Trojan.Vundo.Gen

Popis: Trojan
Úroveň rizika: Kritický
Datum 1. výskytu: Wednesday, April 16, 2008
Poskytovatel Softwaru: (neznámá)
Stručné informace: Trojan is a seemingly legitimate computer program that has been intentionally designed to disrupt and damage computer activity. Trojans are sometimes used in conjunction with viruses.
Odstranění: Tento škodlivý software může být odstraněn pomocí "Spyware Terminatora"

Geogr. rozdělení softwaru "Trojan.Vundo.Gen"

Info o škodlivém softwaru

Zobrazit vše

Detected Items

  1. Detected Files: %SYSDIR%\ulxsmfru.dll MD5: 159AB9E10D8868E8FAF3ACABBD39C1CE Size:68608 %SYSDIR%\kfcomlyn.dll MD5: A4296892C13621C21D3C21FFB85334D5 Size:90624 %SYSDIR%\nnnmJcaB.dll MD5: EEA0DE10651F531FE1D404883D1B5F20 Size:37376 %SYSDIR%\ckvo0.dll MD5: 6BBEFF0C61A738A4140123EBC5169017 Size:85504 MD5: 8D0351A649B5F719983023E31F88B6FE Size:84992 MD5: 9E8AADACD015C1952DD038C34FA51248 Size:85504 MD5: BB03C5D65908018AFB7B7E3DC4ED5DA6 Size:85504 MD5: 5D85307A7DCA16A410AEE337590D11DB Size:85504 MD5: E68579FFF6981A363EE6CF31A1DA30AD Size:85504 MD5: 0C5E995E6D1CF4876A9B983DC1377202 Size:85504 MD5: 3E879434E5381191B7234D7C7C96400C Size:85504 MD5: 50A7E9018126CACA0204B9F71D36E851 Size:85504 MD5: 46CD390CBC6723B61D0449F616C67F45 Size:84992 MD5: CE6E0CD24E280A75B4F44AE99CF70584 Size:85504 MD5: 8EA8E811A761F4F57DA2A4E0301D79E8 Size:85504 and more.... %SYSDIR%\nbisxsfu.dll MD5: 18AD75A8B21061CF5E33605D2D653A78 Size:83456 %SYSDIR%\amvo0.dll MD5: F79FCF2CF6765B4F2B68B8ECBD2C7DFB Size:84992 MD5: F03332C90E36193D1E25D0E893946770 Size:84992 MD5: 5BB11A9802D3CEB47B88001C0568AF7F Size:84992 MD5: 544105939E6B256C4DC3493414975BB6 Size:84992 %SYSDIR%\kxjrcule.dll MD5: E57768E4E2727D0770281E069EBBB194 Size:83456 %SYSDIR%\urqNDTLe.dll MD5: 37A1E4D78BCF535511C1A75F6B4614EB Size:45568 %SYSDIR%\amvo.exe MD5: 01F7265A98E6F8FB79D03E12A3530A52 Size:114342 MD5: 407FD304128D4328EFB20CD44B1D7613 Size:88848 %SYSDIR%\ckvo.exe MD5: 9EFD50F708CD8C8BCD348FC170953F26 Size:90688 MD5: 7128B5A86EB3CAF7614A4C5DD09DD31B Size:90973 MD5: E6E785ED44156032C4DE992F3FEB4C2D Size:91060 %ALLUSERS_APPDATA%\xaxapgba.dll MD5: 41A029FFBF9B16654FCAD6B9AB4E767A Size:110592 %SYSDIR%\pmsycpts.dll MD5: 3BE148967F711A6016E1BCF07B295911 Size:93696 %SYSDIR%\kavo.exe MD5: 7A75F74E0907EE1B6D2278ED101F8F27 Size:102681 MD5: FE33C785C6A11CA798CA7F0CE5212CFA Size:101136 MD5: 9DEB597A80AB24E2D70346AC10A2F983 Size:103318 %SYSDIR%\1025d.dll MD5: 74E88116645926D0F22FDCD4FB75F0AB Size:20480 %SYSDIR%\tmpD4.tmp.dll MD5: A980BCAF719EF194541929FDF911A654 Size:67072 %SystemDiskRoot%\m8wafly.com MD5: F66222644BE732B18EFCD5AD430F0840 Size:131629 %SYSDIR%\iptsokmo.dll MD5: 1AD38EA40DEDD3B0A57E446472A5FAA1 Size:70144 %SystemDiskRoot%\bpu.exe MD5: 6868247FB412B72AEF931A5181ED6497 Size:90258 %SYSDIR%\kavo0.dll MD5: 5E42032FE728E3DD70184B9CFF3113AB Size:165888 d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP6\A0001416.exe MD5: 2C505C06AF88B7B05518A91EAC70E4BA Size:155288 d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP93\A0130633.exe MD5: C6919D4819B6B383DB08E875ADF9BD4F Size:155121 %DESKTOP%\readme.exe MD5: 45A6D0C222E9E332648C149AAC2367BB Size:99840 %SYSDIR%\etwrhdje.dll MD5: 1E5093F6EAEBE8D2C6012DA7B8762CDB Size:90384 %SYSDIR%\ckvo0.dll MD5: 125F1CB04B4E5A64FB4C4C119EC89061 Size:84992 MD5: 9E43E23E4BD83BC7C9950EFF0005C0DF Size:84992 %WINDIR%\TEMP\rundll32.exe MD5: AFEC0B54B3BB29A1696B321A7AD35008 Size:58368 %SystemDiskRoot%\System Volume Information\_restore{4BD78788-1236-4975-90D5-E3DD0D82F676}\RP147\A0155185.exe MD5: DDD12A5B57B82D71568E982406F8EEE1 Size:91177 %SYSDIR%\vtUkkkKc.dll MD5: 000CA732EF5E4785EC8B31A78DE0421E Size:33280 %SYSDIR%\geBqPIbX.dll MD5: 5978F5E8853C395DFEDABAE8393D47E2 Size:25600 d:\g2pfnid.com MD5: D775D4AB396BED6DF76C7C72480CF5C9 Size:87297 %SYSDIR%\lcftiyil.dll MD5: AB9B970A44B51E49B6EFFFFCA9430909 Size:94208 %SYSDIR%\apsquagy.dll MD5: 52CD146FBF327AC153D8A45A191B3F0C Size:121344 %SystemDiskRoot%\system volume information\_restore{522AA546-BDE3-4168-A439-CC5B83810CC6}\RP138\A0031651.exe MD5: EAC84D801111DB85AEBF7CB43FF7FD63 Size:100889 %SystemDiskRoot%\My Backup -- 08-05-23 1021PM\Program Files\Ibuhtieh\rmdfyyda.dll MD5: 6E2BBBA653BD770B1F56D78D7F697684 Size:106496 %SYSDIR%\yvvdhhtn.dll MD5: 2D2A8AF02423373A1505C997F2FDDFF7 Size:76416 %SYSDIR%\imswfihl.dll MD5: 5F5773D3E040DD7A7F1C9AAAC9431671 Size:69120 F:\System Volume Information\_restore{C2887983-0AB6-43AD-978C-53D544F11857}\RP80\A0088437.com MD5: 1B205667B7771DCF4A5A259F6769848C Size:147949 %SYSDIR%\iqcwxvtb.dll MD5: F903283B204C90E446DCDAF127FE1BFA Size:84688
  2. Detected Files with variable Filenames: MD5: 683EA22D8772FDD5394D5D81B5226B9A Size: 129024 %SYSDIR%\wufsvg.dll %SYSDIR%\qratox.dll %SYSDIR%\ynlnugmc.dll %SYSDIR%\gkbcwn.dll %SYSDIR%\cbvgqmfg.dll %SYSDIR%\ihzlfe.dll %SYSDIR%\mysbkt.dll %SYSDIR%\bcuser.dll %SYSDIR%\ewmmjsyy.dll %SYSDIR%\cbcvla.dll %SYSDIR%\xoedvv.dll and next 58 variations. MD5: 378397E45F701452ABDF8FA6451E0149 Size: 72704 %SYSDIR%\qurwyoyl.dll %SYSDIR%\ayxnxdsm.dll %SYSDIR%\ovuqywww.dll %SYSDIR%\hmqxwiwn.dll %SYSDIR%\vwaqepvq.dll %SYSDIR%\mhumrgjv.dll %SYSDIR%\ejrblnou.dll %SYSDIR%\nufrjbkv.dll %SYSDIR%\noxskkto.dll %SYSDIR%\ehsedvpn.dll %SYSDIR%\mrnuucef.dll and next 47 variations. MD5: 0AFDC65A39CFEF12B32E0EB478BB8D94 Size: 102912 %SYSDIR%\mcrfuc.dll %SYSDIR%\ydkhtkqt.dll %SYSDIR%\osjabqns.dll %SYSDIR%\aqsgfj.dll %SYSDIR%\yponpv.dll %SYSDIR%\xsyabv.dll %SYSDIR%\ufbnfl.dll %SYSDIR%\xtlskq.dll %SYSDIR%\fxqlkb.dll %SYSDIR%\bcfbvj.dll %SYSDIR%\mqints.dll and next 57 variations. MD5: 2BE3A9296A14E7DCF761B59F2B11CF85 Size: 85504 %SYSDIR%\ckvo0.dll %SystemDiskRoot%\System Volume Information\_restore{CFB91EEC-293F-4349-9EDA-93DA9A07AE26}\RP107\A0029849.dll MD5: 626B95E3F2C3B17A0E4735B918BDF550 Size: 72704 %SYSDIR%\bxtssxbv.dll %SYSDIR%\govkuctc.dll %SYSDIR%\hgwijcfp.dll %SYSDIR%\twfdppoh.dll %SYSDIR%\ynuxqgdq.dll %SYSDIR%\fmxhxygn.dll %SYSDIR%\rmjfaapk.dll %SYSDIR%\cbhixnrp.dll %SYSDIR%\etbrcoof.dll %SYSDIR%\wlfngrcj.dll %SYSDIR%\jkvjncke.dll and next 12 variations. MD5: D6FC7A41994B00A2C075C4AA657E9AD5 Size: 85504 %SystemDiskRoot%\System Volume Information\_restore{5DF4CDFD-197F-427D-A915-E59E45EA702D}\RP178\A0356881.dll %SystemDiskRoot%\System Volume Information\_restore{5DF4CDFD-197F-427D-A915-E59E45EA702D}\RP178\A0356875.dll %SystemDiskRoot%\System Volume Information\_restore{5DF4CDFD-197F-427D-A915-E59E45EA702D}\RP178\A0356858.dll %SYSDIR%\gasretyw0.dll %SYSDIR%\gasretyw1.dll %SYSDIR%\gasretyw0.dll.ren %SystemDiskRoot%\System Volume Information\_restore{2FF60FDC-11E3-4544-8C6D-853A58F6336D}\RP26\A0012274.dll %SystemDiskRoot%\System Volume Information\_restore{2FF60FDC-11E3-4544-8C6D-853A58F6336D}\RP25\A0012260.dll MD5: 78465B67AF3CC8AB5C424425DFB8689D Size: 103936 %SYSDIR%\thngvf.dll %SYSDIR%\ezaqhp.dll %SYSDIR%\yavxfv.dll %SYSDIR%\uabracpo.dll %SYSDIR%\lqxrxk.dll %SYSDIR%\krgevvem.dll %SYSDIR%\cojbam.dll %SYSDIR%\uynrcy.dll %SYSDIR%\phfldk.dll %SYSDIR%\zibmtl.dll %SYSDIR%\gremcl.dll and next 160 variations. MD5: BF8CC108E191CE615BB108E1A926CAB0 Size: 68096 %SYSDIR%\htiqxlov.dll %SYSDIR%\pycuynso.dll %SYSDIR%\jkulsfvg.dll %SYSDIR%\nxtjhbab.dll %SYSDIR%\ffsdjvyx.dll %SYSDIR%\ujjgkvew.dll %SYSDIR%\ofoftbkm.dll %SYSDIR%\qncycqwi.dll %SYSDIR%\unrdskos.dll %SYSDIR%\kamoacfv.dll %SYSDIR%\krfmialp.dll and next 136 variations. MD5: 500763B69406DF0271C7488EF57F60E0 Size: 85504 %SYSDIR%\ckvo2.dll %SYSDIR%\ckvo1.dll %SYSDIR%\ckvo0.dll MD5: 03BA9670D27F65129A92C52D4E22F313 Size: 84992 %SYSDIR%\ckvo0.dll %SYSDIR%\ckvo2.dll MD5: 2777565E92585B2F43B5948FEBD6BCCC Size: 68608 %SYSDIR%\smbblnlo.dll %SYSDIR%\mupofndm.dll %SYSDIR%\wycdpyfl.dll %SYSDIR%\icqmmstl.dll %SYSDIR%\payrqdkh.dll %SYSDIR%\tfcjcqak.dll %TEMP%\flaxyhde.dll MD5: 8F66E035B8CC3BD88EFF3A1353B0BC8F Size: 36352 %SYSDIR%\byXPiJbb.dll %SYSDIR%\fccyyYpQ.dll %SYSDIR%\xxyyvWNf.dll %SYSDIR%\vtULccYQ.dll %SYSDIR%\pmnnKdCT.dll MD5: FF35BBCFA2897938EC30C81B3C782181 Size: 103936 %SYSDIR%\azwbtk.dll %SYSDIR%\asusxn.dll %SYSDIR%\eqwgvn.dll %SystemDiskRoot%\System Volume Information\_restore{3DBB3491-1B54-4295-9814-C585088556ED}\RP65\A0007708.dll %SystemDiskRoot%\System Volume Information\_restore{3DBB3491-1B54-4295-9814-C585088556ED}\RP65\A0007706.dll %SYSDIR%\uwuagulq.dll %SYSDIR%\kwmpwl.dll %SYSDIR%\wbdupm.dll %SYSDIR%\pjuxwuqf.dll %SYSDIR%\ltkgsr.dll %SYSDIR%\bqpnhyob.dll and next 175 variations. MD5: 05C1A3DD88588E9F7E2FDEA1E97AFC07 Size: 21184 %WINDIR%\m0_glkp_011008.dll %SYSDIR%\c00768C.mat %SYSDIR%\c00A4162.mat %SYSDIR%\c008A40.mat %SYSDIR%\c00EA24.mat MD5: D1B3A8133BF416BEBA0CE1445C60859A Size: 129024 %SYSDIR%\aqihmo.dll %SYSDIR%\wfqrti.dll %SYSDIR%\vezfpd.dll %SYSDIR%\stjfvhnq.dll %SYSDIR%\viccrq.dll %SYSDIR%\mgycnp.dll %SYSDIR%\uacbjx.dll %SYSDIR%\ewteji.dll %SYSDIR%\xjufkx.dll %SYSDIR%\ztlpcr.dll %SYSDIR%\rwgjcuuh.dll and next 48 variations. MD5: 4BA37AFDF4AEC72C0E47F87E8FC3601B Size: 129024 %SYSDIR%\ybxcrb.dll %SYSDIR%\wkzeyi.dll %SYSDIR%\rmdxjojv.dll %SYSDIR%\hhzryn.dll %SYSDIR%\xdjjpnjh.dll %SYSDIR%\paenmy.dll %SYSDIR%\buicex.dll %SYSDIR%\wzqrxx.dll %SYSDIR%\sxwomz.dll %SYSDIR%\dgiltu.dll %SYSDIR%\jrpkrx.dll and next 42 variations. MD5: 335E61439DE822FE4672496AAD1E9F63 Size: 129024 %SYSDIR%\pyigzp.dll %SYSDIR%\udhcqisv.dll %SYSDIR%\smfnwr.dll %SYSDIR%\nwyniwna.dll %SYSDIR%\ggwkqg.dll %SYSDIR%\nkdnit.dll %SYSDIR%\amrnqe.dll %SYSDIR%\uxmnqi.dll %SYSDIR%\damzqs.dll %SYSDIR%\pyrppvin.dll %SYSDIR%\dvykdq.dll and next 52 variations. MD5: EBD18B99D87174589948B07ACA2139B0 Size: 124416 %SYSDIR%\hvqcrr.dll %SYSDIR%\braxjz.dll %SYSDIR%\wmpsxr.dll %SYSDIR%\tdxkbqps.dll %SYSDIR%\hshdxa.dll %SYSDIR%\euyimwui.dll %SYSDIR%\ldxfpk.dll %SYSDIR%\oypcixbk.dll %SYSDIR%\iybnri.dll %SystemDiskRoot%\System Volume Information\_restore{7134E910-3D14-47B5-8CC2-C9E4D67645E3}\RP330\A0074319.dll %SystemDiskRoot%\System Volume Information\_restore{7134E910-3D14-47B5-8CC2-C9E4D67645E3}\RP330\A0074317.dll and next 120 variations. MD5: FB2F41E18CC0D06E59998B669F6E863C Size: 136832 %SYSDIR%\yycahy.dll %SYSDIR%\lhgekv.dll %SYSDIR%\ydgqqwim.dll %SYSDIR%\qwpkec.dll MD5: 962ACDF4C741D32302844EF0B2515DA3 Size: 85504 %SYSDIR%\gasretyw0.dll %SYSDIR%\gasretyw1.dll %SystemDiskRoot%\Qoobox\Quarantine\C\WINDOWS\system32\gasretyw1.dll.vir %SystemDiskRoot%\Qoobox\Quarantine\C\WINDOWS\system32\gasretyw0.dll.vir %SYSDIR%\gasretyw2.dll MD5: 32D93EB8F40458E7929FD5E5A4B109A8 Size: 85504 %SYSDIR%\ckvo1.dll %SYSDIR%\ckvo0.dll MD5: BCF728FEB342E8114CF5DAB704F7A0AE Size: 87927 %SYSDIR%\ckvo.exe %SystemDiskRoot%\1rfw8hjr.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP77\A0104329.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP77\A0104291.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0104273.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0103274.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0103250.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0103227.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0102228.com MD5: 6B79ADDD77B4D5FF29D47D8A7DB907AA Size: 68096 %SystemDiskRoot%\System Volume Information\_restore{3DBB3491-1B54-4295-9814-C585088556ED}\RP65\A0007709.dll %SystemDiskRoot%\System Volume Information\_restore{3DBB3491-1B54-4295-9814-C585088556ED}\RP65\A0007707.dll %SYSDIR%\bycdqjop.dll %SYSDIR%\wgeikmot.dll %SYSDIR%\jfoqmdns.dll %SYSDIR%\mmwgbadk.dll %SYSDIR%\nucmnmww.dll %SYSDIR%\ywrbbrmo.dll %SYSDIR%\dirfkmmw.dll %SYSDIR%\kxdcwbel.dll %SYSDIR%\wuvsvcuf.dll and next 53 variations. MD5: 534E2E5B4CBFAF9A75643C33B8F80142 Size: 101888 %SYSDIR%\rynebxps.dll %SYSDIR%\rierwr.dll MD5: 0A30F6ED4CDA24737BFEB64CCE484C18 Size: 102400 %SYSDIR%\rvldyawe.dll %SYSDIR%\qizryo.dll MD5: 094A22E01CAC8ADDA80BBBCAEB59B8DE Size: 72704 %SYSDIR%\qqcrqkml.dll %SYSDIR%\hvbfuyqg.dll %SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP660\A0486313.dll %SYSDIR%\iqkajbdc.dll %SYSDIR%\atogxnmq.dll %SYSDIR%\hjvhxact.dll %SYSDIR%\tamesuhv.dll %SystemDiskRoot%\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP2260\A0632735.dll %SystemDiskRoot%\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP2259\A0632590.dll %SYSDIR%\ytcoevck.dll %SYSDIR%\wwvqfpop.dll and next 5 variations. MD5: D04F6700D2D2D3774C0AF1DA18789510 Size: 72704 %SYSDIR%\hyelndja.dll %SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP657\A0483103.dll %SystemDiskRoot%\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP2259\A0632613.dll MD5: F7B1FEAC0E830D8F3BF93B0C5165EA10 Size: 84992 %SYSDIR%\ckvo2.dll %SYSDIR%\ckvo0.dll MD5: B7A9828A20F848EBE3CA34725E0D73F7 Size: 20480 %SYSDIR%\advpackf.dll %SYSDIR%\1033g.dll %SYSDIR%\adpropx.dll MD5: B7A3266009C5F1CFEB181CA79FAD6041 Size: 73216 %SystemDiskRoot%\System Volume Information\_restore{E1574E75-81F9-4EDA-A62B-38C352371BC1}\RP248\A0411032.dll %SystemDiskRoot%\System Volume Information\_restore{E1574E75-81F9-4EDA-A62B-38C352371BC1}\RP248\A0411031.dll %SYSDIR%\hlrlmrkl.dll.vir %SYSDIR%\kfdtgebm.dll %SYSDIR%\sdsiodcn.dll %SYSDIR%\igclffxy.dll %SystemDiskRoot%\Users\Utilizador\AppData\Local\Temp\yfhhftqp.dll %SystemDiskRoot%\Users\Utilizador\AppData\Local\Temp\dqorarhk.dll %SYSDIR%\xbtowtty.dll %SYSDIR%\mitglcio.dll %TEMP%\xisoyswt.dll and next 6 variations. MD5: BA49495D75B01392E49048BBC9BC44F4 Size: 123904 %SYSDIR%\kmzanl.dll %SYSDIR%\euwnfu.dll %SYSDIR%\btgcys.dll %SYSDIR%\vsxtdm.dll %SYSDIR%\bibgsh.dll %SYSDIR%\bfupan.dll %SYSDIR%\oivlhc.dll %SYSDIR%\msxuwy.dll %SYSDIR%\fffyem.dll %SYSDIR%\tjqpvd.dll %SYSDIR%\mponli.dll and next 3 variations. MD5: 3E0CA43302D03B30087AA6B074F5DAC3 Size: 90556 %SYSDIR%\ckvo.exe %SystemDiskRoot%\39lpji.com E:\kk3.bat d:\System Volume Information\_restore{C54376AB-DBD6-484D-B342-D2C058D77C67}\RP41\A0027752.bat d:\System Volume Information\_restore{C54376AB-DBD6-484D-B342-D2C058D77C67}\RP40\A0027500.bat MD5: AA73F64C7E8BC0E1A4CBF1FECBE805A4 Size: 92161 %SYSDIR%\ckvo.exe d:\ph.com %SystemDiskRoot%\ph.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP4\A0000160.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP94\A0130674.com MD5: 93BFB2CBC32B5F810D70B155D41AEF0D Size: 101376 %SYSDIR%\rntyvmci.dll %SYSDIR%\laomsu.dll %SYSDIR%\ubzuvv.dll %SYSDIR%\giuxfdub.dll %SYSDIR%\feummr.dll %SYSDIR%\uiedkd.dll %SYSDIR%\nctlas.dll %SYSDIR%\unogasej.dll %SYSDIR%\kjwsdk.dll %TEMP%\hvibkums.dll MD5: B0ECC527DD5F74741F8209A83975BA5A Size: 106496 %SYSDIR%\pqknxdxq.dll %SYSDIR%\vlubvz.dll MD5: 3820C44B9E984BD55651DDC0675659AE Size: 101888 %SYSDIR%\dedzqa.dll %SYSDIR%\acdrqdxc.dll %SYSDIR%\ydyvnclr.dll %SYSDIR%\iawjis.dll %SYSDIR%\esrwgoxq.dll %SYSDIR%\smtlwkuu.dll %SYSDIR%\oujewbqi.dll %SYSDIR%\gpnqln.dll %SYSDIR%\uwnwrx.dll %SYSDIR%\dhipkkiu.dll %SYSDIR%\idpgidqk.dll and next 4 variations. MD5: 2D4DAB2AF01123E12F175C35F7B6830E Size: 123904 %SYSDIR%\idnszo.dll %SYSDIR%\cdebiqux.dll %SYSDIR%\fvngit.dll %SYSDIR%\mrauvc.dll %SYSDIR%\pxvpaa.dll %SYSDIR%\pnofvl.dll %SYSDIR%\wcimkmqf.dll %SYSDIR%\lphgva.dll %SYSDIR%\ivxnqebr.dll %SYSDIR%\epjnlv.dll MD5: 2D671547B0C2A8EE46092ADBD7172BAC Size: 118144 %SYSDIR%\amvo.exe F:\e.com %SystemDiskRoot%\e.com MD5: 6258E367CE99F2BFBA20E9F1D466C179 Size: 88935 %SYSDIR%\ckvo.exe J:\tbm9.bat %SystemDiskRoot%\Qoobox\Quarantine\C\tbm9.bat.vir d:\b3b9u.com %SystemDiskRoot%\b3b9u.com I:\tbm9.bat MD5: BB03C5D65908018AFB7B7E3DC4ED5DA6 Size: 85504 %SYSDIR%\ckvo0.dll %SYSDIR%\ckvo1.dll MD5: D208F1352DE8BC2DF541BF08060F03B6 Size: 89881 %SystemDiskRoot%\u9dyi.exe %SYSDIR%\ckvo.exe d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001996.exe MD5: 08D43885F798E6A7F3D7A6EEB0AD67CE Size: 92661 %SystemDiskRoot%\mnl6on3.com d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001993.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP95\A0130657.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP95\A0130646.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP94\A0130640.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP93\A0130637.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP93\A0130634.com %SYSDIR%\ckvo.exe d:\mnl6on3.com MD5: A53AD5492F28BFBFF63305D84DC2A1D9 Size: 85504 %SYSDIR%\ckvo2.dll %SYSDIR%\ckvo1.dll %SYSDIR%\ckvo0.dll %SYSDIR%\ckvo0.dll.ren %SystemDiskRoot%\System Volume Information\_restore{CFB91EEC-293F-4349-9EDA-93DA9A07AE26}\RP117\A0029991.dll MD5: 222A3050BB1BEDD083C8E7D4334AA1AD Size: 32768 %SYSDIR%\pmnkLDvw.dll %SYSDIR%\rqRKBUNF.dll MD5: 6DD233F2993624CD443568159D9962F6 Size: 125952 %SYSDIR%\utdwtq.dll %SYSDIR%\krpfyecp.dll %SYSDIR%\wvgawkph.dll %SYSDIR%\qhvzly.dll %SYSDIR%\vbsdib.dll %SYSDIR%\awfgof.dll %SYSDIR%\yckmwxia.0ll %SYSDIR%\abtgws.0ll %SYSDIR%\vzvffe.dll %SYSDIR%\eveqdh.dll %SYSDIR%\pawvhvpq.dll and next 1 variations. MD5: 81A75C6812279C69A9A46F6B1E5AAB5F Size: 126464 %SYSDIR%\nkuxqg.dll %SYSDIR%\mlothakr.dll %SYSDIR%\skuzcb.dll %SYSDIR%\krfgeawg.dll %SYSDIR%\twdvtk.dll %SYSDIR%\itbacuee.dll %SYSDIR%\raosev.dll %SYSDIR%\bfbcuq.dll %SYSDIR%\vxpwwm.dll %SYSDIR%\ctwjdz.dll %SYSDIR%\vutwpbod.dll and next 3 variations. MD5: B0344437078AFAFDDFFB766BE67F33F8 Size: 68096 %SYSDIR%\pbmuvotr.dll %SYSDIR%\rdthyfvo.dll %SYSDIR%\gdeywvmu.dll %SYSDIR%\aqamajgr.dll %SYSDIR%\xdbmkppe.dll %SYSDIR%\saraawvg.dll %SYSDIR%\brwalnjd.dll %SYSDIR%\lsqtbslm.dll %SYSDIR%\glfcfvvx.dll %SYSDIR%\bddkkafl.dll %SYSDIR%\gmkrnwhw.dll and next 9 variations. MD5: 90C275F54FFF62636196AAB989B2FD17 Size: 116932 %SYSDIR%\amvo.exe d:\qxbx9blb.com %SystemDiskRoot%\qxbx9blb.com g:\qxbx9blb.com MD5: AB9D3D1631092C0197E5C93CC595844A Size: 25600 %SYSDIR%\awtqrQjG.dll %SYSDIR%\wvUnMghh.dll %SYSDIR%\geBqPFYO.dll MD5: 08D367454D275EC8D0771ADD80E490F3 Size: 129024 %SYSDIR%\nkftdk.dll %SYSDIR%\xxdcmb.dll.ren %SYSDIR%\nxbkow.dll %SYSDIR%\uvdcax.dll %SYSDIR%\leiftjti.dll %SYSDIR%\xxdcmb.dll %SYSDIR%\kwmvhcvy.dll %SYSDIR%\erpnee.dll %SYSDIR%\tshmmj.dll MD5: 5299679D98B9374C7352EA850B0290CF Size: 84992 %ALLUSERS_APPDATA%\BitDefender\Desktop\Quarantine\ckvo0.dll %SYSDIR%\ckvo0.dll MD5: 545A1049BE98D177E114974A81CD0D84 Size: 68608 %SYSDIR%\jcfkeoow.dll %SYSDIR%\wdgjhftf.dll %SYSDIR%\cokvwaos.dll %SYSDIR%\urdwkhdp.dll %SYSDIR%\dqwkjara.dll MD5: FB32DA5769114C0B750042A86438D261 Size: 109056 %TEMP%\WhXV.exe %TEMP%\wbmd.exe MD5: 5D85307A7DCA16A410AEE337590D11DB Size: 85504 %SYSDIR%\ckvo0.dll %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP150\A0188160.dll %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP150\A0188159.dll %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP149\A0188143.DLL %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP143\A0187278.DLL %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP143\A0187229.DLL %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186229.DLL %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186216.DLL %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186198.DLL %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186181.DLL %SystemDiskRoot%\System Volume Information\_restore{9BA639EB-5CF2-449E-93E6-34F89AA9DDA0}\RP142\A0186163.DLL and next 16 variations. MD5: D084A8247940A772AA9D477E8ECBD0B9 Size: 116972 %SYSDIR%\ckvo.exe %SystemDiskRoot%\ffojc.com d:\ffojc.com MD5: C3FD5D15A081A526C57A931B2CD58F1F Size: 91127 %SystemDiskRoot%\n.com f:\n.com e:\n.com d:\n.com MD5: 383C05D06A655452D87083E734ABD69D Size: 89407 %SystemDiskRoot%\bpu.exe d:\bpu.exe %SystemDiskRoot%\Qoobox\Quarantine\C\bpu.exe.vir H:\bpu.exe %SystemDiskRoot%\tyktjfww.exe %SYSDIR%\ckvo.exe MD5: 7DD384111EA83FE4079BF5258D8D20CA Size: 32768 %SYSDIR%\vtUommKd.dll %SYSDIR%\khfFYpnK.dll %SYSDIR%\cbXnliJC.dll %SYSDIR%\yayvSiFV.dll %SYSDIR%\vtUnnlMF.dll %SYSDIR%\qoMfeebb.dll ssqRJdCR.dll %SYSDIR%\ssqRJdCR.dll %SYSDIR%\yayxwvuV.dll %SYSDIR%\wvUkIaWo.dll %SYSDIR%\tuvUomMD.dll and next 2 variations. MD5: C4E9C11FD9372284A168E9F733339276 Size: 86528 %APPDATA%\tmpB9.tmp.exe %TEMP%\tmp7.tmp.exe MD5: 95307A017BFDE77D937BC24F7C1980F8 Size: 89221 %SYSDIR%\ckvo.exe %SystemDiskRoot%\Qoobox\Quarantine\C\tyktjfww.exe.vir d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001995.exe d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0123460.exe d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0123439.exe d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0121437.exe d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0121340.exe d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP87\A0121326.exe d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP86\A0121311.exe d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP85\A0121187.exe d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP85\A0121167.exe and next 3 variations. MD5: BFF684D8B2D426270AC9D6060721FABD Size: 126464 %SYSDIR%\qnyzes.dll %SYSDIR%\brvytcbj.dll %SYSDIR%\uoteixxn.dll %SYSDIR%\dwvmqx.dll %SYSDIR%\nucysg.dll %SYSDIR%\opxliv.dll %SYSDIR%\txuhci.dll %SYSDIR%\rkmitews.dll MD5: 7FE216499F926FB57DD1202A42C17B43 Size: 25600 %USERPROFILE%\Local Settings\Temp\mlJDtQkj.dll %USERPROFILE%\Local Settings\Temp\vtUlKaWn.dll %USERPROFILE%\Local Settings\Temp\efcDTJdC.dll %USERPROFILE%\Local Settings\Temp\khfDuRJc.dll MD5: EA92A12B98C815E07CEC959C29CC530C Size: 91488 %SYSDIR%\sfqdwslv.dll %SYSDIR%\ynkhpahg.dll %SYSDIR%\tjaxkfgq.dll %SYSDIR%\rffjawof.dll MD5: 0C5E995E6D1CF4876A9B983DC1377202 Size: 85504 %SYSDIR%\ckvo0.dll %SystemDiskRoot%\System Volume Information\_restore{7F33CF22-F61B-4A66-9FC0-B4BE67DBCDF1}\RP290\A0203987.DLL %SYSDIR%\ckvo1.dll MD5: 3E879434E5381191B7234D7C7C96400C Size: 85504 %SYSDIR%\ckvo0.dll %SYSDIR%\ckvo2.dll %SYSDIR%\ckvo1.dll MD5: C054DAAD7BC4FC1BF5E35DD92388FF60 Size: 147355 %SYSDIR%\kxvo.exe d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001992.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0102208.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP76\A0101235.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP75\A0101220.com MD5: CFF77ABD3AD8ECC6C9201B19EA2B7400 Size: 123904 %SYSDIR%\povfgq.dll %SYSDIR%\ramgqmsx.dll %SYSDIR%\dfpwcr.dll %SYSDIR%\augejc.dll %SYSDIR%\eihnmfru.dll %SYSDIR%\favxvy.dll %SYSDIR%\iyabrcbl.dll %SYSDIR%\ywbhoh.dll %SYSDIR%\xjkmwt.dll %SYSDIR%\mdrecjpu.dll %SYSDIR%\mpbiuxwi.dll and next 0 variations. MD5: 50A7E9018126CACA0204B9F71D36E851 Size: 85504 %SYSDIR%\ckvo0.dll %SYSDIR%\ckvo1.dll MD5: B33BD2F644A371BBD55428AA9E3E9256 Size: 32768 %SYSDIR%\ljJCtuVM.dll %SYSDIR%\awtrollM.dll %SYSDIR%\cbXOGvst.dll %SYSDIR%\tuvULFXQ.dll %SYSDIR%\tuvSkKAS.dll MD5: 7128B5A86EB3CAF7614A4C5DD09DD31B Size: 90973 %SYSDIR%\ckvo.exe d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP16\A0005024.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP16\A0004025.com %SystemDiskRoot%\ph.com MD5: CE6E0CD24E280A75B4F44AE99CF70584 Size: 85504 %SYSDIR%\ckvo0.dll %SYSDIR%\ckvo1.dll %SYSDIR%\ckvo4.dll %SYSDIR%\ckvo2.dll %SystemDiskRoot%\System Volume Information\_restore{F5D279F6-9E53-46F9-AAA9-19FE623BBC06}\RP182\A0051615.dll MD5: D954047F8F849F05A35123D4380D02A6 Size: 89885 d:\xqf.com %SystemDiskRoot%\xqf.com J:\3rl3lqbq.bat J:\xqf.com F:\xqf.com d:\System Volume Information\_restore{D27B46AF-6978-4EB4-876D-4F5D26459C8B}\RP96\A0122861.com d:\System Volume Information\_restore{AEA45A52-27FE-4E08-8652-B951693B4E0E}\RP13\A0001997.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP80\A0118733.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP80\A0117747.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP79\A0117733.com d:\System Volume Information\_restore{4A9FC11D-BDB9-4949-8F20-CDDEB0F14CCA}\RP79\A0117711.com and next 3 variations. MD5: C9C5B5CDE7120EC38CA5845AA47B505D Size: 128672 d:\g.exe %SystemDiskRoot%\g.exe %SYSDIR%\kavo.exe MD5: 86B51F85BC16D6FF1A8C8C0F718230A8 Size: 123904 %SYSDIR%\yejvvi.dll %SYSDIR%\cbcjgxbx.dll %SYSDIR%\lydjpgmc.dll %SYSDIR%\ceynwu.dll %SYSDIR%\ruocio.dll %SYSDIR%\lrwfxt.dll %SYSDIR%\ytyygmww.dll %SYSDIR%\puqtbmin.dll %SYSDIR%\rnbdit.dll %SYSDIR%\yvhjfd.dll %SYSDIR%\dxwuai.dll and next 2 variations. MD5: 23B01417C46B0C58C5D121C1DA2B0E84 Size: 123904 %SYSDIR%\wcwkanxc.dll %SYSDIR%\svhggn.dll %SYSDIR%\lpubsb.dll %SYSDIR%\vcuegw.dll %SYSDIR%\lntoubtv.dll %SYSDIR%\epawqk.dll MD5: 274F8060F346B9761E22015A3BDE07A2 Size: 123904 %SYSDIR%\voqjqqvv.dll %SYSDIR%\lfhehn.dll %SYSDIR%\vwmhqo.dll %SYSDIR%\tnvjteau.dll %SYSDIR%\mbeafi.dll %SYSDIR%\oyqbfg.dll %SYSDIR%\nuovdwlw.dll %SYSDIR%\vwcacl.dll %SYSDIR%\qhpxdt.dll %SYSDIR%\wggqzl.dll %SYSDIR%\nybioc.dll and next 12 variations. MD5: DEB3F548D649223AB7283B525D7DC3EA Size: 123904 %SYSDIR%\smwbrn.dll %SYSDIR%\lvhayilo.dll %SYSDIR%\niunwgeo.dll %SYSDIR%\cnckxw.dll %SYSDIR%\jyykvd.dll %SYSDIR%\svkohwyu.dll %SYSDIR%\gfwwbf.dll %SYSDIR%\nsgajy.dll %SYSDIR%\mrjtnitd.dll %SYSDIR%\jembtpmp.dll %SYSDIR%\fgzoqi.dll and next 4 variations. MD5: C8175D7976F4FAF6C850756BFBD4B721 Size: 123904 %SYSDIR%\nywqcu.dll %SYSDIR%\dvsljrif.dll %SYSDIR%\vactixju.dll %SYSDIR%\bxijhd.dll %SYSDIR%\mwqkai.dll %SYSDIR%\ixwtfhpk.dll %SYSDIR%\nxcram.dll %SYSDIR%\buqhwo.dll %TEMP%\nqgsyabj.dll %SYSDIR%\wfrkxmaw.dll %SYSDIR%\fjtuzu.dll MD5: C4A55A4047E04AA171B15C2F76B3DA0A Size: 71680 %SYSDIR%\jiaaoqgi.dll %SYSDIR%\fbvuvlye.dll %SYSDIR%\skucumyg.dll %SYSDIR%\ccxdblyr.dll %TEMP%\ibmksghc.dll MD5: 0808BFDFAB50B4E4A86147C15A830EBD Size: 123904 %SYSDIR%\atymbm.dll %SYSDIR%\apimdjfi.dll %SYSDIR%\iczvat.dll %SYSDIR%\bhvximks.dll %SYSDIR%\lljcvb.dll %SYSDIR%\jxcysf.dll %SYSDIR%\gzfyuz.dll %SYSDIR%\mupnoudf.dll %SYSDIR%\prwpjc.dll %SYSDIR%\nwiptuya.dll %SYSDIR%\kntbyj.dll and next 3 variations. MD5: D6A81A78343300329DC0AEA9F0AF2DFD Size: 133120 %SYSDIR%\hszctk.dll %TEMP%\INF83C.tmp %TEMP%\INF83B.tmp %TEMP%\INF838.tmp %SYSDIR%\zhsyxr.dll %SYSDIR%\hzeaps.0ll %SYSDIR%\fykaptdy.0ll %SYSDIR%\jvjpzu.dll %SYSDIR%\hhdhyesp.dll MD5: 5BD117438337E0B336B62CAC729AEBA9 Size: 67584 %SYSDIR%\jdeqolej.dll %SYSDIR%\skrqduqx.dll MD5: 320DDC363C7D9AD8243753FB09871FC1 Size: 72704 %SYSDIR%\laptpxrx.dll %SYSDIR%\sxccowvg.dll %SystemDiskRoot%\System Volume Information\_restore{3E507D8D-7122-4242-94EB-326CB4914499}\RP210\A0032621.dll MD5: F7816A6DABA8A7EF466E31635956ACB0 Size: 132096 %SYSDIR%\qorzln.dll %SYSDIR%\mfvwjn.dll %SYSDIR%\gmabwatr.dll %SYSDIR%\cibbwf.dll %SYSDIR%\qxabpgar.dll %SYSDIR%\okyiqy.dll %SYSDIR%\okmsfukw.dll %SYSDIR%\ykcbcu.dll MD5: E6E785ED44156032C4DE992F3FEB4C2D Size: 91060 %SYSDIR%\ckvo.exe F:\c9hehpa.bat e:\c9hehpa.bat %SystemDiskRoot%\c9hehpa.bat MD5: 6F6D8988141EC0930774F6D7BE4D97FB Size: 84992 %SYSDIR%\ckvo0.dll %SYSDIR%\ckvo1.dll %SYSDIR%\ckvo2.dll MD5: 0D580BC9B5EEE40911C11CBB0A887A48 Size: 101888 %SYSDIR%\ybvnqx.dll %SYSDIR%\sqhbfaqa.dll %SYSDIR%\qctprb.dll MD5: 4DE1E3FB934BB82FB651FEAC0412A827 Size: 132608 %SYSDIR%\asacnf.dll %SYSDIR%\xatnry.dll %SYSDIR%\mcenff.dll %SYSDIR%\bbtrul.dll %SYSDIR%\knaiba.dll %SYSDIR%\cinvxrys.dll %SYSDIR%\dkipca.dll MD5: 4C9B154E86FC60078354AA376499C1DD Size: 20480 %SYSDIR%\accwizd.dll %SYSDIR%\1031f.dll %SYSDIR%\adsnwe.dll %SYSDIR%\18u.dll MD5: D0A52BEEF6E40C9FE6AF13941FBD854E Size: 81408 %SYSDIR%\mureemwo.dll %SYSDIR%\serkmfoe.dll %SYSDIR%\nednuniu.dll MD5: 550288EE775B4483E044BBB6BE84A1DD Size: 91136 %SYSDIR%\rmopdqya.dll %SYSDIR%\onivcufw.dll %SYSDIR%\gnsrguop.dll %SYSDIR%\dafwgcpg.dll MD5: 957647673CC2CBB6EFCCBB4E87D00E24 Size: 71680 %SYSDIR%\jkagtjve.dll %SYSDIR%\bkdgnqvj.dll MD5: 7E91F4B17383DFB2DC84DC0B7F319B61 Size: 89828 %SystemDiskRoot%\ph.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP18\A0006573.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0006391.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0006381.com d:\ph.com f:\ph.com e:\ph.com MD5: 81D10E5406B607A3AE6E85CA2A140860 Size: 90366 %SystemDiskRoot%\mnl6on3.com %SYSDIR%\ckvo.exe f:\mnl6on3.com MD5: 39A3D26DE0D3523157843BF1C007D01D Size: 89901 G:\t1ypkh.exe %SYSDIR%\ckvo.exe MD5: 37811FA88DDB17B475B81777192DA338 Size: 102912 %SYSDIR%\stdajwrx.dll %SYSDIR%\mdmgsm.dll MD5: D4E1BC0883BD41476E3FEFB958E74D57 Size: 102400 %SYSDIR%\olqlfdhe.dll %SYSDIR%\jrirdf.dll MD5: 72B36AE2E856BC9FE296195F197E76FB Size: 152892 d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP6\A0001407.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP6\A0000261.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP5\A0000210.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP5\A0000192.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP4\A0000095.com MD5: 62BBA7E02BE61DDFEC9A29C7E973CEC7 Size: 89370 d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0005245.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0005110.com d:\System Volume Information\_restore{D84089E5-36F8-4DA2-B3D9-DF785F83D9D5}\RP17\A0005064.com F:\ph.com %SystemDiskRoot%\ph.com MD5: 5716AA229C533F6A079008B6CFDA6D82 Size: 85504 %SYSDIR%\ckvo0.dll %SYSDIR%\ckvo1.dll %SYSDIR%\ckvo4.dll %SystemDiskRoot%\System Volume Information\_restore{CFB91EEC-293F-4349-9EDA-93DA9A07AE26}\RP106\A0029701.dll %SYSDIR%\ckvo2.dll MD5: 3F7DCF854D4E1E81A36243B7BE9522E3 Size: 133120 %SYSDIR%\ylptie.dll %SYSDIR%\ixhvargo.dll %SYSDIR%\hrwqpa.dll %SYSDIR%\fmrgky.dll %SYSDIR%\skhskafj.dll %SYSDIR%\dtuwfg.dll %SYSDIR%\hpyihg.dll %SYSDIR%\fhhryr.dll MD5: 3A51285482EA4B38DCB837CAD5C8D903 Size: 67584 %SYSDIR%\girvsppf.dll %SYSDIR%\kljlanqb.dll %USERPROFILE%\Configuracin local\Archivos temporales de Internet\Content.IE5\TK0ZX1G1\upd105320[2] MD5: FE0C5710BA1A41981D9E0D548B268D83 Size: 25600 E:\WINDOWS\system32\yaywtQih.dll %SYSDIR%\ssqNHbAp.dll %SYSDIR%\ddcYsSIb.dll %SYSDIR%\wvUkhFwv.dll MD5: F12626416506027B2CE0360C66FAEBCD Size: 85504 %SYSDIR%\ckvo1.dll %SYSDIR%\ckvo0.dll MD5: 6094D0AE8E2623A77A3B5C614824E25D Size: 81408 h:\WINDOWS\system32\bogvxedx.dll h:\Documents and Settings\mesut\Local Settings\Temporary Internet Files\Content.IE5\KQ2CQFNW\kb678031[1] MD5: 2D400B0F6E32FFF7493E5A8291297311 Size: 91973 %SystemDiskRoot%\System Volume Information\_restore{4BD78788-1236-4975-90D5-E3DD0D82F676}\RP150\A0156379.exe %SystemDiskRoot%\bwpncb6.com MD5: 544105939E6B256C4DC3493414975BB6 Size: 84992 %SYSDIR%\amvo0.dll %SYSDIR%\amvo2.dll MD5: EEF0E5EDF16D51408C5BF82A6A3F811F Size: 128512 %SYSDIR%\fxfiuvjw.dll %SYSDIR%\gjlqqvrk.dll MD5: 26D687CAC768A20ED56445E17766F0EF Size: 35328 k:\WINDOWS\system32\vtUnoNeB.dll k:\WINDOWS\system32\vtUkljHB.dll k:\WINDOWS\system32\pmnlifCs.dll k:\WINDOWS\system32\nnnllKEx.dll k:\WINDOWS\system32\jkkKcDWp.dll k:\WINDOWS\system32\efcCUMdd.dll %SYSDIR%\xxyWQIbX.dll %SYSDIR%\qoMdCsPG.dll %SYSDIR%\efcApOIC.dll %SYSDIR%\opnmMebx.dll %SYSDIR%\yaywvtuv.dll and next 16 variations. MD5: 14DA76D202D72165C6D39565F766507A Size: 85504 %SYSDIR%\ckvo2.dll F:\WINDOWS\system32\ckvo0.dll MD5: DDC8FCE34DD562A872BA1B934B531198 Size: 133120 %SYSDIR%\cikkgx.dll %SYSDIR%\sltimg.dll %SYSDIR%\dlmfqahm.dll %SYSDIR%\pvzsoi.dll %SYSDIR%\ourdhe.dll %SYSDIR%\mddlnb.dll MD5: 4FDED626888767077918FDA8598ECEC1 Size: 94208 %SYSDIR%\pkkxajss.dll %SYSDIR%\ofbebaqr.dll MD5: AA83F3D32ADDCBBD973143A1D739D709 Size: 67584 %SYSDIR%\igqqaoil.dll %TEMP%\vsujpgjk.dll %TEMP%\jedrrvnx.dll MD5: FB552527400A926FFFEE06DCF57E7547 Size: 25600 %SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1449\A0079181.dll %SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078477.dll %SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078469.dll %SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078468.dll %SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078466.dll %SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0078464.dll %SYSDIR%\efcBsSmN.dll %SYSDIR%\fccaYonO.dll MD5: 5E4D611583C4EDACD28A8C9493414FB4 Size: 34304 %SYSDIR%\ddCTjjjk.dll %SYSDIR%\ddcYOgFu.dll MD5: BD5E964D4D5373D68A109DCD0F81E5EF Size: 34304 %SYSDIR%\rqroNDvw.dll %SYSDIR%\opNgEtTL.dll %SYSDIR%\mljkJcbY.dll

Detecting items list:

  1. Files by Name %WINDIR%\qonnlk.dll %APPDATA%\tmp167.tmp.exe %APPDATA%\tmp16C.tmp.exe %SYSDIR%\tmp16C.tmp.dll
  2. Files by MD5 MD5: EFAB714C69B5A220206878CAB0AD5712 Size: 33280 MD5: 46D1E68DD295D836D641EC2BD9FAAFFC Size: 318560 MD5: 812A0433D4D1FAAA89EB97B249337D3D Size: 318048 MD5: 649022D9431DF93755A8E42ABD51CFDE Size: 300640 MD5: 6414F01D165BEF6772DC449C27C990D1 Size: 319584 MD5: 2C65DAFB3AA30F9B0B913F4F65D824D9 Size: 311392 MD5: 0B8A2C469527586F6FD16605F470BA65 Size: 85056 MD5: D9D5E14258F17A3EF35028E8D3AB0FCD Size: 78400 MD5: AF48872EC4DBB1B1FE6D36C12342FB1B Size: 34304 MD5: 90AE40BB48B0F258A14F9643C2AAE688 Size: 316000
  3. Files by CLSID or Name CLSID=89AD4D75-2429-462e-BD4E-443F233F6033

« Jít do Databáze softwaru