Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Trojan.DownLoader8.21727

Added to the Dr.Web virus database: 2013-03-21

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender' = '<Full path to virus>'
Malicious functions:
To complicate detection of its presence in the operating system,
blocks the following features:
  • User Account Control (UAC)
Modifies file system :
Creates the following files:
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2aa5ee63cf709c6a1c473ba849a7bece_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\943914add085ed24ff61c3a218f5f779_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\470f2426ffa4cf8b514e0d77ef71a98c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b3a8e12003477046020f28315a6603ca_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3caa5ff5bcad64ddde3af717a0c25173_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\40de4666dc9b88ca77cf85e6883a1c34_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\a621ce6a307d1d56f2bcfbcf8b247e25_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7ab1f3e46e4bcdca237f882aafd2162e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\88bba7c20797c95d326bba285a694e48_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\4d7926b4eb0fd3e5d2444dec283e4a94_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d565a3f49424f4ca12d8aaf61ab10b19_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0bab8fa809394543a18a425f827c2e66_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\255d8de8caf6d7cd434dc664820e8602_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7fefe46a4a5748f258b0e75d90b6798d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1763ac119c670bd0534ba5ee61ec0ac1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\49b1bc89879f8a77bb25e437459688ad_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ebd06623d90f094a7131dd4860c9acd5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c0d4dafe9b2df1f86b0fc92b65b2857a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ecbeed897ad96ec37f5370e505a8638c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d8c8094c8995f9eb8e85940701685562_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e730920c733d19286083aa4c3fff850e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0a1280a8258d185209ed91a7e3048be6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\37b2730d216943313d9a5beef7fffea9_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\01ed52990a5f3fd4a44b615bbbd28850_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\21c73b3932803b1af0f64cba55a36d15_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c20392a941404a4fee3d6741027e53b8_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7879cc8495dbbdf8090879e92b342875_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\04538e9294ad866d3675b2566cf0e74d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\4cf683befb480f0ce41d3848c90988d1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1fa3647b1e7be33a355e319c41072dfa_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9999b742ef5f6e214f97420daa65c953_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\52ca1b5a6aca757c0a8f90204b9100bd_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5c146e9935a7771327f4984fcdfa1732_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2d599c40540743cc152980283899dd27_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c86ddbeeafe8f1937d6379cf45e2063c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2a52b5e5658aa9ae7cd35db6c7849e0b_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8706112e365cef39e0ee1bb5e7e4711e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\17ae677668b956d3cabd5f9b9639b5bf_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9856672f991fc8c4f245974e5081190c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b783f6043af420792100edda6bd1124f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d2158461183921dd3908fba24dd341e2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\dcac20213ac939fd8991293cb8984085_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1d7b01b5c03b979141c0d5d3c237af61_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\6c7432d232b67e68f5cb78a669c6b38e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8b58c254e67d3da337049f2e58a59c91_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2db33c49d7410341d8a76559c5386e79_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\a53e6815a063305ed16f581e2d098b8c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\878b53594541a63ef4eaca1eb8d5c877_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3ba314c9fdaf7306680a97dc7bb28753_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b623640a4adc238040dac3d356336d08_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\614bf7260742178e81695645a930fe84_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3cd57458feab17cadc20c91f29e874f4_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c68a252059842b4e27ca2d25438329ca_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\fa86a47c516cf7a25838f70731ddd0e6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0a594ca431a6929589b4d93f21f694aa_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ad4f25dca6b16f54c111b8d1a5438b1f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2e2292e4627c519bc1a2982e7a30c1b0_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ec92dbe9e95eb47153f46a0d1a328db4_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1c91c3e0d161ad31c1ed7eb40a7ba9a6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ae9233d3ae08e2e5712b024ddf875a6a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\06f5dc324c1c2857cd894736d417a6c2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2d97cb62e6c19fb7c13baf5d58db5e93_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\db3809219c97ceeead3564d0ceb179da_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\a5b319d2c5e1a53dfa6568ba33e6287b_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0eab44f2b1ace4aa7919e8e1a75b10da_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\55514e1179bf081fe3ac25e374e72996_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7a38b6dcf5b162f5870a2bd27949aba3_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d4999e9a36342bdf1ef7dd6b0bea322d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b4afdac5f4cf0353e57abcdfe0458bec_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b96c874ce09170940023408aa61eb9bc_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ce2084bbb8f858972067cf15a87007f2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b6ccef48524a63f3186910ef03969ec6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5e58b5d058efa749c5b4533340e3b55a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\90c61cee2a08ba247dbc31e61d4d9dfd_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\a3d9b0723257a53468f0418a34d359e4_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\01ebe5199e19951ee1c38eb618dbc349_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\46d53044b0b0c760d473fe6943fc5fae_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c2ea2a1dbc45dc425ffdf08dde645d4d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ff0323f0d07f5fa776b6cd3095ee183d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8c8642ea9710e9ae6a7b11ff93835324_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\6f272e666e220c8b3afd8423d3907ac5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\98121a52f7fa58fc20feb70c4b849a1f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\13cb3efc803657dd64369a3c7a2295fa_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f27be37f58c963a4e91dc0c590b2e944_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d02b9d505d65f03d079bcf7aa296400f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f5dc82e24720792c6c6bde0e6dd39598_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e75732c00d3c712bad62d342741b9e74_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2dd82f6a78c2c1ad037efdae0ab13a60_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\af8975d42acc12e87932016f2a331704_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8593cbc505a464a4724e7da450c4de6d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\469d23183d41f160c4aa689d987e3266_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5590079fdfb5b2a1c1d5c3ae2023dc1e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b8ddb02fde77601cdf7051405fa3ff6e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2de230b30e0e825b31ebb7d5e0fc76d3_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9c2a49cb8d4793944c5b54485d7464f2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0737754873902846d091a738ec3abc50_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\77702617987d6a17b8401df89e8e4222_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7085d72facaf50e3402c06b5b2169365_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\6e83b0bc0f9c656fd3e93e1c7155c603_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\41b66cf2785ca1487e6dc37a51648cac_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\6b31e974e0da5e9dbb15c0ded8e41080_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8d48091a4b437d72a3564dcaa7320df5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0d36ad438f11b6ae4ee3ec978fec1aef_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\57fbd6d7626f57438f9df540d7d7641c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\862771209329a0855f4816b30d2996d2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1e5b5cf17471e7471c476908f46dfaa5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f270d593e0af3761a787b5e59aa0b43b_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b4be9090241b67cc58498564863e0966_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9b7467cfdb00a48a56802f4607409e57_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\72e0d1da-7bf4-464f-8f92-29d43e61ddbe
  • %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2ae7e1cabc5aafc4f8b833de2c4731bc_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ead06367b1384ace4221fd362ec2cfed_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • C:\Mis Documentos\Documento1.docx
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d5273429617d6742f573651a1be4e542_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c86a6858aced4360e7434a00e997713e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9baf52474d18f2fba564d28f0d23b0c7_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\830269043d0adc12d781fb031a2e7cf3_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\aa5effd4accafe8a9162667ba8285abf_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\cdd9b25321ae3d5a535028009ad556cc_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1075456629268ccaf89343c1f4e334bc_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f537ba6fea44e88774ac2534c7782a88_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7d75d684616cd07d4d4e68a3eb1de76f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b5f8ac4776fb80dfa1f3fe721f0e758d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8e3871a98ec40c6f295ff915f45546c1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1bc97e803f1be311d485cedd133e6f34_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\cd02e32f610d987d1b07748ce5c0504e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9735f2f53b5356b6c323eb808e939364_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\bb1a65a499cea0e7b1d72daa86fdd02a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3551a2aa38d3da4750c2cf0116f52636_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2d84d84e9acb1185634cce2dd779570e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ef82d2a511e1c10bce16dc8498cc5fd0_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\06661d55bae50dbcf5533672b01ec4b6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9e4f2c73cbce88128a0bc1e719bc30a8_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\139fb0be399dda2cb3e155d73698b34f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3bbe91e34f46fd2532f69202e482c2a6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\579b0eadfa791055eb4ca1b0a12b02f1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9d7353f911c728be52cfb6b23190d7f1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1919e465726538629722b4bd4aa8d478_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3dca457901743b084b1a7a411f755e69_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\47ae144604bc83308da6d3ea6aac1b69_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\402e9b70dff4d3208cd435e6b07d9dc1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1d85c560028fdfd5de249aa5957e3d8c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e07ab887ac1c22aeebdd413c26c8dd4f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f3b199510f9f7fd16044b28e667b6edd_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1282344ebae76f52ee6f63e9e17356fd_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c010e1b4c6f4f141e0c965c04cedb82d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\441d4cab53ead42627dd8c7bcea96672_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5fc1e35bd038ba0b430b84e57e547de5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\06cd4306d0f8c2eaf617d4944d615660_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\bf8d82ec90faffbb89686398e4b5e2df_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\377fe0ab31cf8b649b13181d37936670_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9accfac35a19c743f5690760fd377476_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e2750f13e1efc0a3ffa772c529ce9f34_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\54680c77692985ad2205670f10db110d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0118df00b1741e4d8dccec05973a4be2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\65cd1585bed8b2beb6b98fc2f7c3dc86_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ad98098d867f6ba1dd167713bb268c5c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5248b4ff581ee37b92fb33289551901b_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\46636ae890650bca2c63e80056284c0a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\a2b999e425d30ba498f4f4e8dc891cab_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\421e448cb553f2c15500a6dbb6a80eb2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\4896c9a2ceb602fdea491fea86e90009_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\dcfc7ea6d07b4b46772712c85ca0b925_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\bb6023acf3253c4eace5317e91161e46_23ef5514-3059-436f-a4a7-4cefaab20eb1
Sets the 'hidden' attribute to the following files:
  • <DRIVERS>\etc\hosts
  • <Full path to virus>
Deletes the following files:
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5590079fdfb5b2a1c1d5c3ae2023dc1e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d02b9d505d65f03d079bcf7aa296400f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\469d23183d41f160c4aa689d987e3266_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b8ddb02fde77601cdf7051405fa3ff6e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2dd82f6a78c2c1ad037efdae0ab13a60_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e75732c00d3c712bad62d342741b9e74_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f27be37f58c963a4e91dc0c590b2e944_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f5dc82e24720792c6c6bde0e6dd39598_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c86a6858aced4360e7434a00e997713e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\830269043d0adc12d781fb031a2e7cf3_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f537ba6fea44e88774ac2534c7782a88_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d5273429617d6742f573651a1be4e542_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8593cbc505a464a4724e7da450c4de6d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\af8975d42acc12e87932016f2a331704_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9baf52474d18f2fba564d28f0d23b0c7_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\57fbd6d7626f57438f9df540d7d7641c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\41b66cf2785ca1487e6dc37a51648cac_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b5f8ac4776fb80dfa1f3fe721f0e758d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\377fe0ab31cf8b649b13181d37936670_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7085d72facaf50e3402c06b5b2169365_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\77702617987d6a17b8401df89e8e4222_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\54680c77692985ad2205670f10db110d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e2750f13e1efc0a3ffa772c529ce9f34_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\bf8d82ec90faffbb89686398e4b5e2df_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9accfac35a19c743f5690760fd377476_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0d36ad438f11b6ae4ee3ec978fec1aef_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9b7467cfdb00a48a56802f4607409e57_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\6e83b0bc0f9c656fd3e93e1c7155c603_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\6b31e974e0da5e9dbb15c0ded8e41080_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2de230b30e0e825b31ebb7d5e0fc76d3_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0737754873902846d091a738ec3abc50_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8d48091a4b437d72a3564dcaa7320df5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9c2a49cb8d4793944c5b54485d7464f2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7d75d684616cd07d4d4e68a3eb1de76f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d8c8094c8995f9eb8e85940701685562_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ecbeed897ad96ec37f5370e505a8638c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c0d4dafe9b2df1f86b0fc92b65b2857a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1075456629268ccaf89343c1f4e334bc_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\255d8de8caf6d7cd434dc664820e8602_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1763ac119c670bd0534ba5ee61ec0ac1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0bab8fa809394543a18a425f827c2e66_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d565a3f49424f4ca12d8aaf61ab10b19_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2aa5ee63cf709c6a1c473ba849a7bece_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\470f2426ffa4cf8b514e0d77ef71a98c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\88bba7c20797c95d326bba285a694e48_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\943914add085ed24ff61c3a218f5f779_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ebd06623d90f094a7131dd4860c9acd5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\49b1bc89879f8a77bb25e437459688ad_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3caa5ff5bcad64ddde3af717a0c25173_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b3a8e12003477046020f28315a6603ca_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\aa5effd4accafe8a9162667ba8285abf_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\55514e1179bf081fe3ac25e374e72996_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b4be9090241b67cc58498564863e0966_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0eab44f2b1ace4aa7919e8e1a75b10da_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\a5b319d2c5e1a53dfa6568ba33e6287b_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8c8642ea9710e9ae6a7b11ff93835324_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ff0323f0d07f5fa776b6cd3095ee183d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d4999e9a36342bdf1ef7dd6b0bea322d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7a38b6dcf5b162f5870a2bd27949aba3_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b96c874ce09170940023408aa61eb9bc_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b4afdac5f4cf0353e57abcdfe0458bec_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7fefe46a4a5748f258b0e75d90b6798d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\dcac20213ac939fd8991293cb8984085_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5e58b5d058efa749c5b4533340e3b55a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b6ccef48524a63f3186910ef03969ec6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ce2084bbb8f858972067cf15a87007f2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\cdd9b25321ae3d5a535028009ad556cc_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7879cc8495dbbdf8090879e92b342875_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\4cf683befb480f0ce41d3848c90988d1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9d7353f911c728be52cfb6b23190d7f1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\04538e9294ad866d3675b2566cf0e74d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\37b2730d216943313d9a5beef7fffea9_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0a1280a8258d185209ed91a7e3048be6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9999b742ef5f6e214f97420daa65c953_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1fa3647b1e7be33a355e319c41072dfa_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1d85c560028fdfd5de249aa5957e3d8c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3bbe91e34f46fd2532f69202e482c2a6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\4d7926b4eb0fd3e5d2444dec283e4a94_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e07ab887ac1c22aeebdd413c26c8dd4f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1919e465726538629722b4bd4aa8d478_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\7ab1f3e46e4bcdca237f882aafd2162e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\139fb0be399dda2cb3e155d73698b34f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\579b0eadfa791055eb4ca1b0a12b02f1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\01ed52990a5f3fd4a44b615bbbd28850_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2d599c40540743cc152980283899dd27_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2a52b5e5658aa9ae7cd35db6c7849e0b_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5c146e9935a7771327f4984fcdfa1732_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\52ca1b5a6aca757c0a8f90204b9100bd_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\e730920c733d19286083aa4c3fff850e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • <DRIVERS>\etc\hosts
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\a621ce6a307d1d56f2bcfbcf8b247e25_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c86ddbeeafe8f1937d6379cf45e2063c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\21c73b3932803b1af0f64cba55a36d15_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\17ae677668b956d3cabd5f9b9639b5bf_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\40de4666dc9b88ca77cf85e6883a1c34_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c20392a941404a4fee3d6741027e53b8_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d2158461183921dd3908fba24dd341e2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b783f6043af420792100edda6bd1124f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8706112e365cef39e0ee1bb5e7e4711e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9856672f991fc8c4f245974e5081190c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\402e9b70dff4d3208cd435e6b07d9dc1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\bb6023acf3253c4eace5317e91161e46_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\dcfc7ea6d07b4b46772712c85ca0b925_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\862771209329a0855f4816b30d2996d2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\4896c9a2ceb602fdea491fea86e90009_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1e5b5cf17471e7471c476908f46dfaa5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ad98098d867f6ba1dd167713bb268c5c_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\65cd1585bed8b2beb6b98fc2f7c3dc86_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\0118df00b1741e4d8dccec05973a4be2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1282344ebae76f52ee6f63e9e17356fd_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\441d4cab53ead42627dd8c7bcea96672_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\c010e1b4c6f4f141e0c965c04cedb82d_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f270d593e0af3761a787b5e59aa0b43b_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\421e448cb553f2c15500a6dbb6a80eb2_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\a2b999e425d30ba498f4f4e8dc891cab_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\06cd4306d0f8c2eaf617d4944d615660_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5fc1e35bd038ba0b430b84e57e547de5_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\46636ae890650bca2c63e80056284c0a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ead06367b1384ace4221fd362ec2cfed_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\cd02e32f610d987d1b07748ce5c0504e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1bc97e803f1be311d485cedd133e6f34_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\8e3871a98ec40c6f295ff915f45546c1_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\47ae144604bc83308da6d3ea6aac1b69_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3dca457901743b084b1a7a411f755e69_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\bb1a65a499cea0e7b1d72daa86fdd02a_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9735f2f53b5356b6c323eb808e939364_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2d84d84e9acb1185634cce2dd779570e_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\3551a2aa38d3da4750c2cf0116f52636_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\5248b4ff581ee37b92fb33289551901b_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\f3b199510f9f7fd16044b28e667b6edd_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\9e4f2c73cbce88128a0bc1e719bc30a8_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\06661d55bae50dbcf5533672b01ec4b6_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\2ae7e1cabc5aafc4f8b833de2c4731bc_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ef82d2a511e1c10bce16dc8498cc5fd0_23ef5514-3059-436f-a4a7-4cefaab20eb1
Substitutes the HOSTS file.
Network activity:
Connects to:
  • 'ce####teunion.com':80
  • 'wp#d':80
TCP:
HTTP GET requests:
  • ce####teunion.com/_server/editor/images/1.txt
  • wp#d/wpad.dat
UDP:
  • DNS ASK ce####teunion.com
  • DNS ASK wp#d

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android