Generic Dropper.vq
Generic Dropper.vq is a malicious computer trojan that may enable an attacker gain remote access to an affected computer system. Generic Dropper.vq can execute a variety of malicious operations on a compromised computer, which involve data theft, keystroke logging and modification or deletion of files. It is recommended removing Generic Dropper.vq as quickly as possible upon detection from your computer system to keep your PC safe.
File System Modifications
- The following files were created in the system:
# File Name 1 %AllUsersProfile%\123.bat 2 %AllUsersProfile%\lanmao.hiv 3 %AllUsersProfile%\lmm.txt 4 %CommonAppData%\lanmao.exe 5 %System%\D001.exe 6 %System%\drivers\tcpz-x86d.sys 7 %System%\E001.exe 8 %System%\JATE.exe 9 %System%\tcpwakglib.exe 10 %Windir%\svchost.exe 11 %Windir%\Temp\126375.dll 12 %Windir%\Temp\30453.dll
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecFilter{1e6963ff-bfe3-4498-a94d-c0e5982071d7}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecFilter{4de0233b-3368-4763-aba8-6b9002734dc9}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecFilter{e788aac0-0854-464d-b3fe-e99614eaa5c8}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{d12ee85a-e3c4-468e-aadf-fbb0ad46d83b}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{27339a81-2984-4141-82aa-bc8c14fc0844}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{4fb58661-b6d2-47d3-bc0b-42b4b9cddbde}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{724bfd81-4eda-44b5-99fb-ee1b7c6dcf7a}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{74f6ef6c-5bcd-426b-8e42-ca194feeac0f}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{667693ee-9ca9-4bf2-9d10-1b9b7c45057f}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{b40c384e-0a44-4b46-b14b-c194fa0e5e8f}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{e63e091a-cef1-4508-9e43-613f41485229}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecPolicy{6344fe9c-c79b-444d-a90f-b589162416d5}HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CQTMASSEHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CQTMASSE\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DAVNLWLBHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DAVNLWLB\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RCMDSVCHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RCMDSVC\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TCPZHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TCPZ\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WAKLSVC\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WAKLSVC\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINRAR_SERVERHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINRAR_SERVER\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WMDMPMSN\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CQtMasseHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CQtMasse\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TCPZHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TCPZ\ParametersHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TCPZ\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WaklSvcHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WaklSvc\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRar ServerHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRar Server\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\daVNLWlBHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\daVNLWlB\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rcmdsvcHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rcmdsvc\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CQTMASSEHKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CQTMASSE\0000\Enum\Root\LEGACY_WMDMPMSN
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.