Trojan.Vundo.Gen
Popis:
|
Trojan
|
Úroveň rizika:
|
Kritický
|
Datum 1. výskytu:
|
Wednesday, April 16, 2008
|
Poskytovatel Softwaru:
|
(neznámá)
|
Stručné informace:
|
Trojan is a seemingly legitimate computer program that has been intentionally designed to disrupt and damage computer activity. Trojans are sometimes used in conjunction with viruses.
|
Odstranění:
|
Tento škodlivý software může být odstraněn pomocí "Spyware
Terminatora"
|
Geogr. rozdělení softwaru "Trojan.Vundo.Gen"
Info o škodlivém softwaru
Zobrazit vše
Detected Items
- Detected Files:
%SYSDIR%\ulxsmfru.dll
MD5: 159AB9E10D8868E8FAF3ACABBD39C1CE Size:68608
%SYSDIR%\kfcomlyn.dll
MD5: A4296892C13621C21D3C21FFB85334D5 Size:90624
%SYSDIR%\nnnmJcaB.dll
MD5: EEA0DE10651F531FE1D404883D1B5F20 Size:37376
%SYSDIR%\ckvo0.dll
MD5: 6BBEFF0C61A738A4140123EBC5169017 Size:85504
MD5: 8D0351A649B5F719983023E31F88B6FE Size:84992
MD5: 9E8AADACD015C1952DD038C34FA51248 Size:85504
MD5: BB03C5D65908018AFB7B7E3DC4ED5DA6 Size:85504
MD5: 5D85307A7DCA16A410AEE337590D11DB Size:85504
MD5: E68579FFF6981A363EE6CF31A1DA30AD Size:85504
MD5: 0C5E995E6D1CF4876A9B983DC1377202 Size:85504
MD5: 3E879434E5381191B7234D7C7C96400C Size:85504
MD5: 50A7E9018126CACA0204B9F71D36E851 Size:85504
MD5: 46CD390CBC6723B61D0449F616C67F45 Size:84992
MD5: CE6E0CD24E280A75B4F44AE99CF70584 Size:85504
MD5: 8EA8E811A761F4F57DA2A4E0301D79E8 Size:85504
and more....
%SYSDIR%\nbisxsfu.dll
MD5: 18AD75A8B21061CF5E33605D2D653A78 Size:83456
%SYSDIR%\amvo0.dll
MD5: F79FCF2CF6765B4F2B68B8ECBD2C7DFB Size:84992
MD5: F03332C90E36193D1E25D0E893946770 Size:84992
MD5: 5BB11A9802D3CEB47B88001C0568AF7F Size:84992
MD5: 544105939E6B256C4DC3493414975BB6 Size:84992
%SYSDIR%\kxjrcule.dll
MD5: E57768E4E2727D0770281E069EBBB194 Size:83456
%SYSDIR%\urqNDTLe.dll
MD5: 37A1E4D78BCF535511C1A75F6B4614EB Size:45568
%SYSDIR%\amvo.exe
MD5: 01F7265A98E6F8FB79D03E12A3530A52 Size:114342
MD5: 407FD304128D4328EFB20CD44B1D7613 Size:88848
%SYSDIR%\ckvo.exe
MD5: 9EFD50F708CD8C8BCD348FC170953F26 Size:90688
MD5: 7128B5A86EB3CAF7614A4C5DD09DD31B Size:90973
MD5: E6E785ED44156032C4DE992F3FEB4C2D Size:91060
%ALLUSERS_APPDATA%\xaxapgba.dll
MD5: 41A029FFBF9B16654FCAD6B9AB4E767A Size:110592
%SYSDIR%\pmsycpts.dll
MD5: 3BE148967F711A6016E1BCF07B295911 Size:93696
%SYSDIR%\kavo.exe
MD5: 7A75F74E0907EE1B6D2278ED101F8F27 Size:102681
MD5: FE33C785C6A11CA798CA7F0CE5212CFA Size:101136
MD5: 9DEB597A80AB24E2D70346AC10A2F983 Size:103318
%SYSDIR%\1025d.dll
MD5: 74E88116645926D0F22FDCD4FB75F0AB Size:20480
%SYSDIR%\tmpD4.tmp.dll
MD5: A980BCAF719EF194541929FDF911A654 Size:67072
%SystemDiskRoot%\m8wafly.com
MD5: F66222644BE732B18EFCD5AD430F0840 Size:131629
%SYSDIR%\iptsokmo.dll
MD5: 1AD38EA40DEDD3B0A57E446472A5FAA1 Size:70144
%SystemDiskRoot%\bpu.exe
MD5: 6868247FB412B72AEF931A5181ED6497 Size:90258
%SYSDIR%\kavo0.dll
MD5: 5E42032FE728E3DD70184B9CFF3113AB Size:165888
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP6\A0001416.exe
MD5: 2C505C06AF88B7B05518A91EAC70E4BA Size:155288
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP93\A0130633.exe
MD5: C6919D4819B6B383DB08E875ADF9BD4F Size:155121
%DESKTOP%\readme.exe
MD5: 45A6D0C222E9E332648C149AAC2367BB Size:99840
%SYSDIR%\etwrhdje.dll
MD5: 1E5093F6EAEBE8D2C6012DA7B8762CDB Size:90384
%SYSDIR%\ckvo0.dll
MD5: 125F1CB04B4E5A64FB4C4C119EC89061 Size:84992
MD5: 9E43E23E4BD83BC7C9950EFF0005C0DF Size:84992
%WINDIR%\TEMP\rundll32.exe
MD5: AFEC0B54B3BB29A1696B321A7AD35008 Size:58368
%SystemDiskRoot%\System Volume Information\_restore{4BD78788-1236-4975-90D5-E3DD0D82F676}\RP147\A0155185.exe
MD5: DDD12A5B57B82D71568E982406F8EEE1 Size:91177
%SYSDIR%\vtUkkkKc.dll
MD5: 000CA732EF5E4785EC8B31A78DE0421E Size:33280
%SYSDIR%\geBqPIbX.dll
MD5: 5978F5E8853C395DFEDABAE8393D47E2 Size:25600
d:\g2pfnid.com
MD5: D775D4AB396BED6DF76C7C72480CF5C9 Size:87297
%SYSDIR%\lcftiyil.dll
MD5: AB9B970A44B51E49B6EFFFFCA9430909 Size:94208
%SYSDIR%\apsquagy.dll
MD5: 52CD146FBF327AC153D8A45A191B3F0C Size:121344
%SystemDiskRoot%\system volume information\_restore{522AA546-BDE3-4168-A439-CC5B83810CC6}\RP138\A0031651.exe
MD5: EAC84D801111DB85AEBF7CB43FF7FD63 Size:100889
%SystemDiskRoot%\My Backup -- 08-05-23 1021PM\Program Files\Ibuhtieh\rmdfyyda.dll
MD5: 6E2BBBA653BD770B1F56D78D7F697684 Size:106496
%SYSDIR%\yvvdhhtn.dll
MD5: 2D2A8AF02423373A1505C997F2FDDFF7 Size:76416
%SYSDIR%\imswfihl.dll
MD5: 5F5773D3E040DD7A7F1C9AAAC9431671 Size:69120
F:\System Volume Information\_restore{C2887983-0AB6-43AD-978C-53D544F11857}\RP80\A0088437.com
MD5: 1B205667B7771DCF4A5A259F6769848C Size:147949
%SYSDIR%\iqcwxvtb.dll
MD5: F903283B204C90E446DCDAF127FE1BFA Size:84688
- Detected Files with variable Filenames:
MD5: 683EA22D8772FDD5394D5D81B5226B9A Size: 129024
%SYSDIR%\wufsvg.dll
%SYSDIR%\qratox.dll
%SYSDIR%\ynlnugmc.dll
%SYSDIR%\gkbcwn.dll
%SYSDIR%\cbvgqmfg.dll
%SYSDIR%\ihzlfe.dll
%SYSDIR%\mysbkt.dll
%SYSDIR%\bcuser.dll
%SYSDIR%\ewmmjsyy.dll
%SYSDIR%\cbcvla.dll
%SYSDIR%\xoedvv.dll
and next 58 variations.
MD5: 378397E45F701452ABDF8FA6451E0149 Size: 72704
%SYSDIR%\qurwyoyl.dll
%SYSDIR%\ayxnxdsm.dll
%SYSDIR%\ovuqywww.dll
%SYSDIR%\hmqxwiwn.dll
%SYSDIR%\vwaqepvq.dll
%SYSDIR%\mhumrgjv.dll
%SYSDIR%\ejrblnou.dll
%SYSDIR%\nufrjbkv.dll
%SYSDIR%\noxskkto.dll
%SYSDIR%\ehsedvpn.dll
%SYSDIR%\mrnuucef.dll
and next 47 variations.
MD5: 0AFDC65A39CFEF12B32E0EB478BB8D94 Size: 102912
%SYSDIR%\mcrfuc.dll
%SYSDIR%\ydkhtkqt.dll
%SYSDIR%\osjabqns.dll
%SYSDIR%\aqsgfj.dll
%SYSDIR%\yponpv.dll
%SYSDIR%\xsyabv.dll
%SYSDIR%\ufbnfl.dll
%SYSDIR%\xtlskq.dll
%SYSDIR%\fxqlkb.dll
%SYSDIR%\bcfbvj.dll
%SYSDIR%\mqints.dll
and next 57 variations.
MD5: 2BE3A9296A14E7DCF761B59F2B11CF85 Size: 85504
%SYSDIR%\ckvo0.dll
%SystemDiskRoot%\System Volume Information\_restore{CFB91EEC-293F-4349-9EDA-93DA9A07AE26}\RP107\A0029849.dll
MD5: 626B95E3F2C3B17A0E4735B918BDF550 Size: 72704
%SYSDIR%\bxtssxbv.dll
%SYSDIR%\govkuctc.dll
%SYSDIR%\hgwijcfp.dll
%SYSDIR%\twfdppoh.dll
%SYSDIR%\ynuxqgdq.dll
%SYSDIR%\fmxhxygn.dll
%SYSDIR%\rmjfaapk.dll
%SYSDIR%\cbhixnrp.dll
%SYSDIR%\etbrcoof.dll
%SYSDIR%\wlfngrcj.dll
%SYSDIR%\jkvjncke.dll
and next 12 variations.
MD5: D6FC7A41994B00A2C075C4AA657E9AD5 Size: 85504
%SystemDiskRoot%\System Volume Information\_restore{5DF4CDFD-197F-427D-A915-E59E45EA702D}\RP178\A0356881.dll
%SystemDiskRoot%\System Volume Information\_restore{5DF4CDFD-197F-427D-A915-E59E45EA702D}\RP178\A0356875.dll
%SystemDiskRoot%\System Volume Information\_restore{5DF4CDFD-197F-427D-A915-E59E45EA702D}\RP178\A0356858.dll
%SYSDIR%\gasretyw0.dll
%SYSDIR%\gasretyw1.dll
%SYSDIR%\gasretyw0.dll.ren
%SystemDiskRoot%\System Volume Information\_restore{2FF60FDC-11E3-4544-8C6D-853A58F6336D}\RP26\A0012274.dll
%SystemDiskRoot%\System Volume Information\_restore{2FF60FDC-11E3-4544-8C6D-853A58F6336D}\RP25\A0012260.dll
MD5: 78465B67AF3CC8AB5C424425DFB8689D Size: 103936
%SYSDIR%\thngvf.dll
%SYSDIR%\ezaqhp.dll
%SYSDIR%\yavxfv.dll
%SYSDIR%\uabracpo.dll
%SYSDIR%\lqxrxk.dll
%SYSDIR%\krgevvem.dll
%SYSDIR%\cojbam.dll
%SYSDIR%\uynrcy.dll
%SYSDIR%\phfldk.dll
%SYSDIR%\zibmtl.dll
%SYSDIR%\gremcl.dll
and next 160 variations.
MD5: BF8CC108E191CE615BB108E1A926CAB0 Size: 68096
%SYSDIR%\htiqxlov.dll
%SYSDIR%\pycuynso.dll
%SYSDIR%\jkulsfvg.dll
%SYSDIR%\nxtjhbab.dll
%SYSDIR%\ffsdjvyx.dll
%SYSDIR%\ujjgkvew.dll
%SYSDIR%\ofoftbkm.dll
%SYSDIR%\qncycqwi.dll
%SYSDIR%\unrdskos.dll
%SYSDIR%\kamoacfv.dll
%SYSDIR%\krfmialp.dll
and next 136 variations.
MD5: 500763B69406DF0271C7488EF57F60E0 Size: 85504
%SYSDIR%\ckvo2.dll
%SYSDIR%\ckvo1.dll
%SYSDIR%\ckvo0.dll
MD5: 03BA9670D27F65129A92C52D4E22F313 Size: 84992
%SYSDIR%\ckvo0.dll
%SYSDIR%\ckvo2.dll
MD5: 2777565E92585B2F43B5948FEBD6BCCC Size: 68608
%SYSDIR%\smbblnlo.dll
%SYSDIR%\mupofndm.dll
%SYSDIR%\wycdpyfl.dll
%SYSDIR%\icqmmstl.dll
%SYSDIR%\payrqdkh.dll
%SYSDIR%\tfcjcqak.dll
%TEMP%\flaxyhde.dll
MD5: 8F66E035B8CC3BD88EFF3A1353B0BC8F Size: 36352
%SYSDIR%\byXPiJbb.dll
%SYSDIR%\fccyyYpQ.dll
%SYSDIR%\xxyyvWNf.dll
%SYSDIR%\vtULccYQ.dll
%SYSDIR%\pmnnKdCT.dll
MD5: FF35BBCFA2897938EC30C81B3C782181 Size: 103936
%SYSDIR%\azwbtk.dll
%SYSDIR%\asusxn.dll
%SYSDIR%\eqwgvn.dll
%SystemDiskRoot%\System Volume Information\_restore{3DBB3491-1B54-4295-9814-C585088556ED}\RP65\A0007708.dll
%SystemDiskRoot%\System Volume Information\_restore{3DBB3491-1B54-4295-9814-C585088556ED}\RP65\A0007706.dll
%SYSDIR%\uwuagulq.dll
%SYSDIR%\kwmpwl.dll
%SYSDIR%\wbdupm.dll
%SYSDIR%\pjuxwuqf.dll
%SYSDIR%\ltkgsr.dll
%SYSDIR%\bqpnhyob.dll
and next 175 variations.
MD5: 05C1A3DD88588E9F7E2FDEA1E97AFC07 Size: 21184
%WINDIR%\m0_glkp_011008.dll
%SYSDIR%\c00768C.mat
%SYSDIR%\c00A4162.mat
%SYSDIR%\c008A40.mat
%SYSDIR%\c00EA24.mat
MD5: D1B3A8133BF416BEBA0CE1445C60859A Size: 129024
%SYSDIR%\aqihmo.dll
%SYSDIR%\wfqrti.dll
%SYSDIR%\vezfpd.dll
%SYSDIR%\stjfvhnq.dll
%SYSDIR%\viccrq.dll
%SYSDIR%\mgycnp.dll
%SYSDIR%\uacbjx.dll
%SYSDIR%\ewteji.dll
%SYSDIR%\xjufkx.dll
%SYSDIR%\ztlpcr.dll
%SYSDIR%\rwgjcuuh.dll
and next 48 variations.
MD5: 4BA37AFDF4AEC72C0E47F87E8FC3601B Size: 129024
%SYSDIR%\ybxcrb.dll
%SYSDIR%\wkzeyi.dll
%SYSDIR%\rmdxjojv.dll
%SYSDIR%\hhzryn.dll
%SYSDIR%\xdjjpnjh.dll
%SYSDIR%\paenmy.dll
%SYSDIR%\buicex.dll
%SYSDIR%\wzqrxx.dll
%SYSDIR%\sxwomz.dll
%SYSDIR%\dgiltu.dll
%SYSDIR%\jrpkrx.dll
and next 42 variations.
MD5: 335E61439DE822FE4672496AAD1E9F63 Size: 129024
%SYSDIR%\pyigzp.dll
%SYSDIR%\udhcqisv.dll
%SYSDIR%\smfnwr.dll
%SYSDIR%\nwyniwna.dll
%SYSDIR%\ggwkqg.dll
%SYSDIR%\nkdnit.dll
%SYSDIR%\amrnqe.dll
%SYSDIR%\uxmnqi.dll
%SYSDIR%\damzqs.dll
%SYSDIR%\pyrppvin.dll
%SYSDIR%\dvykdq.dll
and next 52 variations.
MD5: EBD18B99D87174589948B07ACA2139B0 Size: 124416
%SYSDIR%\hvqcrr.dll
%SYSDIR%\braxjz.dll
%SYSDIR%\wmpsxr.dll
%SYSDIR%\tdxkbqps.dll
%SYSDIR%\hshdxa.dll
%SYSDIR%\euyimwui.dll
%SYSDIR%\ldxfpk.dll
%SYSDIR%\oypcixbk.dll
%SYSDIR%\iybnri.dll
%SystemDiskRoot%\System Volume Information\_restore{7134E910-3D14-47B5-8CC2-C9E4D67645E3}\RP330\A0074319.dll
%SystemDiskRoot%\System Volume Information\_restore{7134E910-3D14-47B5-8CC2-C9E4D67645E3}\RP330\A0074317.dll
and next 120 variations.
MD5: FB2F41E18CC0D06E59998B669F6E863C Size: 136832
%SYSDIR%\yycahy.dll
%SYSDIR%\lhgekv.dll
%SYSDIR%\ydgqqwim.dll
%SYSDIR%\qwpkec.dll
MD5: 962ACDF4C741D32302844EF0B2515DA3 Size: 85504
%SYSDIR%\gasretyw0.dll
%SYSDIR%\gasretyw1.dll
%SystemDiskRoot%\Qoobox\Quarantine\C\WINDOWS\system32\gasretyw1.dll.vir
%SystemDiskRoot%\Qoobox\Quarantine\C\WINDOWS\system32\gasretyw0.dll.vir
%SYSDIR%\gasretyw2.dll
MD5: 32D93EB8F40458E7929FD5E5A4B109A8 Size: 85504
%SYSDIR%\ckvo1.dll
%SYSDIR%\ckvo0.dll
MD5: BCF728FEB342E8114CF5DAB704F7A0AE Size: 87927
%SYSDIR%\ckvo.exe
%SystemDiskRoot%\1rfw8hjr.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP77\A0104329.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP77\A0104291.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0104273.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0103274.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0103250.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0103227.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0102228.com
MD5: 6B79ADDD77B4D5FF29D47D8A7DB907AA Size: 68096
%SystemDiskRoot%\System Volume Information\_restore{3DBB3491-1B54-4295-9814-C585088556ED}\RP65\A0007709.dll
%SystemDiskRoot%\System Volume Information\_restore{3DBB3491-1B54-4295-9814-C585088556ED}\RP65\A0007707.dll
%SYSDIR%\bycdqjop.dll
%SYSDIR%\wgeikmot.dll
%SYSDIR%\jfoqmdns.dll
%SYSDIR%\mmwgbadk.dll
%SYSDIR%\nucmnmww.dll
%SYSDIR%\ywrbbrmo.dll
%SYSDIR%\dirfkmmw.dll
%SYSDIR%\kxdcwbel.dll
%SYSDIR%\wuvsvcuf.dll
and next 53 variations.
MD5: 534E2E5B4CBFAF9A75643C33B8F80142 Size: 101888
%SYSDIR%\rynebxps.dll
%SYSDIR%\rierwr.dll
MD5: 0A30F6ED4CDA24737BFEB64CCE484C18 Size: 102400
%SYSDIR%\rvldyawe.dll
%SYSDIR%\qizryo.dll
MD5: 094A22E01CAC8ADDA80BBBCAEB59B8DE Size: 72704
%SYSDIR%\qqcrqkml.dll
%SYSDIR%\hvbfuyqg.dll
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP660\A0486313.dll
%SYSDIR%\iqkajbdc.dll
%SYSDIR%\atogxnmq.dll
%SYSDIR%\hjvhxact.dll
%SYSDIR%\tamesuhv.dll
%SystemDiskRoot%\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP2260\A0632735.dll
%SystemDiskRoot%\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP2259\A0632590.dll
%SYSDIR%\ytcoevck.dll
%SYSDIR%\wwvqfpop.dll
and next 5 variations.
MD5: D04F6700D2D2D3774C0AF1DA18789510 Size: 72704
%SYSDIR%\hyelndja.dll
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP657\A0483103.dll
%SystemDiskRoot%\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP2259\A0632613.dll
MD5: F7B1FEAC0E830D8F3BF93B0C5165EA10 Size: 84992
%SYSDIR%\ckvo2.dll
%SYSDIR%\ckvo0.dll
MD5: B7A9828A20F848EBE3CA34725E0D73F7 Size: 20480
%SYSDIR%\advpackf.dll
%SYSDIR%\1033g.dll
%SYSDIR%\adpropx.dll
MD5: B7A3266009C5F1CFEB181CA79FAD6041 Size: 73216
%SystemDiskRoot%\System Volume Information\_restore{E1574E75-81F9-4EDA-A62B-38C352371BC1}\RP248\A0411032.dll
%SystemDiskRoot%\System Volume Information\_restore{E1574E75-81F9-4EDA-A62B-38C352371BC1}\RP248\A0411031.dll
%SYSDIR%\hlrlmrkl.dll.vir
%SYSDIR%\kfdtgebm.dll
%SYSDIR%\sdsiodcn.dll
%SYSDIR%\igclffxy.dll
%SystemDiskRoot%\Users\Utilizador\AppData\Local\Temp\yfhhftqp.dll
%SystemDiskRoot%\Users\Utilizador\AppData\Local\Temp\dqorarhk.dll
%SYSDIR%\xbtowtty.dll
%SYSDIR%\mitglcio.dll
%TEMP%\xisoyswt.dll
and next 6 variations.
MD5: BA49495D75B01392E49048BBC9BC44F4 Size: 123904
%SYSDIR%\kmzanl.dll
%SYSDIR%\euwnfu.dll
%SYSDIR%\btgcys.dll
%SYSDIR%\vsxtdm.dll
%SYSDIR%\bibgsh.dll
%SYSDIR%\bfupan.dll
%SYSDIR%\oivlhc.dll
%SYSDIR%\msxuwy.dll
%SYSDIR%\fffyem.dll
%SYSDIR%\tjqpvd.dll
%SYSDIR%\mponli.dll
and next 3 variations.
MD5: 3E0CA43302D03B30087AA6B074F5DAC3 Size: 90556
%SYSDIR%\ckvo.exe
%SystemDiskRoot%\39lpji.com
E:\kk3.bat
d:\System Volume Information\_restore{C54376AB-DBD6-484D-B342-D2C058D77C67}\RP41\A0027752.bat
d:\System Volume Information\_restore{C54376AB-DBD6-484D-B342-D2C058D77C67}\RP40\A0027500.bat
MD5: AA73F64C7E8BC0E1A4CBF1FECBE805A4 Size: 92161
%SYSDIR%\ckvo.exe
d:\ph.com
%SystemDiskRoot%\ph.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP4\A0000160.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP94\A0130674.com
MD5: 93BFB2CBC32B5F810D70B155D41AEF0D Size: 101376
%SYSDIR%\rntyvmci.dll
%SYSDIR%\laomsu.dll
%SYSDIR%\ubzuvv.dll
%SYSDIR%\giuxfdub.dll
%SYSDIR%\feummr.dll
%SYSDIR%\uiedkd.dll
%SYSDIR%\nctlas.dll
%SYSDIR%\unogasej.dll
%SYSDIR%\kjwsdk.dll
%TEMP%\hvibkums.dll
MD5: B0ECC527DD5F74741F8209A83975BA5A Size: 106496
%SYSDIR%\pqknxdxq.dll
%SYSDIR%\vlubvz.dll
MD5: 3820C44B9E984BD55651DDC0675659AE Size: 101888
%SYSDIR%\dedzqa.dll
%SYSDIR%\acdrqdxc.dll
%SYSDIR%\ydyvnclr.dll
%SYSDIR%\iawjis.dll
%SYSDIR%\esrwgoxq.dll
%SYSDIR%\smtlwkuu.dll
%SYSDIR%\oujewbqi.dll
%SYSDIR%\gpnqln.dll
%SYSDIR%\uwnwrx.dll
%SYSDIR%\dhipkkiu.dll
%SYSDIR%\idpgidqk.dll
and next 4 variations.
MD5: 2D4DAB2AF01123E12F175C35F7B6830E Size: 123904
%SYSDIR%\idnszo.dll
%SYSDIR%\cdebiqux.dll
%SYSDIR%\fvngit.dll
%SYSDIR%\mrauvc.dll
%SYSDIR%\pxvpaa.dll
%SYSDIR%\pnofvl.dll
%SYSDIR%\wcimkmqf.dll
%SYSDIR%\lphgva.dll
%SYSDIR%\ivxnqebr.dll
%SYSDIR%\epjnlv.dll
MD5: 2D671547B0C2A8EE46092ADBD7172BAC Size: 118144
%SYSDIR%\amvo.exe
F:\e.com
%SystemDiskRoot%\e.com
MD5: 6258E367CE99F2BFBA20E9F1D466C179 Size: 88935
%SYSDIR%\ckvo.exe
J:\tbm9.bat
%SystemDiskRoot%\Qoobox\Quarantine\C\tbm9.bat.vir
d:\b3b9u.com
%SystemDiskRoot%\b3b9u.com
I:\tbm9.bat
MD5: BB03C5D65908018AFB7B7E3DC4ED5DA6 Size: 85504
%SYSDIR%\ckvo0.dll
%SYSDIR%\ckvo1.dll
MD5: D208F1352DE8BC2DF541BF08060F03B6 Size: 89881
%SystemDiskRoot%\u9dyi.exe
%SYSDIR%\ckvo.exe
d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001996.exe
MD5: 08D43885F798E6A7F3D7A6EEB0AD67CE Size: 92661
%SystemDiskRoot%\mnl6on3.com
d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001993.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP95\A0130657.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP95\A0130646.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP94\A0130640.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP93\A0130637.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP93\A0130634.com
%SYSDIR%\ckvo.exe
d:\mnl6on3.com
MD5: A53AD5492F28BFBFF63305D84DC2A1D9 Size: 85504
%SYSDIR%\ckvo2.dll
%SYSDIR%\ckvo1.dll
%SYSDIR%\ckvo0.dll
%SYSDIR%\ckvo0.dll.ren
%SystemDiskRoot%\System Volume Information\_restore{CFB91EEC-293F-4349-9EDA-93DA9A07AE26}\RP117\A0029991.dll
MD5: 222A3050BB1BEDD083C8E7D4334AA1AD Size: 32768
%SYSDIR%\pmnkLDvw.dll
%SYSDIR%\rqRKBUNF.dll
MD5: 6DD233F2993624CD443568159D9962F6 Size: 125952
%SYSDIR%\utdwtq.dll
%SYSDIR%\krpfyecp.dll
%SYSDIR%\wvgawkph.dll
%SYSDIR%\qhvzly.dll
%SYSDIR%\vbsdib.dll
%SYSDIR%\awfgof.dll
%SYSDIR%\yckmwxia.0ll
%SYSDIR%\abtgws.0ll
%SYSDIR%\vzvffe.dll
%SYSDIR%\eveqdh.dll
%SYSDIR%\pawvhvpq.dll
and next 1 variations.
MD5: 81A75C6812279C69A9A46F6B1E5AAB5F Size: 126464
%SYSDIR%\nkuxqg.dll
%SYSDIR%\mlothakr.dll
%SYSDIR%\skuzcb.dll
%SYSDIR%\krfgeawg.dll
%SYSDIR%\twdvtk.dll
%SYSDIR%\itbacuee.dll
%SYSDIR%\raosev.dll
%SYSDIR%\bfbcuq.dll
%SYSDIR%\vxpwwm.dll
%SYSDIR%\ctwjdz.dll
%SYSDIR%\vutwpbod.dll
and next 3 variations.
MD5: B0344437078AFAFDDFFB766BE67F33F8 Size: 68096
%SYSDIR%\pbmuvotr.dll
%SYSDIR%\rdthyfvo.dll
%SYSDIR%\gdeywvmu.dll
%SYSDIR%\aqamajgr.dll
%SYSDIR%\xdbmkppe.dll
%SYSDIR%\saraawvg.dll
%SYSDIR%\brwalnjd.dll
%SYSDIR%\lsqtbslm.dll
%SYSDIR%\glfcfvvx.dll
%SYSDIR%\bddkkafl.dll
%SYSDIR%\gmkrnwhw.dll
and next 9 variations.
MD5: 90C275F54FFF62636196AAB989B2FD17 Size: 116932
%SYSDIR%\amvo.exe
d:\qxbx9blb.com
%SystemDiskRoot%\qxbx9blb.com
g:\qxbx9blb.com
MD5: AB9D3D1631092C0197E5C93CC595844A Size: 25600
%SYSDIR%\awtqrQjG.dll
%SYSDIR%\wvUnMghh.dll
%SYSDIR%\geBqPFYO.dll
MD5: 08D367454D275EC8D0771ADD80E490F3 Size: 129024
%SYSDIR%\nkftdk.dll
%SYSDIR%\xxdcmb.dll.ren
%SYSDIR%\nxbkow.dll
%SYSDIR%\uvdcax.dll
%SYSDIR%\leiftjti.dll
%SYSDIR%\xxdcmb.dll
%SYSDIR%\kwmvhcvy.dll
%SYSDIR%\erpnee.dll
%SYSDIR%\tshmmj.dll
MD5: 5299679D98B9374C7352EA850B0290CF Size: 84992
%ALLUSERS_APPDATA%\BitDefender\Desktop\Quarantine\ckvo0.dll
%SYSDIR%\ckvo0.dll
MD5: 545A1049BE98D177E114974A81CD0D84 Size: 68608
%SYSDIR%\jcfkeoow.dll
%SYSDIR%\wdgjhftf.dll
%SYSDIR%\cokvwaos.dll
%SYSDIR%\urdwkhdp.dll
%SYSDIR%\dqwkjara.dll
MD5: FB32DA5769114C0B750042A86438D261 Size: 109056
%TEMP%\WhXV.exe
%TEMP%\wbmd.exe
MD5: 5D85307A7DCA16A410AEE337590D11DB Size: 85504
%SYSDIR%\ckvo0.dll
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP150\A0188160.dll
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP150\A0188159.dll
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP149\A0188143.DLL
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP143\A0187278.DLL
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP143\A0187229.DLL
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186229.DLL
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186216.DLL
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186198.DLL
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186181.DLL
%SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186163.DLL
and next 16 variations.
MD5: D084A8247940A772AA9D477E8ECBD0B9 Size: 116972
%SYSDIR%\ckvo.exe
%SystemDiskRoot%\ffojc.com
d:\ffojc.com
MD5: C3FD5D15A081A526C57A931B2CD58F1F Size: 91127
%SystemDiskRoot%\n.com
f:\n.com
e:\n.com
d:\n.com
MD5: 383C05D06A655452D87083E734ABD69D Size: 89407
%SystemDiskRoot%\bpu.exe
d:\bpu.exe
%SystemDiskRoot%\Qoobox\Quarantine\C\bpu.exe.vir
H:\bpu.exe
%SystemDiskRoot%\tyktjfww.exe
%SYSDIR%\ckvo.exe
MD5: 7DD384111EA83FE4079BF5258D8D20CA Size: 32768
%SYSDIR%\vtUommKd.dll
%SYSDIR%\khfFYpnK.dll
%SYSDIR%\cbXnliJC.dll
%SYSDIR%\yayvSiFV.dll
%SYSDIR%\vtUnnlMF.dll
%SYSDIR%\qoMfeebb.dll
ssqRJdCR.dll
%SYSDIR%\ssqRJdCR.dll
%SYSDIR%\yayxwvuV.dll
%SYSDIR%\wvUkIaWo.dll
%SYSDIR%\tuvUomMD.dll
and next 2 variations.
MD5: C4E9C11FD9372284A168E9F733339276 Size: 86528
%APPDATA%\tmpB9.tmp.exe
%TEMP%\tmp7.tmp.exe
MD5: 95307A017BFDE77D937BC24F7C1980F8 Size: 89221
%SYSDIR%\ckvo.exe
%SystemDiskRoot%\Qoobox\Quarantine\C\tyktjfww.exe.vir
d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001995.exe
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0123460.exe
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0123439.exe
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0121437.exe
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0121340.exe
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0121326.exe
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP86\A0121311.exe
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP85\A0121187.exe
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP85\A0121167.exe
and next 3 variations.
MD5: BFF684D8B2D426270AC9D6060721FABD Size: 126464
%SYSDIR%\qnyzes.dll
%SYSDIR%\brvytcbj.dll
%SYSDIR%\uoteixxn.dll
%SYSDIR%\dwvmqx.dll
%SYSDIR%\nucysg.dll
%SYSDIR%\opxliv.dll
%SYSDIR%\txuhci.dll
%SYSDIR%\rkmitews.dll
MD5: 7FE216499F926FB57DD1202A42C17B43 Size: 25600
%USERPROFILE%\Local Settings\Temp\mlJDtQkj.dll
%USERPROFILE%\Local Settings\Temp\vtUlKaWn.dll
%USERPROFILE%\Local Settings\Temp\efcDTJdC.dll
%USERPROFILE%\Local Settings\Temp\khfDuRJc.dll
MD5: EA92A12B98C815E07CEC959C29CC530C Size: 91488
%SYSDIR%\sfqdwslv.dll
%SYSDIR%\ynkhpahg.dll
%SYSDIR%\tjaxkfgq.dll
%SYSDIR%\rffjawof.dll
MD5: 0C5E995E6D1CF4876A9B983DC1377202 Size: 85504
%SYSDIR%\ckvo0.dll
%SystemDiskRoot%\System Volume Information\_restore{7F33CF22-F61B-4A66-9FC0-B4BE67DBCDF1}\RP290\A0203987.DLL
%SYSDIR%\ckvo1.dll
MD5: 3E879434E5381191B7234D7C7C96400C Size: 85504
%SYSDIR%\ckvo0.dll
%SYSDIR%\ckvo2.dll
%SYSDIR%\ckvo1.dll
MD5: C054DAAD7BC4FC1BF5E35DD92388FF60 Size: 147355
%SYSDIR%\kxvo.exe
d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001992.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0102208.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0101235.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP75\A0101220.com
MD5: CFF77ABD3AD8ECC6C9201B19EA2B7400 Size: 123904
%SYSDIR%\povfgq.dll
%SYSDIR%\ramgqmsx.dll
%SYSDIR%\dfpwcr.dll
%SYSDIR%\augejc.dll
%SYSDIR%\eihnmfru.dll
%SYSDIR%\favxvy.dll
%SYSDIR%\iyabrcbl.dll
%SYSDIR%\ywbhoh.dll
%SYSDIR%\xjkmwt.dll
%SYSDIR%\mdrecjpu.dll
%SYSDIR%\mpbiuxwi.dll
and next 0 variations.
MD5: 50A7E9018126CACA0204B9F71D36E851 Size: 85504
%SYSDIR%\ckvo0.dll
%SYSDIR%\ckvo1.dll
MD5: B33BD2F644A371BBD55428AA9E3E9256 Size: 32768
%SYSDIR%\ljJCtuVM.dll
%SYSDIR%\awtrollM.dll
%SYSDIR%\cbXOGvst.dll
%SYSDIR%\tuvULFXQ.dll
%SYSDIR%\tuvSkKAS.dll
MD5: 7128B5A86EB3CAF7614A4C5DD09DD31B Size: 90973
%SYSDIR%\ckvo.exe
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP16\A0005024.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP16\A0004025.com
%SystemDiskRoot%\ph.com
MD5: CE6E0CD24E280A75B4F44AE99CF70584 Size: 85504
%SYSDIR%\ckvo0.dll
%SYSDIR%\ckvo1.dll
%SYSDIR%\ckvo4.dll
%SYSDIR%\ckvo2.dll
%SystemDiskRoot%\System Volume Information\_restore{F5D279F6-9E53-46F9-AAA9-19FE623BBC06}\RP182\A0051615.dll
MD5: D954047F8F849F05A35123D4380D02A6 Size: 89885
d:\xqf.com
%SystemDiskRoot%\xqf.com
J:\3rl3lqbq.bat
J:\xqf.com
F:\xqf.com
d:\System Volume Information\_restore{D27B46AF-6978-4EB4-876D-4F5D26459C8B}\RP96\A0122861.com
d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001997.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP80\A0118733.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP80\A0117747.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP79\A0117733.com
d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP79\A0117711.com
and next 3 variations.
MD5: C9C5B5CDE7120EC38CA5845AA47B505D Size: 128672
d:\g.exe
%SystemDiskRoot%\g.exe
%SYSDIR%\kavo.exe
MD5: 86B51F85BC16D6FF1A8C8C0F718230A8 Size: 123904
%SYSDIR%\yejvvi.dll
%SYSDIR%\cbcjgxbx.dll
%SYSDIR%\lydjpgmc.dll
%SYSDIR%\ceynwu.dll
%SYSDIR%\ruocio.dll
%SYSDIR%\lrwfxt.dll
%SYSDIR%\ytyygmww.dll
%SYSDIR%\puqtbmin.dll
%SYSDIR%\rnbdit.dll
%SYSDIR%\yvhjfd.dll
%SYSDIR%\dxwuai.dll
and next 2 variations.
MD5: 23B01417C46B0C58C5D121C1DA2B0E84 Size: 123904
%SYSDIR%\wcwkanxc.dll
%SYSDIR%\svhggn.dll
%SYSDIR%\lpubsb.dll
%SYSDIR%\vcuegw.dll
%SYSDIR%\lntoubtv.dll
%SYSDIR%\epawqk.dll
MD5: 274F8060F346B9761E22015A3BDE07A2 Size: 123904
%SYSDIR%\voqjqqvv.dll
%SYSDIR%\lfhehn.dll
%SYSDIR%\vwmhqo.dll
%SYSDIR%\tnvjteau.dll
%SYSDIR%\mbeafi.dll
%SYSDIR%\oyqbfg.dll
%SYSDIR%\nuovdwlw.dll
%SYSDIR%\vwcacl.dll
%SYSDIR%\qhpxdt.dll
%SYSDIR%\wggqzl.dll
%SYSDIR%\nybioc.dll
and next 12 variations.
MD5: DEB3F548D649223AB7283B525D7DC3EA Size: 123904
%SYSDIR%\smwbrn.dll
%SYSDIR%\lvhayilo.dll
%SYSDIR%\niunwgeo.dll
%SYSDIR%\cnckxw.dll
%SYSDIR%\jyykvd.dll
%SYSDIR%\svkohwyu.dll
%SYSDIR%\gfwwbf.dll
%SYSDIR%\nsgajy.dll
%SYSDIR%\mrjtnitd.dll
%SYSDIR%\jembtpmp.dll
%SYSDIR%\fgzoqi.dll
and next 4 variations.
MD5: C8175D7976F4FAF6C850756BFBD4B721 Size: 123904
%SYSDIR%\nywqcu.dll
%SYSDIR%\dvsljrif.dll
%SYSDIR%\vactixju.dll
%SYSDIR%\bxijhd.dll
%SYSDIR%\mwqkai.dll
%SYSDIR%\ixwtfhpk.dll
%SYSDIR%\nxcram.dll
%SYSDIR%\buqhwo.dll
%TEMP%\nqgsyabj.dll
%SYSDIR%\wfrkxmaw.dll
%SYSDIR%\fjtuzu.dll
MD5: C4A55A4047E04AA171B15C2F76B3DA0A Size: 71680
%SYSDIR%\jiaaoqgi.dll
%SYSDIR%\fbvuvlye.dll
%SYSDIR%\skucumyg.dll
%SYSDIR%\ccxdblyr.dll
%TEMP%\ibmksghc.dll
MD5: 0808BFDFAB50B4E4A86147C15A830EBD Size: 123904
%SYSDIR%\atymbm.dll
%SYSDIR%\apimdjfi.dll
%SYSDIR%\iczvat.dll
%SYSDIR%\bhvximks.dll
%SYSDIR%\lljcvb.dll
%SYSDIR%\jxcysf.dll
%SYSDIR%\gzfyuz.dll
%SYSDIR%\mupnoudf.dll
%SYSDIR%\prwpjc.dll
%SYSDIR%\nwiptuya.dll
%SYSDIR%\kntbyj.dll
and next 3 variations.
MD5: D6A81A78343300329DC0AEA9F0AF2DFD Size: 133120
%SYSDIR%\hszctk.dll
%TEMP%\INF83C.tmp
%TEMP%\INF83B.tmp
%TEMP%\INF838.tmp
%SYSDIR%\zhsyxr.dll
%SYSDIR%\hzeaps.0ll
%SYSDIR%\fykaptdy.0ll
%SYSDIR%\jvjpzu.dll
%SYSDIR%\hhdhyesp.dll
MD5: 5BD117438337E0B336B62CAC729AEBA9 Size: 67584
%SYSDIR%\jdeqolej.dll
%SYSDIR%\skrqduqx.dll
MD5: 320DDC363C7D9AD8243753FB09871FC1 Size: 72704
%SYSDIR%\laptpxrx.dll
%SYSDIR%\sxccowvg.dll
%SystemDiskRoot%\System Volume Information\_restore{3E507D8D-7122-4242-94EB-326CB4914499}\RP210\A0032621.dll
MD5: F7816A6DABA8A7EF466E31635956ACB0 Size: 132096
%SYSDIR%\qorzln.dll
%SYSDIR%\mfvwjn.dll
%SYSDIR%\gmabwatr.dll
%SYSDIR%\cibbwf.dll
%SYSDIR%\qxabpgar.dll
%SYSDIR%\okyiqy.dll
%SYSDIR%\okmsfukw.dll
%SYSDIR%\ykcbcu.dll
MD5: E6E785ED44156032C4DE992F3FEB4C2D Size: 91060
%SYSDIR%\ckvo.exe
F:\c9hehpa.bat
e:\c9hehpa.bat
%SystemDiskRoot%\c9hehpa.bat
MD5: 6F6D8988141EC0930774F6D7BE4D97FB Size: 84992
%SYSDIR%\ckvo0.dll
%SYSDIR%\ckvo1.dll
%SYSDIR%\ckvo2.dll
MD5: 0D580BC9B5EEE40911C11CBB0A887A48 Size: 101888
%SYSDIR%\ybvnqx.dll
%SYSDIR%\sqhbfaqa.dll
%SYSDIR%\qctprb.dll
MD5: 4DE1E3FB934BB82FB651FEAC0412A827 Size: 132608
%SYSDIR%\asacnf.dll
%SYSDIR%\xatnry.dll
%SYSDIR%\mcenff.dll
%SYSDIR%\bbtrul.dll
%SYSDIR%\knaiba.dll
%SYSDIR%\cinvxrys.dll
%SYSDIR%\dkipca.dll
MD5: 4C9B154E86FC60078354AA376499C1DD Size: 20480
%SYSDIR%\accwizd.dll
%SYSDIR%\1031f.dll
%SYSDIR%\adsnwe.dll
%SYSDIR%\18u.dll
MD5: D0A52BEEF6E40C9FE6AF13941FBD854E Size: 81408
%SYSDIR%\mureemwo.dll
%SYSDIR%\serkmfoe.dll
%SYSDIR%\nednuniu.dll
MD5: 550288EE775B4483E044BBB6BE84A1DD Size: 91136
%SYSDIR%\rmopdqya.dll
%SYSDIR%\onivcufw.dll
%SYSDIR%\gnsrguop.dll
%SYSDIR%\dafwgcpg.dll
MD5: 957647673CC2CBB6EFCCBB4E87D00E24 Size: 71680
%SYSDIR%\jkagtjve.dll
%SYSDIR%\bkdgnqvj.dll
MD5: 7E91F4B17383DFB2DC84DC0B7F319B61 Size: 89828
%SystemDiskRoot%\ph.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP18\A0006573.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0006391.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0006381.com
d:\ph.com
f:\ph.com
e:\ph.com
MD5: 81D10E5406B607A3AE6E85CA2A140860 Size: 90366
%SystemDiskRoot%\mnl6on3.com
%SYSDIR%\ckvo.exe
f:\mnl6on3.com
MD5: 39A3D26DE0D3523157843BF1C007D01D Size: 89901
G:\t1ypkh.exe
%SYSDIR%\ckvo.exe
MD5: 37811FA88DDB17B475B81777192DA338 Size: 102912
%SYSDIR%\stdajwrx.dll
%SYSDIR%\mdmgsm.dll
MD5: D4E1BC0883BD41476E3FEFB958E74D57 Size: 102400
%SYSDIR%\olqlfdhe.dll
%SYSDIR%\jrirdf.dll
MD5: 72B36AE2E856BC9FE296195F197E76FB Size: 152892
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP6\A0001407.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP6\A0000261.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP5\A0000210.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP5\A0000192.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP4\A0000095.com
MD5: 62BBA7E02BE61DDFEC9A29C7E973CEC7 Size: 89370
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0005245.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0005110.com
d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0005064.com
F:\ph.com
%SystemDiskRoot%\ph.com
MD5: 5716AA229C533F6A079008B6CFDA6D82 Size: 85504
%SYSDIR%\ckvo0.dll
%SYSDIR%\ckvo1.dll
%SYSDIR%\ckvo4.dll
%SystemDiskRoot%\System Volume Information\_restore{CFB91EEC-293F-4349-9EDA-93DA9A07AE26}\RP106\A0029701.dll
%SYSDIR%\ckvo2.dll
MD5: 3F7DCF854D4E1E81A36243B7BE9522E3 Size: 133120
%SYSDIR%\ylptie.dll
%SYSDIR%\ixhvargo.dll
%SYSDIR%\hrwqpa.dll
%SYSDIR%\fmrgky.dll
%SYSDIR%\skhskafj.dll
%SYSDIR%\dtuwfg.dll
%SYSDIR%\hpyihg.dll
%SYSDIR%\fhhryr.dll
MD5: 3A51285482EA4B38DCB837CAD5C8D903 Size: 67584
%SYSDIR%\girvsppf.dll
%SYSDIR%\kljlanqb.dll
%USERPROFILE%\Configuracin local\Archivos temporales de Internet\Content.IE5\TK0ZX1G1\upd105320[2]
MD5: FE0C5710BA1A41981D9E0D548B268D83 Size: 25600
E:\WINDOWS\system32\yaywtQih.dll
%SYSDIR%\ssqNHbAp.dll
%SYSDIR%\ddcYsSIb.dll
%SYSDIR%\wvUkhFwv.dll
MD5: F12626416506027B2CE0360C66FAEBCD Size: 85504
%SYSDIR%\ckvo1.dll
%SYSDIR%\ckvo0.dll
MD5: 6094D0AE8E2623A77A3B5C614824E25D Size: 81408
h:\WINDOWS\system32\bogvxedx.dll
h:\Documents and Settings\mesut\Local Settings\Temporary Internet Files\Content.IE5\KQ2CQFNW\kb678031[1]
MD5: 2D400B0F6E32FFF7493E5A8291297311 Size: 91973
%SystemDiskRoot%\System Volume Information\_restore{4BD78788-1236-4975-90D5-E3DD0D82F676}\RP150\A0156379.exe
%SystemDiskRoot%\bwpncb6.com
MD5: 544105939E6B256C4DC3493414975BB6 Size: 84992
%SYSDIR%\amvo0.dll
%SYSDIR%\amvo2.dll
MD5: EEF0E5EDF16D51408C5BF82A6A3F811F Size: 128512
%SYSDIR%\fxfiuvjw.dll
%SYSDIR%\gjlqqvrk.dll
MD5: 26D687CAC768A20ED56445E17766F0EF Size: 35328
k:\WINDOWS\system32\vtUnoNeB.dll
k:\WINDOWS\system32\vtUkljHB.dll
k:\WINDOWS\system32\pmnlifCs.dll
k:\WINDOWS\system32\nnnllKEx.dll
k:\WINDOWS\system32\jkkKcDWp.dll
k:\WINDOWS\system32\efcCUMdd.dll
%SYSDIR%\xxyWQIbX.dll
%SYSDIR%\qoMdCsPG.dll
%SYSDIR%\efcApOIC.dll
%SYSDIR%\opnmMebx.dll
%SYSDIR%\yaywvtuv.dll
and next 16 variations.
MD5: 14DA76D202D72165C6D39565F766507A Size: 85504
%SYSDIR%\ckvo2.dll
F:\WINDOWS\system32\ckvo0.dll
MD5: DDC8FCE34DD562A872BA1B934B531198 Size: 133120
%SYSDIR%\cikkgx.dll
%SYSDIR%\sltimg.dll
%SYSDIR%\dlmfqahm.dll
%SYSDIR%\pvzsoi.dll
%SYSDIR%\ourdhe.dll
%SYSDIR%\mddlnb.dll
MD5: 4FDED626888767077918FDA8598ECEC1 Size: 94208
%SYSDIR%\pkkxajss.dll
%SYSDIR%\ofbebaqr.dll
MD5: AA83F3D32ADDCBBD973143A1D739D709 Size: 67584
%SYSDIR%\igqqaoil.dll
%TEMP%\vsujpgjk.dll
%TEMP%\jedrrvnx.dll
MD5: FB552527400A926FFFEE06DCF57E7547 Size: 25600
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1449\A0079181.dll
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078477.dll
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078469.dll
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078468.dll
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078466.dll
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078464.dll
%SYSDIR%\efcBsSmN.dll
%SYSDIR%\fccaYonO.dll
MD5: 5E4D611583C4EDACD28A8C9493414FB4 Size: 34304
%SYSDIR%\ddCTjjjk.dll
%SYSDIR%\ddcYOgFu.dll
MD5: BD5E964D4D5373D68A109DCD0F81E5EF Size: 34304
%SYSDIR%\rqroNDvw.dll
%SYSDIR%\opNgEtTL.dll
%SYSDIR%\mljkJcbY.dll
Detecting items list:
- Files by Name
%WINDIR%\qonnlk.dll
%APPDATA%\tmp167.tmp.exe
%APPDATA%\tmp16C.tmp.exe
%SYSDIR%\tmp16C.tmp.dll
- Files by MD5
MD5: EFAB714C69B5A220206878CAB0AD5712 Size: 33280
MD5: 46D1E68DD295D836D641EC2BD9FAAFFC Size: 318560
MD5: 812A0433D4D1FAAA89EB97B249337D3D Size: 318048
MD5: 649022D9431DF93755A8E42ABD51CFDE Size: 300640
MD5: 6414F01D165BEF6772DC449C27C990D1 Size: 319584
MD5: 2C65DAFB3AA30F9B0B913F4F65D824D9 Size: 311392
MD5: 0B8A2C469527586F6FD16605F470BA65 Size: 85056
MD5: D9D5E14258F17A3EF35028E8D3AB0FCD Size: 78400
MD5: AF48872EC4DBB1B1FE6D36C12342FB1B Size: 34304
MD5: 90AE40BB48B0F258A14F9643C2AAE688 Size: 316000
- Files by CLSID or Name
CLSID=89AD4D75-2429-462e-BD4E-443F233F6033
«
Jít do Databáze softwaru