Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.DownLoader49.11388

Added to the Dr.Web virus database: 2025-11-04

Virus description added:

Technical Information

Modifies file system
Creates the following files
  • %TEMP%\pkg-3qxkwh\5ad24cd4d19ef03079717bd6309fe0604c2a4829cd92788ebf6da95c41d3d28f
  • %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\package.json
  • %TEMP%\pkg-3qxkwh\8d6b400ae7f69a80d0cdd37a968d7b9a913661fa53475e5b8de49dda21684973
  • %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\lib\sqlite3.js
  • %TEMP%\pkg-3qxkwh\762c7a74d7f92860a3873487b68e89f654a21d2aaeae9524eab5de9c65e66a9c
  • %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\lib\sqlite3-binding.js
  • %TEMP%\pkg-3qxkwh\d06caec6136120c6fb7ee3681b1ca949e8b634e747ea8d3080c90f35aeb7728f
  • %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\lib\trace.js
  • %TEMP%\pkg-3qxkwh\b9a7b76665d92af2d90cc6a15ffdc1a79635559cbc1c40bd1f83c4c4449cd442
  • %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\build\release\node_sqlite3.node
  • %TEMP%\pkg-3qxkwh\2de3ef9fc3bad6955f503dc641da2db24626760ce1004fe6929cc5e64737ad35
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\package.json
  • %TEMP%\pkg-3qxkwh\dc6a2239b69829b7d20aeefc9f5540aa69564d0cac476e442afeb030ae64ca07
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\adm-zip.js
  • %TEMP%\pkg-3qxkwh\6bb5b2d4c07d793ca928daa63a8899c6914fafb5ac3aa04ec10cae07f3d57dca
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\license
  • %TEMP%\pkg-3qxkwh\35295fdfb2d8e5316db897f2e8ed61ed5eee8a68044774aba56b118a9a959daf
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\zipentry.js
  • %TEMP%\pkg-3qxkwh\f95d3d6687e5ed959559943380e3bcf61f3e8849286d740afa45dedb28ffa16d
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\zipfile.js
  • %TEMP%\pkg-3qxkwh\7f6a8eec09cadc72e886d44239d5dfea040678327e1e1d1c99a95092aa6e3844
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\build\a.node
  • %TEMP%\pkg-3qxkwh\1d3bfe941be84e8d0d1a7e61c1bb62c89590794c6134ab1e1f8ba7acf9c82375
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\build\addon.node
  • %TEMP%\pkg-3qxkwh\51b343ba48150d1a4b8d7ea3cc5492028f7cf8c8cf60ff0e4d50e322c8c2b5b0
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\build\check.node
  • %TEMP%\pkg-3qxkwh\74da81544ada9a19754da25b2bd7065a57210be47b1df7bb753a2448ff9abca2
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\build\deadlock.node
  • %TEMP%\pkg-3qxkwh\c16c15242145ff83283003b4bba5cf5656a375cef878659222b331a734934bde
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\build\re.node
  • %TEMP%\pkg-3qxkwh\087817541718806bbc4e2a3d68765beb34df1d91189be149e5e2efaf71db4acf
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\build\send.node
  • %TEMP%\pkg-3qxkwh\b6fc4b17ceab96c07d6c14464b95204b1a130d32d845b348a18eefd5633763b1
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\headers\entryheader.js
  • %TEMP%\pkg-3qxkwh\536e4b5bf009a3d9f6eccfbbc4157cb6de663d889e0826ea5f6e5fa17aaeb8bf
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\headers\index.js
  • %TEMP%\pkg-3qxkwh\28dd1a0db451bc94d8f3234e57d8192ba17154118f841c398e0de35acea286ee
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\headers\mainheader.js
  • %TEMP%\pkg-3qxkwh\6dc41b2460594cfa5136b797653c166b2f7403820a40f2fca17cca35a5de1b5f
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\methods\deflater.js
  • %TEMP%\pkg-3qxkwh\d67714f1a04be942f90be77069af3ff4214aa8ee84b26edeff3a87eb0d8e2dc0
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\methods\index.js
  • %TEMP%\pkg-3qxkwh\c5e4531a11385050d77a5069487b0be8e85c8e44fe6b214d68def321e74528ce
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\methods\inflater.js
  • %TEMP%\pkg-3qxkwh\23365c7eda0ea098385dc7ec649517fc110ce2764d2e707c37bf6b528604e25a
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\methods\zipcrypto.js
  • %TEMP%\pkg-3qxkwh\208e943a2e5faad056047f3c7991cce3cde637d8e272a564f2546210ebdf2069
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\util\constants.js
  • %TEMP%\pkg-3qxkwh\73a0ebb00c4dce2124f07acf0b34374cb03a4384cccd1cd6f58aee27c35953d9
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\util\decoder.js
  • %TEMP%\pkg-3qxkwh\d2d243647737c795c2db8aeba2e1f3841d5f76370b521d436cf465322dd4aab7
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\util\errors.js
  • %TEMP%\pkg-3qxkwh\31c93eb386a2bfbf19ad92a6bf20d510a8f1e7e90cc71d33dd888f89da12362d
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\util\fattr.js
  • %TEMP%\pkg-3qxkwh\dc5b230ed853947ea55c0bf69f0e525fbeffefff09aa3da296d541bb8898314e
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\util\index.js
  • %TEMP%\pkg-3qxkwh\a8983582ad5dfa163303d22acd0b0ab3312059a121fb1b377ad41f4a58ed955b
  • %HOMEPATH%\.cache\pkg\04d9faa3c6e7072a00a6894dbe24678d4b728c96f47e2fd01cf822f30b6e609a\adm-zip\util\utils.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\package.json
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\adm-zip.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\license
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\zipentry.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\zipfile.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\build\a.node
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\build\addon.node
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\build\check.node
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\build\deadlock.node
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\build\re.node
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\build\send.node
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\headers\entryheader.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\headers\index.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\headers\mainheader.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\methods\deflater.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\methods\index.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\methods\inflater.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\methods\zipcrypto.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\util\constants.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\util\decoder.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\util\errors.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\util\fattr.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\util\index.js
  • %HOMEPATH%\.cache\pkg\837809b00ff22d773b6db727583f8bc3869fe5e991c994c2e6ffe88180c99603\adm-zip\util\utils.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\package.json
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\adm-zip.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\license
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\zipentry.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\zipfile.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\build\a.node
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\build\addon.node
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\build\check.node
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\build\deadlock.node
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\build\re.node
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\build\send.node
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\headers\entryheader.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\headers\index.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\headers\mainheader.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\methods\deflater.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\methods\index.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\methods\inflater.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\methods\zipcrypto.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\util\constants.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\util\decoder.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\util\errors.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\util\fattr.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\util\index.js
  • %HOMEPATH%\.cache\pkg\d94cc5b3af0cacb9aa68425545cf8920150ffd20c0029b49646c8c704185d855\adm-zip\util\utils.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\package.json
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\adm-zip.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\license
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\zipentry.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\zipfile.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\build\a.node
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\build\addon.node
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\build\check.node
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\build\deadlock.node
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\build\re.node
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\build\send.node
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\headers\entryheader.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\headers\index.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\headers\mainheader.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\methods\deflater.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\methods\index.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\methods\inflater.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\methods\zipcrypto.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\util\constants.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\util\decoder.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\util\errors.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\util\fattr.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\util\index.js
  • %HOMEPATH%\.cache\pkg\afff85868267113c938b5d49e2b404d61fae8fe705675e93a123596f0b6028f5\adm-zip\util\utils.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\package.json
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\adm-zip.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\license
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\zipentry.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\zipfile.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\build\a.node
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\build\addon.node
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\build\check.node
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\build\deadlock.node
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\build\re.node
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\build\send.node
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\headers\entryheader.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\headers\index.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\headers\mainheader.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\methods\deflater.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\methods\index.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\methods\inflater.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\methods\zipcrypto.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\util\constants.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\util\decoder.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\util\errors.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\util\fattr.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\util\index.js
  • %HOMEPATH%\.cache\pkg\cad711ff286b81fde35dbe96790e51ec1014b0c21210435e98bd18cd0cfc2ecd\adm-zip\util\utils.js
  • nul
  • %TEMP%\th1791.tmp
  • %TEMP%\screencapture\screencapture_1.3.2.bat
  • %TEMP%\screencapture\app.manifest
  • %TEMP%\screencapture\csc52c2cfb2bf794063846c1af41294ce56.tmp
  • %TEMP%\res29d1.tmp
  • %TEMP%\screencapture\screencapture_1.3.2.exe
  • %TEMP%\2025104-1124-iokmdq.nypc9.jpg
  • %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\screencapture_1.3.2.exe.log
Deletes following files that it created itself
  • %TEMP%\res29d1.tmp
  • %TEMP%\screencapture\csc52c2cfb2bf794063846c1af41294ce56.tmp
  • %TEMP%\2025104-1124-iokmdq.nypc9.jpg
  • %TEMP%\pkg-3qxkwh\087817541718806bbc4e2a3d68765beb34df1d91189be149e5e2efaf71db4acf
  • %TEMP%\pkg-3qxkwh\1d3bfe941be84e8d0d1a7e61c1bb62c89590794c6134ab1e1f8ba7acf9c82375
  • %TEMP%\pkg-3qxkwh\208e943a2e5faad056047f3c7991cce3cde637d8e272a564f2546210ebdf2069
  • %TEMP%\pkg-3qxkwh\23365c7eda0ea098385dc7ec649517fc110ce2764d2e707c37bf6b528604e25a
  • %TEMP%\pkg-3qxkwh\28dd1a0db451bc94d8f3234e57d8192ba17154118f841c398e0de35acea286ee
  • %TEMP%\pkg-3qxkwh\2de3ef9fc3bad6955f503dc641da2db24626760ce1004fe6929cc5e64737ad35
  • %TEMP%\pkg-3qxkwh\31c93eb386a2bfbf19ad92a6bf20d510a8f1e7e90cc71d33dd888f89da12362d
  • %TEMP%\pkg-3qxkwh\35295fdfb2d8e5316db897f2e8ed61ed5eee8a68044774aba56b118a9a959daf
  • %TEMP%\pkg-3qxkwh\51b343ba48150d1a4b8d7ea3cc5492028f7cf8c8cf60ff0e4d50e322c8c2b5b0
  • %TEMP%\pkg-3qxkwh\536e4b5bf009a3d9f6eccfbbc4157cb6de663d889e0826ea5f6e5fa17aaeb8bf
  • %TEMP%\pkg-3qxkwh\5ad24cd4d19ef03079717bd6309fe0604c2a4829cd92788ebf6da95c41d3d28f
  • %TEMP%\pkg-3qxkwh\6bb5b2d4c07d793ca928daa63a8899c6914fafb5ac3aa04ec10cae07f3d57dca
  • %TEMP%\pkg-3qxkwh\6dc41b2460594cfa5136b797653c166b2f7403820a40f2fca17cca35a5de1b5f
  • %TEMP%\pkg-3qxkwh\73a0ebb00c4dce2124f07acf0b34374cb03a4384cccd1cd6f58aee27c35953d9
  • %TEMP%\pkg-3qxkwh\74da81544ada9a19754da25b2bd7065a57210be47b1df7bb753a2448ff9abca2
  • %TEMP%\pkg-3qxkwh\762c7a74d7f92860a3873487b68e89f654a21d2aaeae9524eab5de9c65e66a9c
  • %TEMP%\pkg-3qxkwh\7f6a8eec09cadc72e886d44239d5dfea040678327e1e1d1c99a95092aa6e3844
  • %TEMP%\pkg-3qxkwh\8d6b400ae7f69a80d0cdd37a968d7b9a913661fa53475e5b8de49dda21684973
  • %TEMP%\pkg-3qxkwh\a8983582ad5dfa163303d22acd0b0ab3312059a121fb1b377ad41f4a58ed955b
  • %TEMP%\pkg-3qxkwh\b6fc4b17ceab96c07d6c14464b95204b1a130d32d845b348a18eefd5633763b1
  • %TEMP%\pkg-3qxkwh\b9a7b76665d92af2d90cc6a15ffdc1a79635559cbc1c40bd1f83c4c4449cd442
  • %TEMP%\pkg-3qxkwh\c16c15242145ff83283003b4bba5cf5656a375cef878659222b331a734934bde
  • %TEMP%\pkg-3qxkwh\c5e4531a11385050d77a5069487b0be8e85c8e44fe6b214d68def321e74528ce
  • %TEMP%\pkg-3qxkwh\d06caec6136120c6fb7ee3681b1ca949e8b634e747ea8d3080c90f35aeb7728f
  • %TEMP%\pkg-3qxkwh\d2d243647737c795c2db8aeba2e1f3841d5f76370b521d436cf465322dd4aab7
  • %TEMP%\pkg-3qxkwh\d67714f1a04be942f90be77069af3ff4214aa8ee84b26edeff3a87eb0d8e2dc0
  • %TEMP%\pkg-3qxkwh\dc5b230ed853947ea55c0bf69f0e525fbeffefff09aa3da296d541bb8898314e
  • %TEMP%\pkg-3qxkwh\dc6a2239b69829b7d20aeefc9f5540aa69564d0cac476e442afeb030ae64ca07
  • %TEMP%\pkg-3qxkwh\f95d3d6687e5ed959559943380e3bcf61f3e8849286d740afa45dedb28ffa16d
Network activity
Connects to
  • 'ap#.#pify.org':443
  • 'ip##pi.com':80
  • 'co##############e-chains.prod.autograph.services.mozaws.net':443
TCP
HTTP GET requests
  • http://ip##pi.com/json/185.93.40.66?fi################
Other
  • 'ap#.#pify.org':443
UDP
  • DNS ASK ap#.#pify.org
  • DNS ASK ip##pi.com
  • DNS ASK mo#####.map.fastly.net
Miscellaneous
Creates and executes the following
  • '%TEMP%\screencapture\screencapture_1.3.2.exe' %TEMP%\2025104-1124-iokmdq.nypc9.jpg
Executes the following
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\screenCapture\screenCapture_1.3.2.bat %TEMP%\2025104-1124-iokmdq.nypc9.jpg
  • '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' \nologo \r:"Microsoft.VisualBasic.dll" \win32manifest:"app.manifest" \out:"screenCapture_1.3.2.exe" "%TEMP%\SCREEN~1\SCREEN~1.BAT"
  • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES29D1.tmp" "%TEMP%\screenCapture\CSC52C2CFB2BF794063846C1AF41294CE56.TMP"
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\screenCapture\screenCapture_1.3.2.bat %TEMP%\2025104-1124-iokmdq.nypc9.jpg' (with hidden window)
  • '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES29D1.tmp" "%TEMP%\screenCapture\CSC52C2CFB2BF794063846C1AF41294CE56.TMP"' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android