Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.38987

Добавлен в вирусную базу Dr.Web: 2024-05-30

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Создает или изменяет следующие файлы
  • <SYSTEM32>\tasks\windows update
  • <SYSTEM32>\tasks\microsoftedge update
Вредоносные функции
Для затруднения выявления своего присутствия в системе
блокирует запуск следующих системных утилит:
  • Системный антивирус (Защитник Windows)
изменяет следующие системные настройки:
  • [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'DisallowRun' = '00000001'
Читает файлы, отвечающие за хранение паролей сторонними программами
  • %HOMEPATH%\desktop\508softwareandos.doc
  • %HOMEPATH%\desktop\archer.avi
  • %HOMEPATH%\desktop\cveuropeo.doc
  • %HOMEPATH%\desktop\february_catalogue__2015.doc
  • %HOMEPATH%\desktop\dashborder_120.bmp
  • %HOMEPATH%\desktop\lisp_success.doc
  • %HOMEPATH%\desktop\toolbar.bmp
  • %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
  • %HOMEPATH%\desktop\nwfieldnotes1966.docx
Изменения в файловой системе
Создает следующие файлы
  • %TEMP%\tmpe58.tmp
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\if1tr5hi.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\images\darktheme\qazsmr03.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\xwfejdgc.s0s
  • %APPDATA%\mozilla\firefox\profiles\jkail15y.default\n01aywgp.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\kxmf0t55.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\images\darktheme\oc5pgfse.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\d44aqt0c.s0s
  • %APPDATA%\microsoft\windows\themes\cachedfiles\snb2jrk2.s0s
  • %LOCALAPPDATA%\packages\microsoft.oneconnect_8wekyb3d8bbwe\localstate\diagoutputdir\lr0d4eds.s0s
  • %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\nggbgn0h.s0s
  • %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\zgfhvlgi.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\vxya1vob.s0s
  • %LOCALAPPDATA%\packages\microsoft.oneconnect_8wekyb3d8bbwe\localstate\diagoutputdir\hgwc30c3.s0s
  • %APPDATA%\microsoft\windows\start menu\programs\pujtndt4.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\j5yksxuk.s0s
  • %LOCALAPPDATA%\packages\microsoft.oneconnect_8wekyb3d8bbwe\localstate\diagoutputdir\21k5llje.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\p5mqihrc.s0s
  • %LOCALAPPDATA%\packages\microsoft.oneconnect_8wekyb3d8bbwe\localstate\diagoutputdir\21vzr3rd.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\jt3mhhti.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\a1jgtsfx.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\hq4xpayr.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group2\pwpyphgx.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\images\darktheme\uz3b0xsh.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\lz1wpxjw.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\1rpg1ro2.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\idplez3r.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\4wiggl02.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\2ul4bmyq.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\2llriqch.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\tvifqooj.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ez21xxem.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\x5sl1jqp.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\3hcblges.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\rnyzydw1.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\30qdqtjm.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\yqubzmqj.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\gigdi5qz.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\eoj5sssg.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\qh1og3rl.s0s
  • %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\5woitwz1.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\images\darktheme\pw2f1ok2.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\evre1ltb.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\5feeu1wg.s0s
  • %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\f1zcks3r.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\yhza1sfw.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\jpduqfrf.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\1ze2pn3r.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\h0h1x2o3.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\lpvuj0qv.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\v3qjqiks.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\nmsang3s.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group2\atypk0vo.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\3lbmfttc.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group1\bnaax5nm.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\cbd4kzkh.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\4v3gaoja.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\ne0ttbqc.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\logoimages\crlrcogr.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\sevexyyf.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\2agmqinx.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\y0ewn0w1.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\logoimages\rrdoniyz.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\cx1l0hog.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\xdl2rrty.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\gyqnmpr5.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\logoimages\52ynupx4.s0s
  • %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\sgwgg0rd.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\logoimages\a0cebuss.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\y3ngih3l.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\5wthy1tb.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\yuy35m4u.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\imqcvygh.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\wyg3otz2.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group2\g5ljs2jb.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\p3aquosg.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\cj3krjfp.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\mn3yty3r.s0s
  • %LOCALAPPDATA%\packages\microsoft.oneconnect_8wekyb3d8bbwe\localstate\diagoutputdir\ery202vg.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\jocppxhz.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\baw125ms.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\5tjntcmg.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\5tqkmfpt.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\j2ockqfm.s0s
  • %LOCALAPPDATA%\packages\microsoft.oneconnect_8wekyb3d8bbwe\localstate\diagoutputdir\2dotsa2d.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\bboxjkkj.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\4oy2wa2d.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\i2v5qgt4.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\dij42l3y.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\mtsj4qpw.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\uerpy1fm.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group2\abysdjqq.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group2\avrgq3rc.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\nlh3qumg.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\btzwraon.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\fx0mf0s2.s0s
  • %LOCALAPPDATA%\microsoft\windows\winx\group3\gwnvbkk2.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\lhph2zii.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\54p5mrqu.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\a4g2034t.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\zwdh2yys.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\411pwt1m.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\0cjwwed1.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\mecy2dsb.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\xjnahw3f.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\nyyycx0i.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\o5xzt0pa.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\sg4g1twk.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\wjp0ppl2.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\s151atdp.s0s
  • %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\installer\eg1fnwti.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\nvys2nk4.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\vmvgr50q.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\qdx0d042.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\coucy3fv.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\eg2vknra.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\zymt2qgn.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\jqp55gzq.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\h5utu0ia.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\4bgprxlf.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\kffv10lz.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\mqoatagq.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\j0rmkqfg.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\c3v4yr4z.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\ilka04cq.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\zsdwniv4.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\xr3kxklt.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\spsntbwr.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\n43vrcf4.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\ljyq5nwz.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\a2t2g5tc.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\tly40ipy.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\d2wcvwbi.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\cm3gonzk.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\gwrfmfek.s0s
  • %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\visualelements\jamvkges.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\v34gimge.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\1aejt2lz.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\350fnvjd.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\iidyecmf.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\lyk4euba.s0s
  • %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\visualelements\o13bbvhk.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\ubzqfzql.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\0xnwju3b.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\iusxw1iw.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\h4hyydhz.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\3toyxhwa.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\41cihnv5.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\z5yev5fz.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\r5mnfqjd.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\c3lsbibx.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\axsrfvrk.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\slicrehi.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\flhx5dya.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\nuy2ikso.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\qpxlau10.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\exw0lkbj.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\otkm5tkd.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\5ni0gsfy.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\5xlxiyxk.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\45armu2z.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\o2hw1pzy.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\1qpomnht.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\uee1l1u0.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\kvxu0tvp.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\elbnryek.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\tdhfxavs.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\0w5czui2.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\0tsrxawm.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\bi2mao4i.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\iia02hz3.s0s
  • %APPDATA%\opera software\opera stable\themes_backup\exyckpss.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ly11afr4.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\lbpn2tvm.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\oa5d0f0s.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\5004jkny.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\vacz1knd.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\fsasiimw.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\hpdbwvzy.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\2kyznf1j.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\c0xti3wj.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\u03ejjje.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\jgf0gp3w.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\4s3sci0l.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\upofjfmr.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\h4wdbau5.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\iztk1ui0.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\gc00ssc3.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\4ugn0xth.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\c3e20bhp.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\0ywzonpk.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\5xircijk.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\av4wdlt0.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\fwba50jx.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\puxqkbm2.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\ax1hgyhr.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\media\0ijchpin.s0s
  • %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\uhojzmev.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\i0i1xwye.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\pckwlm5o.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\1q2qmqrs.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\4bdsewqj.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\lzzpdxbn.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\c0lz3x2f.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\lqjvhicy.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\xlem30bd.s0s
  • %TEMP%\3h5i5jqu.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\grbt0zqq.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\ipwnwau3.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\d3r13015.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\btc3brn2.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\iqkvukxw.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\kmy3gqjg.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\h35anmvp.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\qdzgy5c0.s0s
  • %LOCALAPPDATA%\microsoft\internet explorer\iecompatdata\cyueat1y.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\llfibqva.s0s
  • %TEMP%\v2aja0ky.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\s15vr1zn.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\imvakqzy.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\30oif43q.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\f5qyo5rp.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ffupod04.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\yxveyh2q.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\hhvvlz0f.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\aiyezmyl.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\d20cshvd.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\hp5xy0qt.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\qx5gqcjs.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\2qrd2dvx.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\fpdqlzpi.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\fozbtxja.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\0wv4hck3.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\feghzlwv.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\hlwdfusd.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\lj000jb0.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\azvlsdv1.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\oedfvwa1.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\zycr1tbm.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\1vj30x1n.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\yiy1o4ik.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\ra5pxdnl.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\xju1itv3.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\te1ocsya.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\4vhmqzn1.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\a5l1g32h.s0s
  • %LOCALAPPDATA%\google\chrome\application\uf0fax0l.s0s
  • %TEMP%\1vtot3dk.s0s
  • %HOMEPATH%\desktop\1clvanc3.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\u5jjegtl.s0s
  • %HOMEPATH%\desktop\lqlov30d.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\bl4e2pgo.s0s
  • %HOMEPATH%\desktop\yjthxain.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\twvuzzob.s0s
  • %HOMEPATH%\desktop\rrdliykz.s0s
  • %HOMEPATH%\desktop\0f0ulkiq.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\clvy533c.s0s
  • %HOMEPATH%\desktop\4nba0y2k.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\0l0jbqzm.s0s
  • %HOMEPATH%\desktop\5irdc5jw.s0s
  • %HOMEPATH%\desktop\ansqqedk.s0s
  • %HOMEPATH%\desktop\ahyfysam.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\342d4bqw.s0s
  • %HOMEPATH%\desktop\d2iq43qn.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\jek0syhh.s0s
  • %HOMEPATH%\desktop\khs5gp2d.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\vlgxl1xq.s0s
  • %HOMEPATH%\desktop\uvgdk3nx.s0s
  • %WINDIR%\syswow64\<Имя файла>.exe
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\mbgg04i5.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\mjid2c4v.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\cyfuyeyp.s0s
  • %HOMEPATH%\links\3z4tamer.s0s
  • %HOMEPATH%\links\x2nzrmkm.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\axyr1y23.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\gw1tm1bw.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\otc50zgq.s0s
  • %TEMP%\55np42v3.s0s
  • %LOCALAPPDATA%\microsoft\internet explorer\mz2ltcgu.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\hkp2vnn1.s0s
  • %TEMP%\1hzvge5c.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\lzp3ml3v.s0s
  • %TEMP%\ip14d1xr.s0s
  • %TEMP%\zpqdj2iv.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\omcurrfv.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\isupzi2m.s0s
  • %TEMP%\reb1cgwc.s0s
  • %TEMP%\twoguyag.s0s
  • %TEMP%\rjeiafu2.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\5vxc3iez.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\z5kdnjd4.s0s
  • %TEMP%\suzzaes2.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ew4nniek.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\rzjuk13v.s0s
  • %TEMP%\c4j3ogpi.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\jqpzia44.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\1vtcjqot.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\2mrlonui.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\dvjvyrl3.s0s
  • %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\localstate\yhmc0i0z.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\j23jgqpu.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\103izvjk.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\h3d5olhy.s0s
  • %LOCALAPPDATA%\microsoft\windows\shell\fklegrkt.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ndabw2sw.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\dhvtqolj.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\zzw4vco5.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ey4gev32.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\tgfz0ild.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\i2ih12fk.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\5zgk5gje.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\t2ww5hsg.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\ns13gyn1.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\q4xjlzfh.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\j3kqdiuh.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ccy1otkj.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\rq5w513m.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\ewrodiij.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\dztffuyj.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\kmihn2zd.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ovspl1mi.s0s
  • %APPDATA%\opera software\opera stable\dictionaries\fls1ldde.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\trojxdwy.s0s
  • %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\afrrwc2z.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\oibrs5mr.s0s
  • %APPDATA%\microsoft\windows\sendto\df2t5w1d.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\y4pur1iw.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\qnqr0bsm.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ez5slyyt.s0s
  • %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\52ofs1kw.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\vlwlu0lu.s0s
  • %APPDATA%\microsoft\internet explorer\quick launch\rvzyexzt.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\jpf3k0ww.s0s
  • %APPDATA%\microsoft\internet explorer\quick launch\n3rlb1j2.s0s
  • %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\lcvkvs1g.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\34025dxl.s0s
  • %APPDATA%\microsoft\internet explorer\quick launch\ri5c4er4.s0s
  • %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\ksji4xst.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ouylv1u0.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\dftvbil0.s0s
  • %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\localstate\ltdatm0d.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\pwe1bksk.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\smz5zkqh.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\xutzr0uw.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\dqm4exed.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\b0hsmf22.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\0wmaauup.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\miogskaw.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\1z1h1w5w.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\4hyb3myi.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\wut4n141.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\oqgqpust.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\p5gr5v3y.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\s3omglhy.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\smrihzev.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\f43vp43r.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\4t3mgo34.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\qcchebne.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\kzxyuiu3.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\zqvuuoiy.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\xgdl2qaa.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\4oepzsvy.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\kj3co0w4.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\zoh5v01x.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\arfkiyww.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\mfiug243.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\y44l22mb.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ujl5up1l.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\gognbhq4.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\cygd5pt3.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\strha1mv.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\eilqfggx.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\yopzbnqk.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\tyk54v4m.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\1wycgjxr.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\1tttscmk.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\jyukeg1x.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\p5qa5w4n.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\kumlo4e0.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\ueape1jk.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\hshipsiw.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\213xyyub.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\32nw02k1.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\5x2ztz53.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\io2d2wq5.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\vsxsqrob.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\qnmiksb5.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\gjwrwnhk.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\bo4slneq.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\dwuoppec.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\230c3nq3.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\gghpwvnu.s0s
  • %ProgramFiles(x86)%\microsoft office\office16\logoimages\0rd5gaze.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\logoimages\1ocqbw23.s0s
  • %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\ptma1ucj.s0s
Изменяет следующие файлы
  • %APPDATA%\microsoft\windows\themes\transcodedwallpaper
  • %APPDATA%\microsoft\windows\themes\cachedfiles\cachedimage_1152_864_pos2.jpg
  • %LOCALAPPDATA%\microsoft\windows\explorer\thumbcache_idx.db
Сетевая активность
Подключается к
  • 'ra#.####ubusercontent.com':443
TCP
Другие
  • 'ra#.####ubusercontent.com':443
UDP
  • DNS ASK ra#.####ubusercontent.com
Другое
Ищет следующие окна
  • ClassName: 'OleMainThreadWndClass' WindowName: ''
Запускает на исполнение
  • '%WINDIR%\syswow64\schtasks.exe' /create /tn "Windows Update" /tr "%WINDIR%\SysWOW64\Eleven.exe" /sc MINUTE /mo 1 /ru SYSTEM /f /rl HIGHEST (со скрытым окном)
  • '%WINDIR%\syswow64\schtasks.exe' /create /tn "MicrosoftEdge Update" /tr "<SYSTEM32>\Eleven.exe" /sc MINUTE /mo 15 /ru SYSTEM /f /rl HIGHEST (со скрытым окном)
  • '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Get-MpPreference -verbose

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке