Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.DownLoader27.16428

Добавлен в вирусную базу Dr.Web: 2018-11-22

Описание добавлено:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKLM>\SYSTEM\ControlSet001\Control\Session Manager] 'BootExecute' = 'autocheck autochk *'
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\ampa] 'ImagePath' = '<SYSTEM32>\ampa.sys'
Modifies file system:
Creates the following files:
  • <Current directory>\Data\xsandbox.bin.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\x86_Microsoft.VC80.MFC@8.0.50727.762.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\Microsoft.VC80.MFC.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfcm80u.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfcm80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfc80u.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfc80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\x86_Microsoft.VC80.CRT@8.0.50727.762.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcr80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcp80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcm80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\Microsoft.VC80.CRT.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_JR.Inno.Setup@1.0.0.0\x86_JR.Inno.Setup@1.0.0.0.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_JR.Inno.Setup@1.0.0.0\JR.Inno.Setup.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\Microsoft.Windows.OSLoader.BcdBoot.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\VhdMgr.dll\VhdMgr.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\UnInstallAb.dll\UnInstallAb.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SSDSecurityErase.dll\SSDSecurityErase.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SetupGreen64.exe\SetupGreen64.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SetupGreen32.exe\SetupGreen32.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\ScanPartition.dll\ScanPartition.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PeLoadDrv.exe\PeLoadDrv.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PE.dll\PE.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PartAssist.exe\PartAssist.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Ntfs2Fat32.exe\Ntfs2Fat32.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\mfc80u.dll\mfc80u.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\mfc80.dll\mfc80.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Winchk.exe_0xdc67840cce7415643dbed358d34ee961.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Winchk.exe\Winchk.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\EPW.exe_0x26d2617834ec75df62cf6302a2139997.1.manifest.__tmp__
  • <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PE.dll
  • <Current directory>\Data\roaming\modified\@SYSDRIVE@\AMTAG.BIN
  • <Current directory>\Data\roaming\meta\@SYSDRIVE@\AMTAG.BIN.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@SYSDRIVE@\AMTAG.BIN
  • <SYSTEM32>\ampa.sys
  • %WINDIR%\ampa.exe
  • <Current directory>\Data\local\stubexe\0x582ABB980551FC15\LoadDrv_Win32.exe.manifest.__tmp__
  • <Current directory>\Data\local\stubexe\0x582ABB980551FC15\LoadDrv_Win32.exe.__tmp__
  • <Current directory>\Data\local\stubexe\0xE0A84939C8975F57\SetupGreen32.exe.manifest.__tmp__
  • <Current directory>\Data\local\stubexe\0xE0A84939C8975F57\SetupGreen32.exe.__tmp__
  • <Current directory>\Data\roaming\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa2.log
  • <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa1.log.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa1.log
  • <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa0.log.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa0.log
  • <Current directory>\Data\roaming\modified\@SYSWOW64@\ampa.sys
  • <Current directory>\Data\roaming\meta\@SYSWOW64@\ampa.sys.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@SYSWOW64@\ampa.sys
  • <Current directory>\Data\roaming\modified\@WINDIR@\ampa.exe
  • <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\native\w2k\x86\fre\ampa.exe.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\native\w2k\x86\fre\ampa.exe
  • <Current directory>\Data\roaming\meta\@WINDIR@\ampa.exe.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@WINDIR@\ampa.exe
  • <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\language.ini.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\language.ini
  • <Current directory>\Data\roaming\meta\@DESKTOP@\AOMEI Partition Assistant Technician Edition 7.5.1.lnk.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@DESKTOP@\AOMEI Partition Assistant Technician Edition 7.5.1.lnk
  • <Current directory>\Data\roaming\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\cfg.ini
  • <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\cfg.ini.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\cfg.ini
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Winchk.exe_0xd620418b13aedfc8a6fc942c08babdfd.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\WimMgr.dll\WimMgr.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\WimMgr.dll_0xd76e9cf4549de45cd5cf74723277dca1.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\WimMgr.dll_0x3be089daa177a822a945800aa0539236.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\VhdMgr.dll_0xfd5a438cc266d5a437d83739046de418.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfcm80u.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\AMBooter.exe_0x6918401b4264d601b9ab30603379ebdf.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\AMBooter.exe_0x2077dc04b4f532cfc930696bfcc46334.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\LoadDrv_x64.exe\LoadDrv_x64.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\LoadDrv_Win32.exe\LoadDrv_Win32.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\loaddrv.exe\loaddrv.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Help.exe\Help.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\GptBcd.dll\GptBcd.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\exfat.dll\exfat.dll.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\EPW.exe\EPW.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\DyndiskConverter.exe\DyndiskConverter.exe.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\Microsoft.Windows.OSLoader.BcdBoot.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\Microsoft.VC80.MFC.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfcm80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\bcdboot.exe_0xc78d8faa496f82160d221ef2056fbdec.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfc80u.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfc80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\amd64_Microsoft.VC80.MFC@8.0.50727.762.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcr80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcp80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcm80.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\Microsoft.VC80.CRT.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\amd64_Microsoft.VC80.CRT@8.0.50727.762.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\AMBooter.exe\AMBooter.exe.manifest.__tmp__
  • <Current directory>\Data\local\stubexe\0xB5FACA007A65F698\PartAssist.exe.manifest.__tmp__
  • <Current directory>\Data\local\stubexe\0xB5FACA007A65F698\PartAssist.exe.__tmp__
  • <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PartAssist.exe.__meta__.__tmp__
  • <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PartAssist.exe
  • <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\wnd.ini
  • <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PE.dll.__meta__.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\DyndiskConverter.exe_0x5c272ec6e8f4e87d7c43aa9c205ca161.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\exfat.dll_0xd071ba1a8bf3165006b0d7ec35e2ed59.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\bcdboot.exe_0x94294c3d1c41e6207c7e5d0cd0f80b2f.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\VhdMgr.dll_0x118a17088bbcd8a83f66c160eb0fa895.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\UnInstallAb.dll_0x9c30a14ed9fcebcc32854bc9ef557674.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\unins000.exe_0x13f2b950b40ed6bb53900c4b0620ec6e.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SSDSecurityErase.dll_0x79bb8e310f8907d1ca8cebdb5b1e1baf.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SetupGreen64.exe_0x786aaa59fc273e0a0d2d6a1b21af2025.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SetupGreen32.exe_0xdff084a7451d4d7b1adae34d578d781b.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\ScanPartition.dll_0xc140a0ac3faad2ce2ff4ed121c326ae6.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\ScanPartition.dll_0x56643a64937901fefcdfd64cb5b00a30.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PeLoadDrv.exe_0x9c81d885425457a48ea6ff25567fce34.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PE.dll_0x52bccfa9738033efe947688920cbf95d.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PE.dll_0x034e8863d97bddaff9db2a178b6695fc.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PartAssist.exe_0xe551d2bb42dab85de85af6af004868fc.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PartAssist.exe_0xb9f64ed8b887e10bc5d80c343500e42d.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Ntfs2Fat32.exe_0x9ff1ce16c26acc103809b0f316105871.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.MFC.manifest_0x97b859f11538bbe20f17dfb9c0979a1c.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.MFC.manifest_0x7dc52d085a05db8a72fed96bb342412b.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.CRT.manifest_0xa72dde00d763aeef1eb04534f8672967.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.CRT.manifest_0x541423a06efdcd4e4554c719061f82cf.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80u.dll_0xccc2e312486ae6b80970211da472268b.1000.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80u.dll_0x21ee912784a013dc44071ecc4f932388.1000.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80.dll_0x9173f70af60c0a864eecdfb3342dc789.1000.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80.dll_0x1b7524806d0270b81360c63a2fa047cb.1000.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\LoadDrv_x64.exe_0x2266bb132b8318b7d1ced34c58312d35.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\LoadDrv_Win32.exe_0x54386df19aa88572e10421917bc8c2f7.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\loaddrv.exe_0x54386df19aa88572e10421917bc8c2f7.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Help.exe_0x3d62b7d3079341e59e1c776035e7b3a9.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\GptBcd.dll_0xa21a0a2d9ab42fe8a4b955a06a0bfa90.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\GptBcd.dll_0x6a20cb2095b0073ec28746629533eda6.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\exfat.dll_0x27ef6b359e11a89d7624bd67d6e94fee.2.manifest.__tmp__
  • <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\wnd.ini.__meta__.__tmp__
Sets the 'hidden' attribute to the following files:
  • <Current directory>\Data\roaming\modified\@SYSDRIVE@\AMTAG.BIN
Deletes the following files:
  • <Current directory>\Data\roaming\meta\@DESKTOP@\AOMEI Partition Assistant Technician Edition 7.5.1.lnk.__meta__
  • <Current directory>\Data\roaming\modified\@WINDIR@\ampa.exe
  • <Current directory>\Data\roaming\meta\@WINDIR@\ampa.exe.__meta__
  • <Current directory>\Data\roaming\modified\@SYSWOW64@\ampa.sys
  • <Current directory>\Data\roaming\meta\@SYSWOW64@\ampa.sys.__meta__
Moves the following files:
  • from <Current directory>\Data\xsandbox.bin.__tmp__ to <Current directory>\Data\xsandbox.bin
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfc80u.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfc80u.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfc80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfc80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\x86_Microsoft.VC80.CRT@8.0.50727.762.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\x86_Microsoft.VC80.CRT@8.0.50727.762.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcr80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcr80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcp80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcp80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcm80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\msvcm80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\Microsoft.VC80.CRT.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.CRT@8.0.50727.762\Microsoft.VC80.CRT.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_JR.Inno.Setup@1.0.0.0\x86_JR.Inno.Setup@1.0.0.0.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_JR.Inno.Setup@1.0.0.0\x86_JR.Inno.Setup@1.0.0.0.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_JR.Inno.Setup@1.0.0.0\JR.Inno.Setup.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_JR.Inno.Setup@1.0.0.0\JR.Inno.Setup.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Winchk.exe\Winchk.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Winchk.exe\Winchk.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\WimMgr.dll\WimMgr.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\WimMgr.dll\WimMgr.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\VhdMgr.dll\VhdMgr.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\VhdMgr.dll\VhdMgr.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\UnInstallAb.dll\UnInstallAb.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\UnInstallAb.dll\UnInstallAb.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SSDSecurityErase.dll\SSDSecurityErase.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SSDSecurityErase.dll\SSDSecurityErase.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SetupGreen64.exe\SetupGreen64.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SetupGreen64.exe\SetupGreen64.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SetupGreen32.exe\SetupGreen32.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\SetupGreen32.exe\SetupGreen32.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\ScanPartition.dll\ScanPartition.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\ScanPartition.dll\ScanPartition.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PeLoadDrv.exe\PeLoadDrv.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PeLoadDrv.exe\PeLoadDrv.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PE.dll\PE.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PE.dll\PE.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PartAssist.exe\PartAssist.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\PartAssist.exe\PartAssist.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Ntfs2Fat32.exe\Ntfs2Fat32.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Ntfs2Fat32.exe\Ntfs2Fat32.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\mfc80u.dll\mfc80u.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\mfc80u.dll\mfc80u.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\mfc80.dll\mfc80.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\mfc80.dll\mfc80.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Winchk.exe_0xdc67840cce7415643dbed358d34ee961.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Winchk.exe_0xdc67840cce7415643dbed358d34ee961.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Winchk.exe_0xd620418b13aedfc8a6fc942c08babdfd.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Winchk.exe_0xd620418b13aedfc8a6fc942c08babdfd.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\WimMgr.dll_0xd76e9cf4549de45cd5cf74723277dca1.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\WimMgr.dll_0xd76e9cf4549de45cd5cf74723277dca1.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\WimMgr.dll_0x3be089daa177a822a945800aa0539236.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\WimMgr.dll_0x3be089daa177a822a945800aa0539236.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfcm80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfcm80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfcm80u.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\mfcm80u.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\Microsoft.VC80.MFC.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\Microsoft.VC80.MFC.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\x86_Microsoft.VC80.MFC@8.0.50727.762.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.VC80.MFC@8.0.50727.762\x86_Microsoft.VC80.MFC@8.0.50727.762.manifest
  • from <Current directory>\Data\roaming\meta\@SYSDRIVE@\AMTAG.BIN.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@SYSDRIVE@\AMTAG.BIN.__meta__
  • from <Current directory>\Data\local\temp\@SYSDRIVE@\AMTAG.BIN to <Current directory>\Data\roaming\modified\@SYSDRIVE@\AMTAG.BIN
  • from <Current directory>\Data\local\stubexe\0x582ABB980551FC15\LoadDrv_Win32.exe.manifest.__tmp__ to <Current directory>\Data\local\stubexe\0x582ABB980551FC15\LoadDrv_Win32.exe.manifest
  • from <Current directory>\Data\local\stubexe\0x582ABB980551FC15\LoadDrv_Win32.exe.__tmp__ to <Current directory>\Data\local\stubexe\0x582ABB980551FC15\LoadDrv_Win32.exe
  • from <Current directory>\Data\local\stubexe\0xE0A84939C8975F57\SetupGreen32.exe.manifest.__tmp__ to <Current directory>\Data\local\stubexe\0xE0A84939C8975F57\SetupGreen32.exe.manifest
  • from <Current directory>\Data\local\stubexe\0xE0A84939C8975F57\SetupGreen32.exe.__tmp__ to <Current directory>\Data\local\stubexe\0xE0A84939C8975F57\SetupGreen32.exe
  • from <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa1.log.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa1.log.__meta__
  • from <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa1.log to <Current directory>\Data\roaming\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa1.log
  • from <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa0.log.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa0.log.__meta__
  • from <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa0.log to <Current directory>\Data\roaming\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\log\ampa0.log
  • from <Current directory>\Data\roaming\meta\@SYSWOW64@\ampa.sys.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@SYSWOW64@\ampa.sys.__meta__
  • from <Current directory>\Data\local\temp\@SYSWOW64@\ampa.sys to <Current directory>\Data\roaming\modified\@SYSWOW64@\ampa.sys
  • from <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\native\w2k\x86\fre\ampa.exe.__meta__.__tmp__ to <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\native\w2k\x86\fre\ampa.exe.__meta__
  • from <Current directory>\Data\roaming\meta\@WINDIR@\ampa.exe.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@WINDIR@\ampa.exe.__meta__
  • from <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\native\w2k\x86\fre\ampa.exe to <Current directory>\Data\local\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\native\w2k\x86\fre\ampa.exe
  • from <Current directory>\Data\local\temp\@WINDIR@\ampa.exe to <Current directory>\Data\roaming\modified\@WINDIR@\ampa.exe
  • from <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\language.ini.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\language.ini.__meta__
  • from <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\language.ini to <Current directory>\Data\roaming\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\language.ini
  • from %HOMEPATH%\Desktop\AOMEI Partition Assistant Unlimited Edition 7.5.1.lnk to %HOMEPATH%\Desktop\AOMEI Partition Assistant Server Edition 7.5.1.lnk
  • from <Current directory>\Data\roaming\modified\@DESKTOP@\AOMEI Partition Assistant Technician Edition 7.5.1.lnk to %HOMEPATH%\Desktop\AOMEI Partition Assistant Unlimited Edition 7.5.1.lnk
  • from <Current directory>\Data\roaming\meta\@DESKTOP@\AOMEI Partition Assistant Technician Edition 7.5.1.lnk.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@DESKTOP@\AOMEI Partition Assistant Technician Edition 7.5.1.lnk.__meta__
  • from <Current directory>\Data\local\temp\@DESKTOP@\AOMEI Partition Assistant Technician Edition 7.5.1.lnk to <Current directory>\Data\roaming\modified\@DESKTOP@\AOMEI Partition Assistant Technician Edition 7.5.1.lnk
  • from <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\cfg.ini.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\cfg.ini.__meta__
  • from <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\cfg.ini to <Current directory>\Data\roaming\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\cfg.ini
  • from <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PE.dll.__meta__.__tmp__ to <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PE.dll.__meta__
  • from <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PE.dll to <Current directory>\Data\local\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PE.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\Microsoft.Windows.OSLoader.BcdBoot.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\x86_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\Microsoft.Windows.OSLoader.BcdBoot.manifest
  • from <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\wnd.ini to <Current directory>\Data\roaming\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\wnd.ini
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\VhdMgr.dll_0xfd5a438cc266d5a437d83739046de418.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\VhdMgr.dll_0xfd5a438cc266d5a437d83739046de418.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\VhdMgr.dll_0x118a17088bbcd8a83f66c160eb0fa895.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\VhdMgr.dll_0x118a17088bbcd8a83f66c160eb0fa895.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\UnInstallAb.dll_0x9c30a14ed9fcebcc32854bc9ef557674.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\UnInstallAb.dll_0x9c30a14ed9fcebcc32854bc9ef557674.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\AMBooter.exe_0x2077dc04b4f532cfc930696bfcc46334.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\AMBooter.exe_0x2077dc04b4f532cfc930696bfcc46334.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\LoadDrv_x64.exe\LoadDrv_x64.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\LoadDrv_x64.exe\LoadDrv_x64.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\LoadDrv_Win32.exe\LoadDrv_Win32.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\LoadDrv_Win32.exe\LoadDrv_Win32.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\loaddrv.exe\loaddrv.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\loaddrv.exe\loaddrv.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Help.exe\Help.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Help.exe\Help.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\GptBcd.dll\GptBcd.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\GptBcd.dll\GptBcd.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\exfat.dll\exfat.dll.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\exfat.dll\exfat.dll.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\EPW.exe\EPW.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\EPW.exe\EPW.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\DyndiskConverter.exe\DyndiskConverter.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\DyndiskConverter.exe\DyndiskConverter.exe.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\Microsoft.Windows.OSLoader.BcdBoot.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\Microsoft.Windows.OSLoader.BcdBoot.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0\amd64_Microsoft.Windows.OSLoader.BcdBoot@5.1.0.0.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\Microsoft.VC80.MFC.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\Microsoft.VC80.MFC.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfcm80u.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfcm80u.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfcm80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfcm80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfc80u.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfc80u.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfc80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\mfc80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\amd64_Microsoft.VC80.MFC@8.0.50727.762.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.MFC@8.0.50727.762\amd64_Microsoft.VC80.MFC@8.0.50727.762.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcr80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcr80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcp80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcp80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcm80.dll.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\msvcm80.dll
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\Microsoft.VC80.CRT.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\Microsoft.VC80.CRT.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\amd64_Microsoft.VC80.CRT@8.0.50727.762.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\amd64_Microsoft.VC80.CRT@8.0.50727.762\amd64_Microsoft.VC80.CRT@8.0.50727.762.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\AMBooter.exe\AMBooter.exe.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\AMBooter.exe\AMBooter.exe.manifest
  • from <Current directory>\Data\local\stubexe\0xB5FACA007A65F698\PartAssist.exe.manifest.__tmp__ to <Current directory>\Data\local\stubexe\0xB5FACA007A65F698\PartAssist.exe.manifest
  • from <Current directory>\Data\local\stubexe\0xB5FACA007A65F698\PartAssist.exe.__tmp__ to <Current directory>\Data\local\stubexe\0xB5FACA007A65F698\PartAssist.exe
  • from <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PartAssist.exe.__meta__.__tmp__ to <Current directory>\Data\local\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PartAssist.exe.__meta__
  • from <Current directory>\Data\local\temp\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PartAssist.exe to <Current directory>\Data\local\modified\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\PartAssist.exe
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\AMBooter.exe_0x6918401b4264d601b9ab30603379ebdf.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\AMBooter.exe_0x6918401b4264d601b9ab30603379ebdf.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\bcdboot.exe_0x94294c3d1c41e6207c7e5d0cd0f80b2f.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\bcdboot.exe_0x94294c3d1c41e6207c7e5d0cd0f80b2f.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\bcdboot.exe_0xc78d8faa496f82160d221ef2056fbdec.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\bcdboot.exe_0xc78d8faa496f82160d221ef2056fbdec.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\DyndiskConverter.exe_0x5c272ec6e8f4e87d7c43aa9c205ca161.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\DyndiskConverter.exe_0x5c272ec6e8f4e87d7c43aa9c205ca161.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SSDSecurityErase.dll_0x79bb8e310f8907d1ca8cebdb5b1e1baf.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SSDSecurityErase.dll_0x79bb8e310f8907d1ca8cebdb5b1e1baf.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SetupGreen64.exe_0x786aaa59fc273e0a0d2d6a1b21af2025.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SetupGreen64.exe_0x786aaa59fc273e0a0d2d6a1b21af2025.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SetupGreen32.exe_0xdff084a7451d4d7b1adae34d578d781b.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\SetupGreen32.exe_0xdff084a7451d4d7b1adae34d578d781b.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\ScanPartition.dll_0xc140a0ac3faad2ce2ff4ed121c326ae6.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\ScanPartition.dll_0xc140a0ac3faad2ce2ff4ed121c326ae6.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\ScanPartition.dll_0x56643a64937901fefcdfd64cb5b00a30.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\ScanPartition.dll_0x56643a64937901fefcdfd64cb5b00a30.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PeLoadDrv.exe_0x9c81d885425457a48ea6ff25567fce34.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PeLoadDrv.exe_0x9c81d885425457a48ea6ff25567fce34.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PE.dll_0x52bccfa9738033efe947688920cbf95d.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PE.dll_0x52bccfa9738033efe947688920cbf95d.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PE.dll_0x034e8863d97bddaff9db2a178b6695fc.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PE.dll_0x034e8863d97bddaff9db2a178b6695fc.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PartAssist.exe_0xe551d2bb42dab85de85af6af004868fc.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PartAssist.exe_0xe551d2bb42dab85de85af6af004868fc.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PartAssist.exe_0xb9f64ed8b887e10bc5d80c343500e42d.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\PartAssist.exe_0xb9f64ed8b887e10bc5d80c343500e42d.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Ntfs2Fat32.exe_0x9ff1ce16c26acc103809b0f316105871.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Ntfs2Fat32.exe_0x9ff1ce16c26acc103809b0f316105871.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.MFC.manifest_0x97b859f11538bbe20f17dfb9c0979a1c.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.MFC.manifest_0x97b859f11538bbe20f17dfb9c0979a1c.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.MFC.manifest_0x7dc52d085a05db8a72fed96bb342412b.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.MFC.manifest_0x7dc52d085a05db8a72fed96bb342412b.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.CRT.manifest_0x541423a06efdcd4e4554c719061f82cf.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.CRT.manifest_0x541423a06efdcd4e4554c719061f82cf.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.CRT.manifest_0xa72dde00d763aeef1eb04534f8672967.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Microsoft.VC80.CRT.manifest_0xa72dde00d763aeef1eb04534f8672967.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80u.dll_0xccc2e312486ae6b80970211da472268b.1000.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80u.dll_0xccc2e312486ae6b80970211da472268b.1000.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80u.dll_0x21ee912784a013dc44071ecc4f932388.1000.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80u.dll_0x21ee912784a013dc44071ecc4f932388.1000.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80.dll_0x9173f70af60c0a864eecdfb3342dc789.1000.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80.dll_0x9173f70af60c0a864eecdfb3342dc789.1000.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80.dll_0x1b7524806d0270b81360c63a2fa047cb.1000.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\mfc80.dll_0x1b7524806d0270b81360c63a2fa047cb.1000.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\LoadDrv_x64.exe_0x2266bb132b8318b7d1ced34c58312d35.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\LoadDrv_x64.exe_0x2266bb132b8318b7d1ced34c58312d35.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\LoadDrv_Win32.exe_0x54386df19aa88572e10421917bc8c2f7.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\LoadDrv_Win32.exe_0x54386df19aa88572e10421917bc8c2f7.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\loaddrv.exe_0x54386df19aa88572e10421917bc8c2f7.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\loaddrv.exe_0x54386df19aa88572e10421917bc8c2f7.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Help.exe_0x3d62b7d3079341e59e1c776035e7b3a9.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\Help.exe_0x3d62b7d3079341e59e1c776035e7b3a9.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\GptBcd.dll_0xa21a0a2d9ab42fe8a4b955a06a0bfa90.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\GptBcd.dll_0xa21a0a2d9ab42fe8a4b955a06a0bfa90.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\GptBcd.dll_0x6a20cb2095b0073ec28746629533eda6.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\GptBcd.dll_0x6a20cb2095b0073ec28746629533eda6.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\exfat.dll_0xd071ba1a8bf3165006b0d7ec35e2ed59.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\exfat.dll_0xd071ba1a8bf3165006b0d7ec35e2ed59.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\exfat.dll_0x27ef6b359e11a89d7624bd67d6e94fee.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\exfat.dll_0x27ef6b359e11a89d7624bd67d6e94fee.2.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\EPW.exe_0x26d2617834ec75df62cf6302a2139997.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\EPW.exe_0x26d2617834ec75df62cf6302a2139997.1.manifest
  • from %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\unins000.exe_0x13f2b950b40ed6bb53900c4b0620ec6e.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0x056B6DD7C6D89185\sxs\Manifests\unins000.exe_0x13f2b950b40ed6bb53900c4b0620ec6e.1.manifest
  • from <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\wnd.ini.__meta__.__tmp__ to <Current directory>\Data\roaming\meta\@PROGRAMFILESX86@\AOMEI Partition Assistant Demo Edition 7.5.1\wnd.ini.__meta__
Network activity:
Connects to:
  • 'localhost':1038
  • 'di####artition.com':443
UDP:
  • DNS ASK www.di####artition.com
Miscellaneous:
Creates and executes the following:
  • '<Current directory>\Data\local\stubexe\0xB5FACA007A65F698\PartAssist.exe'
  • '<Current directory>\Data\local\stubexe\0xE0A84939C8975F57\SetupGreen32.exe' -u
  • '<Current directory>\Data\local\stubexe\0x582ABB980551FC15\LoadDrv_Win32.exe' -u
  • '<Current directory>\Data\local\stubexe\0xE0A84939C8975F57\SetupGreen32.exe'
  • '<Current directory>\Data\local\stubexe\0x582ABB980551FC15\LoadDrv_Win32.exe'

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке