Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop7.29170

Добавлен в вирусную базу Dr.Web: 2017-05-31

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command] '' = '%ProgramFiles%\Mozilla Firefox\firefox.exe'
  • [<HKLM>\SOFTWARE\Classes\FirefoxHTML\shell\open\command] '' = '%ProgramFiles%\Mozilla Firefox\FIREFOX.EXE -requestPending -osint -url "%1"'
  • [<HKLM>\SOFTWARE\Classes\FirefoxURL\shell\open\command] '' = '%ProgramFiles%\Mozilla Firefox\FIREFOX.EXE -requestPending -osint -url "%1"'
Вредоносные функции:
Запускает на исполнение:
  • '%TEMP%\RarSFX0\firefox_setup.exe' -ms -ira
  • '%TEMP%\7zS1.tmp\setup.exe' -ms -ira
  • '%TEMP%\RarSFX0\install.exe'
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\bt2015.bat
Изменения в файловой системе:
Создает следующие файлы:
  • %ProgramFiles%\Mozilla Firefox\res\table-add-column-after-active.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-column-after-hover.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-column-after.gif
  • %ProgramFiles%\Mozilla Firefox\res\mathml.css
  • %ProgramFiles%\Mozilla Firefox\res\quirk.css
  • %ProgramFiles%\Mozilla Firefox\res\svg.css
  • %ProgramFiles%\Mozilla Firefox\res\table-add-column-before-active.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-row-after-hover.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-row-after.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-row-before-active.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-column-before-hover.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-column-before.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-row-after-active.gif
  • %ProgramFiles%\Mozilla Firefox\res\charsetData.properties
  • %ProgramFiles%\Mozilla Firefox\res\cmessage.txt
  • %ProgramFiles%\Mozilla Firefox\res\EditorOverride.css
  • %ProgramFiles%\Mozilla Firefox\res\arrowd.gif
  • %ProgramFiles%\Mozilla Firefox\res\broken-image.gif
  • %ProgramFiles%\Mozilla Firefox\res\charsetalias.properties
  • %ProgramFiles%\Mozilla Firefox\res\forms.css
  • %ProgramFiles%\Mozilla Firefox\res\langGroups.properties
  • %ProgramFiles%\Mozilla Firefox\res\language.properties
  • %ProgramFiles%\Mozilla Firefox\res\loading-image.gif
  • %ProgramFiles%\Mozilla Firefox\res\grabber.gif
  • %ProgramFiles%\Mozilla Firefox\res\hiddenWindow.html
  • %ProgramFiles%\Mozilla Firefox\res\html.css
  • %ProgramFiles%\Mozilla Firefox\res\table-add-row-before-hover.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-sound.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-telnet.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-text.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-image.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-menu.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-movie.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-unknown.gif
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfontCMEX10.properties
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfontCMSY10.properties
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfontMath1.properties
  • %ProgramFiles%\Mozilla Firefox\res\fonts\fontEncoding.properties
  • %ProgramFiles%\Mozilla Firefox\res\fonts\fontNameMap.properties
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfont.properties
  • %ProgramFiles%\Mozilla Firefox\res\table-remove-column.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-remove-row-active.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-remove-row-hover.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-add-row-before.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-remove-column-active.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-remove-column-hover.gif
  • %ProgramFiles%\Mozilla Firefox\res\table-remove-row.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-audio.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-binary.gif
  • %ProgramFiles%\Mozilla Firefox\res\html\gopher-find.gif
  • %ProgramFiles%\Mozilla Firefox\res\ua.css
  • %ProgramFiles%\Mozilla Firefox\res\viewsource.css
  • %ProgramFiles%\Mozilla Firefox\res\wincharset.properties
  • %TEMP%\7zS1.tmp\localized\searchplugins\amazondotcom.xml
  • %TEMP%\7zS1.tmp\localized\searchplugins\answers.xml
  • %TEMP%\7zS1.tmp\localized\searchplugins\creativecommons.xml
  • %TEMP%\7zS1.tmp\localized\defaults\profile\search.rdf
  • %TEMP%\7zS1.tmp\nonlocalized\res\cmessage.txt
  • %TEMP%\7zS1.tmp\nonlocalized\README.txt
  • %TEMP%\7zS1.tmp\localized\searchplugins\eBay.xml
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\qfaservices.xpt
  • %TEMP%\nsc3.tmp\options.ini
  • %TEMP%\nsc3.tmp\components.ini
  • %TEMP%\7zS1.tmp\localized\searchplugins\google.xml
  • %TEMP%\7zS1.tmp\localized\searchplugins\yahoo.xml
  • %TEMP%\7zS1.tmp\nonlocalized\components\browser.xpt
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontSymbol.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\mathml20.properties
  • %TEMP%\7zS1.tmp\localized\old-homepage-default.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontMath4.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontMTExtra.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontPUA.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\transliterate.properties
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\install.rdf
  • %TEMP%\7zS1.tmp\localized\defaults\profile\localstore.rdf
  • %TEMP%\7zS1.tmp\localized\defaults\profile\mimeTypes.rdf
  • %TEMP%\7zS1.tmp\nonlocalized\res\wincharset.properties
  • %TEMP%\7zS1.tmp\nonlocalized\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\install.rdf
  • %TEMP%\nsc3.tmp\shortcuts.ini
  • %ProgramFiles%\Mozilla Firefox\softokn3.chk
  • %ProgramFiles%\Mozilla Firefox\softokn3.dll
  • %ProgramFiles%\Mozilla Firefox\ssl3.dll
  • %ProgramFiles%\Mozilla Firefox\plds4.dll
  • %ProgramFiles%\Mozilla Firefox\README.txt
  • %ProgramFiles%\Mozilla Firefox\smime3.dll
  • %ProgramFiles%\Mozilla Firefox\updater.exe
  • %ProgramFiles%\Mozilla Firefox\xpicleanup.exe
  • %ProgramFiles%\Mozilla Firefox\xpistub.dll
  • %ProgramFiles%\Mozilla Firefox\res\arrow.gif
  • %ProgramFiles%\Mozilla Firefox\xpcom.dll
  • %ProgramFiles%\Mozilla Firefox\xpcom_compat.dll
  • %ProgramFiles%\Mozilla Firefox\xpcom_core.dll
  • %ProgramFiles%\Mozilla Firefox\uninstall\uninstall.log
  • %ProgramFiles%\Mozilla Firefox\firefox.exe
  • %ProgramFiles%\Mozilla Firefox\freebl3.chk
  • %TEMP%\nsc3.tmp\System.dll
  • %ProgramFiles%\Mozilla Firefox\install.log
  • %ProgramFiles%\Mozilla Firefox\AccessibleMarshal.dll
  • %ProgramFiles%\Mozilla Firefox\freebl3.dll
  • %ProgramFiles%\Mozilla Firefox\nss3.dll
  • %ProgramFiles%\Mozilla Firefox\nssckbi.dll
  • %ProgramFiles%\Mozilla Firefox\plc4.dll
  • %ProgramFiles%\Mozilla Firefox\js3250.dll
  • %ProgramFiles%\Mozilla Firefox\LICENSE
  • %ProgramFiles%\Mozilla Firefox\nspr4.dll
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfontMath2.properties
  • %ProgramFiles%\Mozilla Firefox\chrome\toolkit.manifest
  • %ProgramFiles%\Mozilla Firefox\browserconfig.properties
  • %ProgramFiles%\Mozilla Firefox\old-homepage-default.properties
  • %ProgramFiles%\Mozilla Firefox\chrome\reporter.jar
  • %ProgramFiles%\Mozilla Firefox\chrome\reporter.manifest
  • %ProgramFiles%\Mozilla Firefox\chrome\toolkit.jar
  • %ProgramFiles%\Mozilla Firefox\updater.ini
  • %ProgramFiles%\Mozilla Firefox\searchplugins\creativecommons.xml
  • %ProgramFiles%\Mozilla Firefox\searchplugins\eBay.xml
  • %ProgramFiles%\Mozilla Firefox\searchplugins\google.xml
  • %ProgramFiles%\Mozilla Firefox\uninstall\helper.exe
  • %ProgramFiles%\Mozilla Firefox\searchplugins\amazondotcom.xml
  • %ProgramFiles%\Mozilla Firefox\searchplugins\answers.xml
  • %ProgramFiles%\Mozilla Firefox\components\WebContentConverter.js
  • %ProgramFiles%\Mozilla Firefox\components\xpinstal.dll
  • %ProgramFiles%\Mozilla Firefox\chrome\browser.jar
  • %ProgramFiles%\Mozilla Firefox\components\nsURLFormatter.js
  • %ProgramFiles%\Mozilla Firefox\components\nsXmlRpcClient.js
  • %ProgramFiles%\Mozilla Firefox\components\spellchk.dll
  • %ProgramFiles%\Mozilla Firefox\chrome\browser.manifest
  • %ProgramFiles%\Mozilla Firefox\chrome\comm.manifest
  • %ProgramFiles%\Mozilla Firefox\chrome\pippki.jar
  • %ProgramFiles%\Mozilla Firefox\chrome\pippki.manifest
  • %ProgramFiles%\Mozilla Firefox\chrome\classic.jar
  • %ProgramFiles%\Mozilla Firefox\chrome\classic.manifest
  • %ProgramFiles%\Mozilla Firefox\chrome\comm.jar
  • %ProgramFiles%\Mozilla Firefox\searchplugins\yahoo.xml
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.xpt
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback-l10n.ini
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\BrandRes.dll
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\fullsoft.dll
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\master.ini
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.cnt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox (Safe Mode).lnk
  • %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
  • %ALLUSERSPROFILE%\Desktop\Mozilla Firefox.lnk
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.exe
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.hlp
  • %ALLUSERSPROFILE%\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox.lnk
  • %ProgramFiles%\Mozilla Firefox\defaults\profile\localstore.rdf
  • %ProgramFiles%\Mozilla Firefox\defaults\profile\mimeTypes.rdf
  • %ProgramFiles%\Mozilla Firefox\defaults\profile\prefs.js
  • %ProgramFiles%\Mozilla Firefox\dictionaries\en-US.aff
  • %ProgramFiles%\Mozilla Firefox\dictionaries\en-US.dic
  • %ProgramFiles%\Mozilla Firefox\defaults\profile\bookmarks.html
  • %ProgramFiles%\Mozilla Firefox\defaults\profile\search.rdf
  • %ProgramFiles%\Mozilla Firefox\chrome\en-US.jar
  • %ProgramFiles%\Mozilla Firefox\chrome\en-US.manifest
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\install.rdf
  • %ProgramFiles%\Mozilla Firefox\defaults\profile\chrome\userChrome-example.css
  • %ProgramFiles%\Mozilla Firefox\defaults\profile\chrome\userContent-example.css
  • %ProgramFiles%\Mozilla Firefox\defaults\pref\firefox-l10n.js
  • %ProgramFiles%\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
  • %ProgramFiles%\Mozilla Firefox\defaults\pref\channel-prefs.js
  • %ProgramFiles%\Mozilla Firefox\defaults\pref\firefox-branding.js
  • %ProgramFiles%\Mozilla Firefox\greprefs\all.js
  • %ProgramFiles%\Mozilla Firefox\greprefs\security-prefs.js
  • %ProgramFiles%\Mozilla Firefox\greprefs\xpinstall.js
  • %ProgramFiles%\Mozilla Firefox\defaults\pref\firefox.js
  • %ProgramFiles%\Mozilla Firefox\components\browser.xpt
  • %ProgramFiles%\Mozilla Firefox\components\FeedConverter.js
  • %ProgramFiles%\Mozilla Firefox\components\FeedProcessor.js
  • %ProgramFiles%\Mozilla Firefox\defaults\pref\reporter.js
  • %ProgramFiles%\Mozilla Firefox\defaults\autoconfig\platform.js
  • %ProgramFiles%\Mozilla Firefox\defaults\autoconfig\prefcalls.js
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfontSymbol.properties
  • %ProgramFiles%\Mozilla Firefox\res\entityTables\html40Latin1.properties
  • %ProgramFiles%\Mozilla Firefox\res\entityTables\html40Special.properties
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfontMath4.properties
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfontMTExtra.properties
  • %ProgramFiles%\Mozilla Firefox\res\fonts\mathfontPUA.properties
  • %ProgramFiles%\Mozilla Firefox\res\entityTables\html40Symbols.properties
  • %ProgramFiles%\Mozilla Firefox\res\dtd\mathml.dtd
  • %ProgramFiles%\Mozilla Firefox\res\dtd\xhtml11.dtd
  • %ProgramFiles%\Mozilla Firefox\plugins\npnul32.dll
  • %ProgramFiles%\Mozilla Firefox\res\entityTables\htmlEntityVersions.properties
  • %ProgramFiles%\Mozilla Firefox\res\entityTables\mathml20.properties
  • %ProgramFiles%\Mozilla Firefox\res\entityTables\transliterate.properties
  • %ProgramFiles%\Mozilla Firefox\components\FeedWriter.js
  • %ProgramFiles%\Mozilla Firefox\components\nsSearchService.js
  • %ProgramFiles%\Mozilla Firefox\components\nsSearchSuggestions.js
  • %ProgramFiles%\Mozilla Firefox\components\nsSessionStartup.js
  • %ProgramFiles%\Mozilla Firefox\components\nsPostUpdateWin.js
  • %ProgramFiles%\Mozilla Firefox\components\nsProxyAutoConfig.js
  • %ProgramFiles%\Mozilla Firefox\components\nsSafebrowsingApplication.js
  • %ProgramFiles%\Mozilla Firefox\components\nsSessionStore.js
  • %ProgramFiles%\Mozilla Firefox\components\nsUrlClassifierLib.js
  • %ProgramFiles%\Mozilla Firefox\components\nsUrlClassifierListManager.js
  • %ProgramFiles%\Mozilla Firefox\components\nsUrlClassifierTable.js
  • %ProgramFiles%\Mozilla Firefox\components\nsSetDefaultBrowser.js
  • %ProgramFiles%\Mozilla Firefox\components\nsSidebar.js
  • %ProgramFiles%\Mozilla Firefox\components\nsUpdateService.js
  • %ProgramFiles%\Mozilla Firefox\components\myspell.dll
  • %ProgramFiles%\Mozilla Firefox\components\nsBookmarkTransactionManager.js
  • %ProgramFiles%\Mozilla Firefox\components\nsBrowserContentHandler.js
  • %ProgramFiles%\Mozilla Firefox\components\jar50.dll
  • %ProgramFiles%\Mozilla Firefox\components\jsconsole-clhandler.js
  • %ProgramFiles%\Mozilla Firefox\components\jsd3250.dll
  • %ProgramFiles%\Mozilla Firefox\components\nsBrowserGlue.js
  • %ProgramFiles%\Mozilla Firefox\components\nsExtensionManager.js
  • %ProgramFiles%\Mozilla Firefox\components\nsHelperAppDlg.js
  • %ProgramFiles%\Mozilla Firefox\components\nsMicrosummaryService.js
  • %ProgramFiles%\Mozilla Firefox\components\nsCloseAllWindows.js
  • %ProgramFiles%\Mozilla Firefox\components\nsDefaultCLH.js
  • %ProgramFiles%\Mozilla Firefox\components\nsDictionary.js
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontMath2.properties
  • %TEMP%\7zS1.tmp\nonlocalized\freebl3.dll
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\fullsoft.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\jar50.dll
  • %TEMP%\7zS1.tmp\localized\dictionaries\en-US.dic
  • %TEMP%\7zS1.tmp\nonlocalized\AccessibleMarshal.dll
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\BrandRes.dll
  • %TEMP%\7zS1.tmp\nonlocalized\js3250.dll
  • %TEMP%\7zS1.tmp\nonlocalized\nspr4.dll
  • %TEMP%\7zS1.tmp\nonlocalized\nss3.dll
  • %TEMP%\7zS1.tmp\nonlocalized\nssckbi.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\jsd3250.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\myspell.dll
  • %TEMP%\7zS1.tmp\nonlocalized\plugins\npnul32.dll
  • %TEMP%\7zS1.tmp\nonlocalized\res\EditorOverride.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\forms.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\html.css
  • %TEMP%\7zS1.tmp\nonlocalized\freebl3.chk
  • %TEMP%\7zS1.tmp\nonlocalized\softokn3.chk
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\talkback.cnt
  • %TEMP%\7zS1.tmp\nonlocalized\res\mathml.css
  • %TEMP%\7zS1.tmp\localized\defaults\profile\chrome\userChrome-example.css
  • %TEMP%\7zS1.tmp\localized\defaults\profile\chrome\userContent-example.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\viewsource.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\quirk.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\svg.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\ua.css
  • %TEMP%\7zS1.tmp\nonlocalized\plc4.dll
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\talkback.exe
  • %TEMP%\7zS1.tmp\nonlocalized\updater.exe
  • %TEMP%\7zS1.tmp\nonlocalized\xpicleanup.exe
  • %TEMP%\7zS1.tmp\nonlocalized\firefox.exe
  • %TEMP%\7zS1.tmp\localized\uninstall\helper.exe
  • %TEMP%\7zS1.tmp\setup.exe
  • %TEMP%\7zS1.tmp\nonlocalized\res\arrow.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-binary.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-find.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-image.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\arrowd.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\broken-image.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-audio.gif
  • %TEMP%\7zS1.tmp\nonlocalized\softokn3.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\spellchk.dll
  • %TEMP%\7zS1.tmp\nonlocalized\ssl3.dll
  • %TEMP%\7zS1.tmp\nonlocalized\plds4.dll
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\qfaservices.dll
  • %TEMP%\7zS1.tmp\nonlocalized\smime3.dll
  • %TEMP%\7zS1.tmp\nonlocalized\xpcom.dll
  • %TEMP%\7zS1.tmp\nonlocalized\xpistub.dll
  • %TEMP%\7zS1.tmp\nonlocalized\res\dtd\mathml.dtd
  • %TEMP%\7zS1.tmp\nonlocalized\res\dtd\xhtml11.dtd
  • %TEMP%\7zS1.tmp\nonlocalized\xpcom_compat.dll
  • %TEMP%\7zS1.tmp\nonlocalized\xpcom_core.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\xpinstal.dll
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\key3.db
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\secmod.db
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\prefs.js
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\history.dat
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\xpti.dat
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\cert8.db
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\sessionstore.js
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\search.rdf
  • %TEMP%\RarSFX0\A.reg
  • %TEMP%\RarSFX0\B.reg
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\extensions.rdf
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\localstore.rdf
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\mimeTypes.rdf
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\compatibility.ini
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\extensions.ini
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\profiles.ini
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\cookies.txt
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\bookmarkbackups\bookmarks-2007-08-06.html
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\bookmarks.html
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\bookmarks.bak
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\chrome\userChrome-example.css
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\chrome\userContent-example.css
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\compreg.dat
  • %TEMP%\RarSFX0\firefox_setup.exe
  • %TEMP%\RarSFX0\install.exe
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\extensions.cache
  • %TEMP%\RarSFX0\C.reg
  • %TEMP%\RarSFX0\T.reg
  • %TEMP%\RarSFX0\U.reg
  • %TEMP%\RarSFX0\V.reg
  • %TEMP%\RarSFX0\Q.reg
  • %TEMP%\RarSFX0\R.reg
  • %TEMP%\RarSFX0\S.reg
  • %TEMP%\RarSFX0\W.reg
  • %TEMP%\RarSFX0\PROFILE\Mozilla\Firefox\Profiles\p2eog6ij.default\search.sqlite
  • %TEMP%\7zS1.tmp\nonlocalized\LICENSE
  • %TEMP%\7zS1.tmp\localized\dictionaries\en-US.aff
  • %TEMP%\RarSFX0\X.reg
  • %TEMP%\RarSFX0\Y.reg
  • %TEMP%\RarSFX0\Z.reg
  • %TEMP%\RarSFX0\G.reg
  • %TEMP%\RarSFX0\H.reg
  • %TEMP%\RarSFX0\I.reg
  • %TEMP%\RarSFX0\D.reg
  • %TEMP%\RarSFX0\E.reg
  • %TEMP%\RarSFX0\F.reg
  • %TEMP%\RarSFX0\J.reg
  • %TEMP%\RarSFX0\N.reg
  • %TEMP%\RarSFX0\O.reg
  • %TEMP%\RarSFX0\P.reg
  • %TEMP%\RarSFX0\K.reg
  • %TEMP%\RarSFX0\L.reg
  • %TEMP%\RarSFX0\M.reg
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-menu.gif
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsUpdateService.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsUrlClassifierLib.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsUrlClassifierListManager.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSessionStore.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSetDefaultBrowser.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSidebar.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsUrlClassifierTable.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\autoconfig\prefcalls.js
  • %TEMP%\7zS1.tmp\localized\defaults\profile\prefs.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\pref\reporter.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsURLFormatter.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsXmlRpcClient.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\autoconfig\platform.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsDictionary.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsExtensionManager.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsHelperAppDlg.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsBrowserGlue.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsCloseAllWindows.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsDefaultCLH.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsMicrosummaryService.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSearchService.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSearchSuggestions.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSessionStartup.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsPostUpdateWin.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsProxyAutoConfig.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSafebrowsingApplication.js
  • %TEMP%\7zS1.tmp\nonlocalized\greprefs\security-prefs.js
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\html40Latin1.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\html40Special.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\html40Symbols.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\charsetData.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\fontEncoding.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\fontNameMap.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\htmlEntityVersions.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontCMEX10.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontCMSY10.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontMath1.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\langGroups.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\language.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfont.properties
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\browser.manifest
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\chrome.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\classic.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\components\WebContentConverter.js
  • %TEMP%\7zS1.tmp\nonlocalized\greprefs\xpinstall.js
  • %TEMP%\7zS1.tmp\removed-files.log
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\comm.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\toolkit.manifest
  • %TEMP%\7zS1.tmp\localized\browserconfig.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\charsetalias.properties
  • %TEMP%\7zS1.tmp\localized\chrome\en-US.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\pippki.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\reporter.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-before-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-before-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-before.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-after-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-after-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-after.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-column-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-row-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-row.gif
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\talkback.hlp
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-column-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-column.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-row-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-text.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-unknown.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\grabber.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-movie.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-sound.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-telnet.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\loading-image.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-before-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-before-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-before.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-after-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-after-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-after.gif
  • %TEMP%\7zS1.tmp\localized\defaults\profile\bookmarks.html
  • %TEMP%\7zS1.tmp\nonlocalized\components\FeedProcessor.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\FeedWriter.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\pref\firefox-branding.js
  • %TEMP%\7zS1.tmp\nonlocalized\greprefs\all.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\pref\channel-prefs.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\FeedConverter.js
  • %TEMP%\7zS1.tmp\localized\defaults\pref\firefox-l10n.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\jsconsole-clhandler.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsBookmarkTransactionManager.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsBrowserContentHandler.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\pref\firefox.js
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\components\inspector-cmdline.js
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\defaults\preferences\inspector.js
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\talkback-l10n.ini
  • %TEMP%\7zS1.tmp\localized\updater.ini
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\browser.jar
  • %TEMP%\7zS1.tmp\nonlocalized\res\hiddenWindow.html
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\chrome\icons\default\winInspectorMain.ico
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\master.ini
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\classic.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\pippki.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\reporter.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\toolkit.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\comm.jar
  • %TEMP%\7zS1.tmp\localized\chrome\en-US.jar
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\chrome\inspector.jar
Присваивает атрибут 'скрытый' для следующих файлов:
  • %TEMP%\bt2015.bat
Удаляет следующие файлы:
  • %TEMP%\7zS1.tmp\nonlocalized\res\hiddenWindow.html
  • %TEMP%\7zS1.tmp\nonlocalized\res\grabber.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\forms.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-find.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-binary.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-audio.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontMath4.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontMath2.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontMath1.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontSymbol.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontPUA.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontMTExtra.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-image.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\language.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\langGroups.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\html.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\quirk.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\mathml.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\loading-image.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-sound.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-movie.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-menu.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-unknown.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-text.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\html\gopher-telnet.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\charsetalias.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\broken-image.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\arrowd.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\dtd\mathml.dtd
  • %TEMP%\7zS1.tmp\nonlocalized\res\cmessage.txt
  • %TEMP%\7zS1.tmp\nonlocalized\res\charsetData.properties
  • %TEMP%\7zS1.tmp\nonlocalized\plds4.dll
  • %TEMP%\7zS1.tmp\nonlocalized\plc4.dll
  • %TEMP%\7zS1.tmp\nonlocalized\nssckbi.dll
  • %TEMP%\7zS1.tmp\nonlocalized\res\arrow.gif
  • %TEMP%\7zS1.tmp\nonlocalized\README.txt
  • %TEMP%\7zS1.tmp\nonlocalized\plugins\npnul32.dll
  • %TEMP%\7zS1.tmp\nonlocalized\res\dtd\xhtml11.dtd
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\fontNameMap.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\fontEncoding.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\transliterate.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontCMSY10.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfontCMEX10.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\fonts\mathfont.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\html40Special.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\html40Latin1.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\EditorOverride.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\mathml20.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\htmlEntityVersions.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\entityTables\html40Symbols.properties
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\chrome\inspector.jar
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\chrome\icons\default\winInspectorMain.ico
  • %TEMP%\7zS1.tmp\nonlocalized\xpistub.dll
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\defaults\preferences\inspector.js
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\components\inspector-cmdline.js
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\chrome.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\xpcom.dll
  • %TEMP%\7zS1.tmp\nonlocalized\updater.exe
  • %TEMP%\7zS1.tmp\nonlocalized\ssl3.dll
  • %TEMP%\7zS1.tmp\nonlocalized\xpicleanup.exe
  • %TEMP%\7zS1.tmp\nonlocalized\xpcom_core.dll
  • %TEMP%\7zS1.tmp\nonlocalized\xpcom_compat.dll
  • %TEMP%\7zS1.tmp\optional\extensions\inspector@mozilla.org\install.rdf
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\talkback.hlp
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\talkback.exe
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\talkback.cnt
  • %TEMP%\7zS1.tmp\setup.exe
  • %TEMP%\7zS1.tmp\removed-files.log
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\install.rdf
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\master.ini
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\fullsoft.dll
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\BrandRes.dll
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\talkback-l10n.ini
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\qfaservices.xpt
  • %TEMP%\7zS1.tmp\optional\extensions\talkback@mozilla.org\components\qfaservices.dll
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-after-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-after-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-before.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-before-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-before-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-after.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-after-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-after-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\svg.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-before-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-before-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-column-after.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-add-row-before.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\wincharset.properties
  • %TEMP%\7zS1.tmp\nonlocalized\res\viewsource.css
  • %TEMP%\7zS1.tmp\nonlocalized\res\ua.css
  • %TEMP%\7zS1.tmp\nonlocalized\softokn3.dll
  • %TEMP%\7zS1.tmp\nonlocalized\softokn3.chk
  • %TEMP%\7zS1.tmp\nonlocalized\smime3.dll
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-column.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-column-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-column-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-row.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-row-hover.gif
  • %TEMP%\7zS1.tmp\nonlocalized\res\table-remove-row-active.gif
  • %TEMP%\7zS1.tmp\nonlocalized\nss3.dll
  • %TEMP%\7zS1.tmp\localized\searchplugins\yahoo.xml
  • %TEMP%\7zS1.tmp\localized\searchplugins\google.xml
  • %TEMP%\7zS1.tmp\localized\searchplugins\eBay.xml
  • %TEMP%\7zS1.tmp\nonlocalized\AccessibleMarshal.dll
  • %TEMP%\7zS1.tmp\localized\updater.ini
  • %TEMP%\7zS1.tmp\localized\uninstall\helper.exe
  • %TEMP%\7zS1.tmp\localized\old-homepage-default.properties
  • %TEMP%\7zS1.tmp\localized\dictionaries\en-US.dic
  • %TEMP%\7zS1.tmp\localized\dictionaries\en-US.aff
  • %TEMP%\7zS1.tmp\localized\searchplugins\creativecommons.xml
  • %TEMP%\7zS1.tmp\localized\searchplugins\answers.xml
  • %TEMP%\7zS1.tmp\localized\searchplugins\amazondotcom.xml
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\browser.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\reporter.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\reporter.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\pippki.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\components\browser.xpt
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\toolkit.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\toolkit.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\classic.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\classic.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\browser.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\pippki.jar
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\comm.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\chrome\comm.jar
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.hlp
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.exe
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.cnt
  • %TEMP%\nsc3.tmp\options.ini
  • %TEMP%\nsc3.tmp\components.ini
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\install.rdf
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\master.ini
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\fullsoft.dll
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\BrandRes.dll
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback-l10n.ini
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.xpt
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
  • %TEMP%\nsc3.tmp\shortcuts.ini
  • %TEMP%\7zS1.tmp\localized\defaults\profile\localstore.rdf
  • %TEMP%\7zS1.tmp\localized\defaults\profile\chrome\userContent-example.css
  • %TEMP%\7zS1.tmp\localized\defaults\profile\chrome\userChrome-example.css
  • %TEMP%\7zS1.tmp\localized\defaults\profile\search.rdf
  • %TEMP%\7zS1.tmp\localized\defaults\profile\prefs.js
  • %TEMP%\7zS1.tmp\localized\defaults\profile\mimeTypes.rdf
  • %TEMP%\7zS1.tmp\localized\chrome\en-US.jar
  • %TEMP%\7zS1.tmp\localized\browserconfig.properties
  • %TEMP%\nsc3.tmp\System.dll
  • %TEMP%\7zS1.tmp\localized\defaults\profile\bookmarks.html
  • %TEMP%\7zS1.tmp\localized\defaults\pref\firefox-l10n.js
  • %TEMP%\7zS1.tmp\localized\chrome\en-US.manifest
  • %TEMP%\7zS1.tmp\nonlocalized\components\xpinstal.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\WebContentConverter.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\spellchk.dll
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\pref\channel-prefs.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\autoconfig\prefcalls.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\autoconfig\platform.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsUrlClassifierListManager.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsUrlClassifierLib.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsUpdateService.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsXmlRpcClient.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsURLFormatter.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsUrlClassifierTable.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\pref\firefox-branding.js
  • %TEMP%\7zS1.tmp\nonlocalized\greprefs\xpinstall.js
  • %TEMP%\7zS1.tmp\nonlocalized\greprefs\security-prefs.js
  • %TEMP%\7zS1.tmp\nonlocalized\greprefs\all.js
  • %TEMP%\7zS1.tmp\nonlocalized\nspr4.dll
  • %TEMP%\7zS1.tmp\nonlocalized\LICENSE
  • %TEMP%\7zS1.tmp\nonlocalized\js3250.dll
  • %TEMP%\7zS1.tmp\nonlocalized\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\pref\reporter.js
  • %TEMP%\7zS1.tmp\nonlocalized\defaults\pref\firefox.js
  • %TEMP%\7zS1.tmp\nonlocalized\freebl3.dll
  • %TEMP%\7zS1.tmp\nonlocalized\freebl3.chk
  • %TEMP%\7zS1.tmp\nonlocalized\firefox.exe
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsBrowserContentHandler.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsBookmarkTransactionManager.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\myspell.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsDefaultCLH.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsCloseAllWindows.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsBrowserGlue.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\FeedWriter.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\FeedProcessor.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\FeedConverter.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\jsd3250.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\jsconsole-clhandler.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\jar50.dll
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsDictionary.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSessionStartup.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSearchSuggestions.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSearchService.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSidebar.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSetDefaultBrowser.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSessionStore.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsMicrosummaryService.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsHelperAppDlg.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsExtensionManager.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsSafebrowsingApplication.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsProxyAutoConfig.js
  • %TEMP%\7zS1.tmp\nonlocalized\components\nsPostUpdateWin.js
Подменяет следующие файлы:
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback-l10n.ini
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.xpt
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.cnt
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.hlp
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.exe
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\BrandRes.dll
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\install.rdf
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\fullsoft.dll
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
  • %ProgramFiles%\Mozilla Firefox\extensions\talkback@mozilla.org\components\master.ini
Другое:
Ищет следующие окна:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'EDIT' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке