Защити созданное

Другие наши ресурсы

  • free.drweb.kz — бесплатные утилиты, плагины, информеры
  • av-desk.com — интернет-сервис для поставщиков услуг Dr.Web AV-Desk
  • curenet.drweb.kz — сетевая лечащая утилита Dr.Web CureNet!
Закрыть

Библиотека
Моя библиотека

Чтобы добавить ресурс в библиотеку, войдите в аккаунт.

+ Добавить в библиотеку

Ресурсов: -

Последний: -

Моя библиотека

Поддержка
Круглосуточная поддержка | Правила обращения

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen21.48825

Добавлен в вирусную базу Dr.Web: 2023-10-24

Описание добавлено:

Technical Information

Modifies file system
Creates the following files
  • %TEMP%\is-kgvlr.tmp\<File name>.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-onhbf.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-39gi2.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-uf7c7.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-hpeu3.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-6q6fn.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-oi16n.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-asfo5.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-7uk5t.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-uqftt.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-oc26u.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-60r9j.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-spooc.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-gp1u6.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-13se0.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-9mrnp.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-9pgiq.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-08hss.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-2uvb4.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-sr4a1.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-s5r6f.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-egoa7.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-9fr1j.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-afb9h.tmp
  • %ProgramFiles(x86)%\audio recorder\is-4enoi.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-paiqe.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-9eq8l.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-ejcfh.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-a352c.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-f565p.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-p7sbh.tmp
  • %ProgramFiles(x86)%\audio recorder\pf\is-7sfiq.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-gm0mn.tmp
  • %ProgramFiles(x86)%\audio recorder\audiorecorder.exe
  • %ProgramFiles(x86)%\audio recorder\audiences\is-a9rcr.tmp
  • %ProgramFiles(x86)%\audio recorder\unins000.dat
  • %ProgramFiles(x86)%\audio recorder\is-6f1be.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-nr7nd.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-ihcfl.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-na7db.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-4o3j4.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-ue0lh.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-v91sl.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-30nu5.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-1r829.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-hd4bi.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-13vb9.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-7v3if.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-s9n25.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-a7iua.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-mv61o.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-0n7si.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-mcefv.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-o8a4a.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-51oe7.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-qa0il.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-5bbt0.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-n583g.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-649l2.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-dspf1.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-khmef.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-kvcjj.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-f622f.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-ag0ft.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-uv8tl.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-36nni.tmp
  • %ProgramFiles(x86)%\audio recorder\audiences\is-80k1n.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-gogh4.tmp
  • %ProgramFiles(x86)%\audio recorder\is-1bsls.tmp
  • %ProgramFiles(x86)%\audio recorder\is-lrvf4.tmp
  • %ProgramFiles(x86)%\audio recorder\is-7sf9p.tmp
  • %ProgramFiles(x86)%\audio recorder\is-f52f5.tmp
  • %ProgramFiles(x86)%\audio recorder\is-1k6k3.tmp
  • %ProgramFiles(x86)%\audio recorder\is-0p5th.tmp
  • %ProgramFiles(x86)%\audio recorder\is-kmqt9.tmp
  • %ProgramFiles(x86)%\audio recorder\is-k5ras.tmp
  • %ProgramFiles(x86)%\audio recorder\is-4f5rr.tmp
  • %ProgramFiles(x86)%\audio recorder\is-52223.tmp
  • %ProgramFiles(x86)%\audio recorder\is-ik2bj.tmp
  • %ProgramFiles(x86)%\audio recorder\is-gko2b.tmp
  • %ProgramFiles(x86)%\audio recorder\is-q62vh.tmp
  • %ProgramFiles(x86)%\audio recorder\is-lib91.tmp
  • %ProgramFiles(x86)%\audio recorder\is-2rf3v.tmp
  • %ProgramFiles(x86)%\audio recorder\is-bm8b2.tmp
  • %ProgramFiles(x86)%\audio recorder\is-npvbq.tmp
  • %ProgramFiles(x86)%\audio recorder\is-2js2j.tmp
  • %ProgramFiles(x86)%\audio recorder\is-l6b9m.tmp
  • %ProgramFiles(x86)%\audio recorder\is-ojo1i.tmp
  • %ProgramFiles(x86)%\audio recorder\is-8k2jp.tmp
  • %ProgramFiles(x86)%\audio recorder\is-9ak32.tmp
  • %ProgramFiles(x86)%\audio recorder\is-c8rjv.tmp
  • %ProgramFiles(x86)%\audio recorder\is-e4r1q.tmp
  • %ProgramFiles(x86)%\audio recorder\is-url2q.tmp
  • %ProgramFiles(x86)%\audio recorder\is-09q2m.tmp
  • %TEMP%\is-kfpe3.tmp\_isetup\_iscrypt.dll
  • %TEMP%\is-kfpe3.tmp\_isetup\_isdecmp.dll
  • %TEMP%\is-kfpe3.tmp\_isetup\_shfoldr.dll
  • %TEMP%\is-kfpe3.tmp\_isetup\_setup64.tmp
  • %TEMP%\is-kfpe3.tmp\_isetup\_regdll.tmp
  • %ProgramFiles(x86)%\audio recorder\is-32age.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-ilat2.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-2df9f.tmp
  • %ProgramFiles(x86)%\audio recorder\is-s9oej.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-svvs3.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-pgv63.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-35q2u.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-309lo.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-85sj5.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-7rnmg.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-j4pp7.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-ss4nj.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-7qchn.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-b2cbj.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-6vkjk.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-ppma9.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-m9va2.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-mj52m.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-1408h.tmp
  • %ProgramFiles(x86)%\audio recorder\lang\is-argue.tmp
  • %ProgramFiles(x86)%\audio recorder\is-n12ie.tmp
  • %ProgramFiles(x86)%\audio recorder\is-ro9cu.tmp
  • %ProgramFiles(x86)%\audio recorder\is-vf89t.tmp
  • %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\is-gavj5.tmp
  • %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\is-chk51.tmp
  • %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\is-vcafl.tmp
  • %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\is-h79a8.tmp
  • %ProgramFiles(x86)%\audio recorder\is-4ms3q.tmp
  • %ProgramFiles(x86)%\audio recorder\is-6pk06.tmp
  • %ProgramFiles(x86)%\audio recorder\is-drd43.tmp
  • %ProgramFiles(x86)%\audio recorder\is-8ipnn.tmp
  • %ProgramFiles(x86)%\audio recorder\is-2bcqa.tmp
  • %ProgramFiles(x86)%\audio recorder\is-tqm62.tmp
  • %ProgramFiles(x86)%\audio recorder\is-o1jnf.tmp
  • %ProgramFiles(x86)%\audio recorder\is-likt0.tmp
  • %TEMP%\license.txt
Deletes the following files
  • %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt.manifest
  • %ProgramFiles(x86)%\audio recorder\msvcm90.dll
  • %ProgramFiles(x86)%\audio recorder\wait.gif
Moves the following files
  • from %ProgramFiles(x86)%\audio recorder\is-09q2m.tmp to %ProgramFiles(x86)%\audio recorder\unins000.exe
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-onhbf.tmp to %ProgramFiles(x86)%\audio recorder\audiences\1m download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-39gi2.tmp to %ProgramFiles(x86)%\audio recorder\audiences\16k substream for 28k dial-up.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-uf7c7.tmp to %ProgramFiles(x86)%\audio recorder\audiences\150k lan.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-hpeu3.tmp to %ProgramFiles(x86)%\audio recorder\audiences\12k substream for 28k dial-up.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-6q6fn.tmp to %ProgramFiles(x86)%\audio recorder\audiences\128k dual isdn.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-oi16n.tmp to %ProgramFiles(x86)%\audio recorder\audiences\100% quality download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\pf\is-asfo5.tmp to %ProgramFiles(x86)%\audio recorder\pf\wma.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-7uk5t.tmp to %ProgramFiles(x86)%\audio recorder\pf\wav.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-uqftt.tmp to %ProgramFiles(x86)%\audio recorder\pf\voc.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-oc26u.tmp to %ProgramFiles(x86)%\audio recorder\pf\ra.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-60r9j.tmp to %ProgramFiles(x86)%\audio recorder\pf\ogg.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-spooc.tmp to %ProgramFiles(x86)%\audio recorder\pf\mp3.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-gp1u6.tmp to %ProgramFiles(x86)%\audio recorder\pf\mp2.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-13se0.tmp to %ProgramFiles(x86)%\audio recorder\pf\mka.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-9pgiq.tmp to %ProgramFiles(x86)%\audio recorder\pf\m4r.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-7sfiq.tmp to %ProgramFiles(x86)%\audio recorder\pf\m4b.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-08hss.tmp to %ProgramFiles(x86)%\audio recorder\pf\m4a.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-2uvb4.tmp to %ProgramFiles(x86)%\audio recorder\pf\flac.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-sr4a1.tmp to %ProgramFiles(x86)%\audio recorder\pf\au.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-s5r6f.tmp to %ProgramFiles(x86)%\audio recorder\pf\amr.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-egoa7.tmp to %ProgramFiles(x86)%\audio recorder\pf\aiff.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-9fr1j.tmp to %ProgramFiles(x86)%\audio recorder\pf\ac3.pf
  • from %ProgramFiles(x86)%\audio recorder\pf\is-afb9h.tmp to %ProgramFiles(x86)%\audio recorder\pf\aac.pf
  • from %ProgramFiles(x86)%\audio recorder\lang\is-paiqe.tmp to %ProgramFiles(x86)%\audio recorder\lang\index.ini
  • from %ProgramFiles(x86)%\audio recorder\lang\is-9eq8l.tmp to %ProgramFiles(x86)%\audio recorder\lang\waverec_spanish.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-ejcfh.tmp to %ProgramFiles(x86)%\audio recorder\lang\waverec_russian.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-a352c.tmp to %ProgramFiles(x86)%\audio recorder\lang\waverec_portugues.dat
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-9mrnp.tmp to %ProgramFiles(x86)%\audio recorder\audiences\1m multichannel (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-80k1n.tmp to %ProgramFiles(x86)%\audio recorder\audiences\256k dsl or cable.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-nr7nd.tmp to %ProgramFiles(x86)%\audio recorder\audiences\pocketpc local playback.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-a9rcr.tmp to %ProgramFiles(x86)%\audio recorder\audiences\26k substream for 56k dial-up.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-ihcfl.tmp to %ProgramFiles(x86)%\audio recorder\audiences\lossless audio.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-na7db.tmp to %ProgramFiles(x86)%\audio recorder\audiences\general mobile streaming.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-4o3j4.tmp to %ProgramFiles(x86)%\audio recorder\audiences\general mobile local playback.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-ue0lh.tmp to %ProgramFiles(x86)%\audio recorder\audiences\90% quality download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-v91sl.tmp to %ProgramFiles(x86)%\audio recorder\audiences\80% quality download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-30nu5.tmp to %ProgramFiles(x86)%\audio recorder\audiences\768k dsl or cable.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-1r829.tmp to %ProgramFiles(x86)%\audio recorder\audiences\750k surround stereo (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-hd4bi.tmp to %ProgramFiles(x86)%\audio recorder\audiences\750k multichannel (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-13vb9.tmp to %ProgramFiles(x86)%\audio recorder\audiences\750k download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-7v3if.tmp to %ProgramFiles(x86)%\audio recorder\audiences\70% quality download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-s9n25.tmp to %ProgramFiles(x86)%\audio recorder\audiences\64k single isdn.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-mv61o.tmp to %ProgramFiles(x86)%\audio recorder\audiences\5m surround stereo (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-gm0mn.tmp to %ProgramFiles(x86)%\audio recorder\audiences\5m multichannel (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-0n7si.tmp to %ProgramFiles(x86)%\audio recorder\audiences\5m download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-mcefv.tmp to %ProgramFiles(x86)%\audio recorder\audiences\56k dial-up.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-o8a4a.tmp to %ProgramFiles(x86)%\audio recorder\audiences\512k dsl or cable.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-51oe7.tmp to %ProgramFiles(x86)%\audio recorder\audiences\450k surround stereo (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-qa0il.tmp to %ProgramFiles(x86)%\audio recorder\audiences\450k multichannel (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-5bbt0.tmp to %ProgramFiles(x86)%\audio recorder\audiences\450k download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-n583g.tmp to %ProgramFiles(x86)%\audio recorder\audiences\384k dsl or cable.rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-649l2.tmp to %ProgramFiles(x86)%\audio recorder\audiences\350k surround stereo (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-dspf1.tmp to %ProgramFiles(x86)%\audio recorder\audiences\350k multichannel (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-khmef.tmp to %ProgramFiles(x86)%\audio recorder\audiences\350k download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-kvcjj.tmp to %ProgramFiles(x86)%\audio recorder\audiences\2m surround stereo (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-f622f.tmp to %ProgramFiles(x86)%\audio recorder\audiences\2m multichannel (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-ag0ft.tmp to %ProgramFiles(x86)%\audio recorder\audiences\2m download (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-uv8tl.tmp to %ProgramFiles(x86)%\audio recorder\audiences\28k dial-up.rpad
  • from %ProgramFiles(x86)%\audio recorder\lang\is-f565p.tmp to %ProgramFiles(x86)%\audio recorder\lang\waverec_frence.dat
  • from %ProgramFiles(x86)%\audio recorder\audiences\is-36nni.tmp to %ProgramFiles(x86)%\audio recorder\audiences\1m surround stereo (vbr).rpad
  • from %ProgramFiles(x86)%\audio recorder\lang\is-p7sbh.tmp to %ProgramFiles(x86)%\audio recorder\lang\waverec_italian.dat
  • from %ProgramFiles(x86)%\audio recorder\is-o1jnf.tmp to %ProgramFiles(x86)%\audio recorder\ve64.dll
  • from %ProgramFiles(x86)%\audio recorder\is-1bsls.tmp to %ProgramFiles(x86)%\audio recorder\swscale-2.dll
  • from %ProgramFiles(x86)%\audio recorder\is-likt0.tmp to %ProgramFiles(x86)%\audio recorder\swresample-0.dll
  • from %ProgramFiles(x86)%\audio recorder\is-bm8b2.tmp to %ProgramFiles(x86)%\audio recorder\servicectrl.dll
  • from %ProgramFiles(x86)%\audio recorder\is-lrvf4.tmp to %ProgramFiles(x86)%\audio recorder\screenhook.dll
  • from %ProgramFiles(x86)%\audio recorder\is-7sf9p.tmp to %ProgramFiles(x86)%\audio recorder\rmvbencodesync.dll
  • from %ProgramFiles(x86)%\audio recorder\is-f52f5.tmp to %ProgramFiles(x86)%\audio recorder\recwin7.dll
  • from %ProgramFiles(x86)%\audio recorder\is-1k6k3.tmp to %ProgramFiles(x86)%\audio recorder\recordaudio.dll
  • from %ProgramFiles(x86)%\audio recorder\is-0p5th.tmp to %ProgramFiles(x86)%\audio recorder\recodeaudiokernel_old.dll
  • from %ProgramFiles(x86)%\audio recorder\is-kmqt9.tmp to %ProgramFiles(x86)%\audio recorder\recodeaudiokernel.dll
  • from %ProgramFiles(x86)%\audio recorder\is-k5ras.tmp to %ProgramFiles(x86)%\audio recorder\pthreadvc2.dll
  • from %ProgramFiles(x86)%\audio recorder\is-4f5rr.tmp to %ProgramFiles(x86)%\audio recorder\pthreadgc2.dll
  • from %ProgramFiles(x86)%\audio recorder\is-52223.tmp to %ProgramFiles(x86)%\audio recorder\postproc-52.dll
  • from %ProgramFiles(x86)%\audio recorder\is-ik2bj.tmp to %ProgramFiles(x86)%\audio recorder\msvcm90.dll
  • from %ProgramFiles(x86)%\audio recorder\is-gko2b.tmp to %ProgramFiles(x86)%\audio recorder\mp3player.dll
  • from %ProgramFiles(x86)%\audio recorder\is-q62vh.tmp to %ProgramFiles(x86)%\audio recorder\mp3infp.dll
  • from %ProgramFiles(x86)%\audio recorder\is-lib91.tmp to %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt.manifest
  • from %ProgramFiles(x86)%\audio recorder\is-2rf3v.tmp to %ProgramFiles(x86)%\audio recorder\mediaencoderimp.dll
  • from %ProgramFiles(x86)%\audio recorder\is-npvbq.tmp to %ProgramFiles(x86)%\audio recorder\magicskin.dll
  • from %ProgramFiles(x86)%\audio recorder\is-32age.tmp to %ProgramFiles(x86)%\audio recorder\loadernonelevator64.exe
  • from %ProgramFiles(x86)%\audio recorder\is-2js2j.tmp to %ProgramFiles(x86)%\audio recorder\loadernonelevator32.exe
  • from %ProgramFiles(x86)%\audio recorder\is-l6b9m.tmp to %ProgramFiles(x86)%\audio recorder\istask.dll
  • from %ProgramFiles(x86)%\audio recorder\is-ojo1i.tmp to %ProgramFiles(x86)%\audio recorder\intelhw.dll
  • from %ProgramFiles(x86)%\audio recorder\is-8k2jp.tmp to %ProgramFiles(x86)%\audio recorder\installhelp.dll
  • from %ProgramFiles(x86)%\audio recorder\is-9ak32.tmp to %ProgramFiles(x86)%\audio recorder\gsdownload.dll
  • from %ProgramFiles(x86)%\audio recorder\is-c8rjv.tmp to %ProgramFiles(x86)%\audio recorder\gsarservice.exe
  • from %ProgramFiles(x86)%\audio recorder\is-e4r1q.tmp to %ProgramFiles(x86)%\audio recorder\avutil-52.dll
  • from %ProgramFiles(x86)%\audio recorder\is-url2q.tmp to %ProgramFiles(x86)%\audio recorder\avdevice-55.dll
  • from %ProgramFiles(x86)%\audio recorder\is-s9oej.tmp to %ProgramFiles(x86)%\audio recorder\ve32.dll
  • from %ProgramFiles(x86)%\audio recorder\is-tqm62.tmp to %ProgramFiles(x86)%\audio recorder\verify.dll
  • from %ProgramFiles(x86)%\audio recorder\lang\is-gogh4.tmp to %ProgramFiles(x86)%\audio recorder\lang\waverec_chinese(traditional).dat
  • from %ProgramFiles(x86)%\audio recorder\is-2bcqa.tmp to %ProgramFiles(x86)%\audio recorder\wait.gif
  • from %ProgramFiles(x86)%\audio recorder\lang\is-1408h.tmp to %ProgramFiles(x86)%\audio recorder\lang\waverec_japanese.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-2df9f.tmp to %ProgramFiles(x86)%\audio recorder\lang\autosettings_spanish.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-svvs3.tmp to %ProgramFiles(x86)%\audio recorder\lang\autosettings_russian.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-pgv63.tmp to %ProgramFiles(x86)%\audio recorder\lang\autosettings_portugues.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-35q2u.tmp to %ProgramFiles(x86)%\audio recorder\lang\autosettings_frence.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-309lo.tmp to %ProgramFiles(x86)%\audio recorder\lang\autosettings_italian.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-85sj5.tmp to %ProgramFiles(x86)%\audio recorder\lang\autosettings_english.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-7rnmg.tmp to %ProgramFiles(x86)%\audio recorder\lang\autosettings_chinese(traditional).dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-j4pp7.tmp to %ProgramFiles(x86)%\audio recorder\lang\autosettings_japanese.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-ss4nj.tmp to %ProgramFiles(x86)%\audio recorder\lang\audiorecorder.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-7qchn.tmp to %ProgramFiles(x86)%\audio recorder\lang\spanish.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-b2cbj.tmp to %ProgramFiles(x86)%\audio recorder\lang\russian.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-6vkjk.tmp to %ProgramFiles(x86)%\audio recorder\lang\portugues.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-ppma9.tmp to %ProgramFiles(x86)%\audio recorder\lang\frence.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-m9va2.tmp to %ProgramFiles(x86)%\audio recorder\lang\italian.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-mj52m.tmp to %ProgramFiles(x86)%\audio recorder\lang\english.dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-argue.tmp to %ProgramFiles(x86)%\audio recorder\lang\chinese(traditional).dat
  • from %ProgramFiles(x86)%\audio recorder\lang\is-ilat2.tmp to %ProgramFiles(x86)%\audio recorder\lang\japanese.dat
  • from %ProgramFiles(x86)%\audio recorder\is-n12ie.tmp to %ProgramFiles(x86)%\audio recorder\notips.mp3
  • from %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\is-gavj5.tmp to %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\msvcr90.dll
  • from %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\is-chk51.tmp to %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\msvcp90.dll
  • from %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\is-vcafl.tmp to %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\msvcm90.dll
  • from %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\is-h79a8.tmp to %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt\microsoft.vc90.crt.manifest
  • from %ProgramFiles(x86)%\audio recorder\is-4ms3q.tmp to %ProgramFiles(x86)%\audio recorder\xvidcore.dll
  • from %ProgramFiles(x86)%\audio recorder\is-6pk06.tmp to %ProgramFiles(x86)%\audio recorder\wmadecode.dll
  • from %ProgramFiles(x86)%\audio recorder\is-drd43.tmp to %ProgramFiles(x86)%\audio recorder\webrtc.dll
  • from %ProgramFiles(x86)%\audio recorder\is-8ipnn.tmp to %ProgramFiles(x86)%\audio recorder\waverec.dll
  • from %ProgramFiles(x86)%\audio recorder\lang\is-a7iua.tmp to %ProgramFiles(x86)%\audio recorder\lang\waverec_english.dat
  • from %ProgramFiles(x86)%\audio recorder\is-6f1be.tmp to %ProgramFiles(x86)%\audio recorder\audiorecorder.exe
Substitutes the following files
  • %ProgramFiles(x86)%\audio recorder\microsoft.vc90.crt.manifest
  • %ProgramFiles(x86)%\audio recorder\msvcm90.dll
  • %ProgramFiles(x86)%\audio recorder\wait.gif
Network activity
Connects to
  • 'mi####njobs.works':80
TCP
HTTP GET requests
  • http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?43######
HTTP POST requests
  • http://mi####njobs.works/new/net_api
UDP
  • DNS ASK mi####njobs.works
Miscellaneous
Searches for the following windows
  • ClassName: 'z50e19_audio10211Class_z50e19' WindowName: ''
Creates and executes the following
  • '%TEMP%\is-kgvlr.tmp\<File name>.tmp' /SL5="$110188,6988310,354304,<Full path to file>"
  • '%ProgramFiles(x86)%\audio recorder\audiorecorder.exe'
  • '%ProgramFiles(x86)%\audio recorder\audiorecorder.exe' b7a6e7a44962b612cb5ae825cbf51cc9
Executes the following
  • '%WINDIR%\syswow64\schtasks.exe' /Delete /F /TN "AREC1021-1"
  • '%WINDIR%\syswow64\schtasks.exe' /Query

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке