Bibliothèque
Ma bibliothèque

Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.DownLoad3.49132

Added to the Dr.Web virus database: 2017-12-07

Virus description added:

Technical Information

To ensure autorun and distribution
Sets the following service settings
  • [HKLM\System\CurrentControlSet\Services\uploadmgr] 'Start' = '00000002'
  • [HKLM\System\CurrentControlSet\Services\uploadmgr] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
  • [HKLM\SYSTEM\CurrentControlSet\Services\uploadmgr\Parameters] 'ServiceDll' = '<SYSTEM32>\1847\uploadmgr'
Creates the following services
  • 'uploadmgr' <SYSTEM32>\svchost.exe -k netsvcs
Modifies file system
Creates the following files
  • %TEMP%\7zipsfx.000\1001.exe
  • %ProgramFiles%\tencent\appstore\default\res\messagebox\sysmessagebox_warningfile.gft
  • %ProgramFiles%\tencent\appstore\default\res\messagebox\sysmessagebox_questionfile.gft
  • %ProgramFiles%\tencent\appstore\default\res\messagebox\sysmessagebox_inforfile.gft
  • %ProgramFiles%\tencent\appstore\default\res\messagebox\sysmessagebox_errorfile.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\mune_select_bkg.bmp
  • %ProgramFiles%\tencent\appstore\default\res\menu\menu_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menu_cutling.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menu_check.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menu_bkg_board.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menu_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menu_arrow_up.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menu_arrow_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menu_arrow.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menuitemex_seperatordraw.bmp
  • %ProgramFiles%\tencent\appstore\default\res\menu\menuitemex_deltexture.bmp
  • %ProgramFiles%\tencent\appstore\default\res\menu\menuitemex_delhightlighttexture.bmp
  • %ProgramFiles%\tencent\appstore\default\res\menu\menuitemex_checktexture.bmp
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_bar_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\menuitemex_arrowtexture.bmp
  • %ProgramFiles%\tencent\appstore\default\res\menu\menuex_background.bmp
  • %ProgramFiles%\tencent\appstore\default\res\radiobutton\radiobtn_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\progress\progress_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_bar_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowup_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowup_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowup_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowright_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowright_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowright_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowleft_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowleft_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowleft_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowdown_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowdown_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_arrowdown_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\all_horzscrollbar_bkgcross.gft
  • %ProgramFiles%\tencent\appstore\default\res\radiobutton\radiobtn_tick_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\radiobutton\radiobtn_tick_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\radiobutton\radiobtn_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\all_combobox_highlightbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\progress\progress_foreground.gft
  • %ProgramFiles%\tencent\appstore\default\res\common\all_down_arrow.bmp
  • %ProgramFiles%\tencent\appstore\default\res\common\all_close_highlight.bmp
  • %ProgramFiles%\tencent\appstore\default\res\common\all_arrowbtn_down.bmp
  • %ProgramFiles%\tencent\appstore\default\res\combobox\login_inputbtn_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\login_inputbtn_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\login_inputbtn_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\inputbtn_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\inputbtn_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\inputbtn_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\inputbtn_disable.png
  • %ProgramFiles%\tencent\appstore\default\res\combobox\combobox_normalbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\combobox_buttonpusheddraw.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\combobox_buttonnormaldraw.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\combobox_buttonnormaldraw.bmp
  • %ProgramFiles%\tencent\appstore\default\res\combobox\combobox_buttonhighlightdraw.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\comboboxerasebutton_push.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\comboboxerasebutton_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\combobox\comboboxerasebutton_hover.gft
  • %ProgramFiles%\tencent\appstore\default\res\listctrl\all_listctrl_titleline.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\close_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\menu\close_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\common\all_logo16-xp.ico
  • %ProgramFiles%\tencent\appstore\default\res\common\all_close_normal.bmp
  • %ProgramFiles%\tencent\appstore\default\res\listctrl\all_listctrl_titlehightlightbg.gft
  • %ProgramFiles%\tencent\appstore\default\res\listctrl\all_listctrl_titledownbg.gft
  • %ProgramFiles%\tencent\appstore\default\res\listctrl\all_listctrl_titlebg.gft
  • %ProgramFiles%\tencent\appstore\default\res\listctrl\all_listctrl_arrowup.gft
  • %ProgramFiles%\tencent\appstore\default\res\listctrl\all_listctrl_arrowdown.gft
  • %ProgramFiles%\tencent\appstore\default\res\frameborder\framebordereffect_normaldraw.gft
  • %ProgramFiles%\tencent\appstore\default\res\frameborder\framebordereffect_mousedowndraw.gft
  • %ProgramFiles%\tencent\appstore\default\res\frameborder\all_btn_white-side.gft
  • %ProgramFiles%\tencent\appstore\default\res\frameborder\all_btn_light.gft
  • %ProgramFiles%\tencent\appstore\default\res\flash\error.gft
  • %ProgramFiles%\tencent\appstore\default\res\config\theme.xml
  • %ProgramFiles%\tencent\appstore\default\res\config\gfconfigagent.xml
  • %ProgramFiles%\tencent\appstore\default\res\common\loading.png
  • %ProgramFiles%\tencent\appstore\default\res\common\all_selecteditem_itembghighlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\common\all_logo32-xp.ico
  • %ProgramFiles%\tencent\appstore\default\res\common\all_logo32-2000.ico
  • %ProgramFiles%\tencent\appstore\default\res\common\all_logo16-2000.ico
  • %ProgramFiles%\tencent\appstore\default\res\combobox\all_selecteditem_itembghighlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_bar_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\spincontrol\spin_normal_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\all_window_sizegripfile.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\all_window_nostatusbar_windowbkg.bmp
  • %ProgramFiles%\tencent\appstore\default\res\window\all_white_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\all_inside_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\all_inside02_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\allout_close_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\allout_close_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\allout_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\aio_white_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\treectrl\unexpand.gft
  • %ProgramFiles%\tencent\appstore\default\res\treectrl\expand.gft
  • %ProgramFiles%\tencent\appstore\default\res\toolbar\all_arrow_right.gft
  • %ProgramFiles%\tencent\appstore\default\res\toolbar\all_arrow_out.gft
  • %ProgramFiles%\tencent\appstore\default\res\toolbar\all_arrow_left.gft
  • %ProgramFiles%\tencent\appstore\default\res\tipwindow\tips_white_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\tipwindow\tips_png_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\tipwindow\tips_light_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\tabctrl_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\tabctrl_round_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\window\all_window_windowbkg.bmp
  • %ProgramFiles%\tencent\appstore\default\res\window\all_window_windowbkg.gft
  • %TEMP%\appstore\appstore_webctr\data_1
  • %TEMP%\appstore\appstore_webctr\data_0
  • %TEMP%\appstore\appstore_webctr\index
  • %TEMP%\appstore\appstore_webctr\cookies
  • %TEMP%\etilqs_pgwzfyr1eh579kd
  • %TEMP%\appstore\appstore_webctr\cookies-journal
  • <SYSTEM32>\1847\uploadmgr
  • %LOCALAPPDATA%\f2e9e.dll
  • %ALLUSERSPROFILE%\ddratup
  • %ProgramFiles%\tencent\appstore\default\res\button\all_iconbutton_pushedbackground.gft
  • %ProgramFiles%\tencent\appstore\uninst.exe
  • %APPDATA%\microsoft\windows\start menu\programs\ìúñ¶èí¼þ\óîï·öððä\ð¶ôøóîï·öððä.lnk
  • %ProgramFiles%\tencent\appstore\default\xtml\window\gf.window.xml
  • %ProgramFiles%\tencent\appstore\default\xtml\window\gf.window.lua
  • %ProgramFiles%\tencent\appstore\default\version.xml
  • %ProgramFiles%\tencent\appstore\default\typedef\extratypedef.xml
  • %ProgramFiles%\tencent\appstore\default\typedef\basictypedef.xml
  • %ProgramFiles%\tencent\appstore\default\res\window\main_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_down_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\tabbutton_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\tabbutton_round_adjustcolor_seperator.gft
  • %ProgramFiles%\tencent\appstore\default\res\spincontrol\spin_highlight_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\slider\slider_foregroundv.gft
  • %ProgramFiles%\tencent\appstore\default\res\slider\slider_foreground.gft
  • %ProgramFiles%\tencent\appstore\default\res\slider\slider_dragbackgroundv.gft
  • %ProgramFiles%\tencent\appstore\default\res\slider\slider_dragbackground.gft
  • %ProgramFiles%\tencent\appstore\default\res\slider\slider_backgroundv.gft
  • %ProgramFiles%\tencent\appstore\default\res\slider\slider_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_top_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_top_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_top_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_horz_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_horzbar_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_horzbar_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_horzbar_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_down_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\scrollbar\scrollbar_down_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\spincontrol\spin_highlight_up.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\tabbutton_round_adjustcolor_unpushedhighlightbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\spincontrol\spin_normal_up.gft
  • %ProgramFiles%\tencent\appstore\default\res\spincontrol\spin_pushed_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\spincontrol\spin_pushed_up.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\tabbutton_check.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\all_tabbutton_sharp_pushedpushedbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\all_tabbutton_round_pushedpushedbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\allbtn_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_restore_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_restore_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_restore_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_mini_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_mini_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_mini_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_max_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_max_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_max_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_close_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_close_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\sysbutton\btn_close_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\tabctrl\tabbutton_cutline.gft
  • %ProgramFiles%\tencent\appstore\default\res\checkbutton\halfcheckbox_tick_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\checkbutton\halfcheckbox_tick_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\checkbutton\checkbox_tick_normal.gft
  • %ProgramFiles%\tencent\appstore\bin\arkiostub.dll
  • %ProgramFiles%\tencent\appstore\bin\arkimage.dll
  • %ProgramFiles%\tencent\appstore\bin\arkgraphic.dll
  • %ProgramFiles%\tencent\appstore\bin\arkfs.dll
  • %ProgramFiles%\tencent\appstore\bin\ssleay32.dll
  • %ProgramFiles%\tencent\appstore\bin\libuv.dll
  • %ProgramFiles%\tencent\appstore\bin\arkhttpclient.dll
  • %APPDATA%\microsoft\windows\start menu\programs\ìúñ¶èí¼þ\óîï·öððä\óîï·öððä.lnk
  • %ProgramFiles%\tencent\appstore\bin\appstore.exe
  • %ProgramFiles%\tencent\appstore\appstore.tpc
  • %ProgramFiles%\tencent\appstore\appstore\xtml\appstore.xml
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\feedback_bg.gft
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\updating.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\update.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\new.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\finish.png
  • %ProgramFiles%\tencent\appstore\bin\asynctask.dll
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\downloading.gif
  • %ProgramFiles%\tencent\appstore\bin\webctrl.dll
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\top-bar.gft
  • %ProgramFiles%\tencent\appstore\bin\tinyxml.dll
  • %ProgramFiles%\tencent\appstore\bin\sqlite.dll
  • %ProgramFiles%\tencent\appstore\bin\qqexternal.exe
  • %ProgramFiles%\tencent\appstore\bin\processsession.dll
  • %ProgramFiles%\tencent\appstore\bin\minibrowser_qzone_shell.dll
  • %ProgramFiles%\tencent\appstore\bin\lua.dll
  • %ProgramFiles%\tencent\appstore\bin\locales\zh-cn.pak
  • %ProgramFiles%\tencent\appstore\bin\locales\en-us.pak
  • %ProgramFiles%\tencent\appstore\bin\libtcmalloc.dll
  • %ProgramFiles%\tencent\appstore\bin\libpng.dll
  • %ProgramFiles%\tencent\appstore\bin\libjpegturbo.dll
  • %ProgramFiles%\tencent\appstore\bin\libimagequant.dll
  • %ProgramFiles%\tencent\appstore\bin\libexpat.dll
  • %ProgramFiles%\tencent\appstore\bin\libeay32.dll
  • %ProgramFiles%\tencent\appstore\bin\libcef3.dll
  • %ProgramFiles%\tencent\appstore\bin\icudt.dll
  • %ProgramFiles%\tencent\appstore\bin\gf.dll
  • %ProgramFiles%\tencent\appstore\bin\common.dll
  • %ProgramFiles%\tencent\appstore\bin\cefsubprocess.dll
  • %ProgramFiles%\tencent\appstore\bin\ffmpegsumo.dll
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\restore-press.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\app_icon_48.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\feedback_close.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\pull_press.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\pull_normal.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\pull_hover.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\about-close.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\about_logo.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\userlogo_normal.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\userlogo_hover.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\about_bg.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\red_point.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\new_version.png
  • %ProgramFiles%\tencent\appstore\appstore\gf-config.xml
  • %TEMP%\nsg1cf3.tmp\system.dll
  • %TEMP%\nsg1cf3.tmp\appstoreplugin.dll
  • %TEMP%\nsg1cf3.tmp\findprocdll.dll
  • %TEMP%\7zipsfx.000\appstoreupdate_1.3.544.exe
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\app_icon_32.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\tool-bar.png
  • %ProgramFiles%\tencent\appstore\bin\xgraphic32.dll
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\app_icon_16.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\restore-normal.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\restore-hover.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\min-press.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\min-normal.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\min-hover.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\max-press.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\max-normal.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\max-hover.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\closetip-press.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\closetip-normal.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\closetip-hover.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\close-press.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\close-normal.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\close-hover.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\app_icon_16.ico
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\app_icon_96.png
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\app_icon_96.ico
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\app_icon_48.ico
  • %ProgramFiles%\tencent\appstore\appstore\res\appstore\app_icon_40.png
  • %ProgramFiles%\tencent\appstore\bin\arkipc.dll
  • %ProgramFiles%\tencent\appstore\bin\ximage.dll
  • %ProgramFiles%\tencent\appstore\default\res\calendar\calendar_bkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\cameratoolbar_btndown.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\send_buttonbackground_normal.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\send_buttonbackground_highlight.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\rightbtn_normal.png
  • %ProgramFiles%\tencent\appstore\default\res\button\rightbtn_highlight.png
  • %ProgramFiles%\tencent\appstore\default\res\button\rightbtn_focus.png
  • %ProgramFiles%\tencent\appstore\default\res\button\rightbtn_down.png
  • %ProgramFiles%\tencent\appstore\default\res\button\leftbtn_normal.png
  • %ProgramFiles%\tencent\appstore\default\res\button\leftbtn_highlight.png
  • %ProgramFiles%\tencent\appstore\default\res\button\leftbtn_focus.png
  • %ProgramFiles%\tencent\appstore\default\res\button\leftbtn_down.png
  • %ProgramFiles%\tencent\appstore\default\res\button\faceedittipbtn_selected.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\faceedittipbtn_selected.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\defaultbuttonbackground_background.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\cameratoolbar_btnnormal.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\cameratoolbar_btnhover.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\cameratoolbar_btnhover.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\btn_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\calendar\close_button_hightlightbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\calendar\close_button_normalbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\calendar\close_button_pushedbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\calendar\help_button_hightlightbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\checkbutton\checkbox_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\checkbutton\checkbox_hightlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\calendar\preyear_button_pushedbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\preyear_button_normalbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\preyear_button_hightlightbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\premonth_button_pushedbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\premonth_button_normalbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\premonth_button_hightlightbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\nextyear_button_pushedbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\nextyear_button_normalbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\nextyear_button_hightlightbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\nextmonth_button_pushedbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\nextmonth_button_normalbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\nextmonth_button_hightlightbkg.png
  • %ProgramFiles%\tencent\appstore\default\res\calendar\help_button_pushedbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\calendar\help_button_normalbkg.gft
  • %ProgramFiles%\tencent\appstore\default\res\checkbutton\checkbox_tick_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\cameratoolbar_btndown.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\btn_highlight.gft
  • %ProgramFiles%\tencent\appstore\bin\zlib.dll
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\tips_close_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\bubbletiptr_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\bubbletiptl_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\bubbletiprt_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\bubbletiprb_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\bubbletiplt_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\bubbletiplb_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\bubbletipbr_background.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\bubbletipbl_background.gft
  • %ProgramFiles%\tencent\appstore\default\i18n\stringstate.xml
  • %ProgramFiles%\tencent\appstore\default\i18n\config.xml
  • %ProgramFiles%\tencent\appstore\default\i18n\2052\gfstringbundle.xml
  • %ProgramFiles%\tencent\appstore\default\i18n\1033\gfstringbundle.xml
  • %ProgramFiles%\tencent\appstore\default\i18n\1028\gfstringbundle.xml
  • %ProgramFiles%\tencent\appstore\default\common.xml
  • %ProgramFiles%\tencent\appstore\bin\bugreport.exe
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\tips_close_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\aio_bluebar_close.gft
  • %ProgramFiles%\tencent\appstore\default\res\bubbletip\tips_close_mouseover.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\allbtn_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\btn_focus.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\allbtn_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\btn_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\btn2_normal.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\btn2_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\btn2_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\arrow_up.png
  • %ProgramFiles%\tencent\appstore\default\res\button\arrow_down.png
  • %ProgramFiles%\tencent\appstore\default\res\button\all_textbutton_pushedbackground.gft
  • %ALLUSERSPROFILE%\res.dat
  • %TEMP%\appstore\appstore_webctr\data_2
  • %ProgramFiles%\tencent\appstore\default\res\button\all_iconbutton_highlightbackground.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\all_button_pushedaction_sb1_background_t0.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\all_buttonbackground_foreground.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\all_buttonbackground_background.bmp
  • %ProgramFiles%\tencent\appstore\default\res\button\allbtn_right_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\allbtn_right_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\allbtn_left_highlight.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\allbtn_left_down.gft
  • %ProgramFiles%\tencent\appstore\default\res\button\all_textbutton_highlightbackground.gft
  • %TEMP%\appstore\appstore_webctr\data_3
Deletes the following files
  • %TEMP%\nsg1cf3.tmp\appstoreplugin.dll
  • %TEMP%\nsg1cf3.tmp\findprocdll.dll
  • %TEMP%\nsg1cf3.tmp\system.dll
  • %TEMP%\7zipsfx.000\1001.exe
  • %TEMP%\7zipsfx.000\appstoreupdate_1.3.544.exe
Moves the following files
  • from %LOCALAPPDATA%\f2e9e.dll to <SYSTEM32>\1847\uploadmgr.dll
Network activity
Connects to
  • '12#.#17.238.230':9818
  • '<LOCALNET>.51.5':0
  • 'ap####.qzone.qq.com':80
  • 'ap####.qzone.qq.com':443
  • 'ga##.#zone.qq.com':443
  • 'qz####tyle.gtimg.cn':443
TCP
HTTP POST requests
  • http://ap####.qzone.qq.com/cgi-bin/apphub/qzone_game_report
Other
  • 'ap####.qzone.qq.com':443
  • 'ga##.#zone.qq.com':443
  • 'qz####tyle.gtimg.cn':443
UDP
  • DNS ASK ap####.qzone.qq.com
  • DNS ASK ga##.#zone.qq.com
  • DNS ASK qz####tyle.gtimg.cn
Miscellaneous
Creates and executes the following
  • '%TEMP%\7zipsfx.000\appstoreupdate_1.3.544.exe'
  • '%ProgramFiles%\tencent\appstore\bin\appstore.exe'
  • '%TEMP%\7zipsfx.000\1001.exe'
  • '%ProgramFiles%\tencent\appstore\bin\qqexternal.exe' /load=CefSubProcess.dll --high-dpi-support=1 --type=renderer --disable-gpu --in-process-plugins --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --product-version=AppStore/1.3.544 ...
Executes the following
  • '<SYSTEM32>\rundll32.exe' shell32.dll,#268CNM360 "%TEMP%\..\F2E9E.dll"
  • '<SYSTEM32>\rundll32.exe' shell32.dll,#268CNM360 "%TEMP%\..\F2E9E.dll"' (with hidden window)

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android