Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.MulDrop4.29739

Added to the Dr.Web virus database: 2013-03-31

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run] '360safe' = '%WINDIR%\Fonts\wuauclt.exe'
Creates or modifies the following files:
  • %WINDIR%\Tasks\SA.PIF
Malicious functions:
Creates and executes the following:
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.174 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.175 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.172 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.173 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.178 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.179 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.176 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.177 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.166 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.167 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.164 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.165 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.170 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.171 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.168 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.169 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.180 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.191 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.192 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.189 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.190 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.195 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.196 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.193 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.194 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.183 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.184 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.181 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.182 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.187 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.188 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.185 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.186 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.141 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.142 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.139 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.140 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.145 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.146 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.143 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.144 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.133 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.134 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.131 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.132 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.137 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.138 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.135 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.136 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.147 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.158 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.159 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.156 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.157 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.162 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.163 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.160 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.161 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.150 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.151 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.148 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.149 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.154 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.155 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.152 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.153 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.240 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.241 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.238 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.239 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.244 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.245 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.242 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.243 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.232 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.233 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.230 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.231 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.236 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.237 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.234 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.235 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.246 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe /pid=2804
  • %WINDIR%\Downloaded Program Files\alg.exe /pid=980
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.255 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe /pid=624
  • %WINDIR%\Downloaded Program Files\alg.exe /pid=5840
  • %WINDIR%\Downloaded Program Files\alg.exe /pid=3532
  • %WINDIR%\Downloaded Program Files\alg.exe /pid=6080
  • %WINDIR%\Downloaded Program Files\alg.exe /pid=5772
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.249 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.250 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.247 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.248 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.253 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.254 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.251 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.252 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.207 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.208 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.205 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.206 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.211 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.212 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.209 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.210 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.199 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.200 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.197 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.198 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.203 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.204 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.201 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.202 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.213 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.224 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.225 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.222 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.223 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.228 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.229 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.226 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.227 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.216 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.217 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.214 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.215 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.220 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.221 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.218 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.219 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.42 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.43 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.40 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.41 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.46 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.47 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.44 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.45 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.34 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.35 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.32 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.33 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.38 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.39 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.36 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.37 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.48 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.59 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.60 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.57 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.58 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.63 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.64 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.61 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.62 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.51 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.52 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.49 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.50 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.55 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.56 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.53 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.54 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.10 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.11 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.8 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.9 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.14 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.15 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.12 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.13 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.2 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.3 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.0 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.1 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.6 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.7 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.4 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.5 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.16 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.26 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.27 http://i.##c8.com/bb.css
  • %WINDIR%\Fonts\T1MPLatform.exe
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.25 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.30 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.31 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.28 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.29 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.19 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.20 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.17 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.18 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.23 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.24 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.21 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.22 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.108 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.109 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.106 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.107 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.112 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.113 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.110 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.111 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.100 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.101 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.98 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.99 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.104 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.105 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.102 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.103 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.114 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.125 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.126 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.123 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.124 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.129 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.130 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.127 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.128 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.117 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.118 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.115 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.116 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.121 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.122 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.119 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.120 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.75 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.76 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.73 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.74 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.79 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.80 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.77 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.78 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.67 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.68 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.65 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.66 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.71 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.72 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.69 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.70 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.81 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.92 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.93 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.90 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.91 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.96 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.97 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.94 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.95 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.84 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.85 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.82 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.83 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.88 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.89 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.86 http://i.##c8.com/bb.css
  • %WINDIR%\Downloaded Program Files\alg.exe 10.0.0.87 http://i.##c8.com/bb.css
Injects code into
the following system processes:
  • <SYSTEM32>\svchost.exe
Sets a new unauthorized home page for Windows Internet Explorer.
Modifies file system :
Creates the following files:
  • \Device\LanmanRedirector\10.0.0.7\pipe\browser
  • \Device\LanmanRedirector\10.0.0.6\pipe\browser
  • \Device\LanmanRedirector\10.0.0.5\pipe\browser
  • \Device\LanmanRedirector\10.0.0.8\pipe\browser
  • %WINDIR%\Fonts\T1MPLatform.exe
  • \Device\LanmanRedirector\10.0.0.9\pipe\browser
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\y[1].gif
  • \Device\LanmanRedirector\10.0.0.0\pipe\browser
  • %WINDIR%\Downloaded Program Files\alg.exe
  • %WINDIR%\Fonts\wuauclt.exe
  • \Device\LanmanRedirector\10.0.0.1\pipe\browser
  • \Device\LanmanRedirector\10.0.0.4\pipe\browser
  • \Device\LanmanRedirector\10.0.0.3\pipe\browser
  • \Device\LanmanRedirector\10.0.0.2\pipe\browser
Network activity:
Connects to:
  • '<Private IP address>':139
  • '<Private IP address>':80
  • 'i.##c8.com':80
  • 'localhost':1036
  • '<Private IP address>':445
TCP:
HTTP GET requests:
  • i.##c8.com/dd/y.gif
UDP:
  • DNS ASK i.##c8.com

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android