Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen32.28273

Добавлен в вирусную базу Dr.Web: 2026-03-11

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Создает или изменяет следующие файлы
  • <SYSTEM32>\tasks\cms agent watchdog
Устанавливает следующие настройки сервисов
  • [HKLM\SYSTEM\CurrentControlSet\Services\CMSAgent] 'Start' = '00000002'
  • [HKLM\SYSTEM\CurrentControlSet\Services\CMSAgent] 'ImagePath' = '"%ProgramFiles%\CMS\Agent\CMSClient.exe" -config %ALLUSERSPROFILE%\CMS\agent.conf'
Создает следующие сервисы
  • 'CMSAgent' %ProgramFiles%\CMS\Agent\CMSClient.exe" -config %ALLUSERSPROFILE%\CMSgent.con
Изменения в файловой системе
Создает следующие файлы
  • %ALLUSERSPROFILE%\cms\agent\logs\agent.log
  • nul
  • %ProgramFiles%\cms\agent\cmsclient.exe
  • %ALLUSERSPROFILE%\cms\agent.conf
  • %ProgramFiles%\cms\agent\uninstall-cmsagent.ps1
  • %WINDIR%\temp\__psscriptpolicytest_zpu3l0jl.rlr.ps1
  • %WINDIR%\temp\__psscriptpolicytest_vwfeloys.jcy.psm1
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-25-718.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-26-062.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-26-163.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-26-564.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-26-711.dump
  • %WINDIR%\temp\__psscriptpolicytest_onsopfjj.sz5.ps1
  • %WINDIR%\temp\__psscriptpolicytest_q02vunyf.pze.psm1
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-27-421.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-27-474.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-27-659.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-27-806.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-28-326.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-28-628.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-28-643.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-28-650.dump
  • %WINDIR%\temp\content\2568-1180-powershell.exe-21-25-30-927.dump
  • <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
  • %WINDIR%\temp\__psscriptpolicytest_dht124hz.adv.ps1
  • %WINDIR%\temp\__psscriptpolicytest_zu0eh4jk.sgh.psm1
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-33-650.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-33-985.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-34-139.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-34-425.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-34-472.dump
  • %WINDIR%\temp\__psscriptpolicytest_21u1t3fg.1px.ps1
  • %WINDIR%\temp\__psscriptpolicytest_vcq41bvz.qes.psm1
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-34-789.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-34-827.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-34-912.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-35-091.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-35-363.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-36-617.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-36-733.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-36-973.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-37-035.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-37-236.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-38-080.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-38-280.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-38-644.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-39-000.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-39-497.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-39-756.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-058.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-187.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-265.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-334.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-403.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-450.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-504.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-582.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-651.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-736.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-791.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-869.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-40-969.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-41-208.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-42-899.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-43-021.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-43-068.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-43-084.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-43-138.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-43-169.dump
  • %WINDIR%\temp\content\4864-3104-powershell.exe-21-25-43-475.dump
  • %WINDIR%\temp\__psscriptpolicytest_ge0myy3n.2zo.ps1
  • %WINDIR%\temp\__psscriptpolicytest_azey43ej.kur.psm1
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-46-147.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-46-497.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-46-566.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-46-821.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-46-967.dump
  • %WINDIR%\temp\__psscriptpolicytest_smoibpdl.mmc.ps1
  • %WINDIR%\temp\__psscriptpolicytest_bwdglcyx.hu5.psm1
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-188.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-220.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-285.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-400.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-542.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-754.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-807.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-889.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-47-920.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-48-005.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-48-506.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-50-492.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-50-608.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-50-662.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-50-778.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-50-847.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-50-894.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-50-948.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-50-995.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-048.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-095.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-133.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-180.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-234.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-296.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-334.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-365.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-434.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-481.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-513.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-566.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-51-613.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-52-282.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-52-360.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-52-398.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-52-445.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-52-483.dump
  • %WINDIR%\temp\content\2404-704-powershell.exe-21-25-52-609.dump
  • %WINDIR%\temp\__psscriptpolicytest_fd1dumby.yyp.ps1
  • %WINDIR%\temp\__psscriptpolicytest_bqiqfpww.gv0.psm1
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-54-896.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-55-160.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-55-229.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-55-488.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-55-540.dump
  • %WINDIR%\temp\__psscriptpolicytest_5s2x2emo.i0y.ps1
  • %WINDIR%\temp\__psscriptpolicytest_renfhfrz.yua.psm1
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-55-750.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-55-784.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-55-837.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-55-953.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-56-082.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-56-135.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-56-143.dump
  • %WINDIR%\temp\content\400-1400-powershell.exe-21-25-56-427.dump
  • %WINDIR%\temp\__psscriptpolicytest_bv3wrlro.cgf.ps1
  • %WINDIR%\temp\__psscriptpolicytest_rbup5gpf.k5t.psm1
  • %WINDIR%\temp\content\4932-3628-powershell.exe-21-25-58-273.dump
  • %WINDIR%\temp\content\4932-3628-powershell.exe-21-25-58-490.dump
  • %WINDIR%\temp\content\4932-3628-powershell.exe-21-25-58-559.dump
  • %WINDIR%\temp\content\4932-3628-powershell.exe-21-25-58-722.dump
  • %WINDIR%\temp\content\4932-3628-powershell.exe-21-25-58-809.dump
  • %WINDIR%\temp\__psscriptpolicytest_lzctvuig.y1x.ps1
  • %WINDIR%\temp\__psscriptpolicytest_achdqbvs.24c.psm1
  • %WINDIR%\temp\content\1276-4968-powershell.exe-21-26-03-272.dump
  • %WINDIR%\temp\content\1276-4968-powershell.exe-21-26-03-558.dump
  • %WINDIR%\temp\content\1276-4968-powershell.exe-21-26-03-643.dump
  • %WINDIR%\temp\content\1276-4968-powershell.exe-21-26-03-854.dump
  • %WINDIR%\temp\content\1276-4968-powershell.exe-21-26-03-953.dump
  • %WINDIR%\temp\__psscriptpolicytest_xda3c4g2.m50.ps1
  • %WINDIR%\temp\__psscriptpolicytest_ozdtwnly.qod.psm1
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-06-136.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-06-412.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-06-512.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-06-763.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-06-814.dump
  • %WINDIR%\temp\__psscriptpolicytest_s1ythw4i.edz.ps1
  • %WINDIR%\temp\__psscriptpolicytest_r4h1pnmj.hal.psm1
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-084.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-114.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-177.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-293.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-479.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-544.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-552.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-563.dump
  • %WINDIR%\temp\content\3896-3708-powershell.exe-21-26-07-915.dump
  • %WINDIR%\temp\__psscriptpolicytest_rxfy4exz.32w.ps1
  • %WINDIR%\temp\__psscriptpolicytest_dugqa1rn.j5x.psm1
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-10-398.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-10-637.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-10-722.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-10-899.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-10-953.dump
  • %WINDIR%\temp\__psscriptpolicytest_kopdjd5y.mgj.ps1
  • %WINDIR%\temp\__psscriptpolicytest_gjatnhie.k2p.psm1
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-11-137.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-11-168.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-12-322.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-12-496.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-12-760.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-12-932.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-12-964.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-13-048.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-13-095.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-13-180.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-14-103.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-14-245.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-14-488.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-14-603.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-14-994.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-112.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-215.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-289.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-344.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-397.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-531.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-564.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-617.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-839.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-946.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-15-987.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-16-570.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-16-615.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-16-757.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-16-854.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-17-438.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-17-511.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-17-527.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-17-542.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-17-664.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-17-689.dump
  • %WINDIR%\temp\content\2440-996-powershell.exe-21-26-17-940.dump
  • %WINDIR%\temp\__psscriptpolicytest_pwy0j3zg.wvl.ps1
  • %WINDIR%\temp\__psscriptpolicytest_4qpnpfd5.s1c.psm1
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-21-285.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-21-622.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-21-722.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-21-901.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-21-954.dump
  • %WINDIR%\temp\__psscriptpolicytest_ijw2rwjl.1ut.ps1
  • %WINDIR%\temp\__psscriptpolicytest_rrek23kj.ibk.psm1
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-22-187.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-22-240.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-22-303.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-22-419.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-22-603.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-23-139.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-23-189.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-23-276.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-23-324.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-23-390.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-24-051.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-26-485.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-26-588.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-26-638.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-26-759.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-26-810.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-26-854.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-26-896.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-26-939.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-020.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-064.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-106.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-205.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-260.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-344.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-408.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-472.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-525.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-586.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-647.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-700.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-27-828.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-28-537.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-28-609.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-28-637.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-28-653.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-28-799.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-28-831.dump
  • %WINDIR%\temp\content\2724-1644-powershell.exe-21-26-28-996.dump
  • %WINDIR%\temp\__psscriptpolicytest_o1n2d30n.0t1.ps1
  • %WINDIR%\temp\__psscriptpolicytest_yhe3xr31.mtm.psm1
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-32-337.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-32-981.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-33-060.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-33-246.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-33-290.dump
  • %WINDIR%\temp\__psscriptpolicytest_xknyuhbx.4qu.ps1
  • %WINDIR%\temp\__psscriptpolicytest_gg2fhnox.0ix.psm1
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-33-679.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-33-711.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-33-886.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-34-016.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-34-171.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-34-257.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-34-266.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-34-276.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-34-278.dump
  • %WINDIR%\temp\content\872-764-powershell.exe-21-26-34-883.dump
  • %WINDIR%\temp\__psscriptpolicytest_tlu5pnds.5fx.ps1
  • %WINDIR%\temp\__psscriptpolicytest_yijlm1ni.2wt.psm1
  • %WINDIR%\temp\content\4196-2696-powershell.exe-21-26-37-849.dump
  • %WINDIR%\temp\content\4196-2696-powershell.exe-21-26-38-292.dump
  • %WINDIR%\temp\content\4196-2696-powershell.exe-21-26-38-411.dump
  • %WINDIR%\temp\content\4196-2696-powershell.exe-21-26-38-592.dump
  • %WINDIR%\temp\content\4196-2696-powershell.exe-21-26-38-725.dump
  • %WINDIR%\temp\__psscriptpolicytest_3pnd3cvk.2mx.ps1
  • %WINDIR%\temp\__psscriptpolicytest_cx1ijq5q.51r.psm1
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-41-955.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-42-188.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-42-304.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-42-540.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-42-590.dump
  • %WINDIR%\temp\__psscriptpolicytest_s3c1jfrk.0ej.ps1
  • %WINDIR%\temp\__psscriptpolicytest_f0u3azj3.cfk.psm1
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-42-793.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-42-824.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-42-879.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-43-008.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-43-137.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-43-190.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-43-198.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-43-208.dump
  • %WINDIR%\temp\content\3964-3104-powershell.exe-21-26-43-546.dump
  • %WINDIR%\temp\__psscriptpolicytest_ozodvmy1.1mw.ps1
  • %WINDIR%\temp\__psscriptpolicytest_ldedvf2x.fk2.psm1
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-45-923.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-46-193.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-46-294.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-46-545.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-46-588.dump
  • %WINDIR%\temp\__psscriptpolicytest_qap0j12x.cxn.ps1
  • %WINDIR%\temp\__psscriptpolicytest_tgox11hu.nxe.psm1
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-46-880.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-46-924.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-46-994.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-47-114.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-47-296.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-47-582.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-47-671.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-47-762.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-47-831.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-47-932.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-48-410.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-48-500.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-48-726.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-48-831.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-063.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-163.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-248.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-320.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-387.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-428.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-500.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-538.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-601.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-639.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-701.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-752.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-795.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-848.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-49-975.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-50-089.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-50-666.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-50-729.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-50-751.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-50-767.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-50-798.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-50-829.dump
  • %WINDIR%\temp\content\1432-3324-powershell.exe-21-26-50-986.dump
  • %WINDIR%\temp\__psscriptpolicytest_hevreliz.v3v.ps1
  • %WINDIR%\temp\__psscriptpolicytest_hiposcci.pu4.psm1
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-54-157.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-54-489.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-54-590.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-54-823.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-54-876.dump
  • %WINDIR%\temp\__psscriptpolicytest_hdcxfe2b.w5i.ps1
  • %WINDIR%\temp\__psscriptpolicytest_ilkf4mm3.cs1.psm1
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-55-267.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-55-371.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-55-434.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-55-602.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-55-795.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-56-089.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-56-143.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-56-274.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-56-344.dump
  • %WINDIR%\temp\content\1852-464-powershell.exe-21-26-56-444.dump
Удаляет файлы, которые сам же создал
  • %WINDIR%\temp\__psscriptpolicytest_zpu3l0jl.rlr.ps1
  • %WINDIR%\temp\__psscriptpolicytest_vwfeloys.jcy.psm1
  • %WINDIR%\temp\__psscriptpolicytest_onsopfjj.sz5.ps1
  • %WINDIR%\temp\__psscriptpolicytest_q02vunyf.pze.psm1
  • %WINDIR%\temp\__psscriptpolicytest_dht124hz.adv.ps1
  • %WINDIR%\temp\__psscriptpolicytest_zu0eh4jk.sgh.psm1
  • %WINDIR%\temp\__psscriptpolicytest_21u1t3fg.1px.ps1
  • %WINDIR%\temp\__psscriptpolicytest_vcq41bvz.qes.psm1
  • %WINDIR%\temp\__psscriptpolicytest_ge0myy3n.2zo.ps1
  • %WINDIR%\temp\__psscriptpolicytest_azey43ej.kur.psm1
  • %WINDIR%\temp\__psscriptpolicytest_smoibpdl.mmc.ps1
  • %WINDIR%\temp\__psscriptpolicytest_bwdglcyx.hu5.psm1
  • %WINDIR%\temp\__psscriptpolicytest_fd1dumby.yyp.ps1
  • %WINDIR%\temp\__psscriptpolicytest_bqiqfpww.gv0.psm1
  • %WINDIR%\temp\__psscriptpolicytest_5s2x2emo.i0y.ps1
  • %WINDIR%\temp\__psscriptpolicytest_renfhfrz.yua.psm1
  • %WINDIR%\temp\__psscriptpolicytest_bv3wrlro.cgf.ps1
  • %WINDIR%\temp\__psscriptpolicytest_rbup5gpf.k5t.psm1
  • %WINDIR%\temp\__psscriptpolicytest_lzctvuig.y1x.ps1
  • %WINDIR%\temp\__psscriptpolicytest_achdqbvs.24c.psm1
  • %WINDIR%\temp\__psscriptpolicytest_xda3c4g2.m50.ps1
  • %WINDIR%\temp\__psscriptpolicytest_ozdtwnly.qod.psm1
  • %WINDIR%\temp\__psscriptpolicytest_s1ythw4i.edz.ps1
  • %WINDIR%\temp\__psscriptpolicytest_r4h1pnmj.hal.psm1
  • %WINDIR%\temp\__psscriptpolicytest_rxfy4exz.32w.ps1
  • %WINDIR%\temp\__psscriptpolicytest_dugqa1rn.j5x.psm1
  • %WINDIR%\temp\__psscriptpolicytest_kopdjd5y.mgj.ps1
  • %WINDIR%\temp\__psscriptpolicytest_gjatnhie.k2p.psm1
  • %WINDIR%\temp\__psscriptpolicytest_pwy0j3zg.wvl.ps1
  • %WINDIR%\temp\__psscriptpolicytest_4qpnpfd5.s1c.psm1
  • %WINDIR%\temp\__psscriptpolicytest_ijw2rwjl.1ut.ps1
  • %WINDIR%\temp\__psscriptpolicytest_rrek23kj.ibk.psm1
  • %WINDIR%\temp\__psscriptpolicytest_o1n2d30n.0t1.ps1
  • %WINDIR%\temp\__psscriptpolicytest_yhe3xr31.mtm.psm1
  • %WINDIR%\temp\__psscriptpolicytest_xknyuhbx.4qu.ps1
  • %WINDIR%\temp\__psscriptpolicytest_gg2fhnox.0ix.psm1
  • %WINDIR%\temp\__psscriptpolicytest_tlu5pnds.5fx.ps1
  • %WINDIR%\temp\__psscriptpolicytest_yijlm1ni.2wt.psm1
  • %WINDIR%\temp\__psscriptpolicytest_3pnd3cvk.2mx.ps1
  • %WINDIR%\temp\__psscriptpolicytest_cx1ijq5q.51r.psm1
  • %WINDIR%\temp\__psscriptpolicytest_s3c1jfrk.0ej.ps1
  • %WINDIR%\temp\__psscriptpolicytest_f0u3azj3.cfk.psm1
  • %WINDIR%\temp\__psscriptpolicytest_ozodvmy1.1mw.ps1
  • %WINDIR%\temp\__psscriptpolicytest_ldedvf2x.fk2.psm1
  • %WINDIR%\temp\__psscriptpolicytest_qap0j12x.cxn.ps1
  • %WINDIR%\temp\__psscriptpolicytest_tgox11hu.nxe.psm1
  • %WINDIR%\temp\__psscriptpolicytest_hevreliz.v3v.ps1
  • %WINDIR%\temp\__psscriptpolicytest_hiposcci.pu4.psm1
  • %WINDIR%\temp\__psscriptpolicytest_hdcxfe2b.w5i.ps1
  • %WINDIR%\temp\__psscriptpolicytest_ilkf4mm3.cs1.psm1
Сетевая активность
Подключается к
  • 'cm#.#ccops.com':443
  • 'x1.#.lencr.org':80
TCP
Запросы HTTP GET
  • http://x1.#.lencr.org/
Другие
  • 'cm#.#ccops.com':443
UDP
  • DNS ASK cm#.#ccops.com
  • DNS ASK x1.#.lencr.org
Другое
Создает и запускает на исполнение
  • '%ProgramFiles%\cms\agent\cmsclient.exe' -config %ALLUSERSPROFILE%\CMS\agent.conf
Запускает на исполнение
  • '<SYSTEM32>\net.exe' session
  • '<SYSTEM32>\net1.exe' session
  • '<SYSTEM32>\sc.exe' query CMSAgent
  • '<SYSTEM32>\sc.exe' failure CMSAgent "reset= 86400" "actions= restart/60000/restart/60000/restart/60000"
  • '<SYSTEM32>\schtasks.exe' /create /tn "CMS Agent Watchdog" /tr "\"%ProgramFiles%\CMS\Agent\CMSClient.exe\" -config \"%ALLUSERSPROFILE%\CMS\agent.conf\" watchdog-run" /sc minute /mo 1 /ru SYSTEM /rl HIGHEST /f
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "(Get-CimInstance -ClassName Win32_OperatingSystem).Caption"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "(Get-NetIPAddress -AddressFamily IPv4 | Where-Object {$_.InterfaceAlias -notlike '*Loopback*'})[0].IPAddress"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "(Get-NetAdapter | Where-Object {$_.Status -eq 'Up'})[0].MacAddress"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "(Get-CimInstance Win32_BaseBoard | Select-Object -First 1).SerialNumber"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "(Get-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\Cryptography' -Name 'MachineGuid').MachineGuid"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке