Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop36.12459

Добавлен в вирусную базу Dr.Web: 2026-03-11

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Создает или изменяет следующие файлы
  • %WINDIR%\tasks\desktop.ini
Вредоносные функции
Запускает большое число процессов
Изменения в файловой системе
Создает следующие файлы
  • C:\documents and settings\desktop.ini
  • <Текущая директория>\desktop.ini
  • C:\kms\desktop.ini
  • C:\msocache\desktop.ini
  • C:\msocache\all users\desktop.ini
  • C:\perflogs\desktop.ini
  • %CommonProgramFiles%\desktop.ini
  • %ProgramFiles%\internet explorer\desktop.ini
  • %ProgramFiles%\java\desktop.ini
  • %ProgramFiles%\microsoft office\desktop.ini
  • %ProgramFiles%\modifiablewindowsapps\desktop.ini
  • %ProgramFiles%\mozilla firefox\desktop.ini
  • %ProgramFiles%\mozilla thunderbird\desktop.ini
  • %ProgramFiles%\uninstall information\desktop.ini
  • %ProgramFiles%\windows defender advanced threat protection\desktop.ini
  • %ProgramFiles%\windows defender.bak\desktop.ini
  • %ProgramFiles%\windows mail\desktop.ini
  • %ProgramFiles%\windows media player\desktop.ini
  • %ProgramFiles%\windows multimedia platform\desktop.ini
  • %ProgramFiles%\windows nt\desktop.ini
  • %ProgramFiles%\windows photo viewer\desktop.ini
  • %ProgramFiles%\windows portable devices\desktop.ini
  • %ProgramFiles%\windows security\desktop.ini
  • %ProgramFiles%\windows sidebar\desktop.ini
  • %ProgramFiles%\windowsapps\desktop.ini
  • %ProgramFiles%\windowspowershell\desktop.ini
  • %ProgramFiles%\winrar\desktop.ini
  • %ProgramFiles(x86)%\adobe\desktop.ini
  • %CommonProgramFiles(x86)%\desktop.ini
  • %ProgramFiles(x86)%\internet explorer\desktop.ini
  • %ProgramFiles(x86)%\microsoft\desktop.ini
  • %ProgramFiles(x86)%\microsoft analysis services\desktop.ini
  • %ProgramFiles(x86)%\microsoft office\desktop.ini
  • %ProgramFiles(x86)%\microsoft sql server\desktop.ini
  • %ProgramFiles(x86)%\microsoft.net\desktop.ini
  • %ProgramFiles(x86)%\mozilla firefox\desktop.ini
  • %ProgramFiles(x86)%\opera\desktop.ini
  • %ProgramFiles(x86)%\steam\desktop.ini
  • %ProgramFiles(x86)%\windows defender.bak\desktop.ini
  • %ProgramFiles(x86)%\windows mail\desktop.ini
  • %ProgramFiles(x86)%\windows media player\desktop.ini
  • %ProgramFiles(x86)%\windows multimedia platform\desktop.ini
  • %ProgramFiles(x86)%\windows nt\desktop.ini
  • %ProgramFiles(x86)%\windows photo viewer\desktop.ini
  • %ProgramFiles(x86)%\windows portable devices\desktop.ini
  • %ProgramFiles(x86)%\windows sidebar\desktop.ini
  • %ProgramFiles(x86)%\windowspowershell\desktop.ini
  • %ALLUSERSPROFILE%\desktop.ini
  • %ALLUSERSPROFILE%\adobe\desktop.ini
  • %ALLUSERSPROFILE%\application data\desktop.ini
  • %ALLUSERSPROFILE%\desktop\desktop.ini
  • %ALLUSERSPROFILE%\documents\desktop.ini
  • %ALLUSERSPROFILE%\microsoft\desktop.ini
  • %ALLUSERSPROFILE%\microsoft help\desktop.ini
  • %ALLUSERSPROFILE%\mozilla\desktop.ini
  • %ALLUSERSPROFILE%\oracle\desktop.ini
  • %ALLUSERSPROFILE%\package cache\desktop.ini
  • %ALLUSERSPROFILE%\packages\desktop.ini
  • %ALLUSERSPROFILE%\regid.1991-06.com.microsoft\desktop.ini
  • %ALLUSERSPROFILE%\softwaredistribution\desktop.ini
  • %ALLUSERSPROFILE%\ssh\desktop.ini
  • %ALLUSERSPROFILE%\start menu\desktop.ini
  • %ALLUSERSPROFILE%\templates\desktop.ini
  • %ALLUSERSPROFILE%\usoprivate\desktop.ini
  • %ALLUSERSPROFILE%\usoshared\desktop.ini
  • %ALLUSERSPROFILE%\windowsholographicdevices\desktop.ini
  • C:\recovery\desktop.ini
  • C:\recovery\windowsre\desktop.ini
  • C:\system volume information\desktop.ini
  • C:\users\default\desktop.ini
  • C:\users\default user\desktop.ini
  • %HOMEPATH%\desktop.ini
  • %WINDIR%\desktop.ini
  • %WINDIR%\addins\desktop.ini
  • %WINDIR%\appcompat\desktop.ini
  • %WINDIR%\apppatch\desktop.ini
  • %WINDIR%\appreadiness\desktop.ini
  • %WINDIR%\assembly\desktop.ini
  • %WINDIR%\bcastdvr\desktop.ini
  • %WINDIR%\bitlockerdiscoveryvolumecontents\desktop.ini
  • %WINDIR%\branding\desktop.ini
  • %WINDIR%\cbstemp\desktop.ini
  • %WINDIR%\containers\desktop.ini
  • %WINDIR%\csc\desktop.ini
  • %WINDIR%\cursors\desktop.ini
  • %WINDIR%\debug\desktop.ini
  • %WINDIR%\diagtrack\desktop.ini
  • %WINDIR%\digitallocker\desktop.ini
  • %WINDIR%\elambkup\desktop.ini
  • %WINDIR%\en-us\desktop.ini
  • %WINDIR%\gamebarpresencewriter\desktop.ini
  • %WINDIR%\globalization\desktop.ini
  • %WINDIR%\help\desktop.ini
  • %WINDIR%\identitycrl\desktop.ini
  • %WINDIR%\ime\desktop.ini
  • %WINDIR%\immersivecontrolpanel\desktop.ini
  • %WINDIR%\inf\desktop.ini
  • %WINDIR%\inputmethod\desktop.ini
  • %WINDIR%\installer\desktop.ini
  • %WINDIR%\l2schemas\desktop.ini
  • %WINDIR%\livekernelreports\desktop.ini
  • %WINDIR%\logs\desktop.ini
  • %WINDIR%\microsoft.net\desktop.ini
  • %WINDIR%\migration\desktop.ini
  • %WINDIR%\modemlogs\desktop.ini
  • %WINDIR%\panther\desktop.ini
  • %WINDIR%\pchealth\desktop.ini
  • %WINDIR%\performance\desktop.ini
  • %WINDIR%\pla\desktop.ini
  • %WINDIR%\policydefinitions\desktop.ini
  • %WINDIR%\prefetch\desktop.ini
  • %WINDIR%\printdialog\desktop.ini
  • %WINDIR%\provisioning\desktop.ini
  • %WINDIR%\registration\desktop.ini
  • %WINDIR%\remotepackages\desktop.ini
  • %WINDIR%\resources\desktop.ini
  • %WINDIR%\schcache\desktop.ini
  • %WINDIR%\schemas\desktop.ini
  • %WINDIR%\security\desktop.ini
  • %WINDIR%\serviceprofiles\desktop.ini
  • %WINDIR%\servicestate\desktop.ini
  • %WINDIR%\setup\desktop.ini
  • %WINDIR%\shellcomponents\desktop.ini
  • %WINDIR%\shellexperiences\desktop.ini
  • %WINDIR%\shellnew\desktop.ini
  • %WINDIR%\skb\desktop.ini
  • %WINDIR%\softwaredistribution\desktop.ini
  • %WINDIR%\speech\desktop.ini
  • %WINDIR%\speech_onecore\desktop.ini
  • %WINDIR%\system\desktop.ini
  • <SYSTEM32>\desktop.ini
  • %WINDIR%\systemapps\desktop.ini
  • %WINDIR%\syswow64\desktop.ini
  • %WINDIR%\tapi\desktop.ini
  • %WINDIR%\temp\desktop.ini
  • %WINDIR%\tracing\desktop.ini
  • %WINDIR%\twain_32\desktop.ini
  • %WINDIR%\vss\desktop.ini
  • %WINDIR%\web\desktop.ini
Присваивает атрибут 'скрытый' для следующих файлов
  • <Текущая директория>\desktop.ini
  • C:\kms\desktop.ini
  • C:\msocache\desktop.ini
  • C:\msocache\all users\desktop.ini
  • C:\perflogs\desktop.ini
  • %CommonProgramFiles%\desktop.ini
  • %ProgramFiles%\internet explorer\desktop.ini
  • %ProgramFiles%\java\desktop.ini
  • %ProgramFiles%\microsoft office\desktop.ini
  • %ProgramFiles%\modifiablewindowsapps\desktop.ini
  • %ProgramFiles%\mozilla firefox\desktop.ini
  • %ProgramFiles%\mozilla thunderbird\desktop.ini
  • %ProgramFiles%\uninstall information\desktop.ini
  • %ProgramFiles%\windows defender advanced threat protection\desktop.ini
  • %ProgramFiles%\windows defender.bak\desktop.ini
  • %ProgramFiles%\windows mail\desktop.ini
  • %ProgramFiles%\windows media player\desktop.ini
  • %ProgramFiles%\windows multimedia platform\desktop.ini
  • %ProgramFiles%\windows nt\desktop.ini
  • %ProgramFiles%\windows photo viewer\desktop.ini
  • %ProgramFiles%\windows portable devices\desktop.ini
  • %ProgramFiles%\windows security\desktop.ini
  • %ProgramFiles%\windows sidebar\desktop.ini
  • %ProgramFiles%\windowsapps\desktop.ini
  • %ProgramFiles%\windowspowershell\desktop.ini
  • %ProgramFiles%\winrar\desktop.ini
  • %ProgramFiles(x86)%\adobe\desktop.ini
  • %CommonProgramFiles(x86)%\desktop.ini
  • %ProgramFiles(x86)%\internet explorer\desktop.ini
  • %ProgramFiles(x86)%\microsoft\desktop.ini
  • %ProgramFiles(x86)%\microsoft analysis services\desktop.ini
  • %ProgramFiles(x86)%\microsoft office\desktop.ini
  • %ProgramFiles(x86)%\microsoft sql server\desktop.ini
  • %ProgramFiles(x86)%\microsoft.net\desktop.ini
  • %ProgramFiles(x86)%\mozilla firefox\desktop.ini
  • %ProgramFiles(x86)%\opera\desktop.ini
  • %ProgramFiles(x86)%\steam\desktop.ini
  • %ProgramFiles(x86)%\windows defender.bak\desktop.ini
  • %ProgramFiles(x86)%\windows mail\desktop.ini
  • %ProgramFiles(x86)%\windows media player\desktop.ini
  • %ProgramFiles(x86)%\windows multimedia platform\desktop.ini
  • %ProgramFiles(x86)%\windows nt\desktop.ini
  • %ProgramFiles(x86)%\windows photo viewer\desktop.ini
  • %ProgramFiles(x86)%\windows portable devices\desktop.ini
  • %ProgramFiles(x86)%\windows sidebar\desktop.ini
  • %ProgramFiles(x86)%\windowspowershell\desktop.ini
  • %ALLUSERSPROFILE%\desktop.ini
  • %ALLUSERSPROFILE%\adobe\desktop.ini
  • %ALLUSERSPROFILE%\microsoft\desktop.ini
  • %ALLUSERSPROFILE%\microsoft help\desktop.ini
  • %ALLUSERSPROFILE%\mozilla\desktop.ini
  • %ALLUSERSPROFILE%\oracle\desktop.ini
  • %ALLUSERSPROFILE%\package cache\desktop.ini
  • %ALLUSERSPROFILE%\packages\desktop.ini
  • %ALLUSERSPROFILE%\regid.1991-06.com.microsoft\desktop.ini
  • %ALLUSERSPROFILE%\softwaredistribution\desktop.ini
  • %ALLUSERSPROFILE%\ssh\desktop.ini
  • %ALLUSERSPROFILE%\usoprivate\desktop.ini
  • %ALLUSERSPROFILE%\usoshared\desktop.ini
  • %ALLUSERSPROFILE%\windowsholographicdevices\desktop.ini
  • C:\recovery\desktop.ini
  • C:\recovery\windowsre\desktop.ini
  • C:\system volume information\desktop.ini
  • C:\users\default\desktop.ini
  • %HOMEPATH%\desktop.ini
  • %WINDIR%\desktop.ini
  • %WINDIR%\addins\desktop.ini
  • %WINDIR%\appcompat\desktop.ini
  • %WINDIR%\apppatch\desktop.ini
  • %WINDIR%\appreadiness\desktop.ini
  • %WINDIR%\assembly\desktop.ini
  • %WINDIR%\bcastdvr\desktop.ini
  • %WINDIR%\bitlockerdiscoveryvolumecontents\desktop.ini
  • %WINDIR%\branding\desktop.ini
  • %WINDIR%\cbstemp\desktop.ini
  • %WINDIR%\containers\desktop.ini
  • %WINDIR%\csc\desktop.ini
  • %WINDIR%\cursors\desktop.ini
  • %WINDIR%\debug\desktop.ini
  • %WINDIR%\diagtrack\desktop.ini
  • %WINDIR%\digitallocker\desktop.ini
  • %WINDIR%\elambkup\desktop.ini
  • %WINDIR%\en-us\desktop.ini
  • %WINDIR%\gamebarpresencewriter\desktop.ini
  • %WINDIR%\globalization\desktop.ini
  • %WINDIR%\help\desktop.ini
  • %WINDIR%\identitycrl\desktop.ini
  • %WINDIR%\ime\desktop.ini
  • %WINDIR%\immersivecontrolpanel\desktop.ini
  • %WINDIR%\inf\desktop.ini
  • %WINDIR%\inputmethod\desktop.ini
  • %WINDIR%\installer\desktop.ini
  • %WINDIR%\l2schemas\desktop.ini
  • %WINDIR%\livekernelreports\desktop.ini
  • %WINDIR%\logs\desktop.ini
  • %WINDIR%\microsoft.net\desktop.ini
  • %WINDIR%\migration\desktop.ini
  • %WINDIR%\modemlogs\desktop.ini
  • %WINDIR%\panther\desktop.ini
  • %WINDIR%\pchealth\desktop.ini
  • %WINDIR%\performance\desktop.ini
  • %WINDIR%\pla\desktop.ini
  • %WINDIR%\policydefinitions\desktop.ini
  • %WINDIR%\prefetch\desktop.ini
  • %WINDIR%\printdialog\desktop.ini
  • %WINDIR%\provisioning\desktop.ini
  • %WINDIR%\registration\desktop.ini
  • %WINDIR%\remotepackages\desktop.ini
  • %WINDIR%\resources\desktop.ini
  • %WINDIR%\schcache\desktop.ini
  • %WINDIR%\schemas\desktop.ini
  • %WINDIR%\security\desktop.ini
  • %WINDIR%\serviceprofiles\desktop.ini
  • %WINDIR%\servicestate\desktop.ini
  • %WINDIR%\setup\desktop.ini
  • %WINDIR%\shellcomponents\desktop.ini
  • %WINDIR%\shellexperiences\desktop.ini
  • %WINDIR%\shellnew\desktop.ini
  • %WINDIR%\skb\desktop.ini
  • %WINDIR%\softwaredistribution\desktop.ini
  • %WINDIR%\speech\desktop.ini
  • %WINDIR%\speech_onecore\desktop.ini
  • %WINDIR%\system\desktop.ini
  • <SYSTEM32>\desktop.ini
  • %WINDIR%\systemapps\desktop.ini
  • %WINDIR%\syswow64\desktop.ini
  • %WINDIR%\tapi\desktop.ini
  • %WINDIR%\tasks\desktop.ini
  • %WINDIR%\temp\desktop.ini
  • %WINDIR%\tracing\desktop.ini
  • %WINDIR%\twain_32\desktop.ini
  • %WINDIR%\vss\desktop.ini
  • %WINDIR%\web\desktop.ini
Изменяет следующие файлы
  • %ProgramFiles%\desktop.ini
  • %ProgramFiles(x86)%\desktop.ini
  • C:\users\desktop.ini
  • C:\users\public\desktop.ini
Другое
Запускает на исполнение
  • '<SYSTEM32>\cmd.exe'  (со скрытым окном)
  • '<SYSTEM32>\attrib.exe' +h +s "C:\Documents and Settings\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Documents and Settings"
  • '<SYSTEM32>\attrib.exe' +h +s "<Текущая директория>\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "<Текущая директория>"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\kms\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\kms"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\MSOCache\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\MSOCache"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\MSOCache\All Users\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\MSOCache\All Users"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\PerfLogs\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\PerfLogs"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Program Files"
  • '<SYSTEM32>\attrib.exe' +h +s "%CommonProgramFiles%\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%CommonProgramFiles%"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Internet Explorer\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Internet Explorer"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Java\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Java"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Microsoft Office\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Microsoft Office"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\ModifiableWindowsApps\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\ModifiableWindowsApps"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Mozilla Firefox\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Mozilla Firefox"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Mozilla Thunderbird\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Mozilla Thunderbird"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Uninstall Information\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Uninstall Information"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Defender Advanced Threat Protection\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Defender Advanced Threat Protection"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Defender.bak\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Defender.bak"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Mail\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Mail"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Media Player\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Media Player"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Multimedia Platform\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Multimedia Platform"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows NT\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows NT"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Photo Viewer\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Photo Viewer"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Portable Devices\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Portable Devices"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Security\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Security"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\Windows Sidebar\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\Windows Sidebar"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\WindowsApps\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\WindowsApps"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\WindowsPowerShell\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\WindowsPowerShell"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles%\WinRAR\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles%\WinRAR"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Program Files (x86)"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Adobe\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Adobe"
  • '<SYSTEM32>\attrib.exe' +h +s "%CommonProgramFiles(x86)%\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%CommonProgramFiles(x86)%"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Internet Explorer\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Internet Explorer"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Microsoft\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Microsoft"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Microsoft Analysis Services\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Microsoft Analysis Services"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Microsoft Office\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Microsoft Office"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Microsoft SQL Server\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Microsoft SQL Server"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Microsoft.NET\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Microsoft.NET"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Mozilla Firefox\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Mozilla Firefox"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Opera\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Opera"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Steam\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Steam"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Windows Defender.bak\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Windows Defender.bak"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Windows Mail\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Windows Mail"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Windows Media Player\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Windows Media Player"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Windows Multimedia Platform\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Windows Multimedia Platform"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Windows NT\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Windows NT"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Windows Photo Viewer\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Windows Photo Viewer"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Windows Portable Devices\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Windows Portable Devices"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\Windows Sidebar\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\Windows Sidebar"
  • '<SYSTEM32>\attrib.exe' +h +s "%ProgramFiles(x86)%\WindowsPowerShell\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ProgramFiles(x86)%\WindowsPowerShell"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Adobe\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Adobe"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Application Data\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Application Data"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Desktop\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Desktop"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Documents\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Documents"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Microsoft\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Microsoft"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Microsoft Help\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Microsoft Help"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Mozilla\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Mozilla"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Oracle\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Oracle"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Package Cache\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Package Cache"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Packages\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Packages"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\regid.1991-06.com.microsoft\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\regid.1991-06.com.microsoft"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\SoftwareDistribution\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\SoftwareDistribution"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\ssh\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\ssh"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Start Menu\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Start Menu"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\Templates\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\Templates"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\USOPrivate\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\USOPrivate"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\USOShared\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\USOShared"
  • '<SYSTEM32>\attrib.exe' +h +s "%ALLUSERSPROFILE%\WindowsHolographicDevices\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%ALLUSERSPROFILE%\WindowsHolographicDevices"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\Recovery\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Recovery"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\Recovery\WindowsRE\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Recovery\WindowsRE"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\System Volume Information\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\System Volume Information"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\Users\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Users"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\Users\Default\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Users\Default"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\Users\Default User\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Users\Default User"
  • '<SYSTEM32>\attrib.exe' +h +s "C:\Users\Public\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "C:\Users\Public"
  • '<SYSTEM32>\attrib.exe' +h +s "%HOMEPATH%\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%HOMEPATH%"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\addins\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\addins"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\appcompat\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\appcompat"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\apppatch\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\apppatch"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\AppReadiness\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\AppReadiness"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\assembly\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\assembly"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\bcastdvr\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\bcastdvr"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\BitLockerDiscoveryVolumeContents\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\BitLockerDiscoveryVolumeContents"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Boot\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Boot"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Branding\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Branding"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\CbsTemp\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\CbsTemp"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Containers\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Containers"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\CSC\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\CSC"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Cursors\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Cursors"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\debug\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\debug"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\diagnostics\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\diagnostics"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\DiagTrack\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\DiagTrack"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\DigitalLocker\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\DigitalLocker"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Downloaded Program Files\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Downloaded Program Files"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\ELAMBKUP\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\ELAMBKUP"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\en-US\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\en-US"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Fonts\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Fonts"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\GameBarPresenceWriter\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\GameBarPresenceWriter"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Globalization\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Globalization"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Help\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Help"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\IdentityCRL\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\IdentityCRL"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\IME\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\IME"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\ImmersiveControlPanel\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\ImmersiveControlPanel"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\INF\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\INF"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\InputMethod\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\InputMethod"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Installer\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Installer"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\L2Schemas\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\L2Schemas"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\LanguageOverlayCache\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\LanguageOverlayCache"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\LiveKernelReports\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\LiveKernelReports"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Logs\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Logs"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Media\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Media"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Microsoft.NET\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Microsoft.NET"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Migration\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Migration"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\ModemLogs\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\ModemLogs"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\OCR\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\OCR"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Offline Web Pages\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Offline Web Pages"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Panther\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Panther"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\PCHEALTH\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\PCHEALTH"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Performance\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Performance"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\PLA\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\PLA"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\PolicyDefinitions\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\PolicyDefinitions"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Prefetch\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Prefetch"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\PrintDialog\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\PrintDialog"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Provisioning\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Provisioning"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Registration\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Registration"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\RemotePackages\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\RemotePackages"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\rescache\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\rescache"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Resources\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Resources"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\SchCache\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\SchCache"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\schemas\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\schemas"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\security\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\security"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\ServiceProfiles\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\ServiceProfiles"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\ServiceState\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\ServiceState"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\servicing\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\servicing"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Setup\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Setup"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\ShellComponents\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\ShellComponents"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\ShellExperiences\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\ShellExperiences"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\SHELLNEW\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\SHELLNEW"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\SKB\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\SKB"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\SoftwareDistribution\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\SoftwareDistribution"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Speech\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Speech"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Speech_OneCore\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Speech_OneCore"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\System\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\System"
  • '<SYSTEM32>\attrib.exe' +h +s "<SYSTEM32>\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "<SYSTEM32>"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\SystemApps\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\SystemApps"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\SystemResources\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\SystemResources"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\SysWOW64\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\SysWOW64"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\TAPI\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\TAPI"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Tasks\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Tasks"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Temp\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Temp"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\tracing\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\tracing"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\twain_32\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\twain_32"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Vss\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Vss"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\WaaS\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\WaaS"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\Web\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\Web"
  • '<SYSTEM32>\attrib.exe' +h +s "%WINDIR%\WinSxS\desktop.ini"
  • '<SYSTEM32>\attrib.exe' +r +s "%WINDIR%\WinSxS"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке