TROJ_DLOADR.AC
[ACCESSIBLEMARSHAL.DLL]:Generic.dx!wvp (McAfee); Trojan-Dropper.Win32.Agent.ewam (Kaspersky)
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan creates the following folders:
- %System%\exporty
- browser
- browser\appdata
- browser\appdata\Cache
- browser\appdata\extensions
- browser\appdata\extensions\vvisit@www.virtualvisit.cn
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\content
- browser\appdata\OfflineCache
- browser\chrome
- browser\components
- browser\defaults
- browser\defaults\autoconfig
- browser\defaults\pref
- browser\defaults\profile
- browser\defaults\profile\chrome
- browser\greprefs
- browser\modules
- browser\pxy
- browser\res
- browser\res\dtd
- browser\res\entityTables
- browser\res\fonts
- browser\res\html
- browser\appdata\bookmarkbackups
- browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- browser\extensions
- browser\updates\0
- browser\updates
- browser\dictionaries
- browser\searchplugins
- %System Root%\Documents and Settings
- %System Root%\Documents and Settings\Administrator
- %Start Menu%\Programs
Other System Modifications
This Trojan adds the following registry keys:
HKEY_CURRENT_USER\Software\WinRAR SFX
It adds the following registry entries:
HKEY_CURRENT_USER\Software\WinRAR SFX
C%%WINDOWS%system32%exporty% = "%System%\exporty\"
Dropping Routine
This Trojan drops the following files:
- __tmp_rar_sfx_access_check_37765
- appface.dll
- CD.vbs
- config.ini
- ????.vbs
- scvhost.exe
- browser\AccessibleMarshal.dll
- browser\appdata\Cache\06C96FD4d01
- browser\appdata\Cache\9CD83313d01
- browser\appdata\Cache\E527D493d01
- browser\appdata\Cache\EC96F6F9d01
- browser\appdata\Cache\_CACHE_001_
- browser\appdata\Cache\_CACHE_002_
- browser\appdata\Cache\_CACHE_003_
- browser\appdata\Cache\_CACHE_MAP_
- browser\appdata\cert8.db
- browser\appdata\compatibility.ini
- browser\appdata\compreg.dat
- browser\appdata\content-prefs.sqlite
- browser\appdata\cookies.sqlite
- browser\appdata\downloads.sqlite
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\chrome.manifest
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\content\function.js
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\content\overlay.xul
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\content\vvisit.js
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\install.rdf
- browser\appdata\extensions.cache
- browser\appdata\extensions.ini
- browser\appdata\extensions.rdf
- browser\appdata\formhistory.sqlite
- browser\appdata\key3.db
- browser\appdata\localstore.rdf
- browser\appdata\mimeTypes.rdf
- browser\appdata\OfflineCache\index.sqlite
- browser\appdata\permissions.sqlite
- browser\appdata\places.sqlite
- browser\appdata\places.sqlite-journal
- browser\appdata\prefs.js
- browser\appdata\search.sqlite
- browser\appdata\secmod.db
- browser\appdata\sessionstore.js
- browser\appdata\signons3.txt
- browser\appdata\urlclassifier3.sqlite
- browser\appdata\user.js
- browser\appdata\webappsstore.sqlite
- browser\appdata\XPC.mfl
- browser\appdata\xpti.dat
- browser\appdata\XUL.mfl
- browser\application.ini
- browser\blocklist.xml
- browser\chrome\browser.jar
- browser\chrome\browser.manifest
- browser\chrome\classic.jar
- browser\chrome\classic.manifest
- browser\chrome\comm.jar
- browser\chrome\comm.manifest
- browser\chrome\default.jar
- browser\chrome\pippki.jar
- browser\chrome\pippki.manifest
- browser\chrome\reporter.jar
- browser\chrome\reporter.manifest
- browser\chrome\toolkit.jar
- browser\chrome\toolkit.manifest
- browser\chrome\troot.conf
- browser\chrome\zh-CN.jar
- browser\chrome\zh-CN.manifest
- browser\components\aboutRights.js
- browser\components\aboutRobots.js
- browser\components\accessibility-msaa.xpt
- browser\components\accessibility.xpt
- browser\components\alerts.xpt
- browser\components\appshell.xpt
- browser\components\appstartup.xpt
- browser\components\autocomplete.xpt
- browser\components\autoconfig.xpt
- browser\components\browser-feeds.xpt
- browser\components\browsercompsbase.xpt
- browser\components\browserdirprovider.dll
- browser\components\browserplaces.xpt
- browser\components\browsersearch.xpt
- browser\components\brwsrcmp.dll
- browser\components\caps.xpt
- browser\components\chardet.xpt
- browser\components\chrome.xpt
- browser\components\commandhandler.xpt
- browser\components\commandlines.xpt
- browser\components\composer.xpt
- browser\components\contentprefs.xpt
- browser\components\content_base.xpt
- browser\components\content_html.xpt
- browser\components\content_htmldoc.xpt
- browser\components\content_xmldoc.xpt
- browser\components\content_xslt.xpt
- browser\components\content_xtf.xpt
- browser\components\cookie.xpt
- browser\components\directory.xpt
- browser\components\docshell_base.xpt
- browser\components\dom.xpt
- browser\components\dom_base.xpt
- browser\components\dom_canvas.xpt
- browser\components\dom_core.xpt
- browser\components\dom_css.xpt
- browser\components\dom_events.xpt
- browser\components\dom_html.xpt
- browser\components\dom_json.xpt
- browser\components\dom_loadsave.xpt
- browser\components\dom_offline.xpt
- browser\components\dom_range.xpt
- browser\components\dom_sidebar.xpt
- browser\components\dom_storage.xpt
- browser\components\dom_stylesheets.xpt
- browser\components\dom_svg.xpt
- browser\components\dom_traversal.xpt
- browser\components\dom_views.xpt
- browser\components\dom_xbl.xpt
- browser\components\dom_xpath.xpt
- browser\components\dom_xul.xpt
- browser\components\downloads.xpt
- browser\components\editor.xpt
- browser\components\embed_base.xpt
- browser\components\extensions.xpt
- browser\components\exthandler.xpt
- browser\components\exthelper.xpt
- browser\components\fastfind.xpt
- browser\components\FeedConverter.js
- browser\components\FeedProcessor.js
- browser\components\feeds.xpt
- browser\components\FeedWriter.js
- browser\components\find.xpt
- browser\components\fuel.xpt
- browser\components\fuelApplication.js
- browser\components\gfx.xpt
- browser\components\htmlparser.xpt
- browser\components\imgicon.xpt
- browser\components\imglib2.xpt
- browser\components\inspector.xpt
- browser\components\intl.xpt
- browser\components\jar.xpt
- browser\components\jsconsole-clhandler.js
- browser\components\jsdservice.xpt
- browser\components\layout_base.xpt
- browser\components\layout_xul.xpt
- browser\components\layout_xul_tree.xpt
- browser\components\locale.xpt
- browser\components\loginmgr.xpt
- browser\components\lwbrk.xpt
- browser\components\microsummaries.xpt
- browser\components\migration.xpt
- browser\components\mimetype.xpt
- browser\components\mozbrwsr.xpt
- browser\components\mozfind.xpt
- browser\components\necko.xpt
- browser\components\necko_about.xpt
- browser\components\necko_cache.xpt
- browser\components\necko_cookie.xpt
- browser\components\necko_dns.xpt
- browser\components\necko_file.xpt
- browser\components\necko_ftp.xpt
- browser\components\necko_http.xpt
- browser\components\necko_res.xpt
- browser\components\necko_socket.xpt
- browser\components\necko_strconv.xpt
- browser\components\necko_viewsource.xpt
- browser\components\nsAddonRepository.js
- browser\components\nsBadCertHandler.js
- browser\components\nsBlocklistService.js
- browser\components\nsBrowserContentHandler.js
- browser\components\nsBrowserGlue.js
- browser\components\nsContentDispatchChooser.js
- browser\components\nsContentPrefService.js
- browser\components\nsDefaultCLH.js
- browser\components\nsDownloadManagerUI.js
- browser\components\nsExtensionManager.js
- browser\components\nsHandlerService.js
- browser\components\nsHelperAppDlg.js
- browser\components\nsLivemarkService.js
- browser\components\nsLoginInfo.js
- browser\components\nsLoginManager.js
- browser\components\nsLoginManagerPrompter.js
- browser\components\nsMicrosummaryService.js
- browser\components\nsPlacesTransactionsService.js
- browser\components\nsPostUpdateWin.js
- browser\components\nsProgressDialog.js
- browser\components\nsProxyAutoConfig.js
- browser\components\nsResetPref.js
- browser\components\nsSafebrowsingApplication.js
- browser\components\nsSearchService.js
- browser\components\nsSearchSuggestions.js
- browser\components\nsSessionStartup.js
- browser\components\nsSessionStore.js
- browser\components\nsSetDefaultBrowser.js
- browser\components\nsSidebar.js
- browser\components\nsTaggingService.js
- browser\components\nsTryToClose.js
- browser\components\nsUpdateService.js
- browser\components\nsUrlClassifierLib.js
- browser\components\nsUrlClassifierListManager.js
- browser\components\nsURLFormatter.js
- browser\components\nsWebHandlerApp.js
- browser\components\oji.xpt
- browser\components\parentalcontrols.xpt
- browser\components\pipboot.xpt
- browser\components\pipnss.xpt
- browser\components\pippki.xpt
- browser\components\places.xpt
- browser\components\pluginGlue.js
- browser\components\pref.xpt
- browser\components\prefetch.xpt
- browser\components\profile.xpt
- browser\components\proxyObject.xpt
- browser\components\rdf.xpt
- browser\components\satchel.xpt
- browser\components\saxparser.xpt
- browser\components\sessionstore.xpt
- browser\components\shellservice.xpt
- browser\components\shistory.xpt
- browser\components\spellchecker.xpt
- browser\components\storage-Legacy.js
- browser\components\storage.xpt
- browser\components\toolkitprofile.xpt
- browser\components\txEXSLTRegExFunctions.js
- browser\components\txmgr.xpt
- browser\components\txtsvc.xpt
- browser\components\uconv.xpt
- browser\components\unicharutil.xpt
- browser\components\update.xpt
- browser\components\uriloader.xpt
- browser\components\url-classifier.xpt
- browser\components\urlformatter.xpt
- browser\components\webbrowserpersist.xpt
- browser\components\webBrowser_core.xpt
- browser\components\WebContentConverter.js
- browser\components\webshell_idls.xpt
- browser\components\widget.xpt
- browser\components\windowds.xpt
- browser\components\windowwatcher.xpt
- browser\components\xpcom_base.xpt
- browser\components\xpcom_components.xpt
- browser\components\xpcom_ds.xpt
- browser\components\xpcom_io.xpt
- browser\components\xpcom_system.xpt
- browser\components\xpcom_thread.xpt
- browser\components\xpcom_xpti.xpt
- browser\components\xpconnect.xpt
- browser\components\xpinstall.xpt
- browser\components\xulapp.xpt
- browser\components\xuldoc.xpt
- browser\components\xultmpl.xpt
- browser\components\zipwriter.xpt
- browser\defaults\autoconfig\platform.js
- browser\defaults\autoconfig\prefcalls.js
- browser\defaults\pref\channel-prefs.js
- browser\defaults\pref\firefox-branding.js
- browser\defaults\pref\firefox-l10n.js
- browser\defaults\pref\firefox.js
- browser\defaults\pref\reporter.js
- browser\defaults\profile\bookmarks.html
- browser\defaults\profile\chrome\userChrome-example.css
- browser\defaults\profile\chrome\userContent-example.css
- browser\defaults\profile\localstore.rdf
- browser\defaults\profile\mimeTypes.rdf
- browser\defaults\profile\prefs.js
- browser\firefox.exe
- browser\freebl3.chk
- browser\freebl3.dll
- browser\greprefs\all.js
- browser\greprefs\security-prefs.js
- browser\greprefs\xpinstall.js
- browser\hide.txt
- browser\IA2Marshal.dll
- browser\js3250.dll
- browser\Microsoft.VC90.CRT.manifest
- browser\modules\debug.js
- browser\modules\distribution.js
- browser\modules\DownloadUtils.jsm
- browser\modules\ISO8601DateUtils.jsm
- browser\modules\JSON.jsm
- browser\modules\Microformats.js
- browser\modules\PluralForm.jsm
- browser\modules\utils.js
- browser\modules\XPCOMUtils.jsm
- browser\msvcm90.dll
- browser\msvcp90.dll
- browser\msvcr90.dll
- browser\nspr4.dll
- browser\nss3.dll
- browser\nssckbi.dll
- browser\nssdbm3.dll
- browser\nssutil3.dll
- browser\platform.ini
- browser\plc4.dll
- browser\plds4.dll
- browser\pxy\config.txt
- browser\pxy\default.action
- browser\pxy\default.filter
- browser\pxy\mgwz.dll
- browser\pxy\privoxy.dll
- browser\pxy\privoxy.log
- browser\res\arrow.gif
- browser\res\arrowd.gif
- browser\res\broken-image.gif
- browser\res\charsetalias.properties
- browser\res\charsetData.properties
- browser\res\contenteditable.css
- browser\res\designmode.css
- browser\res\dtd\mathml.dtd
- browser\res\dtd\xhtml11.dtd
- browser\res\EditorOverride.css
- browser\res\entityTables\html40Latin1.properties
- browser\res\entityTables\html40Special.properties
- browser\res\entityTables\html40Symbols.properties
- browser\res\entityTables\htmlEntityVersions.properties
- browser\res\entityTables\mathml20.properties
- browser\res\entityTables\transliterate.properties
- browser\res\fonts\mathfont.properties
- browser\res\fonts\mathfontStandardSymbolsL.properties
- browser\res\fonts\mathfontSTIXNonUnicode.properties
- browser\res\fonts\mathfontSTIXSize1.properties
- browser\res\fonts\mathfontSymbol.properties
- browser\res\fonts\mathfontUnicode.properties
- browser\res\forms.css
- browser\res\grabber.gif
- browser\res\hiddenWindow.html
- browser\res\html\folder.png
- browser\res\html.css
- browser\res\langGroups.properties
- browser\res\language.properties
- browser\res\loading-image.gif
- browser\res\mathml.css
- browser\res\quirk.css
- browser\res\svg.css
- browser\res\table-add-column-after-active.gif
- browser\res\table-add-column-after-hover.gif
- browser\res\table-add-column-after.gif
- browser\res\table-add-column-before-active.gif
- browser\res\table-add-column-before-hover.gif
- browser\res\table-add-column-before.gif
- browser\res\table-add-row-after-active.gif
- browser\res\table-add-row-after-hover.gif
- browser\res\table-add-row-after.gif
- browser\res\table-add-row-before-active.gif
- browser\res\table-add-row-before-hover.gif
- browser\res\table-add-row-before.gif
- browser\res\table-remove-column-active.gif
- browser\res\table-remove-column-hover.gif
- browser\res\table-remove-column.gif
- browser\res\table-remove-row-active.gif
- browser\res\table-remove-row-hover.gif
- browser\res\table-remove-row.gif
- browser\res\tbc_vvt_temp_4.txt
- browser\res\tbc_vvt_temp_6.txt
- browser\res\ua.css
- browser\res\viewsource.css
- browser\res\virtual_visit_system_10-05-07.htm
- browser\res\virtual_visit_system_10-05-12.htm
- browser\res\wincharset.properties
- browser\royale.urf
- browser\smime3.dll
- browser\softokn3.chk
- browser\softokn3.dll
- browser\sqlite3.dll
- browser\ssl3.dll
- browser\xpcom.dll
- browser\xul.dll
- $wdd.bat
- %User Startup%\????.lnk
This report is generated via an automated analysis system.
SOLUTION
Step 1
Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.
Step 2
Delete this registry key
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
- In HKEY_CURRENT_USER\Software
- WinRAR SFX
Step 3
Delete this registry value
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
- In HKEY_CURRENT_USER\Software\WinRAR SFX
- C%%WINDOWS%system32%exporty%="%System%\exporty\"
Step 4
Search and delete these folders
- %System%\exporty
- browser
- browser\appdata
- browser\appdata\Cache
- browser\appdata\extensions
- browser\appdata\extensions\vvisit@www.virtualvisit.cn
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\content
- browser\appdata\OfflineCache
- browser\chrome
- browser\components
- browser\defaults
- browser\defaults\autoconfig
- browser\defaults\pref
- browser\defaults\profile
- browser\defaults\profile\chrome
- browser\greprefs
- browser\modules
- browser\pxy
- browser\res
- browser\res\dtd
- browser\res\entityTables
- browser\res\fonts
- browser\res\html
- browser\appdata\bookmarkbackups
- browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- browser\extensions
- browser\updates\0
- browser\updates
- browser\dictionaries
- browser\searchplugins
- %System Root%\Documents and Settings
- %System Root%\Documents and Settings\Administrator
- %Start Menu%\Programs
Step 5
Search and delete these components
- __tmp_rar_sfx_access_check_37765
- appface.dll
- CD.vbs
- config.ini
- ????.vbs
- scvhost.exe
- browser\AccessibleMarshal.dll
- browser\appdata\Cache\06C96FD4d01
- browser\appdata\Cache\9CD83313d01
- browser\appdata\Cache\E527D493d01
- browser\appdata\Cache\EC96F6F9d01
- browser\appdata\Cache\_CACHE_001_
- browser\appdata\Cache\_CACHE_002_
- browser\appdata\Cache\_CACHE_003_
- browser\appdata\Cache\_CACHE_MAP_
- browser\appdata\cert8.db
- browser\appdata\compatibility.ini
- browser\appdata\compreg.dat
- browser\appdata\content-prefs.sqlite
- browser\appdata\cookies.sqlite
- browser\appdata\downloads.sqlite
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\chrome.manifest
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\content\function.js
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\content\overlay.xul
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\content\vvisit.js
- browser\appdata\extensions\vvisit@www.virtualvisit.cn\install.rdf
- browser\appdata\extensions.cache
- browser\appdata\extensions.ini
- browser\appdata\extensions.rdf
- browser\appdata\formhistory.sqlite
- browser\appdata\key3.db
- browser\appdata\localstore.rdf
- browser\appdata\mimeTypes.rdf
- browser\appdata\OfflineCache\index.sqlite
- browser\appdata\permissions.sqlite
- browser\appdata\places.sqlite
- browser\appdata\places.sqlite-journal
- browser\appdata\prefs.js
- browser\appdata\search.sqlite
- browser\appdata\secmod.db
- browser\appdata\sessionstore.js
- browser\appdata\signons3.txt
- browser\appdata\urlclassifier3.sqlite
- browser\appdata\user.js
- browser\appdata\webappsstore.sqlite
- browser\appdata\XPC.mfl
- browser\appdata\xpti.dat
- browser\appdata\XUL.mfl
- browser\application.ini
- browser\blocklist.xml
- browser\chrome\browser.jar
- browser\chrome\browser.manifest
- browser\chrome\classic.jar
- browser\chrome\classic.manifest
- browser\chrome\comm.jar
- browser\chrome\comm.manifest
- browser\chrome\default.jar
- browser\chrome\pippki.jar
- browser\chrome\pippki.manifest
- browser\chrome\reporter.jar
- browser\chrome\reporter.manifest
- browser\chrome\toolkit.jar
- browser\chrome\toolkit.manifest
- browser\chrome\troot.conf
- browser\chrome\zh-CN.jar
- browser\chrome\zh-CN.manifest
- browser\components\aboutRights.js
- browser\components\aboutRobots.js
- browser\components\accessibility-msaa.xpt
- browser\components\accessibility.xpt
- browser\components\alerts.xpt
- browser\components\appshell.xpt
- browser\components\appstartup.xpt
- browser\components\autocomplete.xpt
- browser\components\autoconfig.xpt
- browser\components\browser-feeds.xpt
- browser\components\browsercompsbase.xpt
- browser\components\browserdirprovider.dll
- browser\components\browserplaces.xpt
- browser\components\browsersearch.xpt
- browser\components\brwsrcmp.dll
- browser\components\caps.xpt
- browser\components\chardet.xpt
- browser\components\chrome.xpt
- browser\components\commandhandler.xpt
- browser\components\commandlines.xpt
- browser\components\composer.xpt
- browser\components\contentprefs.xpt
- browser\components\content_base.xpt
- browser\components\content_html.xpt
- browser\components\content_htmldoc.xpt
- browser\components\content_xmldoc.xpt
- browser\components\content_xslt.xpt
- browser\components\content_xtf.xpt
- browser\components\cookie.xpt
- browser\components\directory.xpt
- browser\components\docshell_base.xpt
- browser\components\dom.xpt
- browser\components\dom_base.xpt
- browser\components\dom_canvas.xpt
- browser\components\dom_core.xpt
- browser\components\dom_css.xpt
- browser\components\dom_events.xpt
- browser\components\dom_html.xpt
- browser\components\dom_json.xpt
- browser\components\dom_loadsave.xpt
- browser\components\dom_offline.xpt
- browser\components\dom_range.xpt
- browser\components\dom_sidebar.xpt
- browser\components\dom_storage.xpt
- browser\components\dom_stylesheets.xpt
- browser\components\dom_svg.xpt
- browser\components\dom_traversal.xpt
- browser\components\dom_views.xpt
- browser\components\dom_xbl.xpt
- browser\components\dom_xpath.xpt
- browser\components\dom_xul.xpt
- browser\components\downloads.xpt
- browser\components\editor.xpt
- browser\components\embed_base.xpt
- browser\components\extensions.xpt
- browser\components\exthandler.xpt
- browser\components\exthelper.xpt
- browser\components\fastfind.xpt
- browser\components\FeedConverter.js
- browser\components\FeedProcessor.js
- browser\components\feeds.xpt
- browser\components\FeedWriter.js
- browser\components\find.xpt
- browser\components\fuel.xpt
- browser\components\fuelApplication.js
- browser\components\gfx.xpt
- browser\components\htmlparser.xpt
- browser\components\imgicon.xpt
- browser\components\imglib2.xpt
- browser\components\inspector.xpt
- browser\components\intl.xpt
- browser\components\jar.xpt
- browser\components\jsconsole-clhandler.js
- browser\components\jsdservice.xpt
- browser\components\layout_base.xpt
- browser\components\layout_xul.xpt
- browser\components\layout_xul_tree.xpt
- browser\components\locale.xpt
- browser\components\loginmgr.xpt
- browser\components\lwbrk.xpt
- browser\components\microsummaries.xpt
- browser\components\migration.xpt
- browser\components\mimetype.xpt
- browser\components\mozbrwsr.xpt
- browser\components\mozfind.xpt
- browser\components\necko.xpt
- browser\components\necko_about.xpt
- browser\components\necko_cache.xpt
- browser\components\necko_cookie.xpt
- browser\components\necko_dns.xpt
- browser\components\necko_file.xpt
- browser\components\necko_ftp.xpt
- browser\components\necko_http.xpt
- browser\components\necko_res.xpt
- browser\components\necko_socket.xpt
- browser\components\necko_strconv.xpt
- browser\components\necko_viewsource.xpt
- browser\components\nsAddonRepository.js
- browser\components\nsBadCertHandler.js
- browser\components\nsBlocklistService.js
- browser\components\nsBrowserContentHandler.js
- browser\components\nsBrowserGlue.js
- browser\components\nsContentDispatchChooser.js
- browser\components\nsContentPrefService.js
- browser\components\nsDefaultCLH.js
- browser\components\nsDownloadManagerUI.js
- browser\components\nsExtensionManager.js
- browser\components\nsHandlerService.js
- browser\components\nsHelperAppDlg.js
- browser\components\nsLivemarkService.js
- browser\components\nsLoginInfo.js
- browser\components\nsLoginManager.js
- browser\components\nsLoginManagerPrompter.js
- browser\components\nsMicrosummaryService.js
- browser\components\nsPlacesTransactionsService.js
- browser\components\nsPostUpdateWin.js
- browser\components\nsProgressDialog.js
- browser\components\nsProxyAutoConfig.js
- browser\components\nsResetPref.js
- browser\components\nsSafebrowsingApplication.js
- browser\components\nsSearchService.js
- browser\components\nsSearchSuggestions.js
- browser\components\nsSessionStartup.js
- browser\components\nsSessionStore.js
- browser\components\nsSetDefaultBrowser.js
- browser\components\nsSidebar.js
- browser\components\nsTaggingService.js
- browser\components\nsTryToClose.js
- browser\components\nsUpdateService.js
- browser\components\nsUrlClassifierLib.js
- browser\components\nsUrlClassifierListManager.js
- browser\components\nsURLFormatter.js
- browser\components\nsWebHandlerApp.js
- browser\components\oji.xpt
- browser\components\parentalcontrols.xpt
- browser\components\pipboot.xpt
- browser\components\pipnss.xpt
- browser\components\pippki.xpt
- browser\components\places.xpt
- browser\components\pluginGlue.js
- browser\components\pref.xpt
- browser\components\prefetch.xpt
- browser\components\profile.xpt
- browser\components\proxyObject.xpt
- browser\components\rdf.xpt
- browser\components\satchel.xpt
- browser\components\saxparser.xpt
- browser\components\sessionstore.xpt
- browser\components\shellservice.xpt
- browser\components\shistory.xpt
- browser\components\spellchecker.xpt
- browser\components\storage-Legacy.js
- browser\components\storage.xpt
- browser\components\toolkitprofile.xpt
- browser\components\txEXSLTRegExFunctions.js
- browser\components\txmgr.xpt
- browser\components\txtsvc.xpt
- browser\components\uconv.xpt
- browser\components\unicharutil.xpt
- browser\components\update.xpt
- browser\components\uriloader.xpt
- browser\components\url-classifier.xpt
- browser\components\urlformatter.xpt
- browser\components\webbrowserpersist.xpt
- browser\components\webBrowser_core.xpt
- browser\components\WebContentConverter.js
- browser\components\webshell_idls.xpt
- browser\components\widget.xpt
- browser\components\windowds.xpt
- browser\components\windowwatcher.xpt
- browser\components\xpcom_base.xpt
- browser\components\xpcom_components.xpt
- browser\components\xpcom_ds.xpt
- browser\components\xpcom_io.xpt
- browser\components\xpcom_system.xpt
- browser\components\xpcom_thread.xpt
- browser\components\xpcom_xpti.xpt
- browser\components\xpconnect.xpt
- browser\components\xpinstall.xpt
- browser\components\xulapp.xpt
- browser\components\xuldoc.xpt
- browser\components\xultmpl.xpt
- browser\components\zipwriter.xpt
- browser\defaults\autoconfig\platform.js
- browser\defaults\autoconfig\prefcalls.js
- browser\defaults\pref\channel-prefs.js
- browser\defaults\pref\firefox-branding.js
- browser\defaults\pref\firefox-l10n.js
- browser\defaults\pref\firefox.js
- browser\defaults\pref\reporter.js
- browser\defaults\profile\bookmarks.html
- browser\defaults\profile\chrome\userChrome-example.css
- browser\defaults\profile\chrome\userContent-example.css
- browser\defaults\profile\localstore.rdf
- browser\defaults\profile\mimeTypes.rdf
- browser\defaults\profile\prefs.js
- browser\firefox.exe
- browser\freebl3.chk
- browser\freebl3.dll
- browser\greprefs\all.js
- browser\greprefs\security-prefs.js
- browser\greprefs\xpinstall.js
- browser\hide.txt
- browser\IA2Marshal.dll
- browser\js3250.dll
- browser\Microsoft.VC90.CRT.manifest
- browser\modules\debug.js
- browser\modules\distribution.js
- browser\modules\DownloadUtils.jsm
- browser\modules\ISO8601DateUtils.jsm
- browser\modules\JSON.jsm
- browser\modules\Microformats.js
- browser\modules\PluralForm.jsm
- browser\modules\utils.js
- browser\modules\XPCOMUtils.jsm
- browser\msvcm90.dll
- browser\msvcp90.dll
- browser\msvcr90.dll
- browser\nspr4.dll
- browser\nss3.dll
- browser\nssckbi.dll
- browser\nssdbm3.dll
- browser\nssutil3.dll
- browser\platform.ini
- browser\plc4.dll
- browser\plds4.dll
- browser\pxy\config.txt
- browser\pxy\default.action
- browser\pxy\default.filter
- browser\pxy\mgwz.dll
- browser\pxy\privoxy.dll
- browser\pxy\privoxy.log
- browser\res\arrow.gif
- browser\res\arrowd.gif
- browser\res\broken-image.gif
- browser\res\charsetalias.properties
- browser\res\charsetData.properties
- browser\res\contenteditable.css
- browser\res\designmode.css
- browser\res\dtd\mathml.dtd
- browser\res\dtd\xhtml11.dtd
- browser\res\EditorOverride.css
- browser\res\entityTables\html40Latin1.properties
- browser\res\entityTables\html40Special.properties
- browser\res\entityTables\html40Symbols.properties
- browser\res\entityTables\htmlEntityVersions.properties
- browser\res\entityTables\mathml20.properties
- browser\res\entityTables\transliterate.properties
- browser\res\fonts\mathfont.properties
- browser\res\fonts\mathfontStandardSymbolsL.properties
- browser\res\fonts\mathfontSTIXNonUnicode.properties
- browser\res\fonts\mathfontSTIXSize1.properties
- browser\res\fonts\mathfontSymbol.properties
- browser\res\fonts\mathfontUnicode.properties
- browser\res\forms.css
- browser\res\grabber.gif
- browser\res\hiddenWindow.html
- browser\res\html\folder.png
- browser\res\html.css
- browser\res\langGroups.properties
- browser\res\language.properties
- browser\res\loading-image.gif
- browser\res\mathml.css
- browser\res\quirk.css
- browser\res\svg.css
- browser\res\table-add-column-after-active.gif
- browser\res\table-add-column-after-hover.gif
- browser\res\table-add-column-after.gif
- browser\res\table-add-column-before-active.gif
- browser\res\table-add-column-before-hover.gif
- browser\res\table-add-column-before.gif
- browser\res\table-add-row-after-active.gif
- browser\res\table-add-row-after-hover.gif
- browser\res\table-add-row-after.gif
- browser\res\table-add-row-before-active.gif
- browser\res\table-add-row-before-hover.gif
- browser\res\table-add-row-before.gif
- browser\res\table-remove-column-active.gif
- browser\res\table-remove-column-hover.gif
- browser\res\table-remove-column.gif
- browser\res\table-remove-row-active.gif
- browser\res\table-remove-row-hover.gif
- browser\res\table-remove-row.gif
- browser\res\tbc_vvt_temp_4.txt
- browser\res\tbc_vvt_temp_6.txt
- browser\res\ua.css
- browser\res\viewsource.css
- browser\res\virtual_visit_system_10-05-07.htm
- browser\res\virtual_visit_system_10-05-12.htm
- browser\res\wincharset.properties
- browser\royale.urf
- browser\smime3.dll
- browser\softokn3.chk
- browser\softokn3.dll
- browser\sqlite3.dll
- browser\ssl3.dll
- browser\xpcom.dll
- browser\xul.dll
- $wdd.bat
- %User Startup%\????.lnk
Step 6
Scan your computer with your Trend Micro product to delete files detected as TROJ_DLOADR.AC. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.