別名:

Trojan:Win32/Skeeyah.A!MTB (Microsoft); GenericRXIP-SG!7AC69BBBB4D4 (McAfee); PUA.Yontoo.C (Symantec); Trojan.Win32.Agent.ahovt (Kaspersky); Troj/MSIL-MCD (Sophos); Trojan.Win32.Generic!BT (Sunbelt)

 プラットフォーム:

Windows

 危険度:
 ダメージ度:
 感染力:
 感染確認数:

  • マルウェアタイプ:
    トロイの木馬型

  • 破壊活動の有無:
    なし

  • 暗号化:
     

  • 感染報告の有無 :
    はい

  概要

マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

  詳細

ファイルサイズ 1,598,417 bytes
タイプ EXE
メモリ常駐 はい
発見日 2019年10月16日

侵入方法

マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

インストール

マルウェアは、以下のプロセスを追加します。

  • %User Profile%\Documents\mwps\mwps.exe
  • %User Profile%\Documents\Windows_Run_Ceneter_SIER\53ab00c120c253c4bf4a14ad8c434aa0f5c67785.exe
  • %User Profile%\Documents\proDM\pdm.exe
  • %User Profile%\Documents\comPM\cpm.exe
  • %User Profile%\Documents\wpas mngr.exe

(註:%User Profile%フォルダは、現在ログオンしているユーザのプロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>" です。)

マルウェアは、以下のフォルダを作成します。

  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_642724477
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_36296686
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_553667532
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_127420562
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1630954822
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_427088991
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_740939286
  • %User Profile%\Documents\Windows_INJ_Center_1IER\FJNGC
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1293764797
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_300510450
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_539485666
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_216477507
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_687337006
  • %User Profile%\Documents\Local Apps dlls_SPDR16
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2028838060
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1197616919
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_113238696
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_188113775
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1071038378
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_314692316
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_104080832
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_134511495
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1616772956
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_972823569
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_22114820
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_441270857
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1258310132
  • %User Profile%\Documents\1722078698_Porfile Logs
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_7932954
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1518558147
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_680246073
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_651882341
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_987005435
  • %User Profile%\Documents\2141234735_ZERT
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1092311177
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1818226576
  • %User Profile%\Documents\Windows_INJ_Center_1IER
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1286673864
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2057201792
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_328874182
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1944805117
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2043019926
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_209386574
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2050110859
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1490194415
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_195204708
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_560758465
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1078129311
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_979914502
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2035928993
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_726757420
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1377797740
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1265401065
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1085220244
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1511467214
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_958641703
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_839154095
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1916441385
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1099402110
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1190525986
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_719666487
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_181022842
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_846245028
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1729169631
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_141602428
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1279582931
  • %User Profile%\Documents\proDM
  • %User Profile%\Documents\comPM
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1750442430
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1909350452
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1504376281
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_321783249
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1106493043
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_874608760
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1923532318
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1736260564
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1384888673
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_120329629
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_842021
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1211798785
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_202295641
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1832408442
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_546576599
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1497285348
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_658973274
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_307601383
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2064292725
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1937714184
  • %User Profile%\Documents\Windows_Run_Ceneter_SIER
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_755121152
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_965732636
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_567849398
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1638045755
  • %User Profile%\Documents\Apps_951550770
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1757533363
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1609682023
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_748030219
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1645136688
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1796953777
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_148693361
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_951550770
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_532394733
  • %User Profile%\Documents\1370706807_AppDLLS
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_335965115
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_733848353
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1525649080
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1930623251
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_673155140
  • %User Profile%\Documents\mwps
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_419998058
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_666064207
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1804044710

(註:%User Profile%フォルダは、現在ログオンしているユーザのプロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>" です。)

自動実行方法

マルウェアは、自身のコピーがWindows起動時に自動実行されるよう以下のレジストリ値を追加します。

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
MPSSPDR16 = "%User Profile%\Documents\mwps\mwps.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
wpasmngr = "%User Profile%\Documents\wpas mngr.exe"

他のシステム変更

マルウェアは、以下のレジストリ値を追加します。

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
Advanced
ShowSuperHidden = "0"

作成活動

マルウェアは、以下のファイルを作成します。

  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_673155140\SJ673155140.sys
  • F:\mail_client.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_755121152\SJ755121152.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2057201792\SJ2057201792.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_846245028\SJ846245028.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_666064207\SJ666064207.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_216477507\SJ216477507.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1638045755\SJ1638045755.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_979914502\SJ979914502.sys
  • %User Profile%\Documents\Windows_INJ_Center_1IER\FJNGC\WinLines.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_104080832\SJ104080832.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_188113775\SJ188113775.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1525649080\SJ1525649080.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_642724477\IF.dll
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_307601383\SJ307601383.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1729169631\SJ1729169631.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_127420562\SJ127420562.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1518558147\SJ1518558147.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_658973274\SJ658973274.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_839154095\SJ839154095.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_321783249\SJ321783249.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1937714184\SJ1937714184.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_427088991\SJ427088991.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_148693361\SJ148693361.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_726757420\SJ726757420.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1909350452\SJ1909350452.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_740939286\SJ740939286.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1923532318\SJ1923532318.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_965732636\SJ965732636.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1944805117\SJ1944805117.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1265401065\SJ1265401065.sys
  • F:\data\WinLines.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2050110859\SJ2050110859.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1286673864\SJ1286673864.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_202295641\SJ202295641.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1190525986\SJ1190525986.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1211798785\SJ1211798785.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1078129311\SJ1078129311.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_441270857\SJ441270857.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_209386574\SJ209386574.sys
  • %user profile%\documents\windows_run_ceneter_sier\{malware file name}.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_951550770\SJ951550770.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_532394733\SJ532394733.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1099402110\SJ1099402110.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1796953777\SJ1796953777.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1490194415\SJ1490194415.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_328874182\SJ328874182.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1804044710\SJ1804044710.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_958641703\SJ958641703.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_22114820\SJ22114820.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1293764797\SJ1293764797.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_419998058\SJ419998058.sys
  • %User Profile%\Documents\comPM\cpm.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1377797740\SJ1377797740.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2064292725\SJ2064292725.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_874608760\SJ874608760.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_842021\SJ842021.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_546576599\SJ546576599.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_300510450\SJ300510450.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1616772956\SJ1616772956.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_113238696\SJ113238696.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_539485666\SJ539485666.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_733848353\SJ733848353.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1279582931\SJ1279582931.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1092311177\SJ1092311177.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_141602428\SJ141602428.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_748030219\SJ748030219.sys
  • %User Profile%\Documents\wpas mngr.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1916441385\SJ1916441385.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1071038378\SJ1071038378.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_687337006\SJ687337006.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_314692316\SJ314692316.sys
  • %AppDataLocal%\GDIPFONTCACHEV1.DAT
  • %User Profile%\Documents\mwps\mwps.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1750442430\SJ1750442430.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1106493043\SJ1106493043.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_7932954\SJ7932954.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2028838060\SJ2028838060.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1384888673\SJ1384888673.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_680246073\SJ680246073.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1258310132\SJ1258310132.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1197616919\SJ1197616919.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1832408442\SJ1832408442.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_553667532\SJ553667532.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1511467214\SJ1511467214.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1645136688\SJ1645136688.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1818226576\SJ1818226576.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1609682023\SJ1609682023.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_567849398\SJ567849398.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_120329629\SJ120329629.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_335965115\SJ335965115.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_36296686\SJ36296686.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_181022842\SJ181022842.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1630954822\SJ1630954822.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_195204708\SJ195204708.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2043019926\SJ2043019926.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1497285348\SJ1497285348.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1736260564\SJ1736260564.sys
  • %User Profile%\Documents\Windows_INJ_Center_1IER\FJNGC\mail_client.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_972823569\SJ972823569.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_651882341\SJ651882341.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_560758465\SJ560758465.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1085220244\SJ1085220244.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2035928993\SJ2035928993.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1930623251\SJ1930623251.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1757533363\SJ1757533363.sys
  • %User Profile%\Documents\proDM\pdm.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1504376281\SJ1504376281.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_134511495\SJ134511495.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_987005435\SJ987005435.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_719666487\SJ719666487.sys

(註:%User Profile%フォルダは、現在ログオンしているユーザのプロファイルフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>" です。. %AppDataLocal%フォルダは、ローカルアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local" です。)

このウイルス情報は、自動解析システムにより作成されました。

  対応方法

対応検索エンジン: 9.850

手順 1

Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。

手順 2

Windowsをセーフモードで再起動します。

[ 詳細 ]

手順 3

「Trojan.MSIL.AUTORUN.A」で検出したファイル名を確認し、そのファイルを終了します。

[ 詳細 ]

  • すべての実行中プロセスが、Windows のタスクマネージャに表示されない場合があります。この場合、"Process Explorer" などのツールを使用しマルウェアのファイルを終了してください。"Process Explorer" については、こちらをご参照下さい。
  • 検出ファイルが、Windows のタスクマネージャまたは "Process Explorer" に表示されるものの、削除できない場合があります。この場合、コンピュータをセーフモードで再起動してください。
    セーフモードについては、こちらをご参照下さい。
  • 検出ファイルがタスクマネージャ上で表示されない場合、次の手順にお進みください。

手順 4

このレジストリ値を削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • MPSSPDR16 = "%User Profile%\Documents\mwps\mwps.exe"
  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • wpasmngr = "%User Profile%\Documents\wpas mngr.exe"
  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
    • ShowSuperHidden = "0"

手順 5

以下のファイルを検索し削除します。

[ 詳細 ]
コンポーネントファイルが隠しファイル属性の場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_673155140\SJ673155140.sys
  • F:\mail_client.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_755121152\SJ755121152.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2057201792\SJ2057201792.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_846245028\SJ846245028.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_666064207\SJ666064207.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_216477507\SJ216477507.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1638045755\SJ1638045755.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_979914502\SJ979914502.sys
  • %User Profile%\Documents\Windows_INJ_Center_1IER\FJNGC\WinLines.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_104080832\SJ104080832.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_188113775\SJ188113775.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1525649080\SJ1525649080.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_642724477\IF.dll
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_307601383\SJ307601383.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1729169631\SJ1729169631.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_127420562\SJ127420562.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1518558147\SJ1518558147.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_658973274\SJ658973274.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_839154095\SJ839154095.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_321783249\SJ321783249.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1937714184\SJ1937714184.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_427088991\SJ427088991.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_148693361\SJ148693361.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_726757420\SJ726757420.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1909350452\SJ1909350452.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_740939286\SJ740939286.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1923532318\SJ1923532318.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_965732636\SJ965732636.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1944805117\SJ1944805117.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1265401065\SJ1265401065.sys
  • F:\data\WinLines.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2050110859\SJ2050110859.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1286673864\SJ1286673864.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_202295641\SJ202295641.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1190525986\SJ1190525986.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1211798785\SJ1211798785.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1078129311\SJ1078129311.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_441270857\SJ441270857.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_209386574\SJ209386574.sys
  • %user profile%\documents\windows_run_ceneter_sier\{malware file name}.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_951550770\SJ951550770.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_532394733\SJ532394733.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1099402110\SJ1099402110.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1796953777\SJ1796953777.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1490194415\SJ1490194415.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_328874182\SJ328874182.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1804044710\SJ1804044710.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_958641703\SJ958641703.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_22114820\SJ22114820.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1293764797\SJ1293764797.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_419998058\SJ419998058.sys
  • %User Profile%\Documents\comPM\cpm.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1377797740\SJ1377797740.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2064292725\SJ2064292725.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_874608760\SJ874608760.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_842021\SJ842021.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_546576599\SJ546576599.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_300510450\SJ300510450.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1616772956\SJ1616772956.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_113238696\SJ113238696.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_539485666\SJ539485666.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_733848353\SJ733848353.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1279582931\SJ1279582931.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1092311177\SJ1092311177.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_141602428\SJ141602428.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_748030219\SJ748030219.sys
  • %User Profile%\Documents\wpas mngr.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1916441385\SJ1916441385.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1071038378\SJ1071038378.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_687337006\SJ687337006.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_314692316\SJ314692316.sys
  • %AppDataLocal%\GDIPFONTCACHEV1.DAT
  • %User Profile%\Documents\mwps\mwps.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1750442430\SJ1750442430.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1106493043\SJ1106493043.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_7932954\SJ7932954.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2028838060\SJ2028838060.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1384888673\SJ1384888673.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_680246073\SJ680246073.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1258310132\SJ1258310132.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1197616919\SJ1197616919.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1832408442\SJ1832408442.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_553667532\SJ553667532.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1511467214\SJ1511467214.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1645136688\SJ1645136688.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1818226576\SJ1818226576.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1609682023\SJ1609682023.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_567849398\SJ567849398.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_120329629\SJ120329629.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_335965115\SJ335965115.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_36296686\SJ36296686.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_181022842\SJ181022842.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1630954822\SJ1630954822.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_195204708\SJ195204708.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2043019926\SJ2043019926.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1497285348\SJ1497285348.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1736260564\SJ1736260564.sys
  • %User Profile%\Documents\Windows_INJ_Center_1IER\FJNGC\mail_client.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_972823569\SJ972823569.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_651882341\SJ651882341.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_560758465\SJ560758465.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1085220244\SJ1085220244.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2035928993\SJ2035928993.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1930623251\SJ1930623251.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1757533363\SJ1757533363.sys
  • %User Profile%\Documents\proDM\pdm.exe
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1504376281\SJ1504376281.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_134511495\SJ134511495.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_987005435\SJ987005435.sys
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_719666487\SJ719666487.sys

手順 6

以下のフォルダを検索し削除します。

[ 詳細 ]
フォルダが隠しフォルダ属性に設定されている場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_642724477
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_36296686
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_553667532
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_127420562
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1630954822
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_427088991
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_740939286
  • %User Profile%\Documents\Windows_INJ_Center_1IER\FJNGC
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1293764797
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_300510450
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_539485666
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_216477507
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_687337006
  • %User Profile%\Documents\Local Apps dlls_SPDR16
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2028838060
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1197616919
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_113238696
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_188113775
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1071038378
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_314692316
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_104080832
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_134511495
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1616772956
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_972823569
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_22114820
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_441270857
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1258310132
  • %User Profile%\Documents\1722078698_Porfile Logs
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_7932954
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1518558147
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_680246073
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_651882341
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_987005435
  • %User Profile%\Documents\2141234735_ZERT
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1092311177
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1818226576
  • %User Profile%\Documents\Windows_INJ_Center_1IER
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1286673864
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2057201792
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_328874182
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1944805117
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2043019926
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_209386574
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2050110859
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1490194415
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_195204708
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_560758465
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1078129311
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_979914502
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2035928993
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_726757420
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1377797740
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1265401065
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1085220244
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1511467214
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_958641703
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_839154095
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1916441385
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1099402110
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1190525986
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_719666487
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_181022842
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_846245028
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1729169631
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_141602428
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1279582931
  • %User Profile%\Documents\proDM
  • %User Profile%\Documents\comPM
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1750442430
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1909350452
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1504376281
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_321783249
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1106493043
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_874608760
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1923532318
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1736260564
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1384888673
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_120329629
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_842021
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1211798785
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_202295641
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1832408442
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_546576599
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1497285348
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_658973274
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_307601383
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_2064292725
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1937714184
  • %User Profile%\Documents\Windows_Run_Ceneter_SIER
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_755121152
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_965732636
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_567849398
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1638045755
  • %User Profile%\Documents\Apps_951550770
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1757533363
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1609682023
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_748030219
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1645136688
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1796953777
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_148693361
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_951550770
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_532394733
  • %User Profile%\Documents\1370706807_AppDLLS
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_335965115
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_733848353
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1525649080
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1930623251
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_673155140
  • %User Profile%\Documents\mwps
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_419998058
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_666064207
  • %User Profile%\Documents\Local Apps dlls_SPDR16\SF_1804044710

手順 7

コンピュータを通常モードで再起動し、最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、「Trojan.MSIL.AUTORUN.A」と検出したファイルの検索を実行してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。


ご利用はいかがでしたか? アンケートにご協力ください