Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.DownLoader33.39945

Добавлен в вирусную базу Dr.Web: 2020-05-09

Описание добавлено:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %WINDIR%\win.ini
Modifies file system
Creates the following files
  • <Current directory>\sandbox\xsandbox.bin.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\vcl250.bpl
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\vclimg250.bpl.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\vclimg250.bpl
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\shfolder.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\shfolder.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\rtl250.bpl.__meta__.__tmp__
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\vcl250.bpl.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\rtl250.bpl
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\axcomponentsrtl.bpl
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\axcomponentsvcl.bpl.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\axcomponentsvcl.bpl
  • <Current directory>\sandbox\stub\driverupdater.exe.manifest.__tmp__
  • <Current directory>\sandbox\stub\driverupdater.exe.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_systeminformationhelper@5.0.0.0\x86_systeminformationhelper@5.0.0.0.manifest.__tmp__
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\axcomponentsrtl.bpl.__meta__.__tmp__
  • <Current directory>\sandbox\roaming\modified\@appdatacommon@\auslogics\driver updater\1.x\logs\checkserialnumber.log
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\localizer.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\localizer.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\driverhiveengine.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverupdaterhelper.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\driverupdaterhelper.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\googleanalyticshelper.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\googleanalyticshelper.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\actioncenterhelper.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\actioncenterhelper.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\rescuecenterhelper.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\rescuecenterhelper.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\systeminformationhelper.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\systeminformationhelper.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\taskschedulerhelper.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\taskschedulerhelper.dll
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\commonforms.site.dll.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\commonforms.site.dll
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_systeminformationhelper@5.0.0.0\systeminformationhelper.manifest.__tmp__
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverhiveengine.dll.__meta__.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_servicemanagerhelper@5.0.0.0\x86_servicemanagerhelper@5.0.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_microsoft.windows.dpinst@5.1.0.0\x86_microsoft.windows.dpinst@5.1.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\servicemanagerhelper.dll_0xa5404127f0485fe07c03cf25ad2993df.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\googleanalyticshelper.dll_0x21664b61c8b38ae386cc51fc43623444.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\driverupdaterhelper.dll_0x70b0a9a9552d0108b705a67ebf632136.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\driverupdater.exe_0x4c557d7008c196d245bc90742c9a6a3b.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\dpinst64.exe_0x39e2002abc2793621b7f48c4f2d67c68.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\dpinst32.exe_0x832625c78155909c9e8a1b008b814dad.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\systeminformationhelper.dll_0x9baadf460a43293d8485f83f9368c5ea.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\commonforms.site.dll_0x37375b0a006c06c25b3226a03baa621f.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\browserhelper.dll_0x70b6465c8844352da622661f1130a97a.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\actioncenterhelper.dll_0x001b38eb8a24537c051dd02d37f6c15a.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\amd64_microsoft.windows.dpinst@5.1.0.0\microsoft.windows.dpinst.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\amd64_microsoft.windows.dpinst@5.1.0.0\amd64_microsoft.windows.dpinst@5.1.0.0.manifest.__tmp__
  • <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverupdater.exe.__meta__.__tmp__
  • <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\driverupdater.exe
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\commonforms.routine.dll_0x377756ad5af2159365f61d1a993b4b74.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\vcl250.bpl_0x3e48184d2733e9acf7dc03cc1e23ff9f.1.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_actioncenterhelper@1.24.0.0\actioncenterhelper.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_actioncenterhelper@1.24.0.0\x86_actioncenterhelper@1.24.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_microsoft.windows.dpinst@5.1.0.0\microsoft.windows.dpinst.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_googleanalyticshelper@3.1.0.0\x86_googleanalyticshelper@3.1.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_googleanalyticshelper@3.1.0.0\googleanalyticshelper.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_driverupdaterhelper@1.24.0.0\x86_driverupdaterhelper@1.24.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_driverupdaterhelper@1.24.0.0\driverupdaterhelper.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_delphiapplication@1.0.0.0\x86_delphiapplication@1.0.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_delphiapplication@1.0.0.0\delphiapplication.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.site@8.3.0.0\x86_commonforms.site@8.3.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.site@8.3.0.0\commonforms.site.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.routine@8.3.0.0\x86_commonforms.routine@8.3.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.routine@8.3.0.0\commonforms.routine.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_browserhelper@5.0.0.0\x86_browserhelper@5.0.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_browserhelper@5.0.0.0\browserhelper.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_auslogics driver updater@1.24.0.0\x86_auslogics driver updater@1.24.0.0.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_auslogics driver updater@1.24.0.0\auslogics driver updater.manifest.__tmp__
  • <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_servicemanagerhelper@5.0.0.0\servicemanagerhelper.manifest.__tmp__
  • <Current directory>\sandbox\roaming\modified\@appdatacommon@\auslogics\driver updater\1.x\logs\driverhiveengine_0.log
Moves the following files
  • from <Current directory>\sandbox\xsandbox.bin.__tmp__ to <Current directory>\sandbox\xsandbox.bin
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\vclimg250.bpl.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\vclimg250.bpl.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\vclimg250.bpl to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\vclimg250.bpl
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\shfolder.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\shfolder.dll.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\shfolder.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\shfolder.dll
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\rtl250.bpl.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\rtl250.bpl.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\rtl250.bpl to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\rtl250.bpl
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\vcl250.bpl to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\vcl250.bpl
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\axcomponentsrtl.bpl.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\axcomponentsrtl.bpl.__meta__
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\axcomponentsvcl.bpl.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\axcomponentsvcl.bpl.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\axcomponentsvcl.bpl to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\axcomponentsvcl.bpl
  • from <Current directory>\sandbox\stub\driverupdater.exe.manifest.__tmp__ to <Current directory>\sandbox\stub\driverupdater.exe.manifest
  • from <Current directory>\sandbox\stub\driverupdater.exe.__tmp__ to <Current directory>\sandbox\stub\driverupdater.exe
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_systeminformationhelper@5.0.0.0\x86_systeminformationhelper@5.0.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_systeminformationhelper@5.0.0.0\x86_systeminformationhelper@5.0.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_systeminformationhelper@5.0.0.0\systeminformationhelper.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_systeminformationhelper@5.0.0.0\systeminformationhelper.manifest
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\axcomponentsrtl.bpl to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\axcomponentsrtl.bpl
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\rescuecenterhelper.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\rescuecenterhelper.dll
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\driverhiveengine.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\driverhiveengine.dll
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\localizer.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\localizer.dll.__meta__
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverupdaterhelper.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverupdaterhelper.dll.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\driverupdaterhelper.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\driverupdaterhelper.dll
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\googleanalyticshelper.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\googleanalyticshelper.dll.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\googleanalyticshelper.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\googleanalyticshelper.dll
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\actioncenterhelper.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\actioncenterhelper.dll.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\actioncenterhelper.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\actioncenterhelper.dll
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_servicemanagerhelper@5.0.0.0\x86_servicemanagerhelper@5.0.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_servicemanagerhelper@5.0.0.0\x86_servicemanagerhelper@5.0.0.0.manifest
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\rescuecenterhelper.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\rescuecenterhelper.dll.__meta__
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\systeminformationhelper.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\systeminformationhelper.dll.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\systeminformationhelper.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\systeminformationhelper.dll
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\taskschedulerhelper.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\taskschedulerhelper.dll.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\taskschedulerhelper.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\taskschedulerhelper.dll
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\commonforms.site.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\commonforms.site.dll.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\commonforms.site.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\commonforms.site.dll
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\vcl250.bpl.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\vcl250.bpl.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\localizer.dll to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\localizer.dll
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_servicemanagerhelper@5.0.0.0\servicemanagerhelper.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_servicemanagerhelper@5.0.0.0\servicemanagerhelper.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_actioncenterhelper@1.24.0.0\actioncenterhelper.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_actioncenterhelper@1.24.0.0\actioncenterhelper.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\servicemanagerhelper.dll_0xa5404127f0485fe07c03cf25ad2993df.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\servicemanagerhelper.dll_0xa5404127f0485fe07c03cf25ad2993df.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\googleanalyticshelper.dll_0x21664b61c8b38ae386cc51fc43623444.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\googleanalyticshelper.dll_0x21664b61c8b38ae386cc51fc43623444.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\driverupdaterhelper.dll_0x70b0a9a9552d0108b705a67ebf632136.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\driverupdaterhelper.dll_0x70b0a9a9552d0108b705a67ebf632136.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\driverupdater.exe_0x4c557d7008c196d245bc90742c9a6a3b.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\driverupdater.exe_0x4c557d7008c196d245bc90742c9a6a3b.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\dpinst64.exe_0x39e2002abc2793621b7f48c4f2d67c68.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\dpinst64.exe_0x39e2002abc2793621b7f48c4f2d67c68.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\dpinst32.exe_0x832625c78155909c9e8a1b008b814dad.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\dpinst32.exe_0x832625c78155909c9e8a1b008b814dad.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\systeminformationhelper.dll_0x9baadf460a43293d8485f83f9368c5ea.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\systeminformationhelper.dll_0x9baadf460a43293d8485f83f9368c5ea.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\commonforms.site.dll_0x37375b0a006c06c25b3226a03baa621f.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\commonforms.site.dll_0x37375b0a006c06c25b3226a03baa621f.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\browserhelper.dll_0x70b6465c8844352da622661f1130a97a.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\browserhelper.dll_0x70b6465c8844352da622661f1130a97a.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\actioncenterhelper.dll_0x001b38eb8a24537c051dd02d37f6c15a.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\actioncenterhelper.dll_0x001b38eb8a24537c051dd02d37f6c15a.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\amd64_microsoft.windows.dpinst@5.1.0.0\microsoft.windows.dpinst.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\amd64_microsoft.windows.dpinst@5.1.0.0\microsoft.windows.dpinst.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\amd64_microsoft.windows.dpinst@5.1.0.0\amd64_microsoft.windows.dpinst@5.1.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\amd64_microsoft.windows.dpinst@5.1.0.0\amd64_microsoft.windows.dpinst@5.1.0.0.manifest
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverupdater.exe.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverupdater.exe.__meta__
  • from <Current directory>\sandbox\local\temp\@programfilesx86@\auslogics\driver updater\driverupdater.exe to <Current directory>\sandbox\local\modified\@programfilesx86@\auslogics\driver updater\driverupdater.exe
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\commonforms.routine.dll_0x377756ad5af2159365f61d1a993b4b74.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\commonforms.routine.dll_0x377756ad5af2159365f61d1a993b4b74.1.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.site@8.3.0.0\commonforms.site.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.site@8.3.0.0\commonforms.site.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_microsoft.windows.dpinst@5.1.0.0\microsoft.windows.dpinst.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_microsoft.windows.dpinst@5.1.0.0\microsoft.windows.dpinst.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_actioncenterhelper@1.24.0.0\x86_actioncenterhelper@1.24.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_actioncenterhelper@1.24.0.0\x86_actioncenterhelper@1.24.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_googleanalyticshelper@3.1.0.0\x86_googleanalyticshelper@3.1.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_googleanalyticshelper@3.1.0.0\x86_googleanalyticshelper@3.1.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_googleanalyticshelper@3.1.0.0\googleanalyticshelper.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_googleanalyticshelper@3.1.0.0\googleanalyticshelper.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_driverupdaterhelper@1.24.0.0\x86_driverupdaterhelper@1.24.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_driverupdaterhelper@1.24.0.0\x86_driverupdaterhelper@1.24.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_driverupdaterhelper@1.24.0.0\driverupdaterhelper.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_driverupdaterhelper@1.24.0.0\driverupdaterhelper.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_delphiapplication@1.0.0.0\x86_delphiapplication@1.0.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_delphiapplication@1.0.0.0\x86_delphiapplication@1.0.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_delphiapplication@1.0.0.0\delphiapplication.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_delphiapplication@1.0.0.0\delphiapplication.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_microsoft.windows.dpinst@5.1.0.0\x86_microsoft.windows.dpinst@5.1.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_microsoft.windows.dpinst@5.1.0.0\x86_microsoft.windows.dpinst@5.1.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.site@8.3.0.0\x86_commonforms.site@8.3.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.site@8.3.0.0\x86_commonforms.site@8.3.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.routine@8.3.0.0\x86_commonforms.routine@8.3.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.routine@8.3.0.0\x86_commonforms.routine@8.3.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.routine@8.3.0.0\commonforms.routine.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_commonforms.routine@8.3.0.0\commonforms.routine.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_browserhelper@5.0.0.0\x86_browserhelper@5.0.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_browserhelper@5.0.0.0\x86_browserhelper@5.0.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_browserhelper@5.0.0.0\browserhelper.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_browserhelper@5.0.0.0\browserhelper.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_auslogics driver updater@1.24.0.0\x86_auslogics driver updater@1.24.0.0.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_auslogics driver updater@1.24.0.0\x86_auslogics driver updater@1.24.0.0.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_auslogics driver updater@1.24.0.0\auslogics driver updater.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\x86_auslogics driver updater@1.24.0.0\auslogics driver updater.manifest
  • from <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\vcl250.bpl_0x3e48184d2733e9acf7dc03cc1e23ff9f.1.manifest.__tmp__ to <Current directory>\sandbox\cache\0x78c6a253f2abf336\sxs\manifests\vcl250.bpl_0x3e48184d2733e9acf7dc03cc1e23ff9f.1.manifest
  • from <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverhiveengine.dll.__meta__.__tmp__ to <Current directory>\sandbox\local\meta\@programfilesx86@\auslogics\driver updater\driverhiveengine.dll.__meta__
Network activity
TCP
HTTP GET requests
  • http://ws.###verhive.com/driverservice.asmx
UDP
  • DNS ASK ws.###verhive.com
Miscellaneous
Creates and executes the following
  • '<Current directory>\sandbox\stub\driverupdater.exe' /864A627C-C6B2-464A-AA13-25D62F282BD8
Executes the following
  • '<SYSTEM32>\vssvc.exe'
  • '<SYSTEM32>\svchost.exe' -k swprv

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке