Техническая информация
- <SYSTEM32>\tasks\amhelper
- [<HKLM>\System\CurrentControlSet\Services\amsdk] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\amsdk] 'ImagePath' = '<DRIVERS>\amsdk.sys'
- 'amsdk' <DRIVERS>\amsdk.sys
- iexplore.exe
- firefox.exe
- %TEMP%\aute23.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-shmi8.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-fh70c.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-p7j11.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-3dgeq.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-8ah67.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-8l0k5.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-7455j.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-8adnh.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-636ls.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-rvcq5.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-92so7.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-ruf68.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-85nva.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-7phf6.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-8bls6.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-3h5l8.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-k2qqt.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-0emqt.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-qs7ub.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-goara.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-7h9mm.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-f2u0u.tmp
- %ProgramFiles(x86)%\zemana\antimalware\antimalware.exe
- %TEMP%\aut8f83.tmp
- %LOCALAPPDATA%\zemana\antimalware\logs\eventlog.txt
- %ProgramFiles(x86)%\zemana\antimalware\unins000.dat
- %ProgramFiles(x86)%\zemana\antimalware\unins000.msg
- C:\users\public\desktop\zemana antimalware.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\zemana antimalware\zemana antimalware.lnk
- %WINDIR%\zam.krnl.trace
- %ProgramFiles(x86)%\zemana\antimalware\is-4qio2.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-ka2mi.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-mdv74.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-su9lg.tmp
- %ProgramFiles(x86)%\zemana\antimalware\data\is-gl24q.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-kbhja.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-a2ve9.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-60e94.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-h5oeu.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-l0np5.tmp
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-gcdqe.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-1i78o.tmp
- %TEMP%\aut8fe2.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-tbk2o.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-0hopo.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-f71as.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-g10po.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-169co.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-neiu0.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-4rr6n.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-gr5ft.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-evkfd.tmp
- %WINDIR%\temp\udd3bc7.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-jv5hp.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-4tkju.tmp
- %TEMP%\is-k087m.tmp\2.rtf
- %TEMP%\is-k087m.tmp\partners.ini
- %LOCALAPPDATA%\amsdk\~cyqwjsu.trace
- %TEMP%\is-k087m.tmp\amsdkcore399001.dll
- %TEMP%\is-k087m.tmp\_isetup\_setup64.tmp
- %TEMP%\setup log 2023-02-22 #001.txt
- %TEMP%\is-vjpba.tmp\~cyqwjsu.tmp
- %CommonProgramFiles(x86)%\~cyqwjsu.tmp
- <DRIVERS>\amsdk.sys
- %ProgramFiles(x86)%\zemana\antimalware\is-ujaal.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-rvom5.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-hrort.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-o3s94.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-k81h1.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-nq4ef.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-nb180.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-iqesi.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-82b6a.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-hilku.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-es55t.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-o41mb.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-fpmcs.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-d27er.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-a06nm.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-8fptm.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-1j2iu.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-sco5e.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-pkn5j.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-tfpds.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-lcrap.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-mgrm1.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\is-75167.tmp
- %ProgramFiles(x86)%\zemana\antimalware\antimalware.core.dll
- %CommonProgramFiles(x86)%\~cyqwjsu.tmp
- %ProgramFiles(x86)%\zemana\antimalware\res\216.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\215.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\214.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\210.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\206.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\205.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\2.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\186.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\159.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\1.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\0.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\214.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\210.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\206.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\205.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\2.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\186.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\159.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\1.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\0.ico
- %ProgramFiles(x86)%\zemana\antimalware\antimalware.shared.pdb
- %ProgramFiles(x86)%\zemana\antimalware\antimalware.sdk.pdb
- %ProgramFiles(x86)%\zemana\antimalware\antimalware.pdb
- %ProgramFiles(x86)%\zemana\antimalware\antimalware.core.pdb
- %TEMP%\is-k087m.tmp\2.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\217.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\186.pkcs7
- %TEMP%\aute23.tmp
- %WINDIR%\temp\udd3bc7.tmp
- %TEMP%\is-k087m.tmp\2.rtf
- %TEMP%\is-k087m.tmp\amsdkcore399001.dll
- %TEMP%\is-k087m.tmp\partners.ini
- %TEMP%\is-k087m.tmp\_isetup\_setup64.tmp
- %TEMP%\is-vjpba.tmp\~cyqwjsu.tmp
- %CommonProgramFiles(x86)%\~cyqwjsu.tmp
- %TEMP%\aut8f83.tmp
- %TEMP%\aut8fe2.tmp
- %ProgramFiles(x86)%\zemana\antimalware\is-4tkju.tmp в %ProgramFiles(x86)%\zemana\antimalware\unins000.exe
- %ProgramFiles(x86)%\zemana\antimalware\res\is-3h5l8.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\217.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-8bls6.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\186.pkcs7
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-7phf6.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\arabic.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-85nva.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\bosnian.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-ruf68.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\croatian.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-92so7.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\czech.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-qs7ub.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\dutch.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-rvcq5.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\english.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-8adnh.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\french.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-7455j.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\german.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-8l0k5.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\hungarian.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-8ah67.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\indonesian.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-3dgeq.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\italian.json
- %ProgramFiles(x86)%\zemana\antimalware\res\is-0emqt.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\215.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-k2qqt.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\216.rtf
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-p7j11.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\korean.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-fh70c.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\malay.json
- %ProgramFiles(x86)%\zemana\antimalware\is-mdv74.tmp в %ProgramFiles(x86)%\zemana\antimalware\libeay32.dll
- %ProgramFiles(x86)%\zemana\antimalware\is-su9lg.tmp в %ProgramFiles(x86)%\zemana\antimalware\am_shellext64.dll
- %ProgramFiles(x86)%\zemana\antimalware\data\is-gl24q.tmp в %ProgramFiles(x86)%\zemana\antimalware\data\scanpostfeedback.htm
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-kbhja.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\ukrainian.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-a2ve9.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\turkish.json
- %ProgramFiles(x86)%\zemana\antimalware\res\is-hilku.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\210.ico
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-60e94.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\slovenian.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-l0np5.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\serbian (latin).json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-gcdqe.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\serbian (cyrillic).json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-f2u0u.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\russian.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-7h9mm.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\portuguese (portugal).json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-goara.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\polish.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-636ls.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\persian.json
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-shmi8.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\norwegian.json
- %ProgramFiles(x86)%\zemana\antimalware\res\is-1i78o.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\214.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-tbk2o.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\210.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-75167.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\206.rtf
- %ProgramFiles(x86)%\zemana\antimalware\is-gr5ft.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.exe
- %ProgramFiles(x86)%\zemana\antimalware\is-4rr6n.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.core.dll
- %ProgramFiles(x86)%\zemana\antimalware\is-neiu0.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.shared.dll
- %ProgramFiles(x86)%\zemana\antimalware\is-169co.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.sdk.dll
- %ProgramFiles(x86)%\zemana\antimalware\is-g10po.tmp в %ProgramFiles(x86)%\zemana\antimalware\amsdkcore399001.dll
- %ProgramFiles(x86)%\zemana\antimalware\is-f71as.tmp в %ProgramFiles(x86)%\zemana\antimalware\decision.dll
- %ProgramFiles(x86)%\zemana\antimalware\is-jv5hp.tmp в %ProgramFiles(x86)%\zemana\antimalware\log4net.dll
- %ProgramFiles(x86)%\zemana\antimalware\is-ujaal.tmp в %ProgramFiles(x86)%\zemana\antimalware\log4net.xml
- %ProgramFiles(x86)%\zemana\antimalware\is-rvom5.tmp в %ProgramFiles(x86)%\zemana\antimalware\newtonsoft.json.dll
- %ProgramFiles(x86)%\zemana\antimalware\is-hrort.tmp в %ProgramFiles(x86)%\zemana\antimalware\newtonsoft.json.xml
- %ProgramFiles(x86)%\zemana\antimalware\is-mgrm1.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.core.pdb
- %ProgramFiles(x86)%\zemana\antimalware\is-lcrap.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.pdb
- %ProgramFiles(x86)%\zemana\antimalware\is-tfpds.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.sdk.pdb
- %ProgramFiles(x86)%\zemana\antimalware\is-pkn5j.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.shared.pdb
- %ProgramFiles(x86)%\zemana\antimalware\is-evkfd.tmp в %ProgramFiles(x86)%\zemana\antimalware\setup.exe
- %ProgramFiles(x86)%\zemana\antimalware\is-sco5e.tmp в %ProgramFiles(x86)%\zemana\antimalware\antimalware.exe.manifest
- %ProgramFiles(x86)%\zemana\antimalware\res\is-0hopo.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\205.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-1j2iu.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\0.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\is-8fptm.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\1.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\is-a06nm.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\159.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\is-d27er.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\186.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\is-fpmcs.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\2.ico
- %ProgramFiles(x86)%\zemana\antimalware\res\is-o41mb.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\205.ico
- %ProgramFiles(x86)%\zemana\antimalware\languages\is-h5oeu.tmp в %ProgramFiles(x86)%\zemana\antimalware\languages\slovak.json
- %ProgramFiles(x86)%\zemana\antimalware\res\is-es55t.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\206.ico
- %ProgramFiles(x86)%\zemana\antimalware\is-ka2mi.tmp в %ProgramFiles(x86)%\zemana\antimalware\ssleay32.dll
- %ProgramFiles(x86)%\zemana\antimalware\res\is-iqesi.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\0.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-nb180.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\1.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-nq4ef.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\159.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-k81h1.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\186.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-o3s94.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\2.rtf
- %ProgramFiles(x86)%\zemana\antimalware\res\is-82b6a.tmp в %ProgramFiles(x86)%\zemana\antimalware\res\214.ico
- %ProgramFiles(x86)%\zemana\antimalware\is-4qio2.tmp в %ProgramFiles(x86)%\zemana\antimalware\dotnetfx40_client_setup.exe
- '%CommonProgramFiles(x86)%\~cyqwjsu.tmp' /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
- '%TEMP%\is-vjpba.tmp\~cyqwjsu.tmp' /SL5="$B021A,13025042,780800,%CommonProgramFiles(x86)%\~cyqwjsu.tmp" /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
- '%ProgramFiles(x86)%\zemana\antimalware\antimalware.exe' /SL5="$B021A,13025042,780800,%CommonProgramFiles(x86)%\~cyqwjsu.tmp" /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP- /INSTALLER /SELECTEDLANG x0409 /AUTOSTART /AUTOUPLOAD
- '%CommonProgramFiles(x86)%\~cyqwjsu.tmp' /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /F /RU SYSTEM /RL HIGHEST /SC MINUTE /MO 5 /TN "AMHelper" /TR "'%ProgramFiles(x86)%\Zemana\AntiMalware\AntiMalware.exe' /UPDATE"' (со скрытым окном)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Zemana\AntiMalware\AM_ShellExt64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\Zemana\AntiMalware\AM_ShellExt64.dll"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /F /RU SYSTEM /RL HIGHEST /SC MINUTE /MO 5 /TN "AMHelper" /TR "'%ProgramFiles(x86)%\Zemana\AntiMalware\AntiMalware.exe' /UPDATE"