マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.MulDrop28.35223

Added to the Dr.Web virus database: 2024-10-29

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKCU\Software\Classes\ZoomLauncher\shell\open\command] '' = '"%APPDATA%\Zoom\bin\Zoom.exe" "--url=%1"'
  • [HKCU\Software\Classes\zoommtg\shell\open\command] '' = '"%APPDATA%\Zoom\bin\Zoom.exe" "--url=%1"'
  • [HKCU\Software\Classes\zoomus\shell\open\command] '' = '"%APPDATA%\Zoom\bin\Zoom.exe" "--url=%1"'
  • [HKCU\Software\Classes\ZoomRecording\shell\open\command] '' = '"%APPDATA%\Zoom\bin\zTscoder.exe" "%1"'
  • [HKCU\SOFTWARE\Classes\ZoomPhoneCall\shell\open\command] '' = '"%APPDATA%\Zoom\bin\Zoom.exe" --url="%l"'
  • [HKCU\SOFTWARE\Classes\ZoomPbx.zoomphonecall\shell\open\command] '' = '"%APPDATA%\Zoom\bin\Zoom.exe" --url="%l"'
Creates or modifies the following files
  • <SYSTEM32>\tasks\zoomupdatetaskuser-s-1-5-21-3691498038-2086406363-2140527554-1000
Modifies file system
Creates the following files
  • %TEMP%\7zs80ab8b58\installer.exe
  • %APPDATA%\zoom\tmp_bin\zupdater.exe
  • %APPDATA%\zoom\tmp_bin\droplet.pcm
  • %APPDATA%\zoom\tmp_bin\meeting_chat_chime.pcm
  • %APPDATA%\zoom\tmp_bin\meeting_raisehand_chime.pcm
  • %APPDATA%\zoom\tmp_bin\nanosvg_license.txt
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-console-l1-2-0.dll
  • %APPDATA%\zoom\tmp_bin\libmpg123.dll
  • %APPDATA%\zoom\tmp_bin\cptcontrol.exe
  • %APPDATA%\zoom\tmp_bin\cptservice.exe
  • %APPDATA%\zoom\tmp_bin\cptinstall.exe
  • %APPDATA%\zoom\tmp_bin\leave.pcm
  • %APPDATA%\zoom\tmp_bin\asproxy.dll
  • %APPDATA%\zoom\tmp_bin\xmppdll.dll
  • %APPDATA%\zoom\tmp_bin\zzhost.dll
  • %APPDATA%\zoom\tmp_bin\zwbuires.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-datetime-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-processthreads-l1-1-1.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-processthreads-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-processenvironment-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-namedpipe-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-memory-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-localization-l1-2-0.dll
  • %APPDATA%\zoom\tmp_bin\duilib_license.txt
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-console-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-heap-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-handle-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-file-l2-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-file-l1-2-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-file-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-errorhandling-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-interlocked-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-debug-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\directui_license.txt
  • %APPDATA%\zoom\tmp_bin\duilib.dll
  • %APPDATA%\zoom\tmp_bin\reslib.dll
  • %APPDATA%\zoom\tmp_bin\zcrashreport.dll
  • %APPDATA%\zoom\tmp_bin\zptapp.dll
  • %APPDATA%\zoom\tmp_bin\zchatapp.dll
  • %APPDATA%\zoom\tmp_bin\zcommonchat.dll
  • %APPDATA%\zoom\tmp_bin\zmsgappcommon.dll
  • %APPDATA%\zoom\tmp_bin\zmsgapp.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-profile-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\zchatui.dll
  • %APPDATA%\zoom\tmp_bin\zoominstall.xml
  • %APPDATA%\zoom\tmp_bin\zdata.dll
  • %APPDATA%\zoom\tmp_bin\zwinres.dll
  • %APPDATA%\zoom\tmp_bin\zlt.dll
  • %APPDATA%\zoom\tmp_bin\zmb.dll
  • %APPDATA%\zoom\tmp_bin\zoom.exe
  • %APPDATA%\zoom\tmp_bin\zcrashreport.exe
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-libraryloader-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\ztscoder.exe
  • %APPDATA%\zoom\tmp_bin\zwebservice.dll
  • %APPDATA%\zoom\tmp_bin\zvideoapp.dll
  • %APPDATA%\zoom\tmp_bin\zuires.dll
  • %APPDATA%\zoom\tmp_bin\zui.dll
  • %APPDATA%\zoom\tmp_bin\zpsapp.dll
  • %APPDATA%\zoom\tmp_bin\clap-medium.pcm
  • %APPDATA%\zoom\tmp_bin\clap-high.pcm
  • %APPDATA%\zoom\tmp_bin\zvideoui.dll
  • %APPDATA%\zoom\tmp_bin\zrcsdk.dll
  • %APPDATA%\zoom\tmp_bin\zoom_launcher.exe
  • %APPDATA%\zoom\tmp_bin\annoter.dll
  • %APPDATA%\zoom\tmp_bin\cares.dll
  • %APPDATA%\zoom\tmp_bin\znetutils.dll
  • %APPDATA%\zoom\tmp_bin\znet.dll
  • %APPDATA%\zoom\tmp_bin\zoomtelemetry.dll
  • %APPDATA%\zoom\tmp_bin\zwbui.dll
  • %APPDATA%\zoom\tmp_bin\msvcp140_atomic_wait.dll
  • %APPDATA%\microsoft\windows\start menu\programs\zoom\zoom workplace.lnk
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-synch-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_3.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_2.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_1.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_0.pcm
  • %APPDATA%\zoom\tmp_bin\znetdiagnostic.dll
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_5.pcm
  • %APPDATA%\zoom\tmp_bin\zmeshnetagent.dll
  • %APPDATA%\zoom\tmp_bin\percussion.pcm
  • %APPDATA%\zoom\tmp_bin\archival.pcm
  • %APPDATA%\zoom\tmp_bin\webview2loader.dll
  • %APPDATA%\zoom\tmp_bin\zwebview2agent.exe
  • %APPDATA%\zoom\tmp_bin\viper_async_device.dll
  • %APPDATA%\zoom\tmp_bin\mfadapter.dll
  • %APPDATA%\zoom\tmp_bin\percussion_pause.pcm
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-rtlsupport-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_6.pcm
  • %APPDATA%\zoom\tmp_uninstall\installer.exe
  • %APPDATA%\zoom\tmp_bin\installer.exe
  • %APPDATA%\zoom\tmp_bin\zm_conf_universal_ui.dll
  • %APPDATA%\zoom\tmp_bin\zmdb.dll
  • %APPDATA%\zoom\tmp_bin\zoomtask.dll
  • %APPDATA%\zoom\tmp_bin\zbusinessuicomponent.dll
  • %APPDATA%\zoom\tmp_bin\zzhostipcsdk.dll
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_4.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\ring_pstn.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_hash.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_star.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_a.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_9.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_8.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\beep_intercom.pcm
  • %APPDATA%\zoom\tmp_bin\pcm\dtmf_7.pcm
  • %APPDATA%\zoom\tmp_bin\zoombase_crypto_shared.dll
  • %APPDATA%\zoom\tmp_bin\zkbcrypto.dll
  • %APPDATA%\zoom\tmp_bin\zoutlookimutil.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-convert-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-synch-l1-2-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-sysinfo-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-timezone-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-util-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-xstate-l2-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-core-string-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-conio-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-process-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-filesystem-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-heap-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-locale-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-math-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-multibyte-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-environment-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\zautoupdate.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-runtime-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-time-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-stdio-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\uibase.dll
  • %APPDATA%\zoom\tmp_bin\zoomoutlookimplugin.exe
  • %APPDATA%\zoom\tmp_bin\zoomdocconverter.exe
  • %APPDATA%\zoom\tmp_bin\vcruntime140.dll
  • %APPDATA%\zoom\tmp_bin\vccorlib140.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-string-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\ucrtbase.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-private-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\msvcp140_2.dll
  • %APPDATA%\zoom\tmp_bin\msvcp140_1.dll
  • %APPDATA%\zoom\tmp_bin\msvcp140.dll
  • %APPDATA%\zoom\tmp_bin\concrt140.dll
  • %APPDATA%\zoom\tmp_bin\api-ms-win-crt-utility-l1-1-0.dll
  • %APPDATA%\zoom\tmp_bin\msvcp140_codecvt_ids.dll
  • %APPDATA%\zoom\tmp_bin\pcm\double_beep.pcm
  • %APPDATA%\zoom\tmp_bin\viper.dll
  • %APPDATA%\zoom\tmp_bin\dingdong1.pcm
  • %APPDATA%\zoom\zoom_install_src\cptcontrol.exe
  • %APPDATA%\zoom\zoom_install_src\cmmlib.dll
  • %APPDATA%\zoom\zoom_install_src\cmmbrowserengine.dll
  • %APPDATA%\zoom\zoom_install_src\cmmbiz.dll
  • %APPDATA%\zoom\zoom_install_src\cares.dll
  • %APPDATA%\zoom\zoom_install_src\cptinstall.exe
  • %APPDATA%\zoom\zoom_install_src\asproxy.dll
  • %APPDATA%\zoom\zoom_install_src\zoominstall.xml
  • %APPDATA%\zoom\zoom_install_src\wr_ding.pcm
  • %APPDATA%\zoom\zoom_install_src\win10rt.7z
  • %APPDATA%\zoom\zoom_install_src\unmute.pcm
  • %APPDATA%\zoom\zoom_install_src\ring_spatial.pcm
  • %APPDATA%\zoom\zoom_install_src\ring.pcm
  • %APPDATA%\zoom\zoom_install_src\annoter.dll
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_6.pcm
  • %APPDATA%\zoom\zoom_install_src\cptservice.exe
  • %APPDATA%\zoom\zoom_install_src\util.dll
  • %APPDATA%\zoom\zoom_install_src\uibase.dll
  • %APPDATA%\zoom\zoom_install_src\turbojpeg.dll
  • %APPDATA%\zoom\zoom_install_src\tp.dll
  • %APPDATA%\zoom\zoom_install_src\ssb_sdk.dll
  • %APPDATA%\zoom\zoom_install_src\reslib.dll
  • %APPDATA%\zoom\zoom_install_src\record_stop.pcm
  • %APPDATA%\zoom\zoom_install_src\cpthost.exe
  • %APPDATA%\zoom\zoom_install_src\mfadapter.dll
  • %APPDATA%\zoom\zoom_install_src\mcm.dll
  • %APPDATA%\zoom\zoom_install_src\libssl-3-zm.dll
  • %APPDATA%\zoom\zoom_install_src\libmpg123.dll
  • %APPDATA%\zoom\zoom_install_src\libcrypto-3-zm.dll
  • %APPDATA%\zoom\zoom_install_src\duilib.dll
  • %APPDATA%\zoom\zoom_install_src\msaalib.dll
  • %APPDATA%\zoom\zoom_install_src\cptshare.dll
  • %APPDATA%\zoom\zoom_install_src\record_start.pcm
  • %APPDATA%\zoom\zoom_install_src\percussion_pause.pcm
  • %APPDATA%\zoom\zoom_install_src\percussion.pcm
  • %APPDATA%\zoom\zoom_install_src\dingdong.pcm
  • %TEMP%\7zs80ab8b58\zoom.msi
  • %APPDATA%\zoom\installer.txt
  • %APPDATA%\zoom\zoom_install_src\archival.pcm
  • %APPDATA%\zoom\zoom_install_src\clap-high.pcm
  • %APPDATA%\zoom\zoom_install_src\clap-medium.pcm
  • %APPDATA%\zoom\zoom_install_src\viper.dll
  • %APPDATA%\zoom\zoom_install_src\crashrpt_lang.ini
  • %APPDATA%\zoom\zoom_install_src\mute.pcm
  • %APPDATA%\zoom\zoom_install_src\directui_license.txt
  • %APPDATA%\zoom\zoom_install_src\droplet.pcm
  • %APPDATA%\zoom\zoom_install_src\duilib_license.txt
  • %APPDATA%\zoom\zoom_install_src\leave.pcm
  • %APPDATA%\zoom\zoom_install_src\meeting_chat_chime.pcm
  • %APPDATA%\zoom\zoom_install_src\dingdong1.pcm
  • %APPDATA%\zoom\zoom_install_src\nydus.dll
  • %APPDATA%\zoom\zoom_install_src\nanosvg_license.txt
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_0.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\beep_intercom.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\ring_pstn.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_star.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_hash.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_a.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_9.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\double_beep.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_8.pcm
  • %APPDATA%\zoom\zoom_install_src\meeting_raisehand_chime.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_5.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_4.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_3.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_2.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_1.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_7.pcm
  • %APPDATA%\zoom\zoom_install_src\zoomtelemetry.dll
  • %APPDATA%\zoom\tmp_bin\turbojpeg.dll
  • %APPDATA%\zoom\zoom_install_src\xmppdll.dll
  • %APPDATA%\zoom\tmp_bin\zunifywebview.dll
  • %APPDATA%\zoom\tmp_bin\cmmbiz.dll
  • %APPDATA%\zoom\tmp_bin\cmmlib.dll
  • %APPDATA%\zoom\tmp_bin\cmmbrowserengine.dll
  • %APPDATA%\zoom\tmp_bin\msaalib.dll
  • %APPDATA%\zoom\tmp_bin\cptshare.dll
  • %APPDATA%\zoom\zoom_install_src\zzhostipcsdk.dll
  • %APPDATA%\zoom\zoom_install_src\zwinres.dll
  • %APPDATA%\zoom\zoom_install_src\zwebview2agent.exe
  • %APPDATA%\zoom\zoom_install_src\zwebservice.dll
  • %APPDATA%\zoom\zoom_install_src\zwbuires.dll
  • %APPDATA%\zoom\zoom_install_src\zwbui.dll
  • %APPDATA%\zoom\zoom_install_src\zvideoui.dll
  • %APPDATA%\zoom\zoom_install_src\zzhost.dll
  • %APPDATA%\zoom\zoom_install_src\viper_async_device.dll
  • %APPDATA%\zoom\tmp_bin\crashrpt_lang.ini
  • %APPDATA%\zoom\tmp_bin\tp.dll
  • %APPDATA%\zoom\tmp_bin\libssl-3-zm.dll
  • %APPDATA%\zoom\tmp_bin\ssb_sdk.dll
  • %APPDATA%\zoom\tmp_bin\wr_ding.pcm
  • %APPDATA%\zoom\tmp_bin\record_stop.pcm
  • %APPDATA%\zoom\tmp_bin\record_start.pcm
  • %APPDATA%\zoom\zoom_install_src\zvideoapp.dll
  • %APPDATA%\zoom\tmp_bin\cpthost.exe
  • %APPDATA%\zoom\tmp_bin\unmute.pcm
  • %APPDATA%\zoom\tmp_bin\mute.pcm
  • %APPDATA%\zoom\tmp_bin\ring_spatial.pcm
  • %APPDATA%\zoom\tmp_bin\ring.pcm
  • %APPDATA%\zoom\tmp_bin\nydus.dll
  • %APPDATA%\zoom\tmp_bin\mcm.dll
  • %APPDATA%\zoom\tmp_bin\dingdong.pcm
  • %APPDATA%\zoom\tmp_bin\libcrypto-3-zm.dll
  • %APPDATA%\zoom\zoom_install_src\zupdater.exe
  • %APPDATA%\zoom\zoom_install_src\zunifywebview.dll
  • %APPDATA%\zoom\zoom_install_src\zuires.dll
  • %APPDATA%\zoom\zoom_install_src\zcrashreport.exe
  • %APPDATA%\zoom\zoom_install_src\zautoupdate.dll
  • %APPDATA%\zoom\zoom_install_src\zbusinessuicomponent.dll
  • %APPDATA%\zoom\zoom_install_src\zchatapp.dll
  • %APPDATA%\zoom\zoom_install_src\zchatui.dll
  • %APPDATA%\zoom\zoom_install_src\zcommonchat.dll
  • %APPDATA%\zoom\zoom_install_src\webview2loader.dll
  • %APPDATA%\zoom\zoom_install_src\zcrashreport.dll
  • %APPDATA%\zoom\zoom_install_src\zmsgappcommon.dll
  • %APPDATA%\zoom\zoom_install_src\zkbcrypto.dll
  • %APPDATA%\zoom\zoom_install_src\zlt.dll
  • %APPDATA%\zoom\zoom_install_src\zmb.dll
  • %APPDATA%\zoom\zoom_install_src\zmdb.dll
  • %APPDATA%\zoom\zoom_install_src\zmeshnetagent.dll
  • %APPDATA%\zoom\zoom_install_src\zdata.dll
  • %APPDATA%\zoom\tmp_bin\util.dll
  • %APPDATA%\zoom\zoom_install_src\zm_conf_universal_ui.dll
  • %APPDATA%\zoom\zoom_install_src\znetutils.dll
  • %APPDATA%\zoom\zoom_install_src\znet.dll
  • %APPDATA%\zoom\zoom_install_src\zui.dll
  • %APPDATA%\zoom\zoom_install_src\ztscoder.exe
  • %APPDATA%\zoom\zoom_install_src\zrcsdk.dll
  • %APPDATA%\zoom\zoom_install_src\zptapp.dll
  • %APPDATA%\zoom\zoom_install_src\zpsapp.dll
  • %APPDATA%\zoom\zoom_install_src\znetdiagnostic.dll
  • %APPDATA%\zoom\zoom_install_src\zoutlookimutil.dll
  • %APPDATA%\zoom\zoom_install_src\zmsgapp.dll
  • %APPDATA%\zoom\zoom_install_src\zoomtask.dll
  • %APPDATA%\zoom\zoom_install_src\zoomoutlookimplugin.exe
  • %APPDATA%\zoom\zoom_install_src\zoomdocconverter.exe
  • %APPDATA%\zoom\zoom_install_src\zoombase_crypto_shared.dll
  • %APPDATA%\zoom\zoom_install_src\zoom.exe
  • %APPDATA%\zoom\zoom_install_src\zoom_launcher.exe
  • %APPDATA%\microsoft\windows\start menu\programs\zoom\uninstall zoom workplace.lnk
Deletes the following files
  • %APPDATA%\zoom\zoom_install_src\annoter.dll
  • %APPDATA%\zoom\zoom_install_src\zm_conf_universal_ui.dll
  • %APPDATA%\zoom\zoom_install_src\zmsgappcommon.dll
  • %APPDATA%\zoom\zoom_install_src\zmsgapp.dll
  • %APPDATA%\zoom\zoom_install_src\zmeshnetagent.dll
  • %APPDATA%\zoom\zoom_install_src\zmdb.dll
  • %APPDATA%\zoom\zoom_install_src\zmb.dll
  • %APPDATA%\zoom\zoom_install_src\zlt.dll
  • %APPDATA%\zoom\zoom_install_src\zkbcrypto.dll
  • %APPDATA%\zoom\zoom_install_src\zdata.dll
  • %APPDATA%\zoom\zoom_install_src\zcrashreport.exe
  • %APPDATA%\zoom\zoom_install_src\zcrashreport.dll
  • %APPDATA%\zoom\zoom_install_src\zcommonchat.dll
  • %APPDATA%\zoom\zoom_install_src\zchatui.dll
  • %APPDATA%\zoom\zoom_install_src\zchatapp.dll
  • %APPDATA%\zoom\zoom_install_src\zbusinessuicomponent.dll
  • %APPDATA%\zoom\zoom_install_src\zautoupdate.dll
  • %APPDATA%\zoom\zoom_install_src\xmppdll.dll
  • %APPDATA%\zoom\zoom_install_src\wr_ding.pcm
  • %APPDATA%\zoom\zoom_install_src\win10rt.7z
  • %APPDATA%\zoom\zoom_install_src\webview2loader.dll
  • %APPDATA%\zoom\zoom_install_src\viper_async_device.dll
  • %APPDATA%\zoom\zoom_install_src\viper.dll
  • %APPDATA%\zoom\zoom_install_src\util.dll
  • %APPDATA%\zoom\zoom_install_src\unmute.pcm
  • %APPDATA%\zoom\zoom_install_src\uibase.dll
  • %APPDATA%\zoom\zoom_install_src\znet.dll
  • %APPDATA%\zoom\zoom_install_src\znetutils.dll
  • %TEMP%\7zs80ab8b58\installer.exe
  • %APPDATA%\zoom\zoom_install_src\zoom.exe
  • %APPDATA%\zoom\zoom_install_src\zzhostipcsdk.dll
  • %APPDATA%\zoom\zoom_install_src\zzhost.dll
  • %APPDATA%\zoom\zoom_install_src\zwinres.dll
  • %APPDATA%\zoom\zoom_install_src\zwebview2agent.exe
  • %APPDATA%\zoom\zoom_install_src\zwebservice.dll
  • %APPDATA%\zoom\zoom_install_src\zwbuires.dll
  • %APPDATA%\zoom\zoom_install_src\zwbui.dll
  • %APPDATA%\zoom\zoom_install_src\zvideoui.dll
  • %APPDATA%\zoom\zoom_install_src\zvideoapp.dll
  • %APPDATA%\zoom\zoom_install_src\zupdater.exe
  • %APPDATA%\zoom\zoom_install_src\zunifywebview.dll
  • %APPDATA%\zoom\zoom_install_src\zuires.dll
  • %APPDATA%\zoom\zoom_install_src\zui.dll
  • %APPDATA%\zoom\zoom_install_src\ztscoder.exe
  • %APPDATA%\zoom\zoom_install_src\zrcsdk.dll
  • %APPDATA%\zoom\zoom_install_src\zptapp.dll
  • %APPDATA%\zoom\zoom_install_src\zpsapp.dll
  • %APPDATA%\zoom\zoom_install_src\zoutlookimutil.dll
  • %APPDATA%\zoom\zoom_install_src\zoom_launcher.exe
  • %APPDATA%\zoom\zoom_install_src\zoomtelemetry.dll
  • %APPDATA%\zoom\zoom_install_src\zoomtask.dll
  • %APPDATA%\zoom\zoom_install_src\zoomoutlookimplugin.exe
  • %APPDATA%\zoom\zoom_install_src\zoominstall.xml
  • %APPDATA%\zoom\zoom_install_src\zoomdocconverter.exe
  • %APPDATA%\zoom\zoom_install_src\zoombase_crypto_shared.dll
  • %APPDATA%\zoom\zoom_install_src\turbojpeg.dll
  • %APPDATA%\zoom\zoom_install_src\znetdiagnostic.dll
  • %APPDATA%\zoom\zoom_install_src\tp.dll
  • %APPDATA%\zoom\zoom_install_src\meeting_raisehand_chime.pcm
  • %APPDATA%\zoom\zoom_install_src\mcm.dll
  • %APPDATA%\zoom\zoom_install_src\libssl-3-zm.dll
  • %APPDATA%\zoom\zoom_install_src\libmpg123.dll
  • %APPDATA%\zoom\zoom_install_src\libcrypto-3-zm.dll
  • %APPDATA%\zoom\zoom_install_src\leave.pcm
  • %APPDATA%\zoom\zoom_install_src\duilib_license.txt
  • %APPDATA%\zoom\zoom_install_src\duilib.dll
  • %APPDATA%\zoom\zoom_install_src\droplet.pcm
  • %APPDATA%\zoom\zoom_install_src\directui_license.txt
  • %APPDATA%\zoom\zoom_install_src\dingdong1.pcm
  • %APPDATA%\zoom\zoom_install_src\dingdong.pcm
  • %APPDATA%\zoom\zoom_install_src\crashrpt_lang.ini
  • %APPDATA%\zoom\zoom_install_src\cptshare.dll
  • %APPDATA%\zoom\zoom_install_src\cptservice.exe
  • %APPDATA%\zoom\zoom_install_src\cptinstall.exe
  • %APPDATA%\zoom\zoom_install_src\cpthost.exe
  • %APPDATA%\zoom\zoom_install_src\cptcontrol.exe
  • %APPDATA%\zoom\zoom_install_src\cmmlib.dll
  • %APPDATA%\zoom\zoom_install_src\cmmbrowserengine.dll
  • %APPDATA%\zoom\zoom_install_src\cmmbiz.dll
  • %APPDATA%\zoom\zoom_install_src\clap-medium.pcm
  • %APPDATA%\zoom\zoom_install_src\clap-high.pcm
  • %APPDATA%\zoom\zoom_install_src\cares.dll
  • %APPDATA%\zoom\zoom_install_src\asproxy.dll
  • %APPDATA%\zoom\zoom_install_src\archival.pcm
  • %APPDATA%\zoom\zoom_install_src\meeting_chat_chime.pcm
  • %APPDATA%\zoom\zoom_install_src\mfadapter.dll
  • %APPDATA%\zoom\zoom_install_src\ring_spatial.pcm
  • %APPDATA%\zoom\zoom_install_src\msaalib.dll
  • %APPDATA%\zoom\zoom_install_src\ring.pcm
  • %APPDATA%\zoom\zoom_install_src\reslib.dll
  • %APPDATA%\zoom\zoom_install_src\record_stop.pcm
  • %APPDATA%\zoom\zoom_install_src\record_start.pcm
  • %APPDATA%\zoom\zoom_install_src\percussion_pause.pcm
  • %APPDATA%\zoom\zoom_install_src\percussion.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\ring_pstn.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_star.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_hash.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_a.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_9.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_8.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_7.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_6.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_5.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_4.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_3.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_2.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_1.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\dtmf_0.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\double_beep.pcm
  • %APPDATA%\zoom\zoom_install_src\pcm\beep_intercom.pcm
  • %APPDATA%\zoom\zoom_install_src\nydus.dll
  • %APPDATA%\zoom\zoom_install_src\nanosvg_license.txt
  • %APPDATA%\zoom\zoom_install_src\mute.pcm
  • %APPDATA%\zoom\zoom_install_src\ssb_sdk.dll
  • %TEMP%\7zs80ab8b58\zoom.msi
Miscellaneous
Searches for the following windows
  • ClassName: 'zoom.us Installer Engine' WindowName: 'Zoom Workplace Installer'
Creates and executes the following
  • '%TEMP%\7zs80ab8b58\installer.exe'
  • '%TEMP%\7zs80ab8b58\installer.exe' /addfwexception --bin_home="%APPDATA%\Zoom\bin"
Executes the following
  • '%TEMP%\7zs80ab8b58\installer.exe' /addfwexception --bin_home="%APPDATA%\Zoom\bin"' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android