Trojan.DownLoader23.33575
Added to Dr.Web virus database: | 2016-12-22 |
Virus description was added: | 2016-12-21 |
Technical Information
Malicious functions:
Executes the following:
- '%TEMP%\~nsuA.tmp\Un_A.exe' _?=<Current directory>\
Modifies file system:
Creates the following files:
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\cmi.ironbeast[1].htm
- %TEMP%\nsc3.tmp
- %TEMP%\~nsuA.tmp\Un_A.exe
- %TEMP%\nss4.tmp\inetc.dll
Deletes the following files:
- %TEMP%\nss4.tmp\inetc.dll
- %TEMP%\nsc3.tmp
Deletes itself.
Network activity:
Connects to:
- 'cm#.##onbeast.io':80
TCP:
HTTP POST requests:
- http://cm#.##onbeast.io/
UDP:
- DNS ASK cm#.##onbeast.io
Miscellaneous:
Searches for the following windows:
- ClassName: 'Shell_TrayWnd' WindowName: ''
Curing recommendations
For Microsoft Windows OS:
- If the OS can be loaded (normally or in the safe mode), download the curing utility Dr.Web CureIt! and run a full scan of your computer and the removable media you use.
- If you can't load the OS, change the BIOS settings to load your system from a CD or USB drive. Download the Dr.Web® LiveCD emergency restore disk image or the Dr.Web® LiveUSB emergency recovery utility for your specific OS, using a USB drive , and prepare the appropriate media. After loading the computer with this media, run a full scan and cure detected threats.
- If your OS is locked by malware from the Trojan.Winlock family, use our unlocking service. If you failed to find the unlock code, follow the instructions provided in Section 2.
For Linux:
- On the loaded OS, run a full scan of all disk partitions using the Dr.Web Antivirus for Linux.
- If you can't load the OS, change the BIOS settings to load your system from a CD or USB drive. Download the Dr.Web® LiveCD emergency restore disk image or the Dr.Web® LiveUSB emergency recovery utility for your specific OS, using a USB drive , and prepare the appropriate media. After loading the computer with this media, run a full scan and cure detected threats.
For OS X:
Run a full system scan using the free Dr.Web Light Scanner for OS X. You can download it from the Apple App Store or from Doctor Web's official site.
For Android:
Download and install on your device the free product Dr.Web for Android Light. Perform a full system scan and carry out recommendations to remove the detected threats.