Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Trojan.Siggen4.8405

Added to the Dr.Web virus database: 2012-06-10

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'PWNAGE' = '<DRIVERS>\devoir.exe'
Infects the following executable system files:
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
  • %WINDIR%\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
  • %WINDIR%\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
  • %WINDIR%\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
  • %WINDIR%\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
  • %WINDIR%\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
  • %WINDIR%\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
  • %WINDIR%\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
  • %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
  • %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
  • %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
  • %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
  • %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
  • %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
  • %WINDIR%\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
  • %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
  • %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
  • %WINDIR%\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
  • %WINDIR%\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
  • %WINDIR%\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
  • %WINDIR%\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
  • %WINDIR%\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
  • %WINDIR%\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
  • %WINDIR%\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
  • %WINDIR%\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
  • %WINDIR%\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
  • %WINDIR%\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
  • %WINDIR%\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
  • %WINDIR%\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
  • %WINDIR%\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
  • %WINDIR%\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
  • %WINDIR%\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.Xml.dll
  • %WINDIR%\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
  • %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msiexec.exe
  • %WINDIR%\$NtUninstallKB942288-v3$\msihnd.dll
  • %WINDIR%\winhlp32.exe
  • %WINDIR%\$NtUninstallKB942288-v3$\msi.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\msimsg.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\updspapi.dll
  • %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.exe
  • %WINDIR%\$NtUninstallKB942288-v3$\msisip.dll
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.exe
  • %WINDIR%\regedit.exe
  • %WINDIR%\sfk.exe
  • %WINDIR%\hh.exe
  • %WINDIR%\NOTEPAD.EXE
  • %WINDIR%\sleep.exe
  • %WINDIR%\twunk_32.exe
  • %WINDIR%\vmmreg32.dll
  • %WINDIR%\TASKMAN.EXE
  • %WINDIR%\twain_32.dll
  • %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
  • %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
  • %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
  • %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
  • %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
  • %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
  • %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
  • %WINDIR%\AppPatch\AcLua.dll
  • %WINDIR%\AppPatch\AcSpecfc.dll
  • %WINDIR%\$NtUninstallWIC$\spuninst\updspapi.dll
  • %WINDIR%\AppPatch\AcLayers.dll
  • %WINDIR%\AppPatch\AcXtrnal.dll
  • %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
  • %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
  • %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
  • %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
Substitutes the following executable system files:
  • <SYSTEM32>\dllcache\winhlp32.exe with <SYSTEM32>\dllcache\winhlp32.exe.new
  • %WINDIR%\AppPatch\AcLayers.dll with %WINDIR%\AppPatch\aclayers.dll.new
  • %WINDIR%\AppPatch\AcLua.dll with %WINDIR%\AppPatch\aclua.dll.new
  • <SYSTEM32>\dllcache\twain_32.dll with <SYSTEM32>\dllcache\twain_32.dll.new
  • <SYSTEM32>\dllcache\twunk_32.exe with <SYSTEM32>\dllcache\twunk_32.exe.new
  • <SYSTEM32>\dllcache\vmmreg32.dll with <SYSTEM32>\dllcache\vmmreg32.dll.new
  • <SYSTEM32>\dllcache\aclua.dll with <SYSTEM32>\dllcache\aclua.dll.new
  • <SYSTEM32>\dllcache\acspecfc.dll with <SYSTEM32>\dllcache\acspecfc.dll.new
  • <SYSTEM32>\dllcache\acxtrnal.dll with <SYSTEM32>\dllcache\acxtrnal.dll.new
  • %WINDIR%\AppPatch\AcSpecfc.dll with %WINDIR%\AppPatch\acspecfc.dll.new
  • %WINDIR%\AppPatch\AcXtrnal.dll with %WINDIR%\AppPatch\acxtrnal.dll.new
  • <SYSTEM32>\dllcache\aclayers.dll with <SYSTEM32>\dllcache\aclayers.dll.new
  • %WINDIR%\TASKMAN.EXE with %WINDIR%\taskman.exe.new
  • %WINDIR%\twain_32.dll with %WINDIR%\twain_32.dll.new
  • %WINDIR%\twunk_32.exe with %WINDIR%\twunk_32.exe.new
  • %WINDIR%\hh.exe with %WINDIR%\hh.exe.new
  • %WINDIR%\NOTEPAD.EXE with %WINDIR%\notepad.exe.new
  • %WINDIR%\regedit.exe with %WINDIR%\regedit.exe.new
  • <SYSTEM32>\dllcache\notepad.exe with <SYSTEM32>\dllcache\notepad.exe.new
  • <SYSTEM32>\dllcache\regedit.exe with <SYSTEM32>\dllcache\regedit.exe.new
  • <SYSTEM32>\dllcache\taskman.exe with <SYSTEM32>\dllcache\taskman.exe.new
  • %WINDIR%\vmmreg32.dll with %WINDIR%\vmmreg32.dll.new
  • %WINDIR%\winhlp32.exe with %WINDIR%\winhlp32.exe.new
  • <SYSTEM32>\dllcache\hh.exe with <SYSTEM32>\dllcache\hh.exe.new
Malicious functions:
Executes the following:
  • <SYSTEM32>\reg.exe add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_SZ /d 1 /f
  • <SYSTEM32>\reg.exe add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v PWNAGE /t REG_SZ /d <DRIVERS>\devoir.exe /f
  • <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\devoir.bat""
Modifies file system :
Creates the following files:
  • %WINDIR%\assembly\GAC_32\System.Web\devoir.bat
  • %WINDIR%\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Printing\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Transactions\devoir.bat
  • %WINDIR%\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\devoir.bat
  • %WINDIR%\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\devoir.bat
  • %WINDIR%\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.EnterpriseServices\devoir.bat
  • %WINDIR%\assembly\GAC_32\ISymWrapper\devoir.bat
  • %WINDIR%\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\devoir.bat
  • %WINDIR%\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\devoir.bat
  • %WINDIR%\assembly\GAC_32\CustomMarshalers\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Data\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Data.OracleClient\devoir.bat
  • %WINDIR%\assembly\GAC_32\mscorlib\devoir.bat
  • %WINDIR%\assembly\GAC_32\PresentationCore\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\IIEHost\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\IEExecRemote\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\IEHost\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Tasks\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Engine\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Framework\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\cscompmgd\devoir.bat
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Accessibility\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\AspNetMMCExt\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\devoir.bat
  • %WINDIR%\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\aclua.dll.new
  • <SYSTEM32>\dllcache\aclayers.dll.new
  • %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\acspecfc.dll.new
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\devoir.bat
  • %WINDIR%\AppPatch\apph_sp.sdb.new
  • %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\devoir.bat
  • %WINDIR%\AppPatch\apphelp.sdb.new
  • %WINDIR%\AppPatch\msimain.sdb.new
  • %WINDIR%\AppPatch\sysmain.sdb.new
  • %WINDIR%\AppPatch\drvmain.sdb.new
  • %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\devoir.bat
  • <SYSTEM32>\dllcache\msimain.sdb.new
  • %WINDIR%\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\drvmain.sdb.new
  • %WINDIR%\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\devoir.bat
  • <SYSTEM32>\dllcache\sysmain.sdb.new
  • %WINDIR%\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\devoir.bat
  • %WINDIR%\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\acxtrnal.dll.new
  • %WINDIR%\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\apph_sp.sdb.new
  • <SYSTEM32>\dllcache\apphelp.sdb.new
  • %WINDIR%\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices.Protocols\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Drawing\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.IdentityModel.Selectors\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.IO.Log\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Drawing.Design\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.IdentityModel\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Design\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Linq\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Entity\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Entity.Design\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Data.SqlXml\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Deployment\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services.Client\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services.Design\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.Web\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceProcess\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.Install\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.WasHosting\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Web.DynamicData\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Web.DynamicData.Design\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Speech\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Abstractions\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Messaging\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Net\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Management\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Management.Instrumentation\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Security\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Remoting\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Serialization\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft_VsaVb\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Vsa\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationFontCache\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationBuildTasks\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationCFFRasterizer\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualC\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.JScript\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Utilities\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.AddIn.Contract\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.AddIn\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Core\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Data.DataSetExtensions\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Configuration\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\System.Configuration.Install\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\sysglobl\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Luna\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Royale\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Aero\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Classic\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\Sentinel.v3.5Client\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\SMDiagnostics\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\PresentationUI\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\ReachFramework\devoir.bat
  • %WINDIR%\AppPatch\acxtrnal.dll.new
  • %WINDIR%\twain_32\devoir.bat
  • %WINDIR%\Web\devoir.bat
  • <Auxiliary element>
  • %WINDIR%\Temp\devoir.bat
  • %WINDIR%\notepad.exe.new
  • %WINDIR%\regedit.exe.new
  • %WINDIR%\WinSxS\devoir.bat
  • %WINDIR%\hh.exe.new
  • <SYSTEM32>\devoir.bat
  • %WINDIR%\Santa
  • %WINDIR%\security\devoir.bat
  • %WINDIR%\Resources\devoir.bat
  • %WINDIR%\River
  • %WINDIR%\srchasst\devoir.bat
  • %WINDIR%\system\devoir.bat
  • %WINDIR%\Soap
  • %WINDIR%\SoftwareDistribution\devoir.bat
  • %WINDIR%\assembly\GAC_32\devoir.bat
  • %WINDIR%\assembly\GAC_MSIL\devoir.bat
  • %WINDIR%\$NtUninstallWIC$\spuninst\devoir.bat
  • %WINDIR%\assembly\GAC\devoir.bat
  • %WINDIR%\assembly\NativeImages_v4.0.30319_32\devoir.bat
  • %WINDIR%\assembly\temp\devoir.bat
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\devoir.bat
  • %WINDIR%\assembly\NativeImages_v2.0.50727_32\devoir.bat
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\devoir.bat
  • %WINDIR%\twain_32.dll.new
  • %WINDIR%\twunk_16.exe.new
  • %WINDIR%\taskman.exe.new
  • %WINDIR%\twain.dll.new
  • %WINDIR%\winhelp.exe.new
  • %WINDIR%\winhlp32.exe.new
  • %WINDIR%\twunk_32.exe.new
  • %WINDIR%\vmmreg32.dll.new
  • %WINDIR%\Cursors\devoir.bat
  • %WINDIR%\Debug\devoir.bat
  • %WINDIR%\Config\devoir.bat
  • %WINDIR%\Connection
  • %WINDIR%\Gone
  • %WINDIR%\Help\devoir.bat
  • %WINDIR%\Driver
  • %WINDIR%\ehome\devoir.bat
  • %WINDIR%\Coffee
  • <Current directory>\6783.bat
  • <Current directory>\19485.bat
  • %TEMP%\1.tmp\devoir.bat
  • <Current directory>\21886.bat
  • %WINDIR%\AppPatch\devoir.bat
  • %WINDIR%\Blue
  • %ALLUSERSPROFILE%\Desktop\PathHost
  • %WINDIR%\addins\devoir.bat
  • %WINDIR%\Prairie
  • %WINDIR%\Prefetch\devoir.bat
  • %WINDIR%\pchealth\devoir.bat
  • %WINDIR%\PeerNet\devoir.bat
  • %WINDIR%\Registration\devoir.bat
  • %WINDIR%\repair\devoir.bat
  • %WINDIR%\Provisioning\devoir.bat
  • %WINDIR%\pss\devoir.bat
  • %WINDIR%\Offline
  • %WINDIR%\Media\devoir.bat
  • %WINDIR%\Microsoft.NET\devoir.bat
  • %WINDIR%\ime\devoir.bat
  • %WINDIR%\java\devoir.bat
  • %WINDIR%\mui\devoir.bat
  • %WINDIR%\ocx\devoir.bat
  • %WINDIR%\msagent\devoir.bat
  • %WINDIR%\msapps\devoir.bat
  • <SYSTEM32>\dllcache\taskman.exe.new
  • %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\regedit.exe.new
  • %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\twain_32.dll.new
  • %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\twain.dll.new
  • %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\System.Web.Services\devoir.bat
  • %WINDIR%\assembly\GAC\System.Windows.Forms\devoir.bat
  • %WINDIR%\assembly\GAC\System.Web.Mobile\devoir.bat
  • %WINDIR%\assembly\GAC\System.Web.RegularExpressions\devoir.bat
  • %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\notepad.exe.new
  • %WINDIR%\assembly\GAC\System.Xml\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\winhlp32.exe.new
  • %WINDIR%\AppPatch\acspecfc.dll.new
  • %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\AppPatch\aclayers.dll.new
  • %WINDIR%\AppPatch\aclua.dll.new
  • <SYSTEM32>\dllcache\winhelp.exe.new
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\twunk_32.exe.new
  • %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\twunk_16.exe.new
  • %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\devoir.bat
  • <SYSTEM32>\dllcache\vmmreg32.dll.new
  • %WINDIR%\assembly\GAC\Microsoft.VisualC\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft.Vsa\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\devoir.bat
  • %WINDIR%\assembly\GAC\mscorcfg\devoir.bat
  • %WINDIR%\assembly\GAC\Regcode\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft_VsaVb\devoir.bat
  • %WINDIR%\assembly\GAC\Microsoft.JScript\devoir.bat
  • %WINDIR%\assembly\GAC\cscompmgd\devoir.bat
  • %WINDIR%\assembly\GAC\CustomMarshalers\devoir.bat
  • %WINDIR%\assembly\tmp\devoir.bat
  • %WINDIR%\assembly\GAC\Accessibility\devoir.bat
  • %WINDIR%\assembly\GAC\IIEHost\devoir.bat
  • %WINDIR%\assembly\GAC\ISymWrapper\devoir.bat
  • %WINDIR%\assembly\GAC\IEExecRemote\devoir.bat
  • %WINDIR%\assembly\GAC\IEHost\devoir.bat
  • %WINDIR%\assembly\GAC\System.Runtime.Remoting\devoir.bat
  • %WINDIR%\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\devoir.bat
  • %WINDIR%\assembly\GAC\System.Management\devoir.bat
  • %WINDIR%\assembly\GAC\System.Messaging\devoir.bat
  • <SYSTEM32>\dllcache\hh.exe.new
  • %WINDIR%\assembly\GAC\System.Web\devoir.bat
  • %WINDIR%\assembly\GAC\System.Security\devoir.bat
  • %WINDIR%\assembly\GAC\System.ServiceProcess\devoir.bat
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\devoir.bat
  • %WINDIR%\assembly\GAC\System.Data\devoir.bat
  • %WINDIR%\assembly\GAC\System.Data.OracleClient\devoir.bat
  • %WINDIR%\assembly\GAC\System\devoir.bat
  • %WINDIR%\assembly\GAC\System.Configuration.Install\devoir.bat
  • %WINDIR%\assembly\GAC\System.Drawing\devoir.bat
  • %WINDIR%\assembly\GAC\System.Drawing.Design\devoir.bat
  • %WINDIR%\assembly\GAC\System.Design\devoir.bat
  • %WINDIR%\assembly\GAC\System.DirectoryServices\devoir.bat

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android