Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Inject.4516

Добавлен в вирусную базу Dr.Web: 2012-09-17

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt] 'DLLName' = 'crypts.dll'
Вредоносные функции:
Внедряет код в
следующие системные процессы:
  • %WINDIR%\Explorer.EXE
Изменения в файловой системе:
Создает следующие файлы:
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[54].php
  • %TEMP%\81FD.tmp
  • %TEMP%\851A.tmp
  • %TEMP%\8827.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[54].php
  • %TEMP%\7BF2.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[53].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[53].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[54].php
  • %TEMP%\7EFF.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[55].php
  • %TEMP%\9016.tmp
  • %TEMP%\92B6.tmp
  • %TEMP%\9517.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[55].php
  • %TEMP%\8B44.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[54].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[55].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[55].php
  • %TEMP%\8E03.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[51].php
  • %TEMP%\659B.tmp
  • %TEMP%\68A8.tmp
  • %TEMP%\6BA6.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[52].php
  • %TEMP%\5F81.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[51].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[51].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[51].php
  • %TEMP%\629E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[53].php
  • %TEMP%\73F3.tmp
  • %TEMP%\76B2.tmp
  • %TEMP%\78F4.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[53].php
  • %TEMP%\6EA4.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[52].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[52].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[52].php
  • %TEMP%\7134.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[59].php
  • %TEMP%\BEA8.tmp
  • %TEMP%\C0DB.tmp
  • %TEMP%\C30D.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[59].php
  • %TEMP%\BA53.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[58].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[58].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[59].php
  • %TEMP%\BC85.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[60].php
  • %TEMP%\CB4A.tmp
  • %TEMP%\CD4E.tmp
  • %TEMP%\CFA0.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[60].php
  • %TEMP%\C63A.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[59].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[60].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[60].php
  • %TEMP%\C908.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[56].php
  • %TEMP%\9E6E.tmp
  • %TEMP%\A246.tmp
  • %TEMP%\A757.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[57].php
  • %TEMP%\999C.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[56].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[56].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[56].php
  • %TEMP%\9C1C.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[58].php
  • %TEMP%\B2D1.tmp
  • %TEMP%\B5A0.tmp
  • %TEMP%\B7F1.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[58].php
  • %TEMP%\AA45.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[57].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[57].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[57].php
  • %TEMP%\B09E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[44].php
  • %TEMP%\C9E.tmp
  • %TEMP%\F8C.tmp
  • %TEMP%\1299.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[44].php
  • %TEMP%\6A3.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[43].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[43].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[44].php
  • %TEMP%\9A0.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[45].php
  • %TEMP%\1B82.tmp
  • %TEMP%\1EAF.tmp
  • %TEMP%\218D.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[45].php
  • %TEMP%\1597.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[44].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[45].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[45].php
  • %TEMP%\1894.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[41].php
  • %TEMP%\EF33.tmp
  • %TEMP%\F1D3.tmp
  • %TEMP%\F4D0.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[42].php
  • %TEMP%\EA03.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[41].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[41].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[41].php
  • %TEMP%\ECC2.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[43].php
  • %TEMP%\FDB9.tmp
  • %TEMP%\B7.tmp
  • %TEMP%\3B5.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[43].php
  • %TEMP%\F7CE.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[42].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[42].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[42].php
  • %TEMP%\FABC.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[49].php
  • %TEMP%\4707.tmp
  • %TEMP%\4A05.tmp
  • %TEMP%\4D02.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[49].php
  • %TEMP%\40ED.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[48].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[48].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[49].php
  • %TEMP%\43FA.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[50].php
  • %TEMP%\563A.tmp
  • %TEMP%\5976.tmp
  • %TEMP%\5C83.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[50].php
  • %TEMP%\501F.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[49].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[50].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[50].php
  • %TEMP%\531D.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[46].php
  • %TEMP%\28E0.tmp
  • %TEMP%\2BDE.tmp
  • %TEMP%\2EDC.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[47].php
  • %TEMP%\240E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[46].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[46].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[46].php
  • %TEMP%\2640.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[48].php
  • %TEMP%\37D4.tmp
  • %TEMP%\3AE2.tmp
  • %TEMP%\3DEF.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[48].php
  • %TEMP%\31D9.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[47].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[47].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[47].php
  • %TEMP%\34D7.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[74].php
  • %TEMP%\7FD5.tmp
  • %TEMP%\8246.tmp
  • %TEMP%\863E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[74].php
  • %TEMP%\79AB.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[73].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[73].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[74].php
  • %TEMP%\7CB8.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[75].php
  • %TEMP%\9031.tmp
  • %TEMP%\936D.tmp
  • %TEMP%\96A9.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[75].php
  • %TEMP%\898A.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[74].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[75].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[75].php
  • %TEMP%\8CE5.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[71].php
  • %TEMP%\620C.tmp
  • %TEMP%\6519.tmp
  • %TEMP%\6827.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[72].php
  • %TEMP%\5BB3.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[71].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[71].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[71].php
  • %TEMP%\5EC0.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[73].php
  • %TEMP%\70C2.tmp
  • %TEMP%\73A0.tmp
  • %TEMP%\769E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[73].php
  • %TEMP%\6B53.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[72].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[72].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[72].php
  • %TEMP%\6E51.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[79].php
  • %TEMP%\BC52.tmp
  • %TEMP%\BF20.tmp
  • %TEMP%\C2D9.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[79].php
  • %TEMP%\B6F3.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[78].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[78].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[79].php
  • %TEMP%\B983.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[80].php
  • %TEMP%\CA3C.tmp
  • %TEMP%\CCCC.tmp
  • %TEMP%\CF8B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[80].php
  • %TEMP%\C55A.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[79].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[80].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[80].php
  • %TEMP%\C7DB.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[76].php
  • %TEMP%\9FA2.tmp
  • %TEMP%\A251.tmp
  • %TEMP%\A56E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[77].php
  • %TEMP%\9968.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[76].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[76].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[76].php
  • %TEMP%\9CA4.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[78].php
  • %TEMP%\AF13.tmp
  • %TEMP%\B155.tmp
  • %TEMP%\B414.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[78].php
  • %TEMP%\A8CA.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[77].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[77].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[77].php
  • %TEMP%\AC15.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[64].php
  • %TEMP%\DF1.tmp
  • %TEMP%\10DF.tmp
  • %TEMP%\13BD.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[64].php
  • %TEMP%\9AB.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[63].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[63].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[64].php
  • %TEMP%\BCE.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[65].php
  • %TEMP%\1C1A.tmp
  • %TEMP%\1E9B.tmp
  • %TEMP%\211B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[65].php
  • %TEMP%\163E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[64].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[65].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[65].php
  • %TEMP%\18AF.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[61].php
  • %TEMP%\DF30.tmp
  • %TEMP%\EBD3.tmp
  • %TEMP%\F587.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[62].php
  • %TEMP%\D1F2.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[61].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[61].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[61].php
  • %TEMP%\D7CE.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[63].php
  • %TEMP%\304.tmp
  • %TEMP%\546.tmp
  • %TEMP%\769.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[63].php
  • %TEMP%\FDA5.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[62].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[62].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[62].php
  • %TEMP%\74.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[69].php
  • %TEMP%\4388.tmp
  • %TEMP%\46A5.tmp
  • %TEMP%\49C1.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[69].php
  • %TEMP%\3D7D.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[68].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[68].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[69].php
  • %TEMP%\407A.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[70].php
  • %TEMP%\526C.tmp
  • %TEMP%\5579.tmp
  • %TEMP%\5896.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[70].php
  • %TEMP%\4C90.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[69].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[70].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[70].php
  • %TEMP%\4F8E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[66].php
  • %TEMP%\28CC.tmp
  • %TEMP%\2B1E.tmp
  • %TEMP%\2D6F.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[67].php
  • %TEMP%\2409.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[66].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[66].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[66].php
  • %TEMP%\265B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[68].php
  • %TEMP%\360B.tmp
  • %TEMP%\38BA.tmp
  • %TEMP%\3B1B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[68].php
  • %TEMP%\307D.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[67].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[67].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[67].php
  • %TEMP%\338A.tmp
  • %TEMP%\E7A1.tmp
  • %TEMP%\C2C8.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[14].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[14].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[14].php
  • %TEMP%\C4CC.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[13].php
  • %TEMP%\BC8F.tmp
  • %TEMP%\BEE0.tmp
  • %TEMP%\C0F4.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[13].php
  • %TEMP%\CD58.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[15].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[15].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[15].php
  • %TEMP%\CF5B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[14].php
  • %TEMP%\C6B0.tmp
  • %TEMP%\C950.tmp
  • %TEMP%\CB64.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[15].php
  • %TEMP%\AACC.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[11].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[11].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[12].php
  • %TEMP%\AD5C.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[11].php
  • %TEMP%\A33A.tmp
  • %TEMP%\A5AB.tmp
  • %TEMP%\A84B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[11].php
  • %TEMP%\B80A.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[12].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[13].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[13].php
  • %TEMP%\BA0E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[12].php
  • %TEMP%\AFFC.tmp
  • %TEMP%\B29C.tmp
  • %TEMP%\B53C.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[12].php
  • %TEMP%\F283.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[19].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[19].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[19].php
  • %TEMP%\F571.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[18].php
  • %TEMP%\EA46.tmp
  • %TEMP%\ECD6.tmp
  • %TEMP%\EFA5.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[18].php
  • %TEMP%\7D.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[20].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[20].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[20].php
  • %TEMP%\37B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[19].php
  • %TEMP%\F850.tmp
  • %TEMP%\FB2E.tmp
  • %TEMP%\FDFD.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[20].php
  • %TEMP%\D7C7.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[16].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[16].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[17].php
  • %TEMP%\D9EA.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[16].php
  • %TEMP%\D19D.tmp
  • %TEMP%\D40E.tmp
  • %TEMP%\D602.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[16].php
  • %TEMP%\E4C8.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[17].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[18].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[18].php
  • %TEMP%\E787.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[17].php
  • %TEMP%\DC8A.tmp
  • %TEMP%\DF49.tmp
  • %TEMP%\E218.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[17].php
  • %TEMP%\56FF.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[4].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[4].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[4].php
  • %TEMP%\5A1C.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[3].php
  • %TEMP%\5086.tmp
  • %TEMP%\529A.tmp
  • %TEMP%\549D.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[3].php
  • %TEMP%\649B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[5].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[5].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[5].php
  • %TEMP%\66FC.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[4].php
  • %TEMP%\5D67.tmp
  • %TEMP%\6046.tmp
  • %TEMP%\622A.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[5].php
  • %TEMP%\3D7B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[1].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[1].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[2].php
  • %TEMP%\40D7.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[1].php
  • <SYSTEM32>\crypts.dll
  • %TEMP%\32CD.tmp
  • %TEMP%\3B59.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[1].php
  • %TEMP%\4B08.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[2].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[3].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[3].php
  • %TEMP%\4EA2.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[2].php
  • %TEMP%\4377.tmp
  • %TEMP%\45B9.tmp
  • %TEMP%\47BC.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[2].php
  • %TEMP%\9010.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[9].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[9].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[9].php
  • %TEMP%\92DF.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[8].php
  • %TEMP%\87B3.tmp
  • %TEMP%\8A73.tmp
  • %TEMP%\8D51.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[8].php
  • %TEMP%\9DFB.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[10].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[10].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[10].php
  • %TEMP%\A0C9.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[9].php
  • %TEMP%\95AE.tmp
  • %TEMP%\986D.tmp
  • %TEMP%\9B2C.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[10].php
  • %TEMP%\765E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[6].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[6].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[7].php
  • %TEMP%\78BF.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[6].php
  • %TEMP%\6A19.tmp
  • %TEMP%\713D.tmp
  • %TEMP%\73FD.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[6].php
  • %TEMP%\8264.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[7].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[8].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[8].php
  • %TEMP%\8504.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[7].php
  • %TEMP%\7B40.tmp
  • %TEMP%\7DB1.tmp
  • %TEMP%\7FE3.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[7].php
  • %TEMP%\887A.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[34].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[34].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[34].php
  • %TEMP%\8ABC.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[33].php
  • %TEMP%\8108.tmp
  • %TEMP%\8369.tmp
  • %TEMP%\85DA.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[33].php
  • %TEMP%\93F3.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[35].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[35].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[35].php
  • %TEMP%\9674.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[34].php
  • %TEMP%\8D0E.tmp
  • %TEMP%\8FBD.tmp
  • %TEMP%\91E0.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[35].php
  • %TEMP%\704E.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[31].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[31].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[32].php
  • %TEMP%\7281.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[31].php
  • %TEMP%\692A.tmp
  • %TEMP%\6B5D.tmp
  • %TEMP%\6E1C.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[31].php
  • %TEMP%\7A60.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[32].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[33].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[33].php
  • %TEMP%\7D00.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[32].php
  • %TEMP%\7465.tmp
  • %TEMP%\7659.tmp
  • %TEMP%\785D.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[32].php
  • %TEMP%\D448.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[39].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[39].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[39].php
  • %TEMP%\D6A9.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[38].php
  • %TEMP%\CE2E.tmp
  • %TEMP%\D031.tmp
  • %TEMP%\D225.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[38].php
  • %TEMP%\E213.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[40].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[40].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[40].php
  • %TEMP%\E4F2.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[39].php
  • %TEMP%\D997.tmp
  • %TEMP%\DC95.tmp
  • %TEMP%\DF25.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[40].php
  • %TEMP%\A2F7.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[36].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[36].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[37].php
  • %TEMP%\B0C2.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[36].php
  • %TEMP%\9914.tmp
  • %TEMP%\9BC3.tmp
  • %TEMP%\9FBB.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[36].php
  • %TEMP%\C43B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[37].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[38].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[38].php
  • %TEMP%\CAB3.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[37].php
  • %TEMP%\B660.tmp
  • %TEMP%\BA38.tmp
  • %TEMP%\C005.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[37].php
  • %TEMP%\2403.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[24].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[24].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[24].php
  • %TEMP%\2664.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[23].php
  • %TEMP%\1C81.tmp
  • %TEMP%\1F21.tmp
  • %TEMP%\21D1.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[23].php
  • %TEMP%\2FCB.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[25].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[25].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[25].php
  • %TEMP%\325B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[24].php
  • %TEMP%\2897.tmp
  • %TEMP%\2B27.tmp
  • %TEMP%\2D2B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[25].php
  • %TEMP%\C93.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[21].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[21].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[22].php
  • %TEMP%\EE5.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[21].php
  • %TEMP%\5CD.tmp
  • %TEMP%\7D0.tmp
  • %TEMP%\A03.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[21].php
  • %TEMP%\179F.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[22].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[23].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[23].php
  • %TEMP%\19A3.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[22].php
  • %TEMP%\1185.tmp
  • %TEMP%\1388.tmp
  • %TEMP%\159C.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[22].php
  • %TEMP%\5832.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[29].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[29].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[29].php
  • %TEMP%\5AF2.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[28].php
  • %TEMP%\4FD6.tmp
  • %TEMP%\5295.tmp
  • %TEMP%\5554.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[28].php
  • %TEMP%\64F4.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[30].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[30].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[30].php
  • %TEMP%\6707.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[29].php
  • %TEMP%\5DC0.tmp
  • %TEMP%\6012.tmp
  • %TEMP%\62C2.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[30].php
  • %TEMP%\3CEA.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[26].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[26].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[27].php
  • %TEMP%\3F5B.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[26].php
  • %TEMP%\34BC.tmp
  • %TEMP%\377B.tmp
  • %TEMP%\3A5A.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[26].php
  • %TEMP%\4A96.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\bt[27].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bt[28].php
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[28].php
  • %TEMP%\4D36.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[27].php
  • %TEMP%\4249.tmp
  • %TEMP%\4527.tmp
  • %TEMP%\47F6.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bt[27].php
Удаляет следующие файлы:
  • %TEMP%\851A.tmp
  • %TEMP%\8827.tmp
  • %TEMP%\81FD.tmp
  • %TEMP%\7BF2.tmp
  • %TEMP%\7EFF.tmp
  • %TEMP%\92B6.tmp
  • %TEMP%\9517.tmp
  • %TEMP%\9016.tmp
  • %TEMP%\8B44.tmp
  • %TEMP%\8E03.tmp
  • %TEMP%\68A8.tmp
  • %TEMP%\6BA6.tmp
  • %TEMP%\659B.tmp
  • %TEMP%\5F81.tmp
  • %TEMP%\629E.tmp
  • %TEMP%\76B2.tmp
  • %TEMP%\78F4.tmp
  • %TEMP%\73F3.tmp
  • %TEMP%\6EA4.tmp
  • %TEMP%\7134.tmp
  • %TEMP%\C0DB.tmp
  • %TEMP%\C30D.tmp
  • %TEMP%\BEA8.tmp
  • %TEMP%\BA53.tmp
  • %TEMP%\BC85.tmp
  • %TEMP%\CD4E.tmp
  • %TEMP%\CFA0.tmp
  • %TEMP%\CB4A.tmp
  • %TEMP%\C63A.tmp
  • %TEMP%\C908.tmp
  • %TEMP%\A246.tmp
  • %TEMP%\A757.tmp
  • %TEMP%\9E6E.tmp
  • %TEMP%\999C.tmp
  • %TEMP%\9C1C.tmp
  • %TEMP%\B5A0.tmp
  • %TEMP%\B7F1.tmp
  • %TEMP%\B2D1.tmp
  • %TEMP%\AA45.tmp
  • %TEMP%\B09E.tmp
  • %TEMP%\F8C.tmp
  • %TEMP%\1299.tmp
  • %TEMP%\C9E.tmp
  • %TEMP%\6A3.tmp
  • %TEMP%\9A0.tmp
  • %TEMP%\1EAF.tmp
  • %TEMP%\218D.tmp
  • %TEMP%\1B82.tmp
  • %TEMP%\1597.tmp
  • %TEMP%\1894.tmp
  • %TEMP%\F1D3.tmp
  • %TEMP%\F4D0.tmp
  • %TEMP%\EF33.tmp
  • %TEMP%\EA03.tmp
  • %TEMP%\ECC2.tmp
  • %TEMP%\B7.tmp
  • %TEMP%\3B5.tmp
  • %TEMP%\FDB9.tmp
  • %TEMP%\F7CE.tmp
  • %TEMP%\FABC.tmp
  • %TEMP%\4A05.tmp
  • %TEMP%\4D02.tmp
  • %TEMP%\4707.tmp
  • %TEMP%\40ED.tmp
  • %TEMP%\43FA.tmp
  • %TEMP%\5976.tmp
  • %TEMP%\5C83.tmp
  • %TEMP%\563A.tmp
  • %TEMP%\501F.tmp
  • %TEMP%\531D.tmp
  • %TEMP%\2BDE.tmp
  • %TEMP%\2EDC.tmp
  • %TEMP%\28E0.tmp
  • %TEMP%\240E.tmp
  • %TEMP%\2640.tmp
  • %TEMP%\3AE2.tmp
  • %TEMP%\3DEF.tmp
  • %TEMP%\37D4.tmp
  • %TEMP%\31D9.tmp
  • %TEMP%\34D7.tmp
  • %TEMP%\8246.tmp
  • %TEMP%\863E.tmp
  • %TEMP%\7FD5.tmp
  • %TEMP%\79AB.tmp
  • %TEMP%\7CB8.tmp
  • %TEMP%\936D.tmp
  • %TEMP%\96A9.tmp
  • %TEMP%\9031.tmp
  • %TEMP%\898A.tmp
  • %TEMP%\8CE5.tmp
  • %TEMP%\6519.tmp
  • %TEMP%\6827.tmp
  • %TEMP%\620C.tmp
  • %TEMP%\5BB3.tmp
  • %TEMP%\5EC0.tmp
  • %TEMP%\73A0.tmp
  • %TEMP%\769E.tmp
  • %TEMP%\70C2.tmp
  • %TEMP%\6B53.tmp
  • %TEMP%\6E51.tmp
  • %TEMP%\BF20.tmp
  • %TEMP%\C2D9.tmp
  • %TEMP%\BC52.tmp
  • %TEMP%\B6F3.tmp
  • %TEMP%\B983.tmp
  • %TEMP%\CCCC.tmp
  • %TEMP%\CF8B.tmp
  • %TEMP%\CA3C.tmp
  • %TEMP%\C55A.tmp
  • %TEMP%\C7DB.tmp
  • %TEMP%\A251.tmp
  • %TEMP%\A56E.tmp
  • %TEMP%\9FA2.tmp
  • %TEMP%\9968.tmp
  • %TEMP%\9CA4.tmp
  • %TEMP%\B155.tmp
  • %TEMP%\B414.tmp
  • %TEMP%\AF13.tmp
  • %TEMP%\A8CA.tmp
  • %TEMP%\AC15.tmp
  • %TEMP%\10DF.tmp
  • %TEMP%\13BD.tmp
  • %TEMP%\DF1.tmp
  • %TEMP%\9AB.tmp
  • %TEMP%\BCE.tmp
  • %TEMP%\1E9B.tmp
  • %TEMP%\211B.tmp
  • %TEMP%\1C1A.tmp
  • %TEMP%\163E.tmp
  • %TEMP%\18AF.tmp
  • %TEMP%\EBD3.tmp
  • %TEMP%\F587.tmp
  • %TEMP%\DF30.tmp
  • %TEMP%\D1F2.tmp
  • %TEMP%\D7CE.tmp
  • %TEMP%\546.tmp
  • %TEMP%\769.tmp
  • %TEMP%\304.tmp
  • %TEMP%\FDA5.tmp
  • %TEMP%\74.tmp
  • %TEMP%\46A5.tmp
  • %TEMP%\49C1.tmp
  • %TEMP%\4388.tmp
  • %TEMP%\3D7D.tmp
  • %TEMP%\407A.tmp
  • %TEMP%\5579.tmp
  • %TEMP%\5896.tmp
  • %TEMP%\526C.tmp
  • %TEMP%\4C90.tmp
  • %TEMP%\4F8E.tmp
  • %TEMP%\2B1E.tmp
  • %TEMP%\2D6F.tmp
  • %TEMP%\28CC.tmp
  • %TEMP%\2409.tmp
  • %TEMP%\265B.tmp
  • %TEMP%\38BA.tmp
  • %TEMP%\3B1B.tmp
  • %TEMP%\360B.tmp
  • %TEMP%\307D.tmp
  • %TEMP%\338A.tmp
  • %TEMP%\C4CC.tmp
  • %TEMP%\C6B0.tmp
  • %TEMP%\C2C8.tmp
  • %TEMP%\BEE0.tmp
  • %TEMP%\C0F4.tmp
  • %TEMP%\CF5B.tmp
  • %TEMP%\D19D.tmp
  • %TEMP%\CD58.tmp
  • %TEMP%\C950.tmp
  • %TEMP%\CB64.tmp
  • %TEMP%\AD5C.tmp
  • %TEMP%\AFFC.tmp
  • %TEMP%\AACC.tmp
  • %TEMP%\A5AB.tmp
  • %TEMP%\A84B.tmp
  • %TEMP%\BA0E.tmp
  • %TEMP%\BC8F.tmp
  • %TEMP%\B80A.tmp
  • %TEMP%\B29C.tmp
  • %TEMP%\B53C.tmp
  • %TEMP%\F571.tmp
  • %TEMP%\F850.tmp
  • %TEMP%\F283.tmp
  • %TEMP%\ECD6.tmp
  • %TEMP%\EFA5.tmp
  • %TEMP%\37B.tmp
  • %TEMP%\5CD.tmp
  • %TEMP%\7D.tmp
  • %TEMP%\FB2E.tmp
  • %TEMP%\FDFD.tmp
  • %TEMP%\D9EA.tmp
  • %TEMP%\DC8A.tmp
  • %TEMP%\D7C7.tmp
  • %TEMP%\D40E.tmp
  • %TEMP%\D602.tmp
  • %TEMP%\E787.tmp
  • %TEMP%\EA46.tmp
  • %TEMP%\E4C8.tmp
  • %TEMP%\DF49.tmp
  • %TEMP%\E218.tmp
  • %TEMP%\5A1C.tmp
  • %TEMP%\5D67.tmp
  • %TEMP%\56FF.tmp
  • %TEMP%\529A.tmp
  • %TEMP%\549D.tmp
  • %TEMP%\66FC.tmp
  • %TEMP%\6A19.tmp
  • %TEMP%\649B.tmp
  • %TEMP%\6046.tmp
  • %TEMP%\622A.tmp
  • %TEMP%\40D7.tmp
  • %TEMP%\4377.tmp
  • %TEMP%\3D7B.tmp
  • %TEMP%\32CD.tmp
  • %TEMP%\3B59.tmp
  • %TEMP%\4EA2.tmp
  • %TEMP%\5086.tmp
  • %TEMP%\4B08.tmp
  • %TEMP%\45B9.tmp
  • %TEMP%\47BC.tmp
  • %TEMP%\92DF.tmp
  • %TEMP%\95AE.tmp
  • %TEMP%\9010.tmp
  • %TEMP%\8A73.tmp
  • %TEMP%\8D51.tmp
  • %TEMP%\A0C9.tmp
  • %TEMP%\A33A.tmp
  • %TEMP%\9DFB.tmp
  • %TEMP%\986D.tmp
  • %TEMP%\9B2C.tmp
  • %TEMP%\78BF.tmp
  • %TEMP%\7B40.tmp
  • %TEMP%\765E.tmp
  • %TEMP%\713D.tmp
  • %TEMP%\73FD.tmp
  • %TEMP%\8504.tmp
  • %TEMP%\87B3.tmp
  • %TEMP%\8264.tmp
  • %TEMP%\7DB1.tmp
  • %TEMP%\7FE3.tmp
  • %TEMP%\8ABC.tmp
  • %TEMP%\8D0E.tmp
  • %TEMP%\887A.tmp
  • %TEMP%\8369.tmp
  • %TEMP%\85DA.tmp
  • %TEMP%\9674.tmp
  • %TEMP%\9914.tmp
  • %TEMP%\93F3.tmp
  • %TEMP%\8FBD.tmp
  • %TEMP%\91E0.tmp
  • %TEMP%\7281.tmp
  • %TEMP%\7465.tmp
  • %TEMP%\704E.tmp
  • %TEMP%\6B5D.tmp
  • %TEMP%\6E1C.tmp
  • %TEMP%\7D00.tmp
  • %TEMP%\8108.tmp
  • %TEMP%\7A60.tmp
  • %TEMP%\7659.tmp
  • %TEMP%\785D.tmp
  • %TEMP%\D6A9.tmp
  • %TEMP%\D997.tmp
  • %TEMP%\D448.tmp
  • %TEMP%\D031.tmp
  • %TEMP%\D225.tmp
  • %TEMP%\E4F2.tmp
  • %TEMP%\E7A1.tmp
  • %TEMP%\E213.tmp
  • %TEMP%\DC95.tmp
  • %TEMP%\DF25.tmp
  • %TEMP%\B0C2.tmp
  • %TEMP%\B660.tmp
  • %TEMP%\A2F7.tmp
  • %TEMP%\9BC3.tmp
  • %TEMP%\9FBB.tmp
  • %TEMP%\CAB3.tmp
  • %TEMP%\CE2E.tmp
  • %TEMP%\C43B.tmp
  • %TEMP%\BA38.tmp
  • %TEMP%\C005.tmp
  • %TEMP%\2664.tmp
  • %TEMP%\2897.tmp
  • %TEMP%\2403.tmp
  • %TEMP%\1F21.tmp
  • %TEMP%\21D1.tmp
  • %TEMP%\325B.tmp
  • %TEMP%\34BC.tmp
  • %TEMP%\2FCB.tmp
  • %TEMP%\2B27.tmp
  • %TEMP%\2D2B.tmp
  • %TEMP%\EE5.tmp
  • %TEMP%\1185.tmp
  • %TEMP%\C93.tmp
  • %TEMP%\7D0.tmp
  • %TEMP%\A03.tmp
  • %TEMP%\19A3.tmp
  • %TEMP%\1C81.tmp
  • %TEMP%\179F.tmp
  • %TEMP%\1388.tmp
  • %TEMP%\159C.tmp
  • %TEMP%\5AF2.tmp
  • %TEMP%\5DC0.tmp
  • %TEMP%\5832.tmp
  • %TEMP%\5295.tmp
  • %TEMP%\5554.tmp
  • %TEMP%\6707.tmp
  • %TEMP%\692A.tmp
  • %TEMP%\64F4.tmp
  • %TEMP%\6012.tmp
  • %TEMP%\62C2.tmp
  • %TEMP%\3F5B.tmp
  • %TEMP%\4249.tmp
  • %TEMP%\3CEA.tmp
  • %TEMP%\377B.tmp
  • %TEMP%\3A5A.tmp
  • %TEMP%\4D36.tmp
  • %TEMP%\4FD6.tmp
  • %TEMP%\4A96.tmp
  • %TEMP%\4527.tmp
  • %TEMP%\47F6.tmp
Сетевая активность:
Подключается к:
  • 'b0###656651.com':80
  • 'b0###95994.com':80
  • 'localhost':1035
TCP:
Запросы HTTP GET:
  • b0###656651.com/bt.php?mo###############################################
  • b0###95994.com/bt.php?mo###############################################
UDP:
  • DNS ASK b0###656651.com
  • DNS ASK b0###95994.com

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке