Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Inject1.52376

Добавлен в вирусную базу Dr.Web: 2015-02-08

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] 'msacm.l3acm' = 'l3codeca.acm'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] 'msacm.msgsm610' = 'msgsm32.acm'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'FairAge Conferencing' = '%WINDIR%\Downloaded Program Files\FairAge\Club\GcomFairAge.exe'
  • [<HKLM>\SOFTWARE\Classes\GComGcfFile\shell\open\command] '' = '%WINDIR%\Downloaded Program Files\FairAge\Club\GcomFairAge.exe %1'
  • [<HKLM>\SOFTWARE\Classes\GComGrfFile\shell\open\command] '' = '%WINDIR%\Downloaded Program Files\FairAge\Club\GcomRecordPlayer.exe %1'
  • [<HKLM>\SYSTEM\ControlSet001\Control\Print\Monitors\GcfConvert] 'Driver' = 'GcfConvert.dll'
Изменяет следующие исполняемые системные файлы:
  • <SYSTEM32>\msgsm32.acm
  • <SYSTEM32>\l3codeca.acm
  • <SYSTEM32>\wbem\framedyn.dll
Вредоносные функции:
Создает и запускает на исполнение:
  • '%WINDIR%\Downloaded Program Files\FairAge\Club\GcomFairAge.exe'
  • '%WINDIR%\Downloaded Program Files\FairAge\Club\SetupConfigure.exe'
Запускает на исполнение:
  • '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\SproControlComV1.dll"
  • '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\SproControlOcxV1.ocx"
Внедряет код в
следующие системные процессы:
  • <SYSTEM32>\spoolsv.exe
Изменяет следующие настройки браузера Windows Internet Explorer:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{AEBA21FA-782A-4A90-978D-B72164C80120}' = 'hex:1a,37,61,59,23,52,35,0c,7a,5f,20,17,2f,1e,1a,19,0e,2b,01,73,13,37,13,12,14,1a,15,2a,4e,2c,08,0d,20,1b,28,18,36,32'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{A8A88C49-5EB2-4990-A1A2-0876022C854F}' = 'hex:1a,37,61,59,23,52,35,0c,7a,5f,20,17,2f,1e,1a,19,0e,2b,01,73,13,37,13,12,14,1a,15,2a,4e,2c,08,0d,20,1b,28,18,36,32'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A10' = '00000001'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A05' = '00000000'
Изменения в файловой системе:
Создает следующие файлы:
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHallNavigateRightBar_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHelpWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHallNavigateLeftBar_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHallNavigateCmdBarBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHallNavigateCmdBar_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomRecordWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomRemoteCaptionBut_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomRecordControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomMediaPanelWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomRcrmFeePopUpWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHallNavigateBar_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\FilePanelWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\FilePanelWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\FilePanelHeaderWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\FilePanelBottomWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\FilePanelHeaderWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHallFrame_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHallNavigateBarBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomHallFrameBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomComGuiButton_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomConvertGcfWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomRemoteReturnDeskWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMain_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMdiClientBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiListIco.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiListCtrlBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiListCtrl_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMdiTabWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMenuArrow.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMdiTabWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMdiClient_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMdiTabControlPanel_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiDialog_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomReturnFullScreenWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomScreenCaptureBut_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomRemoteViewToolWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomRemoteToolWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomRemoteViewToolWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiComboBox_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiDialogBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GhatFileGuiDialog_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomTeaSpeeHidWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GcomUploadPopUpWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\FilePanelBottomWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\Decoding\Latin1
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\Decoding\StandardEncoding
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\ColorSpace\DefaultRGB
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\ColorSpace\DefaultCMYK
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\ColorSpace\DefaultGray
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\11.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\12.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\10.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\Decoding\Unicode
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\1.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\UniGB-UCS2-V
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\GBK-EUC-H
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\GBK-EUC-V
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\ETHK-B5-V
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\ETenms-B5-V
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\ETHK-B5-H
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\UniCNS-UCS2-V
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\UniGB-UCS2-H
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\UniCNS-UCS2-H
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\Identity-H
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\Identity-V
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\13.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ChatFileContainerBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ChatFileContainer_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\BulletinGuiControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\BottomGuiDockBar_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\BulletinGuiControlWndPanel_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ChatFileGuiTabCtrl_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ChatPanelWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ChatFileGuiControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ChatFileGuiBottom_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ChatFileGuiBottons_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\BottomGuiDockBarBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\5.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\6.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\4.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\2.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\3.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\AudioGuiControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\Blue.xml
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\9.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\7.wav
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Sound\8.wav
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\rp.log
  • <SYSTEM32>\spool\drivers\w32x86\PSCRIPT5.DLL
  • <SYSTEM32>\GcfConvert.dll
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
  • <SYSTEM32>\spool\drivers\w32x86\PSCRIPT.NTF
  • %HOMEPATH%\Start Menu\Programs\FairAge Communication\FairAge Conferencing Editor.lnk
  • %HOMEPATH%\Start Menu\Programs\FairAge Communication\FairAge Record Player.lnk
  • %HOMEPATH%\Start Menu\Programs\FairAge Communication\FairAge System Configure.lnk
  • %WINDIR%\SproControlOcxV1.ocx
  • %HOMEPATH%\Start Menu\Programs\FairAge Communication\FairAge Conferencing.lnk
  • <SYSTEM32>\spool\drivers\w32x86\PS5UI.dll
  • <SYSTEM32>\spool\drivers\w32x86\PSCRIPT.HLP
  • <SYSTEM32>\spool\drivers\w32x86\GcfConvert.PPD
  • %HOMEPATH%\Start Menu\Programs\FairAge Communication\Uninstall FairAge.lnk
  • %HOMEPATH%\Desktop\FairAge Conferencing.lnk
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\RestorePointSize
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
  • <SYSTEM32>\spool\drivers\w32x86\3\New\PSCRIPT5.DLL
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
  • <SYSTEM32>\spool\drivers\w32x86\3\New\PSCRIPT.NTF
  • <SYSTEM32>\spool\drivers\w32x86\3\GcfConvert.BPD
  • <SYSTEM32>\spool\drivers\w32x86\3\New\PSCRIPT.HLP
  • <SYSTEM32>\spool\drivers\w32x86\3\New\PS5UI.DLL
  • <SYSTEM32>\spool\drivers\w32x86\3\New\GcfConvert.PPD
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
  • %WINDIR%\Uninstall.exe
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\PlugInView_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\RecordPlayerControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\PlugInViewBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\MediaPlugInViewBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\MediaPlugInView_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\TeaSpeeGuiControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\TeaSpeeHidGuiControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\TeaSpeeGuiControlWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\RecordPlayerWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ScreenCaptureWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\LeftGuiDockBar_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiNavigateBar_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiParentTabBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiNavigateBarBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMenuBarBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiMenuPopBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiToolBarBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\LeftGuiDockBarBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiRecPlayerMenuBarBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiParentTab_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\GuiParent_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\ToolBar_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomFairAge.exe
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomFlashPlugIn.dvp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomDialog.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcfDll.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomCommon.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomKeyboardApi.dll
  • %WINDIR%\SproControlComV1.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomImagePlugIn.dvp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomGcfPlugIn.dvp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomGui.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\SproControlOcxV1.ocx
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\VideoGuiControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\VideoGuiDisplayWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\UserPanelWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\UserGuiControlWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\UserPanelWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\VotePlugInVotePanelBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\VotePlugInVotePanel_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\VotePlugInTabCtrl_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\VideoGuiPanelWndBg_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Skins\BlueSkin\VideoGuiPanelWnd_CN.bmp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\p052024l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\s050000l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\p052023l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\p052003l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\p052004l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\dumphint
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\EndOfTask.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\cidfmap
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\z003034l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\afmdiff.awk
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\nemsbis_.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n021004l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n021023l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n021003l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n019063l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n019064l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n022023l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n022024l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n022004l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n021024l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n022003l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\FAPIcidfmap
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_ciecs3.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_cmap.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_ciecs2.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_cidfn.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_cidtt.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_dbt_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_devcs.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_css_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_cmdl.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_cspace.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_cidfm.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_agl.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_btokn.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\Fontmap
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\FAPIconfig
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\FAPIfontmap
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_cidcm.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_ciddc.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_cff.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_ccfnt.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_ce_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n019044l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\msgsm32.acm
  • %WINDIR%\Downloaded Program Files\FairAge\Club\SetupConfigure.exe
  • %WINDIR%\Downloaded Program Files\FairAge\Club\l3codeca.acm
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomWhiteBoardPlugIn.dvp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\h263.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\SproJpegApi.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\SproZlibApi.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\SproImage.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\SproCommon.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\SproControlComV1.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomWebPlugIn.dvp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomRecordPlayer.exe
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomRecordServer.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomRecordApi.dll
  • %WINDIR%\Temp\Club\ClubSetup.rar
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomMediaPlugIn.dvp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomSocket.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomVotePlugIn.dvp
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomRemoteView.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomRemoteApi.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\GcomRemoteServer.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Uninstall.exe
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\d050000l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\fonts.scale
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\c059036l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\c059016l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\c059033l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n019024l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n019043l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n019023l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n019003l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\n019004l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\c059013l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\a010015l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\a010033l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\a010013l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Config.xml
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\GcfConfig.xml
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\b018032l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\b018035l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\b018015l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\a010035l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Fonts\b018012l.pfb
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\opdfread.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdfopt
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\mkcidfm.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\lprsetup.sh
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\markhint.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdf_draw.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdf_font.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdf_base.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdfwrite.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\PDFX_def.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\lines.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_typ32.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_typ42.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_ttf.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_sym_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_trap.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_wl2_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_wl5_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_wl1_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_type1.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_wan_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdf_main.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Printer\PSCRIPT.HLP
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Printer\PSCRIPT.NTF
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Printer\PS5UI.DLL
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Printer\GcfConvert.inf
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Printer\GcfConvert.PPD
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\ETen-B5-V
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\ETenms-B5-H
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\ETen-B5-UCS2
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Printer\PSCRIPT5.DLL
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Resource\CMap\ETen-B5-H
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Printer\GcfConvert.dll
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pf2afm.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\rollconv.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdf_sec.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdf_ops.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\pdf_rbld.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\type1ops.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\xlatmap
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\stcolor.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\showchar.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\stcinfo.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_stres.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_frsd.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_icc.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_fonts.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_fform.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_fntem.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_indxd.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_init.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_img.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_il1_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_il2_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_fapi.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_diskn.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_dpnxt.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_diskf.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_devn.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_devpxl.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_dscp.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_epsf.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_dps2.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_dps.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_dps1.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_kanji.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_res.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_resmp.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_rdlin.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_pdf_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_pfile.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_statd.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_std_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_setpd.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_resst.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_sepr.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_pdfwr.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_lgo_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_lgx_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_lev2.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_ksb_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_l2img.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_mro_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_patrn.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_mgl_e.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_ll3.ps
  • %WINDIR%\Downloaded Program Files\FairAge\Club\Data\Lib\gs_mex_e.ps
Удаляет следующие файлы:
  • <SYSTEM32>\spool\drivers\w32x86\PSCRIPT.HLP
  • <SYSTEM32>\spool\drivers\w32x86\PSCRIPT.NTF
  • <SYSTEM32>\spool\drivers\w32x86\PSCRIPT5.DLL
  • <SYSTEM32>\spool\drivers\w32x86\GcfConvert.PPD
  • <SYSTEM32>\spool\drivers\w32x86\PS5UI.dll
Перемещает следующие файлы:
  • <SYSTEM32>\spool\drivers\w32x86\3\New\PSCRIPT.HLP в <SYSTEM32>\spool\drivers\w32x86\3\PSCRIPT.HLP
  • <SYSTEM32>\spool\drivers\w32x86\3\New\PSCRIPT.NTF в <SYSTEM32>\spool\drivers\w32x86\3\PSCRIPT.NTF
  • <SYSTEM32>\spool\drivers\w32x86\3\New\GcfConvert.PPD в <SYSTEM32>\spool\drivers\w32x86\3\GcfConvert.PPD
  • <SYSTEM32>\spool\drivers\w32x86\3\New\PSCRIPT5.DLL в <SYSTEM32>\spool\drivers\w32x86\3\PSCRIPT5.DLL
  • <SYSTEM32>\spool\drivers\w32x86\3\New\PS5UI.DLL в <SYSTEM32>\spool\drivers\w32x86\3\PS5UI.DLL
Другое:
Ищет следующие окна:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'Afx:Sunpro:VisAllClub' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке