge.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\fonts.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\installed.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\languages.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\media.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\netfx.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\netfx_keep.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\removal of windows security action center.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\onedrive.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\speech.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\system32-dll.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\system32.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\syswow.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\windows.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\windows11.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\windowsapps.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\windowspowershell.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\winsat.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\wmp.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\wuau.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\wuau.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\usersignedin.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\windows settings page visibility.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\taskbar.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\systray_network_flyout.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\systray_classicvolumecontrol.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable system mitigations.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable tamper protection.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable uac.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable vbs.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\enable_folder_options_for_all_users.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\exploit guard_d.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\gamedvr.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\lockdown windows defender security center.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\mitigation of fault torelant heap.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\no more delay and timeouts.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\removal of anti-phishing services.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\removal of sechealthui.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\xbox.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\programfiles.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\removal of windows defender antivirus.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remove security and maintenance.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remove services.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remove shell association.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remove signature updates.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remove startup entries.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remove windows defender firewall rules.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remove windows webthreat.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remover of defender context menu.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\restore_photo_viewer_windows_10.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\security health.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\shippedwithreserves.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\stuckrects3-win10-200x.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable spynet telemetry.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\remove defender tasks.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\xbox.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\remove\xps.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\services.ini
  • %TEMP%\~6784711813192159767..\tools\arm64\wimlib.dll
  • %TEMP%\~6784711813192159767..\tools\imdisk\sys\amd64\imdisk.sys
  • %TEMP%\~6784711813192159767..\tools\nativevhdboot_x64.dll
  • %TEMP%\~6784711813192159767..\tools\nativevhdboot_x86.dll
  • %TEMP%\~6784711813192159767..\tools\x64\bcdboot.exe
  • %TEMP%\~6784711813192159767..\tools\x64\bcdedit.exe
  • %TEMP%\~6784711813192159767..\tools\x64\bootice\bootice.dll
  • %TEMP%\~6784711813192159767..\tools\x64\bootice\booticex64.exe
  • %TEMP%\~6784711813192159767..\tools\x64\bootice\lang\1031.dll
  • %TEMP%\~6784711813192159767..\tools\x64\bootice\lang\1033.dll
  • %TEMP%\~6784711813192159767..\tools\x64\bootice\lang\1049.dll
  • %TEMP%\~6784711813192159767..\tools\x64\bootsect.exe
  • %TEMP%\~6784711813192159767..\tools\x64\dism\dismapi.dll
  • %TEMP%\~6784711813192159767..\tools\x64\dism\dismcoreps.dll
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable smartscreen.reg
  • %TEMP%\~6784711813192159767..\tools\x64\dism\dismprov.dll
  • %TEMP%\~6784711813192159767..\tools\x64\dism\folderprovider.dll
  • %TEMP%\~6784711813192159767..\tools\x64\dism\logprovider.dll
  • %TEMP%\~6784711813192159767..\tools\x64\dism\wofadk.sys
  • %TEMP%\~6784711813192159767..\tools\x64\msstmake.exe
  • %TEMP%\~6784711813192159767..\tools\x64\offreg.dll
  • %TEMP%\~6784711813192159767..\tools\x64\wimgapi.dll
  • %TEMP%\~6784711813192159767..\tools\x64\wimhost.exe
  • %TEMP%\~6784711813192159767..\tools\x64\wimlib.dll
  • %TEMP%\~6784711813192159767..\tools\x86\dism\wofadk.sys
  • %TEMP%\~6784711813192159767..\winntsetup_x64.exe
  • %TEMP%\winntsetup\logs\wimgapi_error.log
  • <DRIVERS>\wofadk.sys
  • %TEMP%\~6784711813192159767..\tools\arm64\wimhost.exe
  • %TEMP%\~6784711813192159767..\tools\x86\dism\readme.txt
  • %TEMP%\~6784711813192159767..\lang\2058.dll
  • %TEMP%\~6784711813192159767..\tools\x64\dism\readme.txt
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\tasks.ini
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\winsxs.ini
  • %TEMP%\~6784711813192159767..\minwin\readme.txt
  • %TEMP%\~6784711813192159767..\minwin\readmechs.txt
  • %TEMP%\~6784711813192159767..\tools\cattrim.ini
  • %TEMP%\~6784711813192159767..\tools\imdisk\cpl\amd64\imdisk.cpl
  • %TEMP%\~6784711813192159767..\tools\mergeide_2600.ini
  • %TEMP%\~6784711813192159767..\tools\mergeide_7600.ini
  • %TEMP%\~6784711813192159767..\tools\mergeide_9200.ini
  • %TEMP%\~6784711813192159767..\tools\win10builds.ini
  • %TEMP%\~6784711813192159767..\tools\win7usb3\readme.txt
  • %TEMP%\~6784711813192159767..\tools\win7usbboot.ini
  • %TEMP%\~6784711813192159767..\tools\x64\bootice\bootice.ini
  • %WINDIR%\temp\udd8f34.tmp
  • %TEMP%\~6784711813192159767..\lang\1058.dll
  • %TEMP%\~6784711813192159767..\unattend\win7-11-select.xml
  • %TEMP%\~6784711813192159767..\wimscript\wimscript.ini
  • %TEMP%\~6784711813192159767..\winntsetup.ini
  • %TEMP%\~6784711813192159767..\winntsetup.ini.txt
  • %TEMP%\~6784711813192159767..\winntsetup_mru.txt
  • %TEMP%\~6784711813192159767..\lang\1028.dll
  • %TEMP%\~6784711813192159767..\lang\1031.dll
  • %TEMP%\~6784711813192159767..\lang\1036.dll
  • %TEMP%\~6784711813192159767..\lang\1040.dll
  • %TEMP%\~6784711813192159767..\lang\1042.dll
  • %TEMP%\~6784711813192159767..\lang\1046.dll
  • %TEMP%\~6784711813192159767..\lang\1049.dll
  • %TEMP%\~6784711813192159767..\lang\1055.dll
  • %TEMP%\~6784711813192159767..\lang\2052.dll
  • %TEMP%\~6784711813192159767..\tools\x64\dism\dismcore.dll
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable microsoft vulnerabile driver blocklist.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\xps.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\speech.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\windowsapps.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\wuau.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\wuau.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\services.ini
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\winsxs.ini
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\add\windows\panther\unattend.xml
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\add\windows\setup\scripts\firstlogon.cmd
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\add\windows\setup\scripts\setupcomplete.cmd
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\antilog.ini
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\antilog.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\antivirus_d.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\antilog.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\bypass.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable antivirus protection.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable defender and security center notifications.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable defender policies.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable dev drive protection.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable lsa protection.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable maintenance task reporting in security health ui.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable microsoft vulnerabile driver blocklist.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable smartscreen.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable spynet telemetry.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable system mitigations.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable tamper protection.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable uac.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\languages.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\onedrive.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\fonts.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\drvstore_inf.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\remove\defender.txt
  • %TEMP%\~4521441901200345935~\sg.tmp
  • %TEMP%\~6784711813192159767..\changelog.txt
  • %TEMP%\~6784711813192159767..\compact\wimbootcompress.ini
  • %TEMP%\~6784711813192159767..\diskpart\bios.txt
  • %TEMP%\~6784711813192159767..\diskpart\uefi.txt
  • %TEMP%\~6784711813192159767..\diskpart\xp_legacy\bios.txt
  • %TEMP%\~6784711813192159767..\dism\sample.ini
  • %TEMP%\~6784711813192159767..\lang\rc 数据_help.txt
  • %TEMP%\~6784711813192159767..\lang\rc 数据_helpchs.txt
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\add\windows\panther\unattend.xml
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\add\windows\setup\scripts\firstlogon.cmd
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\add\windows\setup\scripts\setupcomplete.cmd
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\disable vbs.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\defender anti-phishing_d.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\antilog.ini
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\disable.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\dusmsvc按流量计费.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\edge禁止自动更新.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\enable_folder_options_for_all_users.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\gamedvr.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\restore_photo_viewer_windows_10.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\shippedwithreserves.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\stuckrects3-win10-200x.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\systray_classicvolumecontrol.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\systray_network_flyout.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\taskbar.reg
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\usersignedin.reg
  • %TEMP%\~4511360528732088972.tmp
  • %TEMP%\~6784711813192159767..\minwin\1_轻度精简-无更新\reg\bypass.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\dusmsvc按流量计费.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\edge禁止自动更新.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\enable_folder_options_for_all_users.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\onedrive.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\programfiles.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\speech.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\system32-dll.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\system32.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\syswow.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\windows.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\windowsapps.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\winsat.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\wuau.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\wuau.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\xbox.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\xbox.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\services.ini
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable maintenance task reporting in security health ui.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\winsxs.ini
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\add\windows\panther\unattend.xml
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\add\windows\setup\scripts\firstlogon.cmd
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\add\windows\setup\scripts\setupcomplete.cmd
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\antilog.ini
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\antilog.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\antivirus_d.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\bypass.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\defender anti-phishing_d.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable antivirus protection.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable defender and security center notifications.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable defender policies.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable dev drive protection.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\languages.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remove startup entries.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\fonts.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remove signature updates.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\exploit guard_d.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\gamedvr.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\lockdown windows defender security center.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\mitigation of fault torelant heap.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\no more delay and timeouts.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\removal of anti-phishing services.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\removal of sechealthui.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\removal of windows defender antivirus.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\removal of windows security action center.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remove defender tasks.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remove security and maintenance.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remove services.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remove shell association.reg
  • %TEMP%\~6784711813192159767..\minwin\3_极限精简-无更新\reg\disable lsa protection.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\defender.txt
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remove windows defender firewall rules.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remove windows webthreat.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\remover of defender context menu.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\restore_photo_viewer_windows_10.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\security health.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\shippedwithreserves.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\stuckrects3-win10-200x.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\systray_classicvolumecontrol.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\systray_network_flyout.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\taskbar.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\usersignedin.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\reg\windows settings page visibility.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\defender.reg
  • %TEMP%\~6784711813192159767..\minwin\2_中度精简-无更新\remove\drvstore_inf.txt
  • %WINDIR%\temp\udd8f35.tmp
Sets the 'hidden' attribute to the following files
  • %TEMP%\~4511360528732088972.tmp
Deletes the following files
  • %TEMP%\~~5074702496660032428.tmp
  • %TEMP%\~4521441901200345935~\sg.tmp
  • %TEMP%\~4511360528732088972.tmp
  • %WINDIR%\temp\udd8f34.tmp
  • %WINDIR%\temp\udd8f35.tmp
Miscellaneous
Searches for the following windows
  • ClassName: 'ComboBox' WindowName: ''
  • ClassName: 'EDIT' WindowName: ''
Creates and executes the following
  • '%TEMP%\~4521441901200345935~\sg.tmp' x "%TEMP%\~4511360528732088972.tmp" -y -aoa -o"%TEMP%\~6784711813192159767.."
  • '%TEMP%\~6784711813192159767..\winntsetup_x64.exe'
  • '<SYSTEM32>\cmd.exe' /c set' (with hidden window)
  • '%TEMP%\~4521441901200345935~\sg.tmp' x "%TEMP%\~4511360528732088972.tmp" -y -aoa -o"%TEMP%\~6784711813192159767.."' (with hidden window)
Restarts the analyzed sample
Executes the following
  • '<SYSTEM32>\cmd.exe' /c set

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android