Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.32212

Добавлен в вирусную базу Dr.Web: 2020-07-26

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Создает следующие файлы на съемном носителе
  • <Имя диска съемного носителя>:\conti_readme.txt
  • <Имя диска съемного носителя>:\dialmap.bmp
  • <Имя диска съемного носителя>:\default.bmp
  • <Имя диска съемного носителя>:\dashborder_144.bmp
  • <Имя диска съемного носителя>:\dial.bmp
  • <Имя диска съемного носителя>:\coffee.bmp
  • <Имя диска съемного носителя>:\dashborder_192.bmp
  • <Имя диска съемного носителя>:\sdksampleunprivdeveloper.cer
  • <Имя диска съемного носителя>:\contoso_1.cer
  • <Имя диска съемного носителя>:\pmd.cer
  • <Имя диска съемного носителя>:\weeklysheet1215.doc
  • <Имя диска съемного носителя>:\issi2013_template_for_posters.docx
  • <Имя диска съемного носителя>:\holycrosschurchinstructions.docx
  • <Имя диска съемного носителя>:\thlps_keeper_mayer_1965.docx
Вредоносные функции
Для затруднения выявления своего присутствия в системе
удаляет теневые копии разделов.
Изменения в файловой системе
Создает следующие файлы
  • C:\conti_readme.txt
  • %ProgramFiles%\courier\conti_readme.txt
  • %CommonProgramFiles%\system\msadc\en-us\conti_readme.txt
  • %CommonProgramFiles%\system\msmapi\conti_readme.txt
  • %CommonProgramFiles%\system\msmapi\1033\conti_readme.txt
  • %CommonProgramFiles%\system\ole db\conti_readme.txt
  • %CommonProgramFiles%\system\ole db\en-us\conti_readme.txt
  • %ProgramFiles%\copyx64\conti_readme.txt
  • %ProgramFiles%\cpd\conti_readme.txt
  • %ProgramFiles%\defensewall\conti_readme.txt
  • %ProgramFiles%\csendto\conti_readme.txt
  • %ProgramFiles%\cssexc\conti_readme.txt
  • %ProgramFiles%\custinstall\conti_readme.txt
  • %ProgramFiles%\custsetup\conti_readme.txt
  • %ProgramFiles%\cuteftp\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\ricepapr\conti_readme.txt
  • %ProgramFiles%\dbconvert\conti_readme.txt
  • %CommonProgramFiles%\system\msadc\conti_readme.txt
  • %CommonProgramFiles%\system\ado\en-us\conti_readme.txt
  • %CommonProgramFiles%\system\ado\conti_readme.txt
  • %CommonProgramFiles%\system\conti_readme.txt
  • %CommonProgramFiles%\speechengines\microsoft\conti_readme.txt
  • %CommonProgramFiles%\speechengines\conti_readme.txt
  • %CommonProgramFiles%\services\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\1033\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\web folders\1033\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\web folders\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\1033\conti_readme.txt
  • %ProgramFiles%\dbtool\conti_readme.txt
  • %ProgramFiles%\defwatch\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\pets\conti_readme.txt
  • %ProgramFiles%\drvirus\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\babygirl\conti_readme.txt
  • %ProgramFiles%\drwreg\conti_readme.txt
  • %ProgramFiles%\dvd maker\conti_readme.txt
  • %ProgramFiles%\dvd maker\en-us\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\babyboy\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\flippage\conti_readme.txt
  • %ProgramFiles%\dekaron\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\full\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\huecycle\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\layeredtitles\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\memories\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\oldage\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\performance\conti_readme.txt
  • %ProgramFiles%\drwebwcl\conti_readme.txt
  • %ProgramFiles%\drwebupw\conti_readme.txt
  • %ProgramFiles%\drwebscd\conti_readme.txt
  • %ProgramFiles%\drweb386\conti_readme.txt
  • %ProgramFiles%\drweb32w\conti_readme.txt
  • %ProgramFiles%\drweb\conti_readme.txt
  • %ProgramFiles%\drwadins\conti_readme.txt
  • %ProgramFiles%\drvmap\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\conti_readme.txt
  • %ProgramFiles%\drvctl\conti_readme.txt
  • %ProgramFiles%\dpatrolq\conti_readme.txt
  • %ProgramFiles%\dnf\conti_readme.txt
  • %ProgramFiles%\dislite\conti_readme.txt
  • %ProgramFiles%\directftp\conti_readme.txt
  • %ProgramFiles%\digsby-app\conti_readme.txt
  • %ProgramFiles%\digsby\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\vsto\conti_readme.txt
  • %CommonProgramFiles%\system\en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\vgx\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\vc\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\push\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\blueprnt\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\ice\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\expeditn\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\evrgreen\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\edge\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\eclipse\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\echo\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\deepblue\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\concrete\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\compass\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\cascade\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\capsules\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\canyon\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\breeze\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\boldstri\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\bluecalm\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\axis\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\arctic\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\aftrnoon\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\textconv\en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\stationery\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\journal\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\iris\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\smart tag\lists\1033\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\smart tag\lists\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\smart tag\1033\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\smart tag\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\proof\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\textconv\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\source engine\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\level\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\slate\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\vba\vba7\1033\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\enfr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\sumipntg\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\water\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\watermar\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\arfr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\enes\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\esen\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\indust\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\frar\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\fren\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\triedit\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\triedit\en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\vba\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\vba\vba7\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\studio\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\sky\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\satin\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\rmnsque\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\ripple\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\refined\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\layers\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\sonora\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\radial\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\profile\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\pixel\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\papyrus\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\network\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\spring\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\strtedge\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\quad\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\blends\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\rectangles\conti_readme.txt
  • %ProgramFiles%\egni\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\downloads\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\extensions\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\handling\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\plugins\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\preferences\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\update\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\feedback\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\xpinstall\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\necko\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\passwordmgr\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\pipnss\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\pippki\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\places\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\mozapps\profile\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\services\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global_platform\unix\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global_platform\mac\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global_platform\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\xslt\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\xpinstall\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\xml\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\svg\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\security\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\search\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\layout\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\dom\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\cookie\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\autoconfig\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global_region\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser_region\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\pippki\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\aero\global\console\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\profile\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\update\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\xpinstall\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\passwordmgr\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\satchel\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\xbl_marquee\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\pippki\content\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\aero\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\aero\global\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\aero\global\alerts\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\aero\global\arrow\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\aero\global\checkbox\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\preferences\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\plugins\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\pippki\content\pippki\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\global\cpow\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\handling\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\extensions\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\downloads\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\mozapps\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\global\xml\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\global_platform\win\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\global\svg\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\alerts\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\global\alerts\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\global\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\cookie\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\content\global\bindings\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\en_us\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser\sidebar\conti_readme.txt
  • %ProgramFiles%\ccleaner\conti_readme.txt
  • %ProgramFiles%\filezilla\conti_readme.txt
  • %ProgramFiles%\f-sched\conti_readme.txt
  • %ProgramFiles%\fameh32\conti_readme.txt
  • %ProgramFiles%\far\conti_readme.txt
  • %ProgramFiles%\fch32\conti_readme.txt
  • %ProgramFiles%\fdm\conti_readme.txt
  • %ProgramFiles%\fdmwi\conti_readme.txt
  • %ProgramFiles%\firebird\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\resizingpanels\conti_readme.txt
  • %ProgramFiles%\firefox\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\branding\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\conti_readme.txt
  • %ProgramFiles%\ezantivirusregistrationcheck\conti_readme.txt
  • %ProgramFiles%\exit_av\conti_readme.txt
  • %ProgramFiles%\ewidoctrl\conti_readme.txt
  • %ProgramFiles%\eudora\conti_readme.txt
  • %ProgramFiles%\etherd\conti_readme.txt
  • %ProgramFiles%\elementclient\conti_readme.txt
  • %ProgramFiles%\ekrn\conti_readme.txt
  • %ProgramFiles%\ehsniffer\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\bookmarks\conti_readme.txt
  • %ProgramFiles%\ecmd\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\vignette\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\videowall\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\travel\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\stacking\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\sports\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\specialoccasion\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\certerror\conti_readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\shatter\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\feeds\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\aero\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\browser\places\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\browser\preferences\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\browser\tabbrowser\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\browser\tabview\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\communicator\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\branding\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\migration\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser\downloads\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser\feeds\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser\migration\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser\places\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser\preferences\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\browser\feeds\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\browser\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\aero\browser\tabview\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\aero\browser\tabbrowser\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\aero\browser\preferences\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\aero\browser\places\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\aero\browser\feeds\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\aero\browser\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\en_us\locale\browser\safebrowsing\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\classic\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\skin\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\search\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\safebrowsing\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\preferences\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\places\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\pageinfo\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\browser\content\browser\history\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\word.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\publisher.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proplus\conti_readme.txt
  • %ProgramFiles%\ashquick\conti_readme.txt
  • %ProgramFiles%\antivirus\conti_readme.txt
  • %ProgramFiles%\aoltbserver\conti_readme.txt
  • %ProgramFiles%\armor2net\conti_readme.txt
  • %ProgramFiles%\armorsurf\conti_readme.txt
  • %ProgramFiles%\ash\conti_readme.txt
  • %ProgramFiles%\ashavsrv\conti_readme.txt
  • %ProgramFiles%\ashsimp2\conti_readme.txt
  • %ProgramFiles%\ashchest\conti_readme.txt
  • %ProgramFiles%\ashdisp\conti_readme.txt
  • %ProgramFiles%\ashdug\conti_readme.txt
  • %ProgramFiles%\ashenhcd\conti_readme.txt
  • %ProgramFiles%\ashlogv\conti_readme.txt
  • %ProgramFiles%\ashmaisv\conti_readme.txt
  • %ProgramFiles%\ashavast\conti_readme.txt
  • %ProgramFiles%\anti-trojan\conti_readme.txt
  • %ProgramFiles%\alsvc\conti_readme.txt
  • %ProgramFiles%\almon\conti_readme.txt
  • %ProgramFiles%\airdefense\conti_readme.txt
  • %ProgramFiles%\aimpro\conti_readme.txt
  • %ProgramFiles%\aim6\conti_readme.txt
  • %ProgramFiles%\ahnsd\conti_readme.txt
  • %ProgramFiles%\ageofconan\conti_readme.txt
  • %ProgramFiles%\agb5\conti_readme.txt
  • %ProgramFiles%\admunch\conti_readme.txt
  • %ProgramFiles%\ackwin32\conti_readme.txt
  • %ProgramFiles%\about\conti_readme.txt
  • %ProgramFiles%\aavshield\conti_readme.txt
  • %ProgramFiles%\a2wizard\conti_readme.txt
  • %ProgramFiles%\amsn\conti_readme.txt
  • %ProgramFiles%\amon\conti_readme.txt
  • %ProgramFiles%\avkserv\conti_readme.txt
  • %ProgramFiles%\ashsimpl\conti_readme.txt
  • %ProgramFiles%\avgw\conti_readme.txt
  • %ProgramFiles%\avconsol\conti_readme.txt
  • %ProgramFiles%\avgamsvr\conti_readme.txt
  • %ProgramFiles%\avgcc\conti_readme.txt
  • %ProgramFiles%\avgdiag\conti_readme.txt
  • %ProgramFiles%\avgemc\conti_readme.txt
  • %ProgramFiles%\avgfwsrv\conti_readme.txt
  • %ProgramFiles%\avgnpdln\conti_readme.txt
  • %ProgramFiles%\avgwizfw\conti_readme.txt
  • %ProgramFiles%\avgnpsvc\conti_readme.txt
  • %ProgramFiles%\avgrssvc\conti_readme.txt
  • %ProgramFiles%\avgscan\conti_readme.txt
  • %ProgramFiles%\avgupden\conti_readme.txt
  • %ProgramFiles%\avgupsvc\conti_readme.txt
  • %ProgramFiles%\avgvv\conti_readme.txt
  • %ProgramFiles%\avconfig\conti_readme.txt
  • %ProgramFiles%\ashskpcc\conti_readme.txt
  • %ProgramFiles%\ashskpck\conti_readme.txt
  • %ProgramFiles%\a2start\conti_readme.txt
  • %ProgramFiles%\autodown\conti_readme.txt
  • %ProgramFiles%\avcmd\conti_readme.txt
  • %ProgramFiles%\avciman\conti_readme.txt
  • %ProgramFiles%\avcenter\conti_readme.txt
  • %ProgramFiles%\avadmin\conti_readme.txt
  • %ProgramFiles%\ashserv\conti_readme.txt
  • %ProgramFiles%\autotrace\conti_readme.txt
  • %ProgramFiles%\aswupdsv\conti_readme.txt
  • %ProgramFiles%\a2upd\conti_readme.txt
  • %ProgramFiles%\aswregsvr\conti_readme.txt
  • %ProgramFiles%\ash_updatemediator\conti_readme.txt
  • %ProgramFiles%\ashwebsv\conti_readme.txt
  • %ProgramFiles%\ashupd\conti_readme.txt
  • %ProgramFiles%\autostartexplorer\conti_readme.txt
  • %ProgramFiles%\a2service\conti_readme.txt
  • %ProgramFiles%\a2scan\conti_readme.txt
  • C:\far2\plugins\ftp\conti_readme.txt
  • C:\far2\documentation\eng\conti_readme.txt
  • C:\far2\plugins\farcmds\conti_readme.txt
  • C:\far2\plugins\emenu\conti_readme.txt
  • C:\far2\plugins\editcase\conti_readme.txt
  • C:\far2\plugins\drawline\conti_readme.txt
  • C:\far2\plugins\compare\conti_readme.txt
  • C:\far2\plugins\brackets\conti_readme.txt
  • C:\far2\plugins\autowrap\conti_readme.txt
  • C:\far2\plugins\arclite\conti_readme.txt
  • C:\far2\plugins\align\conti_readme.txt
  • C:\far2\plugins\conti_readme.txt
  • C:\far2\fexcept\conti_readme.txt
  • C:\far2\encyclopedia\tap\conti_readme.txt
  • C:\far2\encyclopedia\conti_readme.txt
  • C:\far2\documentation\rus\conti_readme.txt
  • C:\documents and settings\conti_readme.txt
  • %ProgramFiles%\avinitnt\conti_readme.txt
  • C:\far2\addons\colors\default_highlighting\conti_readme.txt
  • C:\far2\documentation\conti_readme.txt
  • C:\far2\addons\xlat\russian\conti_readme.txt
  • C:\far2\addons\xlat\conti_readme.txt
  • C:\far2\addons\shell\conti_readme.txt
  • C:\far2\addons\setup\conti_readme.txt
  • C:\far2\plugins\hlfviewer\conti_readme.txt
  • C:\far2\addons\macros\conti_readme.txt
  • C:\far2\plugins\ftp\lib\conti_readme.txt
  • C:\far2\addons\colors\conti_readme.txt
  • C:\far2\addons\conti_readme.txt
  • C:\far2\conti_readme.txt
  • D:\conti_readme.txt
  • <Текущая директория>\conti_readme.txt
  • C:\far2\addons\colors\custom_highlighting\conti_readme.txt
  • %ProgramFiles%\avginet\conti_readme.txt
  • C:\far2\plugins\network\conti_readme.txt
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\1033\conti_readme.txt
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\conti_readme.txt
  • C:\far2\plugins\filecase\conti_readme.txt
  • C:\perflogs\conti_readme.txt
  • C:\perflogs\admin\conti_readme.txt
  • %ProgramFiles%\conti_readme.txt
  • %ProgramFiles%\360tray\conti_readme.txt
  • %ProgramFiles%\a2cmd\conti_readme.txt
  • %ProgramFiles%\a2guard\conti_readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\conti_readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\conti_readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\conti_readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\conti_readme.txt
  • %ProgramFiles%\a2hijackfree\conti_readme.txt
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\conti_readme.txt
  • C:\msocache\all users\conti_readme.txt
  • C:\msocache\conti_readme.txt
  • C:\far2\pluginsdk\headers.pas\conti_readme.txt
  • C:\far2\pluginsdk\headers.c\conti_readme.txt
  • C:\far2\pluginsdk\conti_readme.txt
  • C:\far2\plugins\proclist\conti_readme.txt
  • C:\far2\plugins\macroview\conti_readme.txt
  • %ProgramFiles%\ashpopwz\conti_readme.txt
  • %ProgramFiles%\avkservice\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\nl-nl\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\hu-hu\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\osknumpad\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskpred\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\symbols\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\web\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\he-il\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\hr-hr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\hwrcustomization\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ar-sa\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\it-it\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ja-jp\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ko-kr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\lt-lt\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\lv-lv\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\nb-no\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskmenu\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\numbers\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\keypad\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\auxpad\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fr-fr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fi-fi\conti_readme.txt
  • %ProgramFiles%\avkwctl\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\es-es\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\el-gr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\de-de\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\da-dk\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\cs-cz\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\bg-bg\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\pl-pl\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\et-ee\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\pt-br\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\uk-ua\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office32.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\access.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\excel.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\groove.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\infopath.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office32.ww\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ro-ro\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\onenote.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\outlook.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\powerpoint.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.en\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.es\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.fr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\cultures\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\1033\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\msinfo\en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\msinfo\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\msclientdatamgr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\zh-tw\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\zh-cn\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proofing.en-us\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\tr-tr\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\th-th\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\sv-se\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\sr-latn-cs\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\sl-si\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\sk-sk\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ru-ru\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\pt-pt\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\res\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\aero\global\dirlisting\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\grphflt\conti_readme.txt
  • %ProgramFiles%\bdswitch\conti_readme.txt
  • %ProgramFiles%\cavmud\conti_readme.txt
  • %ProgramFiles%\cavmr\conti_readme.txt
  • %ProgramFiles%\cavemsrv\conti_readme.txt
  • %ProgramFiles%\cavaud\conti_readme.txt
  • %ProgramFiles%\cavasm\conti_readme.txt
  • %ProgramFiles%\cavapp\conti_readme.txt
  • %ProgramFiles%\cafix\conti_readme.txt
  • %ProgramFiles%\cabalmain\conti_readme.txt
  • %ProgramFiles%\btinint\conti_readme.txt
  • %ProgramFiles%\btini\conti_readme.txt
  • %ProgramFiles%\blindman\conti_readme.txt
  • %ProgramFiles%\blackice\conti_readme.txt
  • %ProgramFiles%\blackd\conti_readme.txt
  • %ProgramFiles%\bdwizreg\conti_readme.txt
  • %ProgramFiles%\bdsurvey\conti_readme.txt
  • %ProgramFiles%\bdagent\conti_readme.txt
  • %ProgramFiles%\bdsubmitwiz\conti_readme.txt
  • %ProgramFiles%\bdsubmit\conti_readme.txt
  • %ProgramFiles%\bdss\conti_readme.txt
  • %ProgramFiles%\bdoesrv\conti_readme.txt
  • %ProgramFiles%\bdnews\conti_readme.txt
  • %ProgramFiles%\bdmcon\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\help\conti_readme.txt
  • %ProgramFiles%\backweb-4476822\conti_readme.txt
  • %ProgramFiles%\b2\conti_readme.txt
  • %ProgramFiles%\avsynmgr\conti_readme.txt
  • %ProgramFiles%\avscan\conti_readme.txt
  • %ProgramFiles%\avpm\conti_readme.txt
  • %ProgramFiles%\avpcc\conti_readme.txt
  • %ProgramFiles%\avnotify\conti_readme.txt
  • %ProgramFiles%\cavq\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\conti_readme.txt
  • %ProgramFiles%\cavscons\conti_readme.txt
  • %ProgramFiles%\clamtray\conti_readme.txt
  • %CommonProgramFiles%\conti_readme.txt
  • %ProgramFiles%\cleaner\conti_readme.txt
  • %ProgramFiles%\cleaner3\conti_readme.txt
  • %ProgramFiles%\clisvc\conti_readme.txt
  • %ProgramFiles%\clrcche\conti_readme.txt
  • %ProgramFiles%\cmain\conti_readme.txt
  • %ProgramFiles%\cmgrdian\conti_readme.txt
  • %CommonProgramFiles%\designer\conti_readme.txt
  • %ProgramFiles%\cavoar\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\dw\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\equation\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\equation\1033\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\euro\conti_readme.txt
  • %CommonProgramFiles%\microsoft shared\filters\conti_readme.txt
  • %ProgramFiles%\claw95cf\conti_readme.txt
  • %ProgramFiles%\claw95\conti_readme.txt
  • %ProgramFiles%\clamscan\conti_readme.txt
  • %ProgramFiles%\chrome\conti_readme.txt
  • %ProgramFiles%\cemrep\conti_readme.txt
  • %ProgramFiles%\ccsetmgr\conti_readme.txt
  • %ProgramFiles%\ccproxy\conti_readme.txt
  • %ProgramFiles%\ccevtmgr\conti_readme.txt
  • %ProgramFiles%\cavsn\conti_readme.txt
  • %ProgramFiles%\cavse\conti_readme.txt
  • %ProgramFiles%\cavvl\conti_readme.txt
  • %ProgramFiles%\cavuserupd\conti_readme.txt
  • %ProgramFiles%\cavumas\conti_readme.txt
  • %ProgramFiles%\cavsubmit\conti_readme.txt
  • %ProgramFiles%\cavsub\conti_readme.txt
  • %ProgramFiles%\clamwin\conti_readme.txt
  • %ProgramFiles%\ccapp\conti_readme.txt
  • %ProgramFiles%\firefox\chrome\toolkit\skin\classic\aero\global\icons\conti_readme.txt
Изменяет множество файлов пользовательских данных (Trojan.Encoder).
Изменяет расширения файлов пользовательских данных (Trojan.Encoder).
Сетевая активность
UDP
  • '<LOCALNET>.53.1':0
  • '<LOCALNET>.53.255':0
Другое
Создает и запускает на исполнение
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=c: /on=c: /maxsize=401MB' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=c: /on=c: /maxsize=unbounded' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=d: /on=d: /maxsize=401MB' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=d: /on=d: /maxsize=unbounded' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=e: /on=e: /maxsize=401MB' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=e: /on=e: /maxsize=unbounded' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=f: /on=f: /maxsize=401MB' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=f: /on=f: /maxsize=unbounded' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=g: /on=g: /maxsize=401MB' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=g: /on=g: /maxsize=unbounded' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=h: /on=h: /maxsize=401MB' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=h: /on=h: /maxsize=unbounded' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /all /quiet' (со скрытым окном)
Запускает на исполнение
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=c: /on=c: /maxsize=401MB
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=h: /on=h: /maxsize=unbounded
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=h: /on=h: /maxsize=401MB
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=h: /on=h: /maxsize=401MB
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=g: /on=g: /maxsize=unbounded
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=g: /on=g: /maxsize=unbounded
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=g: /on=g: /maxsize=401MB
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=g: /on=g: /maxsize=401MB
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=f: /on=f: /maxsize=unbounded
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=f: /on=f: /maxsize=unbounded
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=f: /on=f: /maxsize=401MB
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=f: /on=f: /maxsize=401MB
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=e: /on=e: /maxsize=unbounded
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=e: /on=e: /maxsize=unbounded
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=e: /on=e: /maxsize=401MB
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=e: /on=e: /maxsize=401MB
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=d: /on=d: /maxsize=unbounded
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=d: /on=d: /maxsize=unbounded
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=d: /on=d: /maxsize=401MB
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=d: /on=d: /maxsize=401MB
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=c: /on=c: /maxsize=unbounded
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=c: /on=c: /maxsize=unbounded
  • '<SYSTEM32>\vssvc.exe'
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=c: /on=c: /maxsize=401MB
  • '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=h: /on=h: /maxsize=unbounded
  • '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /all /quiet

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке