La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Trojan.Siggen11.53182

Aggiunto al database dei virus Dr.Web: 2020-12-02

La descrizione è stata aggiunta:

Technical Information

Modifies file system
Creates the following files
  • %TEMP%\extd910.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set278e.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set27be.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set27ee.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set280e.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set283e.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set285e.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set288e.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set28be.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set290d.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set293d.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2462.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set295d.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set29dc.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set29fc.tmp
  • <SYSTEM32>\spool\drivers\x64\set2a1c.tmp
  • <SYSTEM32>\spool\drivers\x64\set2a5b.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\set9e22.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\set9f4b.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta065.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta1dd.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta2f6.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta420.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set274e.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set276e.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set272e.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set26df.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set269f.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set22b2.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set22e1.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2321.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2341.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2361.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2381.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set23a2.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set23c2.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set23f2.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2421.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta5e5.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set298d.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2442.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set24b2.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set24d2.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2511.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2532.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2552.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set25a1.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set25c1.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2610.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2640.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2670.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2282.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2492.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb8f9.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete905.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta9af.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setcc5b.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setcdb3.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setcefc.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd063.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd18d.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd2a7.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd3c0.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd528.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd680.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd7c9.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta6ff.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd902.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setdb55.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setdc6f.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setddc7.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setdef0.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete077.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete1b0.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete308.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete432.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete59a.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete6c3.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setca27.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setcb22.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc8fe.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc7a6.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc65d.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setabe3.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setad4b.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setae65.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setaf9e.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb0c7.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb1e1.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb2fb.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb434.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb53e.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb658.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta857.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2262.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb7a0.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbb0d.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbc27.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbd31.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbe4b.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbf45.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc07e.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc179.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc274.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc3fb.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc524.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setaac9.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setba03.tmp
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setda3b.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2222.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set1fb5.tmp
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gcon04.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gdsp30.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gepe30.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gf1cla.cat
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gf1cla.inf
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gha750.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_ghmm69.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gi0cca.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gi1cke.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_giptre.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ee415__7.icm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gircd4.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gm1cla.vif
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gmai30.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_goka02.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gppe06.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gpui04.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gsc0ke.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gu3cke.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gupa20.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gupa2e.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_h5uiab.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gaudf1.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gbrsb4.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_dp70ce.prm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_dp131a.dat
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_doka02.dll
  • %TEMP%\pftd9cd~tmp\pftw1.pkg
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ebapi6.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ebpbidi6.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ebpmonb.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ecbtegb.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ee415__1.icm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ee415__2.icm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ee415__3.icm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ee415__4.icm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ee415__5.icm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_h8b0lb.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_gjb724.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ee415__6.icm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\epipgi30.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\epset32.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\epset64.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\epupdate.dat
  • %TEMP%\pftd9cd~tmp\winvista_xp64\epupdate.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\eputy48b.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\eputy48b.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_dd1cka.cfg
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_dge641.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_dm1ccx.lmd
  • %TEMP%\plfd90f.tmp
  • %TEMP%\pftd9cd~tmp\winvista_xp64\ee415__8.icm
  • %TEMP%\pftd9cd~tmp\winvista_xp64\setup\rescan.exe
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set21c3.tmp
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s40mtb.exe
  • %WINDIR%\syswow64\epsptdve.exe
  • %WINDIR%\syswow64\epprtdrv_001.cab
  • %WINDIR%\syswow64\epsmtl32_000.cab
  • %TEMP%\epstpa64_000.exe
  • %TEMP%\epsdiw64_000.exe
  • %TEMP%\epdevmgr.dll
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f14.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f34.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f54.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f74.tmp
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_h8e0lb.dll
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f95.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set1fe5.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2014.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2044.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2074.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set20a4.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set20d4.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2113.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2133.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2163.tmp
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set21a2.tmp
  • %WINDIR%\syswow64\epscmins.dll
  • %WINDIR%\syswow64\epispc98.exe
  • %WINDIR%\syswow64\epsetup_001.cab
  • %ALLUSERSPROFILE%\microsoft\windows\templates\epstplog.txt
  • %TEMP%\eps_icon_000.avi
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s40rpb.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s40sob.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s890lb.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s8b0lb.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s8e2lb.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s8i0lb.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s8x2lb.dat
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_siacsb.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_sku64b.dll
  • %TEMP%\pftd9cd~tmp\winvista_xp64\setup\epsetup.eif
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_qi121e.chm
  • %ProgramFiles%\epson\printerdrivertemp\sprx595\set2202.tmp
  • %TEMP%\pftd9cd~tmp\winvista_xp64\setup\oeminf.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\setup\setup64.exe
  • %WINDIR%\syswow64\epstp64u_000.cab
  • %WINDIR%\syswow64\epsui64w_000.exe
  • %WINDIR%\syswow64\epsmtl64w_000.dll
  • %WINDIR%\syswow64\epsetup_000.cab
  • %WINDIR%\syswow64\epsptdve_000.exe
  • %WINDIR%\syswow64\epinstu.exe
  • %WINDIR%\syswow64\epprtdrv_000.cab
  • %WINDIR%\syswow64\epsmtl32.dll
  • %WINDIR%\syswow64\epsui64w_000.dat
  • %TEMP%\pftd9cd~tmp\winvista_xp64\e_s40rnb.exe
  • %TEMP%\pftd9cd~tmp\winvista_xp64\setup\setup64.dat
  • %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setea0f.tmp
Deletes the following files
  • %TEMP%\extd910.tmp
  • %TEMP%\pftd9cd~tmp\pftw1.pkg
  • %WINDIR%\syswow64\epinstu.exe
Moves the following files
  • from %ALLUSERSPROFILE%\microsoft\windows\templates\epstplog.txt to %ALLUSERSPROFILE%\microsoft\windows\templates\epstplog.bak
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbf45.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s8x2lb.dat
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbe4b.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s40mtb.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbd31.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ebpmonb.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbc27.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_sku64b.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setbb0d.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s40rnb.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setba03.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\epipgi30.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb8f9.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_dd1cka.cfg
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb7a0.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s40sob.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb658.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gpui04.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb53e.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s8i0lb.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb434.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gppe06.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb2fb.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_ghmm69.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb1e1.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_dp70ce.prm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setb0c7.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gupa20.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setaf9e.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gdsp30.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setae65.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s8e2lb.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setad4b.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s8b0lb.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setabe3.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gcon04.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setaac9.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ecbtegb.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta9af.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_goka02.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta857.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gepe30.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta6ff.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_h8e0lb.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta5e5.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gmai30.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta420.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_doka02.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta2f6.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_h8b0lb.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta1dd.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s890lb.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\seta065.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gjb724.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\set9f4b.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_qi121e.chm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\set9e22.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gha750.dll
  • from <SYSTEM32>\spool\drivers\x64\set2a1c.tmp to <SYSTEM32>\spool\drivers\x64\epupdate.exe
  • from <SYSTEM32>\spool\drivers\x64\set2a5b.tmp to <SYSTEM32>\spool\drivers\x64\epupdate.dat
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc07e.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_s40rpb.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc179.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gi0cca.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete6c3.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_dge641.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete59a.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\epset64.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete432.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_dp131a.dat
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete308.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\epset32.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete1b0.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ee415__8.icm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete077.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ee415__7.icm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setdef0.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ee415__6.icm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setddc7.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ee415__5.icm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setdc6f.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ee415__4.icm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setdb55.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ee415__3.icm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setda3b.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ee415__2.icm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd902.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ee415__1.icm
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd7c9.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ebapi6.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd680.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\epupdate.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd3c0.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_giptre.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set269f.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gsc0ke.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd2a7.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_siacsb.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd18d.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\eputy48b.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd063.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gupa2e.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setcefc.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gbrsb4.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setcdb3.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gu3cke.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setcc5b.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\eputy48b.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setcb22.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\ebpbidi6.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setca27.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_dm1ccx.lmd
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc8fe.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_h5uiab.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc7a6.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gm1cla.vif
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc65d.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gsc0ke.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc524.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gircd4.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc3fb.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gaudf1.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setc274.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gi1cke.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set29fc.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_sku64b.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set29dc.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_siacsb.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set298d.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s8x2lb.dat
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2341.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_dp70ce.prm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2321.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_dp131a.dat
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set22e1.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_doka02.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set22b2.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_dm1ccx.lmd
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2282.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_dge641.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2262.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_dd1cka.cfg
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2222.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\eputy48b.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2202.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\eputy48b.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set21c3.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\epupdate.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set21a2.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\epupdate.dat
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2163.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\epset64.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2133.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\epset32.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2113.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\epipgi30.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set20d4.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ee415__8.icm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set20a4.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ee415__7.icm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2074.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ee415__6.icm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2044.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ee415__5.icm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2014.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ee415__4.icm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set1fe5.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ee415__3.icm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set1fb5.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ee415__2.icm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f95.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ee415__1.icm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f74.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ecbtegb.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f54.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ebpmonb.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f34.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ebpbidi6.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set1f14.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\ebapi6.dll
  • from %TEMP%\epdevmgr.dll to <SYSTEM32>\epdevmgr.dll
  • from %WINDIR%\syswow64\epsmtl32.dll to %TEMP%\epsmtl32.dll
  • from %WINDIR%\syswow64\epinstu.exe to %TEMP%\epinstu.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2381.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gbrsb4.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set23a2.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gcon04.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2361.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gaudf1.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set23c2.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gdsp30.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set295d.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s8i0lb.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set23f2.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gepe30.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set293d.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s8e2lb.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set290d.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s8b0lb.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set28be.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s890lb.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set288e.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s40sob.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set285e.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s40rpb.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set283e.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s40rnb.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set280e.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_s40mtb.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set27ee.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_qi121e.chm
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set27be.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_h8e0lb.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set278e.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_h8b0lb.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set276e.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_h5uiab.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set274e.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gupa2e.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set272e.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gupa20.exe
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setd528.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\epupdate.dat
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\sete905.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gf1cla.cat
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2670.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gpui04.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2640.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gppe06.exe
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2610.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_goka02.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set25c1.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gmai30.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set25a1.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gm1cla.vif
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2552.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gjb724.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2532.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gircd4.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2511.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_giptre.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set24d2.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gi1cke.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set24b2.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gi0cca.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2492.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_ghmm69.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2462.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gha750.dll
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2442.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gf1cla.inf
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set2421.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gf1cla.cat
  • from %ProgramFiles%\epson\printerdrivertemp\sprx595\set26df.tmp to %ProgramFiles%\epson\printerdrivertemp\sprx595\e_gu3cke.dll
  • from %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\setea0f.tmp to %TEMP%\{6e3e3198-1685-6df4-13b5-c03312516507}\e_gf1cla.inf
Substitutes the following files
  • %ALLUSERSPROFILE%\microsoft\windows\templates\epstplog.txt
  • %WINDIR%\syswow64\epinstu.exe
  • %WINDIR%\syswow64\epsmtl32.dll
Miscellaneous
Creates and executes the following
  • '%TEMP%\pftd9cd~tmp\winvista_xp64\setup\setup64.exe'
  • '%WINDIR%\syswow64\epsui64w_000.exe' "%TEMP%\pftD9CD~tmp\WINVISTA_XP64\SETUP\SETUP64.EXE" /y:"%TEMP%\pftD9CD~tmp\WINVISTA_XP64\SETUP\SETUP64.EXE"
  • '%TEMP%\epstpa64_000.exe' /HWND:100156 /LPARAM:0
  • '%TEMP%\pftd9cd~tmp\winvista_xp64\setup\oeminf.exe' /INF:"%ProgramFiles%\EPSON\PrinterDriverTemp\SPRX595\E_GF1CLA.INF"
  • '%TEMP%\pftd9cd~tmp\winvista_xp64\setup\setup64.exe' ' (with hidden window)
  • '%TEMP%\epstpa64_000.exe' /HWND:100156 /LPARAM:0' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android