Trojan-Downloader.Win32.Cutwail_217b643887
HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.Win32.Generic!BT (VIPRE), Trojan-Downloader.Win32.Cutwail!IK (Emsisoft), GenericInjector.YR (Lavasoft MAS)
Behaviour: Trojan-Downloader, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
MD5: 217b643887dd7ad9ef4151832dc1b401
SHA1: a069bc6775712d1cb0a08292eae7165ebac6f16b
SHA256: 95ef97b5e2c79b07c9607fb5fc0cad2a6b1854200ecc3d4d75af511f0e78c343
SSDeep: 768:tdt0631lXgLa1RKCuU96162lO 6jfFJiQQV0kpSVoiHYBQhBYpJw2xsvPK:tH0ClQLavtY1D6zFDs0/Ki4qmrRq6
Size: 142339 bytes
File type: PE32
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2013-07-28 00:17:31
Summary:
Trojan-Downloader. Trojan program, which downloads files from the Internet without user's notice and executes them.
Payload
No specific payload has been found.
Process activity
The Trojan-Downloader creates the following process(es):
217b643887dd7ad9ef4151832dc1b401.exe:1860
The Trojan-Downloader injects its code into the following process(es):
217b643887dd7ad9ef4151832dc1b401.exe:740
File activity
The process 217b643887dd7ad9ef4151832dc1b401.exe:740 makes changes in a file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@topex[1].txt (185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\djkentaro[1].htm (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\starmedia[1].htm (466 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\dithd[1].htm (173 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ixtractor[1].htm (801 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\brijindia[1].htm (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\violadagamba[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@totalearthcare.com[1].txt (241 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\fujino-lab[1].htm (2057 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\paulrenna[1].htm (1225 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@ziuabarbatului[1].txt (158 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[1].txt (147 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\celebikalip.com[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\csmbc[1].htm (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\teknorhino[1].htm (2124 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\google[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\atr-technologies[1].htm (18 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[2].txt (301 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\index[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\teasing-video[1].htm (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\dormfantasies[1].htm (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\racknstackwarehouse.com[1].htm (1340 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@glmghotels[1].txt (219 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\actfactory[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\tessera.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[1].txt (150 bytes)
%Documents and Settings%\%current user%\rapixxagibna.exe (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\suspended[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@winery[1].txt (224 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\paulrenna[1].htm (277 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\cath4choice[1].htm (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\niray.com[1].htm (1480 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mibsga[1].htm (14 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@facebook[1].txt (172 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1844237615-1960408961-1801674531-1003\c5b88721db08c824db69d0bbc702beb8_75ed9567-aa58-4c8e-a8ea-3cad7c47ab03 (881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\capitalcitytuxedo[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\tollefsondesign[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ompgp.co[1].htm (17 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (29108 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\winery[1] (248 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\unitedearthgroup[1].htm (523 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\egao[1].htm (15 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[1].txt (1878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\e-shuukyaku[1].htm (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gjk.com[1].htm (24 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@topex[2].txt (332 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\tss[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\m[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[1].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\chscreative[1].htm (1736 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shipeliteexpress[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[2].txt (321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mastechn[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\thedonaldsongroup[1].htm (833 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\geodecisions[1].htm (40 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@msasys[1].txt (204 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\momonophoto[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\suspendedpage[2].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\iktus[1].htm (78 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sydney[1].htm (357 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sun-ele.co[1].htm (11 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[2].txt (147 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[2].txt (1324 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\osouji-school[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\aipi.co[1].htm (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ans-service[1].htm (107 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\vanguardpkg[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[2].htm (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\google[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\fraser-high.school[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\precisionsolutionsky[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\boundbydesign[1].htm (10 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geodecisions[1].txt (273 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\westsidechurch[1].htm (17 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@neurotoxininstitute[1].txt (237 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[2].txt (160 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pixemia[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\acsmedioambiente[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\frederickallergy[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sarpy[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\naijagurus[1].htm (573 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\capitalcitytuxedo[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\trenpalau[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (1103 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[2].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sun-ele.co[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\eygwindows.co[1].htm (822 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\le-mariage[1].htm (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\floridadoubled[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\arckepesajandek[1].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\kafrit[1].htm (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\cabooseonline[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\theprintinghouseltd.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[1].txt (157 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\mojacar-vacaciones[1].htm (876 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\koetterfireprotection[1].htm (1522 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[3].txt (641 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\geothermusa[1].htm (498 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[1].txt (160 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\violadagamba[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\easyformations[1].htm (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\paulrenna[1].htm (277 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\cksglobal[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\etcycles[1].htm (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\easygen[1].htm (13 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (323 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\acsmedioambiente[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\forslav[1].htm (270 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\photoclubs[1].htm (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jacksonsallamerican[1].htm (1178 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@easyformations[1].txt (152 bytes)
The Trojan-Downloader deletes the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@google[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\arckepesajandek[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sun-ele.co[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\violadagamba[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\google[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@topex[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[2].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\tutuji-saitama[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shs-sales.co[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[3].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\capitalcitytuxedo[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\paulrenna[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\paulrenna[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\acsmedioambiente[1].htm (0 bytes)
Registry activity
The process 217b643887dd7ad9ef4151832dc1b401.exe:740 makes changes in a system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"AppManagement" = "74 D8 B0 88 60 38 10 E7 BF 97 6F 47 1F F6 CE A6"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "81 70 A4 FA F9 72 79 FE 5F D1 19 30 57 18 F5 05"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"rapixxagibnazap" = "66 CA A2 7A 52 2A 02 D9 25 FC D4 AC 84 5C 34 0C"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
To automatically run itself each time Windows is booted, the Trojan-Downloader adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"rapixxagibna" = "%Documents and Settings%\%current user%\rapixxagibna.exe"
The Trojan-Downloader modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan-Downloader modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan-Downloader modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan-Downloader deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
Network activity (URLs)
URL | IP |
---|---|
hxxp://photoclubs.com/ | ![]() |
hxxp://penavision.co.in/ | ![]() |
hxxp://nataliecurtiss.com/ | ![]() |
hxxp://teasing-video.com/ | ![]() |
hxxp://alternative-aquitaine.co.uk/ | ![]() |
hxxp://marcusgrimes.co.uk/ | ![]() |
hxxp://nazcapictures.com/ | ![]() |
hxxp://gamblingonlinemagazine.com/ | ![]() |
hxxp://kvadratoff.ru/ | ![]() |
hxxp://kafrit.com/ | ![]() |
hxxp://arckepesajandek.hu/ | ![]() |
hxxp://sun-ele.co.jp/ | ![]() |
hxxp://ans-service.com/ | ![]() |
hxxp://enzoyrodrigo.com.br/ | ![]() |
hxxp://osouji-school.com/ | ![]() |
hxxp://victoria.com.pl/ | ![]() |
hxxp://korta-sa.com/ | ![]() |
hxxp://merceorti.com/ | ![]() |
hxxp://www.google.com/ | ![]() |
hxxp://error.logol.ru/suspended/ | ![]() |
hxxp://icigrain.com/ | ![]() |
hxxp://www.google.ca/?gws_rd=cr | ![]() |
hxxp://unitedearthgroup.com/ | ![]() |
hxxp://icigrain.com/cgi-sys/suspendedpage.cgi | ![]() |
hxxp://thesergery.com/ | ![]() |
hxxp://myfilecenter.com/ | ![]() |
hxxp://ajdo.net/ | ![]() |
hxxp://krafthaus.com/ | ![]() |
hxxp://perc.ca/ | ![]() |
hxxp://kamaruka.vic.edu.au/ | ![]() |
hxxp://fujino-lab.com/ | ![]() |
hxxp://norakuroya.com/ | ![]() |
hxxp://stormwildlifeart.com/ | ![]() |
hxxp://momonophoto.com/ | ![]() |
hxxp://tenpole.com/ | ![]() |
hxxp://violadagamba.com/ | ![]() |
hxxp://agrarno.ru/ | ![]() |
hxxp://selldoor.pl/ | ![]() |
hxxp://avisay.com/ | ![]() |
hxxp://tutuji-saitama.com/ | ![]() |
hxxp://microsoft.com/ | ![]() |
hxxp://selldoor.pl/m/ | ![]() |
hxxp://chscreative.com/ | ![]() |
hxxp://nuritech.com/ | ![]() |
hxxp://lb1.www.ms.akadns.net/ | ![]() |
hxxp://paulrenna.com/ | ![]() |
hxxp://cksglobal.net/ | ![]() |
hxxp://egao.net/ | ![]() |
hxxp://lb1.www.ms.akadns.net/en-ca/default.aspx | ![]() |
hxxp://sigmametalsinc.com/ | ![]() |
hxxp://neurotoxininstitute.com/ | ![]() |
hxxp://glmghotels.com/ | ![]() |
hxxp://niray.com.cn/ | ![]() |
hxxp://www.sigmaaero.com/ | ![]() |
hxxp://westhillsstl.org/ | ![]() |
hxxp://espace-hotelier.com/ | ![]() |
hxxp://miltinio-teatras.lt/ | ![]() |
hxxp://unslp.edu.bo/ | ![]() |
hxxp://meubles-jacquelin.com/ | ![]() |
hxxp://midwestga.com/ | ![]() |
hxxp://mibsga.com/ | ![]() |
hxxp://leadershipforum.us/ | ![]() |
hxxp://sztartufi.com/ | ![]() |
hxxp://pcpeds.com/ | ![]() |
hxxp://mastechn.com/ | ![]() |
hxxp://gcs-cpa.com/ | ![]() |
hxxp://nd-evenementiel.com/ | ![]() |
hxxp://dithd.com/ | ![]() |
hxxp://capitalcitytuxedo.com/ | ![]() |
hxxp://easyformations.net/ | ![]() |
hxxp://frederickallergy.com/ | ![]() |
hxxp://arquiteturadigital.com/ (Malicious) | ![]() |
hxxp://jacksonsallamerican.com/ | ![]() |
hxxp://bigtopmultimedia.com/ | ![]() |
hxxp://topex.ro/ | ![]() |
hxxp://beechwoodmetalworks.com/ | ![]() |
hxxp://wkhk.net/ | ![]() |
hxxp://le-mariage.com/ | ![]() |
hxxp://actfactory.net/ | ![]() |
hxxp://rewardhits.com/ | ![]() |
hxxp://thedonaldsongroup.com/ | ![]() |
hxxp://e-storming.com/ | ![]() |
hxxp://avant-ime.com/ | ![]() |
hxxp://chocolatecovers.com/ | ![]() |
hxxp://starmedia.ca/ | ![]() |
hxxp://heliomare.nl/ | ![]() |
hxxp://youjoomla.com/ | ![]() |
hxxp://mastergrp-spb.ru/ | ![]() |
hxxp://mastergrp-spb.ru/cgi-sys/suspendedpage.cgi | ![]() |
hxxp://geodecisions.com/ | ![]() |
hxxp://ezmedi.com/ | ![]() |
hxxp://berkshirebusiness.org/ | ![]() |
hxxp://etcycles.com/ | ![]() |
hxxp://mattiussiecologia.com/ | ![]() |
hxxp://pixemia.com/ | ![]() |
hxxp://mattiussiecologia.com/en/index.aspx | ![]() |
hxxp://denville.ca/ | ![]() |
hxxp://msasys.com/ | ![]() |
hxxp://coe.pku.edu.cn/ | ![]() |
hxxp://tavdi.com/ | ![]() |
hxxp://toddpipe.com/ | ![]() |
hxxp://boundbydesign.com/ | ![]() |
hxxp://adultlivechat.us/ | ![]() |
hxxp://precisionsolutionsky.com/ | ![]() |
hxxp://shs-sales.co.uk/ | ![]() |
hxxp://ixtractor.com/ | ![]() |
hxxp://cath4choice.org/ | ![]() |
hxxp://djkentaro.com/ | ![]() |
hxxp://stecom.nl/ | ![]() |
hxxp://shipeliteexpress.com/ | ![]() |
hxxp://theprintinghouseltd.co.uk/ | ![]() |
hxxp://figabara.com/ | ![]() |
hxxp://colourprint.nl/ | ![]() |
hxxp://eomc.net/ | ![]() |
hxxp://isp-h.com/ | ![]() |
hxxp://fleshercorp.com/ | ![]() |
hxxp://acsmedioambiente.com/ | ![]() |
hxxp://biurimex.pl/ | ![]() |
hxxp://tss.org/ | ![]() |
hxxp://orion-networks.net/ | ![]() |
hxxp://trenpalau.com/ | ![]() |
hxxp://woodlandhillwinery.com/ | ![]() |
hxxp://woodlandhillwinery.com/winery/ | ![]() |
hxxp://hoyuu.com/ | ![]() |
hxxp://westsidechurch.org/ | ![]() |
hxxp://graintrain.coop/ | ![]() |
hxxp://acmepacificrepairs.com/ | ![]() |
hxxp://fruitspot.co.za/ | ![]() |
hxxp://nori-k.com/ | ![]() |
hxxp://paintball.be/ | ![]() |
hxxp://dormfantasies.com/ | ![]() |
hxxp://spiti.org/ | ![]() |
hxxp://fastarchofamerica.com/ | ![]() |
hxxp://ompgp.co.jp/ | ![]() |
hxxp://kagu-hokuren.com/ | ![]() |
hxxp://atr-technologies.com/ | ![]() |
hxxp://e-kagami.com/ | ![]() |
hxxp://vanguardpkg.com/ | ![]() |
hxxp://fraser-high.school.nz/ | ![]() |
hxxp://cabooseonline.com/ | ![]() |
hxxp://asterisk.com.sg/ | ![]() |
hxxp://istanbultarim.com.tr/ | ![]() |
hxxp://schiedel.it/ | ![]() |
hxxp://racknstackwarehouse.com.au/ | ![]() |
hxxp://combine.or.id/ | ![]() |
hxxp://optiver.com.au/ | ![]() |
hxxp://sdlp.ie/ | ![]() |
hxxp://www.optiver.com/sydney/ | ![]() |
hxxp://shbrazil.com/ | ![]() |
hxxp://audience-web.net/ | ![]() |
hxxp://audience-web.net/cgi-sys/suspendedpage.cgi | ![]() |
hxxp://churchsupplies.net/ | ![]() |
hxxp://padstow.com/ | ![]() |
hxxp://authentica-travel.com/ | ![]() |
hxxp://screaminpeach.com/ | ![]() |
hxxp://theartofhair.com/ | ![]() |
hxxp://wildrosemarketing.com/ | ![]() |
hxxp://csmbc.org/ | ![]() |
hxxp://lognetic.com/ | ![]() |
hxxp://mojacar-vacaciones.com/ | ![]() |
hxxp://tollefsondesign.com/ | ![]() |
hxxp://xing-group.com/ | ![]() |
hxxp://malagacorp.com/ | ![]() |
hxxp://brijindia.com/ | ![]() |
hxxp://floridadoubled.com/ | ![]() |
hxxp://easygen.com/ | ![]() |
hxxp://empordalia.com/ | ![]() |
hxxp://totalearthcare.com.au/ | ![]() |
hxxp://austriansurfing.at/ | ![]() |
hxxp://celebikalip.com.tr/ | ![]() |
hxxp://aipi.co.nz/ | ![]() |
hxxp://areafor.com/ | ![]() |
hxxp://totalearthcare.com.au/cgi-sys/suspendedpage.cgi | ![]() |
hxxp://lockerlookz.com/ | ![]() |
hxxp://forslav.com/ (Malicious) | ![]() |
hxxp://gjk.com.pl/ | ![]() |
hxxp://bigjohnsbeefjerky.com/ | ![]() |
hxxp://eyggroup.com/ | ![]() |
hxxp://eygwindows.co.uk/ | ![]() |
hxxp://s2s.fr/ | ![]() |
hxxp://iktus.fr/ | ![]() |
hxxp://coopsupermarkt.nl/ | ![]() |
hxxp://telenavis.com/ | ![]() |
hxxp://sarpy.com/ | ![]() |
hxxp://koetterfireprotection.com/ | ![]() |
hxxp://geothermusa.com/ | ![]() |
hxxp://tessera.co.jp/ | ![]() |
hxxp://tvndra.net/ | ![]() |
hxxp://agence-des-druides.com/ | ![]() |
meridies.org | ![]() |
digpro.se | ![]() |
www.ixtractor.com | ![]() |
www.photoclubs.com | ![]() |
reyesconstruction.com | ![]() |
www.msasys.com | ![]() |
in1.smtp.messagingengine.com | ![]() |
www.microsoft.com | ![]() |
plainscotton.org | ![]() |
bredainternet.nl | ![]() |
testpile.com | ![]() |
indianz.com | ![]() |
www.cabooseonline.com | ![]() |
surfinggoatdairy.com | ![]() |
shakeyspizza.ph | ![]() |
emconfm.com | ![]() |
www.ans-service.com | ![]() |
serviamus.com | ![]() |
cbsprinting.com.au | ![]() |
www.jacksonsallamerican.com | ![]() |
qginformatik.com | ![]() |
www.atr-technologies.com | ![]() |
kashiwa-kk.com | ![]() |
btitravel.com | ![]() |
eternalbeautyproducts.com.au | ![]() |
firealarms.com | ![]() |
rcap.org | ![]() |
adfolsa.com.ec | ![]() |
naijagurus.com | ![]() |
konishi-hp.com | ![]() |
smtp.mail.yahoo.com | ![]() |
www.momonophoto.com | ![]() |
vnhanoi.com | ![]() |
justconnect.co.za | ![]() |
fnam.pt | ![]() |
www.westsidechurch.org | ![]() |
clx.com.br | ![]() |
alt4.gmail-smtp-in.l.google.com | ![]() |
hartmultimedia.com | ![]() |
sensasilelaki.com | ![]() |
skaner.com.pl | ![]() |
cyclo-tourisme.com | ![]() |
4pipp.com | ![]() |
www.kagu-hokuren.com | ![]() |
mxs.mail.ru | ![]() |
www.racknstackwarehouse.com.au | ![]() |
acetravel-lb.com | ![]() |
www.beechwoodmetalworks.com | ![]() |
dicksvalleyservice.com | ![]() |
ziuabarbatului.ro | ![]() |
aiem.qc.ca | ![]() |
academiakurutziaga.com | ![]() |
hillusa.com | ![]() |
www.wkhk.net | ![]() |
debtrescueusa.com | ![]() |
doctsf.com | ![]() |
studiolegalegiommi.it | ![]() |
www.myfilecenter.com | ![]() |
www.facebook.com | ![]() |
www.gamblingonlinemagazine.com | ![]() |
www.bigjohnsbeefjerky.com | ![]() |
www.mibsga.com | ![]() |
e-shuukyaku.com | ![]() |
nc-concept.com | ![]() |
www.westhillsstl.org | ![]() |
medischmanagement.nl | ![]() |
weinbauerfinancial.com | ![]() |
www.djkentaro.jp | ![]() |
gmail-smtp-in.l.google.com | ![]() |
www.hoyuu.com | ![]() |
www.teknorhino.com | ![]() |
www.chscreative.com | ![]() |
theautospas.com | ![]() |
lotuswell.ch | ![]() |
bitlarge.com | ![]() |
mail7.digitalwaves.co.nz | ![]() |
engsmotortruck.com | ![]() |
yalestreet.com | ![]() |
www.eygwindows.co.uk | ![]() |
vexolpost.com | ![]() |
herpes-zone.com | ![]() |
x-cellcommunications.de | ![]() |
choice-select.com | ![]() |
audio-direkt.net | ![]() |
ballandwall.biz | ![]() |
sspackaginggroup.com | ![]() |
golfpark-moossee.ch | ![]() |
Rootkit activity
No anomalies have been detected.
Propagation
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
217b643887dd7ad9ef4151832dc1b401.exe:1860
- Delete the original Trojan-Downloader file.
- Delete or disinfect the following files created/modified by the Trojan-Downloader:
%Documents and Settings%\%current user%\Cookies\Current_User@topex[1].txt (185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\djkentaro[1].htm (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\starmedia[1].htm (466 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\dithd[1].htm (173 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ixtractor[1].htm (801 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\brijindia[1].htm (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\violadagamba[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@totalearthcare.com[1].txt (241 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\fujino-lab[1].htm (2057 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\paulrenna[1].htm (1225 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@ziuabarbatului[1].txt (158 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[1].txt (147 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\celebikalip.com[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\csmbc[1].htm (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\teknorhino[1].htm (2124 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\google[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\atr-technologies[1].htm (18 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[2].txt (301 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\index[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\teasing-video[1].htm (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\dormfantasies[1].htm (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\racknstackwarehouse.com[1].htm (1340 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@glmghotels[1].txt (219 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\actfactory[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\tessera.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@paintball[1].txt (150 bytes)
%Documents and Settings%\%current user%\rapixxagibna.exe (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\suspended[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@winery[1].txt (224 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\paulrenna[1].htm (277 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\cath4choice[1].htm (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\niray.com[1].htm (1480 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mibsga[1].htm (14 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@facebook[1].txt (172 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1844237615-1960408961-1801674531-1003\c5b88721db08c824db69d0bbc702beb8_75ed9567-aa58-4c8e-a8ea-3cad7c47ab03 (881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\capitalcitytuxedo[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\tollefsondesign[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ompgp.co[1].htm (17 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (29108 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\winery[1] (248 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\unitedearthgroup[1].htm (523 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\egao[1].htm (15 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[1].txt (1878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\e-shuukyaku[1].htm (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gjk.com[1].htm (24 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@topex[2].txt (332 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\tss[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\m[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[1].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\chscreative[1].htm (1736 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shipeliteexpress[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[2].txt (321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mastechn[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\thedonaldsongroup[1].htm (833 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\geodecisions[1].htm (40 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@msasys[1].txt (204 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\momonophoto[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\suspendedpage[2].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\iktus[1].htm (78 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sydney[1].htm (357 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sun-ele.co[1].htm (11 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.microsoft[2].txt (147 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[2].txt (1324 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\osouji-school[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\aipi.co[1].htm (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ans-service[1].htm (107 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\vanguardpkg[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[2].htm (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\google[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\fraser-high.school[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\precisionsolutionsky[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\boundbydesign[1].htm (10 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geodecisions[1].txt (273 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\westsidechurch[1].htm (17 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@neurotoxininstitute[1].txt (237 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[2].txt (160 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pixemia[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\acsmedioambiente[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\frederickallergy[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sarpy[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\naijagurus[1].htm (573 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\capitalcitytuxedo[1].htm (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\trenpalau[1].htm (36 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (1103 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\arckepesajandek[2].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\sun-ele.co[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\eygwindows.co[1].htm (822 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\le-mariage[1].htm (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\floridadoubled[1].htm (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\arckepesajandek[1].htm (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\kafrit[1].htm (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\cabooseonline[1].htm (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\theprintinghouseltd.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\graintrain[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@empordalia[1].txt (157 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\mojacar-vacaciones[1].htm (876 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\koetterfireprotection[1].htm (1522 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@google[3].txt (641 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\geothermusa[1].htm (498 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@geothermusa[1].txt (160 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\violadagamba[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\easyformations[1].htm (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\paulrenna[1].htm (277 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\cksglobal[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\etcycles[1].htm (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\easygen[1].htm (13 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (323 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\acsmedioambiente[1].htm (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\forslav[1].htm (270 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\photoclubs[1].htm (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jacksonsallamerican[1].htm (1178 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@easyformations[1].txt (152 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"rapixxagibna" = "%Documents and Settings%\%current user%\rapixxagibna.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.