Library
My library

+ Add to library

Profile

Trojan.DownLoader34.16821

Added to the Dr.Web virus database: 2020-08-02

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\Software\Classes\4366\shell\open\command] '' = '"%APPDATA%\duowan\4366Game\Launcher.exe" %1'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '4366GameHall' = '"%APPDATA%\duowan\4366Game\Launcher.exe"'
Modifies file system
Creates the following files
  • %TEMP%\nss8aed.tmp\system.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\minbutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\morebutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\msgbox\gp_closebutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\msgbox\gp_custombutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\msgbox\gp_exclamatory.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\msgbox\gp_msgbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\narrowbutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\popbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\popbottom.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\popbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\popclose.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\maxbutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\mainmenu\setupitem.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\pop_combo_btn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\pop_combo_edit.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\pop_combo_list.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\pop_listbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\pop_subtabitem.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\quit\quitbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\quit\quitcheck.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\quit\quitclose.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\quit\quitstay.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\recharge.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\renovate.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\pop_btn_delete.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\pop_btn_enter.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\clock\startbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\pop_btn_edit.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\homepage.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\custom\custom_cbx_btn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\custom\custom_cbx_listframe.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\custom\custom_checkbox.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\custom\custom_frame.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\custom\custom_lb_scrollbar.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\custom\custom_poplist_scrollbar.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\custom\custom_radiobutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\customservice.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\exitfullscreen.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\exitmenu.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\fullscreen.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\login.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\mainmenu\aboutitem.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\logo.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\jifenicon.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\lable_4366.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\lable_clock.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\lable_logo.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\lable_qq.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\lable_setup.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\lable_xiaohao.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\lable_yy.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\listctrlbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\listctrlframe.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\ll.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\gift.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\imlogin.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\closebutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\correct.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\repairattentionbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\daemonservice.exe
  • %APPDATA%\duowan\4366game\3.0.0.20\dmmain.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\gpbase.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\gplatform.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\gplogin.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\gpluginmgr.exe
  • %APPDATA%\duowan\4366game\3.0.0.20\gprender.exe
  • %APPDATA%\duowan\4366game\3.0.0.20\ipc.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\launcher.exe
  • %APPDATA%\duowan\4366game\3.0.0.20\msvcp100.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\msvcr100.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\bugreport.exe
  • %APPDATA%\duowan\4366game\3.0.0.20\crashreport.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\outplugins\gpdnshelper.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\taskmodulehttp.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\update.exe
  • %APPDATA%\duowan\4366game\3.0.0.20\updateclient.dll
  • %HOMEPATH%\desktop\4366óîï·´óìü.lnk
  • %APPDATA%\duowan\4366game\4366óîï·´óìü.lnk
  • %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\4366óîï·´óìü.lnk
  • %APPDATA%\microsoft\windows\start menu\programs\4366óîï·´óìü\4366óîï·´óìü.lnk
  • %APPDATA%\duowan\4366game\version.ini
  • %APPDATA%\duowan\4366game\config.ini
  • %APPDATA%\log\2020-08-02_gprender.log
  • %APPDATA%\log\2020-08-02_gplatform.log
  • %APPDATA%\duowan\4366game\3.0.0.20\outplugins\gplog.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\outplugins\gprenderproxy.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\progressbar.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\incorrect.png
  • %APPDATA%\duowan\4366game\3.0.0.20\renderplugins.cfg
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\repairbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\repairbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\repaircancelbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\repairico.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\repairprocessbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\repairresultbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\restorebutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\setupbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\setup_tabitem.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\stop.png
  • %APPDATA%\duowan\4366game\3.0.0.20\renderpluginsd.cfg
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\repair\progressbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\update.ini
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\loading.gif
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\subtab_lbzx.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\subtab_pageicon.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\subtab_wjzx.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\tab_close.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\tab_skin.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\update\updatebg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\update\updateloop.gif
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\xiaohao.png
  • %APPDATA%\duowan\4366game\3.0.0.20\plugins.cfg
  • %APPDATA%\duowan\4366game\3.0.0.20\pluginsd.cfg
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\subtab_deficon.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\subtab_home.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\tabctrl\subtab_hozx.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\clock\clockwarn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\clock\clockclose.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\clock\clockbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_dropdownbox.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_dropdownboxinner.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_dropdowncosebtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_editframe.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_head.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_loginbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_loginerrbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_loginerrclosebtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_loginpiccodeinputbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_mainbgorangebottom.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_menuexit.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_checkbox.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\custom_checkbox.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_bg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_qqloginbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_qqloginclosebtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_qqloginrefreshbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_qqrecommend.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_registerbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_scrollbar.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_usrlistdefhead.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_yyloginbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\btn-reboot.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\cbx-frame.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\custom_cbx_btn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_normalbtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_minibtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_qqloginbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\dmindex.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_loginmain.xml
  • %TEMP%\nss8aed.tmp\nsutil.dll
  • %TEMP%\nss8aed.tmp\nscurl.dll
  • %TEMP%\nss8aed.tmp\nsdm.dll
  • %TEMP%\nss8aed.tmp\bgworker.dll
  • %APPDATA%\duowan\4366game\launcher.exe
  • %APPDATA%\duowan\4366game\product.7z
  • %TEMP%\nss8aed.tmp\nsis7z.dll
  • %APPDATA%\duowan\4366game\3.0.0.20\gpcommoncfg\plugin-dns.cfg
  • %APPDATA%\duowan\4366game\3.0.0.20\gplog.cfg
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\dmindex.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_ie.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_accountpulldown.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\custom_lb_scrollbar.png
  • %TEMP%\nss8aed.tmp\skin.zip
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_loginpiccode.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_netsetup.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_qqloginmain.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_registermain.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_registermain_higher.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_traymenu.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_yyloginmain.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\global.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\loginerror.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\update.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\dmindex.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_loginingmsgbox.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\layout\xml\dui_loginerror.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\gplogin_closebtn.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\custom_poplist_scrollbar.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\global.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\mainmenu.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\msgbox.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\quitwnd.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\repair.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\repairattention.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\repairprocess.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\repairresult.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\setup.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\update.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\xiaohaoadd.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\exitmenu.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\conflitalert.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\main.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\xiaohaomenu.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\about\aboutclose.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\accountbutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\accountmenu\accountmenu.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\accountmenu\switchitem.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\activepop\active_bg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\activepop\active_close.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\activepop\active_open.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\alarmclock.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\bg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\cbx_frame.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\dmindex.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\dmindex.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\themes\theme0\image\about\aboutbg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\dui_ie.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\clockpopwnd.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\custom_radiobutton.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\popclose.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\pop_cbx_list.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\setup-bg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\update\gplogin_updatebg.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\update\gplogin_updateloop.gif
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderlog.cfg
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\layout\config\cefs.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\layout\config\cfgs.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\layout\config\plugin-gpdnshelper.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\layout\config\urls.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\layout\dmindex.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\layout\xml\global.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gploginres\themes\theme0\image\net-setup\net-setup.png
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\layout\xml\main.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\themes\theme0\dmindex.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\config\cfgs.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\config\plugin-gpdnshelper.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\config\subtaburls.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\config\urls.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\dmindex.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\aboutwnd.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\accountmenu.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\active_popwnd.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\clockadd.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\clockmenu.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gpres\layout\xml\clockmod.xml
  • %APPDATA%\duowan\4366game\3.0.0.20\gprenderres\themes\dmindex.xml
  • %APPDATA%\4366\userconfig\commonconfig.ini
  • %APPDATA%\duowan\4366game\3.0.0.20\log\update.log
Deletes the following files
  • %APPDATA%\duowan\4366game\product.7z
  • %APPDATA%\duowan\4366game\4366óîï·´óìü.lnk
  • %TEMP%\nss8aed.tmp\bgworker.dll
  • %TEMP%\nss8aed.tmp\nscurl.dll
  • %TEMP%\nss8aed.tmp\nsdm.dll
  • %TEMP%\nss8aed.tmp\nsis7z.dll
  • %TEMP%\nss8aed.tmp\nsutil.dll
  • %TEMP%\nss8aed.tmp\skin.zip
  • %TEMP%\nss8aed.tmp\system.dll
Moves the following files
  • from %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\config[1].xml to %APPDATA%\duowan\4366game\3.0.0.20\config\profile.xml
Network activity
TCP
HTTP GET requests
  • http://st##.#ame.yy.com/data.do?ac###############################################################################################################################################################...
  • http://sz.##owan.com/shore/images/20181106142300499.jpg
  • http://sz.##owan.com/shore/images/20181127142103405.jpg
  • http://lo###.dwstatic.com/goa/pic/o/wdcqa_40.png
  • http://cg######to.bs2cdn.yy.com/1554959971966.jpg
  • http://cg######to.bs2cdn.yy.com/1554901745206.jpg
  • http://lo###.dwstatic.com/goa/pic/o/mjtxa_40.png
  • http://cg######to.bs2cdn.yy.com/1544499727391.jpg
  • http://cg######to.bs2cdn.yy.com/1554960062717.jpg
  • http://cg######to.bs2cdn.yy.com/1541647721703.jpg
  • http://sz.##owan.com/shore/images/2017121216235769.jpg
  • http://cg######to.bs2cdn.yy.com/1546569139897.jpg
  • http://lo###.dwstatic.com/goa/pic/o/cqsja_60.png
  • http://cg######to.bs2cdn.yy.com/1547779979745.jpg
  • http://cg######to.bs2cdn.yy.com/1541647763957.jpg
  • http://lo###.dwstatic.com/goa/pic/o/ms_60.png
  • http://sz.##owan.com/shore/images/20180801213751687.png
  • http://sz.##owan.com/shore/images/20171212162429737.jpg
  • http://sz.##owan.com/shore/images/20181031180247372.jpg
  • http://sz.##owan.com/shore/images/2018082819570910.jpg
  • http://sz.##owan.com/shore/images/20180725182911703.jpg
  • http://cg######to.bs2cdn.yy.com/1554961830579.jpg
  • http://cg######to.bs2cdn.yy.com/1554961704891.jpg
  • http://cg######to.bs2cdn.yy.com/1574845888426.jpg
  • http://cg######to.bs2cdn.yy.com/1524107214946.jpg
  • http://cg######to.bs2cdn.yy.com/1554961971841.jpg
  • http://cg######to.bs2cdn.yy.com/1554960148911.jpg
  • http://sz.##owan.com/shore/images/20181119181159926.jpg
  • http://sz.##owan.com/shore/images/20190103191434780.jpg
  • http://sz.##owan.com/shore/images/20180725144609762.jpg
  • http://sz.##owan.com/shore/images/20180828195532714.jpg
  • http://sz.##owan.com/shore/images/20171212162559601.jpg
  • http://sz.##owan.com/shore/images/20180103112305839.jpg
  • http://sz.##owan.com/shore/images/20181031180253713.jpg
  • http://sz.##owan.com/shore/images/20181127142233967.jpg
  • http://sz.##owan.com/shore/images/20181119180122199.jpg
  • http://sz.##owan.com/shore/images/20171212162619871.jpg
  • http://sz.##owan.com/shore/images/20180103112432355.jpg
  • http://sz.##owan.com/shore/images/2018080121361869.png
  • http://cg######to.bs2cdn.yy.com/1554962294300.jpg
  • http://lo###.dwstatic.com/goa/pic/o/yhjxa_60.png
  • http://sz.##owan.com/shore/images/20181106142509671.jpg
  • http://ve#####update.yy.com/version/query?ap###############################################################
  • http://f2#.yy.com/s/lib/jquery/jquery1.8.3.min.js
  • http://f2#.yy.com/s/lib/jquery/plugin/jquery.cookie.min.js
  • http://pl##.4366.com/s/lobby/2.0.1.9/js/home.js?99###
  • http://pl##.4366.com/s/lobby/2.0.1.9/js/common.js?99###
  • http://pl##.4366.com/s/lobby/config.js
  • http://pl##.4366.com/s/lobby/2.0.1.9/css/home.css
  • http://f2#.yy.com/s/lib/sdk/u4366/jquery.u4366sdk-4366client.js
  • http://pl##.4366.com/s/lobby/2.0.1.9/css/common.css
  • http://pl##.4366.com/s/home.html
  • http://pa####rt.4366.com/register/showRealName.do
  • http://do#####d.game.yy.com/goa/xml/4366/flash.xml
  • http://go#.#ame.yy.com/userGsHistory/get.do?oe########
  • http://do#####d.game.yy.com/goa/xml/4366/config.xml
  • http://yl##.hiido.com/c.gif?ac###################################################################################################################################################################...
  • http://tr###.hiido.com/zhsdkinfo.php?ve########
  • http://co####.hiido.com/api/getDeviceConfig?sy#########################################################################################################
  • http://f2#.yy.com/s/lib/jquery/jquery.tinyscrollerbar.min.js
  • http://f2#.yy.com/s/lib/avalon/avalon.min.js
  • http://11#.#0.174.135/c.gif?ac###################################################################################################################################################################...
  • http://sz.##owan.com/shore/images/20190103191624350.jpg
  • http://sz.##owan.com/shore/images/20190117152957376.jpg
  • http://sz.##owan.com/shore/images/2019011715293357.jpg
  • http://sz.##owan.com/shore/images/20171212162745885.jpg
  • http://sz.##owan.com/shore/images/20171212162727895.jpg
  • http://we#.####icdata.game.yy.com/module/conf.do?mo##################################################################################
  • http://st##.#ame.yy.com/data.do?ac##########################################################################################
  • http://ud####in.duowan.com/ext/gslist.do?se################################################################################################################
  • http://we#.####icdata.game.yy.com/module/conf.do?mo#######################################################################################
  • http://pl##.4366.com/s/lobby/2.0.1.9/img/pop-gift-sprite.png?23###
  • http://ca#####nt.game.yy.com/listShowRanking.do?li#############################################################################################################################
  • http://pl##.4366.com/s/lobby/2.0.1.9/img/pagination-sprite.png?e3###
  • http://pl##.4366.com/s/lobby/2.0.1.9/img/home-sprite.png?93###
  • http://pl##.4366.com/s/
  • http://pl##.4366.com/s/img/slider-bg-middle.png
  • http://sz#####ng.duowan.com/feq/4366/yy-f2e-4366.min?_=#############
  • http://sz#####ng.duowan.com/feq/4366/yy-f2e-header-4366.min?t_##############
  • http://lo###.dwstatic.com/goa/pic/o/dhsz_60.png
  • http://cg######to.bs2cdn.yy.com/1541647737494.jpg
HTTP POST requests
  • http://st##.#ame.yy.com/data.do
UDP
  • DNS ASK st##.#ame.yy.com
  • DNS ASK sz.##owan.com
  • DNS ASK ud####in.duowan.com
  • DNS ASK ca#####nt.game.yy.com
  • DNS ASK we#.####icdata.game.yy.com
  • DNS ASK cg#####dia.bs2dl.yy.com
  • DNS ASK cg#######a.bs2dl.dwstatic.com
  • DNS ASK sz#####ng.duowan.com
  • DNS ASK lo###.dwstatic.com
  • DNS ASK f2#.yy.com
  • DNS ASK pl##.4366.com
  • DNS ASK co####.hiido.com
  • DNS ASK pa####rt.4366.com
  • DNS ASK go#.#ame.yy.com
  • DNS ASK do#####d.game.yy.com
  • DNS ASK tr###.hiido.com
  • DNS ASK yl##.hiido.com
  • DNS ASK ve#####update.yy.com
  • DNS ASK cg######to.bs2cdn.yy.com
Miscellaneous
Searches for the following windows
  • ClassName: '#32770' WindowName: ''
  • ClassName: 'MS_AutodialMonitor' WindowName: ''
  • ClassName: 'MS_WebCheckMonitor' WindowName: ''
Creates and executes the following
  • '%APPDATA%\duowan\4366game\launcher.exe'
  • '%APPDATA%\duowan\4366game\launcher.exe' -Admin
  • '%APPDATA%\duowan\4366game\3.0.0.20\gpluginmgr.exe' "-Admin"
  • '%APPDATA%\duowan\4366game\3.0.0.20\daemonservice.exe'
  • '%APPDATA%\duowan\4366game\3.0.0.20\gprender.exe' -tag 1104375 -runid 884_20200802-03:45:16:802
  • '%APPDATA%\duowan\4366game\3.0.0.20\launcher.exe'
  • '%APPDATA%\duowan\4366game\3.0.0.20\gpluginmgr.exe' "default"
  • '%APPDATA%\duowan\4366game\3.0.0.20\gprender.exe' -tag 1114640 -runid 2632_20200802-03:45:28:114
  • '%APPDATA%\duowan\4366game\3.0.0.20\gprender.exe' -tag 1114640 -runid 2632_20200802-03:45:30:755
  • '%APPDATA%\duowan\4366game\3.0.0.20\update.exe' pid=2632

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android