Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Trojan.Siggen18.53493

Added to the Dr.Web virus database: 2022-10-01

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\Software\Classes\openkisclient\shell\open\command] '' = '%ProgramFiles(x86)%\Kingdee\KISCloudClient\client.exe %1'
Sets the following service settings
  • [<HKLM>\System\CurrentControlSet\Services\kisbizsrv] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\kisbizsrv] 'ImagePath' = '%ProgramFiles(x86)%\Kingdee\KISCloudClient\kis_service.exe'
Creates the following services
  • 'kisbizsrv' %ProgramFiles(x86)%\Kingdee\KISCloudClient\kis_service.exe
Modifies file system
Creates the following files
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\msvcr71.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr40.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr4.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr39.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr38.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr37.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr36.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr35.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr34.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr23.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr33.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr31.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr30.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr29.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr28.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr27.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr26.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr25.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr32.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr24.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr5.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc15.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc30.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc28.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc26.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc24.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc22.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc20.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc18.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc17.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr7.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr6.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc13.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc10.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qr_scan_suc.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qr_login2.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qr_login.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qr_invalid.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr9.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr8.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc16.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr22.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr21.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr20.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv6_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv6_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv6_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv6_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv5_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv5_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv5_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv7_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv5_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv4_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv4_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv4_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv40_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv40_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv40_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv40_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv3_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv4_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv7_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv7_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv7_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr11.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr19.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr18.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr17.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr16.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr15.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr14.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr13.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr12.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr10.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv8_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrvfr1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv9_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv9_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv9_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv9_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv8_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv8_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv8_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc32.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc34.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc36.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc40.dat
  • C:\kisnoteprint\kdprint121.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\kiswebprintinst.exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\62axopq5\kisweb´òó¡°²×°°ü[1].exe
  • %WINDIR%\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\kis_service.log
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\ktlicensedll.log
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\upgrade.log
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\ktclient.log
  • C:\kisnoteprint\kfo10.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\restartsv.bat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\msvcp71.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\libeay32.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\msvcr120.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\msvcp120.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\logo.ico
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\5102717_localsrv.jdy.com.pem
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\5102717_localsrv.jdy.com.key
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\liblogcollector.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\mfc71.dll
  • C:\kisnoteprint\kfox.dll
  • C:\kisnoteprint\reg64.reg
  • C:\kisnoteprint\reg32.reg
  • %CommonProgramFiles(x86)%\kingdee\kdprint121.dll
  • %CommonProgramFiles(x86)%\kingdee\kdprint102.dll
  • %CommonProgramFiles(x86)%\kingdee\kdprint.dll
  • %CommonProgramFiles(x86)%\kingdee\kdpdfexport.dll
  • %CommonProgramFiles(x86)%\kingdee\ledger50.ocx
  • %CommonProgramFiles(x86)%\kingdee\kdfu.dll
  • %CommonProgramFiles(x86)%\kingdee\kdf.dll
  • %CommonProgramFiles(x86)%\kingdee\kdnote.ocx
  • %CommonProgramFiles(x86)%\kingdee\kisnoteprint.exe
  • C:\kisnoteprint\kdprint102.dll
  • C:\kisnoteprint\kdprint.dll
  • C:\kisnoteprint\kdpdfexport.dll
  • C:\kisnoteprint\ledger50.ocx
  • C:\kisnoteprint\kdfu.dll
  • C:\kisnoteprint\kdf.dll
  • C:\kisnoteprint\kisnoteprint.exe
  • C:\kisnoteprint\regversion.reg
  • C:\kisnoteprint\copy.bat
  • C:\kisnoteprint\kdnote.ocx
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\libcurl.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\mstscax.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\liccfg.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\failcnn.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\unchecked.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\thumbs.db
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\selected.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc7.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc68.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc66.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc64.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc62.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\unselected.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc60.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc56.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc54.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc52.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc50.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc48.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc46.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc44.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc42.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\rsc58.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\appicon\kisapp1.ico
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\appicon\kisapp2.ico
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\appicon\kisapp3.ico
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\speedservice.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\speedsocket.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\speedsocket64.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\upgradecfg.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\config.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\readme.txt
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\connector.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\client.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cleaner.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\upgrade.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\localim.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\ktlicensedll.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\kis_service.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\deploymentx86.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\connectorex.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\clipper.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\zh-cn\mstscax.dll.mui
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\zh-cn\mstsc.exe.mui
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\zh-cn\aaclient.dll.mui
  • %CommonProgramFiles(x86)%\kingdee\kfo10.dll
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv3_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv3_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv3_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv13_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv13_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv13_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv13_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv12_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv12_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv12_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv12_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\message.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv11_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv11_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv11_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv10_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv10_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv10_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv10_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\min_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\min_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv11_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\min_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv14_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv16_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv19_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv18_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv18_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv18_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv18_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv17_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv17_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv17_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv14_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv14_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv16_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv16_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv16_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv15_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv15_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv15_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv15_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv14_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv17_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\logon.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\information.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\disable_unselected.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_d_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_d_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_d_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_c_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_c_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_c_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_m_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\prxpltlstp.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\prxpltlsti.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\prxpltlstc.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\lzmac.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\ktcloudclientx64.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\ktcloudclient.exe
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\config.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\clouddesktop.rdp
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\cldcentercfg.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\cloudclient\prxpltlsto.ini
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_m_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_m_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\disable_unchecked.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\checked.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\disable_selected.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\disable_checked.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\cmb_push.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\cmb_normal.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\cmb_hover.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\close_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\close_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\close_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_white_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_white_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_white_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_star_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_star_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_star_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_starl_pre.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_starl_nor.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\btn_starl_hot.png
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv19_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv19_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv19_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv1_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv33_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv33_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv33_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv33_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv32_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv32_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv32_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv32_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv34_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv31_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv31_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv31_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv30_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv30_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv30_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv30_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv2_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv2_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv31_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv34_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv34_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv34_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv39_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv39_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv39_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv38_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv38_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv38_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv38_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv37_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv37_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv37_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv37_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv36_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv36_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv36_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv36_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv35_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv35_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv35_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv35_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv2_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv29_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv2_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv29_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv23_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv23_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv23_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv22_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv22_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv22_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv22_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv21_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv23_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv21_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv21_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv20_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv20_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv20_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv20_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv1_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv1_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv1_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv21_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv24_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv24_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv24_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv29_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv29_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv28_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv28_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv28_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv28_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv27_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv27_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv27_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv27_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv26_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv26_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv26_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv26_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv25_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv25_2.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv25_1.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv25_0.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv24_3.dat
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\qrv39_3.dat
  • %CommonProgramFiles(x86)%\kingdee\kfox.dll
Sets the 'hidden' attribute to the following files
  • %ProgramFiles(x86)%\kingdee\kiscloudclient\skinpic\thumbs.db
Deletes the following files
  • %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\62axopq5\kisweb´òó¡°²×°°ü[1].exe
Network activity
Connects to
  • 'ki####.kingdee.com':443
  • 'localhost':49177
  • 'mo#.#mcloud.cn':80
TCP
HTTP GET requests
  • http://mo#.#mcloud.cn/KISWebERP/kispro/print/KISWebґтУЎ°ІЧ°°ь.exe
Other
  • 'ki####.kingdee.com':443
UDP
  • DNS ASK ki####.kingdee.com
  • DNS ASK mo#.#mcloud.cn
Miscellaneous
Searches for the following windows
  • ClassName: 'EDIT' WindowName: ''
Creates and executes the following
  • '%ProgramFiles(x86)%\kingdee\kiscloudclient\client.exe' "pricld"
  • '%ProgramFiles(x86)%\kingdee\kiscloudclient\upgrade.exe' 0
  • '%ProgramFiles(x86)%\kingdee\kiscloudclient\kis_service.exe'
  • '%ProgramFiles(x86)%\kingdee\kiscloudclient\kiswebprintinst.exe'
  • '%WINDIR%\syswow64\sc.exe' create kisbizsrv binPath= "%ProgramFiles(x86)%\Kingdee\KISCloudClient\kis_service.exe" start= auto' (with hidden window)
  • '%WINDIR%\syswow64\sc.exe' start kisbizsrv' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\sc.exe' create kisbizsrv binPath= "%ProgramFiles(x86)%\Kingdee\KISCloudClient\kis_service.exe" start= auto
  • '%WINDIR%\syswow64\sc.exe' start kisbizsrv
  • '%WINDIR%\syswow64\cmd.exe' /c ""C:\KISNotePrint\Copy.bat" "
  • '%WINDIR%\syswow64\regsvr32.exe' /s "%CommonProgramFiles(x86)%\Kingdee\KDNote.ocx"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android