Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.PWS.Siggen1.62037

Добавлен в вирусную базу Dr.Web: 2017-02-18

Описание добавлено:

Техническая информация

Вредоносные функции:
Ищет ветки реестра, отвечающие за хранение паролей сторонними программами:
  • [<HKCU>\Software\SimonTatham\PuTTY\Sessions]
Изменения в файловой системе:
Создает следующие файлы:
  • %TEMP%\Mxt100\usr\share\X11\xkb\semantics\basic
  • %TEMP%\Mxt100\usr\share\X11\xkb\semantics\complete
  • %TEMP%\Mxt100\usr\share\X11\xkb\semantics\default
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\xorg.xml
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\xkb.dtd
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\xorg
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\xorg.lst
  • %TEMP%\Mxt100\usr\share\X11\xkb\semantics\xtest
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\am
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\apl
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ara
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\altwin
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ad
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\af
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\al
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\xfree98
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\sgi_vndr\iris
  • %TEMP%\Mxt100\usr\share\X11\xkb\keymap\xfree86
  • %TEMP%\Mxt100\usr\share\X11\xkb\keymap\xfree98
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\sgi_vndr\indy
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\digital_vndr\lk
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\digital_vndr\pc
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\sgi_vndr\indigo
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\base
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\evdev.extras.xml
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\evdev.lst
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\evdev.xml
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\evdev
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\base.extras.xml
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\base.lst
  • %TEMP%\Mxt100\usr\share\X11\xkb\rules\base.xml
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\de
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\dk
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ee
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\cz
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\cn
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\compose
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ctrl
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\empty
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\fi
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\fo
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\fr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\eurosign
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\epo
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\es
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\et
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\cm
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\be
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\bg
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\br
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\bd
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\at
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\az
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ba
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\brai
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\capslock
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\cd
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ch
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ca
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\bt
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\bw
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\by
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\xfree98
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\xtest
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\amiga
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\ataritt
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\xfree86
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\olpc
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\pc
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\pc98
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\chicony
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\hp
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\keytronic
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\kinesis
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\hhk
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\dell
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\everex
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\fujitsu
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\norepeat
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\complete
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\default
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\iso9995
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\caps
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\accessx
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\basic
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\japan
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\level5
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\misc
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\mousekeys
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\ledscroll
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\keypad
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\ledcaps
  • %TEMP%\Mxt100\usr\share\X11\xkb\compat\lednum
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\ataritt
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\empty
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\evdev
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\amiga
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\sgi_vndr\indy
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\sgi_vndr\O2
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\aliases
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\fujitsu
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\sony
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\sun
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\xfree86
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\olpc
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\hp
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\ibm
  • %TEMP%\Mxt100\usr\share\X11\xkb\keycodes\macintosh
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\sgi_vndr\indigo
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\northgate
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\pc
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\sanwa
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\nokia
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\macintosh
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\microsoft
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\nec
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\sony
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\digital_vndr\lk
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\digital_vndr\pc
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\digital_vndr\unix
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\winbook
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\sun
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\thinkpad
  • %TEMP%\Mxt100\usr\share\X11\xkb\geometry\typematrix
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\gb
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\de
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\dk
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\fi
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\ch
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\fujitsu_vndr\us
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\hp_vndr\us
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\apple
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\fr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\latam
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\nl
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\no
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\jp
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\gb
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\is
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\it
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\fujitsu_vndr\jp
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\typo
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\tz
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ua
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\tw
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\tj
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\tm
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\tr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\us
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\digital_vndr\pc
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\digital_vndr\us
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\digital_vndr\vt
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\digital_vndr\lk
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\uz
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\vn
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\za
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\de
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\dk
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\ee
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\cz
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\br
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\ca
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\ch
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\es
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\it
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\jp
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\kr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\gr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\fi
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\fr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\gb
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\be
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\nokia_vndr\rx-44
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\nokia_vndr\rx-51
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\nokia_vndr\su-8w
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\nec_vndr\jp
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\pt
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\se
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\macintosh_vndr\us
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sgi_vndr\jp
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sharp_vndr\ws020sh
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sony_vndr\us
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sun_vndr\ara
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sharp_vndr\ws011sh
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sharp_vndr\sl-c3x00
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sharp_vndr\ws003sh
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sharp_vndr\ws007sh
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\th
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\kr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\kz
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\la
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\kpdl
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ke
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\kg
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\kh
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\latam
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\lt
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\lv
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ma
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\lk
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\latin
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\level3
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\level5
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\jp
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\group
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\hr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\hu
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\gr
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ge
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\gh
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\gn
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ie
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ir
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\is
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\it
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\iq
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\il
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\in
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\inet
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\rs
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ru
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\rupeesign
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ro
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\pk
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\pl
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\pt
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\se
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\srvr_ctrl
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sy
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\terminate
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sn
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\shift
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\si
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\sk
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ph
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ml
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\mm
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\mn
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\mk
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\mao
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\md
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\me
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\mt
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\no
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\np
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\olpc
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\nl
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\mv
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\nbsp
  • %TEMP%\Mxt100\usr\share\X11\xkb\symbols\ng
  • %TEMP%\Mxt100\usr\share\X11\locale\am_ET.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\armscii-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\armscii-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\am_ET.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\locale.alias
  • %TEMP%\Mxt100\usr\share\X11\locale\locale.dir
  • %TEMP%\Mxt100\usr\share\X11\locale\am_ET.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\armscii-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\en_US.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\en_US.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\georgian-academy\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\en_US.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\C\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\C\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\C\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\compose.dir
  • %TEMP%\Mxt100\usr\share\blackbox\close.xbm
  • %TEMP%\Mxt100\usr\share\blackbox\maximize.xbm
  • %TEMP%\Mxt100\usr\share\blackbox\minimize.xbm
  • %TEMP%\Mxt100\bin\zlib1.dll
  • %TEMP%\Mxt100\bin\swrast_dri.so
  • %TEMP%\Mxt100\bin\twm_w32.exe
  • %TEMP%\Mxt100\bin\xkbcomp_w32.exe
  • %TEMP%\Mxt100\usr\share\blackbox\refresh.xbm
  • %TEMP%\Mxt100\usr\share\X11\rgb.txt
  • %TEMP%\Mxt100\usr\share\X11\XErrorDB
  • %TEMP%\Mxt100\usr\share\X11\XKeysymDB
  • %TEMP%\Mxt100\usr\share\X11\default.xkm
  • %TEMP%\Mxt100\usr\share\blackbox\resize.xbm
  • %TEMP%\Mxt100\usr\share\blackbox\style.twmrc
  • %TEMP%\Mxt100\usr\share\locale\locale.alias
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-11\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-11\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-11\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-10\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-1\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-10\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-10\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-13\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-14\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-15\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-15\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-14\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-13\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-13\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-14\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-1\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\georgian-ps\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ibm-cp1133\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ibm-cp1133\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\georgian-ps\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\georgian-academy\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\georgian-academy\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\georgian-ps\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ibm-cp1133\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\isiri-3342\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\isiri-3342\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-1\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\isiri-3342\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iscii-dev\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iscii-dev\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iscii-dev\XLC_LOCALE
  • %TEMP%\Mxt100\bin\protocol.txt
  • %TEMP%\Mxt100\bin\MobaCalc
  • %TEMP%\Mxt100\bin\MobaTextEditor
  • %TEMP%\Mxt100\bin\MobaCompareFiles
  • %TEMP%\Mxt100\bin\MobaPictureViewer
  • %TEMP%\Mxt100\etc\init.d\nfs
  • %TEMP%\Mxt100\etc\init.d\vnc
  • %TEMP%\Mxt100\bin\MobaListPorts
  • %TEMP%\Mxt100\bin\MobaCompareFolders
  • %TEMP%\Mxt100\etc\protocol
  • %TEMP%\Mxt100\etc\services
  • %TEMP%\Mxt100\tmp\home_%USERNAME%\Desktop
  • %TEMP%\Mxt100\etc\networks
  • %TEMP%\Mxt100\usr\share\zoneinfo\posixrules
  • %TEMP%\Mxt100\bin\sh
  • %TEMP%\Mxt100\etc\hosts
  • %TEMP%\Mxt100\etc\init.d\telnet
  • %TEMP%\Mxt100\etc\fstab
  • %TEMP%\Mxt100\etc\profile
  • %TEMP%\Mxt100\etc\ssh_config
  • %TEMP%\Mxt100\registry
  • %TEMP%\Mxt100\cygdrive
  • %TEMP%\Mxt100\mnt
  • %TEMP%\Mxt100\media
  • %TEMP%\Mxt100\etc\baseprofile
  • %TEMP%\Mxt100\etc\init.d\ftp
  • %TEMP%\Mxt100\etc\init.d\http
  • %TEMP%\Mxt100\etc\init.d\ssh
  • %TEMP%\Mxt100\etc\init.d\tftp
  • %TEMP%\Mxt100\etc\group
  • %TEMP%\Mxt100\etc\passwd
  • %TEMP%\Mxt100\etc\nsswitch.conf
  • %TEMP%\Mxt100\bin\libXau-6.dll
  • %TEMP%\Mxt100\bin\libxcb-1.dll
  • %TEMP%\Mxt100\bin\libxcb-glx-0.dll
  • %TEMP%\Mxt100\bin\libX11-xcb-1.dll
  • %TEMP%\Mxt100\bin\libSM-6.dll
  • %TEMP%\Mxt100\bin\libwinpthread-1.dll
  • %TEMP%\Mxt100\bin\libX11-6.dll
  • %TEMP%\Mxt100\bin\libxcb-image-0.dll
  • %TEMP%\Mxt100\bin\libXfont-1.dll
  • %TEMP%\Mxt100\bin\libXmu-6.dll
  • %TEMP%\Mxt100\bin\libXt-6.dll
  • %TEMP%\Mxt100\bin\libXext-6.dll
  • %TEMP%\Mxt100\bin\libxcb-shm-0.dll
  • %TEMP%\Mxt100\bin\libxcb-util-1.dll
  • %TEMP%\Mxt100\bin\libXdmcp-6.dll
  • %TEMP%\Mxt100\bin\libnativeGLthunk.dll
  • %TEMP%\Mxt100\tmp\sessions\TERM658021
  • %TEMP%\Mxt100\tmp\sessions\TcpCapture
  • %TEMP%\Mxt100\tmp\65802\1.term
  • %TEMP%\Mxt100\tmp\.term
  • %TEMP%\Mxt100\tmp\home_%USERNAME%\MyDocuments
  • %TEMP%\Mxt100\tmp\home_%USERNAME%\LauncherFolder
  • %TEMP%\Mxt100\tmp\home_%USERNAME%\README.txt
  • %TEMP%\Mxt100\bin\default.xkm
  • %TEMP%\Mxt100\bin\libGL-1.dll
  • %TEMP%\Mxt100\bin\libglapi-0.dll
  • %TEMP%\Mxt100\bin\libICE-6.dll
  • %TEMP%\Mxt100\bin\libgcc_s_dw2-1.dll
  • %TEMP%\Mxt100\bin\dwm_w32.exe
  • %TEMP%\Mxt100\bin\libdl.dll
  • %TEMP%\Mxt100\bin\libfontenc-1.dll
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-15\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\th_TH\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\th_TH.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\th_TH.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\th_TH\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\tatar-cyr\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\tatar-cyr\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\th_TH\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\th_TH.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\vi_VN.tcvn\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\vi_VN.tcvn\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\vi_VN.viscii\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\vi_VN.tcvn\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\tscii-0\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\tscii-0\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\tscii-0\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\tatar-cyr\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1256\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1256\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\mulelao-1\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1256\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1255\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1255\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1255\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\mulelao-1\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ru_RU.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ru_RU.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ru_RU.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\nokhchi-1\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\mulelao-1\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\nokhchi-1\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\nokhchi-1\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.big5hkscs\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.big5\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.big5hkscs\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.big5hkscs\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW.big5\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW.big5\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_TW.big5\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.big5\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.gb18030\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.gb18030\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\vi_VN.viscii\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\vi_VN.viscii\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.gb18030\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_HK.big5\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.gbk\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.gbk\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\zh_CN.gbk\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1251\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-9\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-9\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-7\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-7\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-9\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ja\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ja\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.JIS\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ja\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-9e\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-9e\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-9e\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-7\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-3\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-3\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-4\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-3\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-2\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-2\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-2\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-4\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-6\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-6\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-6\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-5\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-4\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-5\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\iso8859-5\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-r\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-r\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-r\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-c\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ko\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-c\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-c\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-u\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ko_KR.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1251\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\microsoft-cp1251\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ko_KR.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-u\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\koi8-u\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ko_KR.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ko\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.S90\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.SJIS\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.SJIS\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.S90\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.JIS\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.JIS\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.S90\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.SJIS\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ja_JP.UTF-8\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ja_JP.UTF-8\XLC_LOCALE
  • %TEMP%\Mxt100\usr\share\X11\locale\ko\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ja_JP.UTF-8\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.U90\Compose
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.U90\XI18N_OBJS
  • %TEMP%\Mxt100\usr\share\X11\locale\ja.U90\XLC_LOCALE
Присваивает атрибут 'скрытый' для следующих файлов:
  • %TEMP%\Mxt100\etc\hosts
  • %TEMP%\Mxt100\etc\networks
  • %TEMP%\Mxt100\etc\init.d\vnc
  • %TEMP%\Mxt100\bin\sh
  • %TEMP%\Mxt100\etc\protocol
  • %TEMP%\Mxt100\tmp\home_%USERNAME%\MyDocuments
  • %TEMP%\Mxt100\tmp\home_%USERNAME%\LauncherFolder
  • %TEMP%\Mxt100\etc\services
  • %TEMP%\Mxt100\tmp\home_%USERNAME%\Desktop
  • %TEMP%\Mxt100\etc\init.d\nfs
  • %TEMP%\Mxt100\media
  • %TEMP%\Mxt100\registry
  • %TEMP%\Mxt100\cygdrive
  • %TEMP%\Mxt100\mnt
  • %TEMP%\Mxt100\etc\init.d\tftp
  • %TEMP%\Mxt100\etc\init.d\ssh
  • %TEMP%\Mxt100\etc\init.d\telnet
  • %TEMP%\Mxt100\etc\init.d\ftp
  • %TEMP%\Mxt100\etc\init.d\http
Удаляет следующие файлы:
  • %TEMP%\Mxt100\mnt
  • %TEMP%\Mxt100\media
  • %TEMP%\Mxt100\registry
  • %TEMP%\Mxt100\cygdrive
Подменяет следующие файлы:
  • %TEMP%\Mxt100\mnt
  • %TEMP%\Mxt100\media
  • %TEMP%\Mxt100\registry
  • %TEMP%\Mxt100\cygdrive
Другое:
Ищет следующие окна:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'TMobaXtermForm' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке