The file XXX_FB.DLL is identified as a virus dropper.
The dropper XXX_FB.DLL is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.
The file XXX_FB.DLL loads into the computer memory and tries to connect to the dangerous web site.
Usually the XXX_FB.DLL dropper does not infect the files on the computer and does not replicate itself on other computers.
Kill the XXX_FB.DLL process and delete the file XXX_FB.DLL.
Malware Analysis of XXX_FB.DLL
Full path on a computer: %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\XXX_FB.DLL
Detected by UnHackMe:
XXX_FB.DLL
Default location: %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\XXX_FB.DLL
Removal Results: Success
Number of reboot: 1
XXX_FB.DLL is known as:
Trojan.Pws
How to quickly detect XXX_FB.DLL presence?
Files:
- %TEMP%\CAB7.TMP
- %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\P2P.DLL
- %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\G711CODC.AX
- %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\SAVEDUMP.EXE
- %APPDATA%\MICROSOFT\WINDOWS\DLLCACHE\XXX_FB.DLL