Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Click2.42520

Добавлен в вирусную базу Dr.Web: 2012-11-10

Описание добавлено:

Техническая информация

Вредоносные функции:
Создает и запускает на исполнение:
  • %PROGRAM_FILES%\soft050903\wl06079.exe
  • %PROGRAM_FILES%\kws\Cookies.exe
  • %PROGRAM_FILES%\soft050903\wl06079.exe (загружен из сети Интернет)
Запускает на исполнение:
  • <SYSTEM32>\reg.exe add "HKCU\Software\VB and VBA Program Settings\baifen" /v "" /d "http://www.q7##7.com/" /f
  • <SYSTEM32>\taskkill.exe /f /im explorer.exe
  • %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://ta##rl.com/4iklm
  • <SYSTEM32>\ntvdm.exe -f -i1
  • %WINDIR%\explorer.exe
  • <SYSTEM32>\ntvdm.exe -f
  • <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\soft050903\300.bat" "
  • <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\soft050903\b_0503.vbe"
  • %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.17##g.com/lianjie/10608.htm
  • <SYSTEM32>\attrib.exe +s +h "<Имя диска съемного носителя>:\Mozilla"
  • %WINDIR%\regedit.exe /s 300.reg
  • <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\soft050903\encrypt.bat" "
Завершает или пытается завершить
следующие системные процессы:
  • %WINDIR%\Explorer.EXE
Изменения в файловой системе:
Создает следующие файлы:
  • C:\60.DLL
  • %WINDIR%\Temp\scs57.tmp
  • C:\61.DLL
  • %WINDIR%\Temp\scs55.tmp
  • C:\59.DLL
  • %WINDIR%\Temp\scs56.tmp
  • %WINDIR%\Temp\scs58.tmp
  • %WINDIR%\Temp\scs5A.tmp
  • C:\64.DLL
  • %WINDIR%\Temp\scs5B.tmp
  • C:\62.DLL
  • %WINDIR%\Temp\scs59.tmp
  • C:\63.DLL
  • C:\58.DLL
  • C:\53.DLL
  • %WINDIR%\Temp\scs50.tmp
  • C:\54.DLL
  • %WINDIR%\Temp\scs4E.tmp
  • C:\52.DLL
  • %WINDIR%\Temp\scs4F.tmp
  • %WINDIR%\Temp\scs51.tmp
  • %WINDIR%\Temp\scs53.tmp
  • C:\57.DLL
  • %WINDIR%\Temp\scs54.tmp
  • C:\55.DLL
  • %WINDIR%\Temp\scs52.tmp
  • C:\56.DLL
  • %WINDIR%\Temp\scs64.tmp
  • C:\74.DLL
  • %WINDIR%\Temp\scs65.tmp
  • C:\72.DLL
  • %WINDIR%\Temp\scs63.tmp
  • C:\73.DLL
  • C:\75.DLL
  • C:\77.DLL
  • %WINDIR%\Temp\scs68.tmp
  • C:\78.DLL
  • %WINDIR%\Temp\scs66.tmp
  • C:\76.DLL
  • %WINDIR%\Temp\scs67.tmp
  • %WINDIR%\Temp\scs62.tmp
  • %WINDIR%\Temp\scs5D.tmp
  • C:\67.DLL
  • %WINDIR%\Temp\scs5E.tmp
  • C:\65.DLL
  • %WINDIR%\Temp\scs5C.tmp
  • C:\66.DLL
  • C:\68.DLL
  • C:\70.DLL
  • %WINDIR%\Temp\scs61.tmp
  • C:\71.DLL
  • %WINDIR%\Temp\scs5F.tmp
  • C:\69.DLL
  • %WINDIR%\Temp\scs60.tmp
  • C:\33.DLL
  • %WINDIR%\Temp\scs3C.tmp
  • C:\34.DLL
  • %WINDIR%\Temp\scs3A.tmp
  • C:\32.DLL
  • %WINDIR%\Temp\scs3B.tmp
  • %WINDIR%\Temp\scs3D.tmp
  • %WINDIR%\Temp\scs3F.tmp
  • C:\37.DLL
  • %WINDIR%\Temp\scs40.tmp
  • C:\35.DLL
  • %WINDIR%\Temp\scs3E.tmp
  • C:\36.DLL
  • C:\31.DLL
  • C:\26.DLL
  • %WINDIR%\Temp\scs35.tmp
  • C:\27.DLL
  • %WINDIR%\Temp\scs33.tmp
  • C:\25.DLL
  • %WINDIR%\Temp\scs34.tmp
  • %WINDIR%\Temp\scs36.tmp
  • %WINDIR%\Temp\scs38.tmp
  • C:\30.DLL
  • %WINDIR%\Temp\scs39.tmp
  • C:\28.DLL
  • %WINDIR%\Temp\scs37.tmp
  • C:\29.DLL
  • %WINDIR%\Temp\scs49.tmp
  • C:\47.DLL
  • %WINDIR%\Temp\scs4A.tmp
  • C:\45.DLL
  • %WINDIR%\Temp\scs48.tmp
  • C:\46.DLL
  • C:\48.DLL
  • C:\50.DLL
  • %WINDIR%\Temp\scs4D.tmp
  • C:\51.DLL
  • %WINDIR%\Temp\scs4B.tmp
  • C:\49.DLL
  • %WINDIR%\Temp\scs4C.tmp
  • %WINDIR%\Temp\scs47.tmp
  • %WINDIR%\Temp\scs42.tmp
  • C:\40.DLL
  • %WINDIR%\Temp\scs43.tmp
  • C:\38.DLL
  • %WINDIR%\Temp\scs41.tmp
  • C:\39.DLL
  • C:\41.DLL
  • C:\43.DLL
  • %WINDIR%\Temp\scs46.tmp
  • C:\44.DLL
  • %WINDIR%\Temp\scs44.tmp
  • C:\42.DLL
  • %WINDIR%\Temp\scs45.tmp
  • C:\114.DLL
  • %WINDIR%\Temp\scs8D.tmp
  • C:\115.DLL
  • %WINDIR%\Temp\scs8B.tmp
  • C:\113.DLL
  • %WINDIR%\Temp\scs8C.tmp
  • %WINDIR%\Temp\scs8E.tmp
  • %WINDIR%\Temp\scs90.tmp
  • C:\118.DLL
  • %WINDIR%\Temp\scs91.tmp
  • C:\116.DLL
  • %WINDIR%\Temp\scs8F.tmp
  • C:\117.DLL
  • C:\112.DLL
  • C:\107.DLL
  • %WINDIR%\Temp\scs86.tmp
  • C:\108.DLL
  • %WINDIR%\Temp\scs84.tmp
  • C:\106.DLL
  • %WINDIR%\Temp\scs85.tmp
  • %WINDIR%\Temp\scs87.tmp
  • %WINDIR%\Temp\scs89.tmp
  • C:\111.DLL
  • %WINDIR%\Temp\scs8A.tmp
  • C:\109.DLL
  • %WINDIR%\Temp\scs88.tmp
  • C:\110.DLL
  • %WINDIR%\Temp\scs9A.tmp
  • C:\128.DLL
  • %WINDIR%\Temp\scs9B.tmp
  • C:\126.DLL
  • %WINDIR%\Temp\scs99.tmp
  • C:\127.DLL
  • C:\129.DLL
  • C:\131.DLL
  • %WINDIR%\Temp\scs9E.tmp
  • C:\132.DLL
  • %WINDIR%\Temp\scs9C.tmp
  • C:\130.DLL
  • %WINDIR%\Temp\scs9D.tmp
  • %WINDIR%\Temp\scs98.tmp
  • %WINDIR%\Temp\scs93.tmp
  • C:\121.DLL
  • %WINDIR%\Temp\scs94.tmp
  • C:\119.DLL
  • %WINDIR%\Temp\scs92.tmp
  • C:\120.DLL
  • C:\122.DLL
  • C:\124.DLL
  • %WINDIR%\Temp\scs97.tmp
  • C:\125.DLL
  • %WINDIR%\Temp\scs95.tmp
  • C:\123.DLL
  • %WINDIR%\Temp\scs96.tmp
  • C:\87.DLL
  • %WINDIR%\Temp\scs72.tmp
  • C:\88.DLL
  • %WINDIR%\Temp\scs70.tmp
  • C:\86.DLL
  • %WINDIR%\Temp\scs71.tmp
  • %WINDIR%\Temp\scs73.tmp
  • %WINDIR%\Temp\scs75.tmp
  • C:\91.DLL
  • %WINDIR%\Temp\scs76.tmp
  • C:\89.DLL
  • %WINDIR%\Temp\scs74.tmp
  • C:\90.DLL
  • C:\85.DLL
  • C:\80.DLL
  • %WINDIR%\Temp\scs6B.tmp
  • C:\81.DLL
  • %WINDIR%\Temp\scs69.tmp
  • C:\79.DLL
  • %WINDIR%\Temp\scs6A.tmp
  • %WINDIR%\Temp\scs6C.tmp
  • %WINDIR%\Temp\scs6E.tmp
  • C:\84.DLL
  • %WINDIR%\Temp\scs6F.tmp
  • C:\82.DLL
  • %WINDIR%\Temp\scs6D.tmp
  • C:\83.DLL
  • %WINDIR%\Temp\scs7F.tmp
  • C:\101.DLL
  • %WINDIR%\Temp\scs80.tmp
  • C:\99.DLL
  • %WINDIR%\Temp\scs7E.tmp
  • C:\100.DLL
  • C:\102.DLL
  • C:\104.DLL
  • %WINDIR%\Temp\scs83.tmp
  • C:\105.DLL
  • %WINDIR%\Temp\scs81.tmp
  • C:\103.DLL
  • %WINDIR%\Temp\scs82.tmp
  • %WINDIR%\Temp\scs7D.tmp
  • %WINDIR%\Temp\scs78.tmp
  • C:\94.DLL
  • %WINDIR%\Temp\scs79.tmp
  • C:\92.DLL
  • %WINDIR%\Temp\scs77.tmp
  • C:\93.DLL
  • C:\95.DLL
  • C:\97.DLL
  • %WINDIR%\Temp\scs7C.tmp
  • C:\98.DLL
  • %WINDIR%\Temp\scs7A.tmp
  • C:\96.DLL
  • %WINDIR%\Temp\scs7B.tmp
  • C:\24.DLL
  • %PROGRAM_FILES%\chaoji_050903\Upgrade.ini
  • %PROGRAM_FILES%\chaoji_050903\ico.ico
  • %PROGRAM_FILES%\chaoji_050903\module.log
  • %PROGRAM_FILES%\chaoji_050903\360SEUP.dll
  • %PROGRAM_FILES%\chaoji_050903\ChaoJi.exe
  • %PROGRAM_FILES%\chaoji_050903\ChaoJi.ini
  • %PROGRAM_FILES%\chaoji_050903\passlist.dat
  • %PROGRAM_FILES%\chaoji_050903\360\searchcore\SearchCfg.dat
  • %PROGRAM_FILES%\chaoji_050903\360\searchcore\plugin.ini
  • %PROGRAM_FILES%\chaoji_050903\360\searchcore\searchcore.dll
  • %PROGRAM_FILES%\chaoji_050903\seext.dll
  • %PROGRAM_FILES%\chaoji_050903\360\360core\360core.dll
  • %PROGRAM_FILES%\chaoji_050903\360\360core\plugin.ini
  • %APPDATA%\Microsoft\Internet Explorer\Quick Launch\ Intarnot Explarer .lnk
  • %PROGRAM_FILES%\Flush\plugin\360snap\screener.exe
  • %PROGRAM_FILES%\Flush\plugin\360snap\snap.ico
  • %PROGRAM_FILES%\Flush\plugin\koudai\add.htm
  • %PROGRAM_FILES%\Flush\plugin\360Skinhelper\skinhelper.ico
  • %PROGRAM_FILES%\Flush\plugin\360snap\360snap.dll
  • %PROGRAM_FILES%\Flush\plugin\360snap\plugin.ini
  • %PROGRAM_FILES%\Flush\plugin\koudai\add.ico
  • %PROGRAM_FILES%\Flush\plugin\zconf\plugin.ini
  • %PROGRAM_FILES%\Flush\plugin\zconf\quickconf.dll
  • %ALLUSERSPROFILE%\Desktop\ Intarnot Explarer .lnk
  • %PROGRAM_FILES%\Flush\plugin\koudai\plugin.ini
  • %PROGRAM_FILES%\Flush\plugin\koudai\readme.txt
  • %PROGRAM_FILES%\Flush\plugin\zconf\conf.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_7.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_8.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_9.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_4.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_5.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_6.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\Thumbs.db
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\jc.360.cn_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\poker.wan.360.cn_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\se.360.cn_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\avc.360.cn_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\down.chinaz.com_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\hao.360.cn_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_3.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_11.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_12.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_13.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_0.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_1.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_10.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_14.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_18.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_19.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_2.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_15.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_16.bmp
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\MouseGesture_17.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_11.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_12.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_13.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_0.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_1.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_10.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_14.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_18.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_19.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_2.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_15.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_16.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_17.bmp
  • %PROGRAM_FILES%\Flush\360\searchcore\searchcore.dll
  • %PROGRAM_FILES%\kws\AutoHotKeykws.ini
  • %PROGRAM_FILES%\kws\Cookieskws.exe
  • %PROGRAM_FILES%\Flush\Flush.exe
  • %TEMP%\nse2.tmp\System.dll
  • %PROGRAM_FILES%\kws\2kws.db
  • %PROGRAM_FILES%\kws\3kws.db
  • %PROGRAM_FILES%\Flush\Flush.ini
  • %PROGRAM_FILES%\Flush\360\360core\plugin.ini
  • %PROGRAM_FILES%\Flush\360\searchcore\SearchCfg.dat
  • %PROGRAM_FILES%\Flush\360\searchcore\plugin.ini
  • %PROGRAM_FILES%\Flush\module.log
  • %PROGRAM_FILES%\Flush\passlist.dat
  • %PROGRAM_FILES%\Flush\360\360core\360core.dll
  • %PROGRAM_FILES%\Flush\ImgCache\www.46.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.58.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.886.la_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.3234.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.360.cn_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.360buy.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.baidu.com_favicon.ico
  • %PROGRAM_FILES%\Flush\Shield\Sandboxie.ini
  • %PROGRAM_FILES%\Flush\plugin\360Skinhelper\Skinhelper.dll
  • %PROGRAM_FILES%\Flush\plugin\360Skinhelper\plugin.ini
  • %PROGRAM_FILES%\Flush\ImgCache\www.ename.cn_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.google.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.qihoo.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.2345a.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_6.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_7.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_8.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_3.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_4.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_5.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\MouseGesture_9.bmp
  • %PROGRAM_FILES%\Flush\ImgCache\se.360.cn_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\wan.360.cn_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\www.2345.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\hao.360.cn_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\new.cnzz.com_favicon.ico
  • %PROGRAM_FILES%\Flush\ImgCache\poker.wan.360.cn_favicon.ico
  • %WINDIR%\Temp\scs15.tmp
  • C:\17.DLL
  • %WINDIR%\Temp\scs16.tmp
  • C:\15.DLL
  • %WINDIR%\Temp\scs14.tmp
  • C:\16.DLL
  • C:\18.DLL
  • C:\19.DLL
  • %WINDIR%\Temp\scs1A.tmp
  • C:\20.DLL
  • %WINDIR%\Temp\scs17.tmp
  • %WINDIR%\Temp\scs18.tmp
  • %WINDIR%\Temp\scs19.tmp
  • %WINDIR%\Temp\scs13.tmp
  • %WINDIR%\Temp\scsE.tmp
  • C:\10.DLL
  • %WINDIR%\Temp\scsF.tmp
  • C:\8.DLL
  • %WINDIR%\Temp\scsD.tmp
  • C:\9.DLL
  • C:\11.DLL
  • C:\13.DLL
  • %WINDIR%\Temp\scs12.tmp
  • C:\14.DLL
  • %WINDIR%\Temp\scs10.tmp
  • C:\12.DLL
  • %WINDIR%\Temp\scs11.tmp
  • %WINDIR%\Temp\scs2C.tmp
  • %WINDIR%\Temp\scs2D.tmp
  • %WINDIR%\Temp\scs2E.tmp
  • %WINDIR%\Temp\scs29.tmp
  • %WINDIR%\Temp\scs2A.tmp
  • %WINDIR%\Temp\scs2B.tmp
  • %WINDIR%\Temp\scs2F.tmp
  • %WINDIR%\Temp\scs31.tmp
  • C:\23.DLL
  • %WINDIR%\Temp\scs32.tmp
  • C:\21.DLL
  • %WINDIR%\Temp\scs30.tmp
  • C:\22.DLL
  • %WINDIR%\Temp\scs28.tmp
  • %WINDIR%\Temp\scs1E.tmp
  • %WINDIR%\Temp\scs1F.tmp
  • %WINDIR%\Temp\scs20.tmp
  • %WINDIR%\Temp\scs1B.tmp
  • %WINDIR%\Temp\scs1C.tmp
  • %WINDIR%\Temp\scs1D.tmp
  • %WINDIR%\Temp\scs21.tmp
  • %WINDIR%\Temp\scs25.tmp
  • %WINDIR%\Temp\scs26.tmp
  • %WINDIR%\Temp\scs27.tmp
  • %WINDIR%\Temp\scs22.tmp
  • %WINDIR%\Temp\scs23.tmp
  • %WINDIR%\Temp\scs24.tmp
  • %PROGRAM_FILES%\chaoji_050903\plugin\360snap\snap.ico
  • %PROGRAM_FILES%\chaoji_050903\plugin\koudai\add.htm
  • %PROGRAM_FILES%\chaoji_050903\plugin\koudai\add.ico
  • %PROGRAM_FILES%\chaoji_050903\plugin\360snap\360snap.dll
  • %PROGRAM_FILES%\chaoji_050903\plugin\360snap\plugin.ini
  • %PROGRAM_FILES%\chaoji_050903\plugin\360snap\screener.exe
  • %PROGRAM_FILES%\chaoji_050903\plugin\koudai\plugin.ini
  • %ALLUSERSPROFILE%\Desktop\ МФ±¦-МШВф.lnk
  • %PROGRAM_FILES%\soft050903\a
  • %PROGRAM_FILES%\soft050903\encrypt.bat
  • %PROGRAM_FILES%\chaoji_050903\plugin\zconf\conf.ico
  • %PROGRAM_FILES%\chaoji_050903\plugin\zconf\plugin.ini
  • %PROGRAM_FILES%\chaoji_050903\plugin\zconf\quickconf.dll
  • %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\skinhelper.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\www.cnzz.com_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\www.google.com_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\www.qihoo.com_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\wan.360.cn_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\www.baidu.com_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\www.baidu123.com_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\www.taoku.com_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\360se_head.bmp
  • %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\Skinhelper.dll
  • %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\plugin.ini
  • %PROGRAM_FILES%\chaoji_050903\ImgCache\www.yijia.com_favicon.ico
  • %PROGRAM_FILES%\chaoji_050903\Shield\Sandboxie.ini
  • %PROGRAM_FILES%\chaoji_050903\plugin\360Skinhelper\360se_default.gif
  • C:\3.DLL
  • %WINDIR%\Temp\scs8.tmp
  • C:\4.DLL
  • C:\2.DLL
  • %WINDIR%\Temp\scs7.tmp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\4iklm[1]
  • %WINDIR%\Temp\scs9.tmp
  • %WINDIR%\Temp\scsB.tmp
  • C:\7.DLL
  • %WINDIR%\Temp\scsC.tmp
  • C:\5.DLL
  • %WINDIR%\Temp\scsA.tmp
  • C:\6.DLL
  • %WINDIR%\Temp\scs6.tmp
  • %PROGRAM_FILES%\soft050903\0320110305030320090305030303.txt
  • %TEMP%\nse2.tmp\Math.dll
  • %TEMP%\nse2.tmp\FindProcDLL.dll
  • %PROGRAM_FILES%\soft050903\w_0503.exe
  • %PROGRAM_FILES%\soft050903\B_0320110305030320090305030303.txt
  • %PROGRAM_FILES%\soft050903\C_0320110305030320090305030303.txt
  • %TEMP%\nse2.tmp\NSISdl.dll
  • %WINDIR%\Temp\scs5.tmp
  • C:\1.DLL
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\10608[1].htm
  • %WINDIR%\Temp\scs3.tmp
  • %PROGRAM_FILES%\soft050903\wl06079.exe
  • %WINDIR%\Temp\scs4.tmp
Присваивает атрибут 'скрытый' для следующих файлов:
  • %PROGRAM_FILES%\chaoji_050903\chaoji_050903.ini
  • %PROGRAM_FILES%\Flush\Flush_050903.ini
Удаляет следующие файлы:
  • %WINDIR%\Temp\scs63.tmp
  • %WINDIR%\Temp\scs62.tmp
  • %WINDIR%\Temp\scs64.tmp
  • %WINDIR%\Temp\scs66.tmp
  • %WINDIR%\Temp\scs65.tmp
  • %WINDIR%\Temp\scs61.tmp
  • %WINDIR%\Temp\scs5D.tmp
  • %WINDIR%\Temp\scs5C.tmp
  • %WINDIR%\Temp\scs5E.tmp
  • %WINDIR%\Temp\scs60.tmp
  • %WINDIR%\Temp\scs5F.tmp
  • %WINDIR%\Temp\scs6E.tmp
  • %WINDIR%\Temp\scs6D.tmp
  • %WINDIR%\Temp\scs6F.tmp
  • %WINDIR%\Temp\scs71.tmp
  • %WINDIR%\Temp\scs70.tmp
  • %WINDIR%\Temp\scs6C.tmp
  • %WINDIR%\Temp\scs68.tmp
  • %WINDIR%\Temp\scs67.tmp
  • %WINDIR%\Temp\scs69.tmp
  • %WINDIR%\Temp\scs6B.tmp
  • %WINDIR%\Temp\scs6A.tmp
  • %WINDIR%\Temp\scs5B.tmp
  • %WINDIR%\Temp\scs4C.tmp
  • %WINDIR%\Temp\scs4B.tmp
  • %WINDIR%\Temp\scs4D.tmp
  • %WINDIR%\Temp\scs4F.tmp
  • %WINDIR%\Temp\scs4E.tmp
  • %WINDIR%\Temp\scs4A.tmp
  • %WINDIR%\Temp\scs46.tmp
  • %WINDIR%\Temp\scs45.tmp
  • %WINDIR%\Temp\scs47.tmp
  • %WINDIR%\Temp\scs49.tmp
  • %WINDIR%\Temp\scs48.tmp
  • %WINDIR%\Temp\scs57.tmp
  • %WINDIR%\Temp\scs56.tmp
  • %WINDIR%\Temp\scs58.tmp
  • %WINDIR%\Temp\scs5A.tmp
  • %WINDIR%\Temp\scs59.tmp
  • %WINDIR%\Temp\scs55.tmp
  • %WINDIR%\Temp\scs51.tmp
  • %WINDIR%\Temp\scs50.tmp
  • %WINDIR%\Temp\scs52.tmp
  • %WINDIR%\Temp\scs54.tmp
  • %WINDIR%\Temp\scs53.tmp
  • %WINDIR%\Temp\scs90.tmp
  • %WINDIR%\Temp\scs8F.tmp
  • %WINDIR%\Temp\scs91.tmp
  • %WINDIR%\Temp\scs93.tmp
  • %WINDIR%\Temp\scs92.tmp
  • %WINDIR%\Temp\scs8E.tmp
  • %WINDIR%\Temp\scs8A.tmp
  • %WINDIR%\Temp\scs89.tmp
  • %WINDIR%\Temp\scs8B.tmp
  • %WINDIR%\Temp\scs8D.tmp
  • %WINDIR%\Temp\scs8C.tmp
  • %WINDIR%\Temp\scs9B.tmp
  • %WINDIR%\Temp\scs9A.tmp
  • %WINDIR%\Temp\scs9C.tmp
  • %WINDIR%\Temp\scs9E.tmp
  • %WINDIR%\Temp\scs9D.tmp
  • %WINDIR%\Temp\scs99.tmp
  • %WINDIR%\Temp\scs95.tmp
  • %WINDIR%\Temp\scs94.tmp
  • %WINDIR%\Temp\scs96.tmp
  • %WINDIR%\Temp\scs98.tmp
  • %WINDIR%\Temp\scs97.tmp
  • %WINDIR%\Temp\scs88.tmp
  • %WINDIR%\Temp\scs79.tmp
  • %WINDIR%\Temp\scs78.tmp
  • %WINDIR%\Temp\scs7A.tmp
  • %WINDIR%\Temp\scs7C.tmp
  • %WINDIR%\Temp\scs7B.tmp
  • %WINDIR%\Temp\scs77.tmp
  • %WINDIR%\Temp\scs73.tmp
  • %WINDIR%\Temp\scs72.tmp
  • %WINDIR%\Temp\scs74.tmp
  • %WINDIR%\Temp\scs76.tmp
  • %WINDIR%\Temp\scs75.tmp
  • %WINDIR%\Temp\scs84.tmp
  • %WINDIR%\Temp\scs83.tmp
  • %WINDIR%\Temp\scs85.tmp
  • %WINDIR%\Temp\scs87.tmp
  • %WINDIR%\Temp\scs86.tmp
  • %WINDIR%\Temp\scs82.tmp
  • %WINDIR%\Temp\scs7E.tmp
  • %WINDIR%\Temp\scs7D.tmp
  • %WINDIR%\Temp\scs7F.tmp
  • %WINDIR%\Temp\scs81.tmp
  • %WINDIR%\Temp\scs80.tmp
  • %WINDIR%\Temp\scs44.tmp
  • C:\2.DLL
  • C:\1.DLL
  • C:\3.DLL
  • C:\5.DLL
  • C:\4.DLL
  • %WINDIR%\Temp\scs1A.tmp
  • %WINDIR%\Temp\scs16.tmp
  • %WINDIR%\Temp\scs15.tmp
  • %WINDIR%\Temp\scs17.tmp
  • %WINDIR%\Temp\scs19.tmp
  • %WINDIR%\Temp\scs18.tmp
  • C:\13.DLL
  • C:\12.DLL
  • C:\14.DLL
  • C:\16.DLL
  • C:\15.DLL
  • C:\11.DLL
  • C:\7.DLL
  • C:\6.DLL
  • C:\8.DLL
  • C:\10.DLL
  • C:\9.DLL
  • %WINDIR%\Temp\scs14.tmp
  • %WINDIR%\Temp\scs6.tmp
  • %WINDIR%\Temp\scs5.tmp
  • %PROGRAM_FILES%\soft050903\300.reg
  • %WINDIR%\Temp\scs8.tmp
  • %WINDIR%\Temp\scs7.tmp
  • %WINDIR%\Temp\scs4.tmp
  • %PROGRAM_FILES%\kws\3.db
  • %PROGRAM_FILES%\kws\2.db
  • %PROGRAM_FILES%\kws\AutoHotKey.ini
  • %WINDIR%\Temp\scs3.tmp
  • %PROGRAM_FILES%\soft050903\b_0503.vbe
  • %WINDIR%\Temp\scs10.tmp
  • %WINDIR%\Temp\scsF.tmp
  • %WINDIR%\Temp\scs11.tmp
  • %WINDIR%\Temp\scs13.tmp
  • %WINDIR%\Temp\scs12.tmp
  • %WINDIR%\Temp\scsE.tmp
  • %WINDIR%\Temp\scsA.tmp
  • %WINDIR%\Temp\scs9.tmp
  • %WINDIR%\Temp\scsB.tmp
  • %WINDIR%\Temp\scsD.tmp
  • %WINDIR%\Temp\scsC.tmp
  • %WINDIR%\Temp\scs35.tmp
  • %WINDIR%\Temp\scs34.tmp
  • %WINDIR%\Temp\scs36.tmp
  • %WINDIR%\Temp\scs38.tmp
  • %WINDIR%\Temp\scs37.tmp
  • %WINDIR%\Temp\scs33.tmp
  • %WINDIR%\Temp\scs2F.tmp
  • %WINDIR%\Temp\scs2E.tmp
  • %WINDIR%\Temp\scs30.tmp
  • %WINDIR%\Temp\scs32.tmp
  • %WINDIR%\Temp\scs31.tmp
  • %WINDIR%\Temp\scs40.tmp
  • %WINDIR%\Temp\scs3F.tmp
  • %WINDIR%\Temp\scs41.tmp
  • %WINDIR%\Temp\scs43.tmp
  • %WINDIR%\Temp\scs42.tmp
  • %WINDIR%\Temp\scs3E.tmp
  • %WINDIR%\Temp\scs3A.tmp
  • %WINDIR%\Temp\scs39.tmp
  • %WINDIR%\Temp\scs3B.tmp
  • %WINDIR%\Temp\scs3D.tmp
  • %WINDIR%\Temp\scs3C.tmp
  • %WINDIR%\Temp\scs2D.tmp
  • %WINDIR%\Temp\scs1E.tmp
  • %WINDIR%\Temp\scs1D.tmp
  • %WINDIR%\Temp\scs1F.tmp
  • %WINDIR%\Temp\scs21.tmp
  • %WINDIR%\Temp\scs20.tmp
  • %WINDIR%\Temp\scs1C.tmp
  • C:\18.DLL
  • C:\17.DLL
  • C:\19.DLL
  • %WINDIR%\Temp\scs1B.tmp
  • C:\20.DLL
  • %WINDIR%\Temp\scs29.tmp
  • %WINDIR%\Temp\scs28.tmp
  • %WINDIR%\Temp\scs2A.tmp
  • %WINDIR%\Temp\scs2C.tmp
  • %WINDIR%\Temp\scs2B.tmp
  • %WINDIR%\Temp\scs27.tmp
  • %WINDIR%\Temp\scs23.tmp
  • %WINDIR%\Temp\scs22.tmp
  • %WINDIR%\Temp\scs24.tmp
  • %WINDIR%\Temp\scs26.tmp
  • %WINDIR%\Temp\scs25.tmp
Перемещает следующие файлы:
  • %PROGRAM_FILES%\soft050903\a в %PROGRAM_FILES%\soft050903\050903.txt
  • %PROGRAM_FILES%\chaoji_050903\ChaoJi.ini в %PROGRAM_FILES%\chaoji_050903\chaoji_050903.ini
  • %PROGRAM_FILES%\chaoji_050903\ChaoJi.exe в %PROGRAM_FILES%\chaoji_050903\chaoji_050903.exe
  • %PROGRAM_FILES%\soft050903\0320110305030320090305030303.txt в %PROGRAM_FILES%\soft050903\b_0503.vbe
  • %PROGRAM_FILES%\soft050903\C_0320110305030320090305030303.txt в %PROGRAM_FILES%\soft050903\300.reg
  • %PROGRAM_FILES%\soft050903\B_0320110305030320090305030303.txt в %PROGRAM_FILES%\soft050903\300.bat
  • %PROGRAM_FILES%\kws\AutoHotKeykws.ini в %PROGRAM_FILES%\kws\AutoHotKey.ini
  • %PROGRAM_FILES%\kws\3kws.db в %PROGRAM_FILES%\kws\3.db
  • %PROGRAM_FILES%\kws\2kws.db в %PROGRAM_FILES%\kws\2.db
  • %PROGRAM_FILES%\Flush\Flush.ini в %PROGRAM_FILES%\Flush\Flush_050903.ini
  • %PROGRAM_FILES%\Flush\Flush.exe в %PROGRAM_FILES%\Flush\Flush_050903.exe
  • %PROGRAM_FILES%\kws\Cookieskws.exe в %PROGRAM_FILES%\kws\Cookies.exe
Сетевая активность:
Подключается к:
  • 'localhost':1041
  • 'ta##rl.com':80
  • 'oo.##mtb.info':888
  • 'localhost':1036
  • 'do##.emoney.cn':80
  • 'www.17##g.com':80
TCP:
Запросы HTTP GET:
  • ta##rl.com/4iklm
  • www.17##g.com/lianjie/10608.htm
  • do##.emoney.cn/wl06079.exe
UDP:
  • DNS ASK ta##rl.com
  • DNS ASK oo.##mtb.info
  • DNS ASK do##.emoney.cn
  • DNS ASK www.17##g.com
Другое:
Ищет следующие окна:
  • ClassName: 'SysListView32' WindowName: ''
  • ClassName: 'BaseBar' WindowName: 'ChanApp'
  • ClassName: 'OleMainThreadWndClass' WindowName: ''
  • ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-d50.d54.3a0001'
  • ClassName: 'CSCHiddenWindow' WindowName: ''
  • ClassName: 'SystemTray_Main' WindowName: ''
  • ClassName: 'Proxy Desktop' WindowName: ''
  • ClassName: 'RegEdit_RegEdit' WindowName: ''
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: '' WindowName: ''
  • ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-abc.ac0.390002'
  • ClassName: 'MS_WebcheckMonitor' WindowName: ''
  • ClassName: 'MS_AutodialMonitor' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке