Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Trojan.Siggen14.26867

Added to the Dr.Web virus database: 2021-07-06

Virus description added:

Technical Information

To ensure autorun and distribution
Sets the following service settings
  • [<HKLM>\System\CurrentControlSet\Services\EUEDKEPM] 'Start' = '00000001'
  • [<HKLM>\System\CurrentControlSet\Services\EUEDKEPM] 'ImagePath' = '<DRIVERS>\EUEDKEPM.sys'
  • [<HKLM>\System\CurrentControlSet\Services\EUDCPEPM] 'Start' = '00000000'
  • [<HKLM>\System\CurrentControlSet\Services\EUDCPEPM] 'ImagePath' = 'system32\drivers\EUDCPEPM.sys'
Creates the following services
  • 'EUEDKEPM' <DRIVERS>\EUEDKEPM.sys
  • 'EUDCPEPM' <DRIVERS>\EUDCPEPM.sys
Malicious functions
Executes the following
  • '%WINDIR%\syswow64\taskkill.exe' /IM EUCloneServer.exe /F
Modifies file system
Creates the following files
  • %ProgramFiles(x86)%\epm\res\loading.gif
  • %ProgramFiles(x86)%\epm\dc\bin\authorizedmng.dll
  • %ProgramFiles(x86)%\epm\bin\auconvex.dll
  • %ProgramFiles(x86)%\epm\bin\auconv.dll
  • %ProgramFiles(x86)%\epm\bin\atl90.dll
  • %ProgramFiles(x86)%\epm\dc\bin\agent.dll
  • %ProgramFiles(x86)%\epm\dc\bin\activeonline.dll
  • %ProgramFiles(x86)%\epm\dc\bin\activationonline.dll
  • %ProgramFiles(x86)%\epm\dc\bin\accountmanager.dll
  • %ProgramFiles(x86)%\epm\bin\winchkdsk.exe
  • %ProgramFiles(x86)%\epm\dc\bin\winchkdsk.exe
  • %ProgramFiles(x86)%\epm\dc\bin\vssfreeze-server.exe
  • %ProgramFiles(x86)%\epm\dc\bin\tblang.exe
  • %ProgramFiles(x86)%\epm\bin\spawn.exe
  • %ProgramFiles(x86)%\epm\nircmd.exe
  • %ProgramFiles(x86)%\epm\bin\main.exe
  • %ProgramFiles(x86)%\epm\hidcon.exe
  • %ProgramFiles(x86)%\epm\dc\bin\eucloneserver.exe
  • %ProgramFiles(x86)%\epm\dc\bin\drvsetup.exe
  • %ProgramFiles(x86)%\epm\bin\convertfat2ntfs.exe
  • %ProgramFiles(x86)%\epm\dc\bin\bootsect.exe
  • %ProgramFiles(x86)%\epm\bin\bootsect.exe
  • %ProgramFiles(x86)%\epm\dc\bin\bcdedit.exe
  • %ProgramFiles(x86)%\epm\bin\bcdedit.exe
  • %ProgramFiles(x86)%\epm\bin\adddrivers.exe
  • %ProgramFiles(x86)%\epm\dc\bin\activetrans.exe
  • %ProgramFiles(x86)%\epm\bin\autoupdate.dll
  • %ProgramFiles(x86)%\epm\bin\boot.dll
  • %ProgramFiles(x86)%\epm\bin\eucloneclient.dll
  • %ProgramFiles(x86)%\epm\dc\bin\bootdriver.dll
  • %ProgramFiles(x86)%\epm\dc\bin\erasedata.dll
  • %ProgramFiles(x86)%\epm\dc\bin\enumdisk.dll
  • %ProgramFiles(x86)%\epm\bin\efiboot.dll
  • %ProgramFiles(x86)%\epm\dc\bin\efiboot.dll
  • %ProgramFiles(x86)%\epm\bin\easeustooldll.dll
  • %ProgramFiles(x86)%\epm\dc\bin\dsrestore.dll
  • %ProgramFiles(x86)%\epm\dc\bin\dsmonitor.dll
  • %ProgramFiles(x86)%\epm\dc\bin\devicemanager.dll
  • %ProgramFiles(x86)%\epm\dc\bin\deviceio.dll
  • %ProgramFiles(x86)%\epm\dc\bin\deviceadapter.dll
  • %ProgramFiles(x86)%\epm\dc\bin\device.dll
  • %ProgramFiles(x86)%\epm\bin\devctrl.dll
  • %ProgramFiles(x86)%\epm\bin\datamana.dll
  • %ProgramFiles(x86)%\epm\dc\bin\correctmbr.dll
  • %ProgramFiles(x86)%\epm\dc\bin\compressfile.dll
  • %ProgramFiles(x86)%\epm\dc\bin\common.dll
  • %ProgramFiles(x86)%\epm\dc\bin\codelog.dll
  • %ProgramFiles(x86)%\epm\bin\codelog.dll
  • %ProgramFiles(x86)%\epm\dc\bin\cmdpack.dll
  • %ProgramFiles(x86)%\epm\dc\bin\cmdmanager.dll
  • %ProgramFiles(x86)%\epm\dc\bin\cloudoperator.dll
  • %ProgramFiles(x86)%\epm\dc\bin\callbackoperator.dll
  • %ProgramFiles(x86)%\epm\dc\bin\burn.dll
  • %ProgramFiles(x86)%\epm\dc\bin\bpvolume.dll
  • %ProgramFiles(x86)%\epm\bin\bootdriver.dll
  • %ProgramFiles(x86)%\epm\dc\bin\tblogsysclient.tblog
  • %ProgramFiles(x86)%\epm\dc\bin\boot.dll
  • %ProgramFiles(x86)%\epm\multi\epmui_en.qm
  • %ProgramFiles(x86)%\epm\bin\extfilesystemanalyser.mo
  • %ProgramFiles(x86)%\epm\bin\devicemanager.mo
  • %ProgramFiles(x86)%\epm\bin\deviceadapter.mo
  • %ProgramFiles(x86)%\epm\bin\device.mo
  • %ProgramFiles(x86)%\epm\bin\convertfattontfs.mo
  • %ProgramFiles(x86)%\epm\bin\config.mo
  • %ProgramFiles(x86)%\epm\bin\common.mo
  • %ProgramFiles(x86)%\epm\bin\checkversion.mo
  • %ProgramFiles(x86)%\epm\bin\callbackoperator.mo
  • %ProgramFiles(x86)%\epm\bin\wow64\syswow64dir.lst
  • %ProgramFiles(x86)%\epm\bin\wow64\syswow64.lst
  • %ProgramFiles(x86)%\epm\bin\wow64\system32.lst
  • %ProgramFiles(x86)%\epm\bin\wow64\softreg.lst
  • %ProgramFiles(x86)%\epm\bin\easeusld.ldr
  • %ProgramFiles(x86)%\epm\bin\hd000.dpt
  • %ProgramFiles(x86)%\epm\bin\licensemgr.dll.bak
  • %ProgramFiles(x86)%\epm\bin\wow64\manifest8.1
  • %ProgramFiles(x86)%\epm\dc\bin\universal.ini
  • %ProgramFiles(x86)%\epm\multi\res_en_us\uiconfigadd.ini
  • %ProgramFiles(x86)%\epm\res\uiconfig.ini
  • %ProgramFiles(x86)%\epm\res\toolsapp.ini
  • %ProgramFiles(x86)%\epm\dc\multi\res_en_us\res\tbemlib.ini
  • %ProgramFiles(x86)%\epm\dc\bin\tbconfig.ini
  • %ProgramFiles(x86)%\epm\bin\tbconfig.ini
  • %ProgramFiles(x86)%\epm\multi\res_en_us\setup.ini
  • %ProgramFiles(x86)%\epm\dc\multi\res_en_us\res\language.ini
  • %ProgramFiles(x86)%\epm\bin\efiboot.mo
  • %ProgramFiles(x86)%\epm\bin\extformat.mo
  • %ProgramFiles(x86)%\epm\bin\thread.mo
  • %ProgramFiles(x86)%\epm\bin\extresizemove.mo
  • %ProgramFiles(x86)%\epm\bin\sectorcopy.mo
  • %ProgramFiles(x86)%\epm\bin\resizentfs.mo
  • %ProgramFiles(x86)%\epm\bin\reglib.mo
  • %ProgramFiles(x86)%\epm\bin\partitionrecovery.mo
  • %ProgramFiles(x86)%\epm\bin\partition.mo
  • %ProgramFiles(x86)%\epm\bin\ntfsutil.mo
  • %ProgramFiles(x86)%\epm\bin\ntfsresizemove.mo
  • %ProgramFiles(x86)%\epm\bin\ntfslib.mo
  • %ProgramFiles(x86)%\epm\bin\ntfsformat.mo
  • %ProgramFiles(x86)%\epm\bin\ntfsfilesystemanalyser.mo
  • %ProgramFiles(x86)%\epm\bin\ntfscopy.mo
  • %ProgramFiles(x86)%\epm\bin\mom.mo
  • %ProgramFiles(x86)%\epm\bin\mergepartition.mo
  • %ProgramFiles(x86)%\epm\bin\log.mo
  • %ProgramFiles(x86)%\epm\bin\ldmmanager.mo
  • %ProgramFiles(x86)%\epm\bin\fixup.mo
  • %ProgramFiles(x86)%\epm\bin\filesystemcheck.mo
  • %ProgramFiles(x86)%\epm\bin\filesystemanalyser.mo
  • %ProgramFiles(x86)%\epm\bin\filesystem.mo
  • %ProgramFiles(x86)%\epm\bin\fatresizemove.mo
  • %ProgramFiles(x86)%\epm\bin\fatlib.mo
  • %ProgramFiles(x86)%\epm\bin\fatformat.mo
  • %ProgramFiles(x86)%\epm\bin\fatfilesystemmove.mo
  • %ProgramFiles(x86)%\epm\bin\fatfilesystemanalyser.mo
  • %ProgramFiles(x86)%\epm\bin\fatcopy.mo
  • %ProgramFiles(x86)%\epm\bin\winformat.mo
  • %ProgramFiles(x86)%\epm\dc\bin\logsys.dll
  • %ProgramFiles(x86)%\epm\bin\eclog.log
  • %ProgramFiles(x86)%\epm\dc\bin\eupipe.dll
  • %ProgramFiles(x86)%\epm\dc\bin\transmit.dll
  • %ProgramFiles(x86)%\epm\dc\bin\thread.dll
  • %ProgramFiles(x86)%\epm\dc\bin\tbservice.dll
  • %ProgramFiles(x86)%\epm\dc\bin\tbgetremotenetinfo.dll
  • %ProgramFiles(x86)%\epm\dc\bin\tbfirewall.dll
  • %ProgramFiles(x86)%\epm\bin\adds\tbexportsdk.dll
  • %ProgramFiles(x86)%\epm\dc\bin\tbdataswap.dll
  • %ProgramFiles(x86)%\epm\dc\bin\superfat.dll
  • %ProgramFiles(x86)%\epm\bin\ssleay32.dll
  • %ProgramFiles(x86)%\epm\dc\bin\resizentfs.dll
  • %ProgramFiles(x86)%\epm\dc\bin\reglib.dll
  • %ProgramFiles(x86)%\epm\bin\reclib.dll
  • %ProgramFiles(x86)%\epm\dc\bin\rapidntfs.dll
  • %ProgramFiles(x86)%\epm\bin\platforms\qwindows.dll
  • %ProgramFiles(x86)%\epm\bin\qtlib.dll
  • %ProgramFiles(x86)%\epm\bin\qt5winextras.dll
  • %ProgramFiles(x86)%\epm\bin\qt5widgets.dll
  • %ProgramFiles(x86)%\epm\bin\qt5gui.dll
  • %ProgramFiles(x86)%\epm\bin\qt5core.dll
  • %ProgramFiles(x86)%\epm\bin\iconengines\qsvgicon.dll
  • %ProgramFiles(x86)%\epm\bin\platforms\qoffscreen.dll
  • %ProgramFiles(x86)%\epm\bin\platforms\qminimal.dll
  • %ProgramFiles(x86)%\epm\bin\imageformats\qico.dll
  • %ProgramFiles(x86)%\epm\bin\imageformats\qgif.dll
  • %ProgramFiles(x86)%\epm\dc\bin\partition.dll
  • %ProgramFiles(x86)%\epm\bin\uiclonemodule.dll
  • %ProgramFiles(x86)%\epm\bin\uicreatewinpemodule.dll
  • %ProgramFiles(x86)%\epm\bin\eulog.dll
  • %ProgramFiles(x86)%\epm\dc\bin\uilogic.dll
  • %TEMP%\euepm_main.exe.log
  • %ProgramFiles(x86)%\epm\bin\epmlog.log
  • %HOMEPATH%\desktop\easeus partition master 14.5.lnk
  • %WINDIR%\syswow64\drivers\.sys
  • %WINDIR%\syswow64\drivers\eudcpepm.sys
  • %WINDIR%\syswow64\drivers\euedkepm.sys
  • %ProgramFiles(x86)%\epm\dc\bin\easeusdrv.log
  • %ProgramFiles(x86)%\epm\drv\euedkepm.sys
  • %ProgramFiles(x86)%\epm\drv\eudcpepm.sys
  • %ProgramFiles(x86)%\epm\dc\bin\usb\x64\delenum.sys
  • %ProgramFiles(x86)%\epm\dc\bin\usb\x86\delenum.sys
  • %ProgramFiles(x86)%\epm\dc\bin\zstd.dll
  • %ProgramFiles(x86)%\epm\dc\bin\zlib1.dll
  • %ProgramFiles(x86)%\epm\bin\adds\xsssdk.dll
  • %ProgramFiles(x86)%\epm\dc\bin\xmlwrapper.dll
  • %ProgramFiles(x86)%\epm\dc\bin\vsssupport.dll
  • %ProgramFiles(x86)%\epm\dc\bin\vcomp90.dll
  • %ProgramFiles(x86)%\epm\dc\bin\usbbootable.dll
  • %ProgramFiles(x86)%\epm\bin\updateinfo.dll
  • %ProgramFiles(x86)%\epm\dc\bin\updateinfo.dll
  • %ProgramFiles(x86)%\epm\bin\uitoolsmodule.dll
  • %ProgramFiles(x86)%\epm\bin\uiresizemovemodule.dll
  • %ProgramFiles(x86)%\epm\bin\uirecoverymodule.dll
  • %ProgramFiles(x86)%\epm\bin\uimanager.dll
  • %ProgramFiles(x86)%\epm\bin\uimainmodule.dll
  • %ProgramFiles(x86)%\epm\dc\bin\options.dll
  • %ProgramFiles(x86)%\epm\multi\res_en_us\language.ini
  • %ProgramFiles(x86)%\epm\dc\bin\ntfsutil.dll
  • %ProgramFiles(x86)%\epm\dc\bin\log.dll
  • %ProgramFiles(x86)%\epm\dc\bin\license.dll
  • %ProgramFiles(x86)%\epm\dc\bin\libxml2.dll
  • %ProgramFiles(x86)%\epm\bin\libxml2.dll
  • %ProgramFiles(x86)%\epm\bin\libssh2.dll
  • %ProgramFiles(x86)%\epm\dc\bin\libraryproc.dll
  • %ProgramFiles(x86)%\epm\bin\libeay32.dll
  • %ProgramFiles(x86)%\epm\bin\libcurl.dll
  • %ProgramFiles(x86)%\epm\bin\intl.dll
  • %ProgramFiles(x86)%\epm\dc\bin\inctaskchange.dll
  • %ProgramFiles(x86)%\epm\dc\bin\iconv.dll
  • %ProgramFiles(x86)%\epm\dc\bin\hotdrv.dll
  • %ProgramFiles(x86)%\epm\bin\getdriverinfo.dll
  • %ProgramFiles(x86)%\epm\dc\bin\getdriverinfo.dll
  • %ProgramFiles(x86)%\epm\bin\fsclog.dll
  • %ProgramFiles(x86)%\epm\dc\bin\filesystemcheck.dll
  • %ProgramFiles(x86)%\epm\dc\bin\filesystemanalyser.dll
  • %ProgramFiles(x86)%\epm\dc\bin\filestorage.dll
  • %ProgramFiles(x86)%\epm\dc\bin\fatsupport.dll
  • %ProgramFiles(x86)%\epm\dc\bin\fatresizemove.dll
  • %ProgramFiles(x86)%\epm\bin\fatlib.dll
  • %ProgramFiles(x86)%\epm\dc\bin\fatlib.dll
  • %ProgramFiles(x86)%\epm\dc\bin\fatfilesystemanalyser.dll
  • %ProgramFiles(x86)%\epm\dc\bin\fatcopy.dll
  • %ProgramFiles(x86)%\epm\bin\euuserrate.dll
  • %ProgramFiles(x86)%\epm\dc\bin\euupdate.dll
  • %ProgramFiles(x86)%\epm\bin\licensemgr.dll
  • %ProgramFiles(x86)%\epm\dc\bin\eucloneclient.dll
  • %ProgramFiles(x86)%\epm\dc\bin\ntfslib.dll
  • %ProgramFiles(x86)%\epm\bin\mfc90.dll
  • %ProgramFiles(x86)%\epm\dc\bin\ntfsformat.dll
  • %ProgramFiles(x86)%\epm\dc\bin\ntfsfilesystemanalyser.dll
  • %ProgramFiles(x86)%\epm\dc\bin\ntfscopy.dll
  • %ProgramFiles(x86)%\epm\dc\bin\netdrive.dll
  • %ProgramFiles(x86)%\epm\dc\bin\nasoperator.dll
  • %ProgramFiles(x86)%\epm\dc\bin\msvcr90.dll
  • %ProgramFiles(x86)%\epm\bin\msvcr90.dll
  • %ProgramFiles(x86)%\epm\bin\msvcr120.dll
  • %ProgramFiles(x86)%\epm\bin\msvcr100.dll
  • %ProgramFiles(x86)%\epm\dc\bin\msvcp90.dll
  • %ProgramFiles(x86)%\epm\bin\msvcp90.dll
  • %ProgramFiles(x86)%\epm\bin\msvcp60.dll
  • %ProgramFiles(x86)%\epm\bin\msvcp120.dll
  • %ProgramFiles(x86)%\epm\bin\msvcp100.dll
  • %ProgramFiles(x86)%\epm\dc\bin\msvcm90.dll
  • %ProgramFiles(x86)%\epm\bin\msvcm90.dll
  • %ProgramFiles(x86)%\epm\dc\bin\mom.dll
  • %ProgramFiles(x86)%\epm\dc\bin\mfcm90u.dll
  • %ProgramFiles(x86)%\epm\bin\mfcm90u.dll
  • %ProgramFiles(x86)%\epm\dc\bin\mfcm90.dll
  • %ProgramFiles(x86)%\epm\bin\mfcm90.dll
  • %ProgramFiles(x86)%\epm\dc\bin\mfc90u.dll
  • %ProgramFiles(x86)%\epm\bin\mfc90u.dll
  • %ProgramFiles(x86)%\epm\dc\bin\mfc90enu.dll
  • %ProgramFiles(x86)%\epm\dc\bin\mfc90.dll
  • %ProgramFiles(x86)%\epm\dc\bin\ntfssupport.dll
  • %ProgramFiles(x86)%\epm\bin\uicreatemodule.dll
  • %ProgramFiles(x86)%\epm\res\langind.ini
  • %ProgramFiles(x86)%\epm\bin\mom.manifest
  • %ProgramFiles(x86)%\epm\res\ic_merge.png
  • %ProgramFiles(x86)%\epm\res\ic_mbr.png
  • %ProgramFiles(x86)%\epm\res\ic_logical.png
  • %ProgramFiles(x86)%\epm\res\ic_letter.png
  • %ProgramFiles(x86)%\epm\res\ic_label.png
  • %ProgramFiles(x86)%\epm\res\ic_initialize.png
  • %ProgramFiles(x86)%\epm\res\ic_hide.png
  • %ProgramFiles(x86)%\epm\res\ic_format.png
  • %ProgramFiles(x86)%\epm\res\ic_explore.png
  • %ProgramFiles(x86)%\epm\res\ic_dynamic.png
  • %ProgramFiles(x86)%\epm\res\ic_descend.png
  • %ProgramFiles(x86)%\epm\res\ic_delete.png
  • %ProgramFiles(x86)%\epm\res\ic_create.png
  • %ProgramFiles(x86)%\epm\res\ic_convert.png
  • %ProgramFiles(x86)%\epm\res\ic_close.png
  • %ProgramFiles(x86)%\epm\res\ic_clone.png
  • %ProgramFiles(x86)%\epm\res\ic_check.png
  • %ProgramFiles(x86)%\epm\res\ic_basic.png
  • %ProgramFiles(x86)%\epm\res\ic_ascend.png
  • %ProgramFiles(x86)%\epm\res\ic_allocatespace.png
  • %ProgramFiles(x86)%\epm\res\ic_4k.png
  • %ProgramFiles(x86)%\epm\res\icon_wrong.png
  • %ProgramFiles(x86)%\epm\res\icon_winpe.png
  • %ProgramFiles(x86)%\epm\res\icon_toolsm.png
  • %ProgramFiles(x86)%\epm\res\icon_tool.png
  • %ProgramFiles(x86)%\epm\res\ic_migrateos.png
  • %ProgramFiles(x86)%\epm\res\ic_more_arrow.png
  • %ProgramFiles(x86)%\epm\res\logocolour_mm.png
  • %ProgramFiles(x86)%\epm\res\ic_nfts.png
  • %ProgramFiles(x86)%\epm\res\logocolour_drw.png
  • %ProgramFiles(x86)%\epm\res\loading\loading07.png
  • %ProgramFiles(x86)%\epm\res\loading\loading06.png
  • %ProgramFiles(x86)%\epm\res\loading\loading05.png
  • %ProgramFiles(x86)%\epm\res\loading\loading04.png
  • %ProgramFiles(x86)%\epm\res\loading\loading03.png
  • %ProgramFiles(x86)%\epm\res\loading\loading02.png
  • %ProgramFiles(x86)%\epm\res\loading\loading01.png
  • %ProgramFiles(x86)%\epm\res\loading\loading00.png
  • %ProgramFiles(x86)%\epm\res\list.png
  • %ProgramFiles(x86)%\epm\res\link_broken.png
  • %ProgramFiles(x86)%\epm\res\limthintover.png
  • %ProgramFiles(x86)%\epm\res\limthint.png
  • %ProgramFiles(x86)%\epm\res\installyes.png
  • %ProgramFiles(x86)%\epm\res\installno.png
  • %ProgramFiles(x86)%\epm\res\info.png
  • %ProgramFiles(x86)%\epm\res\ic_wipe.png
  • %ProgramFiles(x86)%\epm\res\ic_unhide.png
  • %ProgramFiles(x86)%\epm\res\ic_surface.png
  • %ProgramFiles(x86)%\epm\res\ic_setactive.png
  • %ProgramFiles(x86)%\epm\res\ic_resize_ex.png
  • %ProgramFiles(x86)%\epm\res\ic_resize.png
  • %ProgramFiles(x86)%\epm\res\ic_repair.png
  • %ProgramFiles(x86)%\epm\res\ic_property.png
  • %ProgramFiles(x86)%\epm\res\ic_primary.png
  • %ProgramFiles(x86)%\epm\res\icon_recovery.png
  • %ProgramFiles(x86)%\epm\res\ic_more.png
  • %ProgramFiles(x86)%\epm\res\icon_quest.png
  • %ProgramFiles(x86)%\epm\res\easeus.png
  • %ProgramFiles(x86)%\epm\res\drag.png
  • %ProgramFiles(x86)%\epm\res\disk_icon_s.png
  • %ProgramFiles(x86)%\epm\res\compare_unlimited.png
  • %ProgramFiles(x86)%\epm\res\compare_server.png
  • %ProgramFiles(x86)%\epm\res\compare_professional.png
  • %ProgramFiles(x86)%\epm\res\compare_free.png
  • %ProgramFiles(x86)%\epm\res\closepop.png
  • %ProgramFiles(x86)%\epm\res\cleanup.png
  • %ProgramFiles(x86)%\epm\res\check_unsel_disable.png
  • %ProgramFiles(x86)%\epm\res\check_unsel.png
  • %ProgramFiles(x86)%\epm\res\check_sel_disable.png
  • %ProgramFiles(x86)%\epm\res\check_sel.png
  • %ProgramFiles(x86)%\epm\res\check_halfsel_disable.png
  • %ProgramFiles(x86)%\epm\res\check_halfsel.png
  • %ProgramFiles(x86)%\epm\res\buy_version_disable.png
  • %ProgramFiles(x86)%\epm\res\buy.png
  • %ProgramFiles(x86)%\epm\res\border_shadow.png
  • %ProgramFiles(x86)%\epm\res\arrow_expand.png
  • %ProgramFiles(x86)%\epm\res\arrowu.png
  • %ProgramFiles(x86)%\epm\res\arrowd.png
  • %ProgramFiles(x86)%\epm\res\apply.png
  • %ProgramFiles(x86)%\epm\res\allocatedel.png
  • %ProgramFiles(x86)%\epm\res\allocateadd.png
  • %ProgramFiles(x86)%\epm\res\activate_log.png
  • %ProgramFiles(x86)%\epm\res\waiting.gif
  • %ProgramFiles(x86)%\epm\res\drive.png
  • %ProgramFiles(x86)%\epm\res\erroricon.png
  • %ProgramFiles(x86)%\epm\res\icon_partition_recovery.png
  • %ProgramFiles(x86)%\epm\res\file.png
  • %ProgramFiles(x86)%\epm\res\icon_partition.png
  • %ProgramFiles(x86)%\epm\res\icon_mobimover.png
  • %ProgramFiles(x86)%\epm\res\icon_migrate.png
  • %ProgramFiles(x86)%\epm\res\icon_info.png
  • %ProgramFiles(x86)%\epm\res\icon_dropdown.png
  • %ProgramFiles(x86)%\epm\res\icon_disk_os.png
  • %ProgramFiles(x86)%\epm\res\icon_disk_epm.png
  • %ProgramFiles(x86)%\epm\res\icon_command.png
  • %ProgramFiles(x86)%\epm\res\icon_combox_arrow_normal.png
  • %ProgramFiles(x86)%\epm\res\icon_combox_arrow_disbale.png
  • %ProgramFiles(x86)%\epm\res\icon_combox_arrow_disable.png
  • %ProgramFiles(x86)%\epm\res\icon_clone.png
  • %ProgramFiles(x86)%\epm\res\icon_backup.png
  • %ProgramFiles(x86)%\epm\res\icon_arrow_up.png
  • %ProgramFiles(x86)%\epm\res\icon_arrow_down.png
  • %ProgramFiles(x86)%\epm\res\icon_alert.png
  • %ProgramFiles(x86)%\epm\res\icon_addriver.png
  • %ProgramFiles(x86)%\epm\res\ico-logo.png
  • %ProgramFiles(x86)%\epm\res\helppop.png
  • %ProgramFiles(x86)%\epm\res\hdoublearrow.png
  • %ProgramFiles(x86)%\epm\res\hand.png
  • %ProgramFiles(x86)%\epm\res\free_disable.png
  • %ProgramFiles(x86)%\epm\res\folder.png
  • %ProgramFiles(x86)%\epm\res\fleur.png
  • %ProgramFiles(x86)%\epm\res\fill_bg.png
  • %ProgramFiles(x86)%\epm\res\icon_pctrans.png
  • %ProgramFiles(x86)%\epm\res\taskitem.png
  • %ProgramFiles(x86)%\epm\dc\bin\euclone.ini
  • %ProgramFiles(x86)%\epm\res\logocolour_toolm.png
  • %ProgramFiles(x86)%\epm\bin\microsoft.vc90.openmp.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\microsoft.vc90.mfcloc.manifest
  • %ProgramFiles(x86)%\epm\bin\microsoft.vc90.mfcloc.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\microsoft.vc90.mfc.manifest
  • %ProgramFiles(x86)%\epm\bin\microsoft.vc90.mfc.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\microsoft.vc90.crt.manifest
  • %ProgramFiles(x86)%\epm\bin\microsoft.vc90.crt.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\microsoft.vc90.atl.manifest
  • %ProgramFiles(x86)%\epm\bin\microsoft.vc90.atl.manifest
  • %ProgramFiles(x86)%\epm\bin\log.manifest
  • %ProgramFiles(x86)%\epm\bin\ldmmanager.manifest
  • %ProgramFiles(x86)%\epm\bin\fixup.manifest
  • %ProgramFiles(x86)%\epm\bin\filesystemcheck.manifest
  • %ProgramFiles(x86)%\epm\bin\filesystemanalyser.manifest
  • %ProgramFiles(x86)%\epm\bin\filesystem.manifest
  • %ProgramFiles(x86)%\epm\bin\fatresizemove.manifest
  • %ProgramFiles(x86)%\epm\bin\fatlib.manifest
  • %ProgramFiles(x86)%\epm\bin\fatformat.manifest
  • %ProgramFiles(x86)%\epm\bin\fatfilesystemmove.manifest
  • %ProgramFiles(x86)%\epm\bin\fatfilesystemanalyser.manifest
  • %ProgramFiles(x86)%\epm\bin\fatcopy.manifest
  • %ProgramFiles(x86)%\epm\bin\extresizemove.manifest
  • %ProgramFiles(x86)%\epm\bin\extformat.manifest
  • %ProgramFiles(x86)%\epm\bin\extfilesystemanalyser.manifest
  • %ProgramFiles(x86)%\epm\bin\devicemanager.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\microsoft.vc90.openmp.manifest
  • %ProgramFiles(x86)%\epm\bin\ntfscopy.manifest
  • %ProgramFiles(x86)%\epm\res\logocolour_tb.png
  • %ProgramFiles(x86)%\epm\bin\ntfsfilesystemanalyser.manifest
  • %ProgramFiles(x86)%\epm\dc\multi\res_en_us\bin\dsbackupconfig.ini
  • %ProgramFiles(x86)%\epm\res\consolehelp.ini
  • %ProgramFiles(x86)%\epm\dc\bin\config.ini
  • %ProgramFiles(x86)%\epm\res\stylesheet.css
  • %ProgramFiles(x86)%\epm\dc\bin\tbconfig.xml
  • %ProgramFiles(x86)%\epm\bin\residtext.xml
  • %ProgramFiles(x86)%\epm\start.cmd
  • %ProgramFiles(x86)%\epm\dc\bin\xmlwrapper.dll.manifest
  • %ProgramFiles(x86)%\epm\bin\winformat.manifest
  • %ProgramFiles(x86)%\epm\bin\winchkdsk.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\universal.dll.manifest
  • %ProgramFiles(x86)%\epm\bin\thread.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\thread.dll.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\tbgetremotenetinfo.dll.manifest
  • %ProgramFiles(x86)%\epm\bin\spawn.exe.manifest
  • %ProgramFiles(x86)%\epm\bin\sectorcopy.manifest
  • %ProgramFiles(x86)%\epm\bin\resizentfs.manifest
  • %ProgramFiles(x86)%\epm\bin\reglib.manifest
  • %ProgramFiles(x86)%\epm\bin\partitionrecovery.manifest
  • %ProgramFiles(x86)%\epm\bin\partition.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\options.dll.manifest
  • %ProgramFiles(x86)%\epm\bin\ntfsutil.manifest
  • %ProgramFiles(x86)%\epm\bin\ntfsresizemove.manifest
  • %ProgramFiles(x86)%\epm\bin\ntfslib.manifest
  • %ProgramFiles(x86)%\epm\bin\ntfsformat.manifest
  • %ProgramFiles(x86)%\epm\bin\deviceadapter.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\lang.ini
  • %ProgramFiles(x86)%\epm\bin\device.manifest
  • %ProgramFiles(x86)%\epm\res\success_b.png
  • %ProgramFiles(x86)%\epm\res\start-bg.png
  • %ProgramFiles(x86)%\epm\res\server_enable.png
  • %ProgramFiles(x86)%\epm\res\refresh.png
  • %ProgramFiles(x86)%\epm\res\redo.png
  • %ProgramFiles(x86)%\epm\res\radio_unchecked_disable.png
  • %ProgramFiles(x86)%\epm\res\radio_unchecked.png
  • %ProgramFiles(x86)%\epm\res\radio_checked_disable.png
  • %ProgramFiles(x86)%\epm\res\radio_checked.png
  • %ProgramFiles(x86)%\epm\res\professinal_enable.png
  • %ProgramFiles(x86)%\epm\res\pie_ring.png
  • %ProgramFiles(x86)%\epm\res\pci_unallocated.png
  • %ProgramFiles(x86)%\epm\res\menu_twitter.png
  • %ProgramFiles(x86)%\epm\res\menu_tech.png
  • %ProgramFiles(x86)%\epm\res\menu_settings.png
  • %ProgramFiles(x86)%\epm\res\menu_pm.png
  • %ProgramFiles(x86)%\epm\res\menu_more.png
  • %ProgramFiles(x86)%\epm\res\menu_help.png
  • %ProgramFiles(x86)%\epm\res\menu_google.png
  • %ProgramFiles(x86)%\epm\res\menu_generate_report.png
  • %ProgramFiles(x86)%\epm\res\menu_fb.png
  • %ProgramFiles(x86)%\epm\res\menu_email.png
  • %ProgramFiles(x86)%\epm\res\menu_check_upgrade.png
  • %ProgramFiles(x86)%\epm\res\menu_about.png
  • %ProgramFiles(x86)%\epm\res\logo_update.png
  • %ProgramFiles(x86)%\epm\res\logo_chkupdate.png
  • %ProgramFiles(x86)%\epm\res\start-logo.png
  • %ProgramFiles(x86)%\epm\res\logocolour_pct.png
  • %ProgramFiles(x86)%\epm\bin\convertfat2ntfs.exe.manifest
  • %ProgramFiles(x86)%\epm\res\title_activate.png
  • %ProgramFiles(x86)%\epm\bin\config.manifest
  • %ProgramFiles(x86)%\epm\bin\common.manifest
  • %ProgramFiles(x86)%\epm\bin\checkversion.manifest
  • %ProgramFiles(x86)%\epm\bin\callbackoperator.manifest
  • %ProgramFiles(x86)%\epm\bin\autoupdate.manifest
  • %ProgramFiles(x86)%\epm\bin\eucfg.bin
  • %ProgramFiles(x86)%\epm\res\48_48_8.ico
  • %ProgramFiles(x86)%\epm\res\192_192_32.ico
  • %ProgramFiles(x86)%\epm\res\yiwo.png
  • %ProgramFiles(x86)%\epm\res\wizard_arrow_disable.png
  • %ProgramFiles(x86)%\epm\res\wizard_arrow.png
  • %ProgramFiles(x86)%\epm\res\warnicon.png
  • %ProgramFiles(x86)%\epm\res\version_yes.png
  • %ProgramFiles(x86)%\epm\res\version_no.png
  • %ProgramFiles(x86)%\epm\res\unlimited_enable.png
  • %ProgramFiles(x86)%\epm\res\undo.png
  • %ProgramFiles(x86)%\epm\res\unconnectserver.png
  • %ProgramFiles(x86)%\epm\res\unallocated_block.png
  • %ProgramFiles(x86)%\epm\res\title_restorewindow.png
  • %ProgramFiles(x86)%\epm\res\title_minimize.png
  • %ProgramFiles(x86)%\epm\res\title_menu.png
  • %ProgramFiles(x86)%\epm\res\title_maximize.png
  • %ProgramFiles(x86)%\epm\res\title_logo.png
  • %ProgramFiles(x86)%\epm\res\title_help.png
  • %ProgramFiles(x86)%\epm\res\title_close.png
  • %ProgramFiles(x86)%\epm\bin\convertfattontfs.manifest
  • %ProgramFiles(x86)%\epm\dc\bin\eclog.log
Deletes the following files
  • %WINDIR%\syswow64\drivers\.sys
Miscellaneous
Searches for the following windows
  • ClassName: '' WindowName: ''
Creates and executes the following
  • '%ProgramFiles(x86)%\epm\hidcon.exe' start.cmd
  • '%ProgramFiles(x86)%\epm\nircmd.exe' wait 2000
  • '%ProgramFiles(x86)%\epm\dc\bin\drvsetup.exe' drv -install
  • '%ProgramFiles(x86)%\epm\nircmd.exe' shortcut "%ProgramFiles(x86)%\epm\bin\Main.exe" "~$folder.desktop$" "EaseUS Partition Master 14.5"
  • '%ProgramFiles(x86)%\epm\bin\main.exe'
  • '%ProgramFiles(x86)%\epm\dc\bin\eucloneserver.exe' 516 528
  • '%WINDIR%\syswow64\cmd.exe' /c start.cmd' (with hidden window)
  • '%ProgramFiles(x86)%\epm\dc\bin\eucloneserver.exe' 516 528' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c start.cmd
  • '<SYSTEM32>\vds.exe'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android