Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop8.74

Добавлен в вирусную базу Dr.Web: 2018-03-02

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Classes\IrfanView.pgm\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.png\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.pcd\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.pcx\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.ppm\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.ra\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.ras\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.psd\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.psp\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.mng\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.mov\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.med\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.mid\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.mp3\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.ogg\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.pbm\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.mpe\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.mpg\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.raw\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.wbmp\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.webp\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.ttf\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.wav\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.wma\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.xbm\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.xpm\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.wmf\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.wmv\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.sff\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.sfw\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.rle\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.rmi\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.sgi\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.tga\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.tif\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.sid\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.swf\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.kdc\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.cr2\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.crw\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.cam\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.clp\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.cur\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.dds\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.djvu\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view64.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.dcm\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.dcx\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.aif\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.ani\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\Applications\i_view32.exe\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.asf\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.b3d\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.bmp\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.au\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.avi\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.dxf\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.iff\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.img\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.icl\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.ico\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.jls\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.jpg\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.jpm\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.jng\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.jp2\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.eps\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.exr\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.ecw\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.emf\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.flv\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.gif\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.hdp\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.fpx\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Classes\IrfanView.g3\shell\open\command] '' = '"%ProgramFiles%\IrfanView\i_view64.exe" "%1"'
Изменения в файловой системе:
Создает следующие файлы:
  • %ProgramFiles%\IrfanView\plugins\is-61KNO.tmp
  • %ProgramFiles%\IrfanView\plugins\is-2EU5M.tmp
  • %ProgramFiles%\IrfanView\plugins\is-NRBFJ.tmp
  • %ProgramFiles%\IrfanView\plugins\is-9EBRK.tmp
  • %ProgramFiles%\IrfanView\plugins\is-HAQQ9.tmp
  • %ProgramFiles%\IrfanView\plugins\is-LTFSQ.tmp
  • %ProgramFiles%\IrfanView\plugins\is-DNCME.tmp
  • %ProgramFiles%\IrfanView\plugins\is-UGL8P.tmp
  • %ProgramFiles%\IrfanView\plugins\is-PVKPK.tmp
  • %ProgramFiles%\IrfanView\plugins\is-U1OD2.tmp
  • %ProgramFiles%\IrfanView\plugins\is-PMK2U.tmp
  • %ProgramFiles%\IrfanView\plugins\is-U47KI.tmp
  • %ProgramFiles%\IrfanView\plugins\is-KQQD2.tmp
  • %ProgramFiles%\IrfanView\plugins\Filter Factory 8BF\is-Q6RCK.tmp
  • %ProgramFiles%\IrfanView\plugins\Filter Factory 8BF\is-FPN5Q.tmp
  • %ProgramFiles%\IrfanView\plugins\Fmod\is-GKN6V.tmp
  • %ProgramFiles%\IrfanView\plugins\Ecw\is-JFK76.tmp
  • %ProgramFiles%\IrfanView\plugins\Ecw\is-RKDMS.tmp
  • %ProgramFiles%\IrfanView\plugins\Ecw\is-POJPK.tmp
  • %ProgramFiles%\IrfanView\plugins\is-9M8T1.tmp
  • %ProgramFiles%\IrfanView\plugins\is-JAGPB.tmp
  • %ProgramFiles%\IrfanView\plugins\is-9TGP4.tmp
  • %ProgramFiles%\IrfanView\plugins\is-0AOAB.tmp
  • %ProgramFiles%\IrfanView\plugins\is-KR0SL.tmp
  • %ProgramFiles%\IrfanView\plugins\is-MSUGU.tmp
  • %ProgramFiles%\IrfanView\plugins\is-KNN5K.tmp
  • %ProgramFiles%\IrfanView\plugins\is-EK45P.tmp
  • %ProgramFiles%\IrfanView\plugins\is-P3NF9.tmp
  • %ProgramFiles%\IrfanView\plugins\Adobe 8BF\is-BGMH3.tmp
  • %ProgramFiles%\IrfanView\plugins\is-399S6.tmp
  • %ProgramFiles%\IrfanView\plugins\is-00K6I.tmp
  • %ProgramFiles%\IrfanView\plugins\is-7FF9N.tmp
  • %ProgramFiles%\IrfanView\plugins\Adobe 8BF\is-I6ILB.tmp
  • %ProgramFiles%\IrfanView\unins000.dat
  • %ProgramFiles%\IrfanView\Languages\Italian.dll
  • %ProgramFiles%\IrfanView\Languages\IP_Italian.lng
  • %ALLUSERSPROFILE%\Start Menu\Programs\IrfanView.lnk
  • %ALLUSERSPROFILE%\Desktop\IrfanView.lnk
  • %APPDATA%\IrfanView\i_view32.ini
  • %ProgramFiles%\IrfanView\plugins\is-1CT7R.tmp
  • %ProgramFiles%\IrfanView\plugins\is-QD53E.tmp
  • %ProgramFiles%\IrfanView\plugins\is-P546I.tmp
  • %ProgramFiles%\IrfanView\plugins\is-H7GAE.tmp
  • %ProgramFiles%\IrfanView\plugins\is-HGDAJ.tmp
  • %ProgramFiles%\IrfanView\plugins\is-RF1DJ.tmp
  • %ProgramFiles%\IrfanView\plugins\is-0FUKI.tmp
  • %ProgramFiles%\IrfanView\plugins\is-3JP8A.tmp
  • %ProgramFiles%\IrfanView\plugins\is-059BE.tmp
  • %ProgramFiles%\IrfanView\plugins\is-L8ABB.tmp
  • %ProgramFiles%\IrfanView\plugins\is-AB5HN.tmp
  • %ProgramFiles%\IrfanView\plugins\is-3BTNQ.tmp
  • %ProgramFiles%\IrfanView\plugins\is-L7ARH.tmp
  • %ProgramFiles%\IrfanView\plugins\Ecw\is-SGF2A.tmp
  • %ProgramFiles%\IrfanView\plugins\is-C4DO9.tmp
  • %ProgramFiles%\IrfanView\plugins\is-9VA23.tmp
  • %ProgramFiles%\IrfanView\is-FB8UE.tmp
  • %ProgramFiles%\IrfanView\plugins\is-3I7GC.tmp
  • %ProgramFiles%\IrfanView\plugins\is-3LUES.tmp
  • %ProgramFiles%\IrfanView\plugins\is-IGP3I.tmp
  • %ProgramFiles%\IrfanView\is-BM24A.tmp
  • %ProgramFiles%\IrfanView\Languages\is-9I64F.tmp
  • %ProgramFiles%\IrfanView\Languages\is-JFPAN.tmp
  • %ProgramFiles%\IrfanView\Toolbars\is-BRO4A.tmp
  • %ProgramFiles%\IrfanView\Html\is-RN1R1.tmp
  • %ProgramFiles%\IrfanView\Html\is-6KHAQ.tmp
  • %ProgramFiles%\IrfanView\Html\is-M8RH2.tmp
  • %TEMP%\RarSFX0\IrfanView-Full_4.51.exe
  • %TEMP%\is-D84E9.tmp\IrfanView-Full_4.51.tmp
  • %TEMP%\is-LEEQ0.tmp\VclStylesInno.dll
  • %TEMP%\RarSFX0\Italian.dll
  • %TEMP%\RarSFX0\Install_IrfanView.cmd
  • %TEMP%\RarSFX0\IP_Italian.lng
  • %TEMP%\is-LEEQ0.tmp\Windows10Dark.vsf
  • %ProgramFiles%\IrfanView\plugins\is-HE6LL.tmp
  • %ProgramFiles%\IrfanView\plugins\is-6O82F.tmp
  • %ProgramFiles%\IrfanView\plugins\is-HDM3O.tmp
  • %ProgramFiles%\IrfanView\is-0VP58.tmp
  • %ProgramFiles%\IrfanView\is-OVLIL.tmp
  • %ProgramFiles%\IrfanView\is-QAMVU.tmp
  • %ProgramFiles%\IrfanView\plugins\is-CNAIK.tmp
  • %ProgramFiles%\IrfanView\plugins\is-VDIB8.tmp
  • %ProgramFiles%\IrfanView\plugins\is-CMR7O.tmp
  • %ProgramFiles%\IrfanView\plugins\is-HER5U.tmp
  • %ProgramFiles%\IrfanView\plugins\is-OTDE2.tmp
  • %ProgramFiles%\IrfanView\plugins\is-3JJ0U.tmp
  • %ProgramFiles%\IrfanView\plugins\is-LGPSG.tmp
  • %ProgramFiles%\IrfanView\plugins\is-C1RNB.tmp
  • %ProgramFiles%\IrfanView\plugins\is-KH10K.tmp
  • %ProgramFiles%\IrfanView\plugins\is-37P7C.tmp
  • %ProgramFiles%\IrfanView\plugins\is-TQM3F.tmp
  • %ProgramFiles%\IrfanView\plugins\is-ARQ2G.tmp
  • %ProgramFiles%\IrfanView\plugins\is-KK8AU.tmp
  • %ProgramFiles%\IrfanView\Toolbars\is-H4FCA.tmp
  • %ProgramFiles%\IrfanView\Toolbars\is-Q8VMH.tmp
  • %ProgramFiles%\IrfanView\Toolbars\is-N30LT.tmp
  • %ProgramFiles%\IrfanView\Toolbars\is-4HK7G.tmp
  • %ProgramFiles%\IrfanView\Toolbars\is-JCJ7O.tmp
  • %ProgramFiles%\IrfanView\Toolbars\is-5FIQ4.tmp
  • %ProgramFiles%\IrfanView\Toolbars\is-IAQFV.tmp
  • %ProgramFiles%\IrfanView\plugins\is-GJ071.tmp
  • %ProgramFiles%\IrfanView\plugins\is-9ILIS.tmp
  • %ProgramFiles%\IrfanView\plugins\is-27ELB.tmp
  • %ProgramFiles%\IrfanView\plugins\is-OJC4J.tmp
  • %ProgramFiles%\IrfanView\is-KVV6T.tmp
  • %ProgramFiles%\IrfanView\is-UBCQN.tmp
Присваивает атрибут 'скрытый' для следующих файлов:
  • %ProgramFiles%\IrfanView\IrfanView.ico
  • %ProgramFiles%\IrfanView\Desktop.ini
Удаляет следующие файлы:
  • %TEMP%\RarSFX0\IP_Italian.lng
  • %TEMP%\RarSFX0\Install_IrfanView.cmd
  • %TEMP%\RarSFX0\Italian.dll
  • %TEMP%\RarSFX0\IrfanView-Full_4.51.exe
  • %TEMP%\is-LEEQ0.tmp\VclStylesInno.dll
  • %ProgramFiles%\IrfanView\i_view32.chm
  • %TEMP%\is-D84E9.tmp\IrfanView-Full_4.51.tmp
  • %TEMP%\is-LEEQ0.tmp\Windows10Dark.vsf
Перемещает следующие файлы:
  • %ProgramFiles%\IrfanView\plugins\is-LTFSQ.tmp в %ProgramFiles%\IrfanView\plugins\Dicom.dll
  • %ProgramFiles%\IrfanView\plugins\is-61KNO.tmp в %ProgramFiles%\IrfanView\plugins\DjVu.dll
  • %ProgramFiles%\IrfanView\plugins\is-HAQQ9.tmp в %ProgramFiles%\IrfanView\plugins\CADImage.dll
  • %ProgramFiles%\IrfanView\plugins\is-0AOAB.tmp в %ProgramFiles%\IrfanView\plugins\Burning.dll
  • %ProgramFiles%\IrfanView\plugins\is-9EBRK.tmp в %ProgramFiles%\IrfanView\plugins\BurningOld.dll
  • %ProgramFiles%\IrfanView\plugins\is-2EU5M.tmp в %ProgramFiles%\IrfanView\plugins\Email.dll
  • %ProgramFiles%\IrfanView\plugins\is-U47KI.tmp в %ProgramFiles%\IrfanView\plugins\Ftp.dll
  • %ProgramFiles%\IrfanView\plugins\is-KQQD2.tmp в %ProgramFiles%\IrfanView\plugins\FUNLTDIV.dll
  • %ProgramFiles%\IrfanView\plugins\is-PMK2U.tmp в %ProgramFiles%\IrfanView\plugins\Formats.dll
  • %ProgramFiles%\IrfanView\plugins\is-NRBFJ.tmp в %ProgramFiles%\IrfanView\plugins\FilmSim.dll
  • %ProgramFiles%\IrfanView\plugins\is-DNCME.tmp в %ProgramFiles%\IrfanView\plugins\Flash4.dll
  • %ProgramFiles%\IrfanView\plugins\Filter Factory 8BF\is-FPN5Q.tmp в %ProgramFiles%\IrfanView\plugins\Filter Factory 8BF\Afhbevel.8bf
  • %ProgramFiles%\IrfanView\plugins\Fmod\is-GKN6V.tmp в %ProgramFiles%\IrfanView\plugins\Fmod\Fmod.dll
  • %ProgramFiles%\IrfanView\plugins\Filter Factory 8BF\is-Q6RCK.tmp в %ProgramFiles%\IrfanView\plugins\Filter Factory 8BF\3DMaker.8bf
  • %ProgramFiles%\IrfanView\plugins\Ecw\is-RKDMS.tmp в %ProgramFiles%\IrfanView\plugins\Ecw\NCSEcwC.dll
  • %ProgramFiles%\IrfanView\plugins\Ecw\is-POJPK.tmp в %ProgramFiles%\IrfanView\plugins\Ecw\NCSUtil.dll
  • %ProgramFiles%\IrfanView\plugins\is-9M8T1.tmp в %ProgramFiles%\IrfanView\plugins\IV_Player.exe
  • %ProgramFiles%\IrfanView\plugins\is-JAGPB.tmp в %ProgramFiles%\IrfanView\plugins\B3d.dll
  • %ProgramFiles%\IrfanView\plugins\is-9TGP4.tmp в %ProgramFiles%\IrfanView\plugins\BabaCAD4Image.dll
  • %ProgramFiles%\IrfanView\plugins\is-KNN5K.tmp в %ProgramFiles%\IrfanView\plugins\Awd.dll
  • %ProgramFiles%\IrfanView\plugins\is-KR0SL.tmp в %ProgramFiles%\IrfanView\plugins\IrfanView Sandbox.jpac
  • %ProgramFiles%\IrfanView\plugins\is-MSUGU.tmp в %ProgramFiles%\IrfanView\plugins\AltaLux.dll
  • %ProgramFiles%\IrfanView\plugins\is-UGL8P.tmp в %ProgramFiles%\IrfanView\plugins\Hdp.dll
  • %ProgramFiles%\IrfanView\plugins\is-L8ABB.tmp в %ProgramFiles%\IrfanView\plugins\Postscript.dll
  • %ProgramFiles%\IrfanView\plugins\is-399S6.tmp в %ProgramFiles%\IrfanView\plugins\Ra_player.dll
  • %ProgramFiles%\IrfanView\plugins\is-059BE.tmp в %ProgramFiles%\IrfanView\plugins\Pngout.dll
  • %ProgramFiles%\IrfanView\plugins\is-L7ARH.tmp в %ProgramFiles%\IrfanView\plugins\Nero.dll
  • %ProgramFiles%\IrfanView\plugins\is-3JP8A.tmp в %ProgramFiles%\IrfanView\plugins\PDF.dll
  • %ProgramFiles%\IrfanView\plugins\is-00K6I.tmp в %ProgramFiles%\IrfanView\plugins\Riot.dll
  • %ProgramFiles%\IrfanView\plugins\Adobe 8BF\is-BGMH3.tmp в %ProgramFiles%\IrfanView\plugins\Adobe 8BF\HarrysFilters.8bf
  • %ProgramFiles%\IrfanView\plugins\Adobe 8BF\is-I6ILB.tmp в %ProgramFiles%\IrfanView\plugins\Adobe 8BF\PopArt.8bf
  • %ProgramFiles%\IrfanView\plugins\is-P3NF9.tmp в %ProgramFiles%\IrfanView\plugins\WebP.dll
  • %ProgramFiles%\IrfanView\plugins\is-7FF9N.tmp в %ProgramFiles%\IrfanView\plugins\Sff.dll
  • %ProgramFiles%\IrfanView\plugins\is-EK45P.tmp в %ProgramFiles%\IrfanView\plugins\Vtf.dll
  • %ProgramFiles%\IrfanView\plugins\is-HGDAJ.tmp в %ProgramFiles%\IrfanView\plugins\JPEG2000.dll
  • %ProgramFiles%\IrfanView\plugins\is-RF1DJ.tmp в %ProgramFiles%\IrfanView\plugins\Jpeg_LS.dll
  • %ProgramFiles%\IrfanView\plugins\is-H7GAE.tmp в %ProgramFiles%\IrfanView\plugins\IrfanView Sandbox.dll
  • %ProgramFiles%\IrfanView\plugins\is-PVKPK.tmp в %ProgramFiles%\IrfanView\plugins\Ics.dll
  • %ProgramFiles%\IrfanView\plugins\is-U1OD2.tmp в %ProgramFiles%\IrfanView\plugins\ImPDF.dll
  • %ProgramFiles%\IrfanView\plugins\is-1CT7R.tmp в %ProgramFiles%\IrfanView\plugins\JPM.dll
  • %ProgramFiles%\IrfanView\plugins\is-AB5HN.tmp в %ProgramFiles%\IrfanView\plugins\Mrc.dll
  • %ProgramFiles%\IrfanView\plugins\is-3BTNQ.tmp в %ProgramFiles%\IrfanView\plugins\MrSID.dll
  • %ProgramFiles%\IrfanView\plugins\is-0FUKI.tmp в %ProgramFiles%\IrfanView\plugins\Mng.dll
  • %ProgramFiles%\IrfanView\plugins\is-QD53E.tmp в %ProgramFiles%\IrfanView\plugins\Lcms.dll
  • %ProgramFiles%\IrfanView\plugins\is-P546I.tmp в %ProgramFiles%\IrfanView\plugins\Med.dll
  • %ProgramFiles%\IrfanView\plugins\Ecw\is-JFK76.tmp в %ProgramFiles%\IrfanView\plugins\Ecw\NCSEcw.dll
  • %ProgramFiles%\IrfanView\Html\is-M8RH2.tmp в %ProgramFiles%\IrfanView\Html\thumbnails.html
  • %ProgramFiles%\IrfanView\Languages\is-9I64F.tmp в %ProgramFiles%\IrfanView\Languages\Deutsch.dll
  • %ProgramFiles%\IrfanView\Html\is-6KHAQ.tmp в %ProgramFiles%\IrfanView\Html\slideshow.html
  • %ProgramFiles%\IrfanView\is-FB8UE.tmp в %ProgramFiles%\IrfanView\i_view32.chm
  • %ProgramFiles%\IrfanView\Html\is-RN1R1.tmp в %ProgramFiles%\IrfanView\Html\frame.html
  • %ProgramFiles%\IrfanView\Languages\is-JFPAN.tmp в %ProgramFiles%\IrfanView\Languages\IP_Deutsch.lng
  • %ProgramFiles%\IrfanView\Toolbars\is-5FIQ4.tmp в %ProgramFiles%\IrfanView\Toolbars\gnome-colors-wise_32.txt
  • %ProgramFiles%\IrfanView\Toolbars\is-H4FCA.tmp в %ProgramFiles%\IrfanView\Toolbars\Grosberg_24.png
  • %ProgramFiles%\IrfanView\Toolbars\is-JCJ7O.tmp в %ProgramFiles%\IrfanView\Toolbars\gnome-colors-wise_32.png
  • %ProgramFiles%\IrfanView\Toolbars\is-BRO4A.tmp в %ProgramFiles%\IrfanView\Toolbars\gnome-colors-human_48.png
  • %ProgramFiles%\IrfanView\Toolbars\is-4HK7G.tmp в %ProgramFiles%\IrfanView\Toolbars\gnome-colors-human_48.txt
  • %ProgramFiles%\IrfanView\plugins\is-HE6LL.tmp в %ProgramFiles%\IrfanView\plugins\Effects.dll
  • %ProgramFiles%\IrfanView\plugins\is-6O82F.tmp в %ProgramFiles%\IrfanView\plugins\Jpg_transform.dll
  • %ProgramFiles%\IrfanView\is-QAMVU.tmp в %ProgramFiles%\IrfanView\i_view32.ini
  • %ProgramFiles%\IrfanView\is-0VP58.tmp в %ProgramFiles%\IrfanView\unins000.exe
  • %ProgramFiles%\IrfanView\is-OVLIL.tmp в %ProgramFiles%\IrfanView\i_view32.exe
  • %ProgramFiles%\IrfanView\plugins\is-HDM3O.tmp в %ProgramFiles%\IrfanView\plugins\Metadata.dll
  • %ProgramFiles%\IrfanView\plugins\is-C4DO9.tmp в %ProgramFiles%\IrfanView\plugins\Tools.dll
  • %ProgramFiles%\IrfanView\plugins\is-9VA23.tmp в %ProgramFiles%\IrfanView\plugins\Video.dll
  • %ProgramFiles%\IrfanView\plugins\is-IGP3I.tmp в %ProgramFiles%\IrfanView\plugins\Slideshow.exe
  • %ProgramFiles%\IrfanView\plugins\is-3I7GC.tmp в %ProgramFiles%\IrfanView\plugins\Paint.dll
  • %ProgramFiles%\IrfanView\plugins\is-3LUES.tmp в %ProgramFiles%\IrfanView\plugins\RegionCapture.dll
  • %ProgramFiles%\IrfanView\Toolbars\is-Q8VMH.tmp в %ProgramFiles%\IrfanView\Toolbars\Grosberg_24.txt
  • %ProgramFiles%\IrfanView\plugins\is-LGPSG.tmp в %ProgramFiles%\IrfanView\plugins\KDC120.dll
  • %ProgramFiles%\IrfanView\plugins\is-TQM3F.tmp в %ProgramFiles%\IrfanView\plugins\Mp3.dll
  • %ProgramFiles%\IrfanView\plugins\is-CMR7O.tmp в %ProgramFiles%\IrfanView\plugins\ImXCF.dll
  • %ProgramFiles%\IrfanView\plugins\is-CNAIK.tmp в %ProgramFiles%\IrfanView\plugins\Fpx.dll
  • %ProgramFiles%\IrfanView\plugins\is-VDIB8.tmp в %ProgramFiles%\IrfanView\plugins\ImPDN.dll
  • %ProgramFiles%\IrfanView\plugins\is-ARQ2G.tmp в %ProgramFiles%\IrfanView\plugins\Photocd.dll
  • %ProgramFiles%\IrfanView\plugins\is-37P7C.tmp в %ProgramFiles%\IrfanView\plugins\Wsq.dll
  • %ProgramFiles%\IrfanView\plugins\Ecw\is-SGF2A.tmp в %ProgramFiles%\IrfanView\plugins\Ecw\NCScnet.dll
  • %ProgramFiles%\IrfanView\plugins\is-KH10K.tmp в %ProgramFiles%\IrfanView\plugins\Wbz.dll
  • %ProgramFiles%\IrfanView\plugins\is-KK8AU.tmp в %ProgramFiles%\IrfanView\plugins\Quicktime.dll
  • %ProgramFiles%\IrfanView\plugins\is-C1RNB.tmp в %ProgramFiles%\IrfanView\plugins\SoundPlayer.dll
  • %ProgramFiles%\IrfanView\is-KVV6T.tmp в %ProgramFiles%\IrfanView\Desktop.ini
  • %ProgramFiles%\IrfanView\is-UBCQN.tmp в %ProgramFiles%\IrfanView\IrfanView.ico
  • %ProgramFiles%\IrfanView\plugins\is-OJC4J.tmp в %ProgramFiles%\IrfanView\plugins\Icons.dll
  • %ProgramFiles%\IrfanView\Toolbars\is-N30LT.tmp в %ProgramFiles%\IrfanView\Toolbars\Samuel_16.png
  • %ProgramFiles%\IrfanView\Toolbars\is-IAQFV.tmp в %ProgramFiles%\IrfanView\Toolbars\Samuel_16.txt
  • %ProgramFiles%\IrfanView\plugins\is-GJ071.tmp в %ProgramFiles%\IrfanView\plugins\Crw.dll
  • %ProgramFiles%\IrfanView\plugins\is-OTDE2.tmp в %ProgramFiles%\IrfanView\plugins\FFactory.dll
  • %ProgramFiles%\IrfanView\plugins\is-3JJ0U.tmp в %ProgramFiles%\IrfanView\plugins\Flash.dll
  • %ProgramFiles%\IrfanView\plugins\is-HER5U.tmp в %ProgramFiles%\IrfanView\plugins\FaceDetect.dll
  • %ProgramFiles%\IrfanView\plugins\is-9ILIS.tmp в %ProgramFiles%\IrfanView\plugins\Ecw.dll
  • %ProgramFiles%\IrfanView\plugins\is-27ELB.tmp в %ProgramFiles%\IrfanView\plugins\Exr.dll
Подменяет следующие файлы:
  • %ProgramFiles%\IrfanView\i_view32.chm
Другое:
Ищет следующие окна:
  • ClassName: 'EDIT' WindowName: ''
Создает и запускает на исполнение:
  • '%TEMP%\is-D84E9.tmp\IrfanView-Full_4.51.tmp' /SL5="$3010E,31922399,159744,%TEMP%\RarSFX0\IrfanView-Full_4.51.exe" /VERYSILENT /LANG=de /TASKS="desktopicon,plugins"
  • '%TEMP%\RarSFX0\IrfanView-Full_4.51.exe' /VERYSILENT /LANG=de /TASKS="desktopicon,plugins"
Запускает на исполнение:
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\Install_IrfanView.cmd" "

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке