Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.DownLoader6.28437

Added to the Dr.Web virus database: 2012-07-10

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '%WINDIR%\svchost.exe'
Malicious functions:
To bypass firewall, removes or modifies the following registry keys:
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
Creates and executes the following:
  • %TEMP%\svchost.exe
  • %WINDIR%\svchost.exe
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\Plugin-Setup.exe
  • %TEMP%\svchost.exe (downloaded from the Internet)
Executes the following:
  • <SYSTEM32>\netsh.exe firewall set opmode Disable
Modifies file system :
Creates the following files:
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\001a\window\renascencepanel.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\001a\window\shop.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\001a\window\nopick_setting.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\001a\window\popbar.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\AutoAsist.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\001a\window\tools.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\001a\window\viewfightskill.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\001a\window\cover.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\TDLT.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\Thuthapgo.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\RungGai.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\Supercall.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\tool.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\VuotRao.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\Thuthapthaoduoc.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\tool.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\healthy.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\helpsprite.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\gutmodel.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\guttalk.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\NoEXPl.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\noPick.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\mgr.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\new4X.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\GetIDNPC.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\books.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\BuffTC.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\AutoCastLeftSkill.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\autotreasure.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\Confirm.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\fightassist.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\checkplugin.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\collection.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\miniclock.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\miniclock.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\lockaccount.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\lockaccount.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\MPGua.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\NangDong.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\MPGua.dat
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\MPGua.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\item.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\Compose.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\cuonghoa.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\AutoThuongHoi.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\compose.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\equip.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\Hoadang.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\cuonghoa_setting.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\enhance.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\auctionroom.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\AutoChiLing.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\unlock.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\unlock.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\Input0.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\AutoQuanDoanh.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\tool\AutoQuanDoanh.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\tiku.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\system.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\PkRecorder.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\PkRecorder.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\teamportrait.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\team_modify.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\system.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\teamportrait.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\playerpray.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\setting\item\001\other\xuanjing_002_s.spr
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\setting\item\001\other\xuanjing_lv4.spr
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\setting\item\001\other\scriptitem.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\setting\item\001\other\version.cfg
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\ui\001a\UI_POPBAR=552,518.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\ui\001a\window\cover.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\setting\misc\daytip.ini
  • %WINDIR%\svchost.exe
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\Plugin-Setup.exe
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\UI_PLAYERPANEL\zhenyuan.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\XemTruocCuongHoa\base.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\UI_PLAYERPANEL\viewwealthvalue.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\UI_PLAYERPANEL\viewwealthvalue.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\XemTruocCuongHoa\preview.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\XemTruocCuongHoa\PreViewMgr.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\XemTruocCuongHoa\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\XemTruocCuongHoa\preview.ini
  • <SYSTEM32>\autoexec1.bat
  • %TEMP%\aut3.tmp
  • %TEMP%\advsxbk
  • %TEMP%\aut2.tmp
  • %TEMP%\svchost.exe
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\auto.pluginkiemthe[1]
  • <SYSTEM32>\config1.sys
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\svchost[1].a3x
  • %TEMP%\aut1.tmp
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\ui\001b\window\cover.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\ui\001b\wndconfig.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\ui\001a\window\fightmode.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\ui\001a\wndconfig.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\Uninstall.exe
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\Uninstall.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\ui\001c\window\cover.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\ui\001c\wndconfig.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\x20exp.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\xuanjing.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\viewfightskill.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\worldmap_sub.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\autosay.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\AutoSay.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\zhenyuan.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\AutoReply.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\tools.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\renascencepanel.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\Scheduled.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\playname_ex.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\popbar.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\skillprogress.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\TenTPHK.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\shop.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Tools\script\window\shortcuts.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\UI_PLAYERPANEL\playerhonor_wealth.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\reply.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\reply2.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\UI_PLAYERPANEL\Scrip08.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\UI_PLAYERPANEL\Scrip09.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\UI_PLAYERPANEL\playerpanel.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\UI_PLAYERPANEL\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\msg.wav
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\hanhua.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\hanhua1.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\autosay2.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\AutoSay2.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\hanhua4.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\hanhua5.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\hanhua2.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\ui_autosay2\data\hanhua3.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\AutoLDS.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\UI_HETHONG.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\UI_TONGHOP.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\uiSayPanel.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\uiTaskTips.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\script\window\autofight.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\VatPhamDauGia.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\001a\window\autofight.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\uiMsgPad.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\selectnpc.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\partner.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\partner_setting.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\Train.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\Train.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\skillprogress.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\Tien_ich.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autoFollow\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autoFollow\selecttnpc.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autoFollow\key.dat
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autoFollow\main.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\CauCa\diaoyu.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\CauCa\diaoyu.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\CauCa\AutoJiaoYu.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\CauCa\diaoyu.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autoFollow\autoFollow.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\script\window\autoMedicine.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\script\window\auto_fight.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\script\window\autofightdata.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\script\window\autofight_setting.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\script\window\skilltree.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autoFollow\autoFollow.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\script\window\backtrack.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\btssl_autofight\script\window\knockBack.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_BaoVanDong\SelectTrainPos.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_BaoVanDong\SelectTrainPos.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_BaoVanDong\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_BaoVanDong\Remote.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_BaoVanDong\SuperBao.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Mail\auto_mail.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_BaoVanDong\SprBao_setting.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_BaoVanDong\SprBao_setting.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\AutoThief\plugincfg.ini
  • %TEMP%\$inst\5.tmp
  • %TEMP%\$inst\temp_0.tmp
  • %TEMP%\$inst\2.tmp
  • %TEMP%\$inst\4.tmp
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\AutoThief\AutoThief.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\AutoThief\AutoThiefpanel.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\image\ui\001a\common\mouse\win2k_normal.cur
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\image\ui\001a\common\mouse\win2k_pickitem.cur
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\HauPhucNguuSon.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\HeThong.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\BeepTimes.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\CDKB5.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\OnTeamApplyAdd.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\partner.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\LevelAward.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\LichHoatDong.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\BachManSon.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Mail\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Mail\Tools_mail.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Mail\mail.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Mail\mail_client.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\autotheosau.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\AutoTruyNa.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\AutoHLVM.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Auto_Phuongtmp\AutoPartner.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\CauCa\diaoyu1.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\supermaplink\maplink_ui.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\supermaplink\maplink_ui.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\setting\map\wanted_killnpc.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\setting\map\worldmap.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\supermaplink\ReloadCH.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\supermaplink\supermaplink.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\supermaplink\myui.dll
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\supermaplink\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\setting\map\treasuremap_pos.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\TDC.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\TDLT.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\Reload.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\setting\map\maplist.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\setting\map\transmit.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\VSV.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\setting\ct_enemys.wav
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_GiaoDich\itembox.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_GiaoDich\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_GiaoDich\extbagmodify.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\AutoGetAward.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\AutoLDC.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_GiaoDich\trade.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\AutoAnswer.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\playerstate.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\fightsprite.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\image\life_green.spr
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\autoMedicine.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\fightsprite.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\image\mana.spr
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\peresplus_setting.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\image\life_red.spr
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_ChienDau\image\life_yellow.spr
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\zhanhunbag.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\zhanhunbag.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\repository.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\throwAway.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\NhiemVuChinhTuyen\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\NhiemVuChinhTuyen\UI_CHINHTUYEN.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\interfacemanagercfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\NhiemVuChinhTuyen\NhiemVuChinhTuyen.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\repository.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\itembox.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\itembox.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\CauCa\diaoyu1.txt
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\CauCa\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\orderbag_logic.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\plugincfg.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\orderbag.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Hanhtrang_Ruong\orderbag_compare.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\BuyCointTDLT.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\BuyCointVSV.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\BuyCoint.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\BuyCointTDC.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\CheckPhucLoiTDLT.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\CheckPhucLoiVSV.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\CheckPhucLoi.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Recipe\CheckPhucLoiTDC.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Phuongtmp\XiaKe.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\NhiemVuChinhTuyen\UI_TONGHOP.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Phuongtmp\CTC.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\NhiemVuChinhTuyen\ui_chinhtuyen.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\NhiemVuChinhTuyen\UI_HETHONG.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Phuongtmp\TeamControl.ini
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Phuongtmp\TeamControl.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Phuongtmp\member.lua
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Phuongtmp\plugincfg.ini
Sets the 'hidden' attribute to the following files:
  • %WINDIR%\svchost.exe
  • %PROGRAM_FILES%\Company\Plugin_Hoahong_{13-06-2012}\interface\Support_phuongtmp\NangDong.lua
Deletes the following files:
  • %TEMP%\aut2.tmp
  • %TEMP%\advsxbk
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\svchost[1].a3x
  • %TEMP%\aut3.tmp
  • %TEMP%\aut1.tmp
  • %TEMP%\$inst\2.tmp
  • %TEMP%\$inst\temp_0.tmp
  • %TEMP%\$inst\5.tmp
  • %TEMP%\$inst\4.tmp
Network activity:
Connects to:
  • 'au##.##uginkiemthe.com':80
  • 'localhost':1037
  • 'an##me.info':80
TCP:
HTTP GET requests:
  • au##.##uginkiemthe.com/
  • an##me.info/files/svchost.a3x
UDP:
  • DNS ASK au##.##uginkiemthe.com
  • DNS ASK an##me.info
Miscellaneous:
Searches for the following windows:
  • ClassName: 'IEFrame' WindowName: ''
  • ClassName: 'MS_AutodialMonitor' WindowName: ''
  • ClassName: 'MS_WebcheckMonitor' WindowName: ''
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: '' WindowName: 'GINA Logon'
  • ClassName: '' WindowName: ''

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android