Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.StartPage1.47475

Added to the Dr.Web virus database: 2017-11-24

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Clients\StartMenuInternet\2345Explorer.exe\shell\open\command] '' = '%ProgramFiles%\2345Explorer\2345Explorer.exe'
  • [<HKLM>\SOFTWARE\Classes\2345ExplorerHTML\Shell\open\command] '' = '"%ProgramFiles%\2345Explorer\2345Explorer.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\HTTP\shell\open\command] '' = '"%ProgramFiles%\2345Explorer\2345Explorer.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\https\shell\open\command] '' = '"%ProgramFiles%\2345Explorer\2345Explorer.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\file\shell\open\command] '' = '"%ProgramFiles%\2345Explorer\2345Explorer.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\mhtmlfile\shell\open\command] '' = '"%ProgramFiles%\2345Explorer\2345Explorer.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\htmlfile\shell\open\command] '' = '"%ProgramFiles%\2345Explorer\2345Explorer.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IE.HTTP\shell\open\command] '' = '"%ProgramFiles%\2345Explorer\2345Explorer.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IE.HTTPS\shell\open\command] '' = '"%ProgramFiles%\2345Explorer\2345Explorer.exe" "%1"'
Malicious functions:
Injects code into
the following system processes:
  • %WINDIR%\Explorer.EXE
Modifies file system:
Creates the following files:
  • %TEMP%\nsq2.tmp
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_xduote.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_wwiki.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_wsoso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_wbaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_vyouku.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_vtudou.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_vsoso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_vgoogle.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_vbaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_gjyjo.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_soso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_none.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_msoso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_mgoogle.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_mbaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_isoso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_igoogle.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_ibaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_gtaobao.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_gpaipai.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_sogou.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_google.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_xshooter.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_google.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_sogou.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_none.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_msoso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_mgoogle.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_mbaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_isoso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_igoogle.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_ibaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_gtaobao.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_xxunlei.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_xverycd.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_gjyjo.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_gjingdong.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_gdangdang.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_dgoogle.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_dbaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_bing.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_baidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_youdao.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_yahoo.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_gpaipai.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_gjingdong.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_gdangdang.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_dgoogle.png
  • %ProgramFiles%\2345Explorer\StartPage\images\home\baidu_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\home\2345_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\error\btn.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\error\404_2.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\error\404_1.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_soso.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_sohu.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_sogo.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\home\fenghuang_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_sina.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_google.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_fenghuang.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_baidu.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_2345.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_163.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\title_end.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\title_5.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\title_4.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\title_3.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\wico_qq.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\home\game_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\home\dongman_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\home\sina_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_dbaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_bigicon_google.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_bing.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_icon_baidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\informantCenter\popA.png
  • %ProgramFiles%\2345Explorer\StartPage\images\informantCenter\closeA.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_button_bg3.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_button_bg2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_button_bg1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_bigicon_soso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_bigicon_sogou.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_bigicon_baidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\home\sohu_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_bg2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main_search_bg1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\main.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\incognito\bgrx.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\ie8up\btn.png
  • %ProgramFiles%\2345Explorer\StartPage\images\ie8up\bg.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\home\weibo_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\home\tv_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\home\taobao_big.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_soso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_vbaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_vgoogle.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_vsoso.png
  • %APPDATA%\2345Explorer\Users\Default\AliasUrl.data
  • %APPDATA%\2345Explorer\Users\Default\AliasUrl.data-journal
  • %APPDATA%\2345Explorer\2345Explorer.hzv
  • %ProgramFiles%\2345Explorer\Uninstall.exe
  • %APPDATA%\2345Explorer\Users\Default\SystemUrl.data
  • %APPDATA%\2345Explorer\FavIcon\F2A7BED2A1035F9E4EC022B3ECA481A8.ico.jpg
  • %APPDATA%\2345Explorer\FavIcon\A4C4A052651124668E8F829A3AA6D63C.ico.jpg
  • %APPDATA%\2345Explorer\FavIcon\8FDEAD446A8D607C20207D38D669E349.ico.jpg
  • %APPDATA%\2345Explorer\FavIcon\85131C29C8F7B398A345BD7F1A51DAB1.ico.jpg
  • %APPDATA%\2345Explorer\Users\Default\CrashUrl.data-journal
  • %APPDATA%\2345Explorer\FavIcon\81C6AF03AC3E2B181DD99A3C1AFD1AA3.ico.jpg
  • %APPDATA%\2345Explorer\FavIcon\3D6A8AC8F2013B0D7A1EA53076E96320.ico.jpg
  • %APPDATA%\2345Explorer\FavIcon\1860F34853BBC50F66BF81B679989830.ico.jpg
  • %APPDATA%\2345Explorer\FavIcon\taskmanager.ico
  • %APPDATA%\2345Explorer\FavIcon\recovery.ico
  • %APPDATA%\2345Explorer\FavIcon\private.ico
  • %APPDATA%\2345Explorer\FavIcon\home.ico
  • %APPDATA%\2345Explorer\FavIcon\default_page.ico
  • %APPDATA%\2345Explorer\FavIcon\F2A7BED2A1035F9E4EC022B3ECA481A8.ico
  • %APPDATA%\2345Explorer\FavIcon\A4C4A052651124668E8F829A3AA6D63C.ico
  • %APPDATA%\2345Explorer\FavIcon\6E086A7049DD129DF69051413AC6AB3A.ico.jpg
  • %APPDATA%\2345Explorer\Users\Default\CrashUrl.data
  • %APPDATA%\2345Explorer\Users\Default\StartPageConfig.data-journal
  • %APPDATA%\2345Explorer\Users\Default\StartPageConfig.data
  • %TEMP%\2345Explorer\RT~7.tmp
  • %APPDATA%\Microsoft\Internet Explorer\Quick Launch\2345智能浏览器.lnk
  • %HOMEPATH%\Desktop\2345智能浏览器.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\2345智能浏览器\卸载2345智能浏览器.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\2345智能浏览器\2345智能浏览器.lnk
  • %HOMEPATH%\Start Menu\Programs\2345智能浏览器\卸载2345智能浏览器.lnk
  • %HOMEPATH%\Start Menu\Programs\2345智能浏览器\2345智能浏览器.lnk
  • %HOMEPATH%\Start Menu\2345智能浏览器.lnk
  • %TEMP%\2345Explorer\RT~6.tmp
  • %TEMP%\2345Explorer\RT~5.tmp
  • %APPDATA%\2345Explorer\Users\Default\FavoritesUpdate.data
  • %TEMP%\2345Explorer\RT~4.tmp
  • %APPDATA%\2345Explorer\Users\Default\OnlineFav.data
  • %APPDATA%\2345Explorer\Users\Default\FormData.data
  • %APPDATA%\2345Explorer\Users\Default\Default.cfg
  • %APPDATA%\2345Explorer\Users\Default\Download.data
  • %APPDATA%\2345Explorer\Users\Default\Download.data-journal
  • %APPDATA%\2345Explorer\Users\Default\History.data
  • %APPDATA%\2345Explorer\Users\Default\History.data-journal
  • %APPDATA%\2345Explorer\Users\Default\SmartUrl.data
  • %APPDATA%\2345Explorer\Users\Default\SmartUrl.data-journal
  • %APPDATA%\2345Explorer\FavIcon\8FDEAD446A8D607C20207D38D669E349.ico
  • %APPDATA%\2345Explorer\FavIcon\81C6AF03AC3E2B181DD99A3C1AFD1AA3.ico
  • %APPDATA%\2345Explorer\FavIcon\85131C29C8F7B398A345BD7F1A51DAB1.ico
  • %APPDATA%\2345Explorer\FavIcon\6E086A7049DD129DF69051413AC6AB3A.ico
  • %ProgramFiles%\2345Explorer\StartPage\js\move.js
  • %ProgramFiles%\2345Explorer\StartPage\js\jquery.loadmask.js
  • %ProgramFiles%\2345Explorer\StartPage\js\index.js
  • %ProgramFiles%\2345Explorer\StartPage\js\coral_search.js
  • %ProgramFiles%\2345Explorer\StartPage\js\coral_se.js
  • %ProgramFiles%\2345Explorer\StartPage\js\coral_myfav.js
  • %ProgramFiles%\2345Explorer\StartPage\js\coral_lib_min.js
  • %ProgramFiles%\2345Explorer\StartPage\js\coral_commom.js
  • %ProgramFiles%\2345Explorer\StartPage\js\coral_click.js
  • %ProgramFiles%\2345Explorer\StartPage\js\png.js
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_youdao.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_xxunlei.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_xverycd.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_xshooter.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_xduote.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_wwiki.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_wsoso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_wbaidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_vyouku.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_vtudou.png
  • %ProgramFiles%\2345Explorer\StartPage\images\search\main_search_logo_yahoo.png
  • %ProgramFiles%\2345Explorer\Config\FavIcon\1860F34853BBC50F66BF81B679989830.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\3D6A8AC8F2013B0D7A1EA53076E96320.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\6E086A7049DD129DF69051413AC6AB3A.ico
  • %APPDATA%\2345Explorer\FavIcon\3D6A8AC8F2013B0D7A1EA53076E96320.ico
  • %APPDATA%\2345Explorer\FavIcon\1860F34853BBC50F66BF81B679989830.ico
  • %ProgramFiles%\2345Explorer\Config\Users\Default\SystemUrl.data
  • %ProgramFiles%\2345Explorer\Config\FavIcon\F2A7BED2A1035F9E4EC022B3ECA481A8.ico.jpg
  • %ProgramFiles%\2345Explorer\Config\FavIcon\A4C4A052651124668E8F829A3AA6D63C.ico.jpg
  • %ProgramFiles%\2345Explorer\Config\FavIcon\8FDEAD446A8D607C20207D38D669E349.ico.jpg
  • %ProgramFiles%\2345Explorer\Config\FavIcon\85131C29C8F7B398A345BD7F1A51DAB1.ico.jpg
  • %ProgramFiles%\2345Explorer\Config\FavIcon\81C6AF03AC3E2B181DD99A3C1AFD1AA3.ico.jpg
  • %ProgramFiles%\2345Explorer\Config\FavIcon\6E086A7049DD129DF69051413AC6AB3A.ico.jpg
  • %ProgramFiles%\2345Explorer\Config\FavIcon\3D6A8AC8F2013B0D7A1EA53076E96320.ico.jpg
  • %ProgramFiles%\2345Explorer\Config\FavIcon\1860F34853BBC50F66BF81B679989830.ico.jpg
  • %ProgramFiles%\2345Explorer\Config\FavIcon\taskmanager.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\recovery.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\private.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\home.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\default_page.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\F2A7BED2A1035F9E4EC022B3ECA481A8.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\A4C4A052651124668E8F829A3AA6D63C.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\8FDEAD446A8D607C20207D38D669E349.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\85131C29C8F7B398A345BD7F1A51DAB1.ico
  • %ProgramFiles%\2345Explorer\Config\FavIcon\81C6AF03AC3E2B181DD99A3C1AFD1AA3.ico
  • %TEMP%\2345Explorer\RT~8.tmp
  • %ProgramFiles%\2345Explorer\StartPage\images\title_2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\title_1.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\switch_widbar_icon2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\btn_next.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\btn_down_hot.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\btn_down.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\btn_com.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\box_bg_r.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\box_bg_l.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\box_bg.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\blank.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\banner.jpg
  • %ProgramFiles%\2345Explorer\StartPage\fancybox\jquery.fancybox-1.3.4.css
  • %ProgramFiles%\2345Explorer\StartPage\images\all_search_icon_baidu.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_pre_04.bmp
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_pre_03.bmp
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_pre_02.bmp
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_pre_01.bmp
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_Default.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_04.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_03.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_02.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_01.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\Wallpaper_pre_Default.bmp
  • %ProgramFiles%\2345Explorer\StartPage\fancybox\jquery.fancybox-1.3.4.js
  • %ProgramFiles%\2345Explorer\StartPage\images\btn_start.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_title2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\hot.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_ie.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_btn5.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_btn4.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_btn3.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_btn2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_btn1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_title5.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_title4.png
  • %ProgramFiles%\2345Explorer\StartPage\images\close_tab2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\close_tab.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_title1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_line.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_bottom.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_bg.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_bg.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_bg.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\gradient_top.png
  • %ProgramFiles%\2345Explorer\StartPage\images\gradient_bottom.png
  • %ProgramFiles%\2345Explorer\StartPage\images\gradient_bg.png
  • %ProgramFiles%\2345Explorer\StartPage\images\guide_box_title3.png
  • %ProgramFiles%\2345Explorer\StartPage\css\jquery.loadmask.css
  • %ProgramFiles%\2345Explorer\StartPage\css\incognito.css
  • %ProgramFiles%\2345Explorer\StartPage\css\home.css
  • %ProgramFiles%\2345Explorer\2345智能浏览器免责声明.txt
  • %ProgramFiles%\2345Explorer\lang\CoralLang_chs.dll
  • %ProgramFiles%\2345Explorer\Addon\Capture.addon
  • %ProgramFiles%\2345Explorer\Addon\VideoAdBlock.addon
  • %ProgramFiles%\2345Explorer\2345ExplorerReg.exe
  • %ProgramFiles%\2345Explorer\CoralHtmlWnd.dll
  • %ProgramFiles%\2345Explorer\CoralExtract.dll
  • %ProgramFiles%\2345Explorer\StartPage.dll
  • %ProgramFiles%\2345Explorer\msvcr80.dll
  • %ProgramFiles%\2345Explorer\CoralRender.dll
  • %ProgramFiles%\2345Explorer\CoralUI.dll
  • %ProgramFiles%\2345Explorer\CoralTrident.dll
  • %ProgramFiles%\2345Explorer\CoralDownload.dll
  • %ProgramFiles%\2345Explorer\CoralDb.dll
  • %ProgramFiles%\2345Explorer\Coral.dll
  • %ProgramFiles%\2345Explorer\CoralApp.dll
  • %ProgramFiles%\2345Explorer\2345Explorer.exe
  • %TEMP%\nsg3.tmp\FileInfo.dll
  • %TEMP%\nsg3.tmp\System.dll
  • %ProgramFiles%\2345Explorer\CoralUpdate.dll
  • %ProgramFiles%\2345Explorer\atl71.dll
  • %ProgramFiles%\2345Explorer\Microsoft.VC80.CRT.manifest
  • %ProgramFiles%\2345Explorer\CoralUI2.dll
  • %ProgramFiles%\2345Explorer\StartPage\css\css.css
  • %ProgramFiles%\2345Explorer\StartPage\guide3.htm
  • %ProgramFiles%\2345Explorer\StartPage\search.htm
  • %ProgramFiles%\2345Explorer\StartPage\recovery.htm
  • %ProgramFiles%\2345Explorer\StartPage\pop_edit.html
  • %ProgramFiles%\2345Explorer\StartPage\malice.htm
  • %ProgramFiles%\2345Explorer\StartPage\index.htm
  • %ProgramFiles%\2345Explorer\StartPage\incognito.htm
  • %ProgramFiles%\2345Explorer\StartPage\ie8up.htm
  • %ProgramFiles%\2345Explorer\StartPage\guide5.htm
  • %ProgramFiles%\2345Explorer\StartPage\guide4.htm
  • %ProgramFiles%\2345Explorer\StartPage\guide2.htm
  • %ProgramFiles%\2345Explorer\Skins\Coral.dui
  • %ProgramFiles%\2345Explorer\StartPage\guide1.htm
  • %ProgramFiles%\2345Explorer\StartPage\guide.htm
  • %ProgramFiles%\2345Explorer\StartPage\coral404.htm
  • %ProgramFiles%\2345Explorer\StartPage\blank.htm
  • %ProgramFiles%\2345Explorer\Skins\Coral.xml
  • %ProgramFiles%\2345Explorer\Skins\Pink.skn
  • %ProgramFiles%\2345Explorer\Skins\Growth.skn
  • %ProgramFiles%\2345Explorer\Skins\CoralIE.skn
  • %ProgramFiles%\2345Explorer\Skins\Coral.skn
  • %ProgramFiles%\2345Explorer\StartPage\images\ico_360.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\ico_ie.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\ico_sogo.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\ico_tt.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_tit.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_icon4_2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_icon4.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_icon3.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_icon2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_icon1.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_icon.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_button3.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_button2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_tit2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_button.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_edit_bg1.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_edit_bg.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_edit_background2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_edit_background.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_close2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_close.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_background.png
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_background.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\page_white.png
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_edit_bg2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_tit_hover.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_list_tit_hover2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_preview_but.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\switch_bj.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_5r.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_5.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_4r.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_4l.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_4.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_3r.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_3l.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_3.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_2r.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_2l.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_1l.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\step_1.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\skin_4.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\skin_3.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\skin_2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\skin_1.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\quan.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\preview_plus.bmp
  • %ProgramFiles%\2345Explorer\StartPage\images\popup_dialog_preview_but2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\page_bg.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_xl_background1.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_xl_background2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_xl_arrow.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_content_error.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_bottombar_report3.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_bottombar_report2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_bottombar_report.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\logo.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\loading.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\list_bg.png
  • %ProgramFiles%\2345Explorer\StartPage\images\img_tag2.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\img_tag1.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_bar_bj.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\img_icon.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\icon_novel.png
  • %ProgramFiles%\2345Explorer\StartPage\images\icon_news.png
  • %ProgramFiles%\2345Explorer\StartPage\images\icon_music.png
  • %ProgramFiles%\2345Explorer\StartPage\images\icon_movie.png
  • %ProgramFiles%\2345Explorer\StartPage\images\icon_inquiry.png
  • %ProgramFiles%\2345Explorer\StartPage\images\icon_goods.png
  • %ProgramFiles%\2345Explorer\StartPage\images\icon_game.png
  • %ProgramFiles%\2345Explorer\StartPage\images\iconMap.png
  • %ProgramFiles%\2345Explorer\StartPage\images\iconBg.png
  • %ProgramFiles%\2345Explorer\StartPage\images\img_fav.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_bar_blank.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_bar_blank_hover.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_bar_edit.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_button_bg3.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_button_bg2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_button_bg1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_bigicon_soso.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_bigicon_sogou.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_bigicon_google.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_bigicon_baidu.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_bg_search.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_bg2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_search_bg1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_item_loading.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_item_hover1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_item_add.jpg
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_item2_hover1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_item22.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_item2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_item1.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_bar_remove_hover.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_bar_remove2.png
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_bar_remove.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\main_grid_bar_edit_hover.gif
  • %ProgramFiles%\2345Explorer\StartPage\images\switch_combar_icon1.gif
  • %APPDATA%\2345Explorer\Coral.sts
Deletes the following files:
  • %APPDATA%\2345Explorer\Users\Default\AliasUrl.data-journal
  • %APPDATA%\2345Explorer\Users\Default\CrashUrl.data-journal
  • %APPDATA%\2345Explorer\Users\Default\StartPageConfig.data-journal
  • %APPDATA%\2345Explorer\Users\Default\SmartUrl.data-journal
  • %APPDATA%\2345Explorer\Users\Default\History.data-journal
  • %APPDATA%\2345Explorer\Users\Default\Download.data-journal
  • %TEMP%\nsg3.tmp\FileInfo.dll
  • %TEMP%\nsg3.tmp\System.dll
Moves the following files:
  • from %TEMP%\2345Explorer\RT~4.tmp to %APPDATA%\2345Explorer\Users\Default\FormData.data
  • from %TEMP%\2345Explorer\RT~5.tmp to %APPDATA%\2345Explorer\Users\Default\FavoritesUpdate.data
  • from %TEMP%\2345Explorer\RT~6.tmp to %APPDATA%\2345Explorer\Users\Default\Default.cfg
  • from %TEMP%\2345Explorer\RT~7.tmp to %APPDATA%\2345Explorer\Users\Default\Default.cfg
  • from %TEMP%\2345Explorer\RT~8.tmp to %APPDATA%\2345Explorer\Users\Default\Default.cfg
Substitutes the following files:
  • %APPDATA%\2345Explorer\Users\Default\AliasUrl.data-journal
  • %APPDATA%\2345Explorer\Users\Default\CrashUrl.data-journal
  • %APPDATA%\2345Explorer\Users\Default\SmartUrl.data-journal
  • %APPDATA%\2345Explorer\Users\Default\History.data-journal
  • %APPDATA%\2345Explorer\Users\Default\Download.data-journal
Network activity:
Connects to:
  • 'up####.ie.2345.com':80
TCP:
HTTP POST requests:
  • http://up####.ie.2345.com/index.php
UDP:
  • DNS ASK up####.ie.2345.com
Miscellaneous:
Searches for the following windows:
  • ClassName: 'SHELLDLL_DefView' WindowName: ''
  • ClassName: 'SysListView32' WindowName: ''
  • ClassName: '{69CAC4F0-46B3-46B3-8559-AD2C340A26D5}' WindowName: ''
Creates and executes the following:
  • '%ProgramFiles%\2345Explorer\2345Explorer.exe' --config=destory_desktop_bubble
  • '%ProgramFiles%\2345Explorer\2345Explorer.exe' --update=install
  • '%ProgramFiles%\2345Explorer\2345Explorer.exe' --update=send_install
  • '%ProgramFiles%\2345Explorer\2345Explorer.exe' --config=set_default_browser
  • '%ProgramFiles%\2345Explorer\2345Explorer.exe' --config=desktop_bubble

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android