Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.DownLoader25.12207

Добавлен в вирусную базу Dr.Web: 2017-07-23

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Malwarebytes Anti-Malware' = '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent'
Создает следующие сервисы:
  • [<HKLM>\SYSTEM\ControlSet001\Services\MBAMProtector] 'ImagePath' = '<DRIVERS>\mbam.sys'
  • [<HKLM>\SYSTEM\ControlSet001\Services\MBAMService] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\MBAMService] 'ImagePath' = '"%ProgramFiles%\Malwarebytes' Anti-Malware\mbamservice.exe"'
  • [<HKLM>\SYSTEM\ControlSet001\Services\MBAMScheduler] 'ImagePath' = '"%ProgramFiles%\Malwarebytes' Anti-Malware\mbamscheduler.exe"'
  • [<HKLM>\SYSTEM\ControlSet001\Services\SCCommService] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\SCCommService] 'ImagePath' = '"%ProgramFiles%\Malwarebytes' Managed Client\SCComm.exe"'
  • [<HKLM>\SYSTEM\ControlSet001\Services\MBAMScheduler] 'Start' = '00000002'
Вредоносные функции:
Запускает на исполнение:
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set notifyinstallprogram off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set downloadprogram off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamscheduler.exe'
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set limitedusermode off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set fullsilentmode on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /proxy
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /schedule /scan -full -log -terminate -remove /once /starting 08/09/2013 14:52:00 /every 0 /recover 0 /silent /xml
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set detectpum 1
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set detectpup 2
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set alwaysscanarchives on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /unschedule /all
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set language english.lng
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set detectp2p 0
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set autoquarantine on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /update
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /protection -start
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamservice.exe'
  • '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%WINDIR%\TEMP\RESF.tmp" "%WINDIR%\Temp\CSCE.tmp"
  • '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%WINDIR%\TEMP\t_8jrfo2.cmdline"
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamgui.exe' /starttray
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /protection -install
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set delayguistart off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set disableipblocking off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set autoquarantinenotify on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set silentipmode off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set startipdisabled off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set startfsdisabled off
  • '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\Malwarebytes' Anti-Malware\ssubtmr6.dll"
  • '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\Malwarebytes' Anti-Malware\mbamext.dll"
  • '%TEMP%\is-43GHQ.tmp\coreinst.tmp' /SL5="$600E6,9752448,54272,%ProgramFiles%\Malwarebytes' Managed Client\coreinst.exe" /NOICONS /tasks="" /verysilent /SUPPRESSMSGBOXES /NORESTART /RESTARTEXITCODE=101
  • '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%WINDIR%\TEMP\7kvpam1l.cmdline"
  • '%ProgramFiles%\Malwarebytes' Managed Client\SCComm.exe'
  • '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles%\Malwarebytes' Anti-Malware\vbalsgrid6.ocx"
  • '%ProgramFiles%\Malwarebytes' Managed Client\Coreinst.exe' /NOICONS /tasks="" /verysilent /SUPPRESSMSGBOXES /NORESTART /RESTARTEXITCODE=101
  • '<SYSTEM32>\msiexec.exe' -Embedding 7D548E7115A8F1D047F5B281C7854017
  • '<SYSTEM32>\msiexec.exe' /V
  • '<SYSTEM32>\msiexec.exe' /i "%TEMP%\ClientSetup.msi" /qn /norestart Reboot=ReallySuppress
  • '<SYSTEM32>\msiexec.exe' -Embedding 226000246E46C0DD86714D57B1035E5C M Global\MSI0000
  • '<SYSTEM32>\rundll32.exe' "%WINDIR%\Installer\MSI5.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_156609 17 SC.Client.Setup.CustomOperation!SC.Client.Setup.CustomOperation.CustomActions.CheckCommService
  • '<SYSTEM32>\rundll32.exe' "%WINDIR%\Installer\MSI3.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_152265 8 SC.Client.Setup.CustomOperation!SC.Client.Setup.CustomOperation.CustomActions.HideCancelButton
  • '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%WINDIR%\TEMP\RESC.tmp" "%WINDIR%\Temp\CSCB.tmp"
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set alwaysscanfiles on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set alwaysscanmemory on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set alwaysscanregistry on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set advancedHeuristics on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set alwaysscanstartups on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set alwaysscanheuristics on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set updatewarndays 7
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set reportthreats off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set autosavelog on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set terminateie off
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set updatewarn on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set openlog on
  • '%ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe' /set contextmenu on
Изменения в файловой системе:
Создает следующие файлы:
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-O7FI5.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-0L6U6.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-URQB5.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-NGB9V.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-SRMID.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-HLLP8.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-61DL2.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-S58ME.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-8KK7R.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-ON2HK.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-17G9Q.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-02OL1.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-CUMSV.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-NG06T.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-L3HL3.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-CVRFB.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-2T0VV.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-O8E2F.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-ES8NN.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-55Q1A.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-F0702.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-OQC6P.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-UVKGI.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-C4TE1.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-EF1TP.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-UI1BK.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-DOVIB.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-OAGNB.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-G8LON.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-K92EC.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-G38KP.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-43A7N.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-3EJAF.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-8NNG9.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-O21P4.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-RS7AC.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-ASQUM.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-GFDFT.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-CM8DQ.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\is-2GBKR.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-DI6JP.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\rules.ref
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\ignore.dat
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\database.conf
  • %WINDIR%\Temp\t_8jrfo2.0.cs
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\protection-log-2017-07-23-683212.txt
  • %WINDIR%\Installer\{2C992168-FB07-4D3E-884D-924DB7DFD2E8}\_853F67D554F05449430E7E.exe
  • %WINDIR%\Installer\240bc.msi
  • %TEMP%\~DF5DFB.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\custom.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\local.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\exclusions.dat
  • %WINDIR%\Temp\tempSysLog_56a51b7c-531f-44da-bba8-19c12f12d1af.txt
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\protection-log-2017-07-23.txt
  • %WINDIR%\Temp\tempSysLog_8eeed859-7beb-4579-99f5-a1427246d6e5.txt
  • %ALLUSERSPROFILE%\Application Data\sccomm\isthzlir.newcfg
  • %WINDIR%\Temp\t_8jrfo2.out
  • %WINDIR%\Temp\t_8jrfo2.cmdline
  • %WINDIR%\Temp\CSCE.tmp
  • %WINDIR%\Temp\t_8jrfo2.dll
  • %WINDIR%\Temp\RESF.tmp
  • %WINDIR%\Temp\7kvpam1l.dll
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\rules.new
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\version.check
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\rules.new.yaml
  • %ALLUSERSPROFILE%\Application Data\sccomm\omvkhslx.newcfg
  • %ProgramFiles%\Malwarebytes' Managed Client\gpix8ltm.newcfg
  • %ProgramFiles%\Malwarebytes' Anti-Malware\unins000.dat
  • %ProgramFiles%\Malwarebytes' Anti-Malware\unins000.msg
  • %TEMP%\coreinst.result
  • %ALLUSERSPROFILE%\Application Data\sccomm\ClientVersion.txt
  • %ALLUSERSPROFILE%\Application Data\sccomm\Policy.xml
  • %WINDIR%\Temp\7kvpam1l.cmdline
  • %WINDIR%\Temp\7kvpam1l.0.cs
  • %WINDIR%\Temp\7kvpam1l.out
  • %WINDIR%\Temp\RESC.tmp
  • %WINDIR%\Temp\CSCB.tmp
  • %WINDIR%\Installer\MSI9.tmp
  • %ProgramFiles%\Malwarebytes' Managed Client\SC.Client.Setup.CustomAtion.InstallState
  • %ProgramFiles%\Malwarebytes' Managed Client\SCComm.InstallState
  • %ALLUSERSPROFILE%\Application Data\sccomm\sccomm.log
  • %WINDIR%\Installer\MSIA.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-IVLJ6.tmp
  • %WINDIR%\Installer\240ba.ipi
  • %WINDIR%\Installer\MSI5.tmp-\CustomAction.config
  • %TEMP%\~DFDC83.tmp
  • C:\Config.Msi\240bb.rbs
  • %WINDIR%\Installer\MSI6.tmp
  • %WINDIR%\Installer\MSI4.tmp
  • %WINDIR%\Installer\MSI3.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI5.tmp
  • %WINDIR%\Installer\MSI5.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI5.tmp-\SC.Client.Setup.CustomOperation.dll
  • %ProgramFiles%\Malwarebytes' Managed Client\SCComm.exe.config
  • %ProgramFiles%\Malwarebytes' Managed Client\Microsoft.Web.Services3.dll
  • %ProgramFiles%\Malwarebytes' Managed Client\SC.Common.dll
  • %ProgramFiles%\Malwarebytes' Managed Client\Coreinst.exe
  • %WINDIR%\Installer\MSI8.tmp
  • %ProgramFiles%\Malwarebytes' Managed Client\SCComm.exe
  • %ProgramFiles%\Malwarebytes' Managed Client\SC.Client.Setup.CustomAtion.dll
  • %ProgramFiles%\Malwarebytes' Managed Client\MBAMHelper.exe
  • %ProgramFiles%\Malwarebytes' Managed Client\SC.WseBase.dll
  • %ProgramFiles%\Malwarebytes' Managed Client\mee_main.bmp
  • %WINDIR%\Installer\MSI3.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %TEMP%\rules.ref
  • %TEMP%\mbam.check.database
  • %TEMP%\rules.ref.yaml
  • %TEMP%\MBAMHelper.exe
  • %TEMP%\Coreinst.exe
  • %TEMP%\coreinst.xml
  • %TEMP%\ClientSetup.msi
  • %TEMP%\policy.xml
  • %TEMP%\ClientVersion.txt
  • %TEMP%\SCComm.xml
  • %WINDIR%\Installer\MSI1.tmp
  • %WINDIR%\Installer\240b8.msi
  • %TEMP%\CFG2.tmp
  • %WINDIR%\Installer\MSI3.tmp-\SC.Client.Setup.CustomOperation.dll
  • %WINDIR%\Installer\MSI3.tmp
  • %TEMP%\Microsoft.Web.Services3.dll
  • %TEMP%\setup.exe
  • %TEMP%\SC.Common.dll
  • %TEMP%\MSI23b3a.LOG
  • %TEMP%\SC.WseBase.dll
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-HFEOM.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-5ITE6.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-DBFSA.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-C5HFU.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-8HHQM.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-67G4T.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-ON2EG.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-TMOF9.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-E64A5.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-OMT6D.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-JDADF.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-DH6ER.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-I2IRO.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-MG0P0.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-FLCDD.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-5PSLH.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-FR5CA.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-8JSBS.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-0MUFV.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-N7R4R.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-3TCB2.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-9OMPB.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-A17HP.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-18R9D.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-9GRVC.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-PHJD1.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-H2AQB.tmp
  • %ProgramFiles%\Malwarebytes' Managed Client\coreinst.xml
  • <DRIVERS>\is-5GPL3.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-1BPKH.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-QF694.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-I69LI.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-QE0OA.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-3SHVV.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-6G2EE.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-QSEDB.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-GFDJ8.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-UMUSA.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-QQ054.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-VAQKN.tmp
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-27HQR.tmp
Удаляет следующие файлы:
  • %WINDIR%\Installer\MSI6.tmp
  • %WINDIR%\Installer\MSIA.tmp
  • %WINDIR%\Installer\240b8.msi
  • C:\Config.Msi\240bb.rbs
  • %WINDIR%\Temp\7kvpam1l.out
  • %WINDIR%\Temp\7kvpam1l.0.cs
  • %WINDIR%\Temp\7kvpam1l.dll
  • %WINDIR%\Temp\7kvpam1l.cmdline
  • %WINDIR%\Temp\t_8jrfo2.cmdline
  • %WINDIR%\Temp\t_8jrfo2.out
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\ignore.dat
  • %WINDIR%\Temp\t_8jrfo2.dll
  • %WINDIR%\Temp\RESF.tmp
  • %WINDIR%\Installer\240ba.ipi
  • %WINDIR%\Temp\t_8jrfo2.0.cs
  • %WINDIR%\Temp\CSCE.tmp
  • %WINDIR%\Temp\CSCB.tmp
  • %WINDIR%\Installer\MSI4.tmp
  • %WINDIR%\Installer\MSI3.tmp
  • %WINDIR%\Installer\MSI5.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI5.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI3.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI1.tmp
  • %WINDIR%\Installer\MSI3.tmp-\SC.Client.Setup.CustomOperation.dll
  • %WINDIR%\Installer\MSI3.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI8.tmp
  • %TEMP%\is-43GHQ.tmp\coreinst.tmp
  • %WINDIR%\Temp\RESC.tmp
  • %WINDIR%\Installer\MSI9.tmp
  • %WINDIR%\Installer\MSI5.tmp
  • %WINDIR%\Installer\MSI5.tmp-\SC.Client.Setup.CustomOperation.dll
  • %TEMP%\is-NMLMR.tmp\_isetup\_shfoldr.dll
  • %TEMP%\is-NMLMR.tmp\mbam.dll
Перемещает следующие файлы:
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-RS7AC.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\news.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-O21P4.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\html.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-8NNG9.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\custom.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-3EJAF.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\config.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-43A7N.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\build.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-F0702.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\database.conf
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-ON2HK.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\7z.dll
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-8KK7R.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\ssubtmr6.dll
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-S58ME.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\local.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-61DL2.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\manifest.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-HLLP8.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\messaging.conf
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-C4TE1.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\slovak.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-UI1BK.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\slovenian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-OQC6P.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\serbian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-K92EC.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\romanian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-UVKGI.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\russian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-EF1TP.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\spanish.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-DI6JP.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\vietnamese.lng
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\is-2GBKR.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\rules.ref
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-CM8DQ.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\turkish.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-GFDFT.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\swedish.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-ASQUM.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\thai.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-NG06T.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\rundll32.exe
  • %ProgramFiles%\Malwarebytes' Managed Client\gpix8ltm.newcfg в %ProgramFiles%\Malwarebytes' Managed Client\SCComm.exe.config
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-L3HL3.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-17G9Q.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\firefox.scr
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-CUMSV.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
  • %ALLUSERSPROFILE%\Application Data\sccomm\omvkhslx.newcfg в %ALLUSERSPROFILE%\Application Data\sccomm\SCComm.xml
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\protection-log-2017-07-23.txt в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\archived-protection-log-2017-07-23.txt
  • %WINDIR%\Temp\tempSysLog_8eeed859-7beb-4579-99f5-a1427246d6e5.txt в %ALLUSERSPROFILE%\Application Data\sccomm\txsyslog\tempSysLog_8eeed859-7beb-4579-99f5-a1427246d6e5.txt
  • %ALLUSERSPROFILE%\Application Data\sccomm\isthzlir.newcfg в %ALLUSERSPROFILE%\Application Data\sccomm\SCComm.xml
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\protection-log-2017-07-23-683212.txt в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\archived-protection-log-2017-07-23-683212.txt
  • %WINDIR%\Temp\tempSysLog_56a51b7c-531f-44da-bba8-19c12f12d1af.txt в %ALLUSERSPROFILE%\Application Data\sccomm\txsyslog\tempSysLog_56a51b7c-531f-44da-bba8-19c12f12d1af.txt
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-SRMID.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-NGB9V.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.com
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-URQB5.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\mbam-killer.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-0L6U6.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\vbalsgrid6.ocx
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-O7FI5.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-2T0VV.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.pif
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-ES8NN.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\firefox.com
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-02OL1.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\firefox.pif
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-55Q1A.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\firefox.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-CVRFB.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.scr
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\is-O8E2F.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-G38KP.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\portuguesePT.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-QE0OA.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\license.rtf
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-I69LI.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\changes.txt
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-VAQKN.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbam.chm
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-QQ054.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbamapi.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-27HQR.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbamhelper.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-3SHVV.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\arabic.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-ON2EG.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\catalan.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-67G4T.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\chineseSI.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-3TCB2.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\bulgarian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-QSEDB.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\belarusian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-6G2EE.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\bosnian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-1BPKH.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbam.dll
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-A17HP.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbamcore.dll
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-QF694.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbamext.dll
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-H2AQB.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\unins000.exe
  • <DRIVERS>\is-5GPL3.tmp в <DRIVERS>\mbam.sys
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-9OMPB.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbamnet.dll
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-UMUSA.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbamscheduler.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-GFDJ8.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbampt.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-9GRVC.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbamservice.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-18R9D.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\is-PHJD1.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\mbamgui.exe
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-JDADF.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\italian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-I2IRO.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\japanese.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-DH6ER.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\indonesian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-N7R4R.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\hebrew.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-0MUFV.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\hungarian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-FLCDD.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\korean.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-DOVIB.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\polish.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-G8LON.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\portugueseBR.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-OAGNB.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\norwegian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-MG0P0.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\latvian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-IVLJ6.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\lithuanian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-5ITE6.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\danish.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-HFEOM.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\dutch.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-E64A5.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\czech.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-TMOF9.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\chineseTR.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-OMT6D.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\croatian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-DBFSA.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\english.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-5PSLH.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\german.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-8JSBS.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\greek.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-FR5CA.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\french.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-8HHQM.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\estonian.lng
  • %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\is-C5HFU.tmp в %ProgramFiles%\Malwarebytes' Anti-Malware\Languages\finnish.lng
Сетевая активность:
Подключается к:
  • 'lo#####p11.adslocal.net':18457
UDP:
  • DNS ASK lo#####p11.adslocal.net
  • DNS ASK st###.#bamupdates.com
Другое:
Ищет следующие окна:
  • ClassName: '#32770' WindowName: 'Malwarebytes'
  • ClassName: '#32770' WindowName: 'Malwarebytes Managed Client'
  • ClassName: 'MsiDialogCloseClass' WindowName: 'Malwarebytes Managed Client'
  • ClassName: 'MsiDialogCloseClass' WindowName: 'Malwarebytes'

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке