Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.MulDrop16.32626

Added to the Dr.Web virus database: 2021-03-20

Virus description added:

Technical Information

Modifies file system
Creates the following files
  • %WINDIR%\scripttemp.ini
  • %WINDIR%\_tempheukms03201804021088\pic\5-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\6-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\6-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\7-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\7-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\8-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\8-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\9-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\9-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\about-close1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\4-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\5-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\about-close2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\about2.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\about3.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back1.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back2.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back3.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back4.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back5.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\close.png
  • %WINDIR%\_tempheukms03201804021088\pic\color.png
  • %WINDIR%\_tempheukms03201804021088\pic\down.png
  • %WINDIR%\_tempheukms03201804021088\pic\about-close3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\about1.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\4-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\3-3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\3-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\11-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\11-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\12-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\12-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\13-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\13-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\13-3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\14-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\14-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\15-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\15-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\10-3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\16-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\17-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\17-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\18-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\18-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\19-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\2-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\2-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\2-3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\20-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\20-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\3-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\16-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\logo.png
  • %WINDIR%\_tempheukms03201804021088\pic\over.png
  • %WINDIR%\_tempheukms03201804021088\scriptdir.ini
  • %WINDIR%\_tempheukms03201804021088\pic\renewal.jpg
  • %WINDIR%\_tempheukms03201804021088\setupcomplete.data
  • %WINDIR%\_tempheukms03201804021088\svctrigger.xml
  • %WINDIR%\_tempheukms03201804021088\kms-client.exe
  • %WINDIR%\_tempheukms03201804021088\kms-server.exe
  • %WINDIR%\_tempheukms03201804021088\kms.exe
  • %WINDIR%\_tempheukms03201804021088\kms_x64.exe
  • %WINDIR%\_tempheukms03201804021088\oem\bootrest.exe
  • %WINDIR%\_tempheukms03201804021088\oem\bootsect.exe
  • %WINDIR%\_tempheukms03201804021088\oem\oemdumpnet35.exe
  • %WINDIR%\_tempheukms03201804021088\oem\oemdumpnet40.exe
  • %WINDIR%\_tempheukms03201804021088\pic0\windows.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\zanzhu.ico
  • %WINDIR%\_tempheukms03201804021088\oem\uefi.exe
  • %WINDIR%\_tempheukms03201804021088\x64\msvcr100.dll
  • %WINDIR%\_tempheukms03201804021088\x64\secopatcher.dll
  • %WINDIR%\_tempheukms03201804021088\x64\setacl.exe
  • %WINDIR%\_tempheukms03201804021088\x64\sppextcomobjhook.dll
  • %WINDIR%\_tempheukms03201804021088\x64\sppextcomobjhookarm64.dll
  • %WINDIR%\_tempheukms03201804021088\x86\cleanospp.exe
  • %WINDIR%\_tempheukms03201804021088\x86\msvcr100.dll
  • %WINDIR%\_tempheukms03201804021088\x86\secopatcher.dll
  • %WINDIR%\_tempheukms03201804021088\x86\setacl.exe
  • %WINDIR%\_tempheukms03201804021088\x86\sppextcomobjhook.dll
  • %WINDIR%\_tempheukms03201804021088\produkey.exe
  • %WINDIR%\_tempheukms03201804021088\x64\cleanospp.exe
  • %WINDIR%\_tempheukms03201804021088\pic0\ver.ico
  • %WINDIR%\_tempheukms03201804021088\pic0\uninst.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\uninst-tra.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\skin.png
  • %WINDIR%\_tempheukms03201804021088\pic\smart-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\smart-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\tab1.png
  • %WINDIR%\_tempheukms03201804021088\pic\tab2.png
  • %WINDIR%\_tempheukms03201804021088\pic\tab3.png
  • %WINDIR%\_tempheukms03201804021088\pic\tab4.png
  • %WINDIR%\_tempheukms03201804021088\pic\tab5.png
  • %WINDIR%\_tempheukms03201804021088\pic0\backup-en.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\backup-tra.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\backup.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\setting.png
  • %WINDIR%\_tempheukms03201804021088\pic0\ewm_wx.jpg
  • %WINDIR%\_tempheukms03201804021088\pic0\head.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\inst-en.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\inst-tra.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\inst.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\left.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\office.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\restore-en.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\restore-tra.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\restore.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\shuoming.jpg
  • %WINDIR%\_tempheukms03201804021088\pic0\uninst-en.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\ewm_zfb.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\10-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\min.png
  • %WINDIR%\_tempheukms03201804021088\pic\10-1.bmp
  • %WINDIR%\_tempheukms03201804021088\oem\cert\krftwy.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\dell.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\dsgltd.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\equus.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\exc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\exo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\foundr.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\fsc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\fuj.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\gbt.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\gensys.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\datate.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\dealin.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\haier.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hedy06.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\higrad.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hp.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hpqoem.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hspw07.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hyrslp.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\ibm.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\itinfo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\jetway.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\jooyon.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hasee.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hclinf.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\czc011.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\creaas.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\cmscom.xrm-ms
  • %WINDIR%\splashlogo.jpg
  • %TEMP%\aut47ba.tmp
  • %WINDIR%\_tempheukms03201804021088\kmsmini.7z
  • %TEMP%\aut4903.tmp
  • %WINDIR%\_tempheukms03201804021088\digital.7z
  • %TEMP%\aut49af.tmp
  • %WINDIR%\_tempheukms03201804021088\cert.7z
  • %TEMP%\aut49ef.tmp
  • %WINDIR%\_tempheukms03201804021088\digitallicence.7z
  • %TEMP%\aut4a1f.tmp
  • %WINDIR%\_tempheukms03201804021088\7z.exe
  • %TEMP%\aut471d.tmp
  • %WINDIR%\_tempheukms03201804021088\heu_configuration.ini
  • %WINDIR%\_tempheukms03201804021088\heu_set.ini
  • %WINDIR%\_tempheukms03201804021088\oem\cert\acrsys.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\alware.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\aquari.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\atcomp.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\bekopc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\benq.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\bgh.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\casper.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\ccelnf.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\cgwall.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\heu_kms_renewal.xml
  • %WINDIR%\_tempheukms03201804021088\oem\cert\k.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\lanix1.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\pic\1-1.bmp
  • %WINDIR%\_tempheukms03201804021088\oem\cert\lenovo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\toscpl.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\toshib.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tosinv.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tosqci.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\trigem.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\vestel.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\vscaio.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\wortma.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\xplore.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\yutc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tosasu.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tosbyd.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\_asus_.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr1
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr2
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr34
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr5
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr6
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr7
  • %WINDIR%\_tempheukms03201804021088\office2010ospp\ospp.vbs
  • %WINDIR%\_tempheukms03201804021088\office2010ospp\slerror.xml
  • %WINDIR%\_tempheukms03201804021088\otherofficeospp\ospp.vbs
  • %WINDIR%\_tempheukms03201804021088\otherofficeospp\slerror.xml
  • %WINDIR%\_tempheukms03201804021088\oem\emulateslic
  • %WINDIR%\_tempheukms03201804021088\oem\emulateslic.bin
  • %WINDIR%\_tempheukms03201804021088\oem\cert\thtfpc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\thoa21.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tarox1.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\login2.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\matbio.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\matech.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\medion.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\mitac.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\msi_nb.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\navihb.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\nec.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\nokia.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\oegrou.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\olipro.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\lge.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\olislp.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\philco.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\positi.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\prdgt.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\qbexco.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\quanmx.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\rm.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\seccsd.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\sony.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\stinfo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\synnex.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\sysmax.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\onkyo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\pic\1-2.bmp
  • %WINDIR%\_tempheukms03201804021088\heu22_debug.txt
Sets the 'hidden' attribute to the following files
  • %WINDIR%\_tempheukms03201804021088\heu_kms_renewal.xml
  • %WINDIR%\_tempheukms03201804021088\pic\8-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\9-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\9-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\about-close1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\about-close2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\about-close3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\about1.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\about2.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\about3.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back1.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back2.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back3.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back4.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\back5.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\close.png
  • %WINDIR%\_tempheukms03201804021088\pic\color.png
  • %WINDIR%\_tempheukms03201804021088\pic\down.png
  • %WINDIR%\_tempheukms03201804021088\pic\logo.png
  • %WINDIR%\_tempheukms03201804021088\pic\min.png
  • %WINDIR%\_tempheukms03201804021088\pic\over.png
  • %WINDIR%\_tempheukms03201804021088\pic\renewal.jpg
  • %WINDIR%\_tempheukms03201804021088\pic\setting.png
  • %WINDIR%\_tempheukms03201804021088\pic\skin.png
  • %WINDIR%\_tempheukms03201804021088\pic\8-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\smart-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\7-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\6-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\14-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\15-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\15-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\16-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\16-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\17-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\17-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\18-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\18-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\19-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\2-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\2-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\2-3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\20-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\20-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\3-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\3-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\3-3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\4-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\4-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\5-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\5-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\6-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\7-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\smart-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\tab1.png
  • %WINDIR%\_tempheukms03201804021088\pic\tab2.png
  • %WINDIR%\_tempheukms03201804021088\kms_x64.exe
  • %WINDIR%\_tempheukms03201804021088\oem\bootrest.exe
  • %WINDIR%\_tempheukms03201804021088\oem\bootsect.exe
  • %WINDIR%\_tempheukms03201804021088\oem\oemdumpnet35.exe
  • %WINDIR%\_tempheukms03201804021088\oem\oemdumpnet40.exe
  • %WINDIR%\_tempheukms03201804021088\oem\uefi.exe
  • %WINDIR%\_tempheukms03201804021088\produkey.exe
  • %WINDIR%\_tempheukms03201804021088\x64\cleanospp.exe
  • %WINDIR%\_tempheukms03201804021088\x64\msvcr100.dll
  • %WINDIR%\_tempheukms03201804021088\x64\secopatcher.dll
  • %WINDIR%\_tempheukms03201804021088\kmsmini.7z
  • %WINDIR%\_tempheukms03201804021088\x64\setacl.exe
  • %WINDIR%\_tempheukms03201804021088\x86\cleanospp.exe
  • %WINDIR%\_tempheukms03201804021088\x86\msvcr100.dll
  • %WINDIR%\_tempheukms03201804021088\x86\secopatcher.dll
  • %WINDIR%\_tempheukms03201804021088\x86\setacl.exe
  • %WINDIR%\_tempheukms03201804021088\x86\sppextcomobjhook.dll
  • %WINDIR%\_tempheukms03201804021088\7z.exe
  • %WINDIR%\_tempheukms03201804021088\cert.7z
  • %WINDIR%\_tempheukms03201804021088\digital.7z
  • %WINDIR%\_tempheukms03201804021088\digitallicence.7z
  • %WINDIR%\_tempheukms03201804021088\heu_configuration.ini
  • %WINDIR%\_tempheukms03201804021088\kms-server.exe
  • %WINDIR%\_tempheukms03201804021088\kms.exe
  • %WINDIR%\_tempheukms03201804021088\kms-client.exe
  • %WINDIR%\_tempheukms03201804021088\svctrigger.xml
  • %WINDIR%\_tempheukms03201804021088\setupcomplete.data
  • %WINDIR%\_tempheukms03201804021088\pic\tab4.png
  • %WINDIR%\_tempheukms03201804021088\pic\tab5.png
  • %WINDIR%\_tempheukms03201804021088\pic0\backup-en.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\backup-tra.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\backup.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\ewm_wx.jpg
  • %WINDIR%\_tempheukms03201804021088\pic0\ewm_zfb.jpg
  • %WINDIR%\_tempheukms03201804021088\pic0\head.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\inst-en.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\inst-tra.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\14-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\left.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\inst.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\restore-en.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\restore-tra.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\restore.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\shuoming.jpg
  • %WINDIR%\_tempheukms03201804021088\pic0\uninst-en.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\uninst-tra.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\uninst.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\ver.ico
  • %WINDIR%\_tempheukms03201804021088\pic0\windows.bmp
  • %WINDIR%\_tempheukms03201804021088\pic0\zanzhu.ico
  • %WINDIR%\_tempheukms03201804021088\pic\tab3.png
  • %WINDIR%\_tempheukms03201804021088\pic0\office.bmp
  • %WINDIR%\_tempheukms03201804021088\x64\sppextcomobjhook.dll
  • %WINDIR%\_tempheukms03201804021088\pic\13-3.bmp
  • %WINDIR%\_tempheukms03201804021088\otherofficeospp\ospp.vbs
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hasee.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hclinf.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hedy06.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\higrad.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hp.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hpqoem.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hspw07.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\hyrslp.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\ibm.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\itinfo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\jetway.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\jooyon.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\k.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\krftwy.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\lanix1.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\lenovo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\lge.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\login2.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\matbio.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\matech.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\medion.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\mitac.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\msi_nb.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\haier.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\navihb.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\gensys.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\fuj.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\heu_set.ini
  • %WINDIR%\_tempheukms03201804021088\oem\cert\acrsys.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\alware.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\aquari.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\atcomp.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\bekopc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\benq.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\bgh.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\casper.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\ccelnf.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\cgwall.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\cmscom.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\creaas.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\czc011.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\datate.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\dealin.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\dell.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\dsgltd.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\equus.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\exc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\exo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\foundr.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\fsc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\gbt.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\nec.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\nokia.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\oegrou.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\_asus_.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\emulateslic
  • %WINDIR%\_tempheukms03201804021088\oem\emulateslic.bin
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr1
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr2
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr34
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr5
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr6
  • %WINDIR%\_tempheukms03201804021088\oem\gr1dr7
  • %WINDIR%\_tempheukms03201804021088\office2010ospp\ospp.vbs
  • %WINDIR%\_tempheukms03201804021088\pic\13-1.bmp
  • %WINDIR%\_tempheukms03201804021088\office2010ospp\slerror.xml
  • %WINDIR%\_tempheukms03201804021088\otherofficeospp\slerror.xml
  • %WINDIR%\_tempheukms03201804021088\pic\1-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\1-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\10-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\10-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\10-3.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\11-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\11-2.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\12-1.bmp
  • %WINDIR%\_tempheukms03201804021088\pic\12-2.bmp
  • %WINDIR%\_tempheukms03201804021088\oem\cert\xplore.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\yutc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\wortma.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\vscaio.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\vestel.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\olislp.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\onkyo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\philco.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\positi.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\prdgt.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\qbexco.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\quanmx.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\rm.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\seccsd.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\sony.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\pic\13-2.bmp
  • %WINDIR%\_tempheukms03201804021088\oem\cert\synnex.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\stinfo.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tarox1.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\thoa21.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\thtfpc.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tosasu.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tosbyd.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\toscpl.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\toshib.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tosinv.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\tosqci.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\trigem.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\olipro.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\oem\cert\sysmax.xrm-ms
  • %WINDIR%\_tempheukms03201804021088\scriptdir.ini
Deletes the following files
  • %TEMP%\aut471d.tmp
  • %TEMP%\aut47ba.tmp
  • %TEMP%\aut4903.tmp
  • %TEMP%\aut49af.tmp
  • %TEMP%\aut49ef.tmp
  • %TEMP%\aut4a1f.tmp
Network activity
UDP
  • DNS ASK ba##u.com
Miscellaneous
Creates and executes the following
  • '%WINDIR%\_tempheukms03201804021088\7z.exe' x %WINDIR%\_tempheukms03201804021088\KMSmini.7z -y -o%WINDIR%\_tempheukms03201804021088
  • '%WINDIR%\_tempheukms03201804021088\kms_x64.exe'
  • '%WINDIR%\syswow64\cmd.exe' /c echo [Temp] >%windir%\ScriptTemp.ini' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c echo Temp=_tempheukms03201804021088 >>%windir%\ScriptTemp.ini' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c if exist "%WINDIR%\Sysnative\reg.exe" (echo 1)' (with hidden window)
  • '%WINDIR%\_tempheukms03201804021088\7z.exe' x %WINDIR%\_tempheukms03201804021088\KMSmini.7z -y -o%WINDIR%\_tempheukms03201804021088' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c set "Path=%SystemRoot%;%WINDIR%\Sysnative;%WINDIR%\Sysnative\Wbem;%SystemRoot\Sysnative\WindowsPowerShell\v1.0\" & echo [Direction] >%windir%\_tempheukms03201804021088\ScriptDir.ini' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c set "Path=%SystemRoot%;%WINDIR%\Sysnative;%WINDIR%\Sysnative\Wbem;%SystemRoot\Sysnative\WindowsPowerShell\v1.0\" & echo Dir=<Current directory> >>%windir%\_tempheukms03201804021088\ScriptDir...' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c set "Path=%SystemRoot%;%WINDIR%\Sysnative;%WINDIR%\Sysnative\Wbem;%SystemRoot\Sysnative\WindowsPowerShell\v1.0\" & echo Name=<File name>.exe >>%windir%\_tempheukms03201804021088\ScriptDir.in...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c if exist "%WINDIR%\Sysnative\reg.exe" (echo 1)' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c ver' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c echo [Temp] >%windir%\ScriptTemp.ini
  • '%WINDIR%\syswow64\cmd.exe' /c echo Temp=_tempheukms03201804021088 >>%windir%\ScriptTemp.ini
  • '%WINDIR%\syswow64\cmd.exe' /c if exist "%WINDIR%\Sysnative\reg.exe" (echo 1)
  • '%WINDIR%\syswow64\cmd.exe' /c set "Path=%SystemRoot%;%WINDIR%\Sysnative;%WINDIR%\Sysnative\Wbem;%SystemRoot\Sysnative\WindowsPowerShell\v1.0\" & echo [Direction] >%windir%\_tempheukms03201804021088\ScriptDir.ini
  • '%WINDIR%\syswow64\cmd.exe' /c set "Path=%SystemRoot%;%WINDIR%\Sysnative;%WINDIR%\Sysnative\Wbem;%SystemRoot\Sysnative\WindowsPowerShell\v1.0\" & echo Dir=<Current directory> >>%windir%\_tempheukms03201804021088\ScriptDir...
  • '%WINDIR%\syswow64\cmd.exe' /c set "Path=%SystemRoot%;%WINDIR%\Sysnative;%WINDIR%\Sysnative\Wbem;%SystemRoot\Sysnative\WindowsPowerShell\v1.0\" & echo Name=<File name>.exe >>%windir%\_tempheukms03201804021088\ScriptDir.in...
  • '<SYSTEM32>\cmd.exe' /c if exist "%WINDIR%\Sysnative\reg.exe" (echo 1)
  • '<SYSTEM32>\cmd.exe' /c ver

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android