La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Trojan.MulDrop11.18938

Aggiunto al database dei virus Dr.Web: 2019-10-04

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKCU>\Software\Classes\mIRCURL\shell\open\command] '' = '"%ProgramFiles(x86)%\mIRC\mirc.exe" %1'
Changes the following executable system files
  • %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\upnp device host\upnphost\udhisapi.dll
Modifies file system
Creates the following files
  • <Current directory>\ob-native.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_vi.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ur.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_uk.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_tr.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_th.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_te.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ta.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_sw.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_sv.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_sr.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_lt.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_sl.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ru.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ro.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_pt-pt.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_pt-br.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_pl.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_no.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_nl.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ms.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_mr.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ml.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_sk.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_lv.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_zh-cn.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_bg.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_es.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_en-gb.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_en.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_el.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_de.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_da.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_cs.dll
  • %ProgramFiles(x86)%\gum4529.tmp\googleupdatebroker.exe
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ca.dll
  • %ProgramFiles(x86)%\gum4529.tmp\googleupdatehelper.msi
  • %ProgramFiles(x86)%\gum4a3a.tmp\googleupdatesetup.exe
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_zh-tw.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ar.dll
  • %ProgramFiles(x86)%\gum4529.tmp\npgoogleupdate3.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_am.dll
  • %ProgramFiles(x86)%\gum417f.tmp\googlecrashhandler64.exe
  • %ProgramFiles(x86)%\gum4529.tmp\goopdate.dll
  • %ProgramFiles(x86)%\gum417f.tmp\psuser_64.dll
  • %ProgramFiles(x86)%\gum417f.tmp\psuser.dll
  • %ProgramFiles(x86)%\gum417f.tmp\psmachine_64.dll
  • %ProgramFiles(x86)%\gum321e.tmp\googleupdatesetup.exe
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_zh-tw.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_bn.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ko.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ja.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_et.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\googlecrashhandler.exe
  • %ProgramFiles(x86)%\gum4a3a.tmp\psuser.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\psmachine_64.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\psmachine.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\googleupdatecomregistershell64.exe
  • %ProgramFiles(x86)%\gum4a3a.tmp\googleupdateondemand.exe
  • %ProgramFiles(x86)%\gum4a3a.tmp\googleupdatebroker.exe
  • %ProgramFiles(x86)%\gum4a3a.tmp\googleupdatehelper.msi
  • %ProgramFiles(x86)%\gum4a3a.tmp\npgoogleupdate3.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdate.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ar.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\googlecrashhandler64.exe
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_am.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_zh-tw.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_zh-cn.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_vi.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ur.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_uk.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_tr.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_th.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_te.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ta.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\googleupdatesetup.exe
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_bg.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_iw.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_es-419.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\psuser_64.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_it.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_is.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_id.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_hu.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_hr.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_hi.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_gu.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_fr.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_fil.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_fi.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_fa.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_et.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_es-419.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_es.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_en-gb.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_en.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_el.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_de.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_da.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_cs.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_ca.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_bn.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\goopdateres_kn.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\googleupdatehelper.msi
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_fa.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_kn.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ja.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_iw.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_it.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_is.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_id.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_hu.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_hr.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_hi.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_gu.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ko.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_fr.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_fi.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_fa.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_et.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_es-419.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_es.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_en-gb.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_en.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_el.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_de.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_da.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_fil.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_lt.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_lv.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ml.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_zh-tw.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_zh-cn.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_vi.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ur.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_uk.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_tr.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_th.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_te.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ta.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_sw.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_sv.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_sr.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_sl.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_sk.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ru.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ro.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_pt-pt.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_pt-br.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_pl.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_no.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_nl.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ms.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_mr.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_cs.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_sw.dll
  • %ProgramFiles(x86)%\gum4a3a.tmp\googleupdate.exe
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_bg.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_pl.dll
  • %ProgramFiles(x86)%\gum4529.tmp\googleupdateondemand.exe
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_no.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_nl.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ms.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_mr.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ml.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_lv.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_lt.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ko.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_pt-br.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_kn.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_iw.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_it.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_is.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_id.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_hu.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_hr.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_hi.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_gu.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_fr.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_fil.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ja.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_pt-pt.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ro.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ru.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ar.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_am.dll
  • %ProgramFiles(x86)%\gum4529.tmp\googlecrashhandler64.exe
  • %ProgramFiles(x86)%\gum4529.tmp\psuser_64.dll
  • %ProgramFiles(x86)%\gum4529.tmp\psuser.dll
  • %ProgramFiles(x86)%\gum4529.tmp\psmachine_64.dll
  • %ProgramFiles(x86)%\gum4529.tmp\psmachine.dll
  • %ProgramFiles(x86)%\gum4529.tmp\googleupdatecomregistershell64.exe
  • %ProgramFiles(x86)%\gum417f.tmp\googleupdatesetup.exe
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_zh-tw.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_zh-cn.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_vi.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ur.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_uk.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_tr.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_th.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_te.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_ta.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_sw.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_sv.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_sr.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_sl.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_sk.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_bn.dll
  • %ProgramFiles(x86)%\gum417f.tmp\goopdateres_fi.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_sv.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_sr.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_sl.dll
  • %ProgramFiles(x86)%\gum418f.tmp\googleupdate.exe
  • %ProgramFiles(x86)%\gum418f.tmp\googleupdateondemand.exe
  • %ProgramFiles(x86)%\gum417f.tmp\googlecrashhandler.exe
  • %ProgramFiles(x86)%\gum417f.tmp\googleupdate.exe
  • %ProgramFiles(x86)%\gum418f.tmp\googleupdatebroker.exe
  • %ProgramFiles(x86)%\gum418f.tmp\googleupdatehelper.msi
  • %ProgramFiles(x86)%\gum418f.tmp\npgoogleupdate3.dll
  • %ProgramFiles(x86)%\gut4336.tmp
  • %ProgramFiles(x86)%\gum418f.tmp\goopdate.dll
  • %ProgramFiles(x86)%\gum418f.tmp\googlecrashhandler.exe
  • %ProgramFiles(x86)%\gum418f.tmp\psmachine_64.dll
  • %ProgramFiles(x86)%\gum418f.tmp\googleupdatecomregistershell64.exe
  • %ProgramFiles(x86)%\gum418f.tmp\psmachine.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_te.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ta.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_sw.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_sv.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_sr.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_sl.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_sk.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ru.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ro.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_th.dll
  • %ProgramFiles(x86)%\gum418f.tmp\psuser.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_hr.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_pt-pt.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_pl.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_hi.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_gu.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_fr.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_fil.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_fi.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_fa.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_et.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_es-419.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_es.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_en-gb.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_en.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_el.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_de.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_da.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_cs.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ca.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_bn.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_bg.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ar.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_am.dll
  • %ProgramFiles(x86)%\gum418f.tmp\googlecrashhandler64.exe
  • %ProgramFiles(x86)%\gum418f.tmp\psuser_64.dll
  • %ProgramFiles(x86)%\gut4190.tmp
  • %ProgramFiles(x86)%\gum4529.tmp\googleupdatesetup.exe
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_hu.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_no.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_da.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_cs.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ca.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_bn.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_bg.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ar.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_am.dll
  • %ProgramFiles(x86)%\gum321e.tmp\googlecrashhandler64.exe
  • %ProgramFiles(x86)%\gum321e.tmp\psuser_64.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_el.dll
  • %ProgramFiles(x86)%\gum321e.tmp\psuser.dll
  • %ProgramFiles(x86)%\gum321e.tmp\psmachine.dll
  • %ProgramFiles(x86)%\gum321e.tmp\googleupdatecomregistershell64.exe
  • %ProgramFiles(x86)%\gum321e.tmp\googleupdateondemand.exe
  • %ProgramFiles(x86)%\gum321e.tmp\googleupdatebroker.exe
  • %ProgramFiles(x86)%\gum321e.tmp\googleupdatehelper.msi
  • %ProgramFiles(x86)%\gum321e.tmp\npgoogleupdate3.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdate.dll
  • %ProgramFiles(x86)%\gum321e.tmp\googlecrashhandler.exe
  • %ProgramFiles(x86)%\gum321e.tmp\googleupdate.exe
  • %ProgramFiles(x86)%\gut321f.tmp
  • %ProgramFiles(x86)%\gum321e.tmp\psmachine_64.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_en.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_de.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_en-gb.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_nl.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_is.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ms.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_mr.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ml.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_lv.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_lt.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ko.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_kn.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ja.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_iw.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_it.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_id.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_es.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_hu.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_hr.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_hi.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_gu.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_fr.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_fil.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_fi.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_fa.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_et.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_es-419.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_pt-br.dll
  • %ProgramFiles(x86)%\gum4529.tmp\goopdateres_ca.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_id.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_iw.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_fil.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_fi.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_fa.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_et.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_es-419.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_es.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_en-gb.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_en.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_el.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_de.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_fr.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_da.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ca.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_bn.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_bg.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ar.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_am.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\googlecrashhandler64.exe
  • %ProgramFiles(x86)%\gum4c3d.tmp\psuser_64.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\psuser.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\psmachine_64.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\psmachine.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_cs.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_gu.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_hi.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_hr.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_is.dll
  • %ProgramFiles(x86)%\gut4af6.tmp
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_sk.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ru.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ro.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_pt-pt.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_pt-br.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_pl.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_no.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_nl.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ms.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_mr.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ml.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_lv.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_lt.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ko.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_kn.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_ja.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_iw.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_it.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_is.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_id.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdateres_hu.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\googleupdatecomregistershell64.exe
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_it.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\googleupdateondemand.exe
  • %ProgramFiles(x86)%\gum417f.tmp\goopdate.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_sw.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_sv.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_sr.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_sl.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_sk.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ru.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_tr.dll
  • %ProgramFiles(x86)%\gum417f.tmp\npgoogleupdate3.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ro.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_pt-pt.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ta.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_pt-br.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_no.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_nl.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ms.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_mr.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ml.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_lv.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_lt.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ko.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_kn.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ja.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_pl.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_te.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_th.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_tr.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\npgoogleupdate3.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\goopdate.dll
  • %ProgramFiles(x86)%\gum4c3d.tmp\googlecrashhandler.exe
  • %ProgramFiles(x86)%\gum4c3d.tmp\googleupdate.exe
  • %ProgramFiles(x86)%\gum417f.tmp\psmachine.dll
  • %ProgramFiles(x86)%\gum4529.tmp\googlecrashhandler.exe
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_zh-cn.dll
  • %ProgramFiles(x86)%\gut4c3e.tmp
  • %ProgramFiles(x86)%\gum417f.tmp\googleupdatecomregistershell64.exe
  • %ProgramFiles(x86)%\gum4529.tmp\googleupdate.exe
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_vi.dll
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_ur.dll
  • %ProgramFiles(x86)%\gut4559.tmp
  • %ProgramFiles(x86)%\gum417f.tmp\googleupdateondemand.exe
  • %ProgramFiles(x86)%\gum321e.tmp\goopdateres_uk.dll
  • %ProgramFiles(x86)%\gum417f.tmp\googleupdatebroker.exe
  • %ProgramFiles(x86)%\gum418f.tmp\googleupdatesetup.exe
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_zh-tw.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_zh-cn.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_vi.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_ur.dll
  • %ProgramFiles(x86)%\gum418f.tmp\goopdateres_uk.dll
  • %ProgramFiles(x86)%\gum417f.tmp\googleupdatehelper.msi
  • %ProgramFiles(x86)%\gum4c3d.tmp\googleupdatebroker.exe
  • %HOMEPATH%\desktop\~$eklysheet1215.doc
Network activity
UDP
  • DNS ASK tools.google.com
  • '23#.#55.255.250':1900
Miscellaneous
Searches for the following windows
  • ClassName: '\MSITPro::EventQueue' WindowName: ''
  • ClassName: 'Type32_Main_Window' WindowName: ''
  • ClassName: 'WMPlayerApp' WindowName: ''
Creates and executes the following
  • '%ProgramFiles(x86)%\gum418f.tmp\googleupdate.exe' /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=pre...
  • '%ProgramFiles(x86)%\gum4c3d.tmp\googleupdate.exe' /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=pre...
  • '%ProgramFiles(x86)%\gum4a3a.tmp\googleupdate.exe' /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=pre...
  • '%ProgramFiles(x86)%\gum321e.tmp\googleupdate.exe' /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=pre...
  • '%ProgramFiles(x86)%\gum417f.tmp\googleupdate.exe' /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=pre...
  • '%ProgramFiles(x86)%\gum4529.tmp\googleupdate.exe' /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=pre...
Executes the following
  • '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%HOMEPATH%\Desktop\weeklysheet1215.doc"
  • '%ProgramFiles(x86)%\mirc\mirc.exe'
  • '%ProgramFiles(x86)%\windows media player\wmplayer.exe' /Play -Embedding
  • '%ProgramFiles(x86)%\google\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMTEiIHNoZWxsX3ZlcnNpb249IjEuMy4yNi45IiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezFERDZDREI...
  • '%ProgramFiles(x86)%\google\update\googleupdate.exe' /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=prefers" /installsource tag...
  • '%ProgramFiles(x86)%\google\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMTEiIHNoZWxsX3ZlcnNpb249IjEuMy4yNi45IiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezhFRTMzN0U...
  • '%ProgramFiles(x86)%\google\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMTEiIHNoZWxsX3ZlcnNpb249IjEuMy4yNi45IiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezkwNERERUE...
  • '%ProgramFiles(x86)%\google\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMTEiIHNoZWxsX3ZlcnNpb249IjEuMy4yNi45IiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezI5QUY5MkV...
  • '%ProgramFiles(x86)%\google\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMTEiIHNoZWxsX3ZlcnNpb249IjEuMy4yNi45IiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0ie0M0N0Q1MzZ...
  • '%ProgramFiles(x86)%\google\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMTEiIHNoZWxsX3ZlcnNpb249IjEuMy4yNi45IiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0ie0Q4MTMwMEJ...

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android