Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.40857

Добавлен в вирусную базу Dr.Web: 2024-08-16

Описание добавлено:

Техническая информация

Изменения в файловой системе
Создает следующие файлы
  • C:\$recycle.bin\s-1-5-21-3150914307-1777937420-491476919-1000\desktop.ini.raz
  • %CommonProgramFiles%\microsoft shared\translat\frar\readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\esen\readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\enfr\readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\enes\readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\arfr\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\watermar\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\watermar\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\water\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\water\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\sumipntg\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\sumipntg\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\rmnsque\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\studio\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\strtedge\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\strtedge\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\spring\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\spring\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\sonora\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\sonora\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\slate\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\slate\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\sky\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\sky\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\satin\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\satin\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\studio\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\rmnsque\readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\fren\readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\1033\fpext.msg.raz
  • %CommonProgramFiles%\system\msadc\readme.txt
  • %CommonProgramFiles%\system\msadc\en-us\readme.txt
  • %CommonProgramFiles%\system\en-us\readme.txt
  • %CommonProgramFiles%\system\ado\readme.txt
  • %CommonProgramFiles%\system\ado\en-us\readme.txt
  • %CommonProgramFiles%\speechengines\readme.txt
  • %CommonProgramFiles%\speechengines\microsoft\readme.txt
  • %CommonProgramFiles%\services\readme.txt
  • %CommonProgramFiles%\microsoft shared\readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\readme.txt
  • %CommonProgramFiles%\microsoft shared\triedit\en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\translat\readme.txt
  • %CommonProgramFiles%\microsoft shared\web folders\readme.txt
  • %CommonProgramFiles%\microsoft shared\web folders\1033\readme.txt
  • %CommonProgramFiles%\microsoft shared\vsto\readme.txt
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\readme.txt
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\vstoinstaller.exe.raz
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\1033\readme.txt
  • %CommonProgramFiles%\microsoft shared\vgx\readme.txt
  • %CommonProgramFiles%\microsoft shared\vc\readme.txt
  • %CommonProgramFiles%\microsoft shared\vba\readme.txt
  • %CommonProgramFiles%\microsoft shared\vba\vba7\readme.txt
  • %CommonProgramFiles%\microsoft shared\vba\vba7\1033\readme.txt
  • %CommonProgramFiles%\microsoft shared\triedit\readme.txt
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\1033\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\ripple\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\ripple\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\ricepapr\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\edge\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\eclipse\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\eclipse\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\echo\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\echo\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\deepblue\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\deepblue\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\concrete\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\concrete\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\compass\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\compass\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\evrgreen\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\cascade\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\capsules\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\capsules\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\canyon\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\canyon\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\breeze\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\breeze\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\boldstri\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\boldstri\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\blueprnt\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\blueprnt\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\bluecalm\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\bluecalm\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\cascade\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\evrgreen\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\edge\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\expeditn\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\ricepapr\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\network\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\refined\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\refined\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\radial\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\radial\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\quad\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\quad\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\profile\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\profile\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\pixel\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\pixel\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\papyrus\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\papyrus\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\network\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\expeditn\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\level\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\level\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\layers\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\layers\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\journal\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\journal\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\iris\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\iris\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\indust\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\indust\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\ice\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\ice\preview.gif.raz
  • %CommonProgramFiles%\system\msmapi\1033\readme.txt
  • %CommonProgramFiles%\system\ole db\en-us\readme.txt
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00164_.gif.raz
  • %CommonProgramFiles%\system\ole db\readme.txt
  • %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\readme.txt
  • %ProgramFiles%\java\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme.txt.raz
  • %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt.raz
  • %ProgramFiles%\java\jre1.8.0_45\readme.txt.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\security\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\management\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\jvm.hprof.txt.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\jfr\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\amd64\jvm.cfg.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_movenodrop32x32.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_linknodrop32x32.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_linkdrop32x32.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_copynodrop32x32.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_copydrop32x32.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\invalid32x32.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\fonts\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\ext\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\deploy\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\deploy\splash@2x.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\deploy\splash.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\cmm\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\applet\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_movedrop32x32.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\lib\amd64\readme.txt
  • %ProgramFiles%\microsoft analysis services\as oledb\10\resources\1033\readme.txt
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00103_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00163_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00161_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00160_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00158_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00157_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00154_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00142_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00139_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00135_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00130_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00129_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00126_.gif.raz
  • %ProgramFiles%\microsoft analysis services\as oledb\10\readme.txt
  • %ProgramFiles%\microsoft analysis services\as oledb\10\resources\readme.txt
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00092_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00090_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00057_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00052_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00040_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00038_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00037_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00021_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00011_.gif.raz
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00004_.gif.raz
  • %ProgramFiles%\microsoft analysis services\readme.txt
  • %ProgramFiles%\microsoft analysis services\as oledb\readme.txt
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00120_.gif.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\bin\unpack200.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\tnameserv.exe.raz
  • %ProgramFiles%\dvd maker\shared\dvdstyles\vignette\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\videowall\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\travel\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\stacking\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\sports\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\specialoccasion\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\shatter\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\resizingpanels\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\rectangles\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\push\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\pets\readme.txt
  • %ProgramFiles%\dvd maker\shared\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\performance\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\memories\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\layeredtitles\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\huecycle\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\full\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\flippage\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\babygirl\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\babyboy\readme.txt
  • %ProgramFiles%\dvd maker\en-us\readme.txt
  • %ProgramFiles%\dvd maker\dvdmaker.exe.raz
  • %ProgramFiles%\desktop.ini.raz
  • %CommonProgramFiles%\readme.txt
  • %CommonProgramFiles%\system\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\oldage\readme.txt
  • %ProgramFiles%\dvd maker\readme.txt
  • %ProgramFiles%\dvd maker\shared\dvdstyles\readme.txt
  • %ProgramFiles%\internet explorer\en-us\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\bin\ssvagent.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\keytool.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\servertool.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\server\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\bin\server\xusage.txt.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\rmiregistry.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\rmid.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\policytool.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\plugin2\readme.txt
  • %ProgramFiles%\java\jre1.8.0_45\bin\pack200.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\orbd.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\ktab.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\klist.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\kinit.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\jp2launcher.exe.raz
  • %ProgramFiles%\internet explorer\ieinstal.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\jjs.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\javaws.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\java.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\java-rmi.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\jabswitch.exe.raz
  • %ProgramFiles%\java\jre1.8.0_45\bin\dtplugin\readme.txt
  • %ProgramFiles%\internet explorer\readme.txt
  • %ProgramFiles%\internet explorer\signup\readme.txt
  • %ProgramFiles%\internet explorer\iexplore.exe.raz
  • %ProgramFiles%\internet explorer\ielowutil.exe.raz
  • %CommonProgramFiles%\microsoft shared\themes14\blends\readme.txt
  • %CommonProgramFiles%\system\msmapi\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\blends\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\base_heb.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\cs-cz\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\convertinkstore.exe.raz
  • %CommonProgramFiles%\microsoft shared\ink\content.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\bg-bg\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ar-sa\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\alphabet.xml.raz
  • %CommonProgramFiles%\microsoft shared\help\readme.txt
  • %CommonProgramFiles%\microsoft shared\grphflt\readme.txt
  • %CommonProgramFiles%\microsoft shared\grphflt\ms.png.raz
  • %CommonProgramFiles%\microsoft shared\grphflt\ms.jpg.raz
  • %CommonProgramFiles%\microsoft shared\grphflt\ms.gif.raz
  • %CommonProgramFiles%\microsoft shared\grphflt\cgmimp32.cfg.raz
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\accessmuiset.xml.raz
  • %CommonProgramFiles%\microsoft shared\filters\readme.txt
  • %CommonProgramFiles%\microsoft shared\equation\readme.txt
  • %CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe.raz
  • %CommonProgramFiles%\microsoft shared\equation\1033\readme.txt
  • %CommonProgramFiles%\microsoft shared\dw\readme.txt
  • %CommonProgramFiles%\microsoft shared\dw\dwtrig20.exe.raz
  • %CommonProgramFiles%\microsoft shared\dw\dw20.exe.raz
  • %CommonProgramFiles%\designer\readme.txt
  • C:\perflogs\readme.txt
  • C:\perflogs\admin\readme.txt
  • C:\msocache\readme.txt
  • C:\msocache\all users\readme.txt
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\readme.txt
  • %CommonProgramFiles%\microsoft shared\euro\readme.txt
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\da-dk\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\flickanimation.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\base_altgr.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\basealtgr_rtl.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\base.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\keypad.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\keypad\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\keypad\ea.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\auxpad.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\auxpad\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fr-fr\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\el-gr\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\de-de\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fi-fi\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\et-ee\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\es-es\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\en-us\split.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\en-us\join.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\en-us\delete.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\en-us\correct.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\en-us\boxed-split.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\en-us\boxed-join.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\en-us\boxed-delete.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\en-us\boxed-correct.avi.raz
  • %CommonProgramFiles%\microsoft shared\ink\flicklearningwizard.exe.raz
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\readme.txt
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\branding.xml.raz
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\accessmui.xml.raz
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\outlookmui.xml.raz
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\publishermui.xml.raz
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\powerpointmui.xml.raz
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\wordmui.xml.raz
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excelmui.xml.raz
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe.raz
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\proplusww.xml.raz
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\ose.exe.raz
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.xml.raz
  • C:\kms\readme.txt
  • C:\kms\kms_vl_all_aio_debug.log.raz
  • C:\kms\kms_vl_all_aio.cmd.raz
  • <Текущая директория>\readme.txt
  • <Полный путь к файлу>.raz
  • C:\$recycle.bin\readme.txt
  • C:\$recycle.bin\s-1-5-21-3150914307-1777937420-491476919-1000\readme.txt
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\proof.xml.raz
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\onenotemui.xml.raz
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\officemuiset.xml.raz
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\officemui.xml.raz
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dwtrig20.exe.raz
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe.raz
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\branding.xml.raz
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\1033\readme.txt
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\groovemui.xml.raz
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\readme.txt
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\infopathmui.xml.raz
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\office32mui.xml.raz
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\setup.xml.raz
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proofing.xml.raz
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\proof.xml.raz
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\proof.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\base_ca.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\base_jpn.xml.raz
  • %CommonProgramFiles%\microsoft shared\themes14\axis\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\base_kor.xml.raz
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\publisher.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proplus\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proofing.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.fr\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.es\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.en\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\powerpoint.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\outlook.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\onenote.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office32.ww\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office32.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\msclientdatamgr\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\odeploy.exe.raz
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\groove.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\excel.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\access.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\oarpmany.exe.raz
  • %CommonProgramFiles%\microsoft shared\office14\msoxmled.exe.raz
  • %CommonProgramFiles%\microsoft shared\office14\msoicons.exe.raz
  • %CommonProgramFiles%\microsoft shared\office14\liclua.exe.raz
  • %CommonProgramFiles%\microsoft shared\office14\fltldr.exe.raz
  • %CommonProgramFiles%\microsoft shared\office14\cultures\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\1033\readme.txt
  • %CommonProgramFiles%\microsoft shared\msinfo\readme.txt
  • %CommonProgramFiles%\microsoft shared\msinfo\msinfo32.exe.raz
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\infopath.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\msinfo\en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\setup.exe.raz
  • %CommonProgramFiles%\microsoft shared\source engine\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\arctic\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\arctic\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\themes14\aftrnoon\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\aftrnoon\preview.gif.raz
  • %CommonProgramFiles%\microsoft shared\textconv\readme.txt
  • %CommonProgramFiles%\microsoft shared\textconv\en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\stationery\readme.txt
  • %CommonProgramFiles%\microsoft shared\stationery\wrinkled_paper.gif.raz
  • %CommonProgramFiles%\microsoft shared\stationery\tiki.gif.raz
  • %CommonProgramFiles%\microsoft shared\stationery\stucco.gif.raz
  • %CommonProgramFiles%\microsoft shared\stationery\desktop.ini.raz
  • %CommonProgramFiles%\microsoft shared\stationery\connectivity.gif.raz
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\readme.txt
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\word.en-us\readme.txt
  • %CommonProgramFiles%\microsoft shared\source engine\ose.exe.raz
  • %CommonProgramFiles%\microsoft shared\smart tag\readme.txt
  • %CommonProgramFiles%\microsoft shared\smart tag\smarttaginstall.exe.raz
  • %CommonProgramFiles%\microsoft shared\smart tag\metconv.txt.raz
  • %CommonProgramFiles%\microsoft shared\smart tag\lists\readme.txt
  • %CommonProgramFiles%\microsoft shared\smart tag\lists\1033\readme.txt
  • %CommonProgramFiles%\microsoft shared\smart tag\1033\readme.txt
  • %CommonProgramFiles%\microsoft shared\proof\readme.txt
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\readme.txt
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe.raz
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\ospprearm.exe.raz
  • %CommonProgramFiles%\microsoft shared\office14\readme.txt
  • %CommonProgramFiles%\microsoft shared\stationery\cave_drawings.gif.raz
  • %CommonProgramFiles%\microsoft shared\ink\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\zh-tw\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\zh-cn\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\symbols.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\symbols\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\symbols\symbase.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\symbols\ja-jp-sym.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\symbols\ea-sym.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskpred.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskpred\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskpred\oskpredbase.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\osknumpad.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\osknumpad\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\osknumpad\osknumpadbase.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\web\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskmenu.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskmenu\oskmenubase.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\numbers.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\numbers\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\numbers\numbase.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\zh-phonetic.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\zh-dayi.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\zh-changjei.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\ko-kr.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\ja-jp.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\base_rtl.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskmenu\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\web.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\web\webbase.xml.raz
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\uk-ua\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\pl-pl\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\tr-tr\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\th-th\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\tabtip.exe.raz
  • %CommonProgramFiles%\microsoft shared\ink\sv-se\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\sr-latn-cs\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\sl-si\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\sk-sk\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\shapecollector.exe.raz
  • %CommonProgramFiles%\microsoft shared\ink\ru-ru\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ro-ro\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\pt-pt\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\pt-br\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\nl-nl\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\he-il\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\nb-no\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\mip.exe.raz
  • %CommonProgramFiles%\microsoft shared\ink\lv-lv\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\lt-lt\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ko-kr\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\ja-jp\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\it-it\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\inputpersonalization.exe.raz
  • %CommonProgramFiles%\microsoft shared\ink\inkwatson.exe.raz
  • %CommonProgramFiles%\microsoft shared\ink\hwrcustomization\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\hu-hu\readme.txt
  • %CommonProgramFiles%\microsoft shared\ink\hr-hr\readme.txt
  • %CommonProgramFiles%\microsoft shared\themes14\axis\readme.txt
  • %ProgramFiles%\microsoft office\clipart\pub60cor\ag00165_.gif.raz
Подменяет следующие файлы
  • %ProgramFiles%\Java\jre1.8.0_45\README.txt
Самоудаляется.
Изменяет расширения файлов пользовательских данных (Trojan.Encoder).
Сетевая активность
Подключается к
  • 'xm#.###honanywhere.com':443
TCP
Другие
  • 'xm#.###honanywhere.com':443
UDP
  • DNS ASK xm#.###honanywhere.com

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке