Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Trojan.DownLoader11.4626

Added to the Dr.Web virus database: 2014-04-30

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'riliRun' = '<Current directory>\uCalendar.exe -run'
Malicious functions:
Creates and executes the following:
  • '<Current directory>\uCalendar.exe'
Modifies file system :
Creates the following files:
  • <Current directory>\skin\uCalendar\јЩЖЪ_f2.png
  • <Current directory>\skin\uCalendar\јЩЖЪie.png
  • <Current directory>\skin\uCalendar\јЩЖЪ_f1.png
  • <Current directory>\skin\uCalendar\јЩЖЪ_b.png
  • <Current directory>\skin\uCalendar\јЩЖЪ_del.png
  • <Current directory>\skin\uCalendar\јЩЖЪn.png
  • <Current directory>\skin\uCalendar\ЅсМмn.png
  • <Current directory>\skin\uCalendar\ЅсМмu.png
  • <Current directory>\skin\uCalendar\ЅМК¦ЅЪ.png
  • <Current directory>\skin\uCalendar\јЩЖЪu.png
  • <Current directory>\skin\uCalendar\јЩСЎЦР.PNG
  • <Current directory>\skin\uCalendar\јЩ.png
  • <Current directory>\skin\uCalendar\№в№чЅЪ.png
  • <Current directory>\skin\uCalendar\№нЅЪ.png
  • <Current directory>\skin\uCalendar\№Ш»ъ_f2.png
  • <Current directory>\skin\uCalendar\№Ш»ъ_del.png
  • <Current directory>\skin\uCalendar\№Ш»ъ_f1.png
  • <Current directory>\skin\uCalendar\№ъЗмЅЪ.png
  • <Current directory>\skin\uCalendar\јЖЛг»ъ_f1.png
  • <Current directory>\skin\uCalendar\јЖЛг»ъ_f2.png
  • <Current directory>\skin\uCalendar\јЖЛг»ъ_del.png
  • <Current directory>\skin\uCalendar\јЖЛг»ъ.ico
  • <Current directory>\skin\uCalendar\јЖЛг»ъ_b.png
  • <Current directory>\skin\uCalendar\їмµЭ.ico
  • <Current directory>\skin\uCalendar\Ж±СЎЦР.png
  • <Current directory>\skin\uCalendar\ЖЅ°ІТ№.png
  • <Current directory>\skin\uCalendar\Ж±Д¬ИП.png
  • <Current directory>\skin\uCalendar\ДёЗЧЅЪ.png
  • <Current directory>\skin\uCalendar\ДЦЦУ.png
  • <Current directory>\skin\uCalendar\ЖЯП¦ЅЪ.png
  • <Current directory>\skin\uCalendar\ЗйИЛЅЪ.png
  • <Current directory>\skin\uCalendar\И·ИП°ґЕҐ2М¬.png
  • <Current directory>\skin\uCalendar\Зз_РЎ.png
  • <Current directory>\skin\uCalendar\ЗеГчЅЪ.png
  • <Current directory>\skin\uCalendar\Зз.png
  • <Current directory>\skin\uCalendar\Д¬ИПСЎЦР.png
  • <Current directory>\skin\uCalendar\їмµЭ_f2.png
  • <Current directory>\skin\uCalendar\їмµЭie.png
  • <Current directory>\skin\uCalendar\їмµЭ_f1.png
  • <Current directory>\skin\uCalendar\їмµЭ_b.png
  • <Current directory>\skin\uCalendar\їмµЭ_del.png
  • <Current directory>\skin\uCalendar\АН¶ЇЅЪ.png
  • <Current directory>\skin\uCalendar\Д¬ИП.png
  • <Current directory>\skin\uCalendar\Д¬ИПjieri_pic.jpg
  • <Current directory>\skin\uCalendar\Г°єЕ.png
  • <Current directory>\skin\uCalendar\АЧХуУк.png
  • <Current directory>\skin\uCalendar\АЧХуУк_РЎ.png
  • <Current directory>\skin\uCalendar\ґКµд.ico
  • <Current directory>\skin\uCalendar\ґКµд_b.png
  • <Current directory>\skin\uCalendar\ґєЅЪ.png
  • <Current directory>\skin\uCalendar\ІЛµҐbk.png
  • <Current directory>\skin\uCalendar\іэП¦.png
  • <Current directory>\skin\uCalendar\ґКµд_del.png
  • <Current directory>\skin\uCalendar\ґу±©Ук.png
  • <Current directory>\skin\uCalendar\ґу±©Ук_РЎ.png
  • <Current directory>\skin\uCalendar\ґКµдie.png
  • <Current directory>\skin\uCalendar\ґКµд_f1.png
  • <Current directory>\skin\uCalendar\ґКµд_f2.png
  • <Current directory>\skin\uCalendar\ІЛµҐ.png
  • <Current directory>\skin\uCalendar\±ёНь_f1.png
  • <Current directory>\skin\uCalendar\±ёНь_f2.png
  • <Current directory>\skin\uCalendar\±ёНь_del.png
  • <Current directory>\skin\uCalendar\±іѕ°11.png
  • <Current directory>\skin\uCalendar\±ёНь_b.png
  • <Current directory>\skin\uCalendar\±ёНьВјjj.png
  • <Current directory>\skin\uCalendar\±ЪЦЅ_f2.png
  • <Current directory>\skin\uCalendar\±ај­.png
  • <Current directory>\skin\uCalendar\±ЪЦЅ_f1.png
  • <Current directory>\skin\uCalendar\±ЪЦЅ_b.png
  • <Current directory>\skin\uCalendar\±ЪЦЅ_del.png
  • <Current directory>\skin\uCalendar\ґуНёГч.png
  • <Current directory>\skin\uCalendar\¶щНЇЅЪ.png
  • <Current directory>\skin\uCalendar\ёґјю scrollbar.png
  • <Current directory>\skin\uCalendar\¶аФЖЧЄЗз_РЎ.png
  • <Current directory>\skin\uCalendar\¶ЛОзЅЪ.png
  • <Current directory>\skin\uCalendar\¶аФЖЧЄЗз.png
  • <Current directory>\skin\uCalendar\ёёЗЧЅЪ.png
  • <Current directory>\skin\uCalendar\ёь¶а1.png
  • <Current directory>\skin\uCalendar\№Ш»ъ_b.png
  • <Current directory>\skin\uCalendar\ёЯїј.png
  • <Current directory>\skin\uCalendar\ёѕЕ®ЅЪ.png
  • <Current directory>\skin\uCalendar\ёР¶чЅЪ.png
  • <Current directory>\skin\uCalendar\¶іУк_РЎ.png
  • <Current directory>\skin\uCalendar\ґуУк_РЎ.png
  • <Current directory>\skin\uCalendar\µзУ°.ico
  • <Current directory>\skin\uCalendar\ґуУк.png
  • <Current directory>\skin\uCalendar\ґуС©.png
  • <Current directory>\skin\uCalendar\ґуС©_РЎ.png
  • <Current directory>\skin\uCalendar\µзУ°_b.png
  • <Current directory>\skin\uCalendar\µзУ°ie.png
  • <Current directory>\skin\uCalendar\¶іУк.png
  • <Current directory>\skin\uCalendar\µзУ°_f2.png
  • <Current directory>\skin\uCalendar\µзУ°_del.png
  • <Current directory>\skin\uCalendar\µзУ°_f1.png
  • <Current directory>\skin\uCalendar\Тх_РЎ.png
  • <Current directory>\skin\uCalendar\УОП·_b.png
  • <Current directory>\skin\uCalendar\Тх.png
  • <Current directory>\skin\uCalendar\ТфАЦ_f2.png
  • <Current directory>\skin\uCalendar\ТфАЦie.png
  • <Current directory>\skin\uCalendar\УОП·_del.png
  • <Current directory>\skin\uCalendar\УЮИЛЅЪ.png
  • <Current directory>\skin\uCalendar\УкјРС©.png
  • <Current directory>\skin\uCalendar\УОП·ie.png
  • <Current directory>\skin\uCalendar\УОП·_f1.png
  • <Current directory>\skin\uCalendar\УОП·_f2.png
  • <Current directory>\skin\uCalendar\ТфАЦ_f1.png
  • <Current directory>\skin\uCalendar\Т№Нн¶аФЖ_РЎ.png
  • <Current directory>\skin\uCalendar\Т№НнЗзАК.png
  • <Current directory>\skin\uCalendar\Т№Нн¶аФЖ.png
  • <Current directory>\skin\uCalendar\СпЙі.png
  • <Current directory>\skin\uCalendar\СпЙі_РЎ.png
  • <Current directory>\skin\uCalendar\Т№НнЗзАК_РЎ.png
  • <Current directory>\skin\uCalendar\ТфАЦ_b.png
  • <Current directory>\skin\uCalendar\ТфАЦ_del.png
  • <Current directory>\skin\uCalendar\ТфАЦ.ico
  • <Current directory>\skin\uCalendar\ТСМнјУ1.png
  • <Current directory>\skin\uCalendar\ТСМнјУ2.png
  • <Current directory>\skin\uCalendar\УкјРС©_РЎ.png
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\uCalhtml[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\wdj_connection_wrapper[1].dll
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Install[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\md5[1].txt
  • <Current directory>\wdj_connection_wrapper.dll
  • <Current directory>\data\weather.dat
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\startup[1].0&sid=11000000000000000001&pos=&s=62FDC04D9968F0EDA6BDBD1110B7C092
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\tj[1].html
  • <Current directory>\data\Install.ini
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\qian[1].html
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\PopBoxSmall[1].txt
  • <Current directory>\skin\uCalendar\ЦРј¶Йііѕ±©_РЎ.png
  • <Current directory>\skin\uCalendar\ЦРЗпЅЪ.png
  • <Current directory>\skin\uCalendar\ЦРј¶Йііѕ±©.png
  • <Current directory>\skin\uCalendar\ФЄПьЅЪ.png
  • <Current directory>\skin\uCalendar\ФЖїШ.xml
  • <Current directory>\skin\uCalendar\ЦРС©.png
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Version[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\PopBoxBig[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\appimg[1].txt
  • <Current directory>\skin\uCalendar\ЦРС©_РЎ.png
  • <Current directory>\data\Config.ini
  • <Current directory>\skin\uCalendar\МмЖш_del.png
  • <Current directory>\skin\uCalendar\МмЖш_f1.png
  • <Current directory>\skin\uCalendar\МбРС_f2.png
  • <Current directory>\skin\uCalendar\МбРС_del.png
  • <Current directory>\skin\uCalendar\МбРС_f1.png
  • <Current directory>\skin\uCalendar\МмЖш_f2.png
  • <Current directory>\skin\uCalendar\НтКҐЅЪ.png
  • <Current directory>\skin\uCalendar\Он.png
  • <Current directory>\skin\uCalendar\НёГчdel.png
  • <Current directory>\skin\uCalendar\МнјУ.png
  • <Current directory>\skin\uCalendar\МнјУ№¦ДЬ.png
  • <Current directory>\skin\uCalendar\МбРС_b.png
  • <Current directory>\skin\uCalendar\ИХАъ_f1.png
  • <Current directory>\skin\uCalendar\ИХАъ_f2.png
  • <Current directory>\skin\uCalendar\ИХАъ_del.png
  • <Current directory>\skin\uCalendar\И·ИП°ґЕҐіЈМ¬.png
  • <Current directory>\skin\uCalendar\ИХАъ.png
  • <Current directory>\skin\uCalendar\Йііѕ±©.png
  • <Current directory>\skin\uCalendar\МШґу±©Ук_РЎ.png
  • <Current directory>\skin\uCalendar\МШґуЙііѕ±©.png
  • <Current directory>\skin\uCalendar\МШґу±©Ук.png
  • <Current directory>\skin\uCalendar\Йііѕ±©_РЎ.png
  • <Current directory>\skin\uCalendar\КҐµ®ЅЪ.png
  • <Current directory>\skin\uCalendar\Он_РЎ.png
  • <Current directory>\skin\uCalendar\РВОЕie.png
  • <Current directory>\skin\uCalendar\РВФц±ёНь.png
  • <Current directory>\skin\uCalendar\РВОЕ_f2.png
  • <Current directory>\skin\uCalendar\РВОЕ_del.png
  • <Current directory>\skin\uCalendar\РВОЕ_f1.png
  • <Current directory>\skin\uCalendar\РЗЧщ.ico
  • <Current directory>\skin\uCalendar\РЗЧщ_f2.png
  • <Current directory>\skin\uCalendar\РЗЧщie.png
  • <Current directory>\skin\uCalendar\РЗЧщ_f1.png
  • <Current directory>\skin\uCalendar\РЗЧщ_b.png
  • <Current directory>\skin\uCalendar\РЗЧщ_del.png
  • <Current directory>\skin\uCalendar\РВОЕ_b.png
  • <Current directory>\skin\uCalendar\РЎµЅЦРС©.png
  • <Current directory>\skin\uCalendar\РЎµЅЦРС©_РЎ.png
  • <Current directory>\skin\uCalendar\Пы·СХЯ.png
  • <Current directory>\skin\uCalendar\ПВФШЅш¶ИМх0.png
  • <Current directory>\skin\uCalendar\ПВФШЅш¶ИМх1.png
  • <Current directory>\skin\uCalendar\РЎС©.png
  • <Current directory>\skin\uCalendar\РЎУкЧЄЦРУк.png
  • <Current directory>\skin\uCalendar\РЎУкЧЄЦРУк_РЎ.png
  • <Current directory>\skin\uCalendar\РЎУк_РЎ.png
  • <Current directory>\skin\uCalendar\РЎС©_РЎ.png
  • <Current directory>\skin\uCalendar\РЎУк.png
  • <Current directory>\skin\uCalendar\±©Ук_РЎ.png
  • <Current directory>\skin\uCalendar\beijing2.png
  • <Current directory>\skin\uCalendar\beiwanglubj.png
  • <Current directory>\skin\uCalendar\beijing.png
  • <Current directory>\skin\uCalendar\apptool.xml
  • <Current directory>\skin\uCalendar\bar_red.png
  • <Current directory>\skin\uCalendar\beiwanglubj5.png
  • <Current directory>\skin\uCalendar\btn_hot.png
  • <Current directory>\skin\uCalendar\btn_push.png
  • <Current directory>\skin\uCalendar\btn_close_normal.png
  • <Current directory>\skin\uCalendar\btn_close_down.png
  • <Current directory>\skin\uCalendar\btn_close_highlight.png
  • <Current directory>\skin\uCalendar\apptool.png
  • <Current directory>\skin\uCalendar\Vacation.png
  • <Current directory>\skin\uCalendar\Weather_none.png
  • <Current directory>\skin\uCalendar\Transparent.bmp
  • <Current directory>\skin\uCalendar\Temper·ыєЕ.png
  • <Current directory>\skin\uCalendar\Thumbs.db
  • <Current directory>\skin\uCalendar\addapp.png
  • <Current directory>\skin\uCalendar\allbtn_over.png
  • <Current directory>\skin\uCalendar\appbg.png
  • <Current directory>\skin\uCalendar\allbtn_nor.png
  • <Current directory>\skin\uCalendar\addapph.png
  • <Current directory>\skin\uCalendar\allbtn_down.png
  • <Current directory>\skin\uCalendar\button_B_hover.png
  • <Current directory>\skin\uCalendar\g2.png
  • <Current directory>\skin\uCalendar\guanbi1.png
  • <Current directory>\skin\uCalendar\g1.png
  • <Current directory>\skin\uCalendar\dian.png
  • <Current directory>\skin\uCalendar\ff.png
  • <Current directory>\skin\uCalendar\guanbi2.png
  • <Current directory>\skin\uCalendar\icon_close.png
  • <Current directory>\skin\uCalendar\icon_setting.png
  • <Current directory>\skin\uCalendar\icon_clo.png
  • <Current directory>\skin\uCalendar\hl.xml
  • <Current directory>\skin\uCalendar\huanfu.png
  • <Current directory>\skin\uCalendar\delapp2.png
  • <Current directory>\skin\uCalendar\button_hover.png
  • <Current directory>\skin\uCalendar\button_normal.png
  • <Current directory>\skin\uCalendar\button_down.png
  • <Current directory>\skin\uCalendar\button_B_normal.png
  • <Current directory>\skin\uCalendar\button_B_pushed.png
  • <Current directory>\skin\uCalendar\button_p_hover.png
  • <Current directory>\skin\uCalendar\delapp.png
  • <Current directory>\skin\uCalendar\delapp1.png
  • <Current directory>\skin\uCalendar\del.png
  • <Current directory>\skin\uCalendar\button_p_normal.png
  • <Current directory>\skin\uCalendar\button_p_pushed.png
  • <Current directory>\skin\uCalendar\3601.png
  • <Current directory>\skin\uCalendar\360ProgressF.png
  • <Current directory>\skin\uCalendar\2.ico
  • <Current directory>\skin\uCalendar\1221.png
  • <Current directory>\skin\uCalendar\1x1.png
  • <Current directory>\skin\uCalendar\360ProgressF1.png
  • <Current directory>\skin\uCalendar\360thumb.png
  • <Current directory>\skin\uCalendar\723јНДо.png
  • <Current directory>\skin\uCalendar\360_pushed.png
  • <Current directory>\skin\uCalendar\360_hover.png
  • <Current directory>\skin\uCalendar\360_normal.png
  • <Current directory>\skin\uCalendar\111.png
  • <Current directory>\Replace64.dll
  • <Current directory>\huangli.xml
  • <Current directory>\Replace.dll
  • %TEMP%\nsf2.tmp
  • <Current directory>\DesktopCalendar.dll
  • <Current directory>\niaojiao.wav
  • <Current directory>\ui_d.dll
  • <Current directory>\skin\uCalendar\11.png
  • <Current directory>\uCalendar.exe
  • <Current directory>\tclock.ini
  • <Current directory>\uCalExternal.exe
  • <Current directory>\skin\uCalendar\ClockBackchain.png
  • <Current directory>\skin\uCalendar\Temper2.png
  • <Current directory>\skin\uCalendar\Temper3.png
  • <Current directory>\skin\uCalendar\Temper1.png
  • <Current directory>\skin\uCalendar\Temper-.png
  • <Current directory>\skin\uCalendar\Temper0.png
  • <Current directory>\skin\uCalendar\Temper4.png
  • <Current directory>\skin\uCalendar\Temper8.png
  • <Current directory>\skin\uCalendar\Temper9.png
  • <Current directory>\skin\uCalendar\Temper7.png
  • <Current directory>\skin\uCalendar\Temper5.png
  • <Current directory>\skin\uCalendar\Temper6.png
  • <Current directory>\skin\uCalendar\SliderS.bmp
  • <Current directory>\skin\uCalendar\Refresh_normal.png
  • <Current directory>\skin\uCalendar\Refresh_pushed.png
  • <Current directory>\skin\uCalendar\Refresh_hover.png
  • <Current directory>\skin\uCalendar\Festival.xml
  • <Current directory>\skin\uCalendar\InputBox.xml
  • <Current directory>\skin\uCalendar\S_1.png
  • <Current directory>\skin\uCalendar\SliderH.bmp
  • <Current directory>\skin\uCalendar\SliderL.bmp
  • <Current directory>\skin\uCalendar\S_22.png
  • <Current directory>\skin\uCalendar\S_11.png
  • <Current directory>\skin\uCalendar\S_2.png
  • <Current directory>\skin\uCalendar\toolbar_pushed2.png
  • <Current directory>\skin\uCalendar\tray_no.png
  • <Current directory>\skin\uCalendar\toolbar_pushed.png
  • <Current directory>\skin\uCalendar\toolbar_hover2.png
  • <Current directory>\skin\uCalendar\toolbar_normal.png
  • <Current directory>\skin\uCalendar\tray_xp_no.png
  • <Current directory>\skin\uCalendar\tubiao.png
  • <Current directory>\skin\uCalendar\unsel.bmp
  • <Current directory>\skin\uCalendar\ttt.png
  • <Current directory>\skin\uCalendar\tray_xp_yes.png
  • <Current directory>\skin\uCalendar\tray_yes.png
  • <Current directory>\skin\uCalendar\toolbar_hover.png
  • <Current directory>\skin\uCalendar\t2.png
  • <Current directory>\skin\uCalendar\time icon.png
  • <Current directory>\skin\uCalendar\t1.png
  • <Current directory>\skin\uCalendar\skytit4.png
  • <Current directory>\skin\uCalendar\suoxiao2.png
  • <Current directory>\skin\uCalendar\tip.png
  • <Current directory>\skin\uCalendar\today_3.png
  • <Current directory>\skin\uCalendar\today_4.png
  • <Current directory>\skin\uCalendar\today_2.png
  • <Current directory>\skin\uCalendar\tips_D01.png
  • <Current directory>\skin\uCalendar\today_1.png
  • <Current directory>\skin\uCalendar\unsel11.bmp
  • <Current directory>\skin\uCalendar\xwarnTip.xml
  • <Current directory>\skin\uCalendar\xweatherInfo.xml
  • <Current directory>\skin\uCalendar\xuoxiao2.png
  • <Current directory>\skin\uCalendar\xminiTip.xml
  • <Current directory>\skin\uCalendar\xtest.xml
  • <Current directory>\skin\uCalendar\yi.png
  • <Current directory>\skin\uCalendar\±©С©_РЎ.png
  • <Current directory>\skin\uCalendar\±©Ук.png
  • <Current directory>\skin\uCalendar\±©С©.png
  • <Current directory>\skin\uCalendar\°а.png
  • <Current directory>\skin\uCalendar\°аСЎЦР.PNG
  • <Current directory>\skin\uCalendar\xjiaqi.xml
  • <Current directory>\skin\uCalendar\xNotepad.xml
  • <Current directory>\skin\uCalendar\xSetInfo.xml
  • <Current directory>\skin\uCalendar\xColorWnd.xml
  • <Current directory>\skin\uCalendar\updateTip.xml
  • <Current directory>\skin\uCalendar\www.png
  • <Current directory>\skin\uCalendar\xShutdown.xml
  • <Current directory>\skin\uCalendar\xiala_2.png
  • <Current directory>\skin\uCalendar\xiala_3.png
  • <Current directory>\skin\uCalendar\xiala_1.png
  • <Current directory>\skin\uCalendar\xTip.xml
  • <Current directory>\skin\uCalendar\xTipLayer.xml
  • <Current directory>\skin\uCalendar\layerClo.png
  • <Current directory>\skin\uCalendar\list_bk.png
  • <Current directory>\skin\uCalendar\jintian4.png
  • <Current directory>\skin\uCalendar\jintian2.png
  • <Current directory>\skin\uCalendar\jintian3.png
  • <Current directory>\skin\uCalendar\ljty.png
  • <Current directory>\skin\uCalendar\menu_bk.png
  • <Current directory>\skin\uCalendar\mobileTip.xml
  • <Current directory>\skin\uCalendar\mainlayer.xml
  • <Current directory>\skin\uCalendar\log1.png
  • <Current directory>\skin\uCalendar\logo_16icon.png
  • <Current directory>\skin\uCalendar\jintian1.png
  • <Current directory>\skin\uCalendar\ieweb.xml
  • <Current directory>\skin\uCalendar\ie№Ш±Х.png
  • <Current directory>\skin\uCalendar\iebox.xml
  • <Current directory>\skin\uCalendar\icon_skin.png
  • <Current directory>\skin\uCalendar\ie.xml
  • <Current directory>\skin\uCalendar\ie№Ш±Х2.png
  • <Current directory>\skin\uCalendar\input.png
  • <Current directory>\skin\uCalendar\ji.png
  • <Current directory>\skin\uCalendar\infoMenu.xml
  • <Current directory>\skin\uCalendar\ieЛхРЎ.png
  • <Current directory>\skin\uCalendar\ieЛхРЎ2.png
  • <Current directory>\skin\uCalendar\msgwnd.xml
  • <Current directory>\skin\uCalendar\sky1.png
  • <Current directory>\skin\uCalendar\sky2.png
  • <Current directory>\skin\uCalendar\sidebar_4.png
  • <Current directory>\skin\uCalendar\sidebar_2.png
  • <Current directory>\skin\uCalendar\sidebar_3.png
  • <Current directory>\skin\uCalendar\sky3.png
  • <Current directory>\skin\uCalendar\skytit2.png
  • <Current directory>\skin\uCalendar\skytit3.png
  • <Current directory>\skin\uCalendar\skytit1.png
  • <Current directory>\skin\uCalendar\sky4.png
  • <Current directory>\skin\uCalendar\sky_aero.png
  • <Current directory>\skin\uCalendar\sidebar_1.png
  • <Current directory>\skin\uCalendar\pointwnd2.xml
  • <Current directory>\skin\uCalendar\popiebig.png
  • <Current directory>\skin\uCalendar\pointwnd1.xml
  • <Current directory>\skin\uCalendar\payinsure_open_hover.png
  • <Current directory>\skin\uCalendar\pointwnd0.xml
  • <Current directory>\skin\uCalendar\poptip.png
  • <Current directory>\skin\uCalendar\search_bk.png
  • <Current directory>\skin\uCalendar\shutdown.xml
  • <Current directory>\skin\uCalendar\scrollbar.png
  • <Current directory>\skin\uCalendar\s_3.png
  • <Current directory>\skin\uCalendar\scrollbar.bmp
Deletes the following files:
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\md5[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\uCalhtml[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Install[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Version[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\appimg[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\PopBoxSmall[1].txt
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\PopBoxBig[1].txt
Network activity:
Connects to:
  • '7d##.##aoxinrili.com':80
  • 'co###.#iaoxinrili.com':80
  • 'ap#.#780.com':88
  • 'up####.redshu.com':80
  • '12#.#25.114.144':80
  • 'localhost':1048
TCP:
HTTP GET requests:
  • up####.redshu.com/wdj_connection_wrapper.dll
  • up####.redshu.com/uCalhtml.txt
  • up####.redshu.com/Install.txt
  • up####.redshu.com/qian.html?
  • co###.#iaoxinrili.com/startup?ap###################################################################################################
  • 7d##.##aoxinrili.com/city
  • up####.redshu.com/tj.html?
  • up####.redshu.com/md5.txt
  • up####.redshu.com/PopBoxBig.txt
  • up####.redshu.com/appImg/appimg.txt
  • up####.redshu.com/Version.txt
  • up####.redshu.com/PopBoxSmall.txt
  • up####.redshu.com/update.txt
  • 12#.#25.114.144/
  • up####.redshu.com/appImg/AppCloud4.2.xml
UDP:
  • DNS ASK co###.#iaoxinrili.com
  • DNS ASK ap#.#780.com
  • DNS ASK 7d##.##aoxinrili.com
  • DNS ASK up####.redshu.com
  • DNS ASK www.ba##u.com
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Button' WindowName: '(null)'
  • ClassName: 'ReBarWindow32' WindowName: '(null)'
  • ClassName: 'SysListView32' WindowName: '(null)'
  • ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
  • ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
  • ClassName: 'Shell_TrayWnd' WindowName: '(null)'
  • ClassName: 'Indicator' WindowName: '(null)'
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'TrayClockWClass' WindowName: '(null)'
  • ClassName: 'TrayNotifyWnd' WindowName: ''

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android