Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.MulDrop4.27586

Added to the Dr.Web virus database: 2013-03-25

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run] '360safe' = '%WINDIR%\Fonts\wuauclt.exe'
Malicious functions:
Creates and executes the following:
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.175 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.176 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.173 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.174 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.179 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.180 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.177 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.178 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.167 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.168 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.165 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.166 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.171 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.172 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.169 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.170 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.181 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.192 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.193 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.190 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.191 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.196 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.197 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.194 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.195 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.184 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.185 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.182 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.183 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.188 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.189 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.186 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.187 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.142 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.143 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.140 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.141 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.146 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.147 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.144 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.145 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.134 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.135 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.132 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.133 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.138 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.139 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.136 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.137 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.148 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.159 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.160 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.157 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.158 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.163 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.164 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.161 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.162 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.151 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.152 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.149 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.150 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.155 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.156 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.153 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.154 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.198 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.242 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.243 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.240 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.241 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.246 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.247 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.244 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.245 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.234 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.235 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.232 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.233 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.238 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.239 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.236 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.237 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.248 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=5444
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=3828
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=4884
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=5352
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=4372
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=3012
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=3784
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=2736
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.251 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.252 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.249 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.250 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.255 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe /pid=4840
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.253 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.254 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.209 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.210 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.207 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.208 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.213 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.214 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.211 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.212 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.201 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.202 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.199 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.200 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.205 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.206 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.203 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.204 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.215 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.226 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.227 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.224 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.225 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.230 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.231 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.228 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.229 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.218 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.219 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.216 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.217 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.222 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.223 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.220 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.221 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.42 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.43 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.40 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.41 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.46 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.47 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.44 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.45 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.34 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.35 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.32 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.33 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.38 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.39 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.36 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.37 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.48 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.59 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.60 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.57 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.58 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.63 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.64 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.61 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.62 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.51 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.52 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.49 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.50 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.55 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.56 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.53 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.54 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.9 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.10 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.7 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.8 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.13 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.14 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.11 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.12 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.1 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.2 http://f.##c8.com/xx.exe
  • %WINDIR%\Fonts\TIMPIatform.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.0 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.5 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.6 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.3 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.4 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.15 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.26 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.27 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.24 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.25 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.30 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.31 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.28 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.29 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.18 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.19 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.16 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.17 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.22 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.23 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.20 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.21 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.65 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.109 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.110 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.107 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.108 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.113 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.114 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.111 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.112 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.101 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.102 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.99 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.100 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.105 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.106 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.103 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.104 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.115 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.126 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.127 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.124 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.125 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.130 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.131 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.128 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.129 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.118 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.119 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.116 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.117 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.122 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.123 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.120 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.121 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.76 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.77 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.74 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.75 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.80 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.81 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.78 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.79 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.68 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.69 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.66 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.67 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.72 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.73 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.70 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.71 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.82 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.93 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.94 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.91 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.92 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.97 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.98 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.95 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.96 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.85 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.86 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.83 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.84 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.89 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.90 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.87 http://f.##c8.com/xx.exe
  • %WINDIR%\Downloaded Program Files\explorer.exe 10.0.0.88 http://f.##c8.com/xx.exe
Injects code into
the following system processes:
  • <SYSTEM32>\svchost.exe
Sets a new unauthorized home page for Windows Internet Explorer.
Modifies file system :
Creates the following files:
  • \Device\LanmanRedirector\10.0.0.6\pipe\browser
  • \Device\LanmanRedirector\10.0.0.5\pipe\browser
  • \Device\LanmanRedirector\10.0.0.4\pipe\browser
  • \Device\LanmanRedirector\10.0.0.9\pipe\browser
  • \Device\LanmanRedirector\10.0.0.8\pipe\browser
  • \Device\LanmanRedirector\10.0.0.7\pipe\browser
  • \Device\LanmanRedirector\10.0.0.3\pipe\browser
  • %WINDIR%\Downloaded Program Files\explorer.exe
  • %WINDIR%\Fonts\TIMPIatform.exe
  • %WINDIR%\Fonts\wuauclt.exe
  • \Device\LanmanRedirector\10.0.0.2\pipe\browser
  • \Device\LanmanRedirector\10.0.0.1\pipe\browser
  • \Device\LanmanRedirector\10.0.0.0\pipe\browser
Network activity:
Connects to:
  • '<Private IP address>':80
  • '<Private IP address>':139
  • '<Private IP address>':445

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android