Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.DownLoader11.24551

Добавлен в вирусную базу Dr.Web: 2014-07-31

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Classes\GU.Encrypted\Shell\Open\Command] '' = '%PROGRAM_FILES%\Glary Utilities 5\fileencrypt.exe -d %1'
  • [<HKLM>\SOFTWARE\Classes\GU.Splitted\Shell\Open\Command] '' = '%PROGRAM_FILES%\Glary Utilities 5\filesplitter.exe -j %1'
  • [<HKLM>\SYSTEM\ControlSet001\Control\Session Manager] 'BootExecute' = ''
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GUDelayStartup' = '"%PROGRAM_FILES%\Glary Utilities 5\StartupManager.exe" -delayrun'
Создает или изменяет следующие файлы:
  • %WINDIR%\Tasks\GlaryInitialize 5.job
Создает следующие сервисы:
  • [<HKLM>\SYSTEM\ControlSet001\Services\GUBootStartup] 'Start' = '00000001'
  • [<HKLM>\SYSTEM\ControlSet001\Services\BootDefragDriver] 'Start' = '00000000'
Вредоносные функции:
Создает и запускает на исполнение:
  • '%PROGRAM_FILES%\Glary Utilities 5\Initialize.exe' /setupschedule
  • '%PROGRAM_FILES%\Glary Utilities 5\Integrator.exe' -S
  • '%PROGRAM_FILES%\Glary Utilities 5\StartupManager.exe' -install
  • 'C:\~trtggrm.tmp' \S
  • '%PROGRAM_FILES%\Glary Utilities 5\DiskDefrag.exe' -InstallNative
Изменения в файловой системе:
Создает следующие файлы:
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_close_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_close_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_feedback.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\harddisk.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\logo.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_close.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_like.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_right_top_mark_hover_bg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_right_top_mark_sep.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_skin.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_min.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_restore.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\main_right_top_mark_click_bg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\dockpopcurpage.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\dockpopcurpagegray.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\dockpopdarkbg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\clear_tips.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\diskspace.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\dockpopbg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\dockpopturnleft.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\drivers.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\filemanagement.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\foot_transbg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\dockpopturnleftgray.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\dockpopturnright.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\dockpopturnrightgray.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\menu_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\ov_boottimebg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\pop_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\pop_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oneclickmaintenance_bg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oneclickmaintenance_front.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oneclickmaintenance_needclear_bg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\pop_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\progress_bg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\registry.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\search_mark.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\privacy.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\programs.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\progress.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_btn_scan.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\menu_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\menu_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_cancel_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_needclearbg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oneclick_bg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oneclick_progress.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_cancel_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_cancel_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\oc_detailbg.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\activenow_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\main_like.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\oc_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\Property.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\activenow_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\activenow_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\oc_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\tab_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\tab_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\toolbar.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\oc_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\registry.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\tab_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\DrivesNode.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\NetworkNode.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\OperSysNode.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SpyRemover\BKPic.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\StartupManager\toolbar.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\DisplayNode.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\OtherDevicesNode.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\SystemDevicesNode.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\Line.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TracksEraser\OpenFile.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\OverViewNode.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\Picture.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\SysInfo\System Information.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\TurboMode\BackGround.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\activenow_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\activenow_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\activenow_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg8.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg9.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\DockButton_Tip.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\antimalware.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\checkbox_checked.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\checkbox_uncheck.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\body_transbg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\Uninstaller\Recently.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\Uninstaller\View.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\Uninstaller\WindowsUpdates.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\Uninstaller\AllPrograms.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\Uninstaller\Large.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\Uninstaller\RarelyUsed.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg1.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg5.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg6.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg7.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg2.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg3.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\backimages\bg4.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\skin_col_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\sysinfo.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\sysinfohover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\trackseraser.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\spyremoverhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\startupmanager.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\startupmanagerhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\trackseraserhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\drives.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\memory.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\network.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\computer.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\cpu.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\display.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\regdefraghover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\registrycleaner.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\registrycleanerhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\quicksearch.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\quicksearchhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\regdefrag.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\restorecenter.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\shredder.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\shredderhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\spyremover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\restorecenterhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\shortcutfixer.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\shortcutfixerhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\normaldown.png
  • %ALLUSERSPROFILE%\Start Menu\Programs\Glary Utilities 5\Uninstall.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\Glary Utilities 5\Glary Utilities 5.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\Glary Utilities 5.lnk
  • %HOMEPATH%\Templates\GUTracksIni.tmp
  • %PROGRAM_FILES%\Glary Utilities 5\Glary Utilities 5.url
  • %ALLUSERSPROFILE%\Start Menu\Programs\Glary Utilities 5\Website.lnk
  • %ALLUSERSPROFILE%\Desktop\Glary Utilities 5.lnk
  • %TEMP%\nsw3.tmp\inetc.dll
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\install[1].htm
  • %PROGRAM_FILES%\Glary Utilities 5\post_reply.htm
  • %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Glary Utilities 5.lnk
  • %PROGRAM_FILES%\Glary Utilities 5\uninst.exe
  • %TEMP%\nsw3.tmp\xtInfoPlugin.dll
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\topdown.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\windows.png
  • %TEMP%\nsw3.tmp\System.dll
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\normalhot.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\others.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\system information\top.png
  • %PROGRAM_FILES%\Glary Utilities 5\GridMap.ocx
  • <DRIVERS>\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\data\backup.ini
  • <DRIVERS>\GUBootStartup.sys
  • %PROGRAM_FILES%\Glary Utilities 5\ContextHandler.dll
  • %APPDATA%\GlarySoft\Glary Utilities 5\AppMetris\ModuleMetris-54011037000-20140730.ini
  • <SYSTEM32>\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\toolbar.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\usertype_btn.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\skin.ini
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_oc_blue.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_ov.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_ov_blue.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\BrowserAssistant.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\SoftwareUpdate.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\SoftwareUpdatehover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\Uninstaller.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\BrowserAssistanthover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\CheckUpdate.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\CheckUpdatehover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\skintransparentmark.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\systemcontrol.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\systemstatus.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\skin_custom.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\skin_pic_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\skinsbg.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\systemtweaks.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_oc.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_ad.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_ad_blue.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\default\images\tab_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\Uninstallerhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\fileencrypt.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\fileencrypthover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\filesplitter.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\dupefinderhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\emptyfolderfinder.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\emptyfolderfinderhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\filesplitterhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\memdefraghover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\procmgr.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\procmgrhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\fileundelete.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\fileundeletehover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\memdefrag.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\cmmhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\diskanalysis.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\diskanalysishover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\checkdisk.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\checkdiskhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\cmm.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\diskcleaner.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\driverbackup.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\driverbackuphover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\dupefinder.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\diskcleanerhover.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\diskdefrag.png
  • %PROGRAM_FILES%\Glary Utilities 5\skins\icons\diskdefraghover.png
  • %PROGRAM_FILES%\Glary Utilities 5\shredder.exe
  • %PROGRAM_FILES%\Glary Utilities 5\SoftwareUpdate.exe
  • %PROGRAM_FILES%\Glary Utilities 5\SpyRemover.dll
  • %PROGRAM_FILES%\Glary Utilities 5\settings.ini
  • %PROGRAM_FILES%\Glary Utilities 5\ShortcutFixer.dll
  • %PROGRAM_FILES%\Glary Utilities 5\ShortcutFixer.exe
  • %PROGRAM_FILES%\Glary Utilities 5\SpyRemover.exe
  • %PROGRAM_FILES%\Glary Utilities 5\TracksEraser.dll
  • %PROGRAM_FILES%\Glary Utilities 5\TracksEraser.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Undelete.dll
  • %PROGRAM_FILES%\Glary Utilities 5\StartupManager.dll
  • %PROGRAM_FILES%\Glary Utilities 5\StartupManager.exe
  • %PROGRAM_FILES%\Glary Utilities 5\sysinfo.exe
  • %PROGRAM_FILES%\Glary Utilities 5\procmgr.exe
  • %PROGRAM_FILES%\Glary Utilities 5\QuickSearch.exe
  • %PROGRAM_FILES%\Glary Utilities 5\regdefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\ObjectAdmin.dll
  • %PROGRAM_FILES%\Glary Utilities 5\OneClickMaintenance.exe
  • %PROGRAM_FILES%\Glary Utilities 5\PortableMaker.exe
  • %PROGRAM_FILES%\Glary Utilities 5\RegistryCleaner.dll
  • %PROGRAM_FILES%\Glary Utilities 5\RestoreCenter.exe
  • %PROGRAM_FILES%\Glary Utilities 5\ScanFile.dll
  • %PROGRAM_FILES%\Glary Utilities 5\settings.dll
  • %PROGRAM_FILES%\Glary Utilities 5\RegistryCleaner.exe
  • %PROGRAM_FILES%\Glary Utilities 5\RemoveDriver.dll
  • %PROGRAM_FILES%\Glary Utilities 5\RestoreCenter.dll
  • %PROGRAM_FILES%\Glary Utilities 5\Uninstaller.exe
  • %PROGRAM_FILES%\Glary Utilities 5\data\settings.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\startup.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\xb.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\process.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\procsubmit.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\registry.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\xdata.dat
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Czech.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Danish.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Dutch3.lng
  • %PROGRAM_FILES%\Glary Utilities 5\data\xt.dat
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Catala.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Catala2.lng
  • %PROGRAM_FILES%\Glary Utilities 5\data\ModuleInfo.ini
  • %PROGRAM_FILES%\Glary Utilities 5\data\Softwareupdate.xml
  • %PROGRAM_FILES%\Glary Utilities 5\data\apps.dat
  • %PROGRAM_FILES%\Glary Utilities 5\upgrade.exe
  • %PROGRAM_FILES%\Glary Utilities 5\zlib1.dll
  • %PROGRAM_FILES%\Glary Utilities 5\data\BootTime.ini
  • %PROGRAM_FILES%\Glary Utilities 5\data\backup.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\htmldata.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\junk.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\junkInfo.ini
  • %PROGRAM_FILES%\Glary Utilities 5\data\duplicates.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\duplicatesfolder.dat
  • %PROGRAM_FILES%\Glary Utilities 5\data\empty.dat
  • %PROGRAM_FILES%\Glary Utilities 5\Config.dll
  • %PROGRAM_FILES%\Glary Utilities 5\Config_Portable.dll
  • %PROGRAM_FILES%\Glary Utilities 5\CrashReport.dll
  • %PROGRAM_FILES%\Glary Utilities 5\CheckUpdate.dll
  • %PROGRAM_FILES%\Glary Utilities 5\CheckUpdate.exe
  • %PROGRAM_FILES%\Glary Utilities 5\cmm.exe
  • %PROGRAM_FILES%\Glary Utilities 5\CrashReport.exe
  • %PROGRAM_FILES%\Glary Utilities 5\DiskDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\DPInst32.exe
  • %PROGRAM_FILES%\Glary Utilities 5\DPInst64.exe
  • %PROGRAM_FILES%\Glary Utilities 5\DiskAnalysis.exe
  • %PROGRAM_FILES%\Glary Utilities 5\DiskCleaner.dll
  • %PROGRAM_FILES%\Glary Utilities 5\DiskCleaner.exe
  • %PROGRAM_FILES%\Glary Utilities 5\KillProcPath.dll
  • %PROGRAM_FILES%\Glary Utilities 5\AppMetrics.dll
  • %PROGRAM_FILES%\Glary Utilities 5\autodll.dll
  • %TEMP%\aut1.tmp
  • C:\~trtggrm.tmp
  • %TEMP%\nsw3.tmp\GlaryUtilities.ini
  • %PROGRAM_FILES%\Glary Utilities 5\AutoUpdate.exe
  • %PROGRAM_FILES%\Glary Utilities 5\CheckDisk.dll
  • %PROGRAM_FILES%\Glary Utilities 5\CheckDisk.exe
  • %PROGRAM_FILES%\Glary Utilities 5\CheckDiskProgress.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Backup.dll
  • %PROGRAM_FILES%\Glary Utilities 5\BootTime.dll
  • %PROGRAM_FILES%\Glary Utilities 5\BottDefrag.dll
  • %PROGRAM_FILES%\Glary Utilities 5\DriverBackup.exe
  • %PROGRAM_FILES%\Glary Utilities 5\MachineCode.dll
  • %PROGRAM_FILES%\Glary Utilities 5\memdefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Memfiles.dll
  • %PROGRAM_FILES%\Glary Utilities 5\languages.dll
  • %PROGRAM_FILES%\Glary Utilities 5\LockDll.dll
  • %PROGRAM_FILES%\Glary Utilities 5\Log.dll
  • %PROGRAM_FILES%\Glary Utilities 5\MemfilesService.exe
  • %PROGRAM_FILES%\Glary Utilities 5\msvcm90.dll
  • %PROGRAM_FILES%\Glary Utilities 5\msvcp90.dll
  • %PROGRAM_FILES%\Glary Utilities 5\msvcr90.dll
  • %PROGRAM_FILES%\Glary Utilities 5\mfc90u.dll
  • %PROGRAM_FILES%\Glary Utilities 5\Microsoft.VC90.CRT.manifest
  • %PROGRAM_FILES%\Glary Utilities 5\Microsoft.VC90.MFC.manifest
  • %PROGRAM_FILES%\Glary Utilities 5\fileencrypt.exe
  • %PROGRAM_FILES%\Glary Utilities 5\FileScanFilter.dll
  • %PROGRAM_FILES%\Glary Utilities 5\filesplitter.exe
  • %PROGRAM_FILES%\Glary Utilities 5\dupefinder.exe
  • %PROGRAM_FILES%\Glary Utilities 5\EmptyFolderFinder.exe
  • %PROGRAM_FILES%\Glary Utilities 5\EncryptExe.exe
  • %PROGRAM_FILES%\Glary Utilities 5\FileUndelete.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Integrator.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Integrator_Portable.exe
  • %PROGRAM_FILES%\Glary Utilities 5\joinExe.exe
  • %PROGRAM_FILES%\Glary Utilities 5\gsd.exe
  • %PROGRAM_FILES%\Glary Utilities 5\iehelper.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Initialize.exe
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Farsi.lng
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\oc_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\oc_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\oc_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\activenow_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\activenow_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\main_like.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\tab_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskDefrag\toolbar.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\Dupefinder\nopreview.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\Dupefinder\tool.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\tab_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\tab_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\toolbar.png
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wxp_x86\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wxp_x86\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wxp_x86\RegBootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wxp_x64\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wxp_x64\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wxp_x64\RegBootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\CheckDisk\button_expand.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\OpenFile.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\Property.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\activenow_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskAnalysis\file_result.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskAnalysis\toolbar.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\DiskCleaner\Line.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\EmptyFolderFinder\toolbar.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\oc_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\oc_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\tab_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\activenow_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\main_like.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\oc_btn_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\tab_btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\settings\DiskCleanerImageList.bmp
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\settings\TracksEraseImageList.bmp
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\ShortuctFixer\toolbar.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\tab_btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryDefrag\regdefrag.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\settings\CleanRegistryImageList.bmp
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\PortableMaker\btn_normal.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\PortableMaker\progress.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\PortableMaker\progress_bg.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\InternetBooster\IBackGround.jpg
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\PortableMaker\background.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\PortableMaker\btn_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\ProcessManager\RClickMenu.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\Toolbar Default.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\activenow_click.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\activenow_hover.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\ProcessManager\ToolBar.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\QuickSearch\images\quick_search_logo.png
  • %PROGRAM_FILES%\Glary Utilities 5\Resources\RegistryCleaner\Line.png
  • %PROGRAM_FILES%\Glary Utilities 5\languages\chinese.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\chineseT.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\dutch.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Slovak.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Swedish.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\arabic.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\dutch2.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\hebrew.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\italian.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\italian2.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\english.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\french.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\french_nantesph.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\French(#DG#).lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\French(CA).lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\French(FR).lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Finnish.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Francais.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\French (Ad Lib).lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\French_(RT).lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Magyar2.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Romana.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Romania.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\German.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Greek.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\Magyar.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\japanese.lng
  • %PROGRAM_FILES%\Glary Utilities 5\Native\win7_x86\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Native\win7_x86\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wlh_x64\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\languages\vietnamese.lng
  • %PROGRAM_FILES%\Glary Utilities 5\Native\win7_x64\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Native\win7_x64\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wlh_x64\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wnet_x64\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wnet_x86\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wnet_x86\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wlh_x86\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wlh_x86\BootDefragDriver.sys
  • %PROGRAM_FILES%\Glary Utilities 5\Native\wnet_x64\BootDefrag.exe
  • %PROGRAM_FILES%\Glary Utilities 5\languages\russian.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\slovenian.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\slovenian_jrudec.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\korean.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\polish.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\ptbr.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\spain.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\turkish.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\ukrainian.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\ukrainian2.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\spanish (McM).lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\spanish.lng
  • %PROGRAM_FILES%\Glary Utilities 5\languages\spanish_ignacio.lng
Присваивает атрибут 'скрытый' для следующих файлов:
  • C:\~trtggrm.tmp
Удаляет следующие файлы:
  • %TEMP%\nsw3.tmp\System.dll
  • %TEMP%\nsw3.tmp\inetc.dll
  • C:\~trtggrm.tmp
  • %TEMP%\nsw3.tmp\xtInfoPlugin.dll
  • %PROGRAM_FILES%\Glary Utilities 5\data\backup.ini
  • %TEMP%\aut1.tmp
  • %TEMP%\nsw3.tmp\GlaryUtilities.ini
  • %HOMEPATH%\Templates\GUTracksIni.tmp
Сетевая активность:
Подключается к:
  • '54.##6.7.180':80
TCP:
Запросы HTTP POST:
  • 54.##6.7.180/install.php
Другое:
Ищет следующие окна:
  • ClassName: 'Indicator' WindowName: '(null)'
  • ClassName: 'Shell_TrayWnd' WindowName: '(null)'

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке