マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.MulDrop11.19718

Added to the Dr.Web virus database: 2019-10-09

Virus description added:

Technical Information

To ensure autorun and distribution
Creates the following services
  • [<HKLM>\System\CurrentControlSet\Services\LDrvSvc] 'ImagePath' = '<SYSTEM32>\svchost.exe -k LocalDriverService'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\LDrvSvc] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\CurrentControlSet\Services\LDrvSvc\Parameters] 'ServiceDll' = '%ProgramFiles(x86)%\DTLSoft\DriveTheLife\LDrvSvc.dll'
  • [<HKLM>\System\CurrentControlSet\Services\LDrvPro] 'Start' = '00000000'
  • [<HKLM>\System\CurrentControlSet\Services\LDrvPro] 'ImagePath' = 'system32\drivers\LDrvPro64.sys'
  • [<HKLM>\SYSTEM\ControlSet001\services\LDrvPro] 'Start' = '00000000'
  • [<HKLM>\SYSTEM\ControlSet001\services\LDrvPro] 'ImagePath' = 'system32\drivers\LDrvPro64.sys'
  • [<HKLM>\System\CurrentControlSet\Services\dtldrvhelp] 'ImagePath' = '%ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrvhelp64.sys'
Modifies file system
Creates the following files
  • %TEMP%\libcurl.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\bin\cpuidsdk.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlupdater\checkupdate.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlupdater\checkprocess.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\bios.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\atl71.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\atl71.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\detoured.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\bin\cpuidsdk64.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\7z.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\xlbugreport.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\xlbugreport.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\userfeedback.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\uninstall.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\traytool.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\appconfig.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\drv32_usb.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\devcfg.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlconfig.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlautosetup.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\dstudp.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dstudp.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\drvsrc.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drvsrc.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drvget.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drvfilesrc.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drvbak.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drvallrepair.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\download_engine.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\download_engine.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\dl_peer_id.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\dl_peer_id.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\difxapi.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\tips.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\7z.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\signfile.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\onekeyinst.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\newfeatures.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\wdmaudio\win7_x86\wdmaudio.inf
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\autosetup\filter.proc
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\wdmaudio\win8.1_x64\wdmaudio.inf
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\wdmaudio\win8.1_x86\wdmaudio.inf
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\wdmaudio\win8_x64\wdmaudio.inf
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\wdmaudio\win8_x86\wdmaudio.inf
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\wdmaudio\win7_x64\wdmaudio.inf
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\devicemanuf.db3
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\dev64.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\key.dat
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\id.dat
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\id.dat
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\bin\hdcore.dat
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\helper_res.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv3\drv6.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlcrashcatch.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\difxapi.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drivethelife.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\drv64_usb.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\dev32.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\minithunderplatform.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\minithunderplatform.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\hwbox.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\help_ui.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hdtool.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtl_net_tool.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtl_helpme.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtl_drvprotect.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtl_browser.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlupdater\dtlupg.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlservice.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlcrashreport.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\drvsigner64.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\drvsigner.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\drv64.exe
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\libcurl.dll
  • %WINDIR%\temp\udde7e1.tmp
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlnetdevice.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\uninst.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\udp.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\udp.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\tipsdll.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\substat.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\substat.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\usbenum.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\uninstall.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\sqlite3.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\sqlcache.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\softlocalcheck.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\softconfig.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\sftm_localsft.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\bin\sendto.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\substat.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrvcheck.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\xlbughandler.dll
  • <DRIVERS>\ldrvpro64.sys
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlconfig\userconfig.dat
  • %PROGRAMDATA%\microsoft\windows\start menu\programs\驱动人生\卸载驱动人生6.lnk
  • %PROGRAMDATA%\microsoft\windows\start menu\programs\驱动人生\驱动人生6.lnk
  • C:\users\public\desktop\驱动人生6.lnk
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\uninst.dar1
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\uninst.dar0
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\ldrvpro64.sys
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\ldrvpro.sys
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrvhelp64.sys
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrvhelp.sys
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\zlib1.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\zlib1.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\xldl.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\xldl.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\qrencode.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\sqlite3.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\protectcore.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\posturl.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\pnpdrv.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\gzipdll.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\infdrvsetup.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwinfo.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\helper.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\helpcore.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\bin\hardwareinfo.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\gzipdll.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\feedback.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\ldrvsvc.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtluninst.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dtlui.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\dtlui.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlui.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlsubmit.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlplug.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrvuninst.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv0\drv6.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\libcurl.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\minizip.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\ldrvproctrl.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\pcidrv.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\pcidetect.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\pcid.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\pcid.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\bin\pcid.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\p2spd.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\p2spd.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\netdrvcore.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\msvcr71.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\msvcr71.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\msvcp71.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\download\msvcp71.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\monreboot.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\minizip.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\libcurl.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\download\xlbughandler.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv3\drv5.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv1\drv0.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\btn_bg.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\game_page\bj.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\bios_board.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\game_page\bg_newyear.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\bg2.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\bg1.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\closewindown.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\game_page\closewindown.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\8033_48_1450410427.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\8028_48.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\7_48_1458184328.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\702_48.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\701_48.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\6944_48_1371609262.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\bg.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\1841_48_1402968904.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\computer.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\ie.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\hwcheckvr.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\hwcheck.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\hhd_png.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\hhd_image.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\green_btn.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\game_check.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\game.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\game_page\error.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\dx.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\down_stop1.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\display.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\desktop2.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\desktop.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\cpu.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\635519924973657500.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\9601_48x48.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\635488182880255000.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\635224430556216250.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\635224430069341250.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\635945191665798750.jpg
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\1202_48_1384933060.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\1103_48_1387247768.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\10455_48_1377491722.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\103_48_1449798959.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\10314_48_1378453152.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\101_48_1398302313.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\skin\ad_image\20150120wan.jpg
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\12860_48_1397731628.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\skin\ad_image\20150120rili.jpg
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\skin\ad_image\20150120160wifi.jpg
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\vr_loading.gif
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\basic_logo_gif_1.gif
  • %TEMP%\dtl6_wnqd_pcol_silent.exe
  • %TEMP%\resdll.dll
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\laptop.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\contact.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\12_48_1449644161.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\200_48_1421902088.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\12757_48_1392886772.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\635198668781881250.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\56622_48_1402026661.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\501_48.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\4514_48_1447659631.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\4510_48_1444894569.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\3800_48.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\3162_48_1451892075.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\302_48_1450768888.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\2_48_1463041125.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\2904_48_1450145943.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\2902_48_1440573504.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\21707_48_1430792959.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\21499_48_1423036554.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\20832_48_1411460034.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\1855_48_1386734611.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\recommend.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv3\drv4.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\loading.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\what is new.txt
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\hwbox_xml\wnd_gamecheck.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlconfig\wndconfigdata.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\wndconfigdata.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\drv64\wndautodata.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\bin\vr_info.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\bin\display.ini
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\lan\chinese.ini
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\lan\lan.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\hwbox_xml\hwparampage_list.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\hwbox_xml\hwlogopage_list.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\hwbox_xml\hwinfo_list.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\hwbox_xml\hhd_info_list.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\lan\hdcheck_2052.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlconfig\unsetup.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\link.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv0\drv0.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv0\drv4.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv3\drv3.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv2\drv3.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv1\drv3.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv0\drv3.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv2\drv2.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv3\drv2.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv1\drv2.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv0\drv2.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv2\drv1.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv3\drv1.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv1\drv1.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv0\drv1.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv2\drv0.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv3\drv0.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlconfig\dtlsetup.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\hwbox_xml\main_frame.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtlconfig\all_in_one_machine_cpu_moudle.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\skin\ad_image\ad.xml
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\hwbox.ico
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\memory.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\power_up.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\png_display_table.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\notebook.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\monitor.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\minwindown.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\menu.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\main_soft.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\progresss.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\main_pnp.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\main_manage.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\main_dock.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\main_btn_skin.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\logo.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\game_page\logo.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\list_bg.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\dtldrv\dtldrv0\drv5.7zz
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\progress_green_blue_2.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\spent_line.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\processs_bg.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\res\dtl.ico
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\onekeyinst\dataconfig\icon\xlacc2901_48x48.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\weibo_weixiang.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\weibo_sina.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\weibo_qq.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\weibo_btn.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\vrunknow.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\vrok.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\vrnook.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\text_mask.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\text_line_bk.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\tempmonitor.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\system_install_time.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\system.png
  • %ProgramFiles(x86)%\dtlsoft\drivethelife\hwbox\skin\png\screennt_png.png
  • %WINDIR%\temp\uddedfd.tmp
Deletes the following files
  • %WINDIR%\temp\udde7e1.tmp
  • %WINDIR%\temp\uddedfd.tmp
Network activity
UDP
  • DNS ASK in#.#pdrv.com
  • DNS ASK 16#.com
  • DNS ASK so#####fig.updrv.com
  • DNS ASK dt####ate.updrv.com
  • DNS ASK di######.integrate.updrv.com
  • DNS ASK di####ch.updrv.com
  • DNS ASK in#####.integrate.updrv.com
  • '11#.#07.166.205':3000
  • '11#.#07.166.205':4000
Miscellaneous
Searches for the following windows
  • ClassName: 'dtl_inst_univeral_2012' WindowName: ''
Creates and executes the following
  • '%TEMP%\dtl6_wnqd_pcol_silent.exe' -s
  • '%ProgramFiles(x86)%\dtlsoft\drivethelife\hdtool.exe' -hdi
  • '%WINDIR%\syswow64\cmd.exe' /C ping www.16#.com' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /C ping www.16#.com
  • '%WINDIR%\syswow64\ping.exe' www.16#.com
  • '%WINDIR%\syswow64\svchost.exe' -k LocalDriverService

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android