Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.DownLoader34.14984

Добавлен в вирусную базу Dr.Web: 2020-08-01

Описание добавлено:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %APPDATA%\microsoft\windows\start menu\programs\startup\6e65fafddbcafa43.lnk
Malicious functions
Creates and executes the following
  • '%TEMP%\584136010000000.exe'
  • '%TEMP%\firefox.exe'
  • '%TEMP%\setup.exe'
  • '%TEMP%\tor.exe'
  • '%APPDATA%\6e65fafddbcafa43\firefox.exe'
  • '%APPDATA%\6e65fafddbcafa43\tor.exe'
Modifies settings of Windows Internet Explorer
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
Modifies file system
Creates the following files
  • %TEMP%\584136010000000.exe
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-environment-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-filesystem-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-heap-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-locale-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-math-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-multibyte-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-private-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-process-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-runtime-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-stdio-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-string-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-time-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-utility-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\aspnetsetup.log
  • %APPDATA%\6e65fafddbcafa43\aspnetsetup_00000.log
  • %APPDATA%\6e65fafddbcafa43\aspnetsetup_00001.log
  • %APPDATA%\6e65fafddbcafa43\data.dll
  • %APPDATA%\6e65fafddbcafa43\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt
  • %APPDATA%\6e65fafddbcafa43\dd_setuputility.txt
  • %APPDATA%\6e65fafddbcafa43\dd_vcredist_amd64_20151216210341.log
  • %APPDATA%\6e65fafddbcafa43\dd_vcredist_amd64_20151216210341_000_vcruntimeminimum_x64.log
  • %APPDATA%\6e65fafddbcafa43\dd_vcredist_amd64_20151216210341_001_vcruntimeadditional_x64.log
  • %APPDATA%\6e65fafddbcafa43\dd_vcredist_x86_20151216210157.log
  • %APPDATA%\6e65fafddbcafa43\dd_vcredist_x86_20151216210157_000_vcruntimeminimum_x86.log
  • %APPDATA%\6e65fafddbcafa43\dd_vcredist_x86_20151216210157_001_vcruntimeadditional_x86.log
  • %APPDATA%\6e65fafddbcafa43\dd_wcf_ca_smci_20151217_052858_840.txt
  • %APPDATA%\6e65fafddbcafa43\dd_wcf_ca_smci_20151217_052908_497.txt
  • %APPDATA%\6e65fafddbcafa43\dependentlibs.list
  • %APPDATA%\6e65fafddbcafa43\dotnetfx.log
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-convert-l1-1-0.dll
  • C:\msdownld.tmp\as116afc.tmp\setup.exe
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-crt-conio-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-timezone-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\584136010000000.exe
  • %APPDATA%\6e65fafddbcafa43\adobearm.log
  • %APPDATA%\6e65fafddbcafa43\adobearm_notlocked.log
  • %APPDATA%\6e65fafddbcafa43\adobesfx.log
  • %APPDATA%\6e65fafddbcafa43\adobe_admlogs\adobe_adm.log
  • %APPDATA%\6e65fafddbcafa43\adobe_admlogs\adobe_gde.log
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-console-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-datetime-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-debug-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-errorhandling-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-file-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-file-l1-2-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-file-l2-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-handle-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-heap-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-interlocked-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-libraryloader-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-localization-l1-2-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-memory-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-namedpipe-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-processenvironment-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-processthreads-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-processthreads-l1-1-1.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-profile-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-string-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-synch-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-synch-l1-2-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-sysinfo-l1-1-0.dll
  • %APPDATA%\6e65fafddbcafa43\api-ms-win-core-util-l1-1-0.dll
  • %TEMP%\setup.exe
  • %APPDATA%\6e65fafddbcafa43\dotnetfxsdk.log
  • %APPDATA%\6e65fafddbcafa43\javadeployreg.log
  • %APPDATA%\6e65fafddbcafa43\ose00000.exe
  • %APPDATA%\6e65fafddbcafa43\ose00001.exe
  • %APPDATA%\6e65fafddbcafa43\rgie195.tmp
  • %APPDATA%\6e65fafddbcafa43\rgie195.tmp-tmp
  • %APPDATA%\6e65fafddbcafa43\setup.exe
  • %APPDATA%\6e65fafddbcafa43\setupexe(20151124155624744).log
  • %APPDATA%\6e65fafddbcafa43\setupexe(201603101200226dc).log
  • %APPDATA%\6e65fafddbcafa43\setupexe(20160310140634718).log
  • %APPDATA%\6e65fafddbcafa43\ssleay32.dll
  • %APPDATA%\6e65fafddbcafa43\temp1_fp_13.0.0.182_archive.zip\fp_13.0.0.182_archive\13_0_r0_182\flashplayer13_0r0_182_winax.msi
  • %APPDATA%\6e65fafddbcafa43\tor-gencert.exe
  • %APPDATA%\6e65fafddbcafa43\tor.exe
  • %APPDATA%\6e65fafddbcafa43\ucrtbase.dll
  • %TEMP%\data.dll
  • %APPDATA%\6e65fafddbcafa43\user.bmp
  • %APPDATA%\6e65fafddbcafa43\wallpaper.bmp
  • %APPDATA%\6e65fafddbcafa43\webinstaller\qnzuposrqouvfisa\data.txt
  • %APPDATA%\6e65fafddbcafa43\webinstaller\qnzuposrqouvfisa\variant.js
  • %APPDATA%\6e65fafddbcafa43\wmsetup.log
  • %APPDATA%\6e65fafddbcafa43\zlib1.dll
  • %APPDATA%\6e65fafddbcafa43\~df03f0cd284be82d49.tmp
  • %APPDATA%\6e65fafddbcafa43\~df3f6c09d43bbc2ea6.tmp
  • %APPDATA%\6e65fafddbcafa43\~df5e9e9f0b94031a26.tmp
  • %APPDATA%\6e65fafddbcafa43\~df65fa1b97d160ee57.tmp
  • %APPDATA%\6e65fafddbcafa43\~df78de7c8507ecb9c5.tmp
  • %APPDATA%\6e65fafddbcafa43\~df7e0cf45c7cfd96c4.tmp
  • %APPDATA%\6e65fafddbcafa43\~df927034dfcac76d1e.tmp
  • %APPDATA%\6e65fafddbcafa43\~dfbe170db43b112bc3.tmp
  • %APPDATA%\6e65fafddbcafa43\opera installer\opera_installer_20150506170843.log
  • %APPDATA%\6e65fafddbcafa43\opera installer\opera_installer_20150506170857.log
  • %APPDATA%\6e65fafddbcafa43\etilqs_jpnsmjbsc4hhfs9
  • %APPDATA%\6e65fafddbcafa43\etilqs_1bbgbhjgpccy6cr
  • %APPDATA%\6e65fafddbcafa43\msvcp140.dll
  • %APPDATA%\6e65fafddbcafa43\jawshtml.html
  • %APPDATA%\6e65fafddbcafa43\jusched.log
  • %APPDATA%\6e65fafddbcafa43\libcrypto-1_1.dll
  • %APPDATA%\6e65fafddbcafa43\libeay32.dll
  • %APPDATA%\6e65fafddbcafa43\libevent-2-0-5.dll
  • %APPDATA%\6e65fafddbcafa43\libevent-2-1-7.dll
  • %APPDATA%\6e65fafddbcafa43\libevent_core-2-0-5.dll
  • %APPDATA%\6e65fafddbcafa43\libevent_core-2-1-7.dll
  • %APPDATA%\6e65fafddbcafa43\libevent_extra-2-0-5.dll
  • %APPDATA%\6e65fafddbcafa43\libevent_extra-2-1-7.dll
  • %APPDATA%\6e65fafddbcafa43\libgcc_s_sjlj-1.dll
  • %APPDATA%\6e65fafddbcafa43\libgmp-10.dll
  • %APPDATA%\6e65fafddbcafa43\libssl-1_1.dll
  • %APPDATA%\6e65fafddbcafa43\libssp-0.dll
  • %APPDATA%\6e65fafddbcafa43\libwinpthread-1.dll
  • %APPDATA%\6e65fafddbcafa43\microsoft .net framework 4.5 setup_20150506_155317844.html
  • %APPDATA%\6e65fafddbcafa43\microsoft .net framework 4.5.2 setup_20151216_212237215-msi_netfx_full_gdr_x64.msi.txt
  • %APPDATA%\6e65fafddbcafa43\microsoft .net framework 4.5.2 setup_20151216_212237215.html
  • %APPDATA%\6e65fafddbcafa43\microsoft visual c++ 2010 x86 redistributable setup_20150506_155226438.html
  • %APPDATA%\6e65fafddbcafa43\mirc741.exe
  • %APPDATA%\6e65fafddbcafa43\mozglue.dll
  • %APPDATA%\6e65fafddbcafa43\msi1cfbe.log
  • %APPDATA%\6e65fafddbcafa43\msic204f.log
  • %APPDATA%\6e65fafddbcafa43\msid38c.log
  • %APPDATA%\6e65fafddbcafa43\msie45bf.log
  • %APPDATA%\6e65fafddbcafa43\msieb217.log
  • %APPDATA%\6e65fafddbcafa43\msvcp110.dll
  • %APPDATA%\6e65fafddbcafa43\msvcr110.dll
  • %APPDATA%\6e65fafddbcafa43\firefox.exe
  • %APPDATA%\6e65fafddbcafa43\opera installer\opera_installer_20150506170826.log
  • %TEMP%\zlib1.dll
  • C:\msdownld.tmp\as1169f2.tmp\zlib1.dll
  • %TEMP%\vcruntime140.dll
  • C:\msdownld.tmp\as10b21b.tmp\api-ms-win-core-profile-l1-1-0.dll
  • %TEMP%\api-ms-win-core-profile-l1-1-0.dll
  • C:\msdownld.tmp\as10b41f.tmp\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %TEMP%\api-ms-win-core-rtlsupport-l1-1-0.dll
  • C:\msdownld.tmp\as10b529.tmp\api-ms-win-core-string-l1-1-0.dll
  • %TEMP%\api-ms-win-core-string-l1-1-0.dll
  • C:\msdownld.tmp\as10b623.tmp\api-ms-win-core-synch-l1-1-0.dll
  • %TEMP%\api-ms-win-core-synch-l1-1-0.dll
  • C:\msdownld.tmp\as10b71d.tmp\api-ms-win-core-synch-l1-2-0.dll
  • %TEMP%\api-ms-win-core-synch-l1-2-0.dll
  • C:\msdownld.tmp\as10b846.tmp\api-ms-win-core-sysinfo-l1-1-0.dll
  • %TEMP%\api-ms-win-core-sysinfo-l1-1-0.dll
  • C:\msdownld.tmp\as10b940.tmp\api-ms-win-core-timezone-l1-1-0.dll
  • %TEMP%\api-ms-win-core-timezone-l1-1-0.dll
  • C:\msdownld.tmp\as10ba49.tmp\api-ms-win-core-util-l1-1-0.dll
  • %TEMP%\api-ms-win-core-util-l1-1-0.dll
  • C:\msdownld.tmp\as10bb62.tmp\api-ms-win-crt-conio-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-conio-l1-1-0.dll
  • C:\msdownld.tmp\as10bc5c.tmp\api-ms-win-crt-convert-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-convert-l1-1-0.dll
  • C:\msdownld.tmp\as10bd66.tmp\api-ms-win-crt-environment-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-environment-l1-1-0.dll
  • C:\msdownld.tmp\as10be7f.tmp\api-ms-win-crt-filesystem-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-filesystem-l1-1-0.dll
  • C:\msdownld.tmp\as10bf89.tmp\api-ms-win-crt-heap-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-heap-l1-1-0.dll
  • C:\msdownld.tmp\as10c093.tmp\api-ms-win-crt-locale-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-locale-l1-1-0.dll
  • C:\msdownld.tmp\as10b102.tmp\api-ms-win-core-processthreads-l1-1-1.dll
  • C:\msdownld.tmp\as10c18d.tmp\api-ms-win-crt-math-l1-1-0.dll
  • %TEMP%\api-ms-win-core-processthreads-l1-1-0.dll
  • %TEMP%\api-ms-win-core-processenvironment-l1-1-0.dll
  • C:\msdownld.tmp\as106042.tmp\api-ms-win-core-console-l1-1-0.dll
  • %TEMP%\api-ms-win-core-console-l1-1-0.dll
  • C:\msdownld.tmp\as109fdc.tmp\api-ms-win-core-datetime-l1-1-0.dll
  • %TEMP%\api-ms-win-core-datetime-l1-1-0.dll
  • C:\msdownld.tmp\as10a28b.tmp\api-ms-win-core-debug-l1-1-0.dll
  • %TEMP%\api-ms-win-core-debug-l1-1-0.dll
  • C:\msdownld.tmp\as10a3b4.tmp\api-ms-win-core-errorhandling-l1-1-0.dll
  • %TEMP%\api-ms-win-core-errorhandling-l1-1-0.dll
  • C:\msdownld.tmp\as10a4ae.tmp\api-ms-win-core-file-l1-1-0.dll
  • %TEMP%\api-ms-win-core-file-l1-1-0.dll
  • C:\msdownld.tmp\as10a5c7.tmp\api-ms-win-core-file-l1-2-0.dll
  • %TEMP%\api-ms-win-core-file-l1-2-0.dll
  • C:\msdownld.tmp\as10a6d1.tmp\api-ms-win-core-file-l2-1-0.dll
  • %TEMP%\api-ms-win-core-file-l2-1-0.dll
  • C:\msdownld.tmp\as10a7da.tmp\api-ms-win-core-handle-l1-1-0.dll
  • %TEMP%\api-ms-win-core-handle-l1-1-0.dll
  • C:\msdownld.tmp\as10a8d4.tmp\api-ms-win-core-heap-l1-1-0.dll
  • %TEMP%\api-ms-win-core-heap-l1-1-0.dll
  • C:\msdownld.tmp\as10a9de.tmp\api-ms-win-core-interlocked-l1-1-0.dll
  • %TEMP%\api-ms-win-core-interlocked-l1-1-0.dll
  • C:\msdownld.tmp\as10aae8.tmp\api-ms-win-core-libraryloader-l1-1-0.dll
  • %TEMP%\api-ms-win-core-libraryloader-l1-1-0.dll
  • C:\msdownld.tmp\as10abe2.tmp\api-ms-win-core-localization-l1-2-0.dll
  • %TEMP%\api-ms-win-core-localization-l1-2-0.dll
  • C:\msdownld.tmp\as10aceb.tmp\api-ms-win-core-memory-l1-1-0.dll
  • %TEMP%\api-ms-win-core-memory-l1-1-0.dll
  • C:\msdownld.tmp\as10adf5.tmp\api-ms-win-core-namedpipe-l1-1-0.dll
  • %TEMP%\api-ms-win-core-namedpipe-l1-1-0.dll
  • C:\msdownld.tmp\as10aeef.tmp\api-ms-win-core-processenvironment-l1-1-0.dll
  • C:\msdownld.tmp\as10afe9.tmp\api-ms-win-core-processthreads-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-math-l1-1-0.dll
  • %TEMP%\api-ms-win-core-processthreads-l1-1-1.dll
  • C:\msdownld.tmp\as10c296.tmp\api-ms-win-crt-multibyte-l1-1-0.dll
  • C:\msdownld.tmp\as11318c.tmp\libevent_extra-2-1-7.dll
  • C:\msdownld.tmp\as11344c.tmp\libgcc_s_sjlj-1.dll
  • %TEMP%\libgcc_s_sjlj-1.dll
  • C:\msdownld.tmp\as1138ff.tmp\libgmp-10.dll
  • %TEMP%\libgmp-10.dll
  • C:\msdownld.tmp\as113cd7.tmp\libssl-1_1.dll
  • %TEMP%\libssl-1_1.dll
  • C:\msdownld.tmp\as1140a0.tmp\libssp-0.dll
  • %TEMP%\libssp-0.dll
  • C:\msdownld.tmp\as114265.tmp\libwinpthread-1.dll
  • %TEMP%\libwinpthread-1.dll
  • C:\msdownld.tmp\as114553.tmp\mozglue.dll
  • %TEMP%\mozglue.dll
  • C:\msdownld.tmp\as11468b.tmp\msvcp110.dll
  • %TEMP%\msvcp110.dll
  • C:\msdownld.tmp\as114979.tmp\msvcp140.dll
  • %TEMP%\msvcp140.dll
  • C:\msdownld.tmp\as114b8d.tmp\msvcr110.dll
  • %TEMP%\msvcr110.dll
  • C:\msdownld.tmp\as114f55.tmp\ssleay32.dll
  • %TEMP%\ssleay32.dll
  • C:\msdownld.tmp\as115253.tmp\tor-gencert.exe
  • %TEMP%\tor-gencert.exe
  • C:\msdownld.tmp\as11562b.tmp\tor.exe
  • %TEMP%\tor.exe
  • C:\msdownld.tmp\as116493.tmp\ucrtbase.dll
  • %TEMP%\ucrtbase.dll
  • C:\msdownld.tmp\as1168aa.tmp\vcruntime140.dll
  • %TEMP%\libevent_extra-2-0-5.dll
  • %TEMP%\libevent_core-2-1-7.dll
  • %TEMP%\libevent_extra-2-1-7.dll
  • C:\msdownld.tmp\as112f79.tmp\libevent_extra-2-0-5.dll
  • C:\msdownld.tmp\as112c6c.tmp\libevent_core-2-1-7.dll
  • %TEMP%\api-ms-win-crt-multibyte-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-private-l1-1-0.dll
  • C:\msdownld.tmp\as10c65f.tmp\api-ms-win-crt-process-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-process-l1-1-0.dll
  • C:\msdownld.tmp\as10c769.tmp\api-ms-win-crt-runtime-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-runtime-l1-1-0.dll
  • C:\msdownld.tmp\as10c882.tmp\api-ms-win-crt-stdio-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-stdio-l1-1-0.dll
  • C:\msdownld.tmp\as10c98b.tmp\api-ms-win-crt-string-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-string-l1-1-0.dll
  • C:\msdownld.tmp\as10ca95.tmp\api-ms-win-crt-time-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-time-l1-1-0.dll
  • C:\msdownld.tmp\as10cb9f.tmp\api-ms-win-crt-utility-l1-1-0.dll
  • %TEMP%\api-ms-win-crt-utility-l1-1-0.dll
  • %TEMP%\6e65fafddbcafa43
  • %APPDATA%\6e65fafddbcafa43\vcruntime140.dll
  • C:\msdownld.tmp\as10cca8.tmp\data.dll
  • %TEMP%\dependentlibs.list
  • C:\msdownld.tmp\as10d1f8.tmp\firefox.exe
  • %TEMP%\firefox.exe
  • C:\msdownld.tmp\as1106b4.tmp\libcrypto-1_1.dll
  • %TEMP%\libcrypto-1_1.dll
  • C:\msdownld.tmp\as11176d.tmp\libeay32.dll
  • %TEMP%\libeay32.dll
  • C:\msdownld.tmp\as112383.tmp\libevent-2-0-5.dll
  • %TEMP%\libevent-2-0-5.dll
  • C:\msdownld.tmp\as1126a0.tmp\libevent-2-1-7.dll
  • %TEMP%\libevent-2-1-7.dll
  • C:\msdownld.tmp\as112a68.tmp\libevent_core-2-0-5.dll
  • %TEMP%\libevent_core-2-0-5.dll
  • C:\msdownld.tmp\as10c3bf.tmp\api-ms-win-crt-private-l1-1-0.dll
  • C:\msdownld.tmp\as10d0de.tmp\dependentlibs.list
  • %APPDATA%\tor\state.tmp
Deletes the following files
  • C:\msdownld.tmp\as106042.tmp\api-ms-win-core-console-l1-1-0.dll
  • C:\msdownld.tmp\as10c769.tmp\api-ms-win-crt-runtime-l1-1-0.dll
  • C:\msdownld.tmp\as10c882.tmp\api-ms-win-crt-stdio-l1-1-0.dll
  • C:\msdownld.tmp\as10c98b.tmp\api-ms-win-crt-string-l1-1-0.dll
  • C:\msdownld.tmp\as10ca95.tmp\api-ms-win-crt-time-l1-1-0.dll
  • C:\msdownld.tmp\as10cb9f.tmp\api-ms-win-crt-utility-l1-1-0.dll
  • C:\msdownld.tmp\as10cca8.tmp\data.dll
  • C:\msdownld.tmp\as10d0de.tmp\dependentlibs.list
  • C:\msdownld.tmp\as10d1f8.tmp\firefox.exe
  • C:\msdownld.tmp\as1106b4.tmp\libcrypto-1_1.dll
  • C:\msdownld.tmp\as11176d.tmp\libeay32.dll
  • C:\msdownld.tmp\as112383.tmp\libevent-2-0-5.dll
  • C:\msdownld.tmp\as1126a0.tmp\libevent-2-1-7.dll
  • C:\msdownld.tmp\as112a68.tmp\libevent_core-2-0-5.dll
  • C:\msdownld.tmp\as112c6c.tmp\libevent_core-2-1-7.dll
  • C:\msdownld.tmp\as11318c.tmp\libevent_extra-2-1-7.dll
  • C:\msdownld.tmp\as1169f2.tmp\zlib1.dll
  • C:\msdownld.tmp\as11344c.tmp\libgcc_s_sjlj-1.dll
  • C:\msdownld.tmp\as1138ff.tmp\libgmp-10.dll
  • C:\msdownld.tmp\as113cd7.tmp\libssl-1_1.dll
  • C:\msdownld.tmp\as1140a0.tmp\libssp-0.dll
  • C:\msdownld.tmp\as114265.tmp\libwinpthread-1.dll
  • C:\msdownld.tmp\as114553.tmp\mozglue.dll
  • C:\msdownld.tmp\as11468b.tmp\msvcp110.dll
  • C:\msdownld.tmp\as114979.tmp\msvcp140.dll
  • C:\msdownld.tmp\as114b8d.tmp\msvcr110.dll
  • C:\msdownld.tmp\as114f55.tmp\ssleay32.dll
  • C:\msdownld.tmp\as115253.tmp\tor-gencert.exe
  • C:\msdownld.tmp\as11562b.tmp\tor.exe
  • C:\msdownld.tmp\as116493.tmp\ucrtbase.dll
  • C:\msdownld.tmp\as1168aa.tmp\vcruntime140.dll
  • C:\msdownld.tmp\as10c65f.tmp\api-ms-win-crt-process-l1-1-0.dll
  • C:\msdownld.tmp\as112f79.tmp\libevent_extra-2-0-5.dll
  • C:\msdownld.tmp\as10c3bf.tmp\api-ms-win-crt-private-l1-1-0.dll
  • C:\msdownld.tmp\as10afe9.tmp\api-ms-win-core-processthreads-l1-1-0.dll
  • C:\msdownld.tmp\as109fdc.tmp\api-ms-win-core-datetime-l1-1-0.dll
  • C:\msdownld.tmp\as10a28b.tmp\api-ms-win-core-debug-l1-1-0.dll
  • C:\msdownld.tmp\as10a3b4.tmp\api-ms-win-core-errorhandling-l1-1-0.dll
  • C:\msdownld.tmp\as10a4ae.tmp\api-ms-win-core-file-l1-1-0.dll
  • C:\msdownld.tmp\as10a5c7.tmp\api-ms-win-core-file-l1-2-0.dll
  • C:\msdownld.tmp\as10a6d1.tmp\api-ms-win-core-file-l2-1-0.dll
  • C:\msdownld.tmp\as10a7da.tmp\api-ms-win-core-handle-l1-1-0.dll
  • C:\msdownld.tmp\as10a8d4.tmp\api-ms-win-core-heap-l1-1-0.dll
  • C:\msdownld.tmp\as10a9de.tmp\api-ms-win-core-interlocked-l1-1-0.dll
  • C:\msdownld.tmp\as10aae8.tmp\api-ms-win-core-libraryloader-l1-1-0.dll
  • C:\msdownld.tmp\as10abe2.tmp\api-ms-win-core-localization-l1-2-0.dll
  • C:\msdownld.tmp\as10aceb.tmp\api-ms-win-core-memory-l1-1-0.dll
  • C:\msdownld.tmp\as10adf5.tmp\api-ms-win-core-namedpipe-l1-1-0.dll
  • C:\msdownld.tmp\as10aeef.tmp\api-ms-win-core-processenvironment-l1-1-0.dll
  • C:\msdownld.tmp\as10b102.tmp\api-ms-win-core-processthreads-l1-1-1.dll
  • C:\msdownld.tmp\as10c18d.tmp\api-ms-win-crt-math-l1-1-0.dll
  • C:\msdownld.tmp\as10b21b.tmp\api-ms-win-core-profile-l1-1-0.dll
  • C:\msdownld.tmp\as10b41f.tmp\api-ms-win-core-rtlsupport-l1-1-0.dll
  • C:\msdownld.tmp\as10b529.tmp\api-ms-win-core-string-l1-1-0.dll
  • C:\msdownld.tmp\as10b623.tmp\api-ms-win-core-synch-l1-1-0.dll
  • C:\msdownld.tmp\as10b71d.tmp\api-ms-win-core-synch-l1-2-0.dll
  • C:\msdownld.tmp\as10b846.tmp\api-ms-win-core-sysinfo-l1-1-0.dll
  • C:\msdownld.tmp\as10b940.tmp\api-ms-win-core-timezone-l1-1-0.dll
  • C:\msdownld.tmp\as10ba49.tmp\api-ms-win-core-util-l1-1-0.dll
  • C:\msdownld.tmp\as10bb62.tmp\api-ms-win-crt-conio-l1-1-0.dll
  • C:\msdownld.tmp\as10bc5c.tmp\api-ms-win-crt-convert-l1-1-0.dll
  • C:\msdownld.tmp\as10bd66.tmp\api-ms-win-crt-environment-l1-1-0.dll
  • C:\msdownld.tmp\as10be7f.tmp\api-ms-win-crt-filesystem-l1-1-0.dll
  • C:\msdownld.tmp\as10bf89.tmp\api-ms-win-crt-heap-l1-1-0.dll
  • C:\msdownld.tmp\as10c093.tmp\api-ms-win-crt-locale-l1-1-0.dll
  • C:\msdownld.tmp\as10c296.tmp\api-ms-win-crt-multibyte-l1-1-0.dll
  • C:\msdownld.tmp\as116afc.tmp\setup.exe
Moves the following files
  • from %APPDATA%\tor\state.tmp to %APPDATA%\tor\state
Network activity
TCP
HTTP GET requests
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-console-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-stdio-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-string-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-time-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-utility-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/data.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/dependentlibs.list
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/firefox.exe
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libcrypto-1_1.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libeay32.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libevent-2-0-5.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libevent-2-1-7.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libevent_core-2-0-5.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libevent_core-2-1-7.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libevent_extra-2-0-5.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libevent_extra-2-1-7.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libgcc_s_sjlj-1.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libgmp-10.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/setup.exe
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/zlib1.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/vcruntime140.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/ucrtbase.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/tor.exe
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/tor-gencert.exe
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/msvcr110.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/ssleay32.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/msvcp140.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/msvcp110.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/mozglue.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libwinpthread-1.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libssp-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/libssl-1_1.dll
  • http://bl###iya.com/cert.txt
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-runtime-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-process-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-private-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-datetime-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-debug-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-errorhandling-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-file-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-file-l1-2-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-file-l2-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-handle-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-heap-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-interlocked-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-libraryloader-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-localization-l1-2-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-memory-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-namedpipe-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-processenvironment-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-processthreads-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-processthreads-l1-1-1.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-profile-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-math-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-locale-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-heap-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-filesystem-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-environment-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-convert-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-util-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-conio-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-timezone-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-sysinfo-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-synch-l1-2-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-synch-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-string-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-core-rtlsupport-l1-1-0.dll
  • http://19#.#87.30.38/~bodyzwellness/wp-admin/network/bin/bin/api-ms-win-crt-multibyte-l1-1-0.dll
  • http://bl###iya.com/t/cer.p7b
  • '19#.#7.28.82':9001
  • UDP
    • DNS ASK bl###iya.com
    Miscellaneous
    Searches for the following windows
    • ClassName: 'MS_AutodialMonitor' WindowName: ''
    • ClassName: 'MS_WebcheckMonitor' WindowName: ''
    • ClassName: '' WindowName: 'Security Warning'
    • ClassName: '' WindowName: 'avertissement de sГ©curitГ©'
    Executes the following
    • '<SYSTEM32>\wscript.exe' "<PATH_SAMPLE>.js" /elevate

    Рекомендации по лечению

    1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
    2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
    Скачать Dr.Web

    По серийному номеру

    Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

    На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

    Скачать Dr.Web

    По серийному номеру

    1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
    2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
      • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
      • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
      • выключите устройство и включите его в обычном режиме.

    Подробнее о Dr.Web для Android

    Демо бесплатно на 14 дней

    Выдаётся при установке