Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.Crossrider.33821

Added to the Dr.Web virus database: 2014-09-26

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates or modifies the following files:
  • %WINDIR%\Tasks\globalUpdateUpdateTaskMachineCore.job
  • %WINDIR%\Tasks\globalUpdateUpdateTaskMachineUA.job
  • %WINDIR%\Tasks\8c608567-314e-47b0-87c1-ac0da490fcc4-3.job
  • %WINDIR%\Tasks\8c608567-314e-47b0-87c1-ac0da490fcc4-4.job
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\globalUpdate] 'Start' = '00000002'
Malicious functions:
Creates and executes the following:
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /regsvc
  • '%PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe' /regserver
  • '%PROGRAM_FILES%\S10\8c608567-314e-47b0-87c1-ac0da490fcc4-4.exe' /fsZIB /bNWhh='S10' /IwuoagBT='%PROGRAM_FILES%\S10\48924.xpi' /fpfLXLm=48924 /yLaSnZ='000841' /WmmVBML='0' /bQgWYRvA='0' /UGYTdg=6FF1EAAF14AD42368CF307B5D8C607D9IE /wYLoQfK=7a33dadb447f6c9d6bee38d8b6eaa523 /zQsPtaEu=1_34_05_29 /IvVrpyZu=1.34.5.29 /tBlrO=1422874441 /iliKNLLXX=http://st###.#atademoserv.com /JQBAGNOE=http://er####.datademoserv.com /lKMjExrwj=300 /pxdmEx=52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com /mSDqfP=0.94 /acBzg=a52c8b690b0a84d679ecc566aaa231f646a33300ba82b47a5a6c34064823d6e72com48924 /EWkUCl=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/48924.rdf /ftaBR='S10' /sHcghVcLe='We give superior shopping experience by giving you the best offers instantly!' /QrqIW='smart-saverplus' /LhJNy=ie /EwyWCiAJj='{"asw":[0, 0]}' /ELOhKhi /PNbwa /FRnQcX /QGxSgPsyl='http://up####.datademoserv.com/ff_agent_updates/{CAMP_ID}/update.json' /ENHaV /xojRySStB='installer' /oxdikpMgT='%TEMP%\S10Installer_1422874441.log'
  • '%TEMP%\comh.80328\GoogleUpdate.exe' /silent /install "appguid={d66b35db-b2e5-42f7-ad02-bccf77bd0c7e}&appname=11615833-cca6-4099-bc44-02be53d1dac0&needsadmin=True&lang=en"
  • '%PROGRAM_FILES%\S10\8c608567-314e-47b0-87c1-ac0da490fcc4-3.exe' /ItIdMv=uh3v9wr/Fzp00i4Gf3F1fwna7VYUGO8BCY0FE/5q9pGOcWQT0+3NTDpTjhfrajgzjeeDn2Cc8+4Po3ghU8Un1daxBOa6WR1b4/s4vFKe63NQQoW2I8SprDfpY1nV5PXUDLTRajBxJuxhesk4zupl+TUUQ529cCUG0QEEVyjHnVl4wUh6bJDhasKq8msnQUI0ViTy16K5g8kfc081BQHc2hXQwKstKMqWId6B2B/uJCQ3m8ERGlKyrGeXAb7RCn5lMYOCIGvWlhY+DndXV5aWyXTmY5zmGcMgDC2GbwAf2Nf4px5iKsV4IZt/nGAAgnEd7KzA0chFuIWFaNBpY+7q0U+52aqHhu4WN+nvE8E78feHZSP0P/TPE7ozvZrS0vAJYsashYsAqm9XnlU6NjfpJMl6R0xWGfTc/feC1XcGo2813NAm++HzKcUY2pPGhGcP0BRn0Qqmgvaj64pU/pzGD11GAkovOxVsYNQF7OvCYmi3+36XoN6R6PAuvVs0G6P0bvDuKNLWd1v5hvjGLdbhoXiD/Rixap9TuEpJSAlFVJpQoAh0I78JseIJmtQYgMWmHZ74eIpoNl4/bFuVW5ajMPdAd2TevX7nYQqensepeKX1xDR9DWPJ2O7xnKKtvp4q9zHzxRB3HGw0RTYRDX4y9sipzE7vkWqeeJQaWe52GPYzqkVF5yXpLzHsF3X/22eFJSx//mD8090bLcfHPi9eitp8U6pazSHNHtbOkVW5e9oydKSoMKPk2ia+jJrgOVXkIit5oRlpJHyUAeNM89QNFr0hSbVVqSPk7EAno6510Q/Db9bRhIF92TEPc7z9/XaU2GzfWOgvUgE3m/s6AI/1zz501CiOhP/RjNv5+1NurdFIShQJiSvylXXG5KnqLSaO6wQWXx8dOi9PGFZ4I1NuYT4W7NlL6FEULL/5pyQSqLfuJxIxsg9AxWVPaNkgP8nJ/7QeMsYI/BF55qokpqbmDgMxHizWOAwkPt/AVWitkOmPYWrMZunqjobSM0j/BooYE/rKAiNAlNjZYmdDpRKUdaQInI/5oQfEPyjdtMcd3fM2zGpBlCpfW+x+GW58xbu4gMfPuUPZVcKPpu1eiT9eHfQe2mK3qH4sqyvrCYQvi49s5V2yUVDbZm5DJtm0dAEiS0IweKgiaX8lAGUQzHJXtMIlgEtPV8PN+N3nI9aIdoE=
Executes the following:
  • '<SYSTEM32>\wbem\wmiadap.exe' /R /T
  • '<SYSTEM32>\msiexec.exe' /V
Terminates or attempts to terminate
the following user processes:
  • opera.exe
  • firefox.exe
  • iexplore.exe
Modifies file system :
Creates the following files:
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\baaf5940b56ce61f5956d9680f812004.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\e1316b6811082821ae7408c074518395.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\3b5d467953500afc6ab8c9c540ec10c1.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\de45bfa3c5b6bb74069043e8c3526bfe.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\b726f40f42fb2c1033a86ce05cf1f75d.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\d50e30c0e00bd2bc85fc59d466a7c96e.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\93dd92e65cc3256258a3d9c30641cd16.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\d1c42de98bf6b14945101f9ef90752d8.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\7bc77a81b1829a0662c375d725e7f75a.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\14b09c62a7531fd91de97ab43e76e21a.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\60b3f0577112b6f23ab7fb1be417f0a3.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\installer.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\304e2e29ea3cec7e5a978e0ce591e74c.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\a1f2b816d922500a8be72981f152dd62.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\2188548bd024743e351653a92fb83ef4.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\a89b30cb4f29022bb202cb1dc67304cb.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\38e043d61c4529c197490fce4ef09d0b.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\ae1334576d327d8986f949e9e09dc6f0.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\abca4ae61834427906030ce8996dc57d.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\207.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\98.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\userCode\background.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\userCode\extension.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\13.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\78.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\102.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\47.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\17.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\options.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\463fd26ae90fbf4e728a56c12568986c.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\763828c9e15c6bcba8ddfbb224c4a260.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\browser.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\options.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\a953b9f2750b5b9b2b19f6dc4b14c53c.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\background.html
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\dialog.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\search_dialog.xul
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\ffCoreFilesIndex.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\skin.css
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button5.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button3.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon24.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button2.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon48.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\6f884672ca0a420cde0805546894f798.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\update.css
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\popup.html
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button1.png
  • %WINDIR%\Installer\3e139.msi
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite-journal
  • C:\Config.Msi\3e13c.rbs
  • %WINDIR%\Installer\MSIA.tmp
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\button4.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\panelarrow-up.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon16.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\crossrider_statusbar.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\skin\icon128.png
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\a530f2027518f5bf0a4ed49941a442c2.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\028bb427a9f48055fea1d13abcc27318.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\cf89f61db319cb5556997c850cc9d6e9.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\aa9f35c0cada0228c0840babbd6fde7e.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\695149570b3e493b984df085339cb24b.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\5183119dd1f6984bd5437674ae815870.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\098a4e7666842686969d740d81f8d269.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\e42cf254b6b545993cb88732521a1222.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\core\8cdcc3a8a439e6d15f67406bf02a72d6.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\630435cabe836a12300704ea9619ed6d.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\8bbb1b9a5be2a7e8b934f675da39d0d1.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\260759030a63a1e632629d9191dcf1c0.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\049ce0b9d966e2896955a6e773fb6804.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\2cb864184cde2774c95d51b4637a40bd.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\27a84092223531d6799ae95edb851737.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\300e384d56d470c22f3d8f928f045d69.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\34b1e0c04e296a0c2c91daed58266807.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\d7abf41f42786c5502f720178744855a.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome\content\api\df25fbc6abea9e6bc6b291d5b546ac90.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\72.js
  • %PROGRAM_FILES%\S10\48924.crx
  • %TEMP%\comh.80328\psuser.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\goopdate.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
  • %TEMP%\comh.80328\psmachine.dll
  • %TEMP%\comh.80328\goopdate.dll
  • %TEMP%\comh.80328\GoogleUpdateOnDemand.exe
  • %TEMP%\comh.80328\npGoogleUpdate4.dll
  • %TEMP%\comh.80328\goopdateres_en.dll
  • %PROGRAM_FILES%\S10\8c608567-314e-47b0-87c1-ac0da490fcc4-3.exe
  • %TEMP%\Cab4.tmp
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\C3E814D1CB223AFCD58214D14C3B7EAB
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\C3E814D1CB223AFCD58214D14C3B7EAB
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
  • %PROGRAM_FILES%\S10\360-48924.crx
  • %PROGRAM_FILES%\S10\1293297481.mxaddon
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
  • %TEMP%\nsr3.tmp\md5dll.dll
  • %TEMP%\nsr3.tmp\nsisos.dll
  • %TEMP%\nsr3.tmp\inetc.dll
  • %TEMP%\nsr3.tmp\UserInfo.dll
  • %TEMP%\nsr3.tmp\InstallerUtils2.dll
  • %TEMP%\nsr3.tmp\StdUtils.dll
  • %TEMP%\nsw2.tmp
  • %TEMP%\nsr3.tmp\InstallerUtils.dll
  • %TEMP%\nsr3.tmp\System.dll
  • %TEMP%\nsr3.tmp\update.json
  • %TEMP%\comh.80328\GoogleUpdate.exe
  • %TEMP%\comh.80328\GoogleCrashHandler.exe
  • %TEMP%\comh.80328\GoogleUpdateHelper.msi
  • %TEMP%\comh.80328\GoogleUpdateBroker.exe
  • %PROGRAM_FILES%\S10\Uninstall.exe
  • %PROGRAM_FILES%\S10\utils.exe
  • %TEMP%\nsr3.tmp\24924
  • %TEMP%\nsr3.tmp\58931
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\93.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\268.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\91.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\16.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\28.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins.json
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\chrome.manifest
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\183.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\manifest.xml
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\4.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\22.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\177.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\64.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\246.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\14.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\1.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\21.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\104.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\extensionData\plugins\182.js
  • %TEMP%\Cab8.tmp
  • %TEMP%\Cab6.tmp
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\8BD11C4A2318EC8E5A82462092971DEA
  • %PROGRAM_FILES%\S10\48924.xpi
  • %PROGRAM_FILES%\S10\8c608567-314e-47b0-87c1-ac0da490fcc4-4.exe
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\8BD11C4A2318EC8E5A82462092971DEA
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\psuser.dll
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\install.rdf
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\defaults\preferences\prefs.js
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\52c8b690-b0a8-4d67-9ecc-566aaa231f64@6a33300b-a82b-47a5-a6c3-4064823d6e72.com\locale\en-US\translations.dtd
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
  • %TEMP%\nsr3.tmp\ExecDos.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\psmachine.dll
  • %PROGRAM_FILES%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
  • %PROGRAM_FILES%\globalUpdate\Update\GoogleUpdate.exe
Deletes the following files:
  • %WINDIR%\Installer\3e139.msi
  • C:\Config.Msi\3e13c.rbs
  • %WINDIR%\Installer\3e13b.ipi
  • <SYSTEM32>\PerfStringBackup.TMP
  • <SYSTEM32>\wbem\Performance\WmiApRpl.ini
  • %WINDIR%\Installer\MSIA.tmp
  • %TEMP%\Cab4.tmp
  • %TEMP%\nsr3.tmp\24924
  • %TEMP%\Cab6.tmp
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite-journal
  • %TEMP%\Cab8.tmp
Network activity:
Connects to:
  • 'cr#.#hawte.com':80
  • 'www.download.windowsupdate.com':80
  • '97#####88.r.cdn77.net':80
  • 'ts####.ws.symantec.com':80
  • 'er####.datademoserv.com':80
  • 'up####.datademoserv.com':80
  • 'lo##.##tademoserv.com':80
  • 'st###.#atademoserv.com':80
TCP:
HTTP GET requests:
  • cr#.#hawte.com/ThawteTimestampingCA.crl
  • www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • ts####.ws.symantec.com/tss-ca-g2.crl
  • er####.datademoserv.com/ch-agent-error.gif?ac#######################################################################################################################################################################################################################################################################################################################################################################################################################################
  • 97#####88.r.cdn77.net/000841/update.json?rn####
  • er####.datademoserv.com/installer-error.gif?ac#######################################################################################################################################################################################################################################################################################################################################################################################################
  • up####.datademoserv.com/installer_updates/000841/update.json
  • st###.#atademoserv.com/installer.gif?ac###################################################################################################################################################################################################################################################################################################################################################################################################################################
  • www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
  • lo##.##tademoserv.com/monetization.gif?ev##############################################################################################################################################################################################################################################################################################################################################################
UDP:
  • DNS ASK cr#.#hawte.com
  • DNS ASK www.download.windowsupdate.com
  • DNS ASK 97#####88.r.cdn77.net
  • DNS ASK ts####.ws.symantec.com
  • DNS ASK er####.datademoserv.com
  • DNS ASK up####.datademoserv.com
  • DNS ASK lo##.##tademoserv.com
  • DNS ASK st###.#atademoserv.com
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android