At the moment Jetico Personal Firewall detects and prevents such a network activity of malicious programs that are illustrated in firewall test programs like AWFT, DNStest, Copycat, FireHole, Ghost, LeakTest, MBTest, Outbound, PCAudit, PCAudit2, Surfer, Thermit, TooLeaky, WallBreaker, and Yalta.
This Trojan adds the following strings to the Windows HOSTS file: 0.0.0.0 account.norton.com
0.0.0.0 www.gmer.net
0.0.0.0 www.yeabests.cc
0.0.0.0 bleepingcomputer.com
0.0.0.0 www.bleepingcomputer.com
0.0.0.0 malekal.com
0.0.0.0 www.malekal.com
0.0.0.0 accounts.comodo.com
0.0.0.0 activation.adtrustmedia.com
0.0.0.0 activation-v2.kaspersky.com
0.0.0.0 auth.ff.avast.com
0.0.0.0 avstats.avira.com
0.0.0.0 backup1.bullguard.com
0.0.0.0 buddy.bitdefender.com
0.0.0.0 c2.dev.drweb.com
0.0.0.0 antivirus.baidu.com
0.0.0.0 cdn.static.malwarebytes.org
0.0.0.0 csasmain.symantec.com
0.0.0.0 definitionsbd.lavasoft.com
0.0.0.0 dm.kaspersky-labs.com
0.0.0.0 dnsscan.shadowserver.org
0.0.0.0 download.bitdefender.com
0.0.0.0 download.bullguard.com
0.0.0.0 download.comodo.com
0.0.0.0 download.eset.com
0.0.0.0 download.geo.drweb.com
0.0.0.0 downloadnada.lavasoft.com
0.0.0.0 downloads.comodo.com
0.0.0.0 downloads.lavasoft.com
0.0.0.0 www.reasoncoresecurity.com
0.0.0.0 reasoncoresecurity.com
0.0.0.0 drweb.com
0.0.0.0 ec.sunbeltsoftware.com
0.0.0.0 emupdate.avast.com
0.0.0.0 esetnod32.ru
0.0.0.0 zillya.ua
0.0.0.0 www.zillya.ua
0.0.0.0 expire.eset.com
0.0.0.0 gms.ahnlab.com
0.0.0.0 go.eset.eu
0.0.0.0 i1.c.eset.com
0.0.0.0 i2.c.eset.com
0.0.0.0 i3.c.eset.com
0.0.0.0 i4.c.eset.com
0.0.0.0 iploc.eset.com
0.0.0.0 ipm.avira.com
0.0.0.0 ipm.bitdefender.com
0.0.0.0 ksn4-12.kaspersky-labs.com
0.0.0.0 ksn-file-geo.kaspersky-labs.com
0.0.0.0 ksn-info-geo.kaspersky-labs.com
0.0.0.0 ksn-ipm-1.kaspersky-labs.com
0.0.0.0 ksn-kas-geo.kaspersky-labs.com
0.0.0.0 ksn-kddi.kaspersky-labs.com
0.0.0.0 ksn-pbs-geo.kaspersky-labs.com
0.0.0.0 ksn-stat-geo.kaspersky-labs.com
0.0.0.0 ksn-tboot-1.kaspersky-labs.com
0.0.0.0 ksn-tcert-geo.kaspersky-labs.com
0.0.0.0 ksn-tpcert-1.kaspersky-labs.com
0.0.0.0 ksn-url-geo.kaspersky-labs.com
0.0.0.0 ksn-verdict-geo.kaspersky-labs.com
0.0.0.0 licenseactivation.security.comodo.com
0.0.0.0 license.avira.com
0.0.0.0 license.nanoav.ru
0.0.0.0 license.trustport.com
0.0.0.0 licensing.security.comodo.com
0.0.0.0 login.bullguard.com
0.0.0.0 login.norton.com
0.0.0.0 metrics.bitdefender.com
0.0.0.0 mirror01.gdata.de
0.0.0.0 my.bitdefender.com
0.0.0.0 newton.norman.com
0.0.0.0 nimbus.bitdefender.net
0.0.0.0 niufour.norman.no
0.0.0.0 niuone.norman.no
0.0.0.0 niuseven.norman.no
0.0.0.0 o2.norton.com
0.0.0.0 omni.avg.com
0.0.0.0 oms.symantec.com
0.0.0.0 p003.sb.avast.com
0.0.0.0 p.filseclab.com
0.0.0.0 www.filseclab.com
0.0.0.0 ping.avast.com
0.0.0.0 premium.avira-update.com
0.0.0.0 program.avast.com
0.0.0.0 proxy.eset.com
0.0.0.0 redirect.avira.com
0.0.0.0 reg03.eset.com
0.0.0.0 register.k7computing.com
0.0.0.0 resolver1.bullguard.ctmail.com
0.0.0.0 resolver2.bullguard.ctmail.com
0.0.0.0 resolver3.bullguard.ctmail.com
0.0.0.0 resolver4.bullguard.ctmail.com
0.0.0.0 resolver5.bullguard.ctmail.com
0.0.0.0 rol.pandasecurity.com
0.0.0.0 360totalsecurity.com
0.0.0.0 www.360totalsecurity.com
0.0.0.0 secure.comodo.net
0.0.0.0 shasta-rrs.symantec.com
0.0.0.0 shop.esetnod32.ru
0.0.0.0 slcw.ff.avast.com
0.0.0.0 spoc-pool-gtm.norton.com
0.0.0.0 s.program.avast.com
0.0.0.0 static2.avast.com
0.0.0.0 static.avg.com
0.0.0.0 stats.norton.com
0.0.0.0 stats.qalabs.symantec.com
0.0.0.0 store.lavasoft.com
0.0.0.0 su.ff.avast.com
0.0.0.0 support.norton.com
0.0.0.0 symantec.tt.omtrdc.net
0.0.0.0 threatnet.threattrack.com
0.0.0.0 trace.eset.com
0.0.0.0 tracking.lavasoft.com
0.0.0.0 ts-crl.ws.symantec.com
0.0.0.0 ts.eset.com
0.0.0.0 uc.cloud.avg.com
0.0.0.0 um01.eset.com
0.0.0.0 um21.eset.com
0.0.0.0 update2.bullguard.com
0.0.0.0 update.avg.com
0.0.0.0 update.bullguard.com
0.0.0.0 update.eset.com
0.0.0.0 updates.agnitum.com
0.0.0.0 updates.k7computing.com
0.0.0.0 updates.sunbeltsoftware.com
0.0.0.0 upgrade.bitdefender.com
0.0.0.0 upgr-mmxiii-p.cdn.bitdefender.net
0.0.0.0 upgr-mmxiv.cdn.bitdefender.net
0.0.0.0 v7.stats.avast.com
0.0.0.0 versioncheck.eset.com
0.0.0.0 vl.ff.avast.com
0.0.0.0 wam.pandasecurity.com
0.0.0.0 webprot.avgate.net
0.0.0.0 webprot.avira.com
0.0.0.0 webprot.avira.de
0.0.0.0 wsmy.pandasecurity.com
0.0.0.0 www5.avira.com
0.0.0.0 www.avira.com
0.0.0.0 download.sp.f-secure.com
0.0.0.0 www.bullguard.com
0.0.0.0 www.esetnod32.ru
0.0.0.0 www.k7-russia.ru
0.0.0.0 www.lavasoft.com
0.0.0.0 www.mks.com.pl
0.0.0.0 www.nanoav.ru
0.0.0.0 www.pandasecurity.com
0.0.0.0 www-secure.symantec.com
0.0.0.0 www.sunbeltsoftware.com
0.0.0.0 www.trustport.com
0.0.0.0 kaspersky.ru
0.0.0.0 www.kaspersky.ru
0.0.0.0 avast.ru
0.0.0.0 www.avast.ru
0.0.0.0 freeavg.com
0.0.0.0 www.freeavg.com
0.0.0.0 free.avg.com
0.0.0.0 www.free.avg.com
0.0.0.0 avira.com
0.0.0.0 z-oleg.com
0.0.0.0 www.z-oleg.com
0.0.0.0 bitdefender.com
0.0.0.0 www.bitdefender.com
0.0.0.0 bullguard.com
0.0.0.0 personalfirewall.comodo.com
0.0.0.0 www.personalfirewall.comodo.com
0.0.0.0 comodo.com
0.0.0.0 www.comodo.com
0.0.0.0 www.drweb.com
0.0.0.0 www.emsisoft.ru
0.0.0.0 emsisoft.ru
0.0.0.0 avescan.ru
0.0.0.0 www.avescan.ru
0.0.0.0 escanav.com
0.0.0.0 www.escanav.com
0.0.0.0 escan.com
0.0.0.0 www.escan.com
0.0.0.0 f-prot.com
0.0.0.0 www.f-prot.com
0.0.0.0 f-secure.com
0.0.0.0 www.f-secure.com
0.0.0.0 gdatasoftware.com
0.0.0.0 ru.gdatasoftware.com
0.0.0.0 www.gdata.de
0.0.0.0 gdata.de
0.0.0.0 ikarussecurity.com
0.0.0.0 www.ikarussecurity.com
0.0.0.0 malwarebytes.org
0.0.0.0 www.malwarebytes.org
0.0.0.0 nanoav.ru
0.0.0.0 symantec.com
0.0.0.0 www.symantec.com
0.0.0.0 norton.com
0.0.0.0 www.norton.com
0.0.0.0 ru.norton.com
0.0.0.0 agnitum.ru
0.0.0.0 www.agnitum.ru
0.0.0.0 cloudantivirus.com
0.0.0.0 www.cloudantivirus.com
0.0.0.0 pandasecurity.com
0.0.0.0 www.rising.com.cn
0.0.0.0 rising.com.cn
0.0.0.0 rising-global.com
0.0.0.0 www.rising-global.com
0.0.0.0 www.rising-russia.com
0.0.0.0 rising-russia.com
0.0.0.0 freerav.com
0.0.0.0 www.freerav.com
0.0.0.0 safensoft.ru
0.0.0.0 www.safensoft.ru
0.0.0.0 trustport.com
0.0.0.0 www.trustport-ru.ru
0.0.0.0 virustotal.com
0.0.0.0 www.virustotal.com
0.0.0.0 zillya.com
0.0.0.0 www.zillya.com
0.0.0.0 anti-virus.by
0.0.0.0 www.anti-virus.by
0.0.0.0 sophos.com
0.0.0.0 www.sophos.com
0.0.0.0 www.freedrweb.com
0.0.0.0 freedrweb.com
0.0.0.0 www.avirus.ru
0.0.0.0 www.avg.com
0.0.0.0 avg.com
0.0.0.0 mcafee.com
0.0.0.0 www.mcafee.com
0.0.0.0 siteadvisor.com
0.0.0.0 www.siteadvisor.com
0.0.0.0 support.kaspersky.ru
0.0.0.0 www.comss.ru
0.0.0.0 comss.ru
0.0.0.0 www.spyware-ru.com
0.0.0.0 spyware-ru.com
0.0.0.0 virusinfo.info
0.0.0.0 www.virusinfo.info
0.0.0.0 forum.esetnod32.ru
0.0.0.0 www.forum.esetnod32.ru
0.0.0.0 forum.drweb.com
0.0.0.0 www.forum.drweb.com
0.0.0.0 forum.virlab.info
0.0.0.0 www.forum.virlab.info
0.0.0.0 spybot.info
0.0.0.0 www.spybot.info
0.0.0.0 winpatrol.com
0.0.0.0 www.quickheal.com
0.0.0.0 quickheal.com
0.0.0.0 www.winpatrol.com
0.0.0.0 av.download.avg.com
Jetico Firewall License Key
NOTES: It checks the following registry entries to check if running on virtual machine:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\IDEHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\SCSIwhere values are as follows:QEMUVMwareXENSRC&Prod_PVDISKCdRomVBOX_CD-ROMDiskVirtual_HDIt checks the following registry entries to check if running on virtual machine:HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\SystemSystemBiosVersion = "BOCHS - 1"SystemBiosVersion = "VBOX - 1"VideoBiosVersion = "VirtualBox"It checks for the presence of the following regisries which are related to virtual machine:\Registry\Machine\HARDWARE\ACPI\DSDT\VBOX__\Registry\Machine\HARDWARE\ACPI\FADT\BOCHS_\Registry\Machine\HARDWARE\ACPI\DSDT\Xen\Registry\Machine\SYSTEM\CurrentControlSet\Enum\XEN\vifIt deletes AV related classes on the registry:9CC1A7EB-B086-459B-8E62-A8F3B9A3007B24A0C840-2C3D-4410-8236-8B40816C7B90522119B9-1B9A-498A-AC52-148B533EFD506880337A-1EB4-4EF2-9659-0FD2EC60CB1B87C077B2-3D3B-4156-938A-EA51B451D6C68AE85550-832C-4A9B-81BB-2A49DBEE72B4C4A06E97-ED42-47B9-83E1-F12299B286A5C777C165-D422-426D-8EBF-6EAF3FB83ADFFB58BE68-EA9E-4803-847F-2CE814E7B15954505F9E-EE66-4F1D-A63B-B853A175938556EBD688-B772-4181-9610-8633FCEE988D67F2A318-C8F7-4087-9F88-C4B434D417197E0006EA-81A8-4780-B0C8-474E2DBF4D631DF588BB-23CF-4F4F-851C-1DB73E1028643919A341-96C2-44B9-83AF-0A0897327A07C109C8FC-4A4D-4AA8-B592-9C0EA5ADE910It deletes registry entries with the folllwing strings that may prevent programs from running properly:Adobe ReaderJava Java(TM) Antivirusavast! AVG Avira BitdefenderBkavHome ClamWinCOMODO AntivirusCOMODO Internet SecurityComputer SecurityCrystal SecurityDr.WebESET Endpoint AntivirusESET NOD32ESET OnlineESET SmartFMW 1FortiClientF-SecureGeekBuddyHijackThisKasperskyKingsoft AntiVirusKingsoft PC DoctorMcAfee NOD32 antivirus systemNorton 360Norton AntiSpamNorton AntiVirusNorton ConfidentialNorton Internet SecurityNorton PC CheckupMcAfee Virtual TechniciannProtect Anti-VirusnProtect Security PlatformPanda AntivirusPanda Cloud AntivirusPanda Devices AgentPanda Free AntivirusPanda Global ProtectionPanda Internet SecurityPanda Secure VaultPanda SecurityPersonal FirewallPrivatefirewallQuick HealRising AntivirusSophos Anti-RootkitSophos Anti-VirusSophos AutoUpdateSophos Remote Management SystemSophos Virus Removal ToolSymantec AntiVirusSymantec Endpoint ProtectionTraffic InspectorTrend MicroVIPRE AntivirusVirus ScannerVirusTotalZoneAlarmAshampoo WinOptimizerAdvanced System ProtectorPhrase FinderZillya!Ask ToolbarTuneUp UtilitiesWeatherbarIKARUS anti.virusShopping App by AskSearch App by AskHtml5 geolocation providerESET Endpoint SecurityAmazon 1Button AppIt creates the following registry entries to prevent the following programs from executing:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\application namedebugger = "msiexec.exe"Adaware_Installer.exeAvetixSetup.exeBavPro_Setup_Mini_GL.exeBullGuardDownloaderBPP.exeClamAVSetup.exeEmsisoftEmergencyKit.exeEmsisoftInternetSecuritySetup.exeF-SecureNetworkInstaller.exeF-SecureNetworkInstallerUpg.exeF-SecureNetworkInstallerUpgrade.exeF-SecureNetworkInstaller_IS-ESTORE-TRIAL-GLOBAL_.exeFRST.exeFRST64.exeHijackThis.exeHousecallLauncher.exeK7UltimateSecurity_installer.exeMcAfeeSetup.exeOnlineArmorSetup.exeOutpostSecuritySuiteProInstall.exeOutpostSecuritySuiteProInstall_x64.exePSafeAntivirusSetup.exePSafeTotalSetup.exePadvishAntivirusFree.exePandaCloudAntivirus.exeProcessHacker.exeQHTSFT64.EXERoboscan_IS_Free_x64.exeSUPERAntiSpyware.exeSUPERAntiSpywarePro.exeSandboxieInstall.exeSecurityScan_Release.exeSoftonicDownloader_for_panda-antivirus-pro.exeSpyShelter.exeTRAYICOS.EXETiranium_antivirus_setup.exeTrojanHunterSetup.exeUnThreatProSetup.exeVba32.Vista.exeWireshark.exeZillyaInternetSecurity.exeautoruns.exeautorunsc.exeavast_free_antivirus_setup_online.exeavast_free_antivirus_setup_online_cnet.exeavast_internet_security_setup.exeavast_internet_security_setup_online.exeavast_premier_antivirus_setup_online.exeavira_family_protection_suite_ru.exeavira_ultimate_protection_suite_ru.exebitdefender_antivirus.exebitdefender_tsecurity.exebytefence-installer.execispremium_installer.execpuminer-btver1.execureit.exedrweb-900-win-space.exedrweb-900-win.exeescanmon.exeess_trial32_rus.exemd_setup_en.exeminergate-service.exeminergate.exeprocexp.exeregistry-life-setup.exeru-ru.kts.ya.setup.exesetup-vipre-internet-security-en-us-trial.exestop-sign_install.exesystemreset.exetwister8_setup.exeIt changes the NameServer settings of the affected machine by changing the following IP address to free DNS Servers (8.8.8.8,209.244.0.3):195.46.39.39195.46.39.40199.85.126.20199.85.127.20208.67.220.220208.67.222.222209.88.198.13377.88.8.277.88.8.377.88.8.777.88.8.888.20.247.208.26.56.2681.218.119.11It deletes the following registry entries for services related to antivirus programs:HKEY_LOCAL_MACHINE\SOFTWARE\SYSTEM\CurrentControlSet\services\service name360AntiHacker360AvFlt360Box360Box64360Camera360SelfProtection360fsflt360rpA2DDAAAVScanAAVServiceABConfSVABFLTABMainSVABWFPABndisABndisMPAFWALE_NFAMonLWLHAMonTDLHAPPFLTASD2SvcASZFltNtATamptNt_V3IS80AVBackupAVGEMSAVGIDSAgentAVGIDSDriverAVGIDSDriverlAVGIDSHAAVGIDSHXAVGIDSShimAVKProxyAVKServiceAVKWCtlAVPAVP15.0.0AVP15.0.2AVP16.0.0AVSFirewallServiceAVSNDISIMAVSNDISIMMPAVSRegMonDrvAVSTDIFilterDrvAVTasks2AVUpdateAdvancedSystemCareService6AdvancedSystemCareService7AdvancedSystemCareService8AhnActNtAhnFlt2KAhnRec2KAhnRghNtAhnSZEAmFSMAmitiAvHealthAmitiAvSrvAmnpardaz FilterAmspAntiVirMailServiceAntiVirSchedulerServiceAntiVirServiceAntiVirWebServiceApplication UpdaterArcaFsAvArcaRemoteServiceAsdidsAvast Business Console Client Antivirus ServiceAvetixGuardServiceAvetixMonitorServiceAvetixOnAccessAvetixUpdateServiceAvgAvg7AlrtAvg7CoreAvg7RsWAvg7RsXPAvg7UpdSvcAvgAMPSAvgAdminServerAvgTdiAvgbootaAvgbootxAvgdiskaAvgdiskxAvgfwdxAvgfwfdAvgldx64Avgldx86AvglogaAvglogxAvgmfx64Avgmfx86Avgrkx64Avgrkx86AvgtdiaAvgtdixAvgunivxAvgwfpaAvgwfpxAvira.ServiceHostBAPIDRVBAVSvcBDSandBoxBDVEDISKBHDrvx64BHDrvx86BHipsSvcBNmonBRN_APPGUARD_SERVICEBcfilterBcfilterMPBdAgentBdApiUtilBdCameraProtectBdDesktopParentalBdNetBdSpyBdfndisfBehavior Detection SystemBfilterBfmonBhbaseBkavBkavAutoBkavChkUIBkavCoreLibBkavSRBkavSdFltBkavServiceBkavSystemServiceBluProServiceBnbaseBndefBprotectBprotectExBrnFileLockBrowser Defender Update ServiceBsBackupBsBhvScanBsFileScanBsFireBsMailProxyBsMainBsScannerBsUpdateCAAMSvcCAISafeCSCrySecCSObjectsSrvCSVirtualDiskDrvCaCCProvSPCdmDrvNtCezurityAntivirusServiceComFiltrCore Mail ProtectionCore Scanning ServerCore Scanning ServerExDSAFLTDouble Anti-Spy Task ManagerDrWebAVServiceDrWebEngineDrWebFwSvcDrWebLwfDrWebNetFilterDrWebWfpDwDevGuardDwHVDwProtEMLSSESHASRVEconServiceEfiMonEhttpSrvEncDiskEpfwLWFEpfwndisF-Secure GatekeeperF-Secure HIPSFAFileMonFA_SchedulerFCSAMFNETMONFPAVServerFPAV_RTPFSMAFSORSPClientFWCoreFWNDIS_LWFFWServiceFcsSasFileMonitorFkndisfFortiFWFortiRdrFortiShieldFortiWFFortipsGDBackupSvcGDBehaveGDFwSvcGDMnIcptGDNdisIcGDPkIcptGDScanGDTdiInterceptorGDTunerSvcGLoginGeSWallGlassWireGuardXHipShieldKHomeNetSvcHomeVNServiceHookCentreHookPortHookTdiHyperVMIDSFLTIDSVia64IDSVix86IDSxpx86IDriverTIMFserviceISFWEntISIPSEntISPIBEntISPrxEntImmunetNetworkMonitorDriverImmunetProtectImmunetProtectDriverImmunetSelfProtectDriverJetico Personal Firewall serverK7CrvSvcK7EmlPxyK7FWFiltK7FWHlprK7FWSrvcK7PSSrvcK7RTScanK7SentryK7SpmSrcK7TSMngrK7TdiHlpKLIFKLIM6KSafeSvcKerioMailServerKmxAMRTKmxAgentKmxCFKmxCfgKmxFileKmxFilterKmxFwKmxSbxKmxStartL2NDNSLavasoftAdAwareService11MBAMProtectorMBAMSchedulerMBAMServiceMBAMSwissArmyMBAMWebAccessControlMOBKFilterMOBKbackupMPCKptMPCProtectServiceMSDLAVkrnMSK80ServiceMWAgentMcAPExeMcAfee SiteAdvisor ServiceMcAfeeFrameworkMcBootDelayStartSvcMcComponentHostServiceMcMPFSvcMcNaiAnnMcODSMcProxyMcPvDrvMcShieldMcTaskManagerMeDCoreD_V3IS80Microsoft AntimalwareMksMonEnMksMonEvMksMonFdMpFilterMsMpSvcN360NASSNAVENGNAVEX15NETFLTDINETIMFLT01060034NETIMFLT01060039NETIMFLT01060044NGSNHSNIGNISNNFSVCNNSALPCNNSHTTPNNSHTTPSNNSIDSNNSNAHSNNSNAHSLNNSPICCNNSPIHSNNSPIHSWNNSPOP3NNSPROTNNSPRVNNSSMTPNNSSTRMNNSTLSCNNetSecCNPFSvc32NPFSvc32_DataNPROSECNPROSECSVCNSNTGUARDNUAANanoServiceMainNdiskioNisSrvNorman NJeevesNorman ZANDANovaShieldFilterDriverNovaShieldTDIDriverNvcMFltOADeviceOAcatOAmonOAnetOnline Protection SystemOnline Shield Starter ServicePAVFNSVRPAVSRVPCTAppEventPCTBDPCTCorePCTFW-PacketFilterPCTSDPCToolsFirewallPlusPEFServicePPDrvPPEMSCANPROCMON20PROCMON23PSHostPSIMSVCPSINAfltPSINFilePSINKNCPSINProcPSINProtPSINRegPSKMADPSUAServicePanda Software ControllerPandaAgentPavPrSrvPavProcPavTPK.sysPlatinum Host ServiceProcObsrvProductAgentServicePskSvcRetailQHActiveDefenseQMUdiskQQPCRTPQQSysMonQQSysMonX64Quick Update ServiceRVSMONBLRegFilterRoboFwwRoboRtwIFDrvRoboscan_RTSrvRoboscan_UpdSrvRsMgrSvcRsRavMonRusRouteRusRouteMPSAPlusSASDIFSVSASKUTILSAUAVSvcSAVAdminServiceSAVOnAccessSAVOnAccessControlSAVOnAccessFilterSAVServiceSBAMSvcSBFWIMCLSBFWIMCLMPSBPIMSvcSDScannerServiceSDUpdateServiceSDWSCServiceSFWCalloutSKMScanSQLANYs_sem5SRTSPSRTSPXSYMTDISafeBoxSandBoxSbFwScSecSvcScanWscSSchedulerSepMasterServiceShldDrvShldFltSmcServiceSophos AutoUpdate ServiceSophos Client FirewallSophosBootDriverSpiderG3SpyEmrgSpyEmrgAccessSpyEmrgGuardSpyEmrgHealthSpyEmrgSrvSpyshelterSpyshelterKbStopSign Update ManagerSvcOnlineArmorSyDvCtrlSymDSSymEFASymEFASISymELAMSymEventSymIRONSymNetSSysLibSysLib0SysLib1SysLib2SysLib3SysLib4SysLib5SysLib6SysLib7SysPlantTFsFltTICAPDRVTIRepServiceTListenerSvcTMEBCTPPFHOOKTPSrvTS4NTTSKSPTSNxGServiceTSSysKitTeeferTeefer2TfFRegNtTfFsMonTfNetMonTfProcNtTfSysMonThreatFireTrafInspSrvTrojanKillerDriverTsFltMgrUGBroMonUGKrnlDrvUGProtectUGSVCUPDATESRVUPKernelUTSvcManager3UmxEngineUrlFilterV3 ServiceV3Flt2KV3Flu2k_V3IS80V3IFt2KVBCoreNT.0VBEngNTVBFiltVSSERVVba32ECMVba32LdrVba32PP3Vba32ProtVba32dNTVba32ifsVba32mNTVbaControlAgentVsdatantWNMFLTWRDRVWRSVCWRkrnWdBootWdFilterWdNisDrvWdNisSvcWinDefendWinRouteYndisimYndisimMPZAPrivacyServiceZEFAVAuxSvcZEFAVCoreSvcZEFAVEFSvcZhuDongFangYuZillyaAVAuxSvcZillyaAVCoreSvcZnfa2AntiMalwarea2acca2injectiondrivera2utilacssrvafwafwcoreapspDriverarcabitsvarcawfparwfltarwsrvcasd2fsmaswFsBlkaswHwidaswMon2aswMonFltaswNdisaswNdis2aswNdisFltaswNetSecaswRdraswRvrtaswSPaswSnxaswStmaswStmXPaswTdiaswUpdSvaswVmmavas_serviceavasdmftavast! Antivirusavast! Firewallavast! Mail Scanneravast! Web Scanneravc3avchvavckfavetixBCavetixSPavg8emcavg8wdavgfwsavgntfltavgsvcavgunivaavgwdavipbbavkmgravnetfltbc_hash_fbc_ip_fbc_ngnbc_pat_fbc_prt_fbc_tdi_fbcfsrmbcftdibckdbdelambdfsfltrbdftdifbdfwfpfbdfwfpf_pcbdselfprbdsfltbdsnmbsfscatfltccSchedulerSVCccSet_CloudccSet_N360ccSet_NISccSet_NSccSettings_2FF4FBED-F03A-4EE2-AC58-C985811A4FBEccSettings_3AC20362-8119-4C85-8CAC-8FC00AFA6B91cfwidscleanhlpcm_kmcmcenginecmciscmdAgentcmdGuardcmdHlpcmderdcmdvirthdefensewall_servdrwagntddsiodwalleLoggerSvc6eScan Monitor ServiceeScan-trayicoseac_notifysvceac_productsvceamoneamonmeas_httpsvreconcealeconcealMPedevmoneeCtrlehdrvekrnemlssxepfwepfwtdiepfwtdirepfwwfpepfwwfprffsmonfilddsfilmfdfilppdfortiapdfortiloaderfortisnifffortknoxfortknox_drvfsbtsfshosterfsnifsvistaft_vnicgddcdgddcvgdwfpcdgfi_lanss11_attservicegfiarkgfiutilggcgozergswservgzflthVrCommandSvchVrMalSvchooksysiSafeKrnliSafeKrnlBootiSafeKrnlKitiSafeKrnlMoniSafeKrnlR3iSafeNetFilterignisinspectkhelperDriverkl1klactprxkladminserverklbackupfltkldiskklelamklfltklhkklim5klnagentklpdkltdfkltdiklwebsrvklwfpklwtpknepskvnetkwflowerkwfupperkxescorel2nDHCPlliombamchameleonmccspsvcmcpltsvcmdareDriver_48mdareDriver_52mfeapfkmfeavfkmfebopkmfecoremfeelamkmfefiremfefirekmfehidkmfemmsmfencbdcmfencrkmferkdetmfevtpmfewfpkmks_servicesmksfwallfmksidsamksidsfmscankmsdlmwfsmfltrnanofltnanokrnnanosvcnetcontrollernetfilternnetsecnpsvc32nregsecnsesvcnvcoasnvoyoahlpXXpanda_url_filteringpavbootpbfilterpctDSpctEFApctNdispctNdisLWpctNdisLW64pctNdisMPpctgntdipctplfwpctplsmpwipf6qutmdservqutmipcrsdsysrvsengrvsmonrvsmonfrvsmonnsascansascansvcsbaphdsbapifssbhipssbtissbtishtsbwtisscanscfdriverscfndissdAuxServicesdCoreServicesecdlsemlaunchsrvsemsrvsemwebsrvslservicessfwmonsvcssmdrvsstsmonsvcswi_calloutswi_filterswi_serviceswi_updatetdi_nftdifwtdimappertmactmontmcommtmeevwtmeexttmeltmevtmgrtmnciesctmtditmumhtmusatpmgma_servicetpsectrufostwssrvv3engineviprecomsvcvrptcomnvrptselfvsmonwebssxwipesrvwpsdrvntwrUrlFltwsnfwstifxCoreFirewallSvcxCoreUpdateSvczscIt delete files in the following folder (with extensions such as EXE,DLL,SCR,BAT and VBS):C:\Documents and Settings\LocalService\Application DataC:\Documents and Settings\LocalService\Dati applicazioniC:\Documents and Settings\LocalService\Datos de programa"%Program Files%\Common Files%Windows%\system32\config\systemprofile\AppData\Roaming%Application Data%\LocalLow%Application Data%\Local\Temp%Application Data%\Local\Temp\Low%Application Data%\Roaming%Application Data%\Roaming\Microsoft%Application Data%\Roaming\WindowsUpdate%Application Data%\Datos de programa\System%Application Data%\Local Settings\Temp%System Root%\Users\All Users\Documents\svchost%System Root%\Users\All Users\AppData\Roaming\Microsoft\Windows%System Root%\Users\All Users\AppData\Roaming\Windows Update%System Root%\Users\All Users\AppData\Local\Microsoft\Windows%System Root%\Users\All Users\AppData\Roaming\Microsoft\extensions%System Root%\Users\All Users\AppData\Local\Microsoft\extensions%System Root%\Users\All Users\AppData\Roaming\Microsoft\Windows\IEUpdate%System Root%\Users\All Users\AppData\Local\Microsoft\Windows\IEUpdate%System Root%\Users\All Users\AppData\Roaming\Microsoft\Windows\Update%System Root%\Users\All Users\AppData\Roaming\System%Windows%\help\windows\systems%Windows%\fontsIt deletes the following files/folders in the "Program Files" (%Program Files%) directory:2345Soft24x7Help2WdM233download.com\Free Video Downloader34dc5208-3f7e-436e-907b-3dc21b172840360Play3WdM38WdM88WinManPro8ADSafeASPackageAVG Web TuneUpAVHealthMonitorAbrupt TextAccelerer PCActSysAd MuncherAdBlockerAddon EnablerAdguardAdobe-UpdaterAdvanced Monitoring AgentAdvanced Monitoring Agent Network ManagementAdvanced PC CareAdvanced Registry OptimizerAdvanced SystemProtectorAirtostrongAllTubeDownloaderAloof GeneralAlterGeoAmIcoSingLunAmazingTabAmazon Browser BarAmazon\Amazon1ButtonAppAnyDeskAnySendApp BudAppColaAppGraffitiAppetizing IntroductionApplication AssistanceApplication HostingApplication InstallerApplicationHostingAppsetAppsiocEAppthgildeMApptnioPhtooteulBAppverifierAppxelfmuZArchivos comunes\HydrupAruaTussAsistente InfinitumAskPartnerNetworkAssets ManagerAssets Manager\smdmfAtomic Alarm ClockAutomatic UpdateAutorun EaterBIOSTARBRAppBabylonBaiduExBaisvikSoftwareBamcofBandooBetterBrainBin\UpdateToolBitter DisciplineBlazersBocekYazilimBoot CampBreakawayLiveBrownieBrowny02BrownyIndBrowserBrowser DefenderBrowser GoodBrowser LogoBrowser ManagerBrowser RushBrowserCompanionBrowserDefenderBrowserProtectBubbleFighterBuzzing DholByteFenceCCleanerCNN News TickerCalendarToolCaqeqHiamtCashReminderCeroHimnaCetMuuChart ChoosingCheapsterChecked ListCheckerChicaLogic\Chica Password ManagerChomikBoxChristmasTreeClean SweetCleanBrowserCleverSearchClickfreeCloudPrinterClownfishCodeMeterCoffeeFeedCoinMinerCoingeekColorful EatCommon Files\GoobzoCommon Files\HydrupCommon Files\IMGUpdaterCommon Files\PC ToolsCommon TriorisCompanyComputer UpdaterConcomConsumer InputContemplative PathContent DefenderContentProtectorControllerConvertAdCooperative LeadCouponsCoupoonCourageous AnywhereCrowdcoresCrsoftCruel FeeCruel TongueCuHanhCuHanhPlayCupom123DNS UnlockerDWdsManProDDailyPCCleanDailyPcClean SupportDashing GasDatacardServiceDbSecuritySptDeceitful VehicleDefsoftDeltaFixDesProtetorDesk 365DesktopAuthorityDesktopManiaDeuVinDevID AgentDeviceVMDhmReuDisk AnalysisDisplayLink Core SoftwareDolby Advanced Audio v2DownCheckerDripkixDriptaxDriverFinderDriverPack NotifierDriverToolkitDriversProEasy Speed CheckEavitFocEdu AppEgisTec IPSEgisTec\MyWinLocker 3EnterpriseUpdateEnvious PlateEroBisisExperience VideoExtTagExtension FollowExtension ManagerFPSensorFWdMFFaderControllerFast-SearchFastCompress-ZipFastPcToolsFastPlayerFastSearchFeed NotifierFile Association HelperFileToNetFilthy BuddyFilthy HorseFirewall Integrity CheckerFlashBeatFlashGamesRockstarFlexfixFloombyFlwsrfFogtransFolder ShieldFolderSizeFoolish KingFramed DisplayFrantic ShowerFreemakeFreemake SharedFresh TowerFuzzy LivingGOSaferGamesRSGbPluginGenie SoftGiddy ReflectionGigabase\GuardGlary Utilities 5Globe Tattoo BroadbandGlorious LessonGoCouponsGreener WebGritty VacationGrotesque MoneyGuluxMecchHandSetServiceHard CaseHi-Rez StudiosHiSuiteOucHipmoIdodHitsBlenderHoistsearchHollow EstateHomePageDefenderHomeTabHonControllerHorrific ShoulderHost SecureHost32managerHostifyHouse\DormHuge AnythingHuge SwingHulaTooHurt NorthIAC UpdaterICCupICQ6ToolbarIM MagicianIObitBarIQIYI VideoIcyCarjeIdea Net SetterIePluginServiceIePluginServicesImpressionable RoutineInbox StorageInclusionRunnerInfigoInternet Content FilterInternet ExplorarInternetUpdaterIrate RemoveItibiti Soft PhoneJWdMJJWdsManProJJava Security PluginJava Update 2.0Jittery GuitarJittery ToneJoinME DriversJokerAdsJoyous HookJukdEsoiaJumpstartKDubaSoftDownKDubaSoftPgupKRB Updater UtilityKedmAboKeepUpKey SwitcherKeyboard Device UpdateKiller NetworkingKinoroom BrowserKit CookingKleptomaniaKnowhow CloudKokoMossKopEgucKorukoLarge StableLaunch ManagerLaunchyLazy UsualLightzapLittle InfernoLiveWPPUpdateLoadLeaderLogo ExtensionLolClientLolliScanLovi VideoLoviVKLoviVideoLuckyBrowseLuckyTabLyricsTabMAgentMPCBrowserMSConfig Extended 2.0MWdMMMacho PhysicsMagic Memory OptimizerMailUpdateMakeIt-TeamManiacal MailMax Driver UpdaterMaxLimMaxLim\AlarmClockMedia SaverMediaGet ToolbarMediaGet2MediaLinguaMedlightMegaDownloaderMicrosoft Application Virtualization ClientMicrosoft Firewall Client 2004Microsoft Security EssentialsMinerGateMiniLiteMiuiTabMixVideoPlayerUpdaterServiceMixesoftMobile PartnerMobileBrServMobogenieMobogenie3Mortified ClimateMovieDeaMovies AppMovies ToolbarMp3Tube ToolbarMusic AppMusicsPlayersMy Cute BuddyMyBarMyDesktopMyPC BackupMyTubeTheaterNAT ServiceNapnutNet Control 2NetServiceNetTimeNetWriterNewWinDcomSvcNhtBamdNiceHashMinerNixControllerNixSrvNorpallaNorton PC CheckupNote-upNsCpuCNMinerNuanceOLBPreOasis SpaceObject BrowserObnovi SoftOdd AttitudeOlacaritaOneSafe PC CleanerOneSystemCareOutrageous CurrencyPC App StorePC CleanerPC FasterPC PerformerPC Registry ShieldPC Speed MaximizerPC Speed UpPC Ultra SpeedPCPowerSpeedPCValidatorPDF ArchitectPaceItUpPando NetworksPathMaxxPennyBeePerSefitPhotod1exPhraseProfessorPingzapperPirritPlaceEnginePlain ClerkPlayFree BrowserPogo GamesPojkoJetigPompous GivePopAppPopularScreensaversPremierOpinionPrickly RisePrimary ColorPro PC CleanerProbit SoftwareProcess KillerProtector Suite QLProxyAppQualityCheckerQuickSearchQuizzical OfficerREACHitRanlabRayDldRebateInformerReber QuickReg OrganizerRegistry HelperReimageRelayAppendRemote Manipulator System - HostRemote MouseRemote Utilities - HostRiokfByplRipe ValuableRonzapRosettaStoneLtdServicesRrFilterSMART BROSWMiniProSSWinManProSSafeGuardSatelliteAgentSavePass 1.1SaveSenseLiveScpadScreen CaptureSearchDefenderSearchModuleSearchSnacksSearchesToYesbndSecuritySecurity Updates ServiceSeePasswordSelectionToolSersoftSettings ManagerSharp AngleShop and Save UpShopperProShopperPro3SijsUwuccSilverSurferSiteRankerSkrinshoterSkyMonkSleep Memory OptimizerSlippery PolicySmartTweakSmartUpdaterSmartWebSniffer serviceSoftobaseSoftware InformerSoftwareUpdaterSohaServiceSokyraSoloecoSolotoughSound+SourceAppSpIZdqeadXSpaceSoundProSpanplusSpeedItup FreeSpiderMessengerSpiderShareSplendid IncreaseSpotless SmileSpyware Process DetectorStartNow ToolbarSteel CutSticky PullSublightSunlexSupdaterSuper OptimizerSweepTools PC CleanerSystemMonitor2016SystemSafeguardTDataDldTFEIMLPETaladappTangoTaobaoProtectTbccintTeamViewerUpdateTeeny ImprovementTempMoudleSetTencent\AndroidServerTendaTepfelTextEditorThankful GasThcuKedcThhaaWobkThunder MasterTicnoTigo\OnlineUpdateTimeTasksTmp0x0xToday CalendarToggleMarkTomTom HOME 2ToolGetToolsUpdatePlatformTorchTorrent SearchTotal PluginTotal Privacy ProtectorTouchUtilityTrueCafeTunnelBearTv-Plug-InTypingMasterUCBrowserUTILILAB\SystemOPTIMIZERUltraZipUncheckyUniversal Driver UpdaterUniversal UpdaterUpdaterUpdater By SweetpacksUpsPilotUpset CarryUptight DistrictUtatityV-batesVK DownloaderVOPackageVaiafinecoVast AssistVemgIhaViGlanceViafreshVibrateGameDeviceDriverView-PasswordVirtual CookingViscosityVisual Protect ServiceVolumeControlVuuPCWIntEnhancerWInterEnhancerWNEn Browser EnhancerWNetEnhanceWNetEnhancerWNetworkEnhanceWTFast BetaWaIntEnhanceWaIntEnhancerWaInterEnhanceWaInterEnhancerWaInternetEnhancerWaNetworkEnhanceWaNetworkEnhancerWacky GreenWadaBarWajIEnWajInterEnhancerWajInternetEnWajNetEnWajNetworkEnhancerWajaIntEnWajaIntEnhancerWajaInternetEnhancerWajaNetEnWajaWebEnhanceWandoujiaWeatherToolWeb ProtectWebBarWebPlayerWebProtectorPlusWildTangent GamesWinArchiverWinCalendarTimeWinLoaderModuleWinNetSvcWinThrusterWinZip Registry OptimizerWindoWeatherWindows Genuine AdvantageWindows Network AcceleraterWindows SecurityWindows Update EngineWindowsMangerProtectWindowsProtectMangerWindowsUpdWinreview.ruWinsereWixerWizzWifiHotspotXTRM GroupXclientXvirus AdblockerYoutubeDownloader.orgZaxarZetaGamesZetaGamesNewsZetaGamesViewerZitenopZoiperZonzapZuiSyogaWdMaadvPluginafoiralipayamdidxb4bc9939-75e9-422b-af5c-653de35c4f4bbProtectorbanda larga tmnbest-markit-softbestLyricscWinManProccaMyciloPchk32chroomium Browserclick-n-mark Corpcmcm\Clean MastercmdidxcomoBosscpuminercrxbro Browserdaugavadbprotectsupporedbprotectsupportddweatherdesktopfinddlohne25f457c-9287-4f2d-b5a8-8cd714c55009eAHPeNhIUJeDealPopendaxeye performezvitInfofacemoods.comfchk32ffgogogo BrowsergByrATgate snapperghokswa BrowserglobalUpdategocoupongreenapphostskidkiiCLS ClientiSafeiWebariWin GamesiZ3D DriveriretadpUksecurlogishrdma-config.commajtu100_mx_14mediabar Toolbarmizipmysites123net1-sedenetcutnetfilterneurowisentsvcoTweakohnuzepeaeLlzqkseeruyisoschk32screentkserfeserfevsgulPhceTskinappsnda\sdupdatespeed browserstoragecraftsurf slidesushileadssystipst100mx1tiger savingsuCozMediaver9Safer-SurfwainternetenwajainternetenwajanenwajinterenwebgetwinterenwnetworkenyWdMyD9E629DC-CB1C-4A97-9900-81922B4EFFD4003\vxlsnyaiet32.exe005\hzunyanhtn64.exeASP\AdvancedSystemProtector.exeAssistant\AssistantSvc.dllBifrost\server.exeClinckProxy.exeClinckSystemLayer.exeCommon Files\Microsoft shared\ink\pt\services.exeCommon Files\WWS\Watchdog.exeCommon Files\microsoft shared\ink\TabTip.exeCompany\gupdate\gupdate.exeMicrosoft Data\InstallAddons.exeOpera\opera.batRCP\systweakasp.exeSFK\SSFK.exeSecurity\winsec.exeSoftware\Update\SoftwareUpdate.exeWindows AlerterWindows Common FilesWorkspace\offSyncService.exebadu\sys.exebaidu\baidu.execommon files\nt\smetts.execommon files\speechengines\microsoft\spcomon.inifr\fr.exepchd\PCHDPlayer.exesyspwow\syspwow.exeupdate\UpdateAgent.exeIt delete files/folder from User's Temp (%User Temp%) and Windows Temp (%Windows%\Temp) directories:.clamwin360SD360WD360safeAFWCORE.sysAVAST SoftwareArcabitAshampoo\Ashampoo FirewallAvanquestAvg2014AvgPackageAviraBaidu SecurityBaidu\BaiduBaidu\Baidu AntivirusBavPro_Setup_Mini_GLBgInstallAssistOld.txtBitdefenderBkavHome2014BkavWhatsNewEN_filesBullGuardBullGuard Premium Protection Setup.exeComodoCrystal SecurityESCANDB.LOGESETGDATA_Online_UpdateHCBackupHCLauncher.logHouseCallIObitIObit AppsK7 ComputingK7TSInsFont.ttfK7TSInsRes.dllKAV Remote InstallationsLavasoftLavasoftStatisticsMPASBASE.VDMMPASDLTA.VDMMPAVBASE.VDMMPAVDLTA.VDMMPENGINE.DLLMWAV.LOGMalwarebytesMcAfeeMcAfee File LockMicroWorldMpCmdRun.logOnlineArmorPanda SecurityPavLogInstSYMEVENT.LOGSandBox.sysSecurityScan_ReleaseSophos AutoUpdate Install Log.txtSophos Client Firewall CustomActions Log.txtSophos Client Firewall DriverHelper Log.txtSophos Client Firewall install log.txtSophos Standalone Installer.txtSophos Web Intelligence Install.logSpyShelterTiInstTitaniumTrend MicroTrendMicro AntiThreat ToolkitVIPREVIPREPremiumInstaller.logZillya Internet Security_avast5__avast_afw_setup.logavast_ashavginfo.idbaidu\Antivirusbaidu_secureeAccelerationhousecall.guid.cacheiSafeRightKeyScankeriokerio-connect.setup.logkerio-control.setup.logkerio_webmailnanoavpanda4_1dnpandasecurity-manifest.xmlpandasecurity-toolbar.xmlpandasecuritytb_Install_Log.txttrend downloadv3init2.log64F7A9DE-BB02-4DAC-9246-E9B7668B9503It delete the following files in the Windows directory:32\chromex.exeAppUpdate\updater.exeAudioHQ.dll.exeBkavFirewallService.exeBluProService.exeCursors\services.exeFonts\svchost.exeINCAinternet\nProtect Anti-Virus Spyware 3.0\nspsvc.exeINCAinternet\nProtect Anti-Virus Spyware 3.0\nspupsvc.exeImageSAFERSvc.exeInstallDir\svchost.exeInstallDir\winexe.exeK7TSDbg.exeMicrosoft.comSAsrv.exeSSVICHOSST.exeSVOHOST.exeSys\Windows Defender.exeSys\svchost.exeTEMP\system\svchost.exeTaskcall.EXETasks\FLASHUPDATETerms.exeUPDATERWIN.EXEUpdatesvc.exeWin7.exeantivar.exeaswBoot.exebc.exebsmain.execiique.execsrcs.execsrsc.execsrss.exedebug\wmisrv.exedefensewall_serv.exedell\iexplore.exedell\pubwin.vbsdfrg\svc.exedj.exedriver.exedrivers\ctfmon.exedrivers\etc\svchost.exedrivers\svchost.exeext_driver.exeexxplorer.exefonts\anqn.exefonts\taskhost.exehostnamex.exeiexplore\iexplore.exeiexplorer.exeinf\wuauclt.exeipz.exeipz2.exejmesoft\Service.exejusched.exekamsoft.exelogfiles\nssm.exelogfiles\svchost.batlsass.exelsasvc.exemlwps.exempk\MPK.exempk\lsynchost.exenieyou.exeoobe\explorer.exepresident.exercore.exerunSW.exeschost.exesdeeae3e.exesetup\webser.exespeech\csrss.exespeech\taskhost.exessysstem32.exessystemxx32.exesvc49.exesvccost.exesvchoost.exesvchost.comsvchost.exesvshost.exesysfiles\rutserv.exesystem.batsystem\svchost.exesystem\svchosts.exesystem\system\start.vbssystem\taskhost.exesystem\win32.exesyswow\conhost.exetcpsv\ams.exetpnative.exevss\svchost.exewauctla.exewinfile.exewininits.exewinscok.dllwmisrv.exezkz.exe 2ff7e9595c
コメント