Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.29593

Добавлен в вирусную базу Dr.Web: 2019-09-21

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Модифицирует следующие ключи реестра
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'pidgcs.exe' = '%APPDATA%\Pidgcs\pidgcs.exe'
Вредоносные функции
Читает файлы, отвечающие за хранение паролей сторонними программами
  • %HOMEPATH%\desktop\2.jpg
  • %HOMEPATH%\desktop\210252809.jpg
  • %HOMEPATH%\desktop\508softwareandos.doc
  • %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
  • %HOMEPATH%\desktop\cveuropeo.doc
  • %HOMEPATH%\desktop\delete.avi
  • %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
  • %HOMEPATH%\desktop\hanni_umami_chapter.doc
  • %HOMEPATH%\desktop\ovp25012015.doc
  • %HOMEPATH%\desktop\parnas_01.jpeg
  • %HOMEPATH%\desktop\pushkin.jpg
  • %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
Изменения в файловой системе
Создает следующие файлы
  • %WINDIR%\bootstat.dat.locked
  • %ProgramFiles%\steam\friends\trackerui_hungarian.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_greek.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_german.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_french.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_finnish.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_english.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_dutch.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_danish.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_czech.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_bulgarian.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_brazilian.txt.locked
  • %ProgramFiles%\steam\friends\message.wav.locked
  • %ProgramFiles%\steam\friends\friend_online.wav.locked
  • %ProgramFiles%\steam\friends\friend_join.wav.locked
  • %ProgramFiles%\mozilla thunderbird\searchplugins\yahoo.xml.locked
  • %ProgramFiles%\steam\logs\connection_log.txt.locked
  • %ProgramFiles%\mozilla thunderbird\searchplugins\wikipedia.xml.locked
  • %ProgramFiles%\mozilla thunderbird\searchplugins\twitter.xml.locked
  • %ProgramFiles%\steam\friends\trackerui_koreana.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_italian.txt.locked
  • %ProgramFiles%\steam\logs\bootstrap_log.txt.locked
  • %ProgramFiles%\steam\friends\voice_hang_up.wav.locked
  • %ProgramFiles%\steam\friends\trackerui_ukrainian.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_turkish.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_thai.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_tchinese.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_swedish.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_spanish.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_schinese.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_russian.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_romanian.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_portuguese.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_polish.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_norwegian.txt.locked
  • %ProgramFiles%\steam\friends\trackerui_korean.txt.locked
  • C:\msocache\all users\{90120000-001a-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • %ProgramFiles%\steam\friends\trackerui_japanese.txt.locked
  • C:\msocache\all users\{90120000-0117-0409-0000-0000000ff1ce}-c\accessmuiset.xml.locked
  • C:\msocache\all users\{90120000-0115-0409-0000-0000000ff1ce}-c\officemuiset.xml.locked
  • C:\msocache\all users\{90120000-0115-0409-0000-0000000ff1ce}-c\officemui.xml.locked
  • C:\msocache\all users\{90120000-0115-0409-0000-0000000ff1ce}-c\branding.xml.locked
  • C:\msocache\all users\{90120000-0114-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-0114-0409-0000-0000000ff1ce}-c\groovemuiset.xml.locked
  • C:\msocache\all users\{90120000-00a1-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-00a1-0409-0000-0000000ff1ce}-c\onenotemui.xml.locked
  • C:\msocache\all users\{90120000-0044-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-0044-0409-0000-0000000ff1ce}-c\infopathmui.xml.locked
  • C:\msocache\all users\{90120000-0030-0000-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-0030-0000-0000-0000000ff1ce}-c\office64ww.xml.locked
  • C:\msocache\all users\{90120000-0030-0000-0000-0000000ff1ce}-c\enterpriseww.xml.locked
  • C:\msocache\all users\{90120000-002c-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-002c-0409-0000-0000000ff1ce}-c\proofing.xml.locked
  • C:\msocache\all users\{90120000-001b-0409-0000-0000000ff1ce}-c\wordmui.xml.locked
  • %ProgramFiles%\mozilla thunderbird\searchplugins\aol-web-search.xml.locked
  • %ProgramFiles%\mozilla thunderbird\searchplugins\ebay.xml.locked
  • %ProgramFiles%\mozilla thunderbird\searchplugins\bing.xml.locked
  • %ProgramFiles%\adobe\acrobat.com\version.xml.locked
  • C:\msocache\all users\{90120000-0115-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • %ProgramFiles%\mozilla thunderbird\searchplugins\amazondotcom.xml.locked
  • %ProgramFiles%\mozilla firefox\browser\blocklist.xml.locked
  • %ProgramFiles%\movie maker\shared\filters.xml.locked
  • %ProgramFiles%\movie maker\shared\empty.txt.locked
  • %ProgramFiles%\microsoft.net\redistlist\assemblylist_4_extended.xml.locked
  • %ProgramFiles%\microsoft.net\redistlist\assemblylist_4_client.xml.locked
  • %ProgramFiles%\microsoft office\office12\reminder.wav.locked
  • %ProgramFiles%\microsoft office\office12\microsoft.office.interop.infopath.xml.xml.locked
  • %ProgramFiles%\microsoft office\office12\microsoft.office.interop.infopath.semitrust.xml.locked
  • %ProgramFiles%\microsoft office\office12\microsoft.office.infopath.xml.locked
  • %ProgramFiles%\java\jre6\thirdpartylicensereadme.txt.locked
  • %ProgramFiles%\java\jre6\readme.txt.locked
  • %ProgramFiles%\java\jre6\license.txt.locked
  • %ProgramFiles%\far2\addons\readme.txt.locked
  • C:\msocache\all users\{90120000-0117-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-001b-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • %ProgramFiles%\steam\logs\content_log.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_romanian.txt.locked
  • %ProgramFiles%\steam\public\steamui_dutch.txt.locked
  • %ProgramFiles%\steam\public\steamui_danish.txt.locked
  • %ProgramFiles%\steam\public\steamui_czech.txt.locked
  • %ProgramFiles%\steam\public\steamui_bulgarian.txt.locked
  • %ProgramFiles%\steam\public\steamui_brazilian.txt.locked
  • %ProgramFiles%\steam\public\steamclean_ukrainian.txt.locked
  • %ProgramFiles%\steam\public\steamclean_turkish.txt.locked
  • %ProgramFiles%\steam\public\steamclean_thai.txt.locked
  • %ProgramFiles%\steam\public\steamclean_tchinese.txt.locked
  • %ProgramFiles%\steam\public\steamclean_swedish.txt.locked
  • %ProgramFiles%\steam\public\steamclean_spanish.txt.locked
  • %ProgramFiles%\steam\public\steamclean_schinese.txt.locked
  • %ProgramFiles%\steam\public\steamclean_russian.txt.locked
  • %ProgramFiles%\steam\public\steamclean_romanian.txt.locked
  • %ProgramFiles%\steam\public\steamclean_portuguese.txt.locked
  • %ProgramFiles%\steam\public\steamclean_norwegian.txt.locked
  • %ProgramFiles%\steam\public\steamclean_polish.txt.locked
  • %ProgramFiles%\steam\public\steamui_english.txt.locked
  • %ProgramFiles%\steam\public\steamui_finnish.txt.locked
  • %ProgramFiles%\steam\public\steamui_spanish.txt.locked
  • %ProgramFiles%\steam\public\steamui_schinese.txt.locked
  • %ProgramFiles%\steam\public\steamui_russian.txt.locked
  • %ProgramFiles%\steam\public\steamui_romanian.txt.locked
  • %ProgramFiles%\steam\public\steamui_postlogon_greek.txt.locked
  • %ProgramFiles%\steam\public\steamui_portuguese.txt.locked
  • %ProgramFiles%\steam\public\steamui_polish.txt.locked
  • %ProgramFiles%\steam\public\steamui_koreana.txt.locked
  • %WINDIR%\temp\perflib_perfdata_790.dat.locked
  • %ProgramFiles%\steam\public\steamui_korean.txt.locked
  • %ProgramFiles%\steam\public\steamui_japanese.txt.locked
  • %ProgramFiles%\steam\public\steamui_italian.txt.locked
  • %ProgramFiles%\steam\public\steamui_hungarian.txt.locked
  • %ProgramFiles%\steam\public\steamui_greek.txt.locked
  • %ProgramFiles%\steam\public\steamui_german.txt.locked
  • %ProgramFiles%\steam\public\steamui_french.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_czech.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_brazilian.txt.locked
  • %ProgramFiles%\steam\public\steamclean_italian.txt.locked
  • %ProgramFiles%\steam\public\steamclean_japanese.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_polish.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_norwegian.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_koreana.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_korean.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_japanese.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_italian.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_hungarian.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_greek.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_german.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_french.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_finnish.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_english.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_dutch.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_danish.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_portuguese.txt.locked
  • %ProgramFiles%\steam\public\steamclean_korean.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_russian.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_schinese.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_spanish.txt.locked
  • %ProgramFiles%\steam\public\steamclean_greek.txt.locked
  • %ProgramFiles%\steam\public\steamclean_german.txt.locked
  • %ProgramFiles%\steam\public\steamclean_french.txt.locked
  • %ProgramFiles%\steam\public\steamclean_finnish.txt.locked
  • %ProgramFiles%\steam\public\steamclean_english.txt.locked
  • %ProgramFiles%\steam\public\steamclean_dutch.txt.locked
  • %ProgramFiles%\steam\public\steamclean_danish.txt.locked
  • %ProgramFiles%\steam\public\steamclean_czech.txt.locked
  • %ProgramFiles%\steam\public\steamclean_brazilian.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_ukrainian.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_turkish.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_thai.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_tchinese.txt.locked
  • %ProgramFiles%\steam\public\steambootstrapper_swedish.txt.locked
  • %ProgramFiles%\steam\public\steamclean_hungarian.txt.locked
  • C:\msocache\all users\{90120000-001a-0409-0000-0000000ff1ce}-c\outlookmui.xml.locked
  • C:\msocache\all users\{90120000-0019-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-0019-0409-0000-0000000ff1ce}-c\publishermui.xml.locked
  • %WINDIR%\media\windows xp hardware remove.wav.locked
  • %WINDIR%\media\windows xp hardware insert.wav.locked
  • %WINDIR%\media\windows xp hardware fail.wav.locked
  • %WINDIR%\media\windows xp exclamation.wav.locked
  • %WINDIR%\media\windows xp error.wav.locked
  • %WINDIR%\media\windows xp ding.wav.locked
  • %WINDIR%\media\windows xp default.wav.locked
  • %WINDIR%\media\windows xp critical stop.wav.locked
  • %WINDIR%\media\windows xp battery low.wav.locked
  • %WINDIR%\media\windows xp battery critical.wav.locked
  • %WINDIR%\media\windows xp balloon.wav.locked
  • %WINDIR%\media\town.mid.locked
  • %WINDIR%\media\tada.wav.locked
  • %WINDIR%\media\start.wav.locked
  • %WINDIR%\media\windows xp logoff sound.wav.locked
  • %WINDIR%\media\ringout.wav.locked
  • <SYSTEM32>\emptyregdb.dat.locked
  • %WINDIR%\media\ringin.wav.locked
  • <SYSTEM32>\dssec.dat.locked
  • <SYSTEM32>\d3d9caps.dat.locked
  • %WINDIR%\shellnew\mspub.pub.locked
  • %WINDIR%\shellnew\excel12.xlsx.locked
  • %WINDIR%\repair\ntuser.dat.locked
  • %WINDIR%\media\windows xp startup.wav.locked
  • %WINDIR%\media\windows xp start.wav.locked
  • %WINDIR%\media\windows xp shutdown.wav.locked
  • %WINDIR%\media\windows xp ringout.wav.locked
  • %WINDIR%\media\windows xp ringin.wav.locked
  • %WINDIR%\media\windows xp restore.wav.locked
  • %WINDIR%\media\windows xp recycle.wav.locked
  • %WINDIR%\media\windows xp print complete.wav.locked
  • %WINDIR%\media\windows xp pop-up blocked.wav.locked
  • %WINDIR%\media\windows xp notify.wav.locked
  • %WINDIR%\media\windows xp menu command.wav.locked
  • %WINDIR%\media\windows xp logon sound.wav.locked
  • %WINDIR%\media\windows xp minimize.wav.locked
  • %WINDIR%\media\onestop.mid.locked
  • %ProgramFiles%\qip 2012\unins000.dat.locked
  • %ProgramFiles%\netmeeting\blip.wav.locked
  • %ProgramFiles%\mozilla thunderbird\blocklist.xml.locked
  • %ProgramFiles%\mirc\versions.txt.locked
  • %ProgramFiles%\mirc\readme.txt.locked
  • %ProgramFiles%\messenger\type.wav.locked
  • %ProgramFiles%\messenger\online.wav.locked
  • %ProgramFiles%\messenger\newemail.wav.locked
  • %ProgramFiles%\messenger\newalert.wav.locked
  • %ProgramFiles%\messenger\lvback.gif.locked
  • %ProgramFiles%\firefox\readme.txt.locked
  • %ProgramFiles%\firefox\blocklist.xml.locked
  • %WINDIR%\setuplog.txt.locked
  • %WINDIR%\oewablog.txt.locked
  • %WINDIR%\clock.avi.locked
  • %ProgramFiles%\opera\installation_status.xml.locked
  • %WINDIR%\media\recycle.wav.locked
  • <SYSTEM32>\eula.txt.locked
  • %ProgramFiles%\netmeeting\testsnd.wav.locked
  • %WINDIR%\media\notify.wav.locked
  • %WINDIR%\media\flourish.mid.locked
  • %WINDIR%\media\ding.wav.locked
  • %WINDIR%\media\chord.wav.locked
  • %WINDIR%\media\chimes.wav.locked
  • %ProgramFiles%\winrar\zipnew.dat.locked
  • %ProgramFiles%\winrar\whatsnew.txt.locked
  • %ProgramFiles%\winrar\readme.txt.locked
  • %ProgramFiles%\winrar\rarnew.dat.locked
  • %ProgramFiles%\winrar\rar.txt.locked
  • %ProgramFiles%\winrar\license.txt.locked
  • %ProgramFiles%\windows media player\npds.zip.locked
  • %ProgramFiles%\windows media player\npdrmv2.zip.locked
  • %ProgramFiles%\steam\thirdpartylegalnotices.doc.locked
  • %ProgramFiles%\qip 2012\unins000.msg.locked
  • %ProgramFiles%\outlook express\msoe.txt.locked
  • %ProgramFiles%\opera\launcher.visualelementsmanifest.xml.locked
  • %WINDIR%\media\windows xp information bar.wav.locked
  • <SYSTEM32>\graphics.pro.locked
  • %HOMEPATH%\cookies\user@rabotaetvse[1].txt.locked
  • %HOMEPATH%\cookies\user@atdmt[1].txt.locked
  • %HOMEPATH%\cookies\user@point4all[2].txt.locked
  • %HOMEPATH%\cookies\user@opera[1].txt.locked
  • %HOMEPATH%\cookies\user@openstat[1].txt.locked
  • %HOMEPATH%\cookies\user@msn[1].txt.locked
  • %HOMEPATH%\cookies\user@mon.softkey[2].txt.locked
  • %HOMEPATH%\cookies\user@microsoft[1].txt.locked
  • %HOMEPATH%\cookies\user@mail[1].txt.locked
  • %HOMEPATH%\cookies\user@help.softkey[3].txt.locked
  • %HOMEPATH%\cookies\user@help.softkey[2].txt.locked
  • %HOMEPATH%\cookies\user@d.castplatform[2].txt.locked
  • %HOMEPATH%\cookies\user@c.msn[1].txt.locked
  • %HOMEPATH%\cookies\user@c.bing[1].txt.locked
  • %HOMEPATH%\cookies\user@bluekai[2].txt.locked
  • %HOMEPATH%\cookies\user@bing[1].txt.locked
  • %HOMEPATH%\cookies\user@adnxs[1].txt.locked
  • %HOMEPATH%\cookies\user@rambler[2].txt.locked
  • %HOMEPATH%\cookies\user@rarlab[1].txt.locked
  • %HOMEPATH%\cookies\user@scorecardresearch[2].txt.locked
  • %HOMEPATH%\cookies\user@serving-sys[2].txt.locked
  • C:\msocache\all users\{90120000-0018-0409-0000-0000000ff1ce}-c\powerpointmui.xml.locked
  • C:\msocache\all users\{90120000-0016-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-0016-0409-0000-0000000ff1ce}-c\excelmui.xml.locked
  • C:\msocache\all users\{90120000-0010-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • C:\msocache\all users\{90120000-0010-0409-0000-0000000ff1ce}-c\rosebudmui.xml.locked
  • %HOMEPATH%\userdata\index.dat.locked
  • %HOMEPATH%\templates\sndrec.wav.locked
  • %HOMEPATH%\templates\lotus.wk4.locked
  • %HOMEPATH%\cookies\user@yandex[2].txt.locked
  • %HOMEPATH%\cookies\user@yadro[1].txt.locked
  • %HOMEPATH%\cookies\user@www.msn[1].txt.locked
  • %HOMEPATH%\cookies\user@winrar.softkey[2].txt.locked
  • %HOMEPATH%\cookies\user@win-rar[1].txt.locked
  • %HOMEPATH%\cookies\user@softkey[2].txt.locked
  • C:\msocache\all users\{90120000-0018-0409-0000-0000000ff1ce}-c\setup.xml.locked
  • %HOMEPATH%\cookies\user@adobe[1].txt.locked
  • %HOMEPATH%\cookies\user@7ba[1].txt.locked
  • <SYSTEM32>\h323log.txt.locked
  • <SYSTEM32>\perfh009.dat.locked
  • <SYSTEM32>\perffilt.h.locked
  • <SYSTEM32>\perfd009.dat.locked
  • <SYSTEM32>\perfci.h.locked
  • <SYSTEM32>\perfc009.dat.locked
  • <SYSTEM32>\oembios.dat.locked
  • <SYSTEM32>\ntimage.gif.locked
  • <SYSTEM32>\noise.dat.locked
  • <SYSTEM32>\msvcr71d.pdb.locked
  • <SYSTEM32>\msvcr71.pdb.locked
  • <SYSTEM32>\msdtcprf.h.locked
  • <SYSTEM32>\mqprfsym.h.locked
  • <SYSTEM32>\mlang.dat.locked
  • <SYSTEM32>\instcat.sql.locked
  • <SYSTEM32>\perfwci.h.locked
  • <SYSTEM32>\pschdcnt.h.locked
  • <SYSTEM32>\perfi009.dat.locked
  • <SYSTEM32>\rasctrnm.h.locked
  • %HOMEPATH%\cookies\user@326944[1].txt.locked
  • <SYSTEM32>\rsvpcnts.h.locked
  • C:\documents and settings\default user\templates\sndrec.wav.locked
  • C:\documents and settings\default user\templates\lotus.wk4.locked
  • C:\documents and settings\default user\cookies\index.dat.locked
  • %WINDIR%\web\tips.gif.locked
  • %WINDIR%\web\exclam.gif.locked
  • %WINDIR%\web\bullet.gif.locked
  • %ProgramFiles%\steam\public\steamui_norwegian.txt.locked
  • %ProgramFiles%\steam\public\steamui_swedish.txt.locked
  • %WINDIR%\temp\perflib_perfdata_760.dat.locked
  • %WINDIR%\temp\perflib_perfdata_748.dat.locked
  • %WINDIR%\temp\perflib_perfdata_740.dat.locked
  • %WINDIR%\temp\perflib_perfdata_6f0.dat.locked
  • %WINDIR%\temp\perflib_perfdata_568.dat.locked
  • <SYSTEM32>\tslabels.h.locked
  • <SYSTEM32>\secupd.dat.locked
  • %WINDIR%\temp\perflib_perfdata_8e0.dat.locked
  • %ProgramFiles%\steam\public\steamui_tchinese.txt.locked
Удаляет следующие файлы
  • %WINDIR%\bootstat.dat
  • <SYSTEM32>\ntimage.gif
  • <SYSTEM32>\noise.dat
  • <SYSTEM32>\msvcr71d.pdb
  • <SYSTEM32>\msvcr71.pdb
  • <SYSTEM32>\msdtcprf.h
  • <SYSTEM32>\mqprfsym.h
  • <SYSTEM32>\mlang.dat
  • <SYSTEM32>\oembios.dat
  • <SYSTEM32>\instcat.sql
  • <SYSTEM32>\graphics.pro
  • <SYSTEM32>\eula.txt
  • <SYSTEM32>\emptyregdb.dat
  • <SYSTEM32>\dssec.dat
  • %WINDIR%\shellnew\mspub.pub
  • %WINDIR%\shellnew\excel12.xlsx
  • %WINDIR%\repair\ntuser.dat
  • <SYSTEM32>\h323log.txt
  • <SYSTEM32>\perfc009.dat
  • <SYSTEM32>\perfci.h
  • <SYSTEM32>\perfd009.dat
  • %WINDIR%\web\bullet.gif
  • %WINDIR%\temp\perflib_perfdata_8e0.dat
  • %WINDIR%\temp\perflib_perfdata_790.dat
  • %WINDIR%\temp\perflib_perfdata_760.dat
  • %WINDIR%\temp\perflib_perfdata_748.dat
  • %WINDIR%\temp\perflib_perfdata_740.dat
  • %WINDIR%\temp\perflib_perfdata_6f0.dat
  • %WINDIR%\temp\perflib_perfdata_568.dat
  • <SYSTEM32>\tslabels.h
  • <SYSTEM32>\secupd.dat
  • <SYSTEM32>\rsvpcnts.h
  • <SYSTEM32>\rasctrnm.h
  • <SYSTEM32>\pschdcnt.h
  • <SYSTEM32>\perfwci.h
  • <SYSTEM32>\perfi009.dat
  • <SYSTEM32>\perfh009.dat
  • <SYSTEM32>\perffilt.h
  • %WINDIR%\media\windows xp startup.wav
  • %WINDIR%\web\exclam.gif
  • %WINDIR%\media\windows xp start.wav
  • %WINDIR%\media\windows xp ringout.wav
  • %WINDIR%\media\windows xp balloon.wav
  • %WINDIR%\media\town.mid
  • %WINDIR%\media\tada.wav
  • %WINDIR%\media\start.wav
  • %WINDIR%\media\ringout.wav
  • %WINDIR%\media\ringin.wav
  • %WINDIR%\media\recycle.wav
  • %WINDIR%\media\windows xp battery critical.wav
  • %WINDIR%\media\onestop.mid
  • %WINDIR%\media\flourish.mid
  • %WINDIR%\media\ding.wav
  • %WINDIR%\media\chord.wav
  • %WINDIR%\media\chimes.wav
  • %WINDIR%\setuplog.txt
  • %WINDIR%\oewablog.txt
  • %WINDIR%\clock.avi
  • %WINDIR%\media\notify.wav
  • %WINDIR%\media\windows xp battery low.wav
  • %WINDIR%\media\windows xp critical stop.wav
  • %WINDIR%\media\windows xp default.wav
  • %WINDIR%\media\windows xp ringin.wav
  • %WINDIR%\media\windows xp restore.wav
  • %WINDIR%\media\windows xp recycle.wav
  • %WINDIR%\media\windows xp print complete.wav
  • %WINDIR%\media\windows xp pop-up blocked.wav
  • %WINDIR%\media\windows xp notify.wav
  • %WINDIR%\media\windows xp minimize.wav
  • %WINDIR%\media\windows xp menu command.wav
  • %WINDIR%\media\windows xp logon sound.wav
  • %WINDIR%\media\windows xp logoff sound.wav
  • %WINDIR%\media\windows xp information bar.wav
  • %WINDIR%\media\windows xp hardware remove.wav
  • %WINDIR%\media\windows xp hardware insert.wav
  • %WINDIR%\media\windows xp hardware fail.wav
  • %WINDIR%\media\windows xp exclamation.wav
  • %WINDIR%\media\windows xp error.wav
  • %WINDIR%\media\windows xp ding.wav
  • %WINDIR%\media\windows xp shutdown.wav
  • %WINDIR%\web\tips.gif
Изменяет расширения файлов пользовательских данных (Trojan.Encoder).

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке