マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.DownLoader8.28482

Added to the Dr.Web virus database: 2013-03-29

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'msn.exe' = '<DRIVERS>\csrss.exe'
Malicious functions:
Creates and executes the following:
  • <DRIVERS>\smss.exe 10.0.0.169 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.168 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.167 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.170 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.173 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.172 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.171 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.166 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.161 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.160 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.159 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.163 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.165 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.164 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.162 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.174 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.185 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.184 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.183 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.186 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.190 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.189 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.187 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.182 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.177 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.176 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.175 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.178 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.181 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.180 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.179 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.138 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.137 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.136 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.139 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.142 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.141 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.140 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.135 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.130 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.129 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.128 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.131 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.134 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.133 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.132 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.143 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.153 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.154 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.152 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.155 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.158 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.157 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.156 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.151 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.146 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.145 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.144 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.147 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.150 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.149 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.148 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.191 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.234 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.233 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.232 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.235 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.238 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.237 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.236 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.231 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.226 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.225 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.224 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.227 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.230 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.229 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.228 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.239 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.250 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.249 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.248 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.251 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.253 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.254 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.252 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.247 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.242 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.241 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.240 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.243 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.246 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.245 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.244 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.202 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.201 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.200 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.203 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.206 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.205 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.204 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.199 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.194 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.193 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.192 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.195 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.198 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.197 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.196 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.207 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.219 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.218 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.217 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.220 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.223 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.222 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.221 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.216 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.210 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.209 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.208 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.211 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.215 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.214 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.213 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.42 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.41 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.40 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.43 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.46 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.45 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.44 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.39 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.34 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.33 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.32 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.35 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.38 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.37 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.36 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.47 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.58 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.57 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.56 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.59 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.62 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.61 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.60 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.55 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.50 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.49 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.48 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.51 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.54 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.53 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.52 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.11 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.10 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.9 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.12 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.15 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.14 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.13 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.8 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.3 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.2 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\csrss.exe
  • <DRIVERS>\smss.exe 10.0.0.4 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.7 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.6 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.5 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.16 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.27 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.26 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.25 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.28 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.31 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.30 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.29 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.24 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.19 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.18 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.17 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.20 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.23 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.22 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.21 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.63 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.106 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.105 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.104 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.107 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.110 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.109 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.108 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.103 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.98 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.97 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.96 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.99 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.102 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.101 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.100 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.111 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.123 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.122 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.121 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.124 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.127 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.126 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.125 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.120 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.115 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.114 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.113 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.116 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.119 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.118 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.117 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.75 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.74 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.73 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.76 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.79 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.78 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.77 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.72 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.66 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.65 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.64 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.68 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.71 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.70 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.69 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.80 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.91 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.90 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.89 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.93 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.95 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.92 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.94 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.88 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.83 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.82 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.81 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.84 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.87 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.86 http://co##t.xj.cn/count/js/67.exe
  • <DRIVERS>\smss.exe 10.0.0.85 http://co##t.xj.cn/count/js/67.exe
Executes the following:
  • <SYSTEM32>\find.exe "IP Address"
  • <SYSTEM32>\ipconfig.exe
  • %WINDIR%\regedit.exe /s <DRIVERS>\1.txt
Injects code into
the following system processes:
  • <SYSTEM32>\svchost.exe
Modifies file system :
Creates the following files:
  • \Device\LanmanRedirector\10.0.0.7\pipe\browser
  • \Device\LanmanRedirector\10.0.0.6\pipe\browser
  • \Device\LanmanRedirector\10.0.0.5\pipe\browser
  • \Device\LanmanRedirector\10.0.0.8\pipe\browser
  • \Device\LanmanRedirector\10.0.0.11\pipe\browser
  • \Device\LanmanRedirector\10.0.0.10\pipe\browser
  • \Device\LanmanRedirector\10.0.0.9\pipe\browser
  • <DRIVERS>\smss.exe
  • <DRIVERS>\csrss.exe
  • <DRIVERS>\1.txt
  • %TEMP%\bt4041.bat
  • \Device\LanmanRedirector\10.0.0.4\pipe\browser
  • \Device\LanmanRedirector\10.0.0.3\pipe\browser
  • \Device\LanmanRedirector\10.0.0.2\pipe\browser
Sets the 'hidden' attribute to the following files:
  • %TEMP%\bt4041.bat
Deletes the following files:
  • %TEMP%\bt4041.bat
Network activity:
Connects to:
  • '<Private IP address>':80
  • '<Private IP address>':139
  • '<Private IP address>':445
Miscellaneous:
Searches for the following windows:
  • ClassName: 'RegEdit_RegEdit' WindowName: ''
  • ClassName: 'Indicator' WindowName: ''
  • ClassName: 'EDIT' WindowName: ''
  • ClassName: 'Shell_TrayWnd' WindowName: ''

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android