Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop5.42707

Добавлен в вирусную базу Dr.Web: 2014-12-04

Описание добавлено:

Техническая информация

Вредоносные функции:
Создает и запускает на исполнение:
  • '%TEMP%\is-V36CL.tmp\mbamSetup.tmp' /SL5="$200E2,20009049,56832,%TEMP%\7ZipSfx.000\mbamSetup.exe" /sp- /verysilent /norestart
  • '%TEMP%\7ZipSfx.000\mbamSetup.exe' /sp- /verysilent /norestart
  • '%TEMP%\mbam-setup.exe'
Запускает на исполнение:
  • '<SYSTEM32>\taskkill.exe' /f /t /im mbam.exe
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Malwarebytes Anti-Malware 2.0.4.1028.bat" > NUL"
Изменения в файловой системе:
Создает следующие файлы:
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-5NE7R.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-V5PQV.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-BRQHO.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-BR9A3.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-OLKKC.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-CRUUG.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-LBDSC.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Plugins\is-V1RD0.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\imageformats\is-1FK4F.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\accessible\is-E1GFV.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-QJ2UV.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-0G7NV.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-JI1SA.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-VJ5C7.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-Q03VJ.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-UJKO5.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-46B7N.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-G3DPO.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-HUKG3.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\is-IO3KT.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\is-NKFL8.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\is-EMTI5.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-TE832.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-66RT1.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-S68U3.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-NA6ON.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-LUT97.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-IO00R.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-3M0A3.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-KGT1N.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-GR44J.tmp
  • %ALLUSERSPROFILE%\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-6B4T0.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-1GPN5.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-UHPOL.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-QJ2SG.tmp
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\build.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\net.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\settings.conf
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\unins000.dat
  • %ALLUSERSPROFILE%\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk
  • %ALLUSERSPROFILE%\Start Menu\Programs\Malwarebytes Anti-Malware\Uninstall Malwarebytes Anti-Malware.lnk
  • %ALLUSERSPROFILE%\Desktop\Malwarebytes Anti-Malware.lnk
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-QRLT3.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-6567S.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-BCUFG.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-4G0US.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-SSE80.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-9Q9OO.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-KA9GU.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-OIN72.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-E0MFQ.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-1C8D2.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-675VH.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-P50QK.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-2U3Q1.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-8KA92.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-S1BOE.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-JI6OG.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-D0EJG.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-M0RG7.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-54231.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-I99CK.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-I3E4A.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-0KNP7.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-JL8P3.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-OEN92.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-LDGFO.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-Q9J3G.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-A3ADI.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-O59HD.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-NPNAD.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-60ETN.tmp
  • <DRIVERS>\is-7KJIV.tmp
  • %TEMP%\is-V36CL.tmp\mbamSetup.tmp
  • %TEMP%\is-K9RA2.tmp\_isetup\_shfoldr.dll
  • %TEMP%\is-K9RA2.tmp\mbam.dll
  • %TEMP%\7ZipSfx.000\mbamSetup.exe
  • %TEMP%\license.exe
  • %TEMP%\mbam-setup.exe
  • %TEMP%\Malwarebytes Anti-Malware 2.0.4.1028.bat
  • %TEMP%\is-K9RA2.tmp\msvcr100.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-EL6R0.tmp
  • <DRIVERS>\is-AULQV.tmp
  • %TEMP%\is-K9RA2.tmp\msvcp100.dll
  • %TEMP%\is-K9RA2.tmp\master.conf
  • %TEMP%\is-K9RA2.tmp\mbamsrv.dll
  • %TEMP%\is-K9RA2.tmp\QtCore4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-9ND1J.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-4IMQT.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-K52DP.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-R5I7J.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-6C0S8.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-GLNP5.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-7OS21.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-8H08U.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-9G4EB.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-BI1OL.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-O24IM.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-3E9HD.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-TCMTN.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-AOIUG.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-NBAON.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-PKNRC.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-M8A43.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-0FT4R.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-KHR79.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-HQV1E.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-HDSVC.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-F95UA.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-1TIJT.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-2EUOG.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-G76BL.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-BEB61.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-SFQIR.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-13DC5.tmp
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-Q4HAT.tmp
Удаляет следующие файлы:
  • %TEMP%\is-K9RA2.tmp\_isetup\_shfoldr.dll
  • %TEMP%\is-K9RA2.tmp\QtCore4.dll
  • %TEMP%\7ZipSfx.000\mbamSetup.exe
  • %TEMP%\is-V36CL.tmp\mbamSetup.tmp
  • %TEMP%\is-K9RA2.tmp\msvcr100.dll
  • %TEMP%\is-K9RA2.tmp\mbam.dll
  • %TEMP%\is-K9RA2.tmp\master.conf
  • %TEMP%\is-K9RA2.tmp\msvcp100.dll
  • %TEMP%\is-K9RA2.tmp\mbamsrv.dll
Перемещает следующие файлы:
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-LBDSC.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\database.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-BR9A3.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\manifest.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-5NE7R.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\marketing.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-Q03VJ.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\license.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-OLKKC.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\net.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-CRUUG.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\build.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-JI1SA.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\notifications.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-VJ5C7.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\license.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-QJ2UV.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\settings.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-V5PQV.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\scheduler.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-BRQHO.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\statistics.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\is-0G7NV.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\Restore\gatekeeper.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-46B7N.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\build.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-G3DPO.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\database.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-LUT97.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\manifest.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\is-EMTI5.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\swissarmy.ref
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-HUKG3.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\master.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-UJKO5.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\net.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-TE832.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\gatekeeper.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-66RT1.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\notifications.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-S68U3.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\settings.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-IO00R.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\marketing.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-3M0A3.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\scheduler.conf
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\is-NA6ON.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Configuration\statistics.conf
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-1C8D2.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-675VH.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-QRLT3.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.com
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-S1BOE.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.com
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-P50QK.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.pif
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-E0MFQ.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.scr
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-6B4T0.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-KGT1N.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\rundll32.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-GR44J.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\windows.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-1GPN5.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.pif
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-UHPOL.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\firefox.scr
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-QJ2SG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\iexplore.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-9Q9OO.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\7z.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-KA9GU.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\msvcp100.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-OIN72.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\msvcr100.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Plugins\is-V1RD0.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Plugins\fixdamage.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\imageformats\is-1FK4F.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\imageformats\qgif4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\accessible\is-E1GFV.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\accessible\qtaccessiblewidgets4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-4G0US.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-2U3Q1.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-killer.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\is-8KA92.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-SSE80.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\QtCore4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-6567S.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\QtGui4.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-BCUFG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\QtNetwork4.dll
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\is-NKFL8.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\actions.ref
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-LDGFO.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_bg.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-Q9J3G.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ca.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-HQV1E.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_cs.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-60ETN.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\license.rtf
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-A3ADI.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\changes.txt
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-OEN92.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ar.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-PKNRC.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_en.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-M8A43.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_es.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-0FT4R.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_et.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-HDSVC.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_da.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-F95UA.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_de.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-KHR79.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_el.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-I3E4A.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamext.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-0KNP7.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbam.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-JL8P3.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamcore.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-EL6R0.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\unins000.exe
  • <DRIVERS>\is-AULQV.tmp в <DRIVERS>\mbam.sys
  • <DRIVERS>\is-7KJIV.tmp в <DRIVERS>\mbamchameleon.sys
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-54231.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamscheduler.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-O59HD.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbampt.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-NPNAD.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamdor.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-I99CK.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamsrv.dll
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-D0EJG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbam.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\is-M0RG7.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\mbamservice.exe
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-3E9HD.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ro.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-TCMTN.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ru.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-AOIUG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_sk.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-9ND1J.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_pl.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-4IMQT.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_pt_BR.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-K52DP.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_pt_PT.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-BI1OL.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_tr.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-JI6OG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_vi.qm
  • %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\is-IO3KT.tmp в %ALLUSERSPROFILE%\Application Data\Malwarebytes\Malwarebytes Anti-Malware\rules.ref
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-O24IM.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_sl.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-8H08U.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_sv.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-9G4EB.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_th.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-BEB61.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_hu.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-1TIJT.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_id.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-2EUOG.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_it.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-SFQIR.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_fi.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-13DC5.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_fr.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-Q4HAT.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_he.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-GLNP5.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_lv.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-7OS21.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_nl.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-R5I7J.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_no.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-G76BL.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ja.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-NBAON.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_ko.qm
  • %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\is-6C0S8.tmp в %PROGRAM_FILES%\Malwarebytes Anti-Malware\Languages\lang_lt.qm
Другое:
Ищет следующие окна:
  • ClassName: 'SysPager' WindowName: ''
  • ClassName: 'ToolbarWindow32' WindowName: 'Notification Area'
  • ClassName: 'ToolbarWindow32' WindowName: 'User Promoted Notification Area'
  • ClassName: '' WindowName: ''
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'TrayNotifyWnd' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке