Защити созданное

Другие наши ресурсы

  • free.drweb.kz — бесплатные утилиты, плагины, информеры
  • av-desk.com — интернет-сервис для поставщиков услуг Dr.Web AV-Desk
  • curenet.drweb.kz — сетевая лечащая утилита Dr.Web CureNet!
Закрыть

Библиотека
Моя библиотека

Чтобы добавить ресурс в библиотеку, войдите в аккаунт.

+ Добавить в библиотеку

Ресурсов: -

Последний: -

Моя библиотека

Поддержка
Круглосуточная поддержка | Правила обращения

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop8.25644

Добавлен в вирусную базу Dr.Web: 2018-06-06

Описание добавлено:

Technical Information

Modifies file system
Creates the following files
  • %TEMP%\ffffffff-gggg-477e-b520-005419850605\setupcli.exe
  • %WINDIR%\syswow64\pclient\uimodules\~glh006b.tmp
  • %WINDIR%\syswow64\pclient\~glh006c.tmp
  • %WINDIR%\syswow64\pclient\uimodules\~glh006d.tmp
  • %WINDIR%\syswow64\pclient\uimodules\~glh006e.tmp
  • %WINDIR%\syswow64\pclient\uimodules\~glh006f.tmp
  • %WINDIR%\syswow64\pclient\~glh0070.tmp
  • %WINDIR%\syswow64\pclient\resource\~glh0071.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0069.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh006a.tmp
  • %WINDIR%\syswow64\pclient\resource\~glh0072.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0075.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0076.tmp
  • %TEMP%\~glh0077.tmp
  • %WINDIR%\syswow64\msvcp90.dll
  • %TEMP%\~glh0078.tmp
  • %WINDIR%\syswow64\msvcr90.dll
  • %TEMP%\~glh0079.tmp
  • %WINDIR%\syswow64\pclient\~glh0073.tmp
  • %WINDIR%\syswow64\pclient\~glh0074.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0068.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0067.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0066.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0054.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0055.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0056.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0057.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0058.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0059.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh005a.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh005b.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0053.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh005c.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh005e.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh005f.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0060.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0061.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0062.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0063.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0064.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0065.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh005d.tmp
  • %WINDIR%\syswow64\pclient\msvcp80.dll
  • %TEMP%\~glh007a.tmp
  • %WINDIR%\syswow64\pclient\msvcr80.dll
  • %WINDIR%\~glh007b.tmp
  • %WINDIR%\syswow64\pclient\uimodules\~glh0094.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0095.tmp
  • %WINDIR%\syswow64\pclient\~glh0096.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0097.tmp
  • %WINDIR%\syswow64\pclient\~glh0098.tmp
  • %WINDIR%\syswow64\pclient\~glh0099.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh009a.tmp
  • %WINDIR%\syswow64\pclient\uimodules\~glh009b.tmp
  • %WINDIR%\syswow64\pclient\~glh009c.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh009d.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh009e.tmp
  • %WINDIR%\syswow64\pclient\~glh009f.tmp
  • %WINDIR%\syswow64\pclient\~glh00a0.tmp
  • %WINDIR%\syswow64\pclient\~glh00a1.tmp
  • %TEMP%\~glh00a2.tmp
  • %WINDIR%\syswow64\pclient\dbghelp.dll
  • <DRIVERS>\~glh00a3.tmp
  • <DRIVERS>\~glh00a4.tmp
  • <SYSTEM32>\~glh00a5.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0093.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0091.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0092.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0090.tmp
  • %WINDIR%\syswow64\pclient\~glh007d.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh007e.tmp
  • %WINDIR%\syswow64\pclient\~glh007f.tmp
  • %WINDIR%\syswow64\~glh0080.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0081.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0082.tmp
  • %WINDIR%\syswow64\pclient\~glh0083.tmp
  • %WINDIR%\syswow64\pclient\uimodules\~glh0084.tmp
  • %WINDIR%\syswow64\pclient\~glh0085.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0086.tmp
  • %WINDIR%\syswow64\pclient\uimodules\~glh0087.tmp
  • %WINDIR%\syswow64\pclient\uimodules\~glh0088.tmp
  • %WINDIR%\syswow64\pclient\~glh0089.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh008a.tmp
  • %WINDIR%\syswow64\pclient\~glh008b.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh008c.tmp
  • %WINDIR%\syswow64\pclient\~glh008d.tmp
  • %WINDIR%\syswow64\pclient\~glh008e.tmp
  • %WINDIR%\syswow64\pclient\~glh008f.tmp
  • <DRIVERS>\~glh00a6.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0052.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0051.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0050.tmp
  • C:\phenix_client\~glh0011.tmp
  • C:\phenix_client\~glh0012.tmp
  • %ProgramFiles(x86)%\gsc\install\phenixclient.log
  • %TEMP%\~glh0013.tmp
  • %ProgramFiles(x86)%\gsc\install\~glbs383.tmp
  • %TEMP%\~glh0014.tmp
  • %WINDIR%\~glh0015.tmp
  • C:\phenix_client\~glh000f.tmp
  • C:\phenix_client\~glh0010.tmp
  • %TEMP%\~glh0016.tmp
  • %WINDIR%\syswow64\pclient\~glh001a.tmp
  • %WINDIR%\syswow64\pclient\~glh001b.tmp
  • %WINDIR%\syswow64\pclient\~glh001c.tmp
  • %WINDIR%\syswow64\pclient\~glh001d.tmp
  • %WINDIR%\syswow64\pclient\~glh001e.tmp
  • %WINDIR%\syswow64\pclient\~glh001f.tmp
  • %WINDIR%\syswow64\pclient\~glh0020.tmp
  • %WINDIR%\~glh0018.tmp
  • %WINDIR%\syswow64\pclient\~glh0019.tmp
  • C:\phenix_client\~glh000e.tmp
  • C:\phenix_client\~glh000d.tmp
  • C:\phenix_client\~glh000c.tmp
  • %TEMP%\22c36d54-2b65-4a89-b62c-14a9e562383c\1mid.xml
  • %TEMP%\22c36d54-2b65-4a89-b62c-14a9e562383c\phenixcli.exe
  • %TEMP%\glcef7c.tmp
  • %TEMP%\gljef9c.tmp
  • %TEMP%\glkf1b0.tmp
  • %TEMP%\glg226.tmp
  • %TEMP%\~glh0000.tmp
  • C:\phenix_client\~glh0001.tmp
  • %TEMP%\22c36d54-2b65-4a89-b62c-14a9e562383c\setup.ini
  • C:\phenix_client\~glh0002.tmp
  • C:\phenix_client\~glh0004.tmp
  • C:\phenix_client\~glh0005.tmp
  • C:\phenix_client\~glh0006.tmp
  • C:\phenix_client\~glh0007.tmp
  • C:\phenix_client\~glh0008.tmp
  • C:\phenix_client\~glh0009.tmp
  • C:\phenix_client\~glh000a.tmp
  • C:\phenix_client\~glh000b.tmp
  • C:\phenix_client\~glh0003.tmp
  • %WINDIR%\syswow64\pclient\~glh0021.tmp
  • %WINDIR%\syswow64\pclient\~glh0022.tmp
  • %WINDIR%\syswow64\pclient\~glh0023.tmp
  • %WINDIR%\syswow64\pclient\~glh0024.tmp
  • %WINDIR%\syswow64\pclient\~glh003c.tmp
  • %WINDIR%\syswow64\pclient\languagedata\~glh003d.tmp
  • %WINDIR%\syswow64\pclient\browseclassinfo\~glh003e.tmp
  • %WINDIR%\syswow64\pclient\~glh003f.tmp
  • %WINDIR%\syswow64\pclient\~glh0040.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0041.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0042.tmp
  • %WINDIR%\syswow64\pclient\inf\~glh0043.tmp
  • %WINDIR%\syswow64\pclient\inf\~glh0044.tmp
  • %WINDIR%\syswow64\pclient\~glh0045.tmp
  • %WINDIR%\syswow64\pclient\~glh0046.tmp
  • %WINDIR%\syswow64\pclient\~glh0047.tmp
  • %WINDIR%\syswow64\pclient\~glh0048.tmp
  • %WINDIR%\syswow64\pclient\~glh0049.tmp
  • %WINDIR%\syswow64\pclient\~glh004a.tmp
  • %WINDIR%\syswow64\pclient\~glh004b.tmp
  • %WINDIR%\syswow64\pclient\~glh004c.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh004d.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh004e.tmp
  • %WINDIR%\syswow64\pclient\~glh003b.tmp
  • %WINDIR%\syswow64\pclient\~glh0039.tmp
  • %WINDIR%\syswow64\pclient\~glh003a.tmp
  • %WINDIR%\syswow64\pclient\~glh0038.tmp
  • %WINDIR%\syswow64\pclient\~glh0025.tmp
  • %WINDIR%\syswow64\pclient\~glh0026.tmp
  • %WINDIR%\syswow64\pclient\~glh0027.tmp
  • %WINDIR%\syswow64\pclient\~glh0028.tmp
  • %WINDIR%\syswow64\pclient\~glh0029.tmp
  • %WINDIR%\syswow64\pclient\~glh002a.tmp
  • %WINDIR%\syswow64\pclient\~glh002b.tmp
  • %WINDIR%\syswow64\pclient\~glh002c.tmp
  • %WINDIR%\syswow64\pclient\~glh002d.tmp
  • %WINDIR%\syswow64\pclient\~glh002e.tmp
  • %WINDIR%\syswow64\pclient\~glh002f.tmp
  • %WINDIR%\syswow64\pclient\~glh0030.tmp
  • %WINDIR%\syswow64\pclient\~glh0031.tmp
  • %WINDIR%\syswow64\pclient\~glh0032.tmp
  • %WINDIR%\syswow64\pclient\~glh0033.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0034.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh0035.tmp
  • %WINDIR%\syswow64\pclient\~glh0036.tmp
  • %WINDIR%\syswow64\pclient\~glh0037.tmp
  • %WINDIR%\syswow64\pclient\modules\~glh004f.tmp
  • <DRIVERS>\~glh00a7.tmp
Deletes the following files
  • %ProgramFiles(x86)%\gsc\install\phenixclient.log
  • %WINDIR%\bbclp.exe
  • %WINDIR%\syswow64\pclient\bllog.dll
  • %WINDIR%\syswow64\pclient\modules\equipmgr.dll
Moves the following files
  • from %TEMP%\~glh0000.tmp to %TEMP%\productinfo.dat
  • from %WINDIR%\syswow64\pclient\~glh006c.tmp to %WINDIR%\syswow64\pclient\blui.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh006d.tmp to %WINDIR%\syswow64\pclient\uimodules\sendmessage.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh006e.tmp to %WINDIR%\syswow64\pclient\uimodules\shutdown.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh006f.tmp to %WINDIR%\syswow64\pclient\uimodules\patchui.dll
  • from %WINDIR%\syswow64\pclient\~glh0070.tmp to %WINDIR%\syswow64\pclient\pureres.dll
  • from %WINDIR%\syswow64\pclient\resource\~glh0071.tmp to %WINDIR%\syswow64\pclient\resource\pureres.en-us.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh006a.tmp to %WINDIR%\syswow64\pclient\modules\gscpolicy.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh006b.tmp to %WINDIR%\syswow64\pclient\uimodules\admindialog.dll
  • from %WINDIR%\syswow64\pclient\resource\~glh0072.tmp to %WINDIR%\syswow64\pclient\resource\pureres.zh-tw.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0075.tmp to %WINDIR%\syswow64\pclient\modules\ftpsvr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0076.tmp to %WINDIR%\syswow64\pclient\modules\ftpdown.dll
  • from %TEMP%\~glh0077.tmp to %TEMP%\msvcp90.dll
  • from %TEMP%\~glh0078.tmp to %TEMP%\msvcr90.dll
  • from %TEMP%\~glh0079.tmp to %TEMP%\msvcp80.dll
  • from %TEMP%\~glh007a.tmp to %TEMP%\msvcr80.dll
  • from %WINDIR%\syswow64\pclient\~glh0073.tmp to %WINDIR%\syswow64\pclient\krnlmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh0074.tmp to %WINDIR%\syswow64\pclient\netmgr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh007e.tmp to %WINDIR%\syswow64\pclient\modules\ipmcli.dll
  • from %WINDIR%\syswow64\pclient\~glh007d.tmp to %WINDIR%\syswow64\pclient\ipmdll.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0067.tmp to %WINDIR%\syswow64\pclient\modules\assetmgr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0059.tmp to %WINDIR%\syswow64\pclient\modules\ipbind.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh005a.tmp to %WINDIR%\syswow64\pclient\modules\offlinepolicy.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh005b.tmp to %WINDIR%\syswow64\pclient\modules\runproc.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh005c.tmp to %WINDIR%\syswow64\pclient\modules\setcpname.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh005d.tmp to %WINDIR%\syswow64\pclient\modules\website.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0068.tmp to %WINDIR%\syswow64\pclient\modules\sysmanage.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0056.tmp to %WINDIR%\syswow64\pclient\modules\baseinfo.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0069.tmp to %WINDIR%\syswow64\pclient\modules\rmtast.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh005e.tmp to %WINDIR%\syswow64\pclient\modules\netsetup.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0062.tmp to %WINDIR%\syswow64\pclient\modules\vaa.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0063.tmp to %WINDIR%\syswow64\pclient\modules\dialmgr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0064.tmp to %WINDIR%\syswow64\pclient\modules\iospc.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0065.tmp to %WINDIR%\syswow64\pclient\modules\netshare.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0066.tmp to %WINDIR%\syswow64\pclient\modules\setuputl.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh005f.tmp to %WINDIR%\syswow64\pclient\modules\batchnet.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0060.tmp to %WINDIR%\syswow64\pclient\modules\sysadmin.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0061.tmp to %WINDIR%\syswow64\pclient\modules\saveret.dll
  • from %WINDIR%\syswow64\pclient\~glh002a.tmp to %WINDIR%\syswow64\pclient\blproc.dll
  • from %WINDIR%\syswow64\pclient\~glh007f.tmp to %WINDIR%\syswow64\pclient\block.exe
  • from %WINDIR%\syswow64\pclient\~glh0096.tmp to %WINDIR%\syswow64\pclient\ulock.exe
  • from %WINDIR%\syswow64\pclient\~glh0098.tmp to %WINDIR%\syswow64\pclient\buy.xml
  • from %WINDIR%\syswow64\pclient\~glh0099.tmp to %WINDIR%\syswow64\pclient\gscukeybase.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh009a.tmp to %WINDIR%\syswow64\pclient\modules\fcscreen.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh009b.tmp to %WINDIR%\syswow64\pclient\uimodules\copyscreen.dll
  • from %WINDIR%\syswow64\pclient\~glh009c.tmp to %WINDIR%\syswow64\pclient\wmvfile.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0095.tmp to %WINDIR%\syswow64\pclient\modules\usbkeycontrol.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh009d.tmp to %WINDIR%\syswow64\pclient\modules\healthmoniter.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0097.tmp to %WINDIR%\syswow64\pclient\modules\ukeyaudit.dll
  • from %WINDIR%\syswow64\pclient\~glh009f.tmp to %WINDIR%\syswow64\pclient\gscinternetexplorer.exe
  • from %WINDIR%\syswow64\pclient\~glh00a1.tmp to %WINDIR%\syswow64\pclient\uninst.exe
  • from %TEMP%\~glh00a2.tmp to %TEMP%\dbghelp.dll
  • from <DRIVERS>\~glh00a3.tmp to <DRIVERS>\devmgr.sys
  • from <DRIVERS>\~glh00a4.tmp to <DRIVERS>\nmfmgr.sys
  • from <SYSTEM32>\~glh00a5.tmp to <SYSTEM32>\schknmf.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh009e.tmp to %WINDIR%\syswow64\pclient\modules\serviceaudit.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh0094.tmp to %WINDIR%\syswow64\pclient\uimodules\regclientui.dll
  • from %WINDIR%\syswow64\pclient\~glh00a0.tmp to %WINDIR%\syswow64\pclient\clientscript.xml
  • from %WINDIR%\syswow64\pclient\modules\~glh0093.tmp to %WINDIR%\syswow64\pclient\modules\cdwmgr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0092.tmp to %WINDIR%\syswow64\pclient\modules\admtcmgr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0081.tmp to %WINDIR%\syswow64\pclient\modules\prtmgm.dll
  • from %WINDIR%\syswow64\pclient\~glh0083.tmp to %WINDIR%\syswow64\pclient\safedisk.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh0084.tmp to %WINDIR%\syswow64\pclient\uimodules\safetray.dll
  • from %WINDIR%\syswow64\pclient\~glh0085.tmp to %WINDIR%\syswow64\pclient\devhelper.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0086.tmp to %WINDIR%\syswow64\pclient\modules\scanweb.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh0087.tmp to %WINDIR%\syswow64\pclient\uimodules\scanwebu.dll
  • from %WINDIR%\syswow64\pclient\uimodules\~glh0088.tmp to %WINDIR%\syswow64\pclient\uimodules\repairospatch.dll
  • from %WINDIR%\syswow64\pclient\~glh0089.tmp to %WINDIR%\syswow64\pclient\tcmtddl.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0082.tmp to %WINDIR%\syswow64\pclient\modules\syssafe.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh008a.tmp to %WINDIR%\syswow64\pclient\modules\limvisit.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh008c.tmp to %WINDIR%\syswow64\pclient\modules\sysreslist.dll
  • from %WINDIR%\syswow64\pclient\~glh008d.tmp to %WINDIR%\syswow64\pclient\wm_hooks.dll
  • from %WINDIR%\syswow64\pclient\~glh008e.tmp to %WINDIR%\syswow64\pclient\svctrl.exe
  • from %WINDIR%\syswow64\pclient\~glh008f.tmp to %WINDIR%\syswow64\pclient\schook.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0090.tmp to %WINDIR%\syswow64\pclient\modules\osevent.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0091.tmp to %WINDIR%\syswow64\pclient\modules\sysuser.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0055.tmp to %WINDIR%\syswow64\pclient\modules\appmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh008b.tmp to %WINDIR%\syswow64\pclient\sql2ksp4setup.iss
  • from %WINDIR%\syswow64\pclient\modules\~glh0057.tmp to %WINDIR%\syswow64\pclient\modules\equipmgr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0054.tmp to %WINDIR%\syswow64\pclient\modules\deskmgr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0053.tmp to %WINDIR%\syswow64\pclient\modules\ieconfig.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0052.tmp to %WINDIR%\syswow64\pclient\modules\tranfile.dll
  • from %WINDIR%\syswow64\pclient\~glh001a.tmp to %WINDIR%\syswow64\pclient\pcit.exe
  • from %WINDIR%\syswow64\pclient\~glh001b.tmp to %WINDIR%\syswow64\pclient\loaddllinfo.xml
  • from %WINDIR%\syswow64\pclient\~glh001c.tmp to %WINDIR%\syswow64\pclient\bldev_x64.dll
  • from %WINDIR%\syswow64\pclient\~glh001d.tmp to %WINDIR%\syswow64\pclient\blfile_x64.dll
  • from %WINDIR%\syswow64\pclient\~glh001e.tmp to %WINDIR%\syswow64\pclient\blnet_x64.dll
  • from %WINDIR%\~glh0015.tmp to %WINDIR%\bbclp.exe
  • from %TEMP%\~glh0013.tmp to %TEMP%\iospc.dll
  • from %WINDIR%\syswow64\pclient\~glh0019.tmp to %WINDIR%\syswow64\pclient\bllog.dll
  • from %WINDIR%\syswow64\pclient\~glh001f.tmp to %WINDIR%\syswow64\pclient\blproc_x64.dll
  • from %WINDIR%\syswow64\pclient\~glh0023.tmp to %WINDIR%\syswow64\pclient\scrtobj_x64.dll
  • from %WINDIR%\syswow64\pclient\~glh0024.tmp to %WINDIR%\syswow64\pclient\blbase.dll
  • from %WINDIR%\syswow64\pclient\~glh0025.tmp to %WINDIR%\syswow64\pclient\bldev.dll
  • from %WINDIR%\syswow64\pclient\~glh0026.tmp to %WINDIR%\syswow64\pclient\blscr.dll
  • from %WINDIR%\syswow64\pclient\~glh0027.tmp to %WINDIR%\syswow64\pclient\scrtobj.dll
  • from %WINDIR%\syswow64\pclient\~glh0020.tmp to %WINDIR%\syswow64\pclient\blreg_x64.dll
  • from %WINDIR%\syswow64\pclient\~glh0021.tmp to %WINDIR%\syswow64\pclient\blsys_x64.dll
  • from %WINDIR%\syswow64\pclient\~glh0022.tmp to %WINDIR%\syswow64\pclient\fmlib_x64.dll
  • from %TEMP%\~glh0014.tmp to %TEMP%\bllog.dll
  • from C:\phenix_client\~glh0012.tmp to C:\phenix_client\fmlib.dll
  • from %WINDIR%\syswow64\pclient\~glh0028.tmp to %WINDIR%\syswow64\pclient\blfile.dll
  • from C:\phenix_client\~glh0002.tmp to C:\phenix_client\instwse.dll
  • from C:\phenix_client\~glh0003.tmp to C:\phenix_client\pcit.exe
  • from C:\phenix_client\~glh0004.tmp to C:\phenix_client\setuputl.dll
  • from C:\phenix_client\~glh0005.tmp to C:\phenix_client\iospc.dll
  • from C:\phenix_client\~glh0006.tmp to C:\phenix_client\pfmdb.dll
  • from C:\phenix_client\~glh0007.tmp to C:\phenix_client\engsync.dll
  • from C:\phenix_client\~glh0008.tmp to C:\phenix_client\blbase.dll
  • from C:\phenix_client\~glh0001.tmp to C:\phenix_client\bllog.dll
  • from C:\phenix_client\~glh0009.tmp to C:\phenix_client\bldev.dll
  • from C:\phenix_client\~glh000b.tmp to C:\phenix_client\scrtobj.dll
  • from C:\phenix_client\~glh000c.tmp to C:\phenix_client\blfile.dll
  • from C:\phenix_client\~glh000d.tmp to C:\phenix_client\blnet.dll
  • from C:\phenix_client\~glh000e.tmp to C:\phenix_client\blproc.dll
  • from C:\phenix_client\~glh000f.tmp to C:\phenix_client\blreg.dll
  • from C:\phenix_client\~glh0010.tmp to C:\phenix_client\blsys.dll
  • from C:\phenix_client\~glh0011.tmp to C:\phenix_client\blalgo.dll
  • from C:\phenix_client\~glh000a.tmp to C:\phenix_client\blscr.dll
  • from <DRIVERS>\~glh00a6.tmp to <DRIVERS>\netmgr.sys
  • from %WINDIR%\syswow64\~glh0080.tmp to %WINDIR%\syswow64\schk.dll
  • from %WINDIR%\syswow64\pclient\~glh0029.tmp to %WINDIR%\syswow64\pclient\blnet.dll
  • from %WINDIR%\syswow64\pclient\~glh002d.tmp to %WINDIR%\syswow64\pclient\blalgo.dll
  • from %WINDIR%\syswow64\pclient\inf\~glh0044.tmp to %WINDIR%\syswow64\pclient\inf\nmfmgr_m.inf
  • from %WINDIR%\syswow64\pclient\~glh0045.tmp to %WINDIR%\syswow64\pclient\ats.xml
  • from %WINDIR%\syswow64\pclient\~glh0046.tmp to %WINDIR%\syswow64\pclient\lpst.xml
  • from %WINDIR%\syswow64\pclient\~glh0047.tmp to %WINDIR%\syswow64\pclient\init.xml
  • from %WINDIR%\syswow64\pclient\~glh0048.tmp to %WINDIR%\syswow64\pclient\specialapp.xml
  • from %WINDIR%\syswow64\pclient\modules\~glh0041.tmp to %WINDIR%\syswow64\pclient\modules\gnaccltmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh0049.tmp to %WINDIR%\syswow64\pclient\ftdump.xml
  • from %WINDIR%\syswow64\pclient\inf\~glh0043.tmp to %WINDIR%\syswow64\pclient\inf\nmfmgr.inf
  • from %WINDIR%\syswow64\pclient\~glh004b.tmp to %WINDIR%\syswow64\pclient\mid.xml
  • from %WINDIR%\syswow64\pclient\modules\~glh004d.tmp to %WINDIR%\syswow64\pclient\modules\pfmdata.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh004e.tmp to %WINDIR%\syswow64\pclient\modules\softmanage.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh004f.tmp to %WINDIR%\syswow64\pclient\modules\registry.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0050.tmp to %WINDIR%\syswow64\pclient\modules\fluxmgr.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0051.tmp to %WINDIR%\syswow64\pclient\modules\patchmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh004a.tmp to %WINDIR%\syswow64\pclient\lps.xml
  • from %TEMP%\~glh0016.tmp to %TEMP%\pcit.exe
  • from %WINDIR%\syswow64\pclient\~glh004c.tmp to %WINDIR%\syswow64\pclient\nethelptools_sc.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0042.tmp to %WINDIR%\syswow64\pclient\modules\pluginmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh0040.tmp to %WINDIR%\syswow64\pclient\nmfmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh003f.tmp to %WINDIR%\syswow64\pclient\findandsendmessage.exe
  • from %WINDIR%\syswow64\pclient\~glh002e.tmp to %WINDIR%\syswow64\pclient\fmlib.dll
  • from %WINDIR%\syswow64\pclient\~glh002f.tmp to %WINDIR%\syswow64\pclient\pfmcomm.dll
  • from %WINDIR%\syswow64\pclient\~glh0030.tmp to %WINDIR%\syswow64\pclient\pfmscript.dll
  • from %WINDIR%\syswow64\pclient\~glh0031.tmp to %WINDIR%\syswow64\pclient\pfmtask.dll
  • from %WINDIR%\syswow64\pclient\~glh0032.tmp to %WINDIR%\syswow64\pclient\pfmtransmit.dll
  • from %WINDIR%\syswow64\pclient\~glh0033.tmp to %WINDIR%\syswow64\pclient\pnpmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh002c.tmp to %WINDIR%\syswow64\pclient\blsys.dll
  • from %WINDIR%\syswow64\pclient\modules\~glh0034.tmp to %WINDIR%\syswow64\pclient\modules\cltmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh0036.tmp to %WINDIR%\syswow64\pclient\devmgr.dll
  • from %WINDIR%\syswow64\pclient\~glh0038.tmp to %WINDIR%\syswow64\pclient\scclient.exe
  • from %WINDIR%\syswow64\pclient\~glh0039.tmp to %WINDIR%\syswow64\pclient\iobios.dll
  • from %WINDIR%\syswow64\pclient\~glh003a.tmp to %WINDIR%\syswow64\pclient\iobios125.dll
  • from %WINDIR%\syswow64\pclient\~glh003b.tmp to %WINDIR%\syswow64\pclient\scguardc.exe
  • from %WINDIR%\syswow64\pclient\~glh003c.tmp to %WINDIR%\syswow64\pclient\sccltui.exe
  • from %WINDIR%\syswow64\pclient\languagedata\~glh003d.tmp to %WINDIR%\syswow64\pclient\languagedata\languagetranslate.xml
  • from %WINDIR%\syswow64\pclient\modules\~glh0035.tmp to %WINDIR%\syswow64\pclient\modules\pfmtimer.dll
  • from %WINDIR%\syswow64\pclient\browseclassinfo\~glh003e.tmp to %WINDIR%\syswow64\pclient\browseclassinfo\cookiesinfo.xml
  • from %WINDIR%\syswow64\pclient\~glh002b.tmp to %WINDIR%\syswow64\pclient\blreg.dll
  • from <DRIVERS>\~glh00a7.tmp to <DRIVERS>\krnlmgr.sys
Substitutes the following files
  • %ProgramFiles(x86)%\gsc\install\phenixclient.log
  • %ProgramFiles(x86)%\gsc\install\~glbs383.tmp
  • %WINDIR%\bbclp.exe
  • %WINDIR%\syswow64\pclient\bllog.dll
  • %WINDIR%\syswow64\pclient\modules\equipmgr.dll
Miscellaneous
Creates and executes the following
  • '%TEMP%\ffffffff-gggg-477e-b520-005419850605\setupcli.exe'
  • '%WINDIR%\syswow64\pclient\pcit.exe' -SetReg "HKEY_LOCAL_MACHINE" "SOFTWARE\Microsoft\Windows\CurrentVersion" "PhenixCltSetupFlag" 1 "1"
  • '%WINDIR%\syswow64\pclient\pcit.exe' -SetReg "HKEY_LOCAL_MACHINE" "SOFTWARE\Lenovo\GscPhenix" "InstallDir" "<SYSTEM32>\Pclient" "0"
  • '%WINDIR%\syswow64\pclient\pcit.exe' -SetReg "HKEY_LOCAL_MACHINE" "SOFTWARE\Lenovo\GscPhenix" "DisplayName" "SmartConfig Phenix Client" "0"
  • '%WINDIR%\syswow64\pclient\pcit.exe' -SetReg "HKEY_LOCAL_MACHINE" "SOFTWARE\Lenovo\GscPhenix" "DisplayVersion" "62300" "1"
  • '%WINDIR%\syswow64\pclient\pcit.exe' -findfile <DRIVERS>\devmgr.sys
  • '%WINDIR%\syswow64\pclient\pcit.exe' -userpswchanage
  • '%WINDIR%\syswow64\pclient\pcit.exe' -cuthook
  • 'C:\phenix_client\pcit.exe' -osis64
  • '%WINDIR%\syswow64\pclient\pcit.exe' -SetReg HKEY_LOCAL_MACHINE SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IpFilterDriver "" "Driver Group" 0
  • '%WINDIR%\syswow64\pclient\pcit.exe' -StartProcess -hw <SYSTEM32>\Pclient\pcit.exe "-SetReg "HKEY_LOCAL_MACHINE" "SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IpFilterDriver" \"\" \"Driver Group\" "0""
  • '%WINDIR%\syswow64\pclient\pcit.exe' -v 52
  • '%WINDIR%\syswow64\pclient\pcit.exe' -v 70
  • '%WINDIR%\syswow64\pclient\pcit.exe' -v 61
  • '%WINDIR%\syswow64\pclient\pcit.exe' -v 60
  • '%WINDIR%\syswow64\pclient\pcit.exe' -v 51
  • 'C:\phenix_client\pcit.exe' -cltbadpnpdlls 0
  • 'C:\phenix_client\pcit.exe' -k "<SYSTEM32>\Pclient\Block.exe"
  • 'C:\phenix_client\pcit.exe' -k "<SYSTEM32>\Pclient\Svctrl.exe"
  • 'C:\phenix_client\pcit.exe' -k "<SYSTEM32>\Pclient\sccltui.exe"
  • 'C:\phenix_client\pcit.exe' -k "<SYSTEM32>\Pclient\scclient.exe"
  • 'C:\phenix_client\pcit.exe' -k "<SYSTEM32>\Pclient\scguardc.exe"
  • 'C:\phenix_client\pcit.exe' -virtual
  • '%WINDIR%\bbclp.exe'
  • 'C:\phenix_client\pcit.exe' -xpe
  • 'C:\phenix_client\pcit.exe' -DelReg "HKEY_LOCAL_MACHINE" "SOFTWARE\Microsoft\Windows\CurrentVersion" "DomainSetup"
  • 'C:\phenix_client\pcit.exe' -ChkUsr
  • '%TEMP%\22c36d54-2b65-4a89-b62c-14a9e562383c\phenixcli.exe'
  • '%WINDIR%\syswow64\pclient\pcit.exe' -SetReg "HKEY_LOCAL_MACHINE" "SOFTWARE\Microsoft\Windows\CurrentVersion" "nmfflag" 1 "1"
  • '%WINDIR%\syswow64\pclient\pcit.exe' -installinf nmfmgr.inf nmfmgr_m.inf "GSC nmfmgr Driver" "%WINDIR%\SysWOW64\schknmf.dll"
Executes the following
  • 'C:\phenix_client\pcit.exe' -ChkUsr' (with hidden window)
  • '%WINDIR%\bbclp.exe' ' (with hidden window)
  • 'C:\phenix_client\pcit.exe' -virtual' (with hidden window)
  • 'C:\phenix_client\pcit.exe' -cltbadpnpdlls 0' (with hidden window)
  • '%WINDIR%\syswow64\pclient\pcit.exe' -StartProcess -hw <SYSTEM32>\Pclient\pcit.exe "-SetReg "HKEY_LOCAL_MACHINE" "SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IpFilterDriver" \"\" \"Driver Group\" "0""' (with hidden window)
  • '%WINDIR%\syswow64\pclient\pcit.exe' -SetReg HKEY_LOCAL_MACHINE SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IpFilterDriver "" "Driver Group" 0' (with hidden window)
  • 'C:\phenix_client\pcit.exe' -osis64' (with hidden window)
  • '%WINDIR%\syswow64\pclient\pcit.exe' -cuthook' (with hidden window)
  • '%WINDIR%\syswow64\pclient\pcit.exe' -userpswchanage' (with hidden window)
  • '%WINDIR%\syswow64\pclient\pcit.exe' -SetReg "HKEY_LOCAL_MACHINE" "SOFTWARE\Microsoft\Windows\CurrentVersion" "nmfflag" 1 "1"' (with hidden window)
  • '%WINDIR%\syswow64\pclient\pcit.exe' -installinf nmfmgr.inf nmfmgr_m.inf "GSC nmfmgr Driver" "%WINDIR%\SysWOW64\schknmf.dll"' (with hidden window)
  • '%WINDIR%\syswow64\pclient\instdrv.exe' -uninstall gsc_nmfmgr' (with hidden window)
  • '%WINDIR%\syswow64\pclient\instdrv.exe' -install %WINDIR%\inf\nmfmgr.inf gsc_nmfmgr' (with hidden window)

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке