Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.MulDrop9.30352

Добавлен в вирусную базу Dr.Web: 2019-07-17

Описание добавлено:

Technical Information

Modifies file system
Creates the following files
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\data1.cab
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\difxeb60.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\fonteb60.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\coreeb51.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtuseb41.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtcreb32.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtsteb32.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\drive9f9.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\updae9e9.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtcre9e9.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\copye9ca.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\updae9bb.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devce9ab.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\copye97c.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devce96c.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtuse96c.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\setue94d.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\licee95d.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\strieb80.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\isrteb8f.rra
  • %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\set340.tmp
  • %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\set199.tmp
  • %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\set50.tmp
  • %PROGRAMDATA%\microsoft\windows\start menu\programs\realtek usb 2.0 card reader software\uninstall realtek usb 2.0 card reader software.lnk
  • <DRIVERS>\rtstf285.rra
  • %WINDIR%\syswow64\drivers\rtstf265.rra
  • %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setup.ibt
  • %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setuf1e8.rra
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ctodd21.tmp
  • %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setuf1d9.rra
  • %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setuf1c9.rra
  • %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\dataf12d.rra
  • %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\layof11d.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\difxebdd.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\_isrebbe.rra
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\defaebaf.rra
  • %TEMP%\e556.rra
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\isbew64.rgs
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\isbew64.tlb
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\rtstor.sys
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\driveicon.dll
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\setup.iss
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\setup.inx
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\setup.ini
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\setup.ibt
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\rtusbstor64.inf
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\rtusbstor.inf
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\rtcrdriver64.cat
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\rtcrdriver.cat
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\layout.bin
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\engine32.cab
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\data2.cab
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\data1.hdr
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\setup.exe
  • %TEMP%\issda2a.tmp\setup.ini
  • %TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\rtstor64.sys
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\setdba3.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\isbde6f.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ispdba2.tmp\temp.000
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\isbde20.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\objde00.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\ikernel.rgs
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\isprobe.tlb
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\ispdd92.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\iusdd62.tmp
  • %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setup.ini
  • %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\set564.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\dotdd01.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ikedcb2.tmp
  • %TEMP%\ispdc21.tmp\temp.000
  • %TEMP%\_sedc53.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ispdc32.tmp\temp.000
  • %TEMP%\igddc33.tmp
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\f47282171a95201c717532129f59b05e_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\iscdd32.tmp
  • <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem2.cat
Sets the 'hidden' attribute to the following files
  • <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem2.cat
Deletes the following files
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\setdba3.tmp
  • %TEMP%\igddc33.tmp
  • %TEMP%\_sedc53.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\ispdd92.tmp
  • %CommonProgramFiles(x86)%\installshield\professional\runtime\isbde6f.tmp
  • %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\driveicon.dll
  • %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\rtcrdriver64.cat
  • %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\rtstor64.sys
  • %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\rtusbstor64.inf
Moves the following files
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ispdba2.tmp\temp.000 to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ispdba2.tmp\setup.dll
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtsteb32.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtstor.sys
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtuseb41.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtusbstor.inf
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\coreeb51.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\corecomp.ini
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\fonteb60.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\fontdata.ini
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\difxeb60.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\difxdata.ini
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\strieb80.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\stringtable-0009-english.ips
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\isrteb8f.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\isrt.dll
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\defaebaf.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\default.pal
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\_isrebbe.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\_isres.dll
  • from %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\layof11d.rra to %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\layout.bin
  • from %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\set340.tmp to %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\driveicon.dll
  • from %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\dataf12d.rra to %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\data1.hdr
  • from %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\dataf12d.rra to %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\data1.cab
  • from %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setuf1c9.rra to %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setup.exe
  • from %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setuf1d9.rra to %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setup.inx
  • from %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setuf1e8.rra to %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\setup.ini
  • from %WINDIR%\syswow64\drivers\rtstf265.rra to %WINDIR%\syswow64\drivers\rtstor.sys
  • from <DRIVERS>\rtstf285.rra to <DRIVERS>\rtstor64.sys
  • from %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\set50.tmp to %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\rtcrdriver64.cat
  • from %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\set199.tmp to %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\rtstor64.sys
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtcreb32.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtcrdriver.cat
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\difxebdd.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\difxapi.dll
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtsteb32.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtstor64.sys
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\objde00.tmp to %CommonProgramFiles(x86)%\installshield\professional\runtime\objectps.dll
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ispdba2.tmp\setup.dll to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\setup.dll
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ispdc32.tmp\temp.000 to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ispdc32.tmp\igdi.dll
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ispdc32.tmp\igdi.dll to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\igdi.dll
  • from %TEMP%\ispdc21.tmp\temp.000 to %TEMP%\ispdc21.tmp\_setup.dll
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ikedcb2.tmp to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ikernel.dll
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\dotdd01.tmp to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\dotnetinstaller.exe
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ctodd21.tmp to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\ctor.dll
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\iscdd32.tmp to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\iscript.dll
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\iusdd62.tmp to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\iuser.dll
  • from %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\isbde20.tmp to %CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\isbew64.exe
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\updae9e9.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\setue94d.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\setup.inx
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\licee95d.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\license.txt
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtuse96c.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtusbstor64.inf
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devce96c.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\copye97c.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\copyoem64.exe
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devce9ab.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon.exe
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\updae9bb.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update.exe
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\copye9ca.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\copyoem.exe
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtcre9e9.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtcrdriver64.cat
  • from %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\drive9f9.rra to %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\driveicon.dll
  • from %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\set564.tmp to %TEMP%\{51471534-8178-3f23-50d6-1e426be4761e}\rtusbstor64.inf
Substitutes the following files
  • %TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\rtsteb32.rra
  • %ProgramFiles(x86)%\installshield installation information\{dc24971e-1946-445d-8a82-ce685433fa7d}\dataf12d.rra
Miscellaneous
Creates and executes the following
  • '%TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\setup.exe'
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5022 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0151
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0156 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5021
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0156
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0157 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5011 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0157
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0158 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5014 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5020
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0158
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_500A %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_500A
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5020 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_500F %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_500F
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5014
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5010 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5010
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5021 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5023 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0118
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0113
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0151 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0115 %WINDIR%\INF\oem2.inf
  • '%TEMP%\7zsca847dcf\cardreader_realtek_6.0.6000.2001_vistax64\setup.exe' -deleter
  • '%CommonProgramFiles(x86)%\installshield\professional\runtime\11\50\intel32\isbew64.exe' {DD19BC0E-827B-48CE-9D16-F7917E8B486C}:{9361A40C-F499-40F9-A6FF-7B3D262A1998}
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\copyoem64.exe' 1 %TEMP%\{F6F318CF-3BEC-407F-98BC-F2698DC8EB99}\{DC24971E-1946-445D-8A82-CE685433FA7D}\rtusbstor64.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0111 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5025
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0111
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0113 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5022
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5025 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0118 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5024 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0115
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5011
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0116 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0117
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5023
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0116
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5024
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0117 %WINDIR%\INF\oem2.inf
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5023' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5021' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5025 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5020' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5011' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5022 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5014 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5024' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0111' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5020 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5021 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5014' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5022' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0158' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5010' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\copyoem64.exe' 1 %TEMP%\{F6F318CF-3BEC-407F-98BC-F2698DC8EB99}\{DC24971E-1946-445D-8A82-CE685433FA7D}\rtusbstor64.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0111 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5011 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5023 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0113 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0157 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0115 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0113' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0151 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0118' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0118 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0116 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0117 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0116' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0117' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0151' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5010 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0156' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0157' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0158 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_500A %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_500A' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_500F %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_500F' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0BDA&PID_0115' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0BDA&PID_0156 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\update64.exe' USB\VID_0A48&PID_5024 %WINDIR%\INF\oem2.inf' (with hidden window)
  • '%TEMP%\{f6f318cf-3bec-407f-98bc-f2698dc8eb99}\{dc24971e-1946-445d-8a82-ce685433fa7d}\devcon64.exe' remove USB\VID_0A48&PID_5025' (with hidden window)

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке