Trojan-Downloader.Win32.Cutwail_217b643887
HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.Win32.Generic!BT (VIPRE), Trojan-Downloader.Win32.Cutwail!IK (Emsisoft), GenericInjector.YR (Lavasoft MAS)
Behaviour: Trojan-Downloader, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
MD5: 217b643887dd7ad9ef4151832dc1b401
SHA1: a069bc6775712d1cb0a08292eae7165ebac6f16b
SHA256: 95ef97b5e2c79b07c9607fb5fc0cad2a6b1854200ecc3d4d75af511f0e78c343
SSDeep: 768:tdt0631lXgLa1RKCuU96162lO 6jfFJiQQV0kpSVoiHYBQhBYpJw2xsvPK:tH0ClQLavtY1D6zFDs0/Ki4qmrRq6
Size: 142339 bytes
File type: PE32
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2013-07-28 00:17:31
Summary:
Trojan-Downloader. Trojan program, which downloads files from the Internet without user's notice and executes them.
Payload
No specific payload has been found.
Process activity
The Trojan-Downloader creates the following process(es):
217b643887dd7ad9ef4151832dc1b401.exe:1860
The Trojan-Downloader injects its code into the following process(es):
217b643887dd7ad9ef4151832dc1b401.exe:740
File activity
The process 217b643887dd7ad9ef4151832dc1b401.exe:740 makes changes in a file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@topex[1].txt (185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\djkentaro[1].htm (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\starmedia[1].htm (466 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\dithd[1].htm (173 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ixtractor[1].htm (801 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\brijindia[1].htm (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\violadagamba[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@totalearthcare.com[1].txt (241 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\fujino-lab[1].htm (2057 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\paulrenna[1].htm (1225 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@ziuabarbatului[1].txt (158 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[1].txt (147 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\celebikalip.com[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\csmbc[1].htm (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\teknorhino[1].htm (2124 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\google[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\atr-technologies[1].htm (18 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[2].txt (301 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\index[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\teasing-video[1].htm (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\dormfantasies[1].htm (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\racknstackwarehouse.com[1].htm (1340 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@glmghotels[1].txt (219 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\actfactory[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\tessera.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[1].txt (150 bytes)
%Documents and Settings%\%current user%\rapixxagibna.exe (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\suspended[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@winery[1].txt (224 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\paulrenna[1].htm (277 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\cath4choice[1].htm (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\niray.com[1].htm (1480 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mibsga[1].htm (14 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@facebook[1].txt (172 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1844237615-1960408961-1801674531-1003\c5b88721db08c824db69d0bbc702beb8_75ed9567-aa58-4c8e-a8ea-3cad7c47ab03 (881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\capitalcitytuxedo[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\tollefsondesign[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ompgp.co[1].htm (17 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (29108 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\winery[1] (248 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\unitedearthgroup[1].htm (523 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\egao[1].htm (15 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[1].txt (1878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\e-shuukyaku[1].htm (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gjk.com[1].htm (24 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@topex[2].txt (332 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\tss[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\m[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[1].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\chscreative[1].htm (1736 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shipeliteexpress[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[2].txt (321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mastechn[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\thedonaldsongroup[1].htm (833 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\geodecisions[1].htm (40 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@msasys[1].txt (204 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\momonophoto[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\suspendedpage[2].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\iktus[1].htm (78 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sydney[1].htm (357 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sun-ele.co[1].htm (11 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[2].txt (147 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[2].txt (1324 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\osouji-school[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\aipi.co[1].htm (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ans-service[1].htm (107 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\vanguardpkg[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[2].htm (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\google[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\fraser-high.school[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\precisionsolutionsky[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\boundbydesign[1].htm (10 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geodecisions[1].txt (273 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\westsidechurch[1].htm (17 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@neurotoxininstitute[1].txt (237 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[2].txt (160 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pixemia[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\acsmedioambiente[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\frederickallergy[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sarpy[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\naijagurus[1].htm (573 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\capitalcitytuxedo[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\trenpalau[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (1103 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[2].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sun-ele.co[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\eygwindows.co[1].htm (822 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\le-mariage[1].htm (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\floridadoubled[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\arckepesajandek[1].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\kafrit[1].htm (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\cabooseonline[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\theprintinghouseltd.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[1].txt (157 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\mojacar-vacaciones[1].htm (876 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\koetterfireprotection[1].htm (1522 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[3].txt (641 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\geothermusa[1].htm (498 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[1].txt (160 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\violadagamba[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\easyformations[1].htm (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\paulrenna[1].htm (277 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\cksglobal[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\etcycles[1].htm (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\easygen[1].htm (13 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (323 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\acsmedioambiente[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\forslav[1].htm (270 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\photoclubs[1].htm (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jacksonsallamerican[1].htm (1178 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@easyformations[1].txt (152 bytes)
The Trojan-Downloader deletes the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@google[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\arckepesajandek[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sun-ele.co[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\violadagamba[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\google[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@topex[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[2].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\tutuji-saitama[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shs-sales.co[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[3].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\capitalcitytuxedo[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\paulrenna[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\paulrenna[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\acsmedioambiente[1].htm (0 bytes)
Registry activity
The process 217b643887dd7ad9ef4151832dc1b401.exe:740 makes changes in a system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"AppManagement" = "74 D8 B0 88 60 38 10 E7 BF 97 6F 47 1F F6 CE A6"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "81 70 A4 FA F9 72 79 FE 5F D1 19 30 57 18 F5 05"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"rapixxagibnazap" = "66 CA A2 7A 52 2A 02 D9 25 FC D4 AC 84 5C 34 0C"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
To automatically run itself each time Windows is booted, the Trojan-Downloader adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"rapixxagibna" = "%Documents and Settings%\%current user%\rapixxagibna.exe"
The Trojan-Downloader modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan-Downloader modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan-Downloader modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan-Downloader deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
Network activity (URLs)
| URL | IP |
|---|---|
| hxxp://photoclubs.com/ | |
| hxxp://penavision.co.in/ | |
| hxxp://nataliecurtiss.com/ | |
| hxxp://teasing-video.com/ | |
| hxxp://alternative-aquitaine.co.uk/ | |
| hxxp://marcusgrimes.co.uk/ | |
| hxxp://nazcapictures.com/ | |
| hxxp://gamblingonlinemagazine.com/ | |
| hxxp://kvadratoff.ru/ | |
| hxxp://kafrit.com/ | |
| hxxp://arckepesajandek.hu/ | |
| hxxp://sun-ele.co.jp/ | |
| hxxp://ans-service.com/ | |
| hxxp://enzoyrodrigo.com.br/ | |
| hxxp://osouji-school.com/ | |
| hxxp://victoria.com.pl/ | |
| hxxp://korta-sa.com/ | |
| hxxp://merceorti.com/ | |
| hxxp://www.google.com/ | |
| hxxp://error.logol.ru/suspended/ | |
| hxxp://icigrain.com/ | |
| hxxp://www.google.ca/?gws_rd=cr | |
| hxxp://unitedearthgroup.com/ | |
| hxxp://icigrain.com/cgi-sys/suspendedpage.cgi | |
| hxxp://thesergery.com/ | |
| hxxp://myfilecenter.com/ | |
| hxxp://ajdo.net/ | |
| hxxp://krafthaus.com/ | |
| hxxp://perc.ca/ | |
| hxxp://kamaruka.vic.edu.au/ | |
| hxxp://fujino-lab.com/ | |
| hxxp://norakuroya.com/ | |
| hxxp://stormwildlifeart.com/ | |
| hxxp://momonophoto.com/ | |
| hxxp://tenpole.com/ | |
| hxxp://violadagamba.com/ | |
| hxxp://agrarno.ru/ | |
| hxxp://selldoor.pl/ | |
| hxxp://avisay.com/ | |
| hxxp://tutuji-saitama.com/ | |
| hxxp://microsoft.com/ | |
| hxxp://selldoor.pl/m/ | |
| hxxp://chscreative.com/ | |
| hxxp://nuritech.com/ | |
| hxxp://lb1.www.ms.akadns.net/ | |
| hxxp://paulrenna.com/ | |
| hxxp://cksglobal.net/ | |
| hxxp://egao.net/ | |
| hxxp://lb1.www.ms.akadns.net/en-ca/default.aspx | |
| hxxp://sigmametalsinc.com/ | |
| hxxp://neurotoxininstitute.com/ | |
| hxxp://glmghotels.com/ | |
| hxxp://niray.com.cn/ | |
| hxxp://www.sigmaaero.com/ | |
| hxxp://westhillsstl.org/ | |
| hxxp://espace-hotelier.com/ | |
| hxxp://miltinio-teatras.lt/ | |
| hxxp://unslp.edu.bo/ | |
| hxxp://meubles-jacquelin.com/ | |
| hxxp://midwestga.com/ | |
| hxxp://mibsga.com/ | |
| hxxp://leadershipforum.us/ | |
| hxxp://sztartufi.com/ | |
| hxxp://pcpeds.com/ | |
| hxxp://mastechn.com/ | |
| hxxp://gcs-cpa.com/ | |
| hxxp://nd-evenementiel.com/ | |
| hxxp://dithd.com/ | |
| hxxp://capitalcitytuxedo.com/ | |
| hxxp://easyformations.net/ | |
| hxxp://frederickallergy.com/ | |
| hxxp://arquiteturadigital.com/ (Malicious) | |
| hxxp://jacksonsallamerican.com/ | |
| hxxp://bigtopmultimedia.com/ | |
| hxxp://topex.ro/ | |
| hxxp://beechwoodmetalworks.com/ | |
| hxxp://wkhk.net/ | |
| hxxp://le-mariage.com/ | |
| hxxp://actfactory.net/ | |
| hxxp://rewardhits.com/ | |
| hxxp://thedonaldsongroup.com/ | |
| hxxp://e-storming.com/ | |
| hxxp://avant-ime.com/ | |
| hxxp://chocolatecovers.com/ | |
| hxxp://starmedia.ca/ | |
| hxxp://heliomare.nl/ | |
| hxxp://youjoomla.com/ | |
| hxxp://mastergrp-spb.ru/ | |
| hxxp://mastergrp-spb.ru/cgi-sys/suspendedpage.cgi | |
| hxxp://geodecisions.com/ | |
| hxxp://ezmedi.com/ | |
| hxxp://berkshirebusiness.org/ | |
| hxxp://etcycles.com/ | |
| hxxp://mattiussiecologia.com/ | |
| hxxp://pixemia.com/ | |
| hxxp://mattiussiecologia.com/en/index.aspx | |
| hxxp://denville.ca/ | |
| hxxp://msasys.com/ | |
| hxxp://coe.pku.edu.cn/ | |
| hxxp://tavdi.com/ | |
| hxxp://toddpipe.com/ | |
| hxxp://boundbydesign.com/ | |
| hxxp://adultlivechat.us/ | |
| hxxp://precisionsolutionsky.com/ | |
| hxxp://shs-sales.co.uk/ | |
| hxxp://ixtractor.com/ | |
| hxxp://cath4choice.org/ | |
| hxxp://djkentaro.com/ | |
| hxxp://stecom.nl/ | |
| hxxp://shipeliteexpress.com/ | |
| hxxp://theprintinghouseltd.co.uk/ | |
| hxxp://figabara.com/ | |
| hxxp://colourprint.nl/ | |
| hxxp://eomc.net/ | |
| hxxp://isp-h.com/ | |
| hxxp://fleshercorp.com/ | |
| hxxp://acsmedioambiente.com/ | |
| hxxp://biurimex.pl/ | |
| hxxp://tss.org/ | |
| hxxp://orion-networks.net/ | |
| hxxp://trenpalau.com/ | |
| hxxp://woodlandhillwinery.com/ | |
| hxxp://woodlandhillwinery.com/winery/ | |
| hxxp://hoyuu.com/ | |
| hxxp://westsidechurch.org/ | |
| hxxp://graintrain.coop/ | |
| hxxp://acmepacificrepairs.com/ | |
| hxxp://fruitspot.co.za/ | |
| hxxp://nori-k.com/ | |
| hxxp://paintball.be/ | |
| hxxp://dormfantasies.com/ | |
| hxxp://spiti.org/ | |
| hxxp://fastarchofamerica.com/ | |
| hxxp://ompgp.co.jp/ | |
| hxxp://kagu-hokuren.com/ | |
| hxxp://atr-technologies.com/ | |
| hxxp://e-kagami.com/ | |
| hxxp://vanguardpkg.com/ | |
| hxxp://fraser-high.school.nz/ | |
| hxxp://cabooseonline.com/ | |
| hxxp://asterisk.com.sg/ | |
| hxxp://istanbultarim.com.tr/ | |
| hxxp://schiedel.it/ | |
| hxxp://racknstackwarehouse.com.au/ | |
| hxxp://combine.or.id/ | |
| hxxp://optiver.com.au/ | |
| hxxp://sdlp.ie/ | |
| hxxp://www.optiver.com/sydney/ | |
| hxxp://shbrazil.com/ | |
| hxxp://audience-web.net/ | |
| hxxp://audience-web.net/cgi-sys/suspendedpage.cgi | |
| hxxp://churchsupplies.net/ | |
| hxxp://padstow.com/ | |
| hxxp://authentica-travel.com/ | |
| hxxp://screaminpeach.com/ | |
| hxxp://theartofhair.com/ | |
| hxxp://wildrosemarketing.com/ | |
| hxxp://csmbc.org/ | |
| hxxp://lognetic.com/ | |
| hxxp://mojacar-vacaciones.com/ | |
| hxxp://tollefsondesign.com/ | |
| hxxp://xing-group.com/ | |
| hxxp://malagacorp.com/ | |
| hxxp://brijindia.com/ | |
| hxxp://floridadoubled.com/ | |
| hxxp://easygen.com/ | |
| hxxp://empordalia.com/ | |
| hxxp://totalearthcare.com.au/ | |
| hxxp://austriansurfing.at/ | |
| hxxp://celebikalip.com.tr/ | |
| hxxp://aipi.co.nz/ | |
| hxxp://areafor.com/ | |
| hxxp://totalearthcare.com.au/cgi-sys/suspendedpage.cgi | |
| hxxp://lockerlookz.com/ | |
| hxxp://forslav.com/ (Malicious) | |
| hxxp://gjk.com.pl/ | |
| hxxp://bigjohnsbeefjerky.com/ | |
| hxxp://eyggroup.com/ | |
| hxxp://eygwindows.co.uk/ | |
| hxxp://s2s.fr/ | |
| hxxp://iktus.fr/ | |
| hxxp://coopsupermarkt.nl/ | |
| hxxp://telenavis.com/ | |
| hxxp://sarpy.com/ | |
| hxxp://koetterfireprotection.com/ | |
| hxxp://geothermusa.com/ | |
| hxxp://tessera.co.jp/ | |
| hxxp://tvndra.net/ | |
| hxxp://agence-des-druides.com/ | |
| meridies.org | |
| digpro.se | |
| www.ixtractor.com | |
| www.photoclubs.com | |
| reyesconstruction.com | |
| www.msasys.com | |
| in1.smtp.messagingengine.com | |
| www.microsoft.com | |
| plainscotton.org | |
| bredainternet.nl | |
| testpile.com | |
| indianz.com | |
| www.cabooseonline.com | |
| surfinggoatdairy.com | |
| shakeyspizza.ph | |
| emconfm.com | |
| www.ans-service.com | |
| serviamus.com | |
| cbsprinting.com.au | |
| www.jacksonsallamerican.com | |
| qginformatik.com | |
| www.atr-technologies.com | |
| kashiwa-kk.com | |
| btitravel.com | |
| eternalbeautyproducts.com.au | |
| firealarms.com | |
| rcap.org | |
| adfolsa.com.ec | |
| naijagurus.com | |
| konishi-hp.com | |
| smtp.mail.yahoo.com | |
| www.momonophoto.com | |
| vnhanoi.com | |
| justconnect.co.za | |
| fnam.pt | |
| www.westsidechurch.org | |
| clx.com.br | |
| alt4.gmail-smtp-in.l.google.com | |
| hartmultimedia.com | |
| sensasilelaki.com | |
| skaner.com.pl | |
| cyclo-tourisme.com | |
| 4pipp.com | |
| www.kagu-hokuren.com | |
| mxs.mail.ru | |
| www.racknstackwarehouse.com.au | |
| acetravel-lb.com | |
| www.beechwoodmetalworks.com | |
| dicksvalleyservice.com | |
| ziuabarbatului.ro | |
| aiem.qc.ca | |
| academiakurutziaga.com | |
| hillusa.com | |
| www.wkhk.net | |
| debtrescueusa.com | |
| doctsf.com | |
| studiolegalegiommi.it | |
| www.myfilecenter.com | |
| www.facebook.com | |
| www.gamblingonlinemagazine.com | |
| www.bigjohnsbeefjerky.com | |
| www.mibsga.com | |
| e-shuukyaku.com | |
| nc-concept.com | |
| www.westhillsstl.org | |
| medischmanagement.nl | |
| weinbauerfinancial.com | |
| www.djkentaro.jp | |
| gmail-smtp-in.l.google.com | |
| www.hoyuu.com | |
| www.teknorhino.com | |
| www.chscreative.com | |
| theautospas.com | |
| lotuswell.ch | |
| bitlarge.com | |
| mail7.digitalwaves.co.nz | |
| engsmotortruck.com | |
| yalestreet.com | |
| www.eygwindows.co.uk | |
| vexolpost.com | |
| herpes-zone.com | |
| x-cellcommunications.de | |
| choice-select.com | |
| audio-direkt.net | |
| ballandwall.biz | |
| sspackaginggroup.com | |
| golfpark-moossee.ch |
Rootkit activity
No anomalies have been detected.
Propagation
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
217b643887dd7ad9ef4151832dc1b401.exe:1860
- Delete the original Trojan-Downloader file.
- Delete or disinfect the following files created/modified by the Trojan-Downloader:
%Documents and Settings%\%current user%\Cookies\Current_User@topex[1].txt (185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\djkentaro[1].htm (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\starmedia[1].htm (466 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\dithd[1].htm (173 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ixtractor[1].htm (801 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\brijindia[1].htm (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\violadagamba[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@totalearthcare.com[1].txt (241 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\fujino-lab[1].htm (2057 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\paulrenna[1].htm (1225 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@ziuabarbatului[1].txt (158 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[1].txt (147 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\celebikalip.com[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\csmbc[1].htm (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\teknorhino[1].htm (2124 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\google[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\atr-technologies[1].htm (18 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[2].txt (301 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\index[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\teasing-video[1].htm (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\dormfantasies[1].htm (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\racknstackwarehouse.com[1].htm (1340 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@glmghotels[1].txt (219 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\actfactory[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\tessera.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[1].txt (150 bytes)
%Documents and Settings%\%current user%\rapixxagibna.exe (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\suspended[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@winery[1].txt (224 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\paulrenna[1].htm (277 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\cath4choice[1].htm (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\niray.com[1].htm (1480 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mibsga[1].htm (14 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@facebook[1].txt (172 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1844237615-1960408961-1801674531-1003\c5b88721db08c824db69d0bbc702beb8_75ed9567-aa58-4c8e-a8ea-3cad7c47ab03 (881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\capitalcitytuxedo[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\tollefsondesign[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ompgp.co[1].htm (17 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (29108 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\winery[1] (248 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\unitedearthgroup[1].htm (523 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\egao[1].htm (15 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[1].txt (1878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\e-shuukyaku[1].htm (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gjk.com[1].htm (24 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@topex[2].txt (332 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\tss[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\m[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[1].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\chscreative[1].htm (1736 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shipeliteexpress[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[2].txt (321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mastechn[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\thedonaldsongroup[1].htm (833 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\geodecisions[1].htm (40 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@msasys[1].txt (204 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\momonophoto[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\suspendedpage[2].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\iktus[1].htm (78 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sydney[1].htm (357 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sun-ele.co[1].htm (11 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[2].txt (147 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[2].txt (1324 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\osouji-school[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\aipi.co[1].htm (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ans-service[1].htm (107 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\vanguardpkg[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[2].htm (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\google[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\fraser-high.school[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\precisionsolutionsky[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\boundbydesign[1].htm (10 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geodecisions[1].txt (273 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\westsidechurch[1].htm (17 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@neurotoxininstitute[1].txt (237 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[2].txt (160 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pixemia[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\acsmedioambiente[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\frederickallergy[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sarpy[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\naijagurus[1].htm (573 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\capitalcitytuxedo[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\trenpalau[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (1103 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[2].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sun-ele.co[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\eygwindows.co[1].htm (822 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\le-mariage[1].htm (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\floridadoubled[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\arckepesajandek[1].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\kafrit[1].htm (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\cabooseonline[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\theprintinghouseltd.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[1].txt (157 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\mojacar-vacaciones[1].htm (876 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\koetterfireprotection[1].htm (1522 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[3].txt (641 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\geothermusa[1].htm (498 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[1].txt (160 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\violadagamba[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\easyformations[1].htm (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\paulrenna[1].htm (277 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\cksglobal[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\etcycles[1].htm (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\easygen[1].htm (13 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (323 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\acsmedioambiente[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\forslav[1].htm (270 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\photoclubs[1].htm (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jacksonsallamerican[1].htm (1178 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@easyformations[1].txt (152 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"rapixxagibna" = "%Documents and Settings%\%current user%\rapixxagibna.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.