Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.DownLoader45.25657

Добавлен в вирусную базу Dr.Web: 2022-10-18

Описание добавлено:

Technical Information

Modifies file system
Creates the following files
  • %TEMP%\is-9ba07.tmp\is-0c1q2.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-kplsm.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-626ni.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-r4c76.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-cm63j.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-u87os.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-iep7g.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-vvasc.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-vqqii.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-mp65u.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-suh5j.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-uofrd.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-i95en.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-el6ef.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-ajs9i.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-du5ua.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-7qr8c.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-8pi7s.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-1fd20.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-fqi2i.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-8urbh.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-g7dsj.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-oqkrt.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-ftpkl.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-212tm.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-88gd2.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-7an56.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-4qhm5.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-hb39c.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-o1q45.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-3u7li.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-6q3b1.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-iodrk.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-rsb8p.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-jfidp.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-6p2n2.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-qfqmp.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-7vv8h.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-hrc89.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-q07f6.tmp
  • %ProgramFiles(x86)%\universal extractor\uniextract.exe
  • %ProgramFiles(x86)%\universal extractor\bin\is-1l0pe.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-sgltd.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-m0pae.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-fedhq.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-tiam2.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-qbs7g.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-pdrbv.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-d4kgc.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-4e87r.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-8o44h.tmp
  • %ProgramFiles(x86)%\universal extractor\is-s5nbn.tmp
  • %ProgramFiles(x86)%\universal extractor\is-q4iu8.tmp
  • %ProgramFiles(x86)%\universal extractor\is-3qhi8.tmp
  • %ProgramFiles(x86)%\universal extractor\is-nhqad.tmp
  • %ProgramFiles(x86)%\universal extractor\is-ihs8d.tmp
  • %ProgramFiles(x86)%\universal extractor\unins000.dat
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-cnpak.tmp
  • %ProgramFiles(x86)%\universal extractor\is-u6q18.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\unp\is-5o3sb.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-cu976.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-sgn76.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-fqlpd.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-hism7.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-01abg.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-91eg8.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-nsab8.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-9h12c.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-6ok79.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-8a1at.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-oo3m5.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-g6ird.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-vmdjh.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-am4u9.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-t1pfc.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-h07d3.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-0tpau.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-mtoee.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-rj7fl.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-2pi6p.tmp
  • %ProgramFiles(x86)%\universal extractor\bin\is-2825d.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-3ctct.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qkul2.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-d543c.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-20spi.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-99ljp.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-4ucf1.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qicgk.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qlpmp.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-knpln.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-nbs5p.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-ea4ct.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-3slsp.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qdo1r.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-4ehbf.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-o40cn.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-o0699.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-vvh7c.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-3vdfm.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-tk52q.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-cn0bb.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-dfgsb.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-0jlk6.tmp
  • %TEMP%\is-kg7j6.tmp\_isetup\_shfoldr.dll
  • %TEMP%\is-kg7j6.tmp\_iscrypt.dll
  • %ProgramFiles(x86)%\universal extractor\is-r71hm.tmp
  • %ProgramFiles(x86)%\universal extractor\is-pqdpa.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-hp7bm.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-gst4u.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-o4vla.tmp
  • %TEMP%\is-kg7j6.tmp\_isetup\_setup64.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-2k02h.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-bmg9r.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-h588v.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-ihnbr.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-acuuf.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qhpgo.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-5mdmd.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-uu760.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-p3dcs.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-3fja4.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-su3u2.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-a4nsh.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-je568.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-uan29.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-t55la.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-ahs4o.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-fjo38.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-425ht.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-e1paf.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-6ci8r.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qgqon.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-6cmhi.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-gk8ev.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qmkr0.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-b090d.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-5m59n.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-2mfvh.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-25vgq.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-anki7.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-ipe7q.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-bvr6n.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qogn5.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-8fnbt.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-0t3mk.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-7nq0r.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-au3r6.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-lh035.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-2sd05.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-8jjrd.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-8gtmv.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-hclne.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-7ct0v.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-avarf.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-8h9ua.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-sio8n.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-l46a1.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-t3kiq.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-lkc9v.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-issm3.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-gg7kb.tmp
  • %ProgramFiles(x86)%\universal extractor\docs\is-qif1d.tmp
  • %TEMP%\jdegg.txt
Moves the following files
  • from %ProgramFiles(x86)%\universal extractor\is-r71hm.tmp to %ProgramFiles(x86)%\universal extractor\unins000.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-626ni.tmp to %ProgramFiles(x86)%\universal extractor\bin\e_wise_w.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-r4c76.tmp to %ProgramFiles(x86)%\universal extractor\bin\forcelibrary.dll
  • from %ProgramFiles(x86)%\universal extractor\bin\is-cm63j.tmp to %ProgramFiles(x86)%\universal extractor\bin\helpdeco.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-u87os.tmp to %ProgramFiles(x86)%\universal extractor\bin\i3comp.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-iep7g.tmp to %ProgramFiles(x86)%\universal extractor\bin\i5comp.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-7vv8h.tmp to %ProgramFiles(x86)%\universal extractor\bin\7z.dll
  • from %ProgramFiles(x86)%\universal extractor\bin\is-mp65u.tmp to %ProgramFiles(x86)%\universal extractor\bin\i6comp.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-8pi7s.tmp to %ProgramFiles(x86)%\universal extractor\bin\instexpl.dll
  • from %ProgramFiles(x86)%\universal extractor\bin\is-suh5j.tmp to %ProgramFiles(x86)%\universal extractor\bin\instexpl.wcx
  • from %ProgramFiles(x86)%\universal extractor\bin\is-uofrd.tmp to %ProgramFiles(x86)%\universal extractor\bin\isxunpack.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-i95en.tmp to %ProgramFiles(x86)%\universal extractor\bin\lzop.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-el6ef.tmp to %ProgramFiles(x86)%\universal extractor\bin\mhtunp.wcx
  • from %ProgramFiles(x86)%\universal extractor\bin\is-ajs9i.tmp to %ProgramFiles(x86)%\universal extractor\bin\msi.wcx
  • from %ProgramFiles(x86)%\universal extractor\bin\is-vvasc.tmp to %ProgramFiles(x86)%\universal extractor\bin\extract.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-7qr8c.tmp to %ProgramFiles(x86)%\universal extractor\bin\innounp.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-kplsm.tmp to %ProgramFiles(x86)%\universal extractor\bin\e_wise.ini
  • from %ProgramFiles(x86)%\universal extractor\bin\is-vqqii.tmp to %ProgramFiles(x86)%\universal extractor\bin\extractmht.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-1fd20.tmp to %ProgramFiles(x86)%\universal extractor\bin\dbxplug.wcx
  • from %ProgramFiles(x86)%\universal extractor\bin\is-fqi2i.tmp to %ProgramFiles(x86)%\universal extractor\bin\cmdtotal.exe
  • from %ProgramFiles(x86)%\universal extractor\docs\is-ftpkl.tmp to %ProgramFiles(x86)%\universal extractor\docs\unzip_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-212tm.tmp to %ProgramFiles(x86)%\universal extractor\docs\upx_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-88gd2.tmp to %ProgramFiles(x86)%\universal extractor\docs\upx_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-7an56.tmp to %ProgramFiles(x86)%\universal extractor\docs\upx_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-4qhm5.tmp to %ProgramFiles(x86)%\universal extractor\docs\uudeview_license.txt
  • from %ProgramFiles(x86)%\universal extractor\bin\is-du5ua.tmp to %ProgramFiles(x86)%\universal extractor\bin\msix.exe
  • from %ProgramFiles(x86)%\universal extractor\docs\is-o1q45.tmp to %ProgramFiles(x86)%\universal extractor\docs\uudeview_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-hb39c.tmp to %ProgramFiles(x86)%\universal extractor\docs\unzip_license.txt
  • from %ProgramFiles(x86)%\universal extractor\bin\is-3u7li.tmp to %ProgramFiles(x86)%\universal extractor\bin\7z.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-iodrk.tmp to %ProgramFiles(x86)%\universal extractor\bin\arj.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-rsb8p.tmp to %ProgramFiles(x86)%\universal extractor\bin\aspackdie.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-jfidp.tmp to %ProgramFiles(x86)%\universal extractor\bin\bin2iso.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-6p2n2.tmp to %ProgramFiles(x86)%\universal extractor\bin\booz.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-qfqmp.tmp to %ProgramFiles(x86)%\universal extractor\bin\cdirip.exe
  • from %ProgramFiles(x86)%\universal extractor\docs\is-g7dsj.tmp to %ProgramFiles(x86)%\universal extractor\docs\unzip_man.txt
  • from %ProgramFiles(x86)%\universal extractor\bin\is-8urbh.tmp to %ProgramFiles(x86)%\universal extractor\bin\clit.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-6q3b1.tmp to %ProgramFiles(x86)%\universal extractor\bin\arc.exe
  • from %ProgramFiles(x86)%\universal extractor\docs\is-oqkrt.tmp to %ProgramFiles(x86)%\universal extractor\docs\unzip_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\bin\is-hrc89.tmp to %ProgramFiles(x86)%\universal extractor\bin\nbhextract.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-8a1at.tmp to %ProgramFiles(x86)%\universal extractor\bin\raiu.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-d4kgc.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\bzip2_2.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-4e87r.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\bzip2_3.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-sgltd.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\eschalon.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-m0pae.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\gentee.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-fedhq.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\inflate1.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-tiam2.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\inflate2.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\is-mtoee.tmp to %ProgramFiles(x86)%\universal extractor\bin\zd50149.dll
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-qbs7g.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\inflate3.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-8o44h.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\pkware.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-cnpak.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\vise.unp
  • from %ProgramFiles(x86)%\universal extractor\is-u6q18.tmp to %ProgramFiles(x86)%\universal extractor\changelog.txt
  • from %ProgramFiles(x86)%\universal extractor\is-s5nbn.tmp to %ProgramFiles(x86)%\universal extractor\license.txt
  • from %ProgramFiles(x86)%\universal extractor\is-q4iu8.tmp to %ProgramFiles(x86)%\universal extractor\uniextract.ico
  • from %ProgramFiles(x86)%\universal extractor\is-3qhi8.tmp to %ProgramFiles(x86)%\universal extractor\turbosearch.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-cu976.tmp to %ProgramFiles(x86)%\universal extractor\bin\zd55131.dll
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-5o3sb.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\bzip2_1.unp
  • from %ProgramFiles(x86)%\universal extractor\bin\is-sgn76.tmp to %ProgramFiles(x86)%\universal extractor\bin\zd51145.dll
  • from %ProgramFiles(x86)%\universal extractor\bin\is-0tpau.tmp to %ProgramFiles(x86)%\universal extractor\bin\wun.exe
  • from %ProgramFiles(x86)%\universal extractor\docs\is-avarf.tmp to %ProgramFiles(x86)%\universal extractor\docs\lzma_license.txt
  • from %ProgramFiles(x86)%\universal extractor\bin\is-fqlpd.tmp to %ProgramFiles(x86)%\universal extractor\bin\stix_d.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-hism7.tmp to %ProgramFiles(x86)%\universal extractor\bin\tee.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-01abg.tmp to %ProgramFiles(x86)%\universal extractor\bin\trid.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-91eg8.tmp to %ProgramFiles(x86)%\universal extractor\bin\triddefs.trd
  • from %ProgramFiles(x86)%\universal extractor\bin\is-nsab8.tmp to %ProgramFiles(x86)%\universal extractor\bin\uharc02.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-2825d.tmp to %ProgramFiles(x86)%\universal extractor\bin\nrg2iso.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-1l0pe.tmp to %ProgramFiles(x86)%\universal extractor\bin\peid.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-q07f6.tmp to %ProgramFiles(x86)%\universal extractor\bin\pdunsis.wcx
  • from %ProgramFiles(x86)%\universal extractor\bin\is-9h12c.tmp to %ProgramFiles(x86)%\universal extractor\bin\uharc04.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-g6ird.tmp to %ProgramFiles(x86)%\universal extractor\bin\unzip.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-vmdjh.tmp to %ProgramFiles(x86)%\universal extractor\bin\upx.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-am4u9.tmp to %ProgramFiles(x86)%\universal extractor\bin\userdb.txt
  • from %ProgramFiles(x86)%\universal extractor\bin\is-t1pfc.tmp to %ProgramFiles(x86)%\universal extractor\bin\uudeview.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-h07d3.tmp to %ProgramFiles(x86)%\universal extractor\bin\wdosxle.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-6ok79.tmp to %ProgramFiles(x86)%\universal extractor\bin\unlzx.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-oo3m5.tmp to %ProgramFiles(x86)%\universal extractor\bin\unrar.exe
  • from %ProgramFiles(x86)%\universal extractor\bin\is-rj7fl.tmp to %ProgramFiles(x86)%\universal extractor\bin\unuharc06.exe
  • from %ProgramFiles(x86)%\universal extractor\docs\is-2pi6p.tmp to %ProgramFiles(x86)%\universal extractor\docs\unrar_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-3ctct.tmp to %ProgramFiles(x86)%\universal extractor\docs\unrar_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qif1d.tmp to %ProgramFiles(x86)%\universal extractor\docs\unlzx_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qicgk.tmp to %ProgramFiles(x86)%\universal extractor\docs\dbxplug_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qlpmp.tmp to %ProgramFiles(x86)%\universal extractor\docs\ewise_author.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-ea4ct.tmp to %ProgramFiles(x86)%\universal extractor\docs\ewise_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-3vdfm.tmp to %ProgramFiles(x86)%\universal extractor\docs\ewise_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-tk52q.tmp to %ProgramFiles(x86)%\universal extractor\docs\extractmht_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-3slsp.tmp to %ProgramFiles(x86)%\universal extractor\docs\extractmht_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-je568.tmp to %ProgramFiles(x86)%\universal extractor\docs\i5comp_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qdo1r.tmp to %ProgramFiles(x86)%\universal extractor\docs\extract_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-o40cn.tmp to %ProgramFiles(x86)%\universal extractor\docs\helpdeco_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-o0699.tmp to %ProgramFiles(x86)%\universal extractor\docs\helpdeco_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-vvh7c.tmp to %ProgramFiles(x86)%\universal extractor\docs\helpdeco_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-3fja4.tmp to %ProgramFiles(x86)%\universal extractor\docs\hwun_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qkul2.tmp to %ProgramFiles(x86)%\universal extractor\docs\hwun_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-20spi.tmp to %ProgramFiles(x86)%\universal extractor\docs\cmdtotal_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-d543c.tmp to %ProgramFiles(x86)%\universal extractor\docs\cmdtotal_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-4ucf1.tmp to %ProgramFiles(x86)%\universal extractor\docs\convertlit_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-nbs5p.tmp to %ProgramFiles(x86)%\universal extractor\docs\cdrip_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-knpln.tmp to %ProgramFiles(x86)%\universal extractor\docs\cdirip_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\is-pqdpa.tmp to %ProgramFiles(x86)%\universal extractor\english.ini
  • from %ProgramFiles(x86)%\universal extractor\docs\is-gst4u.tmp to %ProgramFiles(x86)%\universal extractor\docs\7zip_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-o4vla.tmp to %ProgramFiles(x86)%\universal extractor\docs\7zip_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-2k02h.tmp to %ProgramFiles(x86)%\universal extractor\docs\arc_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-p3dcs.tmp to %ProgramFiles(x86)%\universal extractor\docs\arc_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-bmg9r.tmp to %ProgramFiles(x86)%\universal extractor\docs\arc_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-su3u2.tmp to %ProgramFiles(x86)%\universal extractor\docs\i3comp_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-h588v.tmp to %ProgramFiles(x86)%\universal extractor\docs\arj_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-4ehbf.tmp to %ProgramFiles(x86)%\universal extractor\docs\extract_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-acuuf.tmp to %ProgramFiles(x86)%\universal extractor\docs\arj_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-5mdmd.tmp to %ProgramFiles(x86)%\universal extractor\docs\aspackdie_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-uu760.tmp to %ProgramFiles(x86)%\universal extractor\docs\bin2iso_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-0jlk6.tmp to %ProgramFiles(x86)%\universal extractor\docs\bin2iso_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-dfgsb.tmp to %ProgramFiles(x86)%\universal extractor\docs\booz_readme.doc
  • from %ProgramFiles(x86)%\universal extractor\docs\is-cn0bb.tmp to %ProgramFiles(x86)%\universal extractor\docs\booz_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-ihnbr.tmp to %ProgramFiles(x86)%\universal extractor\docs\arj_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-hp7bm.tmp to %ProgramFiles(x86)%\universal extractor\docs\7zip_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qhpgo.tmp to %ProgramFiles(x86)%\universal extractor\docs\aspackdie_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-99ljp.tmp to %ProgramFiles(x86)%\universal extractor\docs\convertlit_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-hclne.tmp to %ProgramFiles(x86)%\universal extractor\docs\i5comp_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-uan29.tmp to %ProgramFiles(x86)%\universal extractor\docs\nrg2iso_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-ahs4o.tmp to %ProgramFiles(x86)%\universal extractor\docs\pdunsis_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-fjo38.tmp to %ProgramFiles(x86)%\universal extractor\docs\pdunsis_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-425ht.tmp to %ProgramFiles(x86)%\universal extractor\docs\peid_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-e1paf.tmp to %ProgramFiles(x86)%\universal extractor\docs\peid_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-6cmhi.tmp to %ProgramFiles(x86)%\universal extractor\docs\stix_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qgqon.tmp to %ProgramFiles(x86)%\universal extractor\docs\nbgextract_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-0t3mk.tmp to %ProgramFiles(x86)%\universal extractor\docs\i6comp_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-t55la.tmp to %ProgramFiles(x86)%\universal extractor\docs\nrg2iso_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-anki7.tmp to %ProgramFiles(x86)%\universal extractor\docs\stix_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-b090d.tmp to %ProgramFiles(x86)%\universal extractor\docs\trid_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-5m59n.tmp to %ProgramFiles(x86)%\universal extractor\docs\uharc_license.doc
  • from %ProgramFiles(x86)%\universal extractor\docs\is-2mfvh.tmp to %ProgramFiles(x86)%\universal extractor\docs\uharc_readme.doc
  • from %ProgramFiles(x86)%\universal extractor\docs\is-25vgq.tmp to %ProgramFiles(x86)%\universal extractor\docs\uharc_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-a4nsh.tmp to %ProgramFiles(x86)%\universal extractor\docs\unlzx_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-ipe7q.tmp to %ProgramFiles(x86)%\universal extractor\docs\tee_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-gk8ev.tmp to %ProgramFiles(x86)%\universal extractor\docs\tee_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qmkr0.tmp to %ProgramFiles(x86)%\universal extractor\docs\trid_readme_e.txt
  • from %ProgramFiles(x86)%\universal extractor\bin\unp\is-pdrbv.tmp to %ProgramFiles(x86)%\universal extractor\bin\unp\lzma.unp
  • from %ProgramFiles(x86)%\universal extractor\is-nhqad.tmp to %ProgramFiles(x86)%\universal extractor\uniextract.exe
  • from %ProgramFiles(x86)%\universal extractor\docs\is-qogn5.tmp to %ProgramFiles(x86)%\universal extractor\docs\msix_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-au3r6.tmp to %ProgramFiles(x86)%\universal extractor\docs\innounp_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-lh035.tmp to %ProgramFiles(x86)%\universal extractor\docs\innounp_readme.htm
  • from %ProgramFiles(x86)%\universal extractor\docs\is-2sd05.tmp to %ProgramFiles(x86)%\universal extractor\docs\innounp_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-8jjrd.tmp to %ProgramFiles(x86)%\universal extractor\docs\installexplorer_readme_en.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-8gtmv.tmp to %ProgramFiles(x86)%\universal extractor\docs\installexplorer_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-7ct0v.tmp to %ProgramFiles(x86)%\universal extractor\docs\isxunpack_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-bvr6n.tmp to %ProgramFiles(x86)%\universal extractor\docs\msi_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-6ci8r.tmp to %ProgramFiles(x86)%\universal extractor\docs\msi_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-gg7kb.tmp to %ProgramFiles(x86)%\universal extractor\docs\isxunpack_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-sio8n.tmp to %ProgramFiles(x86)%\universal extractor\docs\lzma_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-l46a1.tmp to %ProgramFiles(x86)%\universal extractor\docs\lzop_license.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-t3kiq.tmp to %ProgramFiles(x86)%\universal extractor\docs\lzop_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-lkc9v.tmp to %ProgramFiles(x86)%\universal extractor\docs\lzop_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-issm3.tmp to %ProgramFiles(x86)%\universal extractor\docs\mhtunp_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-8fnbt.tmp to %ProgramFiles(x86)%\universal extractor\docs\mhtunp_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-7nq0r.tmp to %ProgramFiles(x86)%\universal extractor\docs\i6comp_url.txt
  • from %ProgramFiles(x86)%\universal extractor\docs\is-8h9ua.tmp to %ProgramFiles(x86)%\universal extractor\docs\lzma_readme.txt
  • from %ProgramFiles(x86)%\universal extractor\is-ihs8d.tmp to %ProgramFiles(x86)%\universal extractor\uniextract.ini
Network activity
Connects to
  • 'os##etxi.ga':80
TCP
HTTP GET requests
  • http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?69########
HTTP POST requests
  • http://os##etxi.ga/new/net_api
UDP
  • DNS ASK os##etxi.ga
Miscellaneous
Searches for the following windows
  • ClassName: '{c1959CF5-54FF-11D3-8BDA-2030689aB1B6}' WindowName: ''
Creates and executes the following
  • '%TEMP%\is-9ba07.tmp\is-0c1q2.tmp' /SL4 $B0218 "<Full path to file>" 7454953 52224
  • '%ProgramFiles(x86)%\universal extractor\uniextract.exe'
  • '%ProgramFiles(x86)%\universal extractor\uniextract.exe' 82e77013bdc66bf87adbe0fd0a333d75
Executes the following
  • '%WINDIR%\syswow64\schtasks.exe' /Query
  • '%WINDIR%\syswow64\schtasks.exe' /Delete /F /TN "UniExtract 31"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке