Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop5.41594

Добавлен в вирусную базу Dr.Web: 2014-11-07

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Malwarebytes Anti-Malware' = '%PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent'
Вредоносные функции:
Создает и запускает на исполнение:
  • '%TEMP%\is-9CLN8.tmp\mwb.tmp' /SL5="$200E0,9824451,54272,<SYSTEM32>\mwb.exe" /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
  • '<SYSTEM32>\mwb.exe' /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
Запускает на исполнение:
  • '<SYSTEM32>\regsvr32.exe' /s "%PROGRAM_FILES%\Malwarebytes' Anti-Malware\vbalsgrid6.ocx"
  • '<SYSTEM32>\regsvr32.exe' /s "%PROGRAM_FILES%\Malwarebytes' Anti-Malware\ssubtmr6.dll"
  • '<SYSTEM32>\regsvr32.exe' /s "%PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbamext.dll"
Изменения в файловой системе:
Создает следующие файлы:
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-9H4RG.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-PVCM0.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-GGEN8.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\is-06KHM.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-GPRK2.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-V9PKM.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-DQJ1Q.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-QOPQ0.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-P4901.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-TFVHB.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-2KUGT.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-RMKN8.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-H4FN4.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-CHA34.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-2C7L0.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-N9HFE.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-MTJ7Q.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-KSG5C.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-NLF27.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-QPTN0.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-3NT0A.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-7Q1FR.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-QGV0C.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-BM29E.tmp
  • %ALLUSERSPROFILE%\Start Menu\Programs\Malwarebytes' Anti-Malware\Malwarebytes Anti-Malware.lnk
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-7INIG.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-0GO8U.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-GM6K5.tmp
  • %ALLUSERSPROFILE%\Start Menu\Programs\Malwarebytes' Anti-Malware\Malwarebytes Anti-Malware Help.lnk
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\unins000.msg
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\unins000.dat
  • %ALLUSERSPROFILE%\Desktop\Malwarebytes Anti-Malware.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\Malwarebytes' Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\Malwarebytes' Anti-Malware\Uninstall Malwarebytes Anti-Malware.lnk
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-KFB6U.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-MEBQ0.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-ML6I5.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-6E5T7.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-EG9V7.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-ESAMG.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-I56K6.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-D1R7Q.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-C88PQ.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-9S8PF.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-NBICK.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-PHEE2.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-5R2MQ.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-RIT81.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-R3F41.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-E022C.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-TC5F4.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-8E4UB.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-4B5HE.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-TI7TL.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-46BB8.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-GJ2F4.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-D4H98.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-5G4JS.tmp
  • %TEMP%\is-FD2GR.tmp\_isetup\_shfoldr.dll
  • %TEMP%\is-FD2GR.tmp\mbam.dll
  • %TEMP%\is-9CLN8.tmp\mwb.tmp
  • %TEMP%\aut1.tmp
  • <SYSTEM32>\mwb.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-2F01B.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-0QGC1.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-6U45K.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-P4JLI.tmp
  • <DRIVERS>\is-D4DH7.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-6FQIN.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-N8PTB.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-K2L7F.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-JV1BP.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-V1ND6.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-MO3QT.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-OB8L9.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-PUGDN.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-86FVQ.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-TGMNO.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-CU82J.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-QL4ED.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-58ODG.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-62KQD.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-2PS7M.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-ICD46.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-MLOSV.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-6IF4Q.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-OSE1E.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-89M1S.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-8B8BK.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-0R636.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-VGEMB.tmp
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-PL043.tmp
Удаляет следующие файлы:
  • %TEMP%\is-9CLN8.tmp\mwb.tmp
  • <SYSTEM32>\mwb.exe
  • %TEMP%\is-FD2GR.tmp\_isetup\_shfoldr.dll
  • %TEMP%\aut1.tmp
  • %TEMP%\is-FD2GR.tmp\mbam.dll
Перемещает следующие файлы:
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\is-06KHM.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\rules.ref
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-GPRK2.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\config.conf
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-RMKN8.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\vietnamese.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-NLF27.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\thai.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-QPTN0.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\turkish.lng
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-V9PKM.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\html.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-TFVHB.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\database.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-PVCM0.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\news.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-GGEN8.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\build.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-9H4RG.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\custom.conf
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-2C7L0.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\romanian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-H4FN4.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\russian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-MTJ7Q.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\portuguesePT.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-86FVQ.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\polish.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-N9HFE.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\portugueseBR.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-QGV0C.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\spanish.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-3NT0A.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\swedish.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-7Q1FR.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\slovenian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-CHA34.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\serbian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-KSG5C.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\slovak.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-D1R7Q.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\firefox.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-C88PQ.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\firefox.com
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-9S8PF.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-NBICK.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.pif
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-PHEE2.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.scr
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-7INIG.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-BM29E.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\rundll32.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-GM6K5.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-KFB6U.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\firefox.pif
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-0GO8U.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\firefox.scr
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-QOPQ0.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\7z.dll
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-EG9V7.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\ssubtmr6.dll
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-DQJ1Q.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\local.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-2KUGT.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\manifest.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\is-P4901.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Configuration\messaging.conf
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-ML6I5.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-I56K6.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.com
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-MEBQ0.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\mbam-killer.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-ESAMG.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\vbalsgrid6.ocx
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\is-6E5T7.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-GJ2F4.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\changes.txt
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-D4H98.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\arabic.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-8E4UB.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\license.rtf
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-5R2MQ.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbampt.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-RIT81.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbam.chm
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-MLOSV.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\catalan.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-6IF4Q.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\chineseSI.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-TI7TL.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\bulgarian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-46BB8.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\belarusian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-4B5HE.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\bosnian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-P4JLI.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbam.dll
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-0QGC1.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbamcore.dll
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-6FQIN.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbamext.dll
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-2F01B.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\unins000.exe
  • <DRIVERS>\is-D4DH7.tmp в <DRIVERS>\mbam.sys
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-TC5F4.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbamservice.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-R3F41.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbamscheduler.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-E022C.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbamgui.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-6U45K.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbamnet.dll
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\is-5G4JS.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\mbam.exe
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-N8PTB.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\indonesian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-K2L7F.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\italian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-JV1BP.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\hungarian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-V1ND6.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\greek.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-MO3QT.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\hebrew.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-TGMNO.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\lithuanian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-PUGDN.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\norwegian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-QL4ED.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\latvian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-OB8L9.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\japanese.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-CU82J.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\korean.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-OSE1E.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\danish.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-VGEMB.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\dutch.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-2PS7M.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\czech.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-ICD46.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\chineseTR.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-62KQD.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\croatian.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-8B8BK.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\french.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-58ODG.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\german.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-89M1S.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\finnish.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-PL043.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\english.lng
  • %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\is-0R636.tmp в %PROGRAM_FILES%\Malwarebytes' Anti-Malware\Languages\estonian.lng
Другое:
Ищет следующие окна:
  • ClassName: 'BUTTON' WindowName: ''
  • ClassName: 'Shell_TrayWnd' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке