Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.DownLoader30.31461

Добавлен в вирусную базу Dr.Web: 2019-10-28

Описание добавлено:

Техническая информация

Изменения в файловой системе
Создает следующие файлы
  • %TEMP%\nsscd1b.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_taskbar_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_taskbar_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_desktop_mail.ru agent.lnk
  • %TEMP%\c__users_user_desktop_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_mail.ru portal.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_uninstall mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_startmenu_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_startmenu_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_uninstall mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_winamp.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_winamp.lnk.tmp
  • %TEMP%\c__users_user_desktop_total commander 64 bit.lnk
  • %TEMP%\c__users_user_desktop_total commander 64 bit.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_uninstall or repair total commander.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_uninstall or repair total commander.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_total commander help.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_total commander help.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_total commander 64 bit.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_total commander 64 bit.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_qip 2012.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_qip 2012.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_qip 2012.lnk.tmp
  • %TEMP%\会议日程(最终版本-速发).docx .docx
  • <LS_APPDATA>\81.dll
  • <LS_APPDATA>\aecom.dat
  • <LS_APPDATA>\~$日程(最终版本-速发).docx .docx
  • <LS_APPDATA>\acrobat.bat
  • %TEMP%\c__users_user_desktop_telegram.lnk
  • %TEMP%\c__users_user_desktop_telegram.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_telegram desktop_uninstall telegram.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_telegram desktop_uninstall telegram.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_telegram desktop_telegram.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_telegram desktop_telegram.lnk.tmp
  • <LS_APPDATA>\会议日程(最终版本-速发).docx .docx
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_mozilla thunderbird.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_console rar manual.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_console rar manual.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_what is new in the latest version.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_what is new in the latest version.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_winrar help.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_winrar help.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_winrar.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_winrar.lnk.tmp
  • %TEMP%\c__users_user_desktop_qip 2012.lnk
  • %TEMP%\c__users_user_desktop_qip 2012.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_qip 2012.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_mozilla thunderbird.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_startmenu_icq.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_startmenu_icq.lnk.tmp
Удаляет следующие файлы
  • %TEMP%\c__users_user_desktop_telegram.lnk.tmp
  • %TEMP%\c__users_user_desktop_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_desktop_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_mail.ru portal.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_uninstall mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_uninstall mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_mail.ru_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_winamp.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_winamp.lnk
  • %TEMP%\c__users_user_desktop_total commander 64 bit.lnk.tmp
  • %TEMP%\c__users_user_desktop_total commander 64 bit.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_uninstall or repair total commander.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_uninstall or repair total commander.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_total commander help.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_total commander help.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_total commander 64 bit.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_total commander_total commander 64 bit.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_taskbar_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_startmenu_icq.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_taskbar_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_startmenu_mail.ru agent.lnk.tmp
  • %TEMP%\c__users_user_desktop_telegram.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_telegram desktop_uninstall telegram.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_telegram desktop_uninstall telegram.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_telegram desktop_telegram.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_telegram desktop_telegram.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_mozilla thunderbird.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_mozilla thunderbird.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_console rar manual.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_console rar manual.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_what is new in the latest version.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_what is new in the latest version.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_winrar help.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_winrar help.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_winrar.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_programs_winrar_winrar.lnk
  • %TEMP%\c__users_user_desktop_qip 2012.lnk.tmp
  • %TEMP%\c__users_user_desktop_qip 2012.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_qip 2012.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_qip 2012.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_qip 2012.lnk.tmp
  • %TEMP%\c__users_user_appdata_roaming_microsoft_windows_start menu_qip 2012.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_startmenu_mail.ru agent.lnk
  • %TEMP%\c__users_user_appdata_roaming_microsoft_internet explorer_quick launch_user pinned_startmenu_icq.lnk
Перемещает следующие файлы
  • <LS_APPDATA>\81.dll в <LS_APPDATA>\hgqhp.dll
Самоперемещается
  • из <Полный путь к файлу> в <Текущая директория>\会议日程(最终版本-速发).docx .docx
Сетевая активность
Подключается к
  • '10#.#86.113.117':80
Другое
Создает и запускает на исполнение
  • '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\..\hgqhp.dll",ServiceMain DllRegisterServer' (со скрытым окном)
  • '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\..\hgqhp.dll",DllMoveClassObject "%TEMP%\会议日程(最终版本-速发).docx ...' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%TEMP%\..\Application Data\Kingsoft\WPS Office\wpsupdate.exe"' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%TEMP%\..\Application Data\Kingsoft\WPS Office\wpsnotify.exe"' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%TEMP%\..\Application Data\Kingsoft\WPS Office\desktoptip.exe"' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%TEMP%\..\Application Data\Kingsoft\WPS Office\updateself.exe"' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%LOCALAPPDATA%\Kingsoft\WPS Office\wpsupdate.exe"' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%LOCALAPPDATA%\Kingsoft\WPS Office\wpsnotify.exe"' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%LOCALAPPDATA%\Kingsoft\WPS Office\desktoptip.exe"' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%LOCALAPPDATA%\Kingsoft\WPS Office\updateself.exe"' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c rundll32.exe "<LS_APPDATA>\hgqhp.dll",DllUninstall' (со скрытым окном)
Запускает на исполнение
  • '%ProgramFiles%\microsoft office\office14\winword.exe' /n "<LS_APPDATA>\会议日程(最终版本-速发).docx .docx"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\ICQ.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_Desktop_ICQ.lnk.tmp" "%HOMEPATH%\Desktop\ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_Desktop_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%HOMEPATH%\Desktop\ICQ.lnk" "%TEMP%\C__Users_user_Desktop_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_User Pinned_TaskBar_ICQ.lnk.tmp" "%APPDATA%\Microsoft\Internet Explor...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_User Pinned_TaskBar_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ICQ.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Q...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_User Pinned_StartMenu_ICQ.lnk.tmp" "%APPDATA%\Microsoft\Internet Expl...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_User Pinned_StartMenu_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\ICQ.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Total Commander_Total Commander 64 bit.lnk.tmp" "%APPDATA%\Microsoft\Win...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Total Commander_Total Commander 64 bit.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Total Commander\Total Commander 64 bit.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Total Commander_Total Commander Help.lnk.tmp" "%APPDATA%\Microsoft\Windo...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Total Commander_Total Commander Help.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Total Commander\Total Commander Help.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_S...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Total Commander_Uninstall or Repair Total Commander.lnk.tmp" "%APPDATA%\...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Total Commander_Uninstall or Repair Total Commander.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Total Commander\Uninstall or Repair Total Commander.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Micr...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_Desktop_Total Commander 64 bit.lnk.tmp" "%HOMEPATH%\Desktop\Total Commander 64 bit.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_Desktop_Total Commander 64 bit.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%HOMEPATH%\Desktop\Total Commander 64 bit.lnk" "%TEMP%\C__Users_user_Desktop_Total Commander 64 bit.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Winamp.lnk.tmp" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\W...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Winamp.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Winam...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Mail.Ru_Mail.Ru Agent.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\P...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Mail.Ru_Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Mail.Ru\Mail.Ru Agent.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Progr...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_ICQ.lnk.tmp" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\ICQ....
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\ICQ.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_ICQ.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Accessories_Notepad.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\Pro...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Accessories_Notepad.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Program...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Window Switcher.lnk.tmp" "%APPDATA%\Microsoft\Internet Explorer\Quick...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Window Switcher.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Lau...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Shows Desktop.lnk.tmp" "%APPDATA%\Microsoft\Internet Explorer\Quick L...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Shows Desktop.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launc...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Accessories_System Tools_Control Panel.lnk.tmp" "%APPDATA%\Microsoft\Win...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Accessories_System Tools_Control Panel.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_Links_RecentPlaces.lnk.tmp" "%HOMEPATH%\Links\RecentPlaces.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_Links_RecentPlaces.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_Links_Desktop.lnk.tmp" "%HOMEPATH%\Links\Desktop.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%HOMEPATH%\Links\RecentPlaces.lnk" "%TEMP%\C__Users_user_Links_RecentPlaces.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_Links_Desktop.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%HOMEPATH%\Links\Desktop.lnk" "%TEMP%\C__Users_user_Links_Desktop.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_Links_Downloads.lnk.tmp" "%HOMEPATH%\Links\Downloads.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_Links_Downloads.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%HOMEPATH%\Links\Downloads.lnk" "%TEMP%\C__Users_user_Links_Downloads.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_ICQ_ICQ.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\Programs\ICQ\IC...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_ICQ_ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\ICQ\ICQ.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_ICQ_ICQ.ln...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_ICQ_Uninstall ICQ.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\Progr...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_ICQ_Uninstall ICQ.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\ICQ\Uninstall ICQ.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_ICQ_icq.com.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\Programs\IC...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_ICQ_icq.com.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\ICQ\icq.com.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_ICQ_ic...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Ac...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Mail.Ru_Uninstall Mail.Ru Agent.lnk.tmp" "%APPDATA%\Microsoft\Windows\St...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Mail.Ru_Uninstall Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Mail.Ru\Uninstall Mail.Ru Agent.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start ...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windo...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinRAR_Console RAR manual.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Me...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinRAR_Console RAR manual.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_P...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Mozilla Thunderbird.lnk.tmp" "%APPDATA%\Microsoft\Internet Explorer\Q...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Mozilla Thunderbird.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Telegram Desktop_Telegram.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Me...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Telegram Desktop_Telegram.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Telegram Desktop\Telegram.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_P...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Telegram Desktop_Uninstall Telegram.lnk.tmp" "%APPDATA%\Microsoft\Window...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Telegram Desktop_Uninstall Telegram.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Telegram Desktop\Uninstall Telegram.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_St...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_Desktop_Telegram.lnk.tmp" "%HOMEPATH%\Desktop\Telegram.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_Desktop_Telegram.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%HOMEPATH%\Desktop\Telegram.lnk" "%TEMP%\C__Users_user_Desktop_Telegram.lnk"
  • '%WINDIR%\syswow64\cmd.exe' /c "<LS_APPDATA>\acrobat.bat"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllUninstall
  • '%WINDIR%\syswow64\cmd.exe' /c rundll32.exe "<LS_APPDATA>\hgqhp.dll",DllUninstall
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%LOCALAPPDATA%\Kingsoft\WPS Office\updateself.exe"
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%LOCALAPPDATA%\Kingsoft\WPS Office\desktoptip.exe"
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%LOCALAPPDATA%\Kingsoft\WPS Office\wpsnotify.exe"
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%LOCALAPPDATA%\Kingsoft\WPS Office\wpsupdate.exe"
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%TEMP%\..\Application Data\Kingsoft\WPS Office\updateself.exe"
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%TEMP%\..\Application Data\Kingsoft\WPS Office\desktoptip.exe"
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%TEMP%\..\Application Data\Kingsoft\WPS Office\wpsnotify.exe"
  • '%WINDIR%\syswow64\cmd.exe' /c del /s /f /q "%TEMP%\..\Application Data\Kingsoft\WPS Office\wpsupdate.exe"
  • '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\..\hgqhp.dll",DllMoveClassObject "%TEMP%\会议日程(最终版本-速发).docx ...
  • '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\..\hgqhp.dll",ServiceMain DllRegisterServer
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinRAR_What is new in the latest version.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinRAR_What is new in the latest version.lnk.tmp" "%APPDATA%\Microsoft\W...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinRAR_WinRAR help.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Mail.Ru_Mail.Ru Portal.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Mail.Ru\Mail.Ru Portal.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Prog...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Mail.Ru Agent.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Mail.Ru Agent.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Mail.Ru Agent.lnk.tmp" "%APPDATA%\Microsoft\Internet Explorer\Quick L...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Mail.Ru Agent.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launc...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_Desktop_Mail.Ru Agent.lnk.tmp" "%HOMEPATH%\Desktop\Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_Desktop_Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%HOMEPATH%\Desktop\Mail.Ru Agent.lnk" "%TEMP%\C__Users_user_Desktop_Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_User Pinned_TaskBar_Mail.Ru Agent.lnk.tmp" "%APPDATA%\Microsoft\Inter...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_User Pinned_TaskBar_Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mail.Ru Agent.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet ...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_User Pinned_StartMenu_Mail.Ru Agent.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_User Pinned_StartMenu_Mail.Ru Agent.lnk.tmp" "%APPDATA%\Microsoft\Int...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mail.Ru Agent.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Interne...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_QIP 2012.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\QIP 2012.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_QIP 2012.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\QIP 2012.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_QIP 2012.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_QIP 2012.lnk.tmp" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_QIP 2012.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\QIP 2012.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Internet Explorer_Quick Launch_QIP...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_Desktop_QIP 2012.lnk.tmp" "%HOMEPATH%\Desktop\QIP 2012.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_Desktop_QIP 2012.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%HOMEPATH%\Desktop\QIP 2012.lnk" "%TEMP%\C__Users_user_Desktop_QIP 2012.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinRAR_WinRAR.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\Programs\...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinRAR_WinRAR.lnk"
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%APPDATA%\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk" "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinR...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_WinRAR_WinRAR help.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\Prog...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllCopyClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Mail.Ru_Mail.Ru Portal.lnk.tmp" "%APPDATA%\Microsoft\Windows\Start Menu\...
  • '%WINDIR%\syswow64\rundll32.exe' "<LS_APPDATA>\hgqhp.dll",DllSetClassObject "%TEMP%\C__Users_user_AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Accessories_Run.lnk"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке