La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Trojan.MulDrop5.52420

Aggiunto al database dei virus Dr.Web: 2015-05-01

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run] '360safe' = '%WINDIR%\Fonts\wuauclt.exe'
Malicious functions:
Creates and executes the following:
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.171 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.172 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.169 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.170 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.175 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.176 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.173 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.174 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.163 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.164 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.161 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.162 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.167 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.168 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.165 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.166 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.187 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.188 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.185 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.186 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.191 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.192 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.189 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.190 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.179 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.180 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.177 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.178 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.183 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.184 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.181 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.182 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.139 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.140 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.137 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.138 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.143 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.144 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.141 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.142 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.131 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.132 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.129 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.130 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.135 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.136 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.133 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.134 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.155 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.156 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.153 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.154 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.159 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.160 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.157 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.158 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.147 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.148 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.145 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.146 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.151 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.152 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.149 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.150 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.193 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.236 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.237 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.234 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.235 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.240 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.241 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.238 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.239 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.228 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.229 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.226 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.227 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.232 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.233 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.230 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.231 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.252 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.253 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.250 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.251 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' /pid=3168
  • '%WINDIR%\Downloaded Program Files\explorer.exe' <Auxiliary element>
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.254 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.255 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.244 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.245 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.242 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.243 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.248 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.249 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.246 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.247 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.204 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.205 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.202 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.203 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.208 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.209 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.206 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.207 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.196 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.197 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.194 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.195 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.200 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.201 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.198 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.199 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.220 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.221 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.218 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.219 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.224 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.225 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.222 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.223 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.212 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.213 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.210 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.211 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.216 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.217 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.214 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.215 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.128 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.41 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.42 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.39 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.40 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.45 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.46 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.43 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.44 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.33 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.34 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.31 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.32 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.37 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.38 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.35 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.36 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.57 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.58 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.55 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.56 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.61 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.62 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.59 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.60 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.49 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.50 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.47 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.48 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.53 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.54 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.51 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.52 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.9 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.10 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.7 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.8 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.13 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.14 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.11 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.12 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.1 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.2 http://e.##c8.com/xx.exe
  • '%WINDIR%\Fonts\TIMPIatform.exe'
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.0 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.5 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.6 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.3 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.4 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.25 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.26 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.23 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.24 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.29 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.30 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.27 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.28 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.17 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.18 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.15 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.16 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.21 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.22 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.19 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.20 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.63 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.106 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.107 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.104 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.105 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.110 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.111 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.108 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.109 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.98 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.99 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.96 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.97 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.102 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.103 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.100 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.101 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.122 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.123 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.120 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.121 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.126 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.127 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.124 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.125 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.114 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.115 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.112 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.113 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.118 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.119 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.116 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.117 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.74 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.75 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.72 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.73 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.78 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.79 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.76 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.77 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.66 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.67 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.64 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.65 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.70 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.71 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.68 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.69 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.90 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.91 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.88 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.89 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.94 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.95 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.92 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.93 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.82 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.83 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.80 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.81 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.86 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.87 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.84 http://e.##c8.com/xx.exe
  • '%WINDIR%\Downloaded Program Files\explorer.exe' 10.0.0.85 http://e.##c8.com/xx.exe
Sets a new unauthorized home page for Windows Internet Explorer.
Modifies file system :
Creates the following files:
  • \Device\LanmanRedirector\10.0.0.6\pipe\browser
  • \Device\LanmanRedirector\10.0.0.8\pipe\browser
  • \Device\LanmanRedirector\10.0.0.5\pipe\browser
  • \Device\LanmanRedirector\10.0.0.7\pipe\browser
  • <Auxiliary element>
  • \Device\LanmanRedirector\10.0.0.12\pipe\browser
  • \Device\LanmanRedirector\10.0.0.10\pipe\browser
  • %WINDIR%\Downloaded Program Files\explorer.exe
  • %WINDIR%\Fonts\TIMPIatform.exe
  • %WINDIR%\Fonts\wuauclt.exe
  • \Device\LanmanRedirector\10.0.0.0\pipe\browser
  • \Device\LanmanRedirector\10.0.0.4\pipe\browser
  • \Device\LanmanRedirector\10.0.0.2\pipe\browser
  • \Device\LanmanRedirector\10.0.0.3\pipe\browser
Network activity:
Connects to:
  • '<Private IP address>':80
  • '<Private IP address>':139
  • '<Private IP address>':445

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android