Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.MulDrop28.43849

Добавлен в вирусную базу Dr.Web: 2024-11-22

Описание добавлено:

Technical Information

To ensure autorun and distribution
Creates the following files on removable media
  • <Drive name for removable media>:\readme.txt
Malicious functions
Terminates or attempts to terminate
the following user processes:
  • firefox.exe
Modifies file system
Creates the following files
  • C:\users\public\log.log
  • %ProgramFiles(x86)%\microsoft analysis services\readme.txt
  • %ProgramFiles(x86)%\microsoft office\readme.txt
  • %ProgramFiles(x86)%\microsoft visual studio 8\readme.txt
  • %ProgramFiles(x86)%\microsoft.net\readme.txt
  • %ProgramFiles(x86)%\msbuild\readme.txt
  • %ProgramFiles(x86)%\opera\readme.txt
  • %ProgramFiles(x86)%\reference assemblies\readme.txt
  • %ProgramFiles(x86)%\steam\readme.txt
  • %ProgramFiles(x86)%\uninstall information\readme.txt
  • %ALLUSERSPROFILE%\adobe\readme.txt
  • %ProgramFiles%\dvd maker\readme.txt
  • %ALLUSERSPROFILE%\microsoft\readme.txt
  • %ALLUSERSPROFILE%\mozilla\readme.txt
  • %ALLUSERSPROFILE%\oracle\readme.txt
  • %ALLUSERSPROFILE%\package cache\readme.txt
  • %ALLUSERSPROFILE%\sun\readme.txt
  • C:\recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\readme.txt
  • C:\users\default\readme.txt
  • %HOMEPATH%\readme.txt
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\readme.txt
  • %ProgramFiles(x86)%\internet explorer\readme.txt
  • %ProgramFiles(x86)%\microsoft\readme.txt
  • %CommonProgramFiles(x86)%\readme.txt
  • %ProgramFiles(x86)%\adobe\readme.txt
  • %ProgramFiles%\uninstall information\readme.txt
  • C:\readme.txt
  • <Current directory>\readme.txt
  • C:\kms\readme.txt
  • C:\msocache\readme.txt
  • %ProgramFiles%\readme.txt
  • %ProgramFiles(x86)%\readme.txt
  • %ALLUSERSPROFILE%\readme.txt
  • C:\recovery\readme.txt
  • C:\users\readme.txt
  • C:\msocache\all users\readme.txt
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\readme.txt
  • %ALLUSERSPROFILE%\microsoft help\readme.txt
  • %CommonProgramFiles%\readme.txt
  • %ProgramFiles%\java\readme.txt
  • %ProgramFiles%\microsoft analysis services\readme.txt
  • %ProgramFiles%\microsoft office\readme.txt
  • %ProgramFiles%\microsoft sql server compact edition\readme.txt
  • %ProgramFiles%\microsoft sync framework\readme.txt
  • %ProgramFiles%\microsoft synchronization services\readme.txt
  • %ProgramFiles%\mozilla firefox\readme.txt
  • %ProgramFiles%\mozilla thunderbird\readme.txt
  • %ProgramFiles%\msbuild\readme.txt
  • %ProgramFiles%\reference assemblies\readme.txt
  • D:\readme.txt
  • %ProgramFiles%\internet explorer\readme.txt
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\readme.txt
Moves the following files
  • from %ProgramFiles%\desktop.ini to %ProgramFiles%\2i7r3udtzapfmuoez6.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\latin1.shp to %ProgramFiles%\microsoft office\office14\4igyk75e36rl37fv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\lookup.dat to %ProgramFiles%\microsoft office\office14\4ibth7uy5gr6kv5t.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\microsoft.businessdata.xml to %ProgramFiles%\microsoft office\office14\4ytq3mxcezrq2awek4ur3uoe2ysr3inweiv7mhnzzv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\microsoft.office.businessapplications.runtime.xml to %ProgramFiles%\microsoft office\office14\4ytq3mxcezrq2awe4ax32uon2tr66aoxzlr35mdxklpbgdn42zvrkuoczss7mtxyzsu37dollsm3udg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\microsoft.office.businessapplications.runtimeui.xml to %ProgramFiles%\microsoft office\office14\4ytq3mxcezrq2awe4ax32uon2tr66aoxzlr35mdxklpbgdn42zvrkuoczss7mtxyzsu37dol5yt7mhnzzv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\microsoft.office.businessdata.xml to %ProgramFiles%\microsoft office\office14\4ytq3mxcezrq2awe4ax32uon2tr66aoxzlr35mdxkivrkp4ecwqqp.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\microsoft.office.interop.infopath.semitrust.xml to %ProgramFiles%\microsoft office\office14\4ytq3mxcezrq2awe4ax32uon2tr67dxt2ys3hmwe4lr32duv2lu3vo7x2yqq7yn7eysrkoxpzyqg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\ipirmv.xml to %ProgramFiles%\microsoft office\office14\4lk67t7z5prlvx52.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\jfont.dat to %ProgramFiles%\microsoft office\office14\44n6hx7tlsf6fyg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\microsoft.office.interop.infopath.xml.xml to %ProgramFiles%\microsoft office\office14\4ytq3mxcezrq2awe4ax32uon2tr67dxt2ys3hmwe4lr32duv2lu3vo7pzyqfmhnzzv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mml2omml.xsl to %ProgramFiles%\microsoft office\office14\4y3tp27c4y3tpo7p5z3g.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\msacc.olb to %ProgramFiles%\microsoft office\office14\4y4tfvunlsbtpvv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mscol11.inf to %ProgramFiles%\microsoft office\office14\4y4t3xu236p7m75ekp.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mscol11.ppd to %ProgramFiles%\microsoft office\office14\4y4t3xu236p7mtfvkv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mscss7cm_en.dub to %ProgramFiles%\microsoft office\office14\zysq3mdx3aiqurdlzpr3kaof.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mscss7cm_es.dub to %ProgramFiles%\microsoft office\office14\zysq3mdx3aiqurdle2r3kaof.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mscss7cm_fr.dub to %ProgramFiles%\microsoft office\office14\zysq3mdx3aiqurd3ekr3kaof.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\microsoft.sharepoint.businessdata.administration.client.xml to %ProgramFiles%\microsoft office\office14\4ytq3mxcezrq2awe5zt3fmxl5wrq7dxtlswb5md4zs7r3mu62lu3fo7w2iqq7dx4ezub6potzlrqmo7nzitq5dxtlsm3udg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mlcfg32.cpl to %ProgramFiles%\microsoft office\office14\4y363i7b32sfmvuv4v.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\ipirm.xml to %ProgramFiles%\microsoft office\office14\4lk67t7zls26uxg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\installed_schemas14.xss to %ProgramFiles%\microsoft office\office14\4lrb3anwziq35sfjeziqvsoz2lsxfzwecwsr3.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\installed_resources14.xss to %ProgramFiles%\microsoft office\office14\4lrb3anwziq35sfje47r3ddye4iq5msi3vrbvmdx.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\advcmp.dic to %ProgramFiles%\microsoft office\office14\klfl2vuz5gr6k75n.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\advtel.dic to %ProgramFiles%\microsoft office\office14\klfl2yfl4vr6k75n.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\advzip.dic to %ProgramFiles%\microsoft office\office14\klfl2q745gr6k75n.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\asciieng.lng to %ProgramFiles%\microsoft office\office14\kl4t3754kyb6eo724snv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\bcsclientmanifest.man to %ProgramFiles%\microsoft office\office14\k4wy3vd2zl7qmafz2lr37sxlezufmdowzp.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\bcsevents.man to %ProgramFiles%\microsoft office\office14\k4wy3ioq2yrbkmsezyvqm.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\bdcmetadata.xsd to %ProgramFiles%\microsoft office\office14\24733doleivqkpot26rbvmd6.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\bdcmetadataresource.xsd to %ProgramFiles%\microsoft office\office14\24733doleivqkpot2ls35mdceys33s4ecwsqk.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\waveform.thmx to %ProgramFiles%\microsoft office\document themes 14\5avr2so3zas3uoxtzwqrv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\cgmimp32.hlp to %ProgramFiles%\microsoft office\office14\kzntu75z5gsx6o7k4ikg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\custom.propdesc to %ProgramFiles%\microsoft office\office14\kzur3ancztrbgmxcew735mdn.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\engdic.dat to %ProgramFiles%\microsoft office\office14\kyb6eif4k2r6kv5t.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\engidx.dat to %ProgramFiles%\microsoft office\office14\kyb6e756ogr6kv5t.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\english.lng to %ProgramFiles%\microsoft office\office14\kyb6exf45z6fmxfekm.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\exlirm.xml to %ProgramFiles%\microsoft office\office14\ky26p7574trlvx52.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\exlirmv.xml to %ProgramFiles%\microsoft office\office14\ky26p7574yofmqfz4v.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\french.lng to %ProgramFiles%\microsoft office\office14\ks465x7n4gr6px7b.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\graph.ico to %ProgramFiles%\microsoft office\office14\ka46ftfkls6t3xp.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\charsettable.chr to %ProgramFiles%\microsoft office\office14\kzt3fm7x2yulkpofzi77mpdkek.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mscss7wre_en.dub to %ProgramFiles%\microsoft office\office14\zysq3mdx3adr6s5j2yrfmsny2k.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mscss7wre_es.dub to %ProgramFiles%\microsoft office\office14\zysq3mdx3adr6s5j2ys7msny2k.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mscss7wre_fr.dub to %ProgramFiles%\microsoft office\office14\zysq3mdx3adr6s5j2ssfmsny2k.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mset7db.kic to %ProgramFiles%\microsoft office\office14\zysq5awr2iifmud422.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\pptirmv.xml to %ProgramFiles%\microsoft office\office14\5wklk7574yofmqfz4v.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\reminder.wav to %ProgramFiles%\microsoft office\office14\54ftu75ekify6o7rklog.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\rswop.icm to %ProgramFiles%\microsoft office\office14\544yexuvls6t3xk.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\segoechess.ttf to %ProgramFiles%\microsoft office\office14\5z7qeddlkzt35mdxlsubksv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\sketchpadtestschema.xml to %ProgramFiles%\microsoft office\office14\5zyq5annzwk3fsft2ysrktdnzw7qup4ecwqqp.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\slerror.xml to %ProgramFiles%\microsoft office\office14\5z365t774a4fmqfz4v.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\spanish.lng to %ProgramFiles%\microsoft office\office14\5zk6fx745z6fmxfekm.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\splashscreen.bmp to %ProgramFiles%\microsoft office\office14\5zp3ppoxzw4q3mxl2yrfmpxzeg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\subscription.xsd to %ProgramFiles%\microsoft office\office14\ezuq6mdne4trgan4zarfmhnx2v.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\thocr.psp to %ProgramFiles%\microsoft office\office14\5i66hvu7lskl3tg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\wordcnvpxy.cnv to %ProgramFiles%\microsoft office\office14\5arr6snnzsdbghnslsiqmav.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\wordirm.xml to %ProgramFiles%\microsoft office\office14\5aby6if45437mqfz4v.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\wordirmv.xml to %ProgramFiles%\microsoft office\office14\5aby6if4543y2o7p4y3g.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\xlcprtid.xml to %ProgramFiles%\microsoft office\office14\ow363tf75i6tko7p4y3g.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\xml2word.xsl to %ProgramFiles%\microsoft office\office14\ow3tp27r4a46ko7p5z3g.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\xocr3.psp to %ProgramFiles%\microsoft office\office14\owbt3tixlskl3tg.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\browser\crashreporter-override.ini to %ProgramFiles%\mozilla firefox\browser\2zs3fmdke47rgdd7ei7r6ooces7r6mx42i77muoez6.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\browser\omni.ja to %ProgramFiles%\mozilla firefox\browser\zaqqmu4ez4vv.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\browser\override.ini to %ProgramFiles%\mozilla firefox\browser\zad35mx7zl735ox4zstv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\pptirm.xml to %ProgramFiles%\microsoft office\office14\5wklk7574trlvx52.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\ospp.vbs to %ProgramFiles%\microsoft office\office14\4a4ygtwe5swl3.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\outlfltr.dat to %ProgramFiles%\microsoft office\office14\4a5ykxf34i5l6o76kl5g.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\ospp.htm to %ProgramFiles%\microsoft office\office14\4a4ygtwe4w56u.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mset7en.kic to %ProgramFiles%\microsoft office\office14\zysq5awr2yrfmud422.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mset7es.kic to %ProgramFiles%\microsoft office\office14\zysq5awr2ys7mud422.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mset7fr.kic to %ProgramFiles%\microsoft office\office14\zysq5awr2ssfmud422.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mset7ge.kic to %ProgramFiles%\microsoft office\office14\zysq5awr2a77mud422.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mset7jp.kic to %ProgramFiles%\microsoft office\office14\zysq5awrz4pfmud422.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\msn.ico to %ProgramFiles%\microsoft office\office14\4y4tmo74kzbv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mso0127.acl to %ProgramFiles%\microsoft office\office14\4y4th2wi3kd7mv5n4v.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\msoutl.olb to %ProgramFiles%\microsoft office\office14\4y4thy5t4vr6hxff.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\msppt.olb to %ProgramFiles%\microsoft office\office14\4y4ygtftlsbtpvv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mspub.tlb to %ProgramFiles%\microsoft office\office14\4y4ygy5fls56pvv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\msword.olb to %ProgramFiles%\microsoft office\office14\4y4yexu7kvr6hxff.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\mysl.ico to %ProgramFiles%\microsoft office\office14\4y2y3xwe4lwth.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\ocrhc.dat to %ProgramFiles%\microsoft office\office14\4awy67fnlsf6fyg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\ocrvc.dat to %ProgramFiles%\microsoft office\office14\4awy6y7nlsf6fyg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\oemprint.cat to %ProgramFiles%\microsoft office\office14\4aftutf74lblko7nkl5g.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\olkirm.xml to %ProgramFiles%\microsoft office\office14\4a36q7574trlvx52.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\olkirmv.xml to %ProgramFiles%\microsoft office\office14\4a36q7574yofmqfz4v.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\omml2mml.xsl to %ProgramFiles%\microsoft office\office14\4a3tuxw74y3tpo7p5z3g.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\office14\onenoteirm.xml to %ProgramFiles%\microsoft office\office14\4ab65x7c5ift7t7zls26uxg.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\distibution\policies.json to %ProgramFiles%\mozilla firefox\distibution\ewrqpuonzl7r3ox5ezrqm.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\verve.thmx to %ProgramFiles%\microsoft office\document themes 14\5s7r6axllsu3vdop.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\urban.thmx to %ProgramFiles%\microsoft office\document themes 14\5ys36poelsu3vdop.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\trek.thmx to %ProgramFiles%\microsoft office\document themes 14\5is35useeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\updater.ini to %ProgramFiles%\mozilla thunderbird\eyp3kpot2ysfmuoez6.dragonforce_encrypted
  • from %ProgramFiles%\winrar\default.sfx to %ProgramFiles%\winrar\ki7q2poyziufmtu3og.dragonforce_encrypted
  • from %ProgramFiles%\winrar\default64.sfx to %ProgramFiles%\winrar\ki7q2poyziun2zwe5znlv.dragonforce_encrypted
  • from %ProgramFiles%\winrar\descript.ion to %ProgramFiles%\winrar\ki7r3pd7zlpbkox4zarg.dragonforce_encrypted
  • from %ProgramFiles%\winrar\license.txt to %ProgramFiles%\winrar\4itq3soeez77manpev.dragonforce_encrypted
  • from %ProgramFiles%\winrar\order.htm to %ProgramFiles%\winrar\4as3kso7lstbkdk.dragonforce_encrypted
  • from %ProgramFiles%\winrar\rar.txt to %ProgramFiles%\winrar\54vr6oxtcwug.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\thunderbird.visualelementsmanifest.xml to %ProgramFiles%\mozilla thunderbird\eitb5dx62ys36uo72vrl2uoxeyvqpio22yqq5dxtez3qfdx42s7r3awecwqqp.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\update-settings.ini to %ProgramFiles%\mozilla thunderbird\eyp3kpot2tqr3soteitqmsdxlstqmuk.dragonforce_encrypted
  • from %ProgramFiles%\winrar\rarfiles.lst to %ProgramFiles%\winrar\54vr6ix4zi7r3ox2ezug.dragonforce_encrypted
  • from %ProgramFiles%\winrar\whatsnew.txt to %ProgramFiles%\winrar\5at3fanx4s7reoxtcwug.dragonforce_encrypted
  • from %ProgramFiles%\winrar\wincon.sfx to %ProgramFiles%\winrar\5atqmvdczprl3i7p.dragonforce_encrypted
  • from %ProgramFiles%\winrar\wincon64.sfx to %ProgramFiles%\winrar\5atqmvdczpdnko7xks2g.dragonforce_encrypted
  • from %ProgramFiles%\winrar\winrar.chm to %ProgramFiles%\winrar\5atqmt7w5kr33unz.dragonforce_encrypted
  • from %ProgramFiles%\winrar\zip.sfx to %ProgramFiles%\winrar\o4trgo7xks2g.dragonforce_encrypted
  • from %ProgramFiles%\winrar\zip64.sfx to %ProgramFiles%\winrar\o4trgzitls4t2qg.dragonforce_encrypted
  • from %ProgramFiles%\winrar\zipnew.dat to %ProgramFiles%\winrar\c4trgdxlemr3kpot.dragonforce_encrypted
  • from %ProgramFiles%\winrar\rarnew.dat to %ProgramFiles%\winrar\e4vr6dxlemr3kpot.dragonforce_encrypted
  • from %ProgramFiles%\winrar\uninstall.lst to %ProgramFiles%\winrar\5yr37dxxeivqpdwezisrk.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\removed-files to %ProgramFiles%\mozilla thunderbird\e47quddq2y7fusx4zi7r3.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\precomplete to %ProgramFiles%\mozilla thunderbird\ews35pdczyp3psot2t.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\platform.ini to %ProgramFiles%\mozilla thunderbird\ewq3fan3zas3uox4zstv.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\accessible.tlb to %ProgramFiles%\mozilla firefox\kliq3soxeztq6dnllsu3ppv.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\application.ini to %ProgramFiles%\mozilla firefox\2lpbgdn42zvrkuoczpr37dx4.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\crashreporter.ini to %ProgramFiles%\mozilla firefox\2zs3fmdke47rgdd7ei7r6ox4zstv.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\dependentlibs.list to %ProgramFiles%\mozilla firefox\2i7rgsoe2i7qman2zlib3ox2zlsrk.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\firefox.visualelementsmanifest.xml to %ProgramFiles%\mozilla firefox\2str6so3zamfmyx4ezuqfdflzi7qusoeeistupoezlx35mdtlsm3udg.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\install.log to %ProgramFiles%\mozilla firefox\zlrb3anwziqfmdnc2m.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\omni.ja to %ProgramFiles%\mozilla firefox\zaqqmu4ez4vv.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\platform.ini to %ProgramFiles%\mozilla firefox\ewq3fan3zas3uox4zstv.dragonforce_encrypted
  • from %ProgramFiles(x86)%\desktop.ini to %ProgramFiles(x86)%\2i7r3udtzapfmuoez6.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\precomplete to %ProgramFiles%\mozilla firefox\ews35pdczyp3psot2t.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\update-settings.ini to %ProgramFiles%\mozilla firefox\eyp3kpot2tqr3soteitqmsdxlstqmuk.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\updater.ini to %ProgramFiles%\mozilla firefox\eyp3kpot2ysfmuoez6.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\accessible.tlb to %ProgramFiles%\mozilla thunderbird\kliq3soxeztq6dnllsu3ppv.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\application.ini to %ProgramFiles%\mozilla thunderbird\2lpbgdn42zvrkuoczpr37dx4.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\crashreporter.ini to %ProgramFiles%\mozilla thunderbird\2zs3fmdke47rgdd7ei7r6ox4zstv.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\dependentlibs.list to %ProgramFiles%\mozilla thunderbird\2i7rgsoe2i7qman2zlib3ox2zlsrk.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\install.log to %ProgramFiles%\mozilla thunderbird\zlrb3anwziqfmdnc2m.dragonforce_encrypted
  • from %ProgramFiles%\mozilla thunderbird\omni.ja to %ProgramFiles%\mozilla thunderbird\zaqqmu4ez4vv.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\removed-files to %ProgramFiles%\mozilla firefox\e47quddq2y7fusx4zi7r3.dragonforce_encrypted
  • from %ProgramFiles(x86)%\msbuild\microsoft.office.infopath.targets to %ProgramFiles(x86)%\msbuild\4ytq3mxcezrq2awe4ax32uon2tr67dx3zak3fanklsu3fmxb2yub3.dragonforce_encrypted
  • from %ProgramFiles(x86)%\opera\installation_status.xml to %ProgramFiles(x86)%\opera\zlrb3anwziq3fan4zarlhmdt2lub5msecwqqp.dragonforce_encrypted
  • from %ProgramFiles(x86)%\opera\installer_prefs.json to %ProgramFiles(x86)%\opera\zlrb3anwziq35m7jews35sxxlsyb3dde.dragonforce_encrypted
  • from %ProgramFiles(x86)%\opera\launcher.visualelementsmanifest.xml to %ProgramFiles(x86)%\opera\zivr5dxnzw7r6oxqzlsr5po22yq35dolzsub3dowzstq2soxevrbvdo2.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\executive.thmx to %ProgramFiles%\microsoft office\document themes 14\kym35pdyeitr2s4eeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\flow.thmx to %ProgramFiles%\microsoft office\document themes 14\ksq3haseeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\foundry.thmx to %ProgramFiles%\microsoft office\document themes 14\ksrr5dx6e4m7mankzymg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\grid.thmx to %ProgramFiles%\microsoft office\document themes 14\kas37sweeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\hardcover.thmx to %ProgramFiles%\microsoft office\document themes 14\4wvr6snnzad35mieeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\horizon.thmx to %ProgramFiles%\microsoft office\document themes 14\4wrr6uouzarfmankzymg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\median.thmx to %ProgramFiles%\microsoft office\document themes 14\4y7qkuowzprbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\metro.thmx to %ProgramFiles%\microsoft office\document themes 14\4y7rkmxclsu3vdop.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\module.thmx to %ProgramFiles%\microsoft office\document themes 14\4yrqkao22trbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\newsprint.thmx to %ProgramFiles%\microsoft office\document themes 14\4s7remdve4tqmaweeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\opulent.thmx to %ProgramFiles%\microsoft office\document themes 14\4apb5dnlzsufmankzymg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\oriel.thmx to %ProgramFiles%\microsoft office\document themes 14\4as37so2lsu3vdop.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\origin.thmx to %ProgramFiles%\microsoft office\document themes 14\4as37sd4zprbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\paper.thmx to %ProgramFiles%\microsoft office\document themes 14\5wvrgso7lsu3vdop.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\perspective.thmx to %ProgramFiles%\microsoft office\document themes 14\5w7r6mdv2yirkuoq2trbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\pushpin.thmx to %ProgramFiles%\microsoft office\document themes 14\5wur3unvzlrfmankzymg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\slipstream.thmx to %ProgramFiles%\microsoft office\document themes 14\5zq37mnxeis35pozlsu3vdop.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\solstice.thmx to %ProgramFiles%\microsoft office\document themes 14\5zrqpmdtzliq5oxtzwqrv.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\technic.thmx to %ProgramFiles%\microsoft office\document themes 14\5i7q3unezli7mankzymg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\essential.thmx to %ProgramFiles%\microsoft office\document themes 14\kysr3soeeitqfdweeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\elemental.thmx to %ProgramFiles%\microsoft office\document themes 14\kyq35dolzsu3fdweeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\equity.thmx to %ProgramFiles%\microsoft office\document themes 14\kypr5uotc6rbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\couture.thmx to %ProgramFiles%\microsoft office\document themes 14\kzrr5anye477mankzymg.dragonforce_encrypted
  • from %ProgramFiles(x86)%\opera\resources.pri to %ProgramFiles(x86)%\opera\547r3ddye4iq5mseews37.dragonforce_encrypted
  • from %ProgramFiles(x86)%\steam\steam.cfg to %ProgramFiles(x86)%\steam\ezu35pozlsiq2sp.dragonforce_encrypted
  • from %ProgramFiles%\internet explorer\signup\install.ins to %ProgramFiles%\internet explorer\signup\zlrb3anwziqfmuoee2.dragonforce_encrypted
  • from %ProgramFiles%\java\jre1.8.0_45\copyright to %ProgramFiles%\java\jre1.8.0_45\kzbygq574lntvyg.dragonforce_encrypted
  • from %ProgramFiles%\java\jre1.8.0_45\license to %ProgramFiles%\java\jre1.8.0_45\4i6t3i5e5zfv.dragonforce_encrypted
  • from %ProgramFiles%\java\jre1.8.0_45\release to %ProgramFiles%\java\jre1.8.0_45\e47qpsowez7v.dragonforce_encrypted
  • from %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt to %ProgramFiles%\java\jre1.8.0_45\5i667t765wgy6yfs4i6t3i5e5zfy6i5wki3t5o55klo6fi7plsubvag.dragonforce_encrypted
  • from %ProgramFiles%\java\jre1.8.0_45\welcome.html to %ProgramFiles%\java\jre1.8.0_45\5a7qppdczy77muntzyqg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\adjacency.thmx to %ProgramFiles%\microsoft office\document themes 14\kl73tpon2yr33h4eeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\angles.thmx to %ProgramFiles%\microsoft office\document themes 14\klr3ednle2rbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\apex.thmx to %ProgramFiles%\microsoft office\document themes 14\klp35hweeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\apothecary.thmx to %ProgramFiles%\microsoft office\document themes 14\klp3hank2yiqfmxslsu3vdop.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\aspect.thmx to %ProgramFiles%\microsoft office\document themes 14\klsrgsonevrbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\austin.thmx to %ProgramFiles%\microsoft office\document themes 14\klur3an4zprbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\black tie.thmx to %ProgramFiles%\microsoft office\document themes 14\k4q3fpdo6w537s4eeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\civic.thmx to %ProgramFiles%\microsoft office\document themes 14\kztr2uonlsu3vdop.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\clarity.thmx to %ProgramFiles%\microsoft office\document themes 14\kzq3fmx4eim7mankzymg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\composite.thmx to %ProgramFiles%\microsoft office\document themes 14\kzrqumnceztrks4eeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\concourse.thmx to %ProgramFiles%\microsoft office\document themes 14\kzrqmpdceysb3s4eeit3uhg.dragonforce_encrypted
  • from %ProgramFiles%\microsoft office\document themes 14\thatch.thmx to %ProgramFiles%\microsoft office\document themes 14\5it3fannzgrbkunzcg.dragonforce_encrypted
  • from %ProgramFiles%\mozilla firefox\fonts\twemojimozilla.ttf to %ProgramFiles%\mozilla firefox\fonts\5idq5docz4ttudduzlq3pp4eeiu32.dragonforce_encrypted
Modifies the following files
  • %ProgramFiles%\desktop.ini
  • %ProgramFiles%\mozilla thunderbird\updater.ini
  • %ProgramFiles%\mozilla thunderbird\update-settings.ini
  • %ProgramFiles%\mozilla thunderbird\thunderbird.visualelementsmanifest.xml
  • %ProgramFiles%\mozilla thunderbird\removed-files
  • %ProgramFiles%\mozilla thunderbird\precomplete
  • %ProgramFiles%\mozilla thunderbird\platform.ini
  • %ProgramFiles%\mozilla thunderbird\omni.ja
  • %ProgramFiles%\mozilla thunderbird\install.log
  • %ProgramFiles%\mozilla thunderbird\dependentlibs.list
  • %ProgramFiles%\mozilla thunderbird\crashreporter.ini
  • %ProgramFiles%\mozilla thunderbird\application.ini
  • %ProgramFiles%\mozilla thunderbird\accessible.tlb
  • %ProgramFiles%\mozilla firefox\updater.ini
  • %ProgramFiles%\mozilla firefox\update-settings.ini
  • %ProgramFiles%\mozilla firefox\removed-files
  • %ProgramFiles%\mozilla firefox\precomplete
  • %ProgramFiles%\mozilla firefox\platform.ini
  • %ProgramFiles%\mozilla firefox\omni.ja
  • %ProgramFiles%\mozilla firefox\install.log
  • %ProgramFiles%\mozilla firefox\firefox.visualelementsmanifest.xml
  • %ProgramFiles%\mozilla firefox\dependentlibs.list
  • %ProgramFiles%\mozilla firefox\crashreporter.ini
  • %ProgramFiles%\mozilla firefox\application.ini
  • %ProgramFiles%\mozilla firefox\accessible.tlb
  • C:\users\desktop.ini
  • %ProgramFiles(x86)%\desktop.ini
  • <Drive name for removable media>:\delete.avi
  • %ProgramFiles%\winrar\readme.txt
  • %ProgramFiles%\winrar\descript.ion
Modifies multiple files.
Network activity
Connects to
  • '<LOCALNET>.26.0':445
  • '<LOCALNET>.26.161':445
  • '<LOCALNET>.26.162':445
  • '<LOCALNET>.26.163':445
  • '<LOCALNET>.26.164':445
  • '<LOCALNET>.26.165':445
  • '<LOCALNET>.26.166':445
  • '<LOCALNET>.26.167':445
  • '<LOCALNET>.26.168':445
  • '<LOCALNET>.26.169':445
  • '<LOCALNET>.26.170':445
  • '<LOCALNET>.26.171':445
  • '<LOCALNET>.26.172':445
  • '<LOCALNET>.26.173':445
  • '<LOCALNET>.26.175':445
  • '<LOCALNET>.26.189':445
  • '<LOCALNET>.26.176':445
  • '<LOCALNET>.26.177':445
  • '<LOCALNET>.26.178':445
  • '<LOCALNET>.26.179':445
  • '<LOCALNET>.26.180':445
  • '<LOCALNET>.26.181':445
  • '<LOCALNET>.26.182':445
  • '<LOCALNET>.26.183':445
  • '<LOCALNET>.26.184':445
  • '<LOCALNET>.26.185':445
  • '<LOCALNET>.26.186':445
  • '<LOCALNET>.26.187':445
  • '<LOCALNET>.26.188':445
  • '<LOCALNET>.26.160':445
  • '<LOCALNET>.26.174':445
  • '<LOCALNET>.26.159':445
  • '<LOCALNET>.26.142':445
  • '<LOCALNET>.26.129':445
  • '<LOCALNET>.26.130':445
  • '<LOCALNET>.26.131':445
  • '<LOCALNET>.26.132':445
  • '<LOCALNET>.26.133':445
  • '<LOCALNET>.26.134':445
  • '<LOCALNET>.26.135':445
  • '<LOCALNET>.26.136':445
  • '<LOCALNET>.26.137':445
  • '<LOCALNET>.26.138':445
  • '<LOCALNET>.26.139':445
  • '<LOCALNET>.26.140':445
  • '<LOCALNET>.26.141':445
  • '<LOCALNET>.26.143':445
  • '<LOCALNET>.26.157':445
  • '<LOCALNET>.26.144':445
  • '<LOCALNET>.26.145':445
  • '<LOCALNET>.26.146':445
  • '<LOCALNET>.26.147':445
  • '<LOCALNET>.26.148':445
  • '<LOCALNET>.26.149':445
  • '<LOCALNET>.26.150':445
  • '<LOCALNET>.26.151':445
  • '<LOCALNET>.26.152':445
  • '<LOCALNET>.26.153':445
  • '<LOCALNET>.26.154':445
  • '<LOCALNET>.26.155':445
  • '<LOCALNET>.26.156':445
  • '<LOCALNET>.26.158':445
  • '<LOCALNET>.26.207':445
  • '<LOCALNET>.26.253':445
  • '<LOCALNET>.26.192':445
  • '<LOCALNET>.26.225':445
  • '<LOCALNET>.26.226':445
  • '<LOCALNET>.26.227':445
  • '<LOCALNET>.26.228':445
  • '<LOCALNET>.26.229':445
  • '<LOCALNET>.26.230':445
  • '<LOCALNET>.26.231':445
  • '<LOCALNET>.26.232':445
  • '<LOCALNET>.26.233':445
  • '<LOCALNET>.26.234':445
  • '<LOCALNET>.26.235':445
  • '<LOCALNET>.26.236':445
  • '<LOCALNET>.26.237':445
  • '<LOCALNET>.26.239':445
  • '<LOCALNET>.26.191':445
  • '<LOCALNET>.26.240':445
  • '<LOCALNET>.26.241':445
  • '<LOCALNET>.26.242':445
  • '<LOCALNET>.26.243':445
  • '<LOCALNET>.26.244':445
  • '<LOCALNET>.26.245':445
  • '<LOCALNET>.26.246':445
  • '<LOCALNET>.26.247':445
  • '<LOCALNET>.26.248':445
  • '<LOCALNET>.26.249':445
  • '<LOCALNET>.26.250':445
  • '<LOCALNET>.26.251':445
  • '<LOCALNET>.26.252':445
  • '<LOCALNET>.26.224':445
  • '<LOCALNET>.26.128':445
  • '<LOCALNET>.26.223':445
  • '<LOCALNET>.26.206':445
  • '<LOCALNET>.26.193':445
  • '<LOCALNET>.26.194':445
  • '<LOCALNET>.26.195':445
  • '<LOCALNET>.26.196':445
  • '<LOCALNET>.26.197':445
  • '<LOCALNET>.26.198':445
  • '<LOCALNET>.26.199':445
  • '<LOCALNET>.26.200':445
  • '<LOCALNET>.26.201':445
  • '<LOCALNET>.26.202':445
  • '<LOCALNET>.26.203':445
  • '<LOCALNET>.26.204':445
  • '<LOCALNET>.26.205':445
  • '<LOCALNET>.26.190':445
  • '<LOCALNET>.26.221':445
  • '<LOCALNET>.26.208':445
  • '<LOCALNET>.26.209':445
  • '<LOCALNET>.26.210':445
  • '<LOCALNET>.26.211':445
  • '<LOCALNET>.26.212':445
  • '<LOCALNET>.26.213':445
  • '<LOCALNET>.26.214':445
  • '<LOCALNET>.26.215':445
  • '<LOCALNET>.26.216':445
  • '<LOCALNET>.26.217':445
  • '<LOCALNET>.26.218':445
  • '<LOCALNET>.26.219':445
  • '<LOCALNET>.26.220':445
  • '<LOCALNET>.26.222':445
  • '<LOCALNET>.26.238':445
  • '<LOCALNET>.26.127':445
  • '<LOCALNET>.26.110':445
  • '<LOCALNET>.26.33':445
  • '<LOCALNET>.26.34':445
  • '<LOCALNET>.26.35':445
  • '<LOCALNET>.26.36':445
  • '<LOCALNET>.26.37':445
  • '<LOCALNET>.26.38':445
  • '<LOCALNET>.26.39':445
  • '<LOCALNET>.26.40':445
  • '<LOCALNET>.26.41':445
  • '<LOCALNET>.26.42':445
  • '<LOCALNET>.26.43':445
  • '<LOCALNET>.26.44':445
  • '<LOCALNET>.26.45':445
  • '<LOCALNET>.26.47':445
  • '<LOCALNET>.26.61':445
  • '<LOCALNET>.26.48':445
  • '<LOCALNET>.26.49':445
  • '<LOCALNET>.26.50':445
  • '<LOCALNET>.26.51':445
  • '<LOCALNET>.26.52':445
  • '<LOCALNET>.26.53':445
  • '<LOCALNET>.26.54':445
  • '<LOCALNET>.26.55':445
  • '<LOCALNET>.26.56':445
  • '<LOCALNET>.26.57':445
  • '<LOCALNET>.26.58':445
  • '<LOCALNET>.26.59':445
  • '<LOCALNET>.26.60':445
  • '<LOCALNET>.26.32':445
  • '<LOCALNET>.26.46':445
  • '<LOCALNET>.26.31':445
  • '<LOCALNET>.26.14':445
  • '<LOCALNET>.26.1':445
  • '<LOCALNET>.26.2':445
  • '<LOCALNET>.26.3':445
  • '<LOCALNET>.26.4':445
  • '<LOCALNET>.26.5':445
  • '<LOCALNET>.26.6':445
  • '<LOCALNET>.26.7':445
  • '<LOCALNET>.26.8':445
  • '<LOCALNET>.26.9':445
  • '<LOCALNET>.26.10':445
  • '<LOCALNET>.26.11':445
  • '<LOCALNET>.26.12':445
  • '<LOCALNET>.26.13':445
  • '<LOCALNET>.26.15':445
  • '<LOCALNET>.26.29':445
  • '<LOCALNET>.26.16':445
  • '<LOCALNET>.26.17':445
  • '<LOCALNET>.26.18':445
  • '<LOCALNET>.26.19':445
  • '<LOCALNET>.26.20':445
  • '<LOCALNET>.26.21':445
  • '<LOCALNET>.26.22':445
  • '<LOCALNET>.26.23':445
  • '<LOCALNET>.26.24':445
  • '<LOCALNET>.26.25':445
  • '<LOCALNET>.26.26':445
  • '<LOCALNET>.26.27':445
  • '<LOCALNET>.26.28':445
  • '<LOCALNET>.26.30':445
  • '<LOCALNET>.26.79':445
  • '<LOCALNET>.26.125':445
  • '<LOCALNET>.26.64':445
  • '<LOCALNET>.26.97':445
  • '<LOCALNET>.26.98':445
  • '<LOCALNET>.26.99':445
  • '<LOCALNET>.26.100':445
  • '<LOCALNET>.26.101':445
  • '<LOCALNET>.26.102':445
  • '<LOCALNET>.26.103':445
  • '<LOCALNET>.26.104':445
  • '<LOCALNET>.26.105':445
  • '<LOCALNET>.26.106':445
  • '<LOCALNET>.26.107':445
  • '<LOCALNET>.26.108':445
  • '<LOCALNET>.26.109':445
  • '<LOCALNET>.26.111':445
  • '<LOCALNET>.26.63':445
  • '<LOCALNET>.26.112':445
  • '<LOCALNET>.26.113':445
  • '<LOCALNET>.26.114':445
  • '<LOCALNET>.26.115':445
  • '<LOCALNET>.26.116':445
  • '<LOCALNET>.26.117':445
  • '<LOCALNET>.26.118':445
  • '<LOCALNET>.26.119':445
  • '<LOCALNET>.26.120':445
  • '<LOCALNET>.26.121':445
  • '<LOCALNET>.26.122':445
  • '<LOCALNET>.26.123':445
  • '<LOCALNET>.26.124':445
  • '<LOCALNET>.26.96':445
  • '<LOCALNET>.26.126':445
  • '<LOCALNET>.26.95':445
  • '<LOCALNET>.26.78':445
  • '<LOCALNET>.26.65':445
  • '<LOCALNET>.26.66':445
  • '<LOCALNET>.26.67':445
  • '<LOCALNET>.26.68':445
  • '<LOCALNET>.26.69':445
  • '<LOCALNET>.26.70':445
  • '<LOCALNET>.26.71':445
  • '<LOCALNET>.26.72':445
  • '<LOCALNET>.26.73':445
  • '<LOCALNET>.26.74':445
  • '<LOCALNET>.26.75':445
  • '<LOCALNET>.26.76':445
  • '<LOCALNET>.26.77':445
  • '<LOCALNET>.26.62':445
  • '<LOCALNET>.26.93':445
  • '<LOCALNET>.26.80':445
  • '<LOCALNET>.26.81':445
  • '<LOCALNET>.26.82':445
  • '<LOCALNET>.26.83':445
  • '<LOCALNET>.26.84':445
  • '<LOCALNET>.26.85':445
  • '<LOCALNET>.26.86':445
  • '<LOCALNET>.26.87':445
  • '<LOCALNET>.26.88':445
  • '<LOCALNET>.26.89':445
  • '<LOCALNET>.26.90':445
  • '<LOCALNET>.26.91':445
  • '<LOCALNET>.26.92':445
  • '<LOCALNET>.26.94':445
  • '<LOCALNET>.26.254':445

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке