Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.Crossrider.30283

Added to the Dr.Web virus database: 2014-08-22

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates or modifies the following files:
  • %WINDIR%\Tasks\globalUpdateUpdateTaskMachineCore.job
  • %WINDIR%\Tasks\globalUpdateUpdateTaskMachineUA.job
  • %WINDIR%\Tasks\e897c2f8-56b0-4114-8d77-acc0480b1272-1.job
  • %WINDIR%\Tasks\e897c2f8-56b0-4114-8d77-acc0480b1272-3.job
  • %WINDIR%\Tasks\e897c2f8-56b0-4114-8d77-acc0480b1272-11.job
  • %WINDIR%\Tasks\e897c2f8-56b0-4114-8d77-acc0480b1272-4.job
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\globalUpdate] 'Start' = '00000002'
Malicious functions:
Creates and executes the following:
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMCIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins0RUU0OTI4Qi0wMkVDLTQ5RkYtOEVDMS1EQTNEREE1NjJBQTR9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHRlc3Rzb3VyY2U9ImF1dG8iIHJlcXVlc3RpZD0iezVDRTY3NjYyLUE1NUMtNDk5My1BOEEwLUJEMUZBOEM3NDA3OH0iPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI1LjEiIHNwPSJTZXJ2aWNlIFBhY2sgMiIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0iezQzMEZENEQwLUI3MjktNEY2MS1BQTM0LTkxNTI2NDgxNzk5RH0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4yNS4wIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48L2FwcD48L3JlcXVlc3Q-
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /regserver
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /svc
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /handoff "appguid={d66b35db-b2e5-42f7-ad02-bccf77bd0c7e}&appname=05c2d991-e674-4e93-9190-5f3add2e89bd&needsadmin=True&lang=en" /installsource otherinstallcmd /sessionid "{4EE4928B-02EC-49FF-8EC1-DA3DDA562AA4}" /silent
  • '%PROGRAM_FILES%\S10\e897c2f8-56b0-4114-8d77-acc0480b1272-11.exe' /vvxbgFsD=SyRDknXT4saXHNKRynw2gbwZalpnhCmmLTm453jpkUFXQ5CLhZg9OutuUGWzvrdydk3J60rsk2N9nuEiOGLLP58CyJCihJ/9VoMkTwmuEmkRGsqD4TMDYn1ZcM0wbpfr0sGAXmjwUBEbm+8jl2ai8pmw59NA27D2kzFTShCGHFyYlbWioHE977NGfrBxhmJ8skU+/0gixBoWSHQc01NFXeyDg6vw6ZoLPiGUqBBDl8Vk6UlZiGDaVG1RKcEnetuTcDS8m0at6xFv43wSdN0YMmVMeBGR7d2OfxOTOwt4j3CSUN6yC7IiX70tZZsGDMcwlCRTY9zAQSI3ce4xpcilTWwdJ69kT6in5L8hzH5uMmgZqNUiqB7SmCATW0cjSb0q8JorSe/tBv3pRSxzKdKxMpRT2wttXqLLwV4OwwhUOhl53ogJL2GJyuZ69wVp1oshjmcBeqG7n4d0WCTaia51tBX+bqy/OQQFGDnvACkjTRmB7NjVXcP7eg2ARNTEN+Nsqn9md8B9vXMK7/2K7eFWRyZ7qO+fkp112Ny6ijrSVXifLM/q3BHRHDY5+SWoz9wkFRmpaVVwZ23RZy+s1FnbxjgnAKzvc3kgtvrji9xQDeBZvBSogkdvIJNbl0UJ3lT2C4ClzfyIK51Y7caRSSCQkDCKlRHuaJ/VaGvSCDH17/G4qUT34e6ahrLJi/J7Hso4yG93DTF0csQmlXM2ypB5zvzd+HZyDhyw0cGruVB5wVskETpaDdv3OsLiwRvsSTiDw71VvnDrHXvo7wjJKAeH99qRptjgdy3Uf/1SEjAUk83vbRoKbso1D2cbLN4ibBzUFJ3xsoFUg7HFOBXTKMpDLAShuq6YP/NZJn4SazFdw8tMPh28wjhD7QabrBcEpM94pk9PpjHVIpJtxCiVc4r9eUDtXnbGv+kOrfUV0lTnHKmR3IuF5AyuJGlj5Kg1I0INVRA4gSteNsBEYwA/BXt7MvsEy2H45YHaFDNmgWdH5dFVCE+0v8Gl6w3zaEGvVZxYKQrP+9NTOYL+fV7p7M1Ux4fzRI3z2PzZkRuAV+fW1YYiYsHdrOthWz+nocZLAfBsl6ZUbKejn+egDgAiJgvFKyTOp/tWYk7Y/hHdOtxkozb1YFa2ovQnbu9fvRZ7vLz3/Qe8xO1o2NQjze9pJqnxNyvhMz5SGkVJvtj8NCYu9CIVXZOnK6C7sD/4FTQF4kpdXN3F6z8lhCq9Phs6uY+z+tVTIChLM3bIyav7Z/0wG/pwwL7p/IJGhy1mappMrTCa3yQ2kUzLTTPAfn0leb5WZKRlS+JODp0ooAVx9GzopCwM7bBGi1eNBHU02NiNN4cmSDjfJmP6oAlSOe8jSRq2Uji+ZFhwUjI2IQISQgwLajFBOZc50fFK0ImZY3DxOLX08LMT3RuolAImOeknezujZwRZJ0iH9d4IAkCO80Jp8ycnPqYSgzEtRFcp3Ub+//tuyu5YxEUDCQoqZ5WhGmnXIx2EMTwFylMVYx79hjmrE6oLZ0CEfKV9/kF/Pscj55lCiPWSq6IJPVSsdJDANB6Av29+gZtoPE38q+xxWjWRcHmCCZc10fSOK1ZOYfqVo8WkNIKXCvF3PibarE+9I5s0sfmcFPHa5PAP3qtjpC6tFZPQXw/b6IwTac09pb9WI0n/6zmCXHTXGv0K/BKRS+PRJwU0SCi4lJWfPZ/hkxrz4Kk=
  • '%TEMP%\comh.389091\GoogleUpdate.exe' /silent /install "appguid={d66b35db-b2e5-42f7-ad02-bccf77bd0c7e}&appname=05c2d991-e674-4e93-9190-5f3add2e89bd&needsadmin=True&lang=en"
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /regsvc
  • '%PROGRAM_FILES%\S10\e897c2f8-56b0-4114-8d77-acc0480b1272-4.exe' /kFPWJkFGD /IUXMDU='S10' /yipZVAu='%PROGRAM_FILES%\S10\48924.xpi' /olRhMk=48924 /KDoZhQ='000841' /qGpeZpKa='0' /STVERlHs='0' /vZBUbBwDF=4DF29FFCC270489DA65269071907768EIE /CFPRnblA=f8d0604364f20cfea4b2437661c1e446 /PIrxq=1_34_06_10 /yUHiguY=1.34.6.10 /cNhgkFhbB=1408676426 /uNZoBlc=http://st###.#atagenserv.com /bRlsqwaSv=http://er####.datagenserv.com /jjiseWj=300 /QmcNbFsL=52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com /Ufqwcqhal=0.94 /sDUVVrbXn=a52c8b690b0a84d679ecc566aaa231f646a33300ba82b47a5a6c34064823d6e72com48924 /BlgkgUaxO=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/48924.rdf /abgHh='S10' /URUEtQL='We give superior shopping experience by giving you the best offers instantly!' /uVgwK='smart-saverplus' /aOPUAuI=ie /NfCTFgQHU='{"asw":[0, 0, 0]}' /JEBgn /GEUPHXK /WjuQXE /VIIBIGMYB='http://up####.datagenserv.com/ff_agent_updates/{CAMP_ID}/update.json' /zAoPaM /axTmrUB='installer' /NVpEssDCH='%TEMP%\S10Installer_1408676426.log'
Executes the following:
  • '<SYSTEM32>\msiexec.exe' /V
Terminates or attempts to terminate
the following user processes:
  • opera.exe
  • firefox.exe
  • iexplore.exe
Modifies file system :
Creates the following files:
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\babeee4bb694d5a976146d72f2d7e660.js
  • %WINDIR%\Installer\MSIA.tmp
  • C:\Config.Msi\45d90.rbs
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\c4624b7019a002a7177bf7d2467c4512.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\0d46c844b162a6c93e6535e09466a9ad.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\02a9b04feb449104979a9109e815129e.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\8b81eb935c2951e8c2af73f5444fbfd1.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\5e86994198346783c3ba2046b3d19876.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\8215510175a753cd8933e34feea1f420.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\c3bf3a562d3fa09ebe05dbb4ae736930.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\installer.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\baa6649d8ea2493a2296fd59e1dae16f.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\91f1b1e8d205d943c2db0eccfdcab26f.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\3365e64331c9fda42f2d3f613a13bc46.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\41b31abd9bca2094c3156eee8111be84.js
  • %TEMP%\MSI46f8f.LOG
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\f8010ce72efc9bf0309dbd4d3c5f3ab0.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\be4186db61102401c5e13709c912290b.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\f676a6bc14629473390136f35ae650df.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\98.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\13.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\userCode\extension.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\207.js
  • %WINDIR%\Installer\45d8d.msi
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\78.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\102.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\47.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\17.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\userCode\background.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\search_dialog.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\a4bdf8744d04c3e9bb97659eb01f0784.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\browser.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\options.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\ffCoreFilesIndex.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\76b994ece0714ec3de1703cbae7d0cfb.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\options.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\background.html
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\dialog.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\dea68891f6e4de565d0fc71cb3cd95d7.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\update.css
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\popup.html
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button5.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button2.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon48.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\28939de048ee2a4fa499a0bc2fd796ce.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\bf5d93633000bddbcd907c6fb38a1cd0.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\9074abaa511833cf61907d7f8c48a6e2.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\5bbba83bac1f1d954e7f37b9e30c0970.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\skin.css
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\crossrider_statusbar.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon128.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite-journal
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button4.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\panelarrow-up.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button3.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon24.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon16.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button1.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\9334ab4c9649f28def2026e4ccb7c85b.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\f1171d2eb42d73c236e30bbfc2709bee.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\dcb7caf3d8a8d7b0695a672c2c8abf5f.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\5bd3ba6ce8478c8bdab66d1fe4986ccf.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\e08953cb19194192ef6965cd13fc1833.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\14194f2a23377980d578f8ad445b8492.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\8e35fc7bbb2696f734c649132736ada4.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\d6fe4d4f31959a225350b710897dd579.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\ff54393df85be96bf8d350f75bdc2b9b.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\07f7edaa8360025d7b46d77c04ecf528.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\d6e7f338991389df084ffe8d04580d3e.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\57c0e589d6de29d3c270d30ce3a17628.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\424a881ba1ff62d2822e88720ce2902d.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\0a333c35201bb699a5a2fc8a80e96347.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\c7104bf1a301800415eacfaca198c00f.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\c4f1087e07367021eaa291b48f2fa9e7.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\53197804db05bdaf8634fc4312883c1e.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\d0b709df4859bde4fbc194e85215d0dd.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\d3cc6be00cc1f3ab6678cd3d7d1a34bb.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\72.js
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\goopdate.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
  • %PROGRAM_FILES%\S10\48924.crx
  • %TEMP%\comh.389091\psuser.dll
  • %TEMP%\comh.389091\goopdateres_en.dll
  • %TEMP%\comh.389091\goopdate.dll
  • %TEMP%\comh.389091\psmachine.dll
  • %TEMP%\comh.389091\npGoogleUpdate4.dll
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
  • %PROGRAM_FILES%\S10\e897c2f8-56b0-4114-8d77-acc0480b1272.crx
  • %PROGRAM_FILES%\S10\360-48924.crx
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\C3E814D1CB223AFCD58214D14C3B7EAB
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\C3E814D1CB223AFCD58214D14C3B7EAB
  • %PROGRAM_FILES%\S10\1293297481.mxaddon
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
  • %PROGRAM_FILES%\S10\e897c2f8-56b0-4114-8d77-acc0480b1272-3.exe
  • %TEMP%\Cab4.tmp
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
  • %TEMP%\nsj3.tmp\md5dll.dll
  • %TEMP%\nsj3.tmp\nsisos.dll
  • %TEMP%\nsj3.tmp\inetc.dll
  • %TEMP%\nsj3.tmp\UserInfo.dll
  • %TEMP%\nsj3.tmp\InstallerUtils2.dll
  • %TEMP%\nsj3.tmp\StdUtils.dll
  • %TEMP%\nsy2.tmp
  • %TEMP%\nsj3.tmp\InstallerUtils.dll
  • %TEMP%\nsj3.tmp\System.dll
  • %TEMP%\nsj3.tmp\update.json
  • %TEMP%\comh.389091\GoogleUpdateBroker.exe
  • %TEMP%\comh.389091\GoogleUpdate.exe
  • %TEMP%\comh.389091\GoogleUpdateOnDemand.exe
  • %TEMP%\comh.389091\GoogleUpdateHelper.msi
  • %TEMP%\comh.389091\GoogleCrashHandler.exe
  • %TEMP%\nsj3.tmp\422622
  • %PROGRAM_FILES%\S10\utils.exe
  • %PROGRAM_FILES%\S10\Uninstall.exe
  • %TEMP%\nsj3.tmp\389905
  • %PROGRAM_FILES%\S10\e897c2f8-56b0-4114-8d77-acc0480b1272-11.exe
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\93.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\268.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\91.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\16.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\28.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins.json
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome.manifest
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\183.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\manifest.xml
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\4.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\22.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\177.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\64.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\246.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\14.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\1.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\21.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\104.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\182.js
  • %PROGRAM_FILES%\S10\e897c2f8-56b0-4114-8d77-acc0480b1272-4.exe
  • %PROGRAM_FILES%\S10\48924.xpi
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
  • %TEMP%\Cab8.tmp
  • %TEMP%\Cab6.tmp
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\8BD11C4A2318EC8E5A82462092971DEA
  • %TEMP%\nsj3.tmp\ExecDos.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\8BD11C4A2318EC8E5A82462092971DEA
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\install.rdf
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\defaults\preferences\prefs.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\locale\en-US\translations.dtd
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\psmachine.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\psuser.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
  • %PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe
Deletes the following files:
  • C:\Config.Msi\45d90.rbs
  • %WINDIR%\Installer\MSIA.tmp
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite-journal
  • %WINDIR%\Installer\45d8d.msi
  • %TEMP%\Cab4.tmp
  • %TEMP%\nsj3.tmp\389905
  • %TEMP%\Cab8.tmp
  • %TEMP%\Cab6.tmp
Network activity:
Connects to:
  • 'ts####.ws.symantec.com':80
  • 'cr#.#hawte.com':80
  • 'localhost':1046
  • 'localhost':1045
  • 'www.download.windowsupdate.com':80
  • 'er####.datagenserv.com':80
  • 'up####.datagenserv.com':80
  • 'lo##.##tagenserv.com':80
  • 'st###.#atagenserv.com':80
TCP:
HTTP GET requests:
  • cr#.#hawte.com/ThawteTimestampingCA.crl
  • ts####.ws.symantec.com/tss-ca-g2.crl
  • up####.datagenserv.com/omaha/430FD4D0-B729-4F61-AA34-91526481799D/1/ping.xml?ra#######
  • up####.datagenserv.com/installer_updates/000841/update.json
  • www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
  • www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
UDP:
  • DNS ASK www.download.windowsupdate.com
  • DNS ASK cr#.#hawte.com
  • DNS ASK ts####.ws.symantec.com
  • DNS ASK lo##.##tagenserv.com
  • DNS ASK up####.datagenserv.com
  • DNS ASK er####.datagenserv.com
  • DNS ASK st###.#atagenserv.com
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android