Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.Siggen33.58671

Added to the Dr.Web virus database: 2026-08-28

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'MicrosoftEdgeUpdate' = '"%APPDATA%\Microsoft\WindowsUpdate\wuauserv.exe" --silent'
  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'WindowsUpdateHelper' = '%APPDATA%\Microsoft\WindowsUpdate\wuauserv.exe'
Sets the following service settings
  • [HKLM\SYSTEM\CurrentControlSet\Services\WindowsUpdateAssistant] 'Start' = '00000002'
  • [HKLM\SYSTEM\CurrentControlSet\Services\WindowsUpdateAssistant] 'ImagePath' = '%APPDATA%\Microsoft\WindowsUpdate\wuauserv.exe --silent'
Creates the following services
  • 'WindowsUpdateAssistant' %APPDATA%\Microsoft\WindowsUpdate\wuauserv.exe --silent
  • 'WindowsUpdateAssistant' <SYSTEM32>\config\systemprofile\AppData\Roaming\Microsoft\WindowsUpdate\wuauserv.exe --silent
Malicious functions
Terminates or attempts to terminate
the following system processes:
  • <SYSTEM32>\tasklist.exe
Reads files which store third party applications passwords
  • %LOCALAPPDATA%\google\chrome\user data\default\cookies
  • %LOCALAPPDATA%\google\chrome\user data\default\login data
  • %LOCALAPPDATA%\microsoft\edge\user data\default\login data
  • %LOCALAPPDATA%\microsoft\edge\user data\default\web data
Modifies file system
Creates the following files
  • %TEMP%\_mei00000bb82\crypto\cipher\_arc4.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_salsa20.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_chacha20.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_pkcs1_decode.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_aes.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_aesni.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_arc2.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_blowfish.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_cast.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_cbc.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_cfb.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_ctr.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_des.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_des3.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_ecb.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_eksblowfish.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_ocb.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_ofb.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_blake2b.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_blake2s.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_md2.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_md4.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_md5.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_ripemd160.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha1.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha224.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha256.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha384.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha512.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_ghash_clmul.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_ghash_portable.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_keccak.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_poly1305.pyd
  • %TEMP%\_mei00000bb82\crypto\math\_modexp.pyd
  • %TEMP%\_mei00000bb82\crypto\protocol\_scrypt.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_curve25519.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_curve448.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_ec_ws.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_ed25519.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_ed448.pyd
  • %TEMP%\_mei00000bb82\crypto\util\_cpuid_c.pyd
  • %TEMP%\_mei00000bb82\crypto\util\_strxor.pyd
  • %TEMP%\_mei00000bb82\pil\_avif.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_imaging.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_imagingcms.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_imagingmath.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_imagingtk.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_webp.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\vcruntime140.dll
  • %TEMP%\_mei00000bb82\vcruntime140_1.dll
  • %TEMP%\_mei00000bb82\_bz2.pyd
  • %TEMP%\_mei00000bb82\_ctypes.pyd
  • %TEMP%\_mei00000bb82\_decimal.pyd
  • %TEMP%\_mei00000bb82\_elementtree.pyd
  • %TEMP%\_mei00000bb82\_hashlib.pyd
  • %TEMP%\_mei00000bb82\_lzma.pyd
  • %TEMP%\_mei00000bb82\_multiprocessing.pyd
  • %TEMP%\_mei00000bb82\_queue.pyd
  • %TEMP%\_mei00000bb82\_socket.pyd
  • %TEMP%\_mei00000bb82\_sqlite3.pyd
  • %TEMP%\_mei00000bb82\_ssl.pyd
  • %TEMP%\_mei00000bb82\_uuid.pyd
  • %TEMP%\_mei00000bb82\_wmi.pyd
  • %TEMP%\_mei00000bb82\base_library.zip
  • %TEMP%\_mei00000bb82\certifi\cacert.pem
  • %TEMP%\_mei00000bb82\charset_normalizer\cd.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\charset_normalizer\md.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\discord_badge_farmer.exe
  • %TEMP%\_mei00000bb82\libcrypto-3.dll
  • %TEMP%\_mei00000bb82\libffi-8.dll
  • %TEMP%\_mei00000bb82\libssl-3.dll
  • %TEMP%\_mei00000bb82\psutil\_psutil_windows.pyd
  • %TEMP%\_mei00000bb82\pyexpat.pyd
  • %TEMP%\_mei00000bb82\python3.dll
  • %TEMP%\_mei00000bb82\python312.dll
  • %TEMP%\_mei00000bb82\pywin32_system32\pywintypes312.dll
  • %TEMP%\_mei00000bb82\select.pyd
  • %TEMP%\_mei00000bb82\setuptools\_vendor\jaraco\text\lorem ipsum.txt
  • %TEMP%\_mei00000bb82\sqlite3.dll
  • %TEMP%\_mei00000bb82\unicodedata.pyd
  • %TEMP%\_mei00000bb82\win32\win32crypt.pyd
  • %TEMP%\_mei00000bb82\win32\win32gui.pyd
  • %TEMP%\3npep4uw
  • %TEMP%\binder_1787960721167.exe
  • %TEMP%\_mei000011202\pil\_avif.cp314-win_amd64.pyd
  • %APPDATA%\microsoft\windowsupdate\wuauserv.exe
  • %TEMP%\_mei000011202\pil\_imaging.cp314-win_amd64.pyd
  • %TEMP%\_mei000011202\pil\_imagingcms.cp314-win_amd64.pyd
  • %TEMP%\_mei000011202\pil\_imagingmath.cp314-win_amd64.pyd
  • %TEMP%\_mei000011202\pil\_imagingtk.cp314-win_amd64.pyd
  • %TEMP%\_mei000011202\pil\_webp.cp314-win_amd64.pyd
  • %TEMP%\_mei000011202\vcruntime140.dll
  • %TEMP%\_mei000011202\vcruntime140_1.dll
  • %TEMP%\_mei000011202\_bz2.pyd
  • %TEMP%\_mei000011202\_ctypes.pyd
  • %TEMP%\_mei000011202\_decimal.pyd
  • %TEMP%\_mei000011202\_elementtree.pyd
  • %TEMP%\_mei000011202\_hashlib.pyd
  • %TEMP%\_mei000011202\_lzma.pyd
  • %TEMP%\_mei000011202\_socket.pyd
  • %TEMP%\_mei000011202\_ssl.pyd
  • %TEMP%\_mei000011202\_tkinter.pyd
  • %TEMP%\_mei000011202\_uuid.pyd
  • %TEMP%\_mei000011202\_wmi.pyd
  • %TEMP%\_mei000011202\_zstd.pyd
  • %TEMP%\_mei000011202\base_library.zip
  • %TEMP%\_mei000011202\customtkinter\assets\.ds_store
  • %TEMP%\_mei000011202\customtkinter\assets\fonts\customtkinter_shapes_font.otf
  • %TEMP%\_mei000011202\customtkinter\assets\fonts\roboto\roboto-medium.ttf
  • %TEMP%\_mei000011202\customtkinter\assets\fonts\roboto\roboto-regular.ttf
  • %TEMP%\_mei000011202\customtkinter\assets\icons\.ds_store
  • %TEMP%\_mei000011202\customtkinter\assets\icons\customtkinter_icon_windows.ico
  • %TEMP%\_mei000011202\customtkinter\assets\themes\blue.json
  • %TEMP%\_mei000011202\customtkinter\assets\themes\dark-blue.json
  • %TEMP%\_mei000011202\customtkinter\assets\themes\gold.json
  • %TEMP%\_mei000011202\customtkinter\assets\themes\green.json
  • %TEMP%\_mei000011202\libcrypto-3.dll
  • %TEMP%\_mei000011202\libffi-8.dll
  • %TEMP%\_mei000011202\libssl-3.dll
  • %TEMP%\_mei000011202\libtommath.dll
  • %TEMP%\_mei000011202\pyexpat.pyd
  • %TEMP%\_mei000011202\python314.dll
  • %TEMP%\_mei000011202\select.pyd
  • %TEMP%\_mei000011202\tcl90.dll
  • %TEMP%\_mei000011202\tcl9tk90.dll
  • %TEMP%\_mei000011202\unicodedata.pyd
  • %TEMP%\_mei000011202\zlib1.dll
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_arc4.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_salsa20.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_chacha20.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_pkcs1_decode.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_aes.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_aesni.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_arc2.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_blowfish.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_cast.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_cbc.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_cfb.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_ctr.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_des.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_des3.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_ecb.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_eksblowfish.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_ocb.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\cipher\_raw_ofb.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_blake2b.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_blake2s.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_md2.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_md4.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_md5.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_ripemd160.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_sha1.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_sha224.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_sha256.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_sha384.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_sha512.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_ghash_clmul.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_ghash_portable.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_keccak.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\hash\_poly1305.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\math\_modexp.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\protocol\_scrypt.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\publickey\_curve25519.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\publickey\_curve448.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\publickey\_ec_ws.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\publickey\_ed25519.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\publickey\_ed448.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\util\_cpuid_c.pyd
  • %WINDIR%\temp\_mei000011f42\crypto\util\_strxor.pyd
  • %WINDIR%\temp\_mei000011f42\pil\_avif.cp312-win_amd64.pyd
  • %WINDIR%\temp\_mei000011f42\pil\_imaging.cp312-win_amd64.pyd
  • %WINDIR%\temp\_mei000011f42\pil\_imagingcms.cp312-win_amd64.pyd
  • %WINDIR%\temp\_mei000011f42\pil\_imagingmath.cp312-win_amd64.pyd
  • %WINDIR%\temp\_mei000011f42\pil\_imagingtk.cp312-win_amd64.pyd
  • %WINDIR%\temp\_mei000011f42\pil\_webp.cp312-win_amd64.pyd
  • %WINDIR%\temp\_mei000011f42\vcruntime140.dll
  • %WINDIR%\temp\_mei000011f42\vcruntime140_1.dll
  • %WINDIR%\temp\_mei000011f42\_bz2.pyd
  • %WINDIR%\temp\_mei000011f42\_ctypes.pyd
  • %WINDIR%\temp\_mei000011f42\_decimal.pyd
  • %WINDIR%\temp\_mei000011f42\_elementtree.pyd
  • %WINDIR%\temp\_mei000011f42\_hashlib.pyd
  • %WINDIR%\temp\_mei000011f42\_lzma.pyd
  • %WINDIR%\temp\_mei000011f42\_multiprocessing.pyd
  • %WINDIR%\temp\_mei000011f42\_queue.pyd
  • %WINDIR%\temp\_mei000011f42\_socket.pyd
  • %WINDIR%\temp\_mei000011f42\_sqlite3.pyd
  • %WINDIR%\temp\_mei000011f42\_ssl.pyd
  • %WINDIR%\temp\_mei000011f42\_uuid.pyd
  • %WINDIR%\temp\_mei000011f42\_wmi.pyd
  • %WINDIR%\temp\_mei000011f42\base_library.zip
  • %WINDIR%\temp\_mei000011f42\certifi\cacert.pem
  • %WINDIR%\temp\_mei000011f42\charset_normalizer\cd.cp312-win_amd64.pyd
  • %WINDIR%\temp\_mei000011f42\charset_normalizer\md.cp312-win_amd64.pyd
  • %WINDIR%\temp\_mei000011f42\discord_badge_farmer.exe
  • %WINDIR%\temp\_mei000011f42\libcrypto-3.dll
  • %WINDIR%\temp\_mei000011f42\libffi-8.dll
  • %WINDIR%\temp\_mei000011f42\libssl-3.dll
  • %WINDIR%\temp\_mei000011f42\psutil\_psutil_windows.pyd
  • %WINDIR%\temp\_mei000011f42\pyexpat.pyd
  • %WINDIR%\temp\_mei000011f42\python3.dll
  • %WINDIR%\temp\_mei000011f42\python312.dll
  • %WINDIR%\temp\_mei000011f42\pywin32_system32\pywintypes312.dll
  • %WINDIR%\temp\_mei000011f42\select.pyd
  • %WINDIR%\temp\_mei000011f42\setuptools\_vendor\jaraco\text\lorem ipsum.txt
  • %WINDIR%\temp\_mei000011f42\sqlite3.dll
  • %WINDIR%\temp\_mei000011f42\unicodedata.pyd
  • %WINDIR%\temp\_mei000011f42\win32\win32crypt.pyd
  • %WINDIR%\temp\_mei000011f42\win32\win32gui.pyd
  • %WINDIR%\temp\6fwuurbv
  • %WINDIR%\temp\binder_1787960753519.exe
  • %WINDIR%\temp\_mei00000e642\pil\_avif.cp314-win_amd64.pyd
  • <SYSTEM32>\config\systemprofile\appdata\roaming\microsoft\windowsupdate\wuauserv.exe
  • %WINDIR%\temp\_mei00000e642\pil\_imaging.cp314-win_amd64.pyd
  • %WINDIR%\temp\_mei00000e642\pil\_imagingcms.cp314-win_amd64.pyd
  • %WINDIR%\temp\_mei00000e642\pil\_imagingmath.cp314-win_amd64.pyd
  • %WINDIR%\temp\_mei00000e642\pil\_imagingtk.cp314-win_amd64.pyd
  • %WINDIR%\temp\_mei00000e642\pil\_webp.cp314-win_amd64.pyd
  • %WINDIR%\temp\_mei00000e642\vcruntime140.dll
  • %WINDIR%\temp\_mei00000e642\vcruntime140_1.dll
  • %WINDIR%\temp\_mei00000e642\_bz2.pyd
  • %WINDIR%\temp\_mei00000e642\_ctypes.pyd
  • %WINDIR%\temp\_mei00000e642\_decimal.pyd
  • %WINDIR%\temp\_mei00000e642\_elementtree.pyd
  • %WINDIR%\temp\_mei00000e642\_hashlib.pyd
  • %WINDIR%\temp\_mei00000e642\_lzma.pyd
  • %WINDIR%\temp\_mei00000e642\_socket.pyd
  • %WINDIR%\temp\__psscriptpolicytest_oo4kv3x5.uta.ps1
  • %WINDIR%\temp\__psscriptpolicytest_4af2ce2g.vsb.psm1
  • %WINDIR%\temp\_mei00000e642\_ssl.pyd
  • %WINDIR%\temp\_mei00000e642\_tkinter.pyd
  • %WINDIR%\temp\_mei00000e642\_uuid.pyd
  • %WINDIR%\temp\_mei00000e642\_wmi.pyd
  • %WINDIR%\temp\_mei00000e642\_zstd.pyd
  • %WINDIR%\temp\_mei00000e642\base_library.zip
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\.ds_store
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\fonts\customtkinter_shapes_font.otf
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\fonts\roboto\roboto-medium.ttf
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\fonts\roboto\roboto-regular.ttf
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\icons\.ds_store
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\icons\customtkinter_icon_windows.ico
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\themes\blue.json
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\themes\dark-blue.json
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\themes\gold.json
  • %WINDIR%\temp\_mei00000e642\customtkinter\assets\themes\green.json
  • %WINDIR%\temp\_mei00000e642\libcrypto-3.dll
  • %WINDIR%\temp\content\2288-672-powershell.exe-16-46-00-926.dump
  • <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
  • %WINDIR%\temp\_mei00000e642\libffi-8.dll
  • %WINDIR%\temp\_mei00000e642\libssl-3.dll
  • %WINDIR%\temp\_mei00000e642\libtommath.dll
  • %WINDIR%\temp\_mei00000e642\pyexpat.pyd
  • %WINDIR%\temp\_mei00000e642\python314.dll
  • %WINDIR%\temp\_mei00000e642\select.pyd
  • %WINDIR%\temp\_mei00000e642\tcl90.dll
  • %WINDIR%\temp\_mei00000e642\tcl9tk90.dll
  • %WINDIR%\temp\_mei00000e642\unicodedata.pyd
  • %WINDIR%\temp\_mei00000e642\zlib1.dll
  • %WINDIR%\temp\__psscriptpolicytest_dccmvow4.0pa.ps1
  • %WINDIR%\temp\__psscriptpolicytest_5i3zz1gs.aza.psm1
  • %WINDIR%\temp\content\3756-1640-powershell.exe-16-46-04-475.dump
  • %TEMP%\tmp8o71xt15.db
  • %TEMP%\ss_59f64b1a.png
  • %TEMP%\tmpkxonbggv.db
  • %TEMP%\tmpkxonbggv.db-shm
  • %TEMP%\tmp0h9wqci5.db
  • %TEMP%\tmp8ir_iqaa.db
  • %WINDIR%\temp\__psscriptpolicytest_tksn04sv.3oe.ps1
  • %WINDIR%\temp\__psscriptpolicytest_3rdzlmpu.d0i.psm1
  • %WINDIR%\temp\content\1684-824-powershell.exe-16-46-27-930.dump
  • %WINDIR%\temp\content\1684-824-powershell.exe-16-46-28-306.dump
  • %WINDIR%\temp\content\1684-824-powershell.exe-16-46-28-522.dump
  • %WINDIR%\temp\content\1684-824-powershell.exe-16-46-28-815.dump
  • %WINDIR%\temp\content\1684-824-powershell.exe-16-46-29-484.dump
  • %TEMP%\etilqs_u52esjfrfkbuifa
  • %TEMP%\tmp8ya6zhpa.db
  • %TEMP%\tmputz4m3vw.db
  • %TEMP%\tmpwtewgurq.db
  • %TEMP%\tmp3jwt4s7h.db
  • %TEMP%\etilqs_be7ne7ghxu5ks7s
  • %TEMP%\etilqs_uve8sldci5kosj1
  • %TEMP%\8331.tmp
Sets the 'hidden' attribute to the following files
  • %APPDATA%\microsoft\windowsupdate\wuauserv.exe
  • <SYSTEM32>\config\systemprofile\appdata\roaming\microsoft\windowsupdate\wuauserv.exe
Deletes following files that it created itself
  • %TEMP%\3npep4uw
  • %WINDIR%\temp\6fwuurbv
  • %WINDIR%\temp\__psscriptpolicytest_oo4kv3x5.uta.ps1
  • %WINDIR%\temp\__psscriptpolicytest_4af2ce2g.vsb.psm1
  • %WINDIR%\temp\__psscriptpolicytest_dccmvow4.0pa.ps1
  • %WINDIR%\temp\__psscriptpolicytest_5i3zz1gs.aza.psm1
  • %TEMP%\tmpkxonbggv.db-shm
  • %TEMP%\tmpkxonbggv.db
  • %TEMP%\tmp0h9wqci5.db
  • %TEMP%\tmp8ir_iqaa.db
  • %WINDIR%\temp\__psscriptpolicytest_tksn04sv.3oe.ps1
  • %WINDIR%\temp\__psscriptpolicytest_3rdzlmpu.d0i.psm1
  • %TEMP%\tmp8ya6zhpa.db
  • %TEMP%\tmputz4m3vw.db
  • %TEMP%\tmpwtewgurq.db
  • %TEMP%\tmp3jwt4s7h.db
  • %TEMP%\8331.tmp
  • %TEMP%\_mei00000bb82\base_library.zip
  • %TEMP%\_mei00000bb82\certifi\cacert.pem
  • %TEMP%\_mei00000bb82\charset_normalizer\cd.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\charset_normalizer\md.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_arc4.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_chacha20.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_pkcs1_decode.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_aes.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_aesni.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_arc2.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_blowfish.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_cast.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_cbc.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_cfb.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_ctr.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_des.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_des3.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_ecb.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_eksblowfish.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_ocb.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_raw_ofb.pyd
  • %TEMP%\_mei00000bb82\crypto\cipher\_salsa20.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_blake2b.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_blake2s.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_ghash_clmul.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_ghash_portable.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_keccak.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_md2.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_md4.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_md5.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_poly1305.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_ripemd160.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha1.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha224.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha256.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha384.pyd
  • %TEMP%\_mei00000bb82\crypto\hash\_sha512.pyd
  • %TEMP%\_mei00000bb82\crypto\math\_modexp.pyd
  • %TEMP%\_mei00000bb82\crypto\protocol\_scrypt.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_curve25519.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_curve448.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_ec_ws.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_ed25519.pyd
  • %TEMP%\_mei00000bb82\crypto\publickey\_ed448.pyd
  • %TEMP%\_mei00000bb82\crypto\util\_cpuid_c.pyd
  • %TEMP%\_mei00000bb82\crypto\util\_strxor.pyd
  • %TEMP%\_mei00000bb82\discord_badge_farmer.exe
  • %TEMP%\_mei00000bb82\libcrypto-3.dll
  • %TEMP%\_mei00000bb82\libffi-8.dll
  • %TEMP%\_mei00000bb82\libssl-3.dll
  • %TEMP%\_mei00000bb82\pil\_avif.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_imaging.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_imagingcms.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_imagingmath.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_imagingtk.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\pil\_webp.cp312-win_amd64.pyd
  • %TEMP%\_mei00000bb82\psutil\_psutil_windows.pyd
  • %TEMP%\_mei00000bb82\pyexpat.pyd
  • %TEMP%\_mei00000bb82\python3.dll
  • %TEMP%\_mei00000bb82\python312.dll
  • %TEMP%\_mei00000bb82\pywin32_system32\pywintypes312.dll
  • %TEMP%\_mei00000bb82\select.pyd
  • %TEMP%\_mei00000bb82\setuptools\_vendor\jaraco\text\lorem ipsum.txt
  • %TEMP%\_mei00000bb82\sqlite3.dll
  • %TEMP%\_mei00000bb82\unicodedata.pyd
  • %TEMP%\_mei00000bb82\vcruntime140.dll
  • %TEMP%\_mei00000bb82\vcruntime140_1.dll
  • %TEMP%\_mei00000bb82\win32\win32crypt.pyd
  • %TEMP%\_mei00000bb82\win32\win32gui.pyd
  • %TEMP%\_mei00000bb82\_bz2.pyd
  • %TEMP%\_mei00000bb82\_ctypes.pyd
  • %TEMP%\_mei00000bb82\_decimal.pyd
  • %TEMP%\_mei00000bb82\_elementtree.pyd
  • %TEMP%\_mei00000bb82\_hashlib.pyd
  • %TEMP%\_mei00000bb82\_lzma.pyd
  • %TEMP%\_mei00000bb82\_multiprocessing.pyd
  • %TEMP%\_mei00000bb82\_queue.pyd
  • %TEMP%\_mei00000bb82\_socket.pyd
  • %TEMP%\_mei00000bb82\_sqlite3.pyd
  • %TEMP%\_mei00000bb82\_ssl.pyd
  • %TEMP%\_mei00000bb82\_uuid.pyd
  • %TEMP%\_mei00000bb82\_wmi.pyd
Network activity
Connects to
  • 'cd#.##scordapp.com':443
  • 'ap#.#pify.org':443
  • 'localhost':49698
  • 'localhost':49699
  • 'google.com':80
  • 'du###uckgo.com':443
  • 'bing.com':80
  • 'am##on.com':80
  • 'am##on.com':443
  • 'au######te.geo.opera.com':443
  • 'en.###ipedia.org':80
  • 'se####.yahoo.com':80
  • 'en.###ipedia.org':443
  • 'se####.yahoo.com':443
  • 'fa###ook.com':80
  • 'fz###.ttk.ru':80
  • 'x1.#.lencr.org':80
  • 'cr#.####g2.amazontrust.com':80
  • 'st#####.##gitalcertvalidation.com':80
  • 'oc##.###tg2.amazontrust.com':80
  • 're###.opera.com':443
  • 'do#####d3.operacdn.com':443
  • 'oc##.####ca1.amazontrust.com':80
  • 'oc##.###04.amazontrust.com':80
  • 're###.opera.com':80
  • 'x2.#.lencr.org':80
  • 'ye.#.lencr.org':80
  • 'eb##.com':80
  • 'ye#.#.lencr.org':80
  • 'eb##.com':443
  • 'oc##.#ectigo.com':80
  • 'sd#####es.operacdn.com':443
  • 'wa##art.com':80
  • 'wa##art.com':443
  • '14#.#5.118.133':80
TCP
HTTP GET requests
  • http://www.google.com/favicon.ico
  • http://www.bing.com/s/a/bing_p.ico
  • http://en.###ipedia.org/favicon.ico
  • http://se####.yahoo.com/favicon.ico
  • http://fz###.ttk.ru/favicon.ico
  • http://www.fa###ook.com/favicon.ico
  • http://oc##.###tg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
  • http://oc##.####ca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEk8qlS4%2B0YpYvbhdG8DOXyc%3D
  • http://oc##.###04.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTihuFvpmFDw5hOcIp918Jm5B3CQgQUH1KSYVaCVH%2BBZtgdPQqqMlyH3QgCEAVmDC6oVuPVI5U%2Bk56Ia10%3D
  • http://x2.#.lencr.org/
  • http://www.am##on.com/
  • http://ye.#.lencr.org/
  • http://ye#.#.lencr.org/96.crl
  • http://re###.opera.com/speeddials/partner/tripadvisor_us
  • http://oc##.#ectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTQfBYvI8FkPbXYaEjaJPq5dNxTywQUe%2BJJoWC0u%2BhC5sanVBEcYWRTVdECEGfjBZvmJPgK6%2B5LYIBPkzg%3D
  • http://www.eb##.com/favicon.ico
  • http://www.wa##art.com/
Other
  • 'cd#.##scordapp.com':443
  • 'ap#.#pify.org':443
  • 'localhost':49714
  • 'localhost':49716
  • 'localhost':49717
  • 'localhost':49720
  • 'localhost':49721
  • 'localhost':49722
  • 'localhost':49723
  • 'localhost':49724
  • 'localhost':49725
  • 'du###uckgo.com':443
  • 'am##on.com':443
  • 'au######te.geo.opera.com':443
  • 'en.###ipedia.org':443
  • 'se####.yahoo.com':443
  • 're###.opera.com':443
  • 'do#####d3.operacdn.com':443
  • 'eb##.com':443
  • 'sd#####es.operacdn.com':443
  • 'wa##art.com':443
UDP
  • DNS ASK cd#.##scordapp.com
  • DNS ASK ap#.#pify.org
  • DNS ASK google.com
  • DNS ASK se####.yahoo.com
  • DNS ASK du###uckgo.com
  • DNS ASK am##on.com
  • DNS ASK bing.com
  • DNS ASK bi##.#ikimedia.org
  • DNS ASK en.###ipedia.org
  • DNS ASK au######te.geo.opera.com
  • DNS ASK fa###ook.com
  • DNS ASK x1.#.lencr.org
  • DNS ASK cr#.####g2.amazontrust.com
  • DNS ASK st#####.##gitalcertvalidation.com
  • DNS ASK fz###.ttk.ru
  • DNS ASK re###.opera.com
  • DNS ASK x.##2.us
  • DNS ASK o.##2.us
  • DNS ASK do#####d3.operacdn.com
  • DNS ASK s.##2.us
  • DNS ASK oc##.###tg2.amazontrust.com
  • DNS ASK oc##.####ca1.amazontrust.com
  • DNS ASK x2.#.lencr.org
  • DNS ASK oc##.###04.amazontrust.com
  • DNS ASK ye.#.lencr.org
  • DNS ASK eb##.com
  • DNS ASK ye#.#.lencr.org
  • DNS ASK oc##.#ectigo.com
  • DNS ASK sd#####es.operacdn.com
  • DNS ASK bo##ing.com
  • DNS ASK al###press.com
  • DNS ASK wa##art.com
  • DNS ASK ov###tock.com
  • DNS ASK tr###dvisor.com
Miscellaneous
Searches for the following windows
  • ClassName: 'Opera_MessageWindow' WindowName: '%APPDATA%\Opera Software\Opera Stable'
Creates and executes the following
  • '%TEMP%\binder_1787960721167.exe'
  • '%APPDATA%\microsoft\windowsupdate\wuauserv.exe' --silent
  • '%WINDIR%\temp\binder_1787960753519.exe'
Restarts the analyzed sample
Executes the following
  • '<SYSTEM32>\cmd.exe' /c "%TEMP%\binder_1787960721167.exe"
  • '<SYSTEM32>\cmd.exe' /c "powershell -ExecutionPolicy Bypass -Command " $TaskName = "WindowsMaintenance" $TaskPath = "\Microsoft\Windows\Maintenance" $Action = New-ScheduledTaskAction -Execute "%APPDATA%\Microsoft\W...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command "
  • '<SYSTEM32>\cmd.exe' /c "powershell -ExecutionPolicy Bypass -Command " $FilterArgs = @{Name='StartupFilter'; EventNameSpace='root\cimv2'; QueryLanguage='WQL'; Query="SELECT * FROM Win32_ProcessStartTrace WHERE Proc...
  • '<SYSTEM32>\cmd.exe' /c "sc create "WindowsUpdateAssistant" binPath= "%APPDATA%\Microsoft\WindowsUpdate\wuauserv.exe --silent" DisplayName= "Windows Update Assistant" start= auto"
  • '<SYSTEM32>\cmd.exe' /c "ver"
  • '<SYSTEM32>\sc.exe' create "WindowsUpdateAssistant" binPath= "%APPDATA%\Microsoft\WindowsUpdate\wuauserv.exe --silent" DisplayName= "Windows Update Assistant" start= auto
  • '<SYSTEM32>\cmd.exe' /c "sc description "WindowsUpdateAssistant" "Assists Windows Update in maintaining system security""
  • '<SYSTEM32>\tasklist.exe'
  • '<SYSTEM32>\sc.exe' description "WindowsUpdateAssistant" "Assists Windows Update in maintaining system security"
  • '<SYSTEM32>\cmd.exe' /c "sc failure "WindowsUpdateAssistant" reset= 86400 actions= restart/5000"
  • '<SYSTEM32>\sc.exe' failure "WindowsUpdateAssistant" reset= 86400 actions= restart/5000
  • '<SYSTEM32>\cmd.exe' /c "sc start "WindowsUpdateAssistant""
  • '<SYSTEM32>\sc.exe' start "WindowsUpdateAssistant"
  • '<SYSTEM32>\cmd.exe' /c "%WINDIR%\TEMP\binder_1787960753519.exe"
  • '<SYSTEM32>\cmd.exe' /c "powershell -ExecutionPolicy Bypass -Command " $TaskName = "WindowsMaintenance" $TaskPath = "\Microsoft\Windows\Maintenance" $Action = New-ScheduledTaskAction -Execute "<SYSTEM32>\config\sys...
  • '<SYSTEM32>\cmd.exe' /c "sc create "WindowsUpdateAssistant" binPath= "<SYSTEM32>\config\systemprofile\AppData\Roaming\Microsoft\WindowsUpdate\wuauserv.exe --silent" DisplayName= "Windows Update Assistant" start= au...
  • '<SYSTEM32>\sc.exe' create "WindowsUpdateAssistant" binPath= "<SYSTEM32>\config\systemprofile\AppData\Roaming\Microsoft\WindowsUpdate\wuauserv.exe --silent" DisplayName= "Windows Update Assistant" start= auto
  • '<SYSTEM32>\cmd.exe' /c "netsh wlan show profiles"
  • '<SYSTEM32>\netsh.exe' wlan show profiles
  • '<SYSTEM32>\cmd.exe' /c "wmic path win32_VideoController get name"
  • '%ProgramFiles(x86)%\opera\launcher.exe' --remote-debugging-port=49698 "--user-data-dir=%APPDATA%\Opera Software\Opera Stable" --headless=new --no-first-run --no-default-browser-check --disable-gpu --disable-extensions --disable-backg...
  • '<SYSTEM32>\wbem\wmic.exe' path win32_VideoController get name
  • '%ProgramFiles(x86)%\opera\launcher.exe' --remote-debugging-port=49699 "--user-data-dir=%APPDATA%\Opera Software\Opera Stable" --headless=new --no-first-run --no-default-browser-check --disable-gpu --disable-extensions --disable-backg...
  • '%ProgramFiles(x86)%\opera\36.0.2130.46\opera.exe' --remote-debugging-port=49698 --user-data-dir="%APPDATA%\Opera Software\Opera Stable" --headless=new --no-first-run --no-default-browser-check --disable-gpu --disable-extensions --disable-backg...
  • '%ProgramFiles(x86)%\opera\36.0.2130.46\opera.exe' --remote-debugging-port=49699 --user-data-dir="%APPDATA%\Opera Software\Opera Stable" --headless=new --no-first-run --no-default-browser-check --disable-gpu --disable-extensions --disable-backg...
  • '<SYSTEM32>\cmd.exe' /c "wmic os get Caption"
  • '<SYSTEM32>\wbem\wmic.exe' os get Caption
  • '<SYSTEM32>\cmd.exe' /c "powershell -command "Get-Clipboard -Raw""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Get-Clipboard -Raw"
  • '%ProgramFiles(x86)%\opera\36.0.2130.46\opera_crashreporter.exe' --remote-debugging-port=49698 --user-data-dir="%APPDATA%\Opera Software\Opera Stable" --headless=new --no-first-run --no-default-browser-check --disable-gpu --disable-extensions --disable-backg...
  • '%ProgramFiles(x86)%\opera\36.0.2130.46\opera_crashreporter.exe' --remote-debugging-port=49699 --user-data-dir="%APPDATA%\Opera Software\Opera Stable" --headless=new --no-first-run --no-default-browser-check --disable-gpu --disable-extensions --disable-backg...
  • '%ProgramFiles(x86)%\opera\36.0.2130.46\opera.exe' --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --lang=en-US --user-data-dir="%APPDATA%\Opera Software\Opera Stable" --user-data-dir="%APPDATA%...
  • '%ProgramFiles(x86)%\opera\36.0.2130.46\opera.exe' --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --lang=en-US --user-data-dir="%APPDATA%\Opera Software\Opera Stable" --extension-process --enab...
  • '%ProgramFiles(x86)%\opera\36.0.2130.46\opera.exe' --type=utility --channel="424.4.17913983\288080848" --lang=en-US --user-data-dir="%APPDATA%\Opera Software\Opera Stable" --with-feature:installer-experiment-test=off --with-feature:installer-ui...
  • '%ProgramFiles(x86)%\opera\36.0.2130.46\opera.exe' --type=utility --channel="424.5.316444628\1463006219" --lang=en-US --user-data-dir="%APPDATA%\Opera Software\Opera Stable" --with-feature:installer-experiment-test=off --with-feature:installer-...
  • '<SYSTEM32>\cmd.exe' /c "%TEMP%\binder_1787960721167.exe"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "powershell -ExecutionPolicy Bypass -Command " $TaskName = "WindowsMaintenance" $TaskPath = "\Microsoft\Windows\Maintenance" $Action = New-ScheduledTaskAction -Execute "%APPDATA%\Microsoft\W...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "powershell -ExecutionPolicy Bypass -Command " $FilterArgs = @{Name='StartupFilter'; EventNameSpace='root\cimv2'; QueryLanguage='WQL'; Query="SELECT * FROM Win32_ProcessStartTrace WHERE Proc...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "sc create "WindowsUpdateAssistant" binPath= "%APPDATA%\Microsoft\WindowsUpdate\wuauserv.exe --silent" DisplayName= "Windows Update Assistant" start= auto"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "ver"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "sc description "WindowsUpdateAssistant" "Assists Windows Update in maintaining system security""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "sc failure "WindowsUpdateAssistant" reset= 86400 actions= restart/5000"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "sc start "WindowsUpdateAssistant""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "%WINDIR%\TEMP\binder_1787960753519.exe"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "powershell -ExecutionPolicy Bypass -Command " $TaskName = "WindowsMaintenance" $TaskPath = "\Microsoft\Windows\Maintenance" $Action = New-ScheduledTaskAction -Execute "<SYSTEM32>\config\sys...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "sc create "WindowsUpdateAssistant" binPath= "<SYSTEM32>\config\systemprofile\AppData\Roaming\Microsoft\WindowsUpdate\wuauserv.exe --silent" DisplayName= "Windows Update Assistant" start= au...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "netsh wlan show profiles"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "wmic path win32_VideoController get name"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "wmic os get Caption"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c "powershell -command "Get-Clipboard -Raw""' (with hidden window)

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android