Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Siggen31.55625

Added to the Dr.Web virus database: 2025-09-12

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'sd_notice' = '<Current directory>\SD_Assistant.exe'
Modifies file system
Creates the following files
  • %TEMP%\20250911132319.exe
  • %TEMP%\nsj76be.tmp\nsprocess.dll
  • %WINDIR%\syswow64\helper_dll.dll
  • %ProgramFiles(x86)%\dbillsoft\01.ico
  • %ProgramFiles(x86)%\dbillsoft\02.ico
  • %ProgramFiles(x86)%\dbillsoft\7z.dll
  • %ProgramFiles(x86)%\dbillsoft\7z.exe
  • %ProgramFiles(x86)%\dbillsoft\launcher.exe
  • %APPDATA%\microsoft\windows\start menu\dbillsoft\ôööµë°·¢æ±¿ªæ±èí¼þ£¨êýµç°æ£©.lnk
  • %ProgramFiles(x86)%\dbillsoft\launcher.ini
  • %ProgramFiles(x86)%\dbillsoft\csc.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\01.png
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\7z.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\7z.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\address.ini
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\address_list.ini
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\aenc.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\book9.xlsx
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\audio\qtaudio_windows.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\bearer\qgenericbearer.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\bearer\qnativewifibearer.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\bswjurl.ini
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\certoperate.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\certparamd.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\cgsrz.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\chkchar.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\cosinfo.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\crlparamd.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\crypt\cryp_api.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\cryp_api.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\cssssssign.cer
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\customsdk.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\customsdk71.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\dbmark.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\dbtrans.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\decodecert.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\dmv.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\dpmgjh.ini
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\engine_pkcs11.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\enumusbdevice.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\excelhistory.xls
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\getexinfo.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\getexinfo_v2.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\gexd20.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\gmoperate.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\gmp-6.0.0.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\hzxxbqd_v1.0.doc
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\iconengines\qsvgicon.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\iconv.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\icudt54.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\icuin54.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\icuuc54.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imop.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\jroud.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\jroud.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\jsadaapi.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qdds.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qgif.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qicns.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qico.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qjp2.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qjpeg.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qmng.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qsvg.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qtga.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qtiff.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qwbmp.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\imageformats\qwebp.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\buriedpoint\bc.buriedpoint.plugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\buriedpoint\config\appidconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\buriedpoint\config\buriedpointsetting.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\buriedpoint\config\clientlogconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\configmanager\bc.configmanager.plugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\bc.init.plugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\config\clientlogconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\config\guardtipsettinginfo.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\config\localsoftwarerecordrule.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\config\processconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\config\serverconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\config\sysconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\config\texfiledownloadconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\config\thirdpartyproducts.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\third\aliyun.oss.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\third\icsharpcode.sharpziplib.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\init\third\zprog.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\bc.invoicedata.plugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\allcomconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\clientlogconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\compensateconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\extractdataconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\extractstrategy.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\kpchecksetting.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\showformconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\sysconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\ukeyextractdll.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\ukeyextractdllnew.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\ukeyextractparms.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\config\uploadconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\aenc.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\basicutil.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\bwkpqtver.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\clifecrypt.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\dghost.ini
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\getskppath.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\invoiceinfos.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\invoiceinterface.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\ipclock.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\jsdiskdll.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\msvcr100.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\newsqlite3.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\newtonsoft.json.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\sqlite.interop.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\sqlite.interop.dll.cc
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\themis.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoicedata\third\wxlibrary.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoiceukey\bc.invoiceukey.plugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\invoiceukey\config\authinfo.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\logger\bc.logger.plugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\logger\log4net.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\networkchannel\bc.networkchannel.plugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\networkchannel\config\httpconfig.json
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\sqllite\bc.sqllite.plugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\sqllite\third\sqlite.interop.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\third\aliyun.oss.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\third\newtonsoft.json.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\third\worksafe.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\addins\third\wxgenerator.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\bc.baseform.core.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\bc.basic.util.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\bc.plugin.core.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\bc.plugin.entity.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\config.ini
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\customsdk.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\entityframework.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\entityframework.sqlserver.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\entityframework.sqlserver.xml
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\entityframework.xml
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\fpzs.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\fpzs.exe.config
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\icsharpcode.sharpziplib.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\log4net.config
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\newtonsoft.json.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\system.data.sqlite.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\system.data.sqlite.ef6.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\system.data.sqlite.linq.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\system.data.sqlite.xml
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kjkp\zxing.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kp.chm
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\ukkp.chm
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kpencrypt.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\launcher.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\kp_res2.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\languages\print_zh_cn.qm
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libeay32.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libeay321.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libegl.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libgcc_s_dw2-1.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libglesv2.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libltdl3.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libnisecskf.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libp11.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libstdc++-6.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libswukeyskf.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\libwinpthread-1.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\log4cpp.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\7z.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\7z.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\api_login_handler.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\bw_cookie_helper.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\cef.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\cefpssrst.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\cef_100_percent.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\cef_200_percent.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\cef_extensions.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\config.ini
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\d3dcompiler_43.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\d3dcompiler_47.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\debug.log
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\devtools_resources.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\flag.txt
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\icsharpcode.sharpziplib.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\icudtl.dat
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\jsadaapi.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\jsadahttp.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\libcef.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\libcurl.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\libegl.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\libglesv2.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\libxl.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\cjson.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\esdklogapi.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\huaweisecurec.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\hwcobs.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\hwcobsdlogger.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\libcurl.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\libeay32.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\libesdkobs.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\libssh2.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\libxml2.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\nvds.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\pcre.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\ssleay32.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\hwcobsdlogger\zlibwapi.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\locales\en-gb.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\locales\en-us.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\locales\zh-cn.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\locales\zh-tw.pak
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\logo\lsdkp.html
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\logo\sdkp.html
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\lsdkp.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\mfc90.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\mfc90u.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\mfcm90.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\mfcm90u.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\microsoft.vc90.atl.manifest
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\microsoft.vc90.crt.manifest
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\microsoft.vc90.mfc.manifest
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\msvcm90.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\msvcp90.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\msvcr90.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\natives_blob.bin
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\newtonsoft.json.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\shanghai.tpass
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\snapshot_blob.bin
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\sqlite3.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\sqlite3raw.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\system.data.sqlite.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\upgrade.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\uplibcurl.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\utility.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\widevinecdmadapter.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\wow_helper.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\yy9000.data
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\lsdkp\zip.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\mediaservice\dsengine.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\mediaservice\qtmedia_audioengine.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\midsharedata.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\msvcr71.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\msvcr90.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\multiprecisioncalculation.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\mydll.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\net_util.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\net_util_x.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\helper_exe.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\dbillsoft.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\nisecsslnet.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\nisec_pkcsshell.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\nisec_skp.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\nisec_sksc.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\nisec_skscold.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\nisecinstaller.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\¹ú¼òë°îñ×ü¾öö¤êé¹üàí¹¤¾ßë°¿øåì°æ.exe
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\oaukey.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\ofdcore.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\opengl32sw.dll
  • %TEMP%\nsyda89.tmp
  • %TEMP%\nsddaa9.tmp\system.dll
  • %TEMP%\nsddaa9.tmp\userinfo.dll
  • %ProgramFiles(x86)%\nisec\nisec_cspshell32.dll
  • %ProgramFiles(x86)%\nisec\nisec_cspimpl32.dll
  • %ProgramFiles(x86)%\nisec\nisec_pkcsshell.dll
  • %ProgramFiles(x86)%\nisec\nisec_pkcsimpl.dll
  • %ProgramFiles(x86)%\nisec\nisec_safehelper.dll
  • %ProgramFiles(x86)%\nisec\nisec_ukupdate.dll
  • %ProgramFiles(x86)%\nisec\nisec_ui.dll
  • %ProgramFiles(x86)%\nisec\utility.dll
  • %ProgramFiles(x86)%\nisec\hyperlink.ico
  • %ProgramFiles(x86)%\nisec\uninstall.ico
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\platforms\qwindows.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\playlistformats\qtmultimedia_m3u.dll
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-4226853953-3309226944-3078887307-1000\cbaa2bce874b853762420fd11962e15f_8cf7b530-613e-439b-a8c5-ccfc0e745400
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\plugins\imageconvertor.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\plugins\oesplugin.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\plugins\ofddom.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\plugins\ofdsign.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\plugins\receipttool.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\plugins\imageformats\qsvg.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\position\qtposition_positionpoll.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\printcontrol.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\printcontrol_u.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\printing.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\printlib.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\printsupport\windowsprintersupport.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\process.dat
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\processlock.dat
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qdpt_lib.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qrencode.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qrgenerator.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5core.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5gui.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5multimedia.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5multimediawidgets.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5network.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5opengl.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5positioning.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5printsupport.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5qml.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5quick.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5sensors.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5serialport.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5sql.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5svg.dll
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5webchannel.dll
  • %TEMP%\wrpe6d0.tmp
  • %ProgramFiles(x86)%\dbillsoft\1.1.7.0\qt5webkit.dll
  • %TEMP%\wrpe6d1.tmp
  • %TEMP%\wrpe6e1.tmp
  • %WINDIR%\syswow64\ctplkcs.dll
  • %ProgramFiles%\nisec\nisec_cspshell64.dll
  • %ProgramFiles%\nisec\nisec_cspimpl64.dll
  • %ProgramFiles%\nisec\nisec_pkcsshell.dll
  • %ProgramFiles%\nisec\nisec_pkcsimpl.dll
  • %ProgramFiles%\nisec\nisec_safehelper.dll
  • %ProgramFiles%\nisec\nisec_ui.dll
  • %ProgramFiles%\nisec\utility.dll
Network activity
Connects to
  • 'di#####soft.efapiao.com':443
TCP
Other
  • 'di#####soft.efapiao.com':443
UDP
  • DNS ASK di#####soft.efapiao.com
Miscellaneous
Creates and executes the following
  • '%TEMP%\20250911132319.exe'
  • '%ProgramFiles(x86)%\dbillsoft\1.1.7.0\nisecinstaller.exe' /S
Executes the following
  • '%WINDIR%\syswow64\regsvr32.exe' /s /i NISEC_CSPShell32.dll
  • '<SYSTEM32>\regsvr32.exe' /s /i NISEC_CSPShell64.dll
  • '%WINDIR%\syswow64\net.exe' start WTKeySrv_Name
  • '%WINDIR%\syswow64\net1.exe' start WTKeySrv_Name
  • '%TEMP%\20250911132319.exe' ' (with hidden window)
  • '%WINDIR%\syswow64\net.exe' start WTKeySrv_Name' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android