Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop8.62648

Добавлен в вирусную базу Dr.Web: 2018-12-19

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Adguard' = '%ProgramFiles%\Adguard\Adguard.exe /nosplash /nosplash'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Adguard' = '%ProgramFiles%\Adguard\Adguard.exe /nosplash'
Создает следующие сервисы:
  • [<HKLM>\SYSTEM\ControlSet001\Services\Adguard Service] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\Adguard Service] 'ImagePath' = '"%ProgramFiles%\Adguard\AdguardSvc.exe"'
  • [<HKLM>\SYSTEM\ControlSet001\Services\adgnetworktdidrv] 'Start' = '00000001'
  • [<HKLM>\SYSTEM\ControlSet001\Services\adgnetworktdidrv] 'ImagePath' = 'system32\drivers\adgnetworktdidrv.sys'
Вредоносные функции:
Для обхода брандмауэра удаляет или модифицирует следующие ключи реестра:
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ProgramFiles%\Adguard\AdguardSvc.exe' = '%ProgramFiles%\Adguard\Adgua...
Изменения в файловой системе:
Создает следующие файлы:
  • C:\Progressive\Adguard\Adguard.exe.config
  • %ProgramFiles%\Adguard\AdguardSvc.exe
  • %ProgramFiles%\Adguard\AdguardNetLib.dll
  • %ProgramFiles%\Adguard\AdguardNetApi.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.zh-TW.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.zh.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.vi.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.uk.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.tr.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.sv.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.sr.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.sl.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.sk.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.ru.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.ro.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.pt-PT.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.pl.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.pt.dll
  • %ProgramFiles%\Adguard\AdguardSvc.exe.config
  • %ProgramFiles%\Adguard\AdguardSvc.exe.manifest
  • %ProgramFiles%\Adguard\nss\nss3.dll
  • %ProgramFiles%\Adguard\Newtonsoft.Json.dll
  • %ProgramFiles%\Adguard\Microsoft.Expression.Interactions.dll
  • %ProgramFiles%\Adguard\logo.png
  • %ProgramFiles%\Adguard\nss\libplds4.dll
  • %ProgramFiles%\Adguard\nss\libplc4.dll
  • %ProgramFiles%\Adguard\nss\libnspr4.dll
  • %ProgramFiles%\Adguard\default.adg
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.fa.dll
  • %ProgramFiles%\Adguard\ICSharpCode.AvalonEdit.dll
  • %ProgramFiles%\Adguard\nss\freebl3.dll
  • %ProgramFiles%\Adguard\drivers.bin
  • %ProgramFiles%\Adguard\nss\certutil.exe
  • %ProgramFiles%\Adguard\Brotli.NET.dll
  • %ProgramFiles%\Adguard\brolib64.dll
  • %ProgramFiles%\Adguard\brolib32.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.no.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.nl.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.ko.dll
  • %ProgramFiles%\Adguard\Adguard.Network.dll
  • %ProgramFiles%\Adguard\Adguard.Ipc.dll
  • %ProgramFiles%\Adguard\Adguard.Global.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.zh-TW.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.zh.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.vi.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.uk.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.tr.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.sv.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.sr.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.sk.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.ru.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.ro.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.pt-PT.dll
  • %ProgramFiles%\Adguard\Adguard.Service.dll
  • %ProgramFiles%\Adguard\Adguard.Tools.exe
  • %ProgramFiles%\Adguard\Adguard.Safebrowsing.dll
  • %ProgramFiles%\Adguard\Adguard.Tools.exe.manifest
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.ja.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.ar.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.it.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.id.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.hy.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.hu.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.hr.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.he.dll
  • %ProgramFiles%\Adguard\libs\inststlib64.dll
  • %ProgramFiles%\Adguard\nss\nssckbi.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.es.dll
  • %ProgramFiles%\Adguard\Adguard.UI.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.de.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.da.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.cs.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.bg.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.be.dll
  • %ProgramFiles%\Adguard\langs\Adguard.UI.resources.fr.dll
  • %ProgramFiles%\Adguard\nss\nssdbm3.dll
  • %ProgramFiles%\Adguard\nss\nssutil3.dll
  • %ProgramFiles%\Adguard\nss\smime3.dll
  • %ALLUSERSPROFILE%\Application Data\Adguard\safebrowsing.db
  • %ALLUSERSPROFILE%\Application Data\Adguard\safebrowsing.db-journal
  • %TEMP%\3B7A9.dmp
  • %TEMP%\dw.log
  • %ALLUSERSPROFILE%\Desktop\Adguard.lnk
  • <LS_APPDATA>\Adguard_Software_Ltd\Adguard.exe_StrongName_fx3hfgw3lp332eqb4g0rna0r2dpoucxg\6.4.1814.4903\hccnykoi.newcfg
  • %ALLUSERSPROFILE%\Application Data\Adguard\Logs\agent\agent_18-12-2018-16_31_15-2018-12-18.log
  • %WINDIR%\Installer\MSI10.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI10.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI10.tmp-\Adguard.CustomActions.dll
  • %ALLUSERSPROFILE%\Application Data\Adguard\locale.dat
  • %WINDIR%\Installer\MSI10.tmp
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Web of Trust.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Web of Trust Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Web of Trust.txt
  • %ALLUSERSPROFILE%\Application Data\fontcacheev1.dat
  • <DRIVERS>\vwifikerneldrv.sys
  • <SYSTEM32>\d3dx9_11.dll.tmp
  • %WINDIR%\WinSxS\poqexecv2sys.log
  • %ALLUSERSPROFILE%\Application Data\Adguard\NetworkTemp\SSL\cert.db
  • <DRIVERS>\adgnetworktdidrv.sys
  • %ProgramFiles%\Adguard\Drivers\x86\AdguardNetReg.exe
  • %ProgramFiles%\Adguard\Drivers\x86\AdguardNetLib.dll
  • %ProgramFiles%\Adguard\Drivers\x86\adgnetworkwfpdrv.sys
  • %ProgramFiles%\Adguard\Drivers\x86\adgnetworktdidrv.sys
  • %ProgramFiles%\Adguard\Drivers\x64\AdguardNetReg.exe
  • %ProgramFiles%\Adguard\Drivers\x64\adgnetworkwfpdrv.sys
  • %ProgramFiles%\Adguard\Drivers\x64\AdguardNetLib.dll
  • %ProgramFiles%\Adguard\Drivers\x64\adgnetworktdidrv.sys
  • %ProgramFiles%\Adguard\Drivers\win10\x86\adgnetworkwfpdrv.sys
  • %ProgramFiles%\Adguard\Drivers\win10\x86\adgnetworktdidrv.sys
  • %ProgramFiles%\Adguard\Drivers\win10\x64\adgnetworkwfpdrv.sys
  • %ProgramFiles%\Adguard\Drivers\win10\x64\adgnetworktdidrv.sys
  • %ALLUSERSPROFILE%\Application Data\Microsoft\Network\admngr.dat
  • %WINDIR%\ehome\usrsts..dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.pt.dll
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Popup Blocker by AdGuard (Beta).txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Popup Blocker by AdGuard.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Popup Blocker by AdGuard (Beta).txt
  • %WINDIR%\Installer\MSIF.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSIF.tmp
  • %WINDIR%\Installer\MSIE.tmp
  • %WINDIR%\Installer\{685F6AB3-7C61-42D1-AE5B-3864E48D1035}\Uninstall.exe
  • %WINDIR%\Installer\{685F6AB3-7C61-42D1-AE5B-3864E48D1035}\AdguardIcon.exe
  • %WINDIR%\Installer\2fb52.msi
  • %WINDIR%\Installer\MSIC.tmp
  • %ALLUSERSPROFILE%\Start Menu\Programs\Adguard\Uninstall AdGuard.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\Adguard\AdGuard.lnk
  • %WINDIR%\Installer\MSIB.tmp
  • %ProgramFiles%\Adguard\System.Windows.Interactivity.dll
  • %ProgramFiles%\Adguard\System.Data.SQLite.dll
  • %ProgramFiles%\Adguard\nss\sqlite3.dll
  • %ProgramFiles%\Adguard\SQLite.Interop.dll
  • %ProgramFiles%\Adguard\nss\softokn3.dll
  • %WINDIR%\Installer\MSIF.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSIF.tmp-\CustomAction.config
  • %ALLUSERSPROFILE%\Application Data\Adguard\Logs\service\service_18-12-2018-16_31_08-2018-12-18.log
  • %ALLUSERSPROFILE%\Application Data\Adguard\adguard.db-journal
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Adguard Assistant Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Web of Trust.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Web of Trust Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Popup Blocker by AdGuard.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Popup Blocker by AdGuard (Beta).txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Adguard Assistant.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Adguard Assistant Beta.txt
  • %ALLUSERSPROFILE%\Application Data\Adguard\NetworkTemp\SSL\Adguard Personal CA.cer
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Popup Blocker by AdGuard.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Adguard Assistant.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Adguard Assistant Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\settings.json
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Filters\6.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Filters\2.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Filters\1.txt
  • %ALLUSERSPROFILE%\Application Data\Adguard\adguard.db
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Adguard Assistant.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Web of Trust Beta.txt
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.pl.dll
  • %WINDIR%\Installer\MSI2.tmp-\CustomAction.config
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.zh.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.zh-TW.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.vi.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.uk.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.tr.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.sv.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.sr.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.sk.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.ru.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.ro.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.pt.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.pt-PT.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.pl.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.no.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.nl.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.ja.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.ko.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.ar.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.be.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.nl.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.ko.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.ja.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.it.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.id.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.hy.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.hu.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.he.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.bg.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.fr.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.fa.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.es.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.de.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.da.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.cs.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.bg.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.it.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.id.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.hy.dll
  • C:\Progressive\Adguard\Adguard.Network.dll
  • C:\Progressive\Adguard\Adguard.Ipc.dll
  • C:\Progressive\Adguard\Adguard.Global.dll
  • C:\Progressive\Adguard\Adguard.Filter.dll
  • C:\Progressive\Adguard\Adguard.exe
  • C:\Progressive\Adguard\Adguard.Commons.dll
  • C:\Progressive\setup.msi
  • C:\Progressive\Adguard\logo.png
  • C:\Progressive\Adguard\drivers.bin
  • C:\Progressive\Adguard\default.adg
  • C:\Progressive\Adguard\AdguardSvc.exe.manifest
  • C:\Progressive\Adguard\AdguardSvc.exe.config
  • C:\Progressive\Adguard\Adguard.Tools.exe.manifest
  • C:\Progressive\Adguard\Adguard.exe.manifest
  • C:\Progressive\Adguard\Adguard.Service.dll
  • C:\Progressive\Adguard\Adguard.Tools.exe
  • C:\Progressive\Adguard\Adguard.Safebrowsing.dll
  • C:\Progressive\Adguard\Adguard.UI.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.hu.dll
  • C:\Progressive\Adguard\AdguardNetApi.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.hr.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.he.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.fr.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.fa.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.es.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.de.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.hr.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.no.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.ar.dll
  • C:\Progressive\Adguard\ICSharpCode.AvalonEdit.dll
  • C:\Progressive\Adguard\Brotli.NET.dll
  • C:\Progressive\Adguard\brolib64.dll
  • C:\Progressive\Adguard\brolib32.dll
  • C:\Progressive\Adguard\AdguardSvc.exe
  • C:\Progressive\Adguard\AdguardNetLib.dll
  • C:\Progressive\Adguard\langs\Adguard.Filter.resources.da.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.pl.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.pt-PT.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.pt.dll
  • C:\Config.Msi\2fb51.rbs
  • %WINDIR%\Installer\MSI9.tmp
  • %WINDIR%\Installer\MSI8.tmp
  • %WINDIR%\Installer\MSI7.tmp
  • %WINDIR%\Installer\MSI6.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI6.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI6.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSI6.tmp
  • %WINDIR%\Installer\MSI5.tmp
  • %WINDIR%\Installer\2fb50.ipi
  • %WINDIR%\Installer\MSI4.tmp
  • %WINDIR%\Installer\MSI3.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI3.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI3.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSI3.tmp
  • %ProgramFiles%\Adguard\Adguard.Commons.dll
  • %ProgramFiles%\Adguard\Adguard.exe
  • %ProgramFiles%\Adguard\Adguard.exe.config
  • %ProgramFiles%\Adguard\Adguard.exe.manifest
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.ko.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.ja.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.it.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.id.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.hy.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.hu.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.hr.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.fr.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.he.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.fa.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.es.dll
  • %ProgramFiles%\Adguard\Adguard.Filter.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.de.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.da.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.bg.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.ar.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.no.dll
  • C:\Progressive\Adguard\SQLite.Interop.dll
  • %WINDIR%\Installer\MSI2.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI2.tmp-\Adguard.CustomActions.dll
  • C:\Progressive\Adguard\nss\certutil.exe
  • C:\Progressive\Adguard\Newtonsoft.Json.dll
  • C:\Progressive\Adguard\Microsoft.Expression.Interactions.dll
  • C:\Progressive\Adguard\libs\inststlib64.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.zh.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.zh-TW.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.vi.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.uk.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.tr.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.sv.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.sr.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.sl.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.sk.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.ru.dll
  • C:\Progressive\Adguard\langs\Adguard.UI.resources.ro.dll
  • C:\Progressive\Adguard\nss\freebl3.dll
  • C:\Progressive\Adguard\nss\libnspr4.dll
  • C:\Progressive\Adguard\nss\libplc4.dll
  • C:\Progressive\Adguard\nss\libplds4.dll
  • %WINDIR%\Installer\MSI1.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI1.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI1.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSI1.tmp
  • %WINDIR%\Installer\2fb4e.msi
  • C:\Progressive\Kur.exe
  • C:\Progressive\Adguard\System.Windows.Interactivity.dll
  • %ProgramFiles%\Adguard\langs\Adguard.Filter.resources.nl.dll
  • C:\Progressive\Adguard\System.Data.SQLite.dll
  • C:\Progressive\Adguard\nss\sqlite3.dll
  • C:\Progressive\Adguard\nss\softokn3.dll
  • C:\Progressive\Adguard\nss\smime3.dll
  • C:\Progressive\Adguard\nss\nssutil3.dll
  • C:\Progressive\Adguard\nss\nssdbm3.dll
  • C:\Progressive\Adguard\nss\nssckbi.dll
  • C:\Progressive\Adguard\nss\nss3.dll
  • %WINDIR%\Installer\MSI2.tmp
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\CJCTQ25G\wpad[1].cache
Удаляет следующие файлы:
  • %WINDIR%\Installer\MSI1.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Adguard Assistant.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Adguard Assistant Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Web of Trust.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Web of Trust Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Popup Blocker by AdGuard.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Popup Blocker by AdGuard (Beta).txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Filters\1.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Adguard Assistant.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Popup Blocker by AdGuard.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Popup Blocker by AdGuard (Beta).txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Adguard Assistant.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Adguard Assistant Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\settings.json
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Filters\6.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Requires\Adguard Assistant Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Filters\2.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Popup Blocker by AdGuard (Beta).txt
  • %ProgramFiles%\Adguard\Drivers\win10\x86\adgnetworktdidrv.sys
  • %ProgramFiles%\Adguard\Drivers\x86\adgnetworkwfpdrv.sys
  • %ProgramFiles%\Adguard\Drivers\x86\adgnetworktdidrv.sys
  • %ProgramFiles%\Adguard\Drivers\x64\AdguardNetReg.exe
  • %ProgramFiles%\Adguard\Drivers\x64\AdguardNetLib.dll
  • %ProgramFiles%\Adguard\Drivers\x64\adgnetworkwfpdrv.sys
  • %ProgramFiles%\Adguard\Drivers\x64\adgnetworktdidrv.sys
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Web of Trust Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Popup Blocker by AdGuard.txt
  • %ProgramFiles%\Adguard\Drivers\win10\x64\adgnetworkwfpdrv.sys
  • %ProgramFiles%\Adguard\Drivers\win10\x64\adgnetworktdidrv.sys
  • %ALLUSERSPROFILE%\Application Data\Adguard\safebrowsing.db-journal
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Web of Trust.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Web of Trust Beta.txt
  • %WINDIR%\Temp\Adguard\f420dba0c94740d6afc723c61ba1de21\Userscripts\Resources\Web of Trust.txt
  • %ProgramFiles%\Adguard\Drivers\win10\x86\adgnetworkwfpdrv.sys
  • %WINDIR%\Installer\2fb50.ipi
  • %WINDIR%\Installer\2fb4e.msi
  • %WINDIR%\Installer\MSI10.tmp
  • %WINDIR%\Installer\MSI6.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSI4.tmp
  • %WINDIR%\Installer\MSI3.tmp
  • %WINDIR%\Installer\MSI3.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI3.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI6.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI3.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSI2.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI2.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI2.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSI1.tmp
  • %WINDIR%\Installer\MSI1.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI1.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI2.tmp
  • %WINDIR%\Installer\MSI6.tmp
  • %WINDIR%\Installer\MSI6.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI7.tmp
  • <SYSTEM32>\d3d9caps.dat
  • %WINDIR%\Installer\MSIF.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSI10.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSI10.tmp-\CustomAction.config
  • %WINDIR%\Installer\MSI10.tmp-\Adguard.CustomActions.dll
  • %WINDIR%\Installer\MSIF.tmp
  • %WINDIR%\Installer\MSIF.tmp-\Microsoft.Deployment.WindowsInstaller.dll
  • %WINDIR%\Installer\MSIF.tmp-\CustomAction.config
  • %ALLUSERSPROFILE%\Application Data\Adguard\adguard.db-journal
  • %WINDIR%\Installer\MSI8.tmp
  • %WINDIR%\Installer\MSIE.tmp
  • C:\Config.Msi\2fb51.rbs
  • %WINDIR%\Installer\MSI5.tmp
  • %WINDIR%\Installer\MSIC.tmp
  • %WINDIR%\Installer\MSIB.tmp
  • %WINDIR%\Installer\MSI9.tmp
  • %ProgramFiles%\Adguard\Drivers\x86\AdguardNetLib.dll
  • %ProgramFiles%\Adguard\Drivers\x86\AdguardNetReg.exe
Перемещает следующие файлы:
  • <LS_APPDATA>\Adguard_Software_Ltd\Adguard.exe_StrongName_fx3hfgw3lp332eqb4g0rna0r2dpoucxg\6.4.1814.4903\hccnykoi.newcfg в <LS_APPDATA>\Adguard_Software_Ltd\Adguard.exe_StrongName_fx3hfgw3lp332eqb4g0rna0r2dpoucxg\6.4.1814.4903\user.config
Подменяет следующие файлы:
  • %ALLUSERSPROFILE%\Application Data\Adguard\adguard.db-journal
  • <SYSTEM32>\d3d9caps.dat
  • %ALLUSERSPROFILE%\Application Data\Adguard\safebrowsing.db-journal
Сетевая активность:
Подключается к:
  • 'wp#d':80
TCP:
Запросы HTTP GET:
  • http://11#.#11.111.2/wpad.dat via wp#d
UDP:
  • DNS ASK google.com
  • DNS ASK lo###.adguard.com
  • DNS ASK wp#d
Другое:
Добавляет корневой сертификат
Создает и запускает на исполнение:
  • 'C:\Progressive\Kur.exe'
  • '%ProgramFiles%\Adguard\AdguardSvc.exe'
  • '%ProgramFiles%\Adguard\Adguard.exe' /visible
  • '%ProgramFiles%\Adguard\nss\certutil.exe' -A -t "TCu" -i "%ALLUSERSPROFILE%\Application Data\Adguard\NetworkTemp\SSL\ADGUAR~1.CER" -n "Adguard Personal CA" -d "%APPDATA%\Mozilla\Firefox\Profiles\CWDGT0~1.DEF"
Запускает на исполнение:
  • '<SYSTEM32>\msiexec.exe' /i "C:\Progressive\setup.msi" /quiet /norestart INSTALLDESKTOPSHORTCUT=1
  • '<SYSTEM32>\cmd.exe' /C "schtasks /delete /tn AdguardUpdater /f"
  • '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1500
  • '<SYSTEM32>\rundll32.exe' "%WINDIR%\Installer\MSI10.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_234062 139 Adguard.CustomActions!Adguard.CustomActions.CustomActions.OnFirstInstallOrMajorUpgradeFinalize
  • '<SYSTEM32>\net1.exe' start "Adguard Service"
  • '<SYSTEM32>\net.exe' start "Adguard Service"
  • '<SYSTEM32>\cmd.exe' /C "net start "Adguard Service""
  • '<SYSTEM32>\schtasks.exe' /delete /tn AdguardUpdater /f
  • '<SYSTEM32>\rundll32.exe' "%WINDIR%\Installer\MSIF.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_221796 97 Adguard.CustomActions!Adguard.CustomActions.CustomActions.OnInstallFinalize
  • '<SYSTEM32>\rundll32.exe' "%WINDIR%\Installer\MSI6.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_207500 56 Adguard.CustomActions!Adguard.CustomActions.CustomActions.CheckServiceStop
  • '<SYSTEM32>\rundll32.exe' "%WINDIR%\Installer\MSI3.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_204515 31 Adguard.CustomActions!Adguard.CustomActions.CustomActions.OnInstallInitialize
  • '<SYSTEM32>\rundll32.exe' "%WINDIR%\Installer\MSI2.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_199921 12 Adguard.CustomActions!Adguard.CustomActions.CustomActions.PermanentActions
  • '<SYSTEM32>\rundll32.exe' "%WINDIR%\Installer\MSI1.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_197546 1 Adguard.CustomActions!Adguard.CustomActions.CustomActions.OnFirstInstall
  • '<SYSTEM32>\msiexec.exe' -Embedding 5181AD2E5EB1995C8186D9C9339624B2
  • '<SYSTEM32>\msiexec.exe' /V
  • '<SYSTEM32>\msiexec.exe' -Embedding 5651220097F3DC4377F4BAD0F5B63C74 M Global\MSI0000
  • '<SYSTEM32>\sc.exe' sdshow "Adguard Service"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке