Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop5.41078

Добавлен в вирусную базу Dr.Web: 2014-10-18

Описание добавлено:

Техническая информация

Вредоносные функции:
Создает и запускает на исполнение:
  • '%TEMP%\is-BNVRR.tmp\Setup.tmp' /SL5="$40194,18919122,56832,%APPDATA%\Roaming\Setup.exe" /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
  • '%APPDATA%\Roaming\Setup.exe' /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
Изменения в файловой системе:
Создает следующие файлы:
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-3VDOQ.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-DCG5H.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-G4TJD.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-5ROHN.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-726EK.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-CAMJK.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-KEKUO.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-LR1F6.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Plugins\is-9IV24.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\imageformats\is-GNU21.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-O0MHR.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-K8G01.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-2P03D.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-9GT9E.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-GMODS.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-3C888.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-24K0E.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-A3KQ1.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-FQN4D.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-K356O.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-CCDTO.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-83G4S.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-IF2A4.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-E8VJG.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-4QRL3.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-NR5UJ.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-08RFN.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-FVQ8J.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-P2EL2.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-RS5BO.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-BERFG.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-6829I.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-2C6TD.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-K8A6D.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-35D9N.tmp
  • C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\unins000.dat
  • \Device\Mup\BVNSEUHJ*\MAILSLOT\NET\NETLOGON
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Uninstall Malwarebytes Anti-Malware.lnk
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-S18TE.tmp
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-3B770.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-UONMV.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-8ISUV.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-T2862.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\accessible\is-ASO7P.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-6UV3T.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-93TCN.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-85VFG.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-AOFS7.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-D67V1.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-1ECOK.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-C6T0A.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-E2257.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-D3SL3.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-J7UAP.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-KV4QS.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-E4PC8.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-9B93G.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-8S21K.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-KAQ6M.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-D9NGC.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-T2051.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-678FP.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-MCF7H.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-EO09H.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-G1CHS.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-H7COV.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-27GAI.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-2O01O.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-86KFF.tmp
  • <DRIVERS>\is-ID8OR.tmp
  • <DRIVERS>\is-HQBTS.tmp
  • %TEMP%\is-6P8AL.tmp\_isetup\_shfoldr.dll
  • %TEMP%\autEAF.tmp
  • %APPDATA%\Roaming\Setup.exe
  • %TEMP%\is-BNVRR.tmp\Setup.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-9G29A.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-GN0UN.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-4CSJ0.tmp
  • <DRIVERS>\is-BQA09.tmp
  • <DRIVERS>\is-4LO6A.tmp
  • <DRIVERS>\is-FNBSP.tmp
  • <DRIVERS>\is-DF6AA.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-5SB4I.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-HMVTN.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-U8CVN.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-3T9DP.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-NJOF1.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-DHQB1.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-Q47V9.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-2LEV0.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-20K0M.tmp
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-TBE8A.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-02P6A.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-18FV1.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-GJF5R.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-TH4R7.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-G4FH8.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-N9HQN.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-74248.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-25HGD.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-SSABS.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-Q7CGO.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-RBE7G.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-S0LID.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-F8PH7.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-K4G8F.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-M6LRG.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-LGJN4.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-H2K5P.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-PL90C.tmp
Присваивает атрибут 'скрытый' для следующих файлов:
  • %APPDATA%\Roaming\Setup.exe
Удаляет следующие файлы:
  • %TEMP%\is-6P8AL.tmp\_isetup\_shfoldr.dll
  • %TEMP%\is-BNVRR.tmp\Setup.tmp
  • %APPDATA%\Roaming\Setup.exe
  • <DRIVERS>\mbamchameleon.sys
  • %TEMP%\autEAF.tmp
  • <DRIVERS>\mbam.sys
  • <DRIVERS>\mwac.sys
Перемещает следующие файлы:
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-CAMJK.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\net.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-KEKUO.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\build.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-5ROHN.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\database.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-IF2A4.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\notifications.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-E8VJG.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\settings.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-726EK.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\license.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-K8G01.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\statistics.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-2P03D.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\gatekeeper.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-9GT9E.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\notifications.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-3VDOQ.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\manifest.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-DCG5H.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\marketing.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-G4TJD.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\scheduler.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-83G4S.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\gatekeeper.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-CCDTO.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\ips.ref
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-A3KQ1.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\master.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-GMODS.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\net.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-J7UAP.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\actions.ref
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-FQN4D.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\swissarmy.ref
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-K356O.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\domains.ref
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-08RFN.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\marketing.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-FVQ8J.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\scheduler.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-4QRL3.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\statistics.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-3C888.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\build.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-24K0E.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\database.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-NR5UJ.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\manifest.conf
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-O0MHR.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\license.conf
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-D67V1.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-2C6TD.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-K8A6D.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.com
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-1ECOK.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.com
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-85VFG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.pif
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-AOFS7.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.scr
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-RS5BO.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-BERFG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\rundll32.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-S18TE.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\windows.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-35D9N.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.pif
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-6829I.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.scr
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-P2EL2.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\iexplore.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-D3SL3.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\accessible\is-ASO7P.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\accessible\qtaccessiblewidgets4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-6UV3T.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\7z.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-93TCN.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\msvcp100.dll
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-LR1F6.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\settings.conf
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Plugins\is-9IV24.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Plugins\fixdamage.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\imageformats\is-GNU21.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\imageformats\qgif4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-8ISUV.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\QtNetwork4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-C6T0A.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-E2257.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-killer.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-T2862.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\msvcr100.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-3B770.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\QtCore4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-UONMV.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\QtGui4.dll
  • C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\is-TBE8A.tmp в C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\rules.ref
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-9B93G.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\license.rtf
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-H7COV.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\changes.txt
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-27GAI.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ar.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-8S21K.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamscheduler.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-KV4QS.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbampt.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-E4PC8.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamdor.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-MCF7H.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_da.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-EO09H.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_de.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-SSABS.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_el.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-2O01O.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_bg.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-G1CHS.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ca.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-678FP.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_cs.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-T2051.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamservice.exe
  • <DRIVERS>\is-4LO6A.tmp в <DRIVERS>\mwac.sys
  • <DRIVERS>\is-FNBSP.tmp в <DRIVERS>\mwac.sys
  • <DRIVERS>\is-DF6AA.tmp в <DRIVERS>\mbamchameleon.sys
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-86KFF.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\unins000.exe
  • <DRIVERS>\is-ID8OR.tmp в <DRIVERS>\mbam.sys
  • <DRIVERS>\is-HQBTS.tmp в <DRIVERS>\mbam.sys
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-4CSJ0.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamcore.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-KAQ6M.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamsrv.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-D9NGC.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbam.exe
  • <DRIVERS>\is-BQA09.tmp в <DRIVERS>\mbamchameleon.sys
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-9G29A.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamext.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-GN0UN.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbam.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-Q7CGO.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_en.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-5SB4I.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_pt_PT.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-HMVTN.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ro.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-U8CVN.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ru.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-DHQB1.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_no.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-Q47V9.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_pl.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-3T9DP.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_pt_BR.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-02P6A.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_th.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-2LEV0.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_tr.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-20K0M.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_vi.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-18FV1.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_sk.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-GJF5R.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_sl.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-TH4R7.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_sv.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-NJOF1.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_nl.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-N9HQN.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_fr.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-74248.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_he.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-LGJN4.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_hu.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-RBE7G.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_es.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-25HGD.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_et.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-G4FH8.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_fi.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-S0LID.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ko.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-F8PH7.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_lt.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-K4G8F.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_lv.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-H2K5P.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_id.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-PL90C.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_it.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-M6LRG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ja.qm
Другое:
Ищет следующие окна:
  • ClassName: 'Shell_TrayWnd' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке