マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.DownLoader26.11338

Added to the Dr.Web virus database: 2018-01-19

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%APPDATA%\ComObject\update.exe" about:robots'
Modifies file system:
Creates the following files:
  • %APPDATA%\ComObject\res\is-158BI.tmp
  • %APPDATA%\ComObject\res\is-BEDG0.tmp
  • %APPDATA%\ComObject\res\is-LOJKQ.tmp
  • %APPDATA%\ComObject\res\is-CUIAN.tmp
  • %APPDATA%\ComObject\res\is-8AVA9.tmp
  • %APPDATA%\ComObject\res\is-SIACJ.tmp
  • %APPDATA%\ComObject\res\is-KB27D.tmp
  • %APPDATA%\ComObject\res\is-SDP2L.tmp
  • %APPDATA%\ComObject\res\is-U15Q3.tmp
  • %APPDATA%\ComObject\res\is-OES2M.tmp
  • %APPDATA%\ComObject\res\is-E9IB0.tmp
  • %APPDATA%\ComObject\res\is-7CBJK.tmp
  • %APPDATA%\ComObject\res\is-OC0ID.tmp
  • %APPDATA%\ComObject\res\is-08UV9.tmp
  • %APPDATA%\ComObject\res\is-9VJMT.tmp
  • %APPDATA%\ComObject\res\is-A1RA9.tmp
  • %APPDATA%\ComObject\res\entityTables\is-OR63D.tmp
  • %APPDATA%\ComObject\res\entityTables\is-559J9.tmp
  • %APPDATA%\ComObject\res\dtd\is-8DF2S.tmp
  • %APPDATA%\ComObject\res\dtd\is-4T9T3.tmp
  • %APPDATA%\ComObject\res\entityTables\is-245NU.tmp
  • %APPDATA%\ComObject\res\entityTables\is-S9BSU.tmp
  • %APPDATA%\ComObject\res\entityTables\is-ONJJP.tmp
  • %APPDATA%\ComObject\res\entityTables\is-6B8CJ.tmp
  • %APPDATA%\ComObject\res\is-HC47B.tmp
  • %APPDATA%\ComObject\res\is-8G7GR.tmp
  • %APPDATA%\ComObject\res\is-9655E.tmp
  • %APPDATA%\ComObject\res\is-IA43S.tmp
  • %APPDATA%\ComObject\res\is-56OFF.tmp
  • %APPDATA%\ComObject\res\is-M33SG.tmp
  • %APPDATA%\ComObject\res\is-67DPM.tmp
  • %APPDATA%\ComObject\res\is-GA243.tmp
  • %APPDATA%\ComObject\res\is-JNJ6G.tmp
  • %APPDATA%\ComObject\modules\is-MDUEN.tmp
  • %APPDATA%\ComObject\modules\is-0QD7J.tmp
  • %APPDATA%\ComObject\modules\is-TTBBJ.tmp
  • %APPDATA%\ComObject\modules\is-7P3QD.tmp
  • %APPDATA%\ComObject\modules\is-8AGBI.tmp
  • %APPDATA%\ComObject\modules\is-I3NUM.tmp
  • %APPDATA%\ComObject\modules\is-B9F46.tmp
  • %APPDATA%\ComObject\modules\is-CGOKC.tmp
  • %APPDATA%\ComObject\modules\is-G9IJT.tmp
  • %APPDATA%\ComObject\modules\is-LVP3D.tmp
  • %APPDATA%\ComObject\modules\is-5ALP3.tmp
  • %APPDATA%\ComObject\modules\is-4HPFR.tmp
  • %APPDATA%\ComObject\modules\is-1LKBE.tmp
  • %APPDATA%\ComObject\modules\is-QOA03.tmp
  • %APPDATA%\ComObject\modules\is-1EDP5.tmp
  • %APPDATA%\ComObject\modules\is-662F5.tmp
  • %APPDATA%\ComObject\res\is-C390J.tmp
  • %APPDATA%\ComObject\res\is-NGPSV.tmp
  • %APPDATA%\ComObject\res\is-OVAKA.tmp
  • %APPDATA%\ComObject\res\is-IGJ1V.tmp
  • %APPDATA%\ComObject\res\is-IMOT0.tmp
  • %APPDATA%\ComObject\res\is-6UCHS.tmp
  • %APPDATA%\ComObject\res\is-4G5QV.tmp
  • %APPDATA%\ComObject\res\is-KFV28.tmp
  • %APPDATA%\ComObject\res\is-IJ5JK.tmp
  • %APPDATA%\ComObject\res\is-05BU4.tmp
  • %APPDATA%\ComObject\plugins\is-13QQL.tmp
  • %APPDATA%\ComObject\plugins\is-VI1JP.tmp
  • %APPDATA%\ComObject\res\is-M43SO.tmp
  • %APPDATA%\ComObject\res\is-6PTIK.tmp
  • %APPDATA%\ComObject\res\is-TIFAP.tmp
  • %APPDATA%\ComObject\res\is-GER3D.tmp
  • %APPDATA%\ComObject\res\fonts\is-F2JJ4.tmp
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\search.json
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\formhistory.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\search.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\search.sqlite
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\content-prefs.sqlite
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\mimeTypes-1.rdf
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\formhistory.sqlite
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\content-prefs.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions.rdf
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\prefs-1.js
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions-1.cache
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions-1.ini
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\pluginreg.dat
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions-1.rdf
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\places.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\places.sqlite
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\urlclassifier3.sqlite-journal
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\urlclassifier3.sqlite
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\Cache\_CACHE_003_
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\Cache\_CACHE_MAP_
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\downloads.sqlite
  • %TEMP%\jCiOxMUr.part
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\localstore-1.rdf
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\downloads.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\cert8.db
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\key3.db
  • %TEMP%\nsz5.tmp\System.dll
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\secmod.db
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\Cache\_CACHE_001_
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\Cache\_CACHE_002_
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\cookies.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\cookies.sqlite
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\permissions.sqlite
  • %APPDATA%\ComObject\searchplugins\is-EETKP.tmp
  • %APPDATA%\ComObject\searchplugins\is-584ND.tmp
  • %APPDATA%\ComObject\searchplugins\is-ETV7N.tmp
  • %APPDATA%\ComObject\searchplugins\is-4R0KH.tmp
  • %APPDATA%\is-2R37H.tmp
  • %TEMP%\is-KENC2.tmp\rog\unins000.dat
  • %APPDATA%\ComObject\searchplugins\is-3RUAP.tmp
  • %APPDATA%\ComObject\uninstall\is-SPLAS.tmp
  • %APPDATA%\ComObject\res\fonts\is-4S558.tmp
  • %APPDATA%\ComObject\res\fonts\is-SIARM.tmp
  • %APPDATA%\ComObject\res\fonts\is-N2EKC.tmp
  • %APPDATA%\ComObject\res\fonts\is-S44LQ.tmp
  • %APPDATA%\ComObject\searchplugins\is-4VKRV.tmp
  • %APPDATA%\ComObject\searchplugins\is-AOES7.tmp
  • %APPDATA%\ComObject\res\fonts\is-F8VQ5.tmp
  • %APPDATA%\ComObject\res\html\is-4NAPO.tmp
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\compatibility.ini
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\xpti.dat.tmp
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\mimeTypes.rdf
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\prefs.js
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\XUL.mfl
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\permissions.sqlite-journal
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\XPC.mfl
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\compreg.dat.tmp
  • %APPDATA%\ComObject\components\xpti.dat.tmp
  • %APPDATA%\AMozilla\AFirefox\profiles.ini
  • %TEMP%\nso2.tmp
  • %APPDATA%\AMozilla\AFirefox\Crash Reports\InstallTime20100401080539
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\chrome\userContent-example.css
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\localstore.rdf
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\bookmarks.html
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\chrome\userChrome-example.css
  • %APPDATA%\ComObject\modules\is-4LC0P.tmp
  • %APPDATA%\ComObject\chrome\is-CL472.tmp
  • %APPDATA%\ComObject\chrome\is-8G66I.tmp
  • %APPDATA%\ComObject\chrome\is-AKQ5Q.tmp
  • %APPDATA%\ComObject\chrome\is-H7OKQ.tmp
  • %APPDATA%\ComObject\chrome\is-E1IPN.tmp
  • %APPDATA%\ComObject\chrome\is-6V6MP.tmp
  • %APPDATA%\ComObject\chrome\is-1T0P7.tmp
  • %APPDATA%\ComObject\chrome\is-1M10O.tmp
  • %APPDATA%\ComObject\chrome\is-BP6BH.tmp
  • %APPDATA%\ComObject\chrome\is-PS96P.tmp
  • %APPDATA%\ComObject\is-URHU5.tmp
  • %APPDATA%\ComObject\is-JPK8H.tmp
  • %APPDATA%\ComObject\chrome\is-UJ7T8.tmp
  • %APPDATA%\ComObject\chrome\is-J1BIF.tmp
  • %APPDATA%\ComObject\chrome\is-7Q9CD.tmp
  • %APPDATA%\ComObject\chrome\is-LUBQL.tmp
  • %APPDATA%\ComObject\components\is-NNEQ4.tmp
  • %APPDATA%\ComObject\components\is-U68HP.tmp
  • %APPDATA%\ComObject\components\is-BHIEJ.tmp
  • %APPDATA%\ComObject\components\is-IUMCK.tmp
  • %APPDATA%\ComObject\components\is-FJG7I.tmp
  • %APPDATA%\ComObject\components\is-7O182.tmp
  • %APPDATA%\ComObject\components\is-VBFD9.tmp
  • %APPDATA%\ComObject\components\is-8QOH4.tmp
  • %APPDATA%\ComObject\components\is-OT1PU.tmp
  • %APPDATA%\ComObject\components\is-S1BQS.tmp
  • %APPDATA%\ComObject\components\is-AEP9A.tmp
  • %APPDATA%\ComObject\components\is-2F9C6.tmp
  • %APPDATA%\ComObject\components\is-36S0G.tmp
  • %APPDATA%\ComObject\components\is-543EK.tmp
  • %APPDATA%\ComObject\components\is-QOLCR.tmp
  • %APPDATA%\ComObject\components\is-OB28T.tmp
  • %APPDATA%\ComObject\is-II4JO.tmp
  • %APPDATA%\ComObject\is-ICFPV.tmp
  • %APPDATA%\ComObject\is-0Q48O.tmp
  • %APPDATA%\ComObject\is-6BGCU.tmp
  • %APPDATA%\ComObject\is-HK8I2.tmp
  • %APPDATA%\ComObject\is-LHP8O.tmp
  • %APPDATA%\ComObject\is-HOK9O.tmp
  • %APPDATA%\ComObject\is-9K3MS.tmp
  • %APPDATA%\ComObject\is-QF6IQ.tmp
  • %TEMP%\is-KENC2.tmp\rog\is-0U5DT.tmp
  • %APPDATA%\ComObject\is-Q5GEE.tmp
  • %TEMP%\is-AMOOV.tmp\<File name>.tmp
  • %TEMP%\is-KENC2.tmp\_isetup\_isdecmp.dll
  • %APPDATA%\ComObject\is-R22UU.tmp
  • %APPDATA%\ComObject\is-NMBQI.tmp
  • %APPDATA%\ComObject\is-TE0TC.tmp
  • %APPDATA%\ComObject\is-GVQ58.tmp
  • %APPDATA%\ComObject\is-LTE99.tmp
  • %APPDATA%\ComObject\is-562H9.tmp
  • %APPDATA%\ComObject\is-0QMCI.tmp
  • %APPDATA%\ComObject\is-62NCA.tmp
  • %APPDATA%\ComObject\is-V4ROK.tmp
  • %APPDATA%\ComObject\is-21OL4.tmp
  • %APPDATA%\ComObject\is-UVODJ.tmp
  • %APPDATA%\ComObject\is-C510C.tmp
  • %APPDATA%\ComObject\is-8KQP3.tmp
  • %APPDATA%\ComObject\is-45T2B.tmp
  • %APPDATA%\ComObject\is-BNNEV.tmp
  • %APPDATA%\ComObject\is-EBRA9.tmp
  • %APPDATA%\ComObject\is-LABSL.tmp
  • %APPDATA%\ComObject\is-DJCB9.tmp
  • %APPDATA%\ComObject\is-UN9CU.tmp
  • %APPDATA%\ComObject\is-OUJF6.tmp
  • %APPDATA%\ComObject\components\is-UJ2RM.tmp
  • %APPDATA%\ComObject\defaults\pref\is-BBJD0.tmp
  • %APPDATA%\ComObject\defaults\pref\is-K47JO.tmp
  • %APPDATA%\ComObject\defaults\autoconfig\is-0ER2O.tmp
  • %APPDATA%\ComObject\defaults\pref\is-OPU0T.tmp
  • %APPDATA%\ComObject\defaults\profile\is-00RUB.tmp
  • %APPDATA%\ComObject\defaults\profile\is-MO85E.tmp
  • %APPDATA%\ComObject\defaults\pref\is-JJ38K.tmp
  • %APPDATA%\ComObject\defaults\pref\is-GR6HC.tmp
  • %APPDATA%\ComObject\components\is-40T1M.tmp
  • %APPDATA%\ComObject\components\is-0M7L5.tmp
  • %APPDATA%\ComObject\components\is-8FO4M.tmp
  • %APPDATA%\ComObject\components\is-73NKL.tmp
  • %APPDATA%\ComObject\components\is-11B4C.tmp
  • %APPDATA%\ComObject\defaults\autoconfig\is-PEETI.tmp
  • %APPDATA%\ComObject\components\is-ICIHM.tmp
  • %APPDATA%\ComObject\components\is-RPU8J.tmp
  • %APPDATA%\ComObject\greprefs\is-22SE3.tmp
  • %APPDATA%\ComObject\greprefs\is-H2354.tmp
  • %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\is-A40AP.tmp
  • %APPDATA%\ComObject\greprefs\is-735L4.tmp
  • %APPDATA%\ComObject\modules\is-0KTDO.tmp
  • %APPDATA%\ComObject\modules\is-GU7UC.tmp
  • %APPDATA%\ComObject\modules\is-N3KRG.tmp
  • %APPDATA%\ComObject\modules\is-4I5RL.tmp
  • %APPDATA%\ComObject\defaults\profile\chrome\is-580F5.tmp
  • %APPDATA%\ComObject\defaults\profile\chrome\is-URJ4D.tmp
  • %APPDATA%\ComObject\defaults\profile\is-A2J84.tmp
  • %APPDATA%\ComObject\defaults\profile\is-K8OHO.tmp
  • %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\is-LJ8A4.tmp
  • %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\is-FC56C.tmp
  • %APPDATA%\ComObject\dictionaries\is-7SFPT.tmp
  • %APPDATA%\ComObject\dictionaries\is-0F3TO.tmp
  • %APPDATA%\ComObject\components\is-SFPGO.tmp
  • %APPDATA%\ComObject\components\is-GBQV8.tmp
  • %APPDATA%\ComObject\components\is-1HMCK.tmp
  • %APPDATA%\ComObject\components\is-D6F0M.tmp
  • %APPDATA%\ComObject\components\is-OI7QD.tmp
  • %APPDATA%\ComObject\components\is-RENNI.tmp
  • %APPDATA%\ComObject\components\is-FJ05A.tmp
  • %APPDATA%\ComObject\components\is-V9HPO.tmp
  • %APPDATA%\ComObject\components\is-RNUEM.tmp
  • %APPDATA%\ComObject\components\is-3JSP7.tmp
  • %APPDATA%\ComObject\components\is-5CH0H.tmp
  • %APPDATA%\ComObject\components\is-P9HK4.tmp
  • %APPDATA%\ComObject\components\is-A44TJ.tmp
  • %APPDATA%\ComObject\components\is-G0HH1.tmp
  • %APPDATA%\ComObject\components\is-8T1MJ.tmp
  • %APPDATA%\ComObject\components\is-7UEND.tmp
  • %APPDATA%\ComObject\components\is-4464V.tmp
  • %APPDATA%\ComObject\components\is-LJOUU.tmp
  • %APPDATA%\ComObject\components\is-4TV76.tmp
  • %APPDATA%\ComObject\components\is-JKA10.tmp
  • %APPDATA%\ComObject\components\is-8VKNU.tmp
  • %APPDATA%\ComObject\components\is-UEDLB.tmp
  • %APPDATA%\ComObject\components\is-UM2M7.tmp
  • %APPDATA%\ComObject\components\is-CPSAK.tmp
  • %APPDATA%\ComObject\components\is-OKAV1.tmp
  • %APPDATA%\ComObject\components\is-EA7HQ.tmp
  • %APPDATA%\ComObject\components\is-NLLNG.tmp
  • %APPDATA%\ComObject\components\is-VD4GA.tmp
  • %APPDATA%\ComObject\components\is-AM56H.tmp
  • %APPDATA%\ComObject\components\is-BD99M.tmp
  • %APPDATA%\ComObject\components\is-SO9DS.tmp
  • %APPDATA%\ComObject\components\is-U7GM5.tmp
  • %APPDATA%\ComObject\components\is-G63QM.tmp
Deletes the following files:
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\formhistory.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\content-prefs.sqlite-journal
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\XUL.mfl
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\search.sqlite-journal
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\urlclassifier3.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\downloads.sqlite-journal
  • %TEMP%\nsz5.tmp\System.dll
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\cookies.sqlite-journal
  • %TEMP%\is-KENC2.tmp\_isetup\_isdecmp.dll
  • %APPDATA%\ComObject\components\xpti.dat
  • %TEMP%\is-KENC2.tmp\rog\unins000.dat
  • %TEMP%\is-KENC2.tmp\rog\unins000.exe
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\compreg.dat
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\xpti.dat
  • %TEMP%\is-AMOOV.tmp\<File name>.tmp
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\permissions.sqlite-journal
Moves the following files:
  • from %APPDATA%\ComObject\plugins\is-13QQL.tmp to %APPDATA%\ComObject\plugins\npbasic.dll
  • from %APPDATA%\ComObject\modules\is-I3NUM.tmp to %APPDATA%\ComObject\modules\XPCOMUtils.jsm
  • from %APPDATA%\ComObject\modules\is-8AGBI.tmp to %APPDATA%\ComObject\modules\WindowsPreviewPerTab.jsm
  • from %APPDATA%\ComObject\res\is-05BU4.tmp to %APPDATA%\ComObject\res\arrowd.gif
  • from %APPDATA%\ComObject\res\is-IJ5JK.tmp to %APPDATA%\ComObject\res\arrow.gif
  • from %APPDATA%\ComObject\plugins\is-VI1JP.tmp to %APPDATA%\ComObject\plugins\npnul32.dll
  • from %APPDATA%\ComObject\modules\is-CGOKC.tmp to %APPDATA%\ComObject\modules\WindowDraggingUtils.jsm
  • from %APPDATA%\ComObject\modules\is-7P3QD.tmp to %APPDATA%\ComObject\modules\PlacesDBUtils.jsm
  • from %APPDATA%\ComObject\modules\is-TTBBJ.tmp to %APPDATA%\ComObject\modules\openLocationLastURL.jsm
  • from %APPDATA%\ComObject\modules\is-QOA03.tmp to %APPDATA%\ComObject\modules\NetworkPrioritizer.jsm
  • from %APPDATA%\ComObject\modules\is-B9F46.tmp to %APPDATA%\ComObject\modules\utils.js
  • from %APPDATA%\ComObject\modules\is-0QD7J.tmp to %APPDATA%\ComObject\modules\SpatialNavigation.js
  • from %APPDATA%\ComObject\modules\is-MDUEN.tmp to %APPDATA%\ComObject\modules\PluralForm.jsm
  • from %APPDATA%\ComObject\res\is-TIFAP.tmp to %APPDATA%\ComObject\res\broken-image.png
  • from %APPDATA%\ComObject\res\is-IMOT0.tmp to %APPDATA%\ComObject\res\langGroups.properties
  • from %APPDATA%\ComObject\res\is-KFV28.tmp to %APPDATA%\ComObject\res\html.css
  • from %APPDATA%\ComObject\res\is-4G5QV.tmp to %APPDATA%\ComObject\res\hiddenWindow.html
  • from %APPDATA%\ComObject\res\is-E9IB0.tmp to %APPDATA%\ComObject\res\mathml.css
  • from %APPDATA%\ComObject\res\is-JNJ6G.tmp to %APPDATA%\ComObject\res\loading-image.png
  • from %APPDATA%\ComObject\res\is-6UCHS.tmp to %APPDATA%\ComObject\res\language.properties
  • from %APPDATA%\ComObject\res\is-NGPSV.tmp to %APPDATA%\ComObject\res\grabber.gif
  • from %APPDATA%\ComObject\res\is-6PTIK.tmp to %APPDATA%\ComObject\res\contenteditable.css
  • from %APPDATA%\ComObject\res\is-M43SO.tmp to %APPDATA%\ComObject\res\charsetData.properties
  • from %APPDATA%\ComObject\res\is-GER3D.tmp to %APPDATA%\ComObject\res\charsetalias.properties
  • from %APPDATA%\ComObject\res\is-C390J.tmp to %APPDATA%\ComObject\res\forms.css
  • from %APPDATA%\ComObject\res\is-IGJ1V.tmp to %APPDATA%\ComObject\res\EditorOverride.css
  • from %APPDATA%\ComObject\res\is-OVAKA.tmp to %APPDATA%\ComObject\res\designmode.css
  • from %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\is-LJ8A4.tmp to %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png
  • from %APPDATA%\ComObject\dictionaries\is-0F3TO.tmp to %APPDATA%\ComObject\dictionaries\en-US.dic
  • from %APPDATA%\ComObject\dictionaries\is-7SFPT.tmp to %APPDATA%\ComObject\dictionaries\en-US.aff
  • from %APPDATA%\ComObject\greprefs\is-735L4.tmp to %APPDATA%\ComObject\greprefs\all.js
  • from %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\is-A40AP.tmp to %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\preview.png
  • from %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\is-FC56C.tmp to %APPDATA%\ComObject\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
  • from %APPDATA%\ComObject\defaults\profile\chrome\is-URJ4D.tmp to %APPDATA%\ComObject\defaults\profile\chrome\userContent-example.css
  • from %APPDATA%\ComObject\defaults\profile\is-MO85E.tmp to %APPDATA%\ComObject\defaults\profile\localstore.rdf
  • from %APPDATA%\ComObject\defaults\profile\is-00RUB.tmp to %APPDATA%\ComObject\defaults\profile\bookmarks.html
  • from %APPDATA%\ComObject\defaults\pref\is-GR6HC.tmp to %APPDATA%\ComObject\defaults\pref\reporter.js
  • from %APPDATA%\ComObject\defaults\profile\chrome\is-580F5.tmp to %APPDATA%\ComObject\defaults\profile\chrome\userChrome-example.css
  • from %APPDATA%\ComObject\defaults\profile\is-K8OHO.tmp to %APPDATA%\ComObject\defaults\profile\prefs.js
  • from %APPDATA%\ComObject\defaults\profile\is-A2J84.tmp to %APPDATA%\ComObject\defaults\profile\mimeTypes.rdf
  • from %APPDATA%\ComObject\greprefs\is-22SE3.tmp to %APPDATA%\ComObject\greprefs\security-prefs.js
  • from %APPDATA%\ComObject\modules\is-LVP3D.tmp to %APPDATA%\ComObject\modules\LightweightThemeConsumer.jsm
  • from %APPDATA%\ComObject\modules\is-G9IJT.tmp to %APPDATA%\ComObject\modules\ISO8601DateUtils.jsm
  • from %APPDATA%\ComObject\modules\is-4HPFR.tmp to %APPDATA%\ComObject\modules\FileUtils.jsm
  • from %APPDATA%\ComObject\modules\is-1LKBE.tmp to %APPDATA%\ComObject\modules\NetUtil.jsm
  • from %APPDATA%\ComObject\modules\is-662F5.tmp to %APPDATA%\ComObject\modules\Microformats.js
  • from %APPDATA%\ComObject\modules\is-1EDP5.tmp to %APPDATA%\ComObject\modules\LightweightThemeManager.jsm
  • from %APPDATA%\ComObject\modules\is-5ALP3.tmp to %APPDATA%\ComObject\modules\DownloadUtils.jsm
  • from %APPDATA%\ComObject\modules\is-4I5RL.tmp to %APPDATA%\ComObject\modules\ctypes.jsm
  • from %APPDATA%\ComObject\modules\is-N3KRG.tmp to %APPDATA%\ComObject\modules\CertUtils.jsm
  • from %APPDATA%\ComObject\greprefs\is-H2354.tmp to %APPDATA%\ComObject\greprefs\xpinstall.js
  • from %APPDATA%\ComObject\modules\is-4LC0P.tmp to %APPDATA%\ComObject\modules\DownloadLastDir.jsm
  • from %APPDATA%\ComObject\modules\is-GU7UC.tmp to %APPDATA%\ComObject\modules\distribution.js
  • from %APPDATA%\ComObject\modules\is-0KTDO.tmp to %APPDATA%\ComObject\modules\debug.js
  • from %APPDATA%\ComObject\res\is-7CBJK.tmp to %APPDATA%\ComObject\res\quirk.css
  • from %APPDATA%\ComObject\res\html\is-4NAPO.tmp to %APPDATA%\ComObject\res\html\folder.png
  • from %APPDATA%\ComObject\res\fonts\is-F8VQ5.tmp to %APPDATA%\ComObject\res\fonts\mathfontUnicode.properties
  • from %APPDATA%\ComObject\res\fonts\is-SIARM.tmp to %APPDATA%\ComObject\res\fonts\mathfontSymbol.properties
  • from %APPDATA%\ComObject\searchplugins\is-ETV7N.tmp to %APPDATA%\ComObject\searchplugins\creativecommons.xml
  • from %APPDATA%\ComObject\searchplugins\is-AOES7.tmp to %APPDATA%\ComObject\searchplugins\answers.xml
  • from %APPDATA%\ComObject\searchplugins\is-4VKRV.tmp to %APPDATA%\ComObject\searchplugins\amazondotcom.xml
  • from %APPDATA%\ComObject\res\fonts\is-4S558.tmp to %APPDATA%\ComObject\res\fonts\mathfontSTIXSize1.properties
  • from %APPDATA%\ComObject\res\entityTables\is-S9BSU.tmp to %APPDATA%\ComObject\res\entityTables\transliterate.properties
  • from %APPDATA%\ComObject\res\entityTables\is-245NU.tmp to %APPDATA%\ComObject\res\entityTables\mathml20.properties
  • from %APPDATA%\ComObject\res\entityTables\is-6B8CJ.tmp to %APPDATA%\ComObject\res\entityTables\htmlEntityVersions.properties
  • from %APPDATA%\ComObject\res\fonts\is-S44LQ.tmp to %APPDATA%\ComObject\res\fonts\mathfontSTIXNonUnicode.properties
  • from %APPDATA%\ComObject\res\fonts\is-N2EKC.tmp to %APPDATA%\ComObject\res\fonts\mathfontStandardSymbolsL.properties
  • from %APPDATA%\ComObject\res\fonts\is-F2JJ4.tmp to %APPDATA%\ComObject\res\fonts\mathfont.properties
  • from %APPDATA%\ComObject\searchplugins\is-4R0KH.tmp to %APPDATA%\ComObject\searchplugins\eBay.xml
  • from %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\prefs-1.js to %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\prefs.js
  • from %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions-1.ini to %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions.ini
  • from %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions-1.cache to %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions.cache
  • from %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\localstore-1.rdf to %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\localstore.rdf
  • from %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\mimeTypes-1.rdf to %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\mimeTypes.rdf
  • from %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions-1.rdf to %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions.rdf
  • from %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\compreg.dat.tmp to %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\compreg.dat
  • from %APPDATA%\ComObject\searchplugins\is-3RUAP.tmp to %APPDATA%\ComObject\searchplugins\yahoo.xml
  • from %APPDATA%\ComObject\searchplugins\is-584ND.tmp to %APPDATA%\ComObject\searchplugins\wikipedia.xml
  • from %APPDATA%\ComObject\searchplugins\is-EETKP.tmp to %APPDATA%\ComObject\searchplugins\google.xml
  • from %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\xpti.dat.tmp to %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\xpti.dat
  • from %APPDATA%\is-2R37H.tmp to %APPDATA%\Rainlendar-Lite-2.13.1-32bit.exe
  • from %APPDATA%\ComObject\uninstall\is-SPLAS.tmp to %APPDATA%\ComObject\uninstall\helper.exe
  • from %APPDATA%\ComObject\res\is-BEDG0.tmp to %APPDATA%\ComObject\res\table-add-row-after.gif
  • from %APPDATA%\ComObject\res\is-158BI.tmp to %APPDATA%\ComObject\res\table-add-row-after-hover.gif
  • from %APPDATA%\ComObject\res\is-CUIAN.tmp to %APPDATA%\ComObject\res\table-add-row-after-active.gif
  • from %APPDATA%\ComObject\res\is-8AVA9.tmp to %APPDATA%\ComObject\res\table-add-row-before.gif
  • from %APPDATA%\ComObject\res\is-SDP2L.tmp to %APPDATA%\ComObject\res\table-add-row-before-hover.gif
  • from %APPDATA%\ComObject\res\is-KB27D.tmp to %APPDATA%\ComObject\res\table-add-row-before-active.gif
  • from %APPDATA%\ComObject\res\is-LOJKQ.tmp to %APPDATA%\ComObject\res\table-add-column-before.gif
  • from %APPDATA%\ComObject\res\is-9VJMT.tmp to %APPDATA%\ComObject\res\table-add-column-after-hover.gif
  • from %APPDATA%\ComObject\res\is-OES2M.tmp to %APPDATA%\ComObject\res\table-add-column-after-active.gif
  • from %APPDATA%\ComObject\res\is-U15Q3.tmp to %APPDATA%\ComObject\res\svg.css
  • from %APPDATA%\ComObject\res\is-08UV9.tmp to %APPDATA%\ComObject\res\table-add-column-before-hover.gif
  • from %APPDATA%\ComObject\res\is-OC0ID.tmp to %APPDATA%\ComObject\res\table-add-column-before-active.gif
  • from %APPDATA%\ComObject\res\is-A1RA9.tmp to %APPDATA%\ComObject\res\table-add-column-after.gif
  • from %APPDATA%\ComObject\res\is-SIACJ.tmp to %APPDATA%\ComObject\res\table-remove-column-active.gif
  • from %APPDATA%\ComObject\res\dtd\is-4T9T3.tmp to %APPDATA%\ComObject\res\dtd\xhtml11.dtd
  • from %APPDATA%\ComObject\res\dtd\is-8DF2S.tmp to %APPDATA%\ComObject\res\dtd\mathml.dtd
  • from %APPDATA%\ComObject\res\is-M33SG.tmp to %APPDATA%\ComObject\res\wincharset.properties
  • from %APPDATA%\ComObject\res\entityTables\is-ONJJP.tmp to %APPDATA%\ComObject\res\entityTables\html40Symbols.properties
  • from %APPDATA%\ComObject\res\entityTables\is-559J9.tmp to %APPDATA%\ComObject\res\entityTables\html40Special.properties
  • from %APPDATA%\ComObject\res\entityTables\is-OR63D.tmp to %APPDATA%\ComObject\res\entityTables\html40Latin1.properties
  • from %APPDATA%\ComObject\res\is-56OFF.tmp to %APPDATA%\ComObject\res\viewsource.css
  • from %APPDATA%\ComObject\res\is-HC47B.tmp to %APPDATA%\ComObject\res\table-remove-row-active.gif
  • from %APPDATA%\ComObject\res\is-IA43S.tmp to %APPDATA%\ComObject\res\table-remove-column.gif
  • from %APPDATA%\ComObject\res\is-9655E.tmp to %APPDATA%\ComObject\res\table-remove-column-hover.gif
  • from %APPDATA%\ComObject\res\is-GA243.tmp to %APPDATA%\ComObject\res\ua.css
  • from %APPDATA%\ComObject\res\is-67DPM.tmp to %APPDATA%\ComObject\res\table-remove-row.gif
  • from %APPDATA%\ComObject\res\is-8G7GR.tmp to %APPDATA%\ComObject\res\table-remove-row-hover.gif
  • from %APPDATA%\ComObject\defaults\pref\is-JJ38K.tmp to %APPDATA%\ComObject\defaults\pref\firefox.js
  • from %APPDATA%\ComObject\chrome\is-LUBQL.tmp to %APPDATA%\ComObject\chrome\classic.manifest
  • from %APPDATA%\ComObject\chrome\is-7Q9CD.tmp to %APPDATA%\ComObject\chrome\classic.jar
  • from %APPDATA%\ComObject\chrome\is-PS96P.tmp to %APPDATA%\ComObject\chrome\browser.manifest
  • from %APPDATA%\ComObject\chrome\is-AKQ5Q.tmp to %APPDATA%\ComObject\chrome\en-US.jar
  • from %APPDATA%\ComObject\chrome\is-J1BIF.tmp to %APPDATA%\ComObject\chrome\comm.manifest
  • from %APPDATA%\ComObject\chrome\is-UJ7T8.tmp to %APPDATA%\ComObject\chrome\comm.jar
  • from %APPDATA%\ComObject\chrome\is-BP6BH.tmp to %APPDATA%\ComObject\chrome\browser.jar
  • from %APPDATA%\ComObject\is-21OL4.tmp to %APPDATA%\ComObject\update.locale
  • from %APPDATA%\ComObject\is-V4ROK.tmp to %APPDATA%\ComObject\update.exe
  • from %APPDATA%\ComObject\is-C510C.tmp to %APPDATA%\ComObject\ssl3.dll
  • from %APPDATA%\ComObject\is-JPK8H.tmp to %APPDATA%\ComObject\xul.dll
  • from %APPDATA%\ComObject\is-URHU5.tmp to %APPDATA%\ComObject\xpcom.dll
  • from %APPDATA%\ComObject\is-II4JO.tmp to %APPDATA%\ComObject\updater.ini
  • from %APPDATA%\ComObject\chrome\is-H7OKQ.tmp to %APPDATA%\ComObject\chrome\en-US.manifest
  • from %APPDATA%\ComObject\components\is-S1BQS.tmp to %APPDATA%\ComObject\components\components.list
  • from %APPDATA%\ComObject\components\is-OT1PU.tmp to %APPDATA%\ComObject\components\brwsrcmp.dll
  • from %APPDATA%\ComObject\components\is-2F9C6.tmp to %APPDATA%\ComObject\components\browserdirprovider.dll
  • from %APPDATA%\ComObject\components\is-36S0G.tmp to %APPDATA%\ComObject\components\FeedProcessor.js
  • from %APPDATA%\ComObject\components\is-OB28T.tmp to %APPDATA%\ComObject\components\FeedConverter.js
  • from %APPDATA%\ComObject\components\is-QOLCR.tmp to %APPDATA%\ComObject\components\compreg.dat
  • from %APPDATA%\ComObject\components\is-AEP9A.tmp to %APPDATA%\ComObject\components\browser.xpt
  • from %APPDATA%\ComObject\chrome\is-1T0P7.tmp to %APPDATA%\ComObject\chrome\reporter.jar
  • from %APPDATA%\ComObject\chrome\is-8G66I.tmp to %APPDATA%\ComObject\chrome\pippki.manifest
  • from %APPDATA%\ComObject\chrome\is-CL472.tmp to %APPDATA%\ComObject\chrome\pippki.jar
  • from %APPDATA%\ComObject\chrome\is-6V6MP.tmp to %APPDATA%\ComObject\chrome\toolkit.manifest
  • from %APPDATA%\ComObject\chrome\is-E1IPN.tmp to %APPDATA%\ComObject\chrome\toolkit.jar
  • from %APPDATA%\ComObject\chrome\is-1M10O.tmp to %APPDATA%\ComObject\chrome\reporter.manifest
  • from %APPDATA%\ComObject\is-0Q48O.tmp to %APPDATA%\ComObject\freebl3.dll
  • from %APPDATA%\ComObject\is-ICFPV.tmp to %APPDATA%\ComObject\freebl3.chk
  • from %APPDATA%\ComObject\is-HK8I2.tmp to %APPDATA%\ComObject\crashreporter.ini
  • from %APPDATA%\ComObject\is-LHP8O.tmp to %APPDATA%\ComObject\mozcrt19.dll
  • from %APPDATA%\ComObject\is-QF6IQ.tmp to %APPDATA%\ComObject\LICENSE
  • from %APPDATA%\ComObject\is-9K3MS.tmp to %APPDATA%\ComObject\js3250.dll
  • from %APPDATA%\ComObject\is-6BGCU.tmp to %APPDATA%\ComObject\crashreporter.exe
  • from %APPDATA%\ComObject\is-TE0TC.tmp to %APPDATA%\ComObject\application.ini
  • from %APPDATA%\ComObject\is-Q5GEE.tmp to %APPDATA%\ComObject\AccessibleMarshal.dll
  • from %TEMP%\is-KENC2.tmp\rog\is-0U5DT.tmp to %TEMP%\is-KENC2.tmp\rog\unins000.exe
  • from %APPDATA%\ComObject\is-NMBQI.tmp to %APPDATA%\ComObject\crashreporter-override.ini
  • from %APPDATA%\ComObject\is-R22UU.tmp to %APPDATA%\ComObject\browserconfig.properties
  • from %APPDATA%\ComObject\is-GVQ58.tmp to %APPDATA%\ComObject\blocklist.xml
  • from %APPDATA%\ComObject\is-HOK9O.tmp to %APPDATA%\ComObject\nspr4.dll
  • from %APPDATA%\ComObject\is-62NCA.tmp to %APPDATA%\ComObject\smime3.dll
  • from %APPDATA%\ComObject\is-0QMCI.tmp to %APPDATA%\ComObject\README.txt
  • from %APPDATA%\ComObject\is-DJCB9.tmp to %APPDATA%\ComObject\plds4.dll
  • from %APPDATA%\ComObject\is-UVODJ.tmp to %APPDATA%\ComObject\sqlite3.dll
  • from %APPDATA%\ComObject\is-562H9.tmp to %APPDATA%\ComObject\softokn3.dll
  • from %APPDATA%\ComObject\is-LTE99.tmp to %APPDATA%\ComObject\softokn3.chk
  • from %APPDATA%\ComObject\is-LABSL.tmp to %APPDATA%\ComObject\plc4.dll
  • from %APPDATA%\ComObject\is-8KQP3.tmp to %APPDATA%\ComObject\nssdbm3.chk
  • from %APPDATA%\ComObject\is-EBRA9.tmp to %APPDATA%\ComObject\nssckbi.dll
  • from %APPDATA%\ComObject\is-BNNEV.tmp to %APPDATA%\ComObject\nss3.dll
  • from %APPDATA%\ComObject\is-OUJF6.tmp to %APPDATA%\ComObject\platform.ini
  • from %APPDATA%\ComObject\is-UN9CU.tmp to %APPDATA%\ComObject\nssutil3.dll
  • from %APPDATA%\ComObject\is-45T2B.tmp to %APPDATA%\ComObject\nssdbm3.dll
  • from %APPDATA%\ComObject\components\is-543EK.tmp to %APPDATA%\ComObject\components\FeedWriter.js
  • from %APPDATA%\ComObject\components\is-4TV76.tmp to %APPDATA%\ComObject\components\nsUpdateService.js
  • from %APPDATA%\ComObject\components\is-LJOUU.tmp to %APPDATA%\ComObject\components\nsTryToClose.js
  • from %APPDATA%\ComObject\components\is-8VKNU.tmp to %APPDATA%\ComObject\components\nsTaggingService.js
  • from %APPDATA%\ComObject\components\is-UEDLB.tmp to %APPDATA%\ComObject\components\nsUrlClassifierLib.js
  • from %APPDATA%\ComObject\components\is-OKAV1.tmp to %APPDATA%\ComObject\components\nsUpdateTimerManager.js
  • from %APPDATA%\ComObject\components\is-CPSAK.tmp to %APPDATA%\ComObject\components\nsUpdateServiceStub.js
  • from %APPDATA%\ComObject\components\is-JKA10.tmp to %APPDATA%\ComObject\components\nsSidebar.js
  • from %APPDATA%\ComObject\components\is-U7GM5.tmp to %APPDATA%\ComObject\components\nsSearchSuggestions.js
  • from %APPDATA%\ComObject\components\is-NLLNG.tmp to %APPDATA%\ComObject\components\nsSearchService.js
  • from %APPDATA%\ComObject\components\is-EA7HQ.tmp to %APPDATA%\ComObject\components\nsSafebrowsingApplication.js
  • from %APPDATA%\ComObject\components\is-SO9DS.tmp to %APPDATA%\ComObject\components\nsSetDefaultBrowser.js
  • from %APPDATA%\ComObject\components\is-BD99M.tmp to %APPDATA%\ComObject\components\nsSessionStore.js
  • from %APPDATA%\ComObject\components\is-G63QM.tmp to %APPDATA%\ComObject\components\nsSessionStartup.js
  • from %APPDATA%\ComObject\components\is-UM2M7.tmp to %APPDATA%\ComObject\components\nsUrlClassifierListManager.js
  • from %APPDATA%\ComObject\defaults\autoconfig\is-0ER2O.tmp to %APPDATA%\ComObject\defaults\autoconfig\prefcalls.js
  • from %APPDATA%\ComObject\defaults\autoconfig\is-PEETI.tmp to %APPDATA%\ComObject\defaults\autoconfig\platform.js
  • from %APPDATA%\ComObject\components\is-11B4C.tmp to %APPDATA%\ComObject\components\xpti.dat
  • from %APPDATA%\ComObject\defaults\pref\is-K47JO.tmp to %APPDATA%\ComObject\defaults\pref\firefox-l10n.js
  • from %APPDATA%\ComObject\defaults\pref\is-BBJD0.tmp to %APPDATA%\ComObject\defaults\pref\firefox-branding.js
  • from %APPDATA%\ComObject\defaults\pref\is-OPU0T.tmp to %APPDATA%\ComObject\defaults\pref\channel-prefs.js
  • from %APPDATA%\ComObject\components\is-RPU8J.tmp to %APPDATA%\ComObject\components\WebContentConverter.js
  • from %APPDATA%\ComObject\components\is-73NKL.tmp to %APPDATA%\ComObject\components\pluginGlue.js
  • from %APPDATA%\ComObject\components\is-8FO4M.tmp to %APPDATA%\ComObject\components\nsWebHandlerApp.js
  • from %APPDATA%\ComObject\components\is-SFPGO.tmp to %APPDATA%\ComObject\components\nsURLFormatter.js
  • from %APPDATA%\ComObject\components\is-ICIHM.tmp to %APPDATA%\ComObject\components\txEXSLTRegExFunctions.js
  • from %APPDATA%\ComObject\components\is-0M7L5.tmp to %APPDATA%\ComObject\components\storage-mozStorage.js
  • from %APPDATA%\ComObject\components\is-40T1M.tmp to %APPDATA%\ComObject\components\storage-Legacy.js
  • from %APPDATA%\ComObject\components\is-P9HK4.tmp to %APPDATA%\ComObject\components\nsContentDispatchChooser.js
  • from %APPDATA%\ComObject\components\is-UJ2RM.tmp to %APPDATA%\ComObject\components\nsBrowserGlue.js
  • from %APPDATA%\ComObject\components\is-7O182.tmp to %APPDATA%\ComObject\components\nsBrowserContentHandler.js
  • from %APPDATA%\ComObject\components\is-5CH0H.tmp to %APPDATA%\ComObject\components\nsDownloadManagerUI.js
  • from %APPDATA%\ComObject\components\is-3JSP7.tmp to %APPDATA%\ComObject\components\nsDefaultCLH.js
  • from %APPDATA%\ComObject\components\is-A44TJ.tmp to %APPDATA%\ComObject\components\nsContentPrefService.js
  • from %APPDATA%\ComObject\components\is-FJG7I.tmp to %APPDATA%\ComObject\components\nsBlocklistService.js
  • from %APPDATA%\ComObject\components\is-NNEQ4.tmp to %APPDATA%\ComObject\components\jsconsole-clhandler.js
  • from %APPDATA%\ComObject\components\is-IUMCK.tmp to %APPDATA%\ComObject\components\GPSDGeolocationProvider.js
  • from %APPDATA%\ComObject\components\is-BHIEJ.tmp to %APPDATA%\ComObject\components\fuelApplication.js
  • from %APPDATA%\ComObject\components\is-8QOH4.tmp to %APPDATA%\ComObject\components\nsBadCertHandler.js
  • from %APPDATA%\ComObject\components\is-VBFD9.tmp to %APPDATA%\ComObject\components\nsAddonRepository.js
  • from %APPDATA%\ComObject\components\is-U68HP.tmp to %APPDATA%\ComObject\components\NetworkGeolocationProvider.js
  • from %APPDATA%\ComObject\components\is-7UEND.tmp to %APPDATA%\ComObject\components\nsExtensionManager.js
  • from %APPDATA%\ComObject\components\is-RENNI.tmp to %APPDATA%\ComObject\components\nsPlacesDBFlush.js
  • from %APPDATA%\ComObject\components\is-RNUEM.tmp to %APPDATA%\ComObject\components\nsPlacesAutoComplete.js
  • from %APPDATA%\ComObject\components\is-V9HPO.tmp to %APPDATA%\ComObject\components\nsMicrosummaryService.js
  • from %APPDATA%\ComObject\components\is-AM56H.tmp to %APPDATA%\ComObject\components\nsProxyAutoConfig.js
  • from %APPDATA%\ComObject\components\is-VD4GA.tmp to %APPDATA%\ComObject\components\nsPrivateBrowsingService.js
  • from %APPDATA%\ComObject\components\is-FJ05A.tmp to %APPDATA%\ComObject\components\nsPlacesTransactionsService.js
  • from %APPDATA%\ComObject\components\is-1HMCK.tmp to %APPDATA%\ComObject\components\nsLoginManagerPrompter.js
  • from %APPDATA%\ComObject\components\is-8T1MJ.tmp to %APPDATA%\ComObject\components\nsHelperAppDlg.js
  • from %APPDATA%\ComObject\components\is-G0HH1.tmp to %APPDATA%\ComObject\components\nsHandlerService.js
  • from %APPDATA%\ComObject\components\is-4464V.tmp to %APPDATA%\ComObject\components\nsFormAutoComplete.js
  • from %APPDATA%\ComObject\components\is-GBQV8.tmp to %APPDATA%\ComObject\components\nsLoginManager.js
  • from %APPDATA%\ComObject\components\is-OI7QD.tmp to %APPDATA%\ComObject\components\nsLoginInfo.js
  • from %APPDATA%\ComObject\components\is-D6F0M.tmp to %APPDATA%\ComObject\components\nsLivemarkService.js
Substitutes the following files:
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\content-prefs.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\mimeTypes-1.rdf
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions-1.ini
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\XUL.mfl
  • <LS_APPDATA>\AMozilla\AFirefox\Profiles\w719l9wj.default\urlclassifier3.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\downloads.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\mimeTypes.rdf
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\cookies.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\xpti.dat.tmp
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\xpti.dat
  • %APPDATA%\ComObject\components\xpti.dat
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\permissions.sqlite-journal
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\prefs-1.js
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\extensions-1.cache
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\compreg.dat.tmp
  • %APPDATA%\AMozilla\AFirefox\Profiles\w719l9wj.default\compreg.dat
Network activity:
Connects to:
  • '74.##5.232.51':443
  • 'fx####s.mozilla.com':80
  • 'ag###itches.com':80
  • 'localhost':1036
  • 'localhost':1038
  • 'localhost':1040
TCP:
HTTP GET requests:
  • http://ag###itches.com/
  • http://fx####s.mozilla.com/en-US/firefox/headlines.xml
UDP:
  • DNS ASK ag###itches.com
  • DNS ASK fx####s.mozilla.com
  • DNS ASK sb-ssl.google.com
Miscellaneous:
Searches for the following windows:
  • ClassName: '#32770' WindowName: ''
  • ClassName: 'AFirefoxMessageWindow' WindowName: ''
Creates and executes the following:
  • '%APPDATA%\ComObject\update.exe' about:robots
  • '%APPDATA%\ComObject\uninstall\helper.exe' /SetAsDefaultAppUser
  • '%TEMP%\is-AMOOV.tmp\<File name>.tmp' /SL5="$50034,26909322,57856,<Full path to file>"
  • '%APPDATA%\Rainlendar-Lite-2.13.1-32bit.exe'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android