Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Click2.64117

Added to the Dr.Web virus database: 2013-08-25

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Classes\WinZipper.rpm\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.lha\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.arj\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.deb\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.z\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.tpz\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.lzh\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.taz\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.vhd\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.hfs\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.dmg\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.squashfs\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.xar\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.swm\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.wim\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.ntfs\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.fat\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.tgz\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.iso\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.cab\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.txz\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.xz\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.zip\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.7z\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.001\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.rar\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.lzma\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.tbz\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.tbz2\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.gzip\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.gz\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.cpio\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.tar\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.bzip2\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
  • [<HKLM>\SOFTWARE\Classes\WinZipper.bz2\shell\open\command] '' = '"%PROGRAM_FILES%\WinZipper\WinZipper.exe" "o" "%1"'
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\winzipersvc] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\WsysSvc] 'Start' = '00000002'
Infects the following executable system files:
  • <SYSTEM32>\msvcr100.dll
  • <SYSTEM32>\msvcp100.dll
Creates the following files on removable media:
  • <Drive name for removable media>:\oui_mem_leak.txt
Malicious functions:
Creates and executes the following:
  • '%PROGRAM_FILES%\WinZipper\dup.exe' -oem:zip -check
  • '%PROGRAM_FILES%\WinZipper\winzipersvc.exe'
  • '%PROGRAM_FILES%\WinZipper\WinZipper.exe' default
  • '%TEMP%\eIntaller\14538E655B034ab2B6B37D8A5A772A13\eXQ.exe' -ptid=newgdp -h -s -p -hp=10 -addr=delta-homes -sc=1 -reg=0 -check=1
  • '%APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\delta-homes.exe' -ptid=newgdp -h -s -p -hp=10 -addr=delta-homes -sc=1 -reg=0 -check=1
  • '%APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\WinZipper.exe' -s -ptid:newgdp
  • '%ALLUSERSPROFILE%\Application Data\eSafe\eGdpSvc.exe' -run
  • '%ALLUSERSPROFILE%\Application Data\eSafe\eGdpSvc.exe'
  • '%PROGRAM_FILES%\WinZipper\winzipersvc.exe' -run -svc:"winzipersvc" -svcdisp:"WinZiper service" -svcdesc:"WinZipper service" -oem:zip -oemver:1.4.8 -softuid:Global\WinZipper{473B1420-2757-4800-A252-6EBD958DE934}WinZipper
  • '%TEMP%\WinZipper\eInstall\eInstall.exe' "-oz" -s -ptid:newgdp
  • '%TEMP%\eIntaller\14538E655B034ab2B6B37D8A5A772A13\eXQ.exe' (downloaded from the Internet)
Executes the following:
  • '<SYSTEM32>\regsvr32.exe' /s "%PROGRAM_FILES%\WinZipper\eshellctx.dll"
Modifies file system :
Creates the following files:
  • %PROGRAM_FILES%\WinZipper\language\en_us\eCompress_lang.ini
  • %PROGRAM_FILES%\WinZipper\language\en_us\install_lang.ini
  • %PROGRAM_FILES%\WinZipper\language\es_es\eCompress_lang.ini
  • %PROGRAM_FILES%\WinZipper\language\es_es\install_lang.ini
  • %PROGRAM_FILES%\WinZipper\image\default\appicon.png
  • %PROGRAM_FILES%\WinZipper\image\default\app_icon.png
  • %PROGRAM_FILES%\WinZipper\image\default\about_bg.png
  • %PROGRAM_FILES%\WinZipper\image\default\additem.png
  • %PROGRAM_FILES%\WinZipper\wz_settings.ini
  • %PROGRAM_FILES%\WinZipper\language\protocol.txt
  • %PROGRAM_FILES%\WinZipper\sqlite3.dll
  • %PROGRAM_FILES%\WinZipper\dup.exe
  • %PROGRAM_FILES%\WinZipper\language\pt_br\eCompress_lang.ini
  • %PROGRAM_FILES%\WinZipper\language\pt_br\install_lang.ini
  • %PROGRAM_FILES%\WinZipper\language\tr_tr\eCompress_lang.ini
  • %PROGRAM_FILES%\WinZipper\language\tr_tr\install_lang.ini
  • %PROGRAM_FILES%\WinZipper\image\default\back.png
  • %PROGRAM_FILES%\WinZipper\image\default\deleteitem.png
  • %PROGRAM_FILES%\WinZipper\image\default\deskbtnbk.png
  • %PROGRAM_FILES%\WinZipper\image\default\combo.png
  • %PROGRAM_FILES%\WinZipper\image\default\combo_skin.png
  • %PROGRAM_FILES%\WinZipper\image\default\folder.png
  • %PROGRAM_FILES%\WinZipper\image\default\footerbg.png
  • %PROGRAM_FILES%\WinZipper\image\default\edit_skin.png
  • %PROGRAM_FILES%\WinZipper\image\default\extractto.png
  • %PROGRAM_FILES%\WinZipper\image\default\browse.png
  • %PROGRAM_FILES%\WinZipper\image\default\button_mid_size.png
  • %PROGRAM_FILES%\WinZipper\image\default\Background_Main.png
  • %PROGRAM_FILES%\WinZipper\image\default\Background_Small_2.png
  • %PROGRAM_FILES%\WinZipper\image\default\checkbox_blank.png
  • %PROGRAM_FILES%\WinZipper\image\default\checkbox_select.png
  • %PROGRAM_FILES%\WinZipper\image\default\cfgclose.png
  • %PROGRAM_FILES%\WinZipper\image\default\change_skin.png
  • %TEMP%\WinZipper\omigazip\WinZipper.exe
  • %TEMP%\WinZipper\omigazip\7z.dll
  • %TEMP%\WinZipper\omigazip\TrayDownloader.exe
  • %TEMP%\WinZipper\omigazip\winzipersvc.exe
  • %TEMP%\WinZipper\omigazip\eshellctx64.dll
  • %TEMP%\WinZipper\omigazip\libpng.dll
  • %TEMP%\WinZipper\omigazip\ebase.dll
  • %TEMP%\WinZipper\omigazip\eshellctx.dll
  • %TEMP%\WinZipper\eInstall\segoeuib.ttf
  • %TEMP%\WinZipper\eInstall\Install\gamelogin.inst
  • %TEMP%\WinZipper\eInstall\language\es_es\install_lang.ini
  • %TEMP%\WinZipper\eInstall\segoeui.ttf
  • %TEMP%\WinZipper\omigazip\dup.exe
  • %TEMP%\WinZipper\omigazip\eUninstall.exe
  • %TEMP%\WinZipper\eInstall\Install\OmigaZip.inst
  • %TEMP%\WinZipper\eInstall\Install\resmgrInstall.inst
  • %TEMP%\WinZipper\omigazip\ouilibnl.dll
  • %PROGRAM_FILES%\WinZipper\libpng.dll
  • %PROGRAM_FILES%\WinZipper\ouilibnl.dll
  • %PROGRAM_FILES%\WinZipper\ebase.dll
  • %PROGRAM_FILES%\WinZipper\7z.dll
  • %PROGRAM_FILES%\WinZipper\TrayDownloader.exe
  • %PROGRAM_FILES%\WinZipper\winzipersvc.exe
  • %PROGRAM_FILES%\WinZipper\WinZipper.exe
  • %PROGRAM_FILES%\WinZipper\eUninstall.exe
  • %TEMP%\WinZipper\eInstall\msvcp100.dll
  • %TEMP%\WinZipper\eInstall\msvcr100.dll
  • %TEMP%\WinZipper\omigazip\sqlite3.dll
  • %TEMP%\WinZipper\eInstall\eInstall.exe
  • %PROGRAM_FILES%\WinZipper\main
  • %PROGRAM_FILES%\WinZipper\eshellctx.dll
  • %PROGRAM_FILES%\WinZipper\segoeui.ttf
  • %PROGRAM_FILES%\WinZipper\segoeuib.ttf
  • %PROGRAM_FILES%\WinZipper\image\default\install_back.png
  • %PROGRAM_FILES%\WinZipper\layout\default\gamelogin.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\install_msgbox.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\error.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\extractpath.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\OmigaZipInstall.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\overwrite.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\languageSelect.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\msgbox.xml
  • %PROGRAM_FILES%\WinZipper\image\default\tobutton1.png
  • %PROGRAM_FILES%\WinZipper\image\default\vscroll.png
  • %PROGRAM_FILES%\WinZipper\image\default\sys_button_restore.PNG
  • %PROGRAM_FILES%\WinZipper\image\default\sys_close.png
  • %PROGRAM_FILES%\WinZipper\layout\default\compresspath.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\compresspwd.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\about.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\brower.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\password.xml
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\softupdate[1].8&uid=<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001&pid=
  • %PROGRAM_FILES%\WinZipper\uninstaller\OmigaZip.inst
  • %ALLUSERSPROFILE%\Start Menu\Programs\WinZipper\Uninstall.lnk
  • %TEMP%\eIntaller\14538E655B034ab2B6B37D8A5A772A13\eXQ.exe
  • %ALLUSERSPROFILE%\Application Data\eSafe\eDelayinfo.edb
  • %TEMP%\eIntaller\14538E655B034ab2B6B37D8A5A772A13\Config.ini
  • %TEMP%\eIntaller\14538E655B034ab2B6B37D8A5A772A13\newtab.crx
  • %PROGRAM_FILES%\WinZipper\layout\default\setting.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\uninstDeskPlus.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\progress.xml
  • %PROGRAM_FILES%\WinZipper\layout\default\rename.xml
  • %PROGRAM_FILES%\WinZipper\style\style.xml
  • %PROGRAM_FILES%\WinZipper\uninstaller\gamelogin.inst
  • %PROGRAM_FILES%\WinZipper\layout\default\uninstOmigaZip.xml
  • %PROGRAM_FILES%\WinZipper\style\install_style.xml
  • %PROGRAM_FILES%\WinZipper\image\default\menu_bkg.png
  • %PROGRAM_FILES%\WinZipper\image\default\menu_item_over.png
  • %PROGRAM_FILES%\WinZipper\image\default\listview_thumb.png
  • %PROGRAM_FILES%\WinZipper\image\default\menubg.png
  • %PROGRAM_FILES%\WinZipper\image\default\pic-error.png
  • %PROGRAM_FILES%\WinZipper\image\default\pic-info.png
  • %PROGRAM_FILES%\WinZipper\image\default\onekeyextract.png
  • %PROGRAM_FILES%\WinZipper\image\default\patch_file_icon.png
  • %PROGRAM_FILES%\WinZipper\image\default\install_check_intermediate.png
  • %PROGRAM_FILES%\WinZipper\image\default\install_check_uncheck.png
  • %PROGRAM_FILES%\WinZipper\image\default\install_button_skin.png
  • %PROGRAM_FILES%\WinZipper\image\default\install_check_checked.png
  • %PROGRAM_FILES%\WinZipper\image\default\listctrl_header_bk.png
  • %PROGRAM_FILES%\WinZipper\image\default\listview_report.png
  • %PROGRAM_FILES%\WinZipper\image\default\install_logo.png
  • %PROGRAM_FILES%\WinZipper\image\default\install_resource.xml
  • %PROGRAM_FILES%\WinZipper\image\default\pic-question.png
  • %PROGRAM_FILES%\WinZipper\image\default\resource.xml
  • %PROGRAM_FILES%\WinZipper\image\default\settingbkg.png
  • %PROGRAM_FILES%\WinZipper\image\default\radio_normal.png
  • %PROGRAM_FILES%\WinZipper\image\default\radio_selected.png
  • %PROGRAM_FILES%\WinZipper\image\default\sys_button_max.PNG
  • %PROGRAM_FILES%\WinZipper\image\default\sys_button_min.PNG
  • %PROGRAM_FILES%\WinZipper\image\default\settingtab.png
  • %PROGRAM_FILES%\WinZipper\image\default\sys_button_close.png
  • %PROGRAM_FILES%\WinZipper\image\default\progressbar_bk.png
  • %PROGRAM_FILES%\WinZipper\image\default\progressbar_image.png
  • %PROGRAM_FILES%\WinZipper\image\default\pic-warning.png
  • %PROGRAM_FILES%\WinZipper\image\default\popup_dialog_bk.png
  • %PROGRAM_FILES%\WinZipper\image\default\pwd_lock.png
  • %PROGRAM_FILES%\WinZipper\image\default\pwd_unlock.png
  • %PROGRAM_FILES%\WinZipper\image\default\progress_bk.png
  • %PROGRAM_FILES%\WinZipper\image\default\progress_meter.png
  • %TEMP%\WinZipper\omigazip\image\default\pic-error.png
  • %TEMP%\WinZipper\omigazip\image\default\pic-info.png
  • %TEMP%\WinZipper\omigazip\image\default\onekeyextract.png
  • %TEMP%\WinZipper\omigazip\image\default\patch_file_icon.png
  • %TEMP%\WinZipper\omigazip\image\default\popup_dialog_bk.png
  • %TEMP%\WinZipper\omigazip\image\default\progressbar_bk.png
  • %TEMP%\WinZipper\omigazip\image\default\pic-question.png
  • %TEMP%\WinZipper\omigazip\image\default\pic-warning.png
  • %TEMP%\WinZipper\omigazip\image\default\listctrl_header_bk.png
  • %TEMP%\WinZipper\omigazip\image\default\listview_report.png
  • %TEMP%\WinZipper\omigazip\image\default\install_check_uncheck.png
  • %TEMP%\WinZipper\omigazip\image\default\install_logo.png
  • %TEMP%\WinZipper\omigazip\image\default\menu_bkg.png
  • %TEMP%\WinZipper\omigazip\image\default\menu_item_over.png
  • %TEMP%\WinZipper\omigazip\image\default\listview_thumb.png
  • %TEMP%\WinZipper\omigazip\image\default\menubg.png
  • %TEMP%\WinZipper\omigazip\image\default\progressbar_image.png
  • %TEMP%\WinZipper\omigazip\image\default\sys_button_min.PNG
  • %TEMP%\WinZipper\omigazip\image\default\sys_button_restore.PNG
  • %TEMP%\WinZipper\omigazip\image\default\sys_button_close.png
  • %TEMP%\WinZipper\omigazip\image\default\sys_button_max.PNG
  • %TEMP%\WinZipper\omigazip\image\default\vscroll.png
  • %TEMP%\WinZipper\omigazip\layout\default\about.xml
  • %TEMP%\WinZipper\omigazip\image\default\sys_close.png
  • %TEMP%\WinZipper\omigazip\image\default\tobutton1.png
  • %TEMP%\WinZipper\omigazip\image\default\pwd_lock.png
  • %TEMP%\WinZipper\omigazip\image\default\pwd_unlock.png
  • %TEMP%\WinZipper\omigazip\image\default\progress_bk.png
  • %TEMP%\WinZipper\omigazip\image\default\progress_meter.png
  • %TEMP%\WinZipper\omigazip\image\default\settingbkg.png
  • %TEMP%\WinZipper\omigazip\image\default\settingtab.png
  • %TEMP%\WinZipper\omigazip\image\default\radio_normal.png
  • %TEMP%\WinZipper\omigazip\image\default\radio_selected.png
  • %TEMP%\WinZipper\omigazip\image\default\appicon.png
  • %TEMP%\WinZipper\omigazip\image\default\app_icon.png
  • %TEMP%\WinZipper\omigazip\image\default\about_bg.png
  • %TEMP%\WinZipper\omigazip\image\default\additem.png
  • %TEMP%\WinZipper\omigazip\image\default\Background_Small_2.png
  • %TEMP%\WinZipper\omigazip\image\default\browse.png
  • %TEMP%\WinZipper\omigazip\image\default\back.png
  • %TEMP%\WinZipper\omigazip\image\default\Background_Main.png
  • %APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\WinZipper.exe
  • %APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\eSafe\eGdpSvc.exe
  • %APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\config.ini
  • %APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\delta-homes.exe
  • %ALLUSERSPROFILE%\Application Data\eSafe\log\eGdpSvc.LOG
  • %TEMP%\WinZipper\omigazip\main
  • %ALLUSERSPROFILE%\Application Data\eSafe\eGdpSvc.exe
  • %TEMP%\installer.7z
  • %TEMP%\WinZipper\omigazip\image\default\button_mid_size.png
  • %TEMP%\WinZipper\omigazip\image\default\folder.png
  • %TEMP%\WinZipper\omigazip\image\default\footerbg.png
  • %TEMP%\WinZipper\omigazip\image\default\edit_skin.png
  • %TEMP%\WinZipper\omigazip\image\default\extractto.png
  • %TEMP%\WinZipper\omigazip\image\default\install_check_checked.png
  • %TEMP%\WinZipper\omigazip\image\default\install_check_intermediate.png
  • %TEMP%\WinZipper\omigazip\image\default\install_back.png
  • %TEMP%\WinZipper\omigazip\image\default\install_button_skin.png
  • %TEMP%\WinZipper\omigazip\image\default\checkbox_blank.png
  • %TEMP%\WinZipper\omigazip\image\default\checkbox_select.png
  • %TEMP%\WinZipper\omigazip\image\default\cfgclose.png
  • %TEMP%\WinZipper\omigazip\image\default\change_skin.png
  • %TEMP%\WinZipper\omigazip\image\default\deleteitem.png
  • %TEMP%\WinZipper\omigazip\image\default\deskbtnbk.png
  • %TEMP%\WinZipper\omigazip\image\default\combo.png
  • %TEMP%\WinZipper\omigazip\image\default\combo_skin.png
  • %TEMP%\WinZipper\omigazip\layout\default\brower.xml
  • %TEMP%\WinZipper\eInstall\image\default\patch_file_icon.png
  • %TEMP%\WinZipper\eInstall\image\default\pic-error.png
  • %TEMP%\WinZipper\eInstall\image\default\install_check_uncheck.png
  • %TEMP%\WinZipper\eInstall\image\default\install_logo.png
  • %TEMP%\WinZipper\eInstall\image\default\pic-warning.png
  • %TEMP%\WinZipper\eInstall\image\default\popup_dialog_bk.png
  • %TEMP%\WinZipper\eInstall\image\default\pic-info.png
  • %TEMP%\WinZipper\eInstall\image\default\pic-question.png
  • %TEMP%\WinZipper\eInstall\image\default\combo_skin.png
  • %TEMP%\WinZipper\eInstall\image\default\edit_skin.png
  • %TEMP%\WinZipper\eInstall\image\default\app_icon.png
  • %TEMP%\WinZipper\eInstall\image\default\change_skin.png
  • %TEMP%\WinZipper\eInstall\image\default\install_check_checked.png
  • %TEMP%\WinZipper\eInstall\image\default\install_check_intermediate.png
  • %TEMP%\WinZipper\eInstall\image\default\install_back.png
  • %TEMP%\WinZipper\eInstall\image\default\install_button_skin.png
  • %TEMP%\WinZipper\eInstall\image\default\progressbar_bk.png
  • %TEMP%\WinZipper\eInstall\layout\default\OmigaZipInstall.xml
  • %TEMP%\WinZipper\eInstall\layout\default\uninstOmigaZip.xml
  • %TEMP%\WinZipper\eInstall\style\install_style.xml
  • %TEMP%\WinZipper\eInstall\layout\default\languageSelect.xml
  • %TEMP%\WinZipper\eInstall\language\pt_br\install_lang.ini
  • %TEMP%\WinZipper\eInstall\language\tr_tr\install_lang.ini
  • %TEMP%\WinZipper\eInstall\language\protocol.txt
  • %TEMP%\WinZipper\eInstall\language\en_us\install_lang.ini
  • %TEMP%\WinZipper\eInstall\image\default\radio_selected.png
  • %TEMP%\WinZipper\eInstall\image\default\sys_close.png
  • %TEMP%\WinZipper\eInstall\image\default\progressbar_image.png
  • %TEMP%\WinZipper\eInstall\image\default\radio_normal.png
  • %TEMP%\WinZipper\eInstall\layout\default\install_msgbox.xml
  • %TEMP%\WinZipper\eInstall\image\default\install_resource.xml
  • %TEMP%\WinZipper\eInstall\layout\default\DeskPlusInstall.xml
  • %TEMP%\WinZipper\eInstall\layout\default\gamelogin.xml
  • %TEMP%\WinZipper\omigazip\layout\default\OmigaZipInstall.xml
  • %TEMP%\WinZipper\omigazip\layout\default\overwrite.xml
  • %TEMP%\WinZipper\omigazip\layout\default\languageSelect.xml
  • %TEMP%\WinZipper\omigazip\layout\default\msgbox.xml
  • %TEMP%\WinZipper\omigazip\layout\default\rename.xml
  • %TEMP%\WinZipper\omigazip\image\default\resource.xml
  • %TEMP%\WinZipper\omigazip\layout\default\password.xml
  • %TEMP%\WinZipper\omigazip\layout\default\progress.xml
  • %TEMP%\WinZipper\omigazip\layout\default\error.xml
  • %TEMP%\WinZipper\omigazip\layout\default\extractpath.xml
  • %TEMP%\WinZipper\omigazip\layout\default\compresspath.xml
  • %TEMP%\WinZipper\omigazip\layout\default\compresspwd.xml
  • %TEMP%\WinZipper\omigazip\image\default\install_resource.xml
  • %TEMP%\WinZipper\omigazip\style\install_style.xml
  • %TEMP%\WinZipper\omigazip\layout\default\gamelogin.xml
  • %TEMP%\WinZipper\omigazip\layout\default\install_msgbox.xml
  • %TEMP%\WinZipper\omigazip\layout\default\setting.xml
  • %TEMP%\WinZipper\omigazip\language\tr_tr\install_lang.ini
  • %TEMP%\WinZipper\omigazip\language\es_es\install_lang.ini
  • %TEMP%\WinZipper\omigazip\language\en_us\install_lang.ini
  • %TEMP%\WinZipper\omigazip\language\pt_br\install_lang.ini
  • %TEMP%\WinZipper\omigazip\uninstaller\OmigaZip.inst
  • %TEMP%\WinZipper\eInstall\main
  • %TEMP%\WinZipper\omigazip\wz_settings.ini
  • %TEMP%\WinZipper\omigazip\uninstaller\gamelogin.inst
  • %TEMP%\WinZipper\omigazip\layout\default\uninstOmigaZip.xml
  • %TEMP%\WinZipper\omigazip\language\protocol.txt
  • %TEMP%\WinZipper\omigazip\style\style.xml
  • %TEMP%\WinZipper\omigazip\layout\default\uninstDeskPlus.xml
  • %TEMP%\WinZipper\omigazip\language\tr_tr\eCompress_lang.ini
  • %TEMP%\WinZipper\omigazip\language\es_es\eCompress_lang.ini
  • %TEMP%\WinZipper\omigazip\language\en_us\eCompress_lang.ini
  • %TEMP%\WinZipper\omigazip\language\pt_br\eCompress_lang.ini
Deletes the following files:
  • %TEMP%\WinZipper\omigazip\image\default\sys_button_min.PNG
  • %TEMP%\WinZipper\omigazip\image\default\sys_button_max.PNG
  • %TEMP%\WinZipper\omigazip\image\default\sys_close.png
  • %TEMP%\WinZipper\omigazip\image\default\sys_button_restore.PNG
  • %TEMP%\WinZipper\omigazip\image\default\sys_button_close.png
  • %TEMP%\WinZipper\omigazip\image\default\resource.xml
  • %TEMP%\WinZipper\omigazip\image\default\radio_selected.png
  • %TEMP%\WinZipper\omigazip\image\default\settingtab.png
  • %TEMP%\WinZipper\omigazip\image\default\settingbkg.png
  • %TEMP%\WinZipper\omigazip\image\default\tobutton1.png
  • %TEMP%\WinZipper\eInstall\segoeuib.ttf
  • %TEMP%\WinZipper\eInstall\segoeui.ttf
  • %TEMP%\WinZipper\eInstall\layout\default\DeskPlusInstall.xml
  • %TEMP%\WinZipper\eInstall\style\install_style.xml
  • %TEMP%\WinZipper\eInstall\msvcr100.dll
  • %TEMP%\WinZipper\eInstall\eInstall.exe
  • %TEMP%\WinZipper\omigazip\image\default\vscroll.png
  • %TEMP%\WinZipper\eInstall\msvcp100.dll
  • %TEMP%\WinZipper\eInstall\main
  • %TEMP%\WinZipper\omigazip\image\default\patch_file_icon.png
  • %TEMP%\WinZipper\omigazip\image\default\onekeyextract.png
  • %TEMP%\WinZipper\omigazip\image\default\pic-info.png
  • %TEMP%\WinZipper\omigazip\image\default\pic-error.png
  • %TEMP%\WinZipper\omigazip\image\default\menu_item_over.png
  • %TEMP%\WinZipper\omigazip\image\default\listview_thumb.png
  • %TEMP%\WinZipper\omigazip\image\default\listview_report.png
  • %TEMP%\WinZipper\omigazip\image\default\menu_bkg.png
  • %TEMP%\WinZipper\omigazip\image\default\menubg.png
  • %TEMP%\WinZipper\omigazip\image\default\pic-question.png
  • %TEMP%\WinZipper\omigazip\image\default\pwd_lock.png
  • %TEMP%\WinZipper\omigazip\image\default\progress_meter.png
  • %TEMP%\WinZipper\omigazip\image\default\radio_normal.png
  • %TEMP%\WinZipper\omigazip\image\default\pwd_unlock.png
  • %TEMP%\WinZipper\omigazip\image\default\progress_bk.png
  • %TEMP%\WinZipper\omigazip\image\default\popup_dialog_bk.png
  • %TEMP%\WinZipper\omigazip\image\default\pic-warning.png
  • %TEMP%\WinZipper\omigazip\image\default\progressbar_image.png
  • %TEMP%\WinZipper\omigazip\image\default\progressbar_bk.png
  • %TEMP%\WinZipper\eInstall\layout\default\gamelogin.xml
  • %TEMP%\WinZipper\eInstall\image\default\pic-info.png
  • %TEMP%\WinZipper\eInstall\image\default\pic-error.png
  • %TEMP%\WinZipper\eInstall\image\default\pic-warning.png
  • %TEMP%\WinZipper\eInstall\image\default\pic-question.png
  • %TEMP%\WinZipper\eInstall\image\default\patch_file_icon.png
  • %TEMP%\WinZipper\eInstall\image\default\install_check_uncheck.png
  • %TEMP%\WinZipper\eInstall\image\default\install_check_intermediate.png
  • %TEMP%\WinZipper\eInstall\image\default\install_resource.xml
  • %TEMP%\WinZipper\eInstall\image\default\install_logo.png
  • %TEMP%\WinZipper\eInstall\image\default\popup_dialog_bk.png
  • %APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\delta-homes.exe
  • %APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\config.ini
  • %APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\WinZipper.exe
  • %APPDATA%\eUpdate\53BEBE48A69E4e879DC1D3846A22527F\eSafe\eGdpSvc.exe
  • %TEMP%\WinZipper\eInstall\image\default\sys_close.png
  • %TEMP%\WinZipper\eInstall\image\default\progressbar_image.png
  • %TEMP%\WinZipper\eInstall\image\default\progressbar_bk.png
  • %TEMP%\WinZipper\eInstall\image\default\radio_selected.png
  • %TEMP%\WinZipper\eInstall\image\default\radio_normal.png
  • %TEMP%\WinZipper\eInstall\language\pt_br\install_lang.ini
  • %TEMP%\WinZipper\eInstall\language\tr_tr\install_lang.ini
  • %TEMP%\WinZipper\eInstall\language\en_us\install_lang.ini
  • %TEMP%\WinZipper\eInstall\language\es_es\install_lang.ini
  • %TEMP%\WinZipper\eInstall\language\protocol.txt
  • %TEMP%\WinZipper\eInstall\layout\default\languageSelect.xml
  • %TEMP%\WinZipper\eInstall\layout\default\install_msgbox.xml
  • %TEMP%\WinZipper\eInstall\layout\default\uninstOmigaZip.xml
  • %TEMP%\WinZipper\eInstall\layout\default\OmigaZipInstall.xml
  • %TEMP%\WinZipper\eInstall\Install\gamelogin.inst
  • %TEMP%\WinZipper\eInstall\image\default\install_back.png
  • %TEMP%\WinZipper\eInstall\image\default\edit_skin.png
  • %TEMP%\WinZipper\eInstall\image\default\install_check_checked.png
  • %TEMP%\WinZipper\eInstall\image\default\install_button_skin.png
  • %TEMP%\WinZipper\eInstall\image\default\combo_skin.png
  • %TEMP%\WinZipper\eInstall\Install\resmgrInstall.inst
  • %TEMP%\WinZipper\eInstall\Install\OmigaZip.inst
  • %TEMP%\WinZipper\eInstall\image\default\change_skin.png
  • %TEMP%\WinZipper\eInstall\image\default\app_icon.png
  • %TEMP%\WinZipper\omigazip\layout\default\error.xml
  • %TEMP%\WinZipper\omigazip\layout\default\compresspwd.xml
  • %TEMP%\WinZipper\omigazip\layout\default\gamelogin.xml
  • %TEMP%\WinZipper\omigazip\layout\default\extractpath.xml
  • %TEMP%\WinZipper\omigazip\layout\default\compresspath.xml
  • %TEMP%\WinZipper\omigazip\style\style.xml
  • %TEMP%\WinZipper\omigazip\style\install_style.xml
  • %TEMP%\WinZipper\omigazip\layout\default\brower.xml
  • %TEMP%\WinZipper\omigazip\layout\default\about.xml
  • %TEMP%\WinZipper\omigazip\layout\default\install_msgbox.xml
  • %TEMP%\WinZipper\omigazip\layout\default\rename.xml
  • %TEMP%\WinZipper\omigazip\layout\default\progress.xml
  • %TEMP%\WinZipper\omigazip\layout\default\uninstDeskPlus.xml
  • %TEMP%\WinZipper\omigazip\layout\default\setting.xml
  • %TEMP%\WinZipper\omigazip\layout\default\password.xml
  • %TEMP%\WinZipper\omigazip\layout\default\msgbox.xml
  • %TEMP%\WinZipper\omigazip\layout\default\languageSelect.xml
  • %TEMP%\WinZipper\omigazip\layout\default\overwrite.xml
  • %TEMP%\WinZipper\omigazip\layout\default\OmigaZipInstall.xml
  • %TEMP%\WinZipper\omigazip\eshellctx.dll
  • %TEMP%\WinZipper\omigazip\ebase.dll
  • %TEMP%\WinZipper\omigazip\eUninstall.exe
  • %TEMP%\WinZipper\omigazip\eshellctx64.dll
  • %TEMP%\WinZipper\omigazip\dup.exe
  • <Drive name for removable media>:\oui_mem_leak.txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\softupdate[1].8&uid=<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001&pid=
  • %TEMP%\WinZipper\omigazip\7z.dll
  • %TEMP%\installer.7z
  • %TEMP%\WinZipper\omigazip\libpng.dll
  • %TEMP%\WinZipper\omigazip\wz_settings.ini
  • %TEMP%\WinZipper\omigazip\WinZipper.exe
  • %TEMP%\WinZipper\omigazip\uninstaller\OmigaZip.inst
  • %TEMP%\WinZipper\omigazip\uninstaller\gamelogin.inst
  • %TEMP%\WinZipper\omigazip\winzipersvc.exe
  • %TEMP%\WinZipper\omigazip\ouilibnl.dll
  • %TEMP%\WinZipper\omigazip\main
  • %TEMP%\WinZipper\omigazip\TrayDownloader.exe
  • %TEMP%\WinZipper\omigazip\sqlite3.dll
  • %TEMP%\WinZipper\omigazip\layout\default\uninstOmigaZip.xml
  • %TEMP%\WinZipper\omigazip\image\default\deskbtnbk.png
  • %TEMP%\WinZipper\omigazip\image\default\deleteitem.png
  • %TEMP%\WinZipper\omigazip\image\default\extractto.png
  • %TEMP%\WinZipper\omigazip\image\default\edit_skin.png
  • %TEMP%\WinZipper\omigazip\image\default\combo_skin.png
  • %TEMP%\WinZipper\omigazip\image\default\checkbox_blank.png
  • %TEMP%\WinZipper\omigazip\image\default\change_skin.png
  • %TEMP%\WinZipper\omigazip\image\default\combo.png
  • %TEMP%\WinZipper\omigazip\image\default\checkbox_select.png
  • %TEMP%\WinZipper\omigazip\image\default\folder.png
  • %TEMP%\WinZipper\omigazip\image\default\install_logo.png
  • %TEMP%\WinZipper\omigazip\image\default\install_check_uncheck.png
  • %TEMP%\WinZipper\omigazip\image\default\listctrl_header_bk.png
  • %TEMP%\WinZipper\omigazip\image\default\install_resource.xml
  • %TEMP%\WinZipper\omigazip\image\default\install_check_intermediate.png
  • %TEMP%\WinZipper\omigazip\image\default\install_back.png
  • %TEMP%\WinZipper\omigazip\image\default\footerbg.png
  • %TEMP%\WinZipper\omigazip\image\default\install_check_checked.png
  • %TEMP%\WinZipper\omigazip\image\default\install_button_skin.png
  • %TEMP%\WinZipper\omigazip\language\es_es\install_lang.ini
  • %TEMP%\WinZipper\omigazip\language\es_es\eCompress_lang.ini
  • %TEMP%\WinZipper\omigazip\language\en_us\install_lang.ini
  • %TEMP%\WinZipper\omigazip\language\en_us\eCompress_lang.ini
  • %TEMP%\WinZipper\omigazip\language\pt_br\install_lang.ini
  • %TEMP%\WinZipper\omigazip\language\tr_tr\eCompress_lang.ini
  • %TEMP%\WinZipper\omigazip\language\protocol.txt
  • %TEMP%\WinZipper\omigazip\language\pt_br\eCompress_lang.ini
  • %TEMP%\WinZipper\omigazip\language\tr_tr\install_lang.ini
  • %TEMP%\WinZipper\omigazip\image\default\about_bg.png
  • %TEMP%\WinZipper\omigazip\image\default\browse.png
  • %TEMP%\WinZipper\omigazip\image\default\Background_Small_2.png
  • %TEMP%\WinZipper\omigazip\image\default\cfgclose.png
  • %TEMP%\WinZipper\omigazip\image\default\button_mid_size.png
  • %TEMP%\WinZipper\omigazip\image\default\Background_Main.png
  • %TEMP%\WinZipper\omigazip\image\default\appicon.png
  • %TEMP%\WinZipper\omigazip\image\default\additem.png
  • %TEMP%\WinZipper\omigazip\image\default\back.png
  • %TEMP%\WinZipper\omigazip\image\default\app_icon.png
Moves the following files:
  • from %PROGRAM_FILES%\WinZipper\segoeuib.ttf to %WINDIR%\Fonts\segoeuib.ttf
  • from %PROGRAM_FILES%\WinZipper\segoeui.ttf to %WINDIR%\Fonts\segoeui.ttf
Deletes itself.
Network activity:
Connects to:
  • 'ap##.#oft365.com':80
  • 'www.tw##ext.com':80
  • 'xa.###gcloud.com':80
  • 'up.##ft365.com':80
TCP:
HTTP GET requests:
  • xa.###gcloud.com/v4/sof-newhpnt/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac#############################
  • www.tw##ext.com/download/res/eXQ.exe
  • xa.###gcloud.com/v4/sof-newhpnt/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac###################################
  • xa.###gcloud.com/v4/sof-newhpnt/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac##############################################################################################################
  • xa.###gcloud.com/v4/sof-newhpnt/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac#########################################
  • ap##.#oft365.com/Inf/browser_pl?co######################################################################################################################################################################################
  • xa.###gcloud.com/v4/sof-newgdp/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac##############################################################
  • up.##ft365.com/gdp/softupdate?pt############################################################################################
  • xa.###gcloud.com/v4/sof-newhpnt/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac###########################################################################
  • xa.###gcloud.com/v4/sof-newhpnt/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac###################################################################
  • xa.###gcloud.com/v4/sof-newgdp/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac##################################################################################################
  • xa.###gcloud.com/v4/sof-zip/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac##########################################################
  • xa.###gcloud.com/v4/sof-newgdp/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac##################################################
  • xa.###gcloud.com/v4/sof-newgdp/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac#####################################################################################################
  • xa.###gcloud.com/v4/sof-zip/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac###################################################################
  • xa.###gcloud.com/v4/sof-zip/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac###########################################################################
  • xa.###gcloud.com/v4/sof-newhpnt/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac##########################################################
  • xa.###gcloud.com/v4/sof-zip/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac############################################################################################################################################
  • up.##ft365.com/gdp/softupdate?pt#########################################################################################
UDP:
  • DNS ASK ap##.#oft365.com
  • DNS ASK www.tw##ext.com
  • DNS ASK xa.###gcloud.com
  • DNS ASK up.##ft365.com

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android