Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen6.22652

Добавлен в вирусную базу Dr.Web: 2014-08-23

Описание добавлено:

Техническая информация

Вредоносные функции:
Для обхода брандмауэра удаляет или модифицирует следующие ключи реестра:
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\Temp\KMSpico\AutoPico.exe' = '%WINDIR%\Temp\KMSpico\AutoPico.exe:*:Enabled:KMS Emulator'
Создает и запускает на исполнение:
  • '%WINDIR%\Temp\KMSpico\AutoPico.exe'
Запускает на исполнение:
  • '<SYSTEM32>\net.exe' STOP "Windows Defender Service"
  • '<SYSTEM32>\net1.exe' STOP "Windows Defender Service"
  • '<SYSTEM32>\schtasks.exe' /Create /TN "AutoPico Daily Restart" /TR "%WINDIR%\Temp\KMSpico\AutoPico.exe /silent" /SC DAILY /ST 11:59:59 /RU SYSTEM /RL Highest /F
  • '<SYSTEM32>\findstr.exe' /I "\<10\>"
  • '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\Temp\KMSpico\AutoRun.cmd" "
  • '<SYSTEM32>\cscript.exe' DisableSmartScreen.vbs
  • '<SYSTEM32>\reg.exe' QUERY "HKLM\SOFTWARE\Microsoft\Internet Explorer" /v "Version"
Изменения в файловой системе:
Создает следующие файлы:
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPrem_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\WordVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioPro_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Visio\VisioStd_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasicsVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasicsVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasicsVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\StandardVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\StandardVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\Standard_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\StandardAcad_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\SmallBusBasics\SmallBusBasics_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\StandardAcad_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\StandardVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\StandardAcad_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Standard\StandardAcad_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\LicenseSetData._3E4294DD_A765_49BC_8DBD_CF8B62A4BD3D.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\LicenseSetData._3E4294DD_A765_49BC_8DBD_CF8B62A4BD3D.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\LicenseSetData._2B88C4F2_EA8F_43CD_805E_4D41346E18A7.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\LicenseSetData._B322DA9C_A2E2_4058_9E4E_F59A6970BD69.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\LicenseSetData._2B88C4F2_EA8F_43CD_805E_4D41346E18A7.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\LicenseSetData._2B88C4F2_EA8F_43CD_805E_4D41346E18A7.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\proplus.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\LicenseSetData._B322DA9C_A2E2_4058_9E4E_F59A6970BD69.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\LicenseSetData._B322DA9C_A2E2_4058_9E4E_F59A6970BD69.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\LicenseSetData._3E4294DD_A765_49BC_8DBD_CF8B62A4BD3D.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\sounds\begin.mp3
  • %WINDIR%\Temp\KMSpico\sounds\complete.mp3
  • %WINDIR%\Temp\KMSpico\ReadMe KMSpico Portable.txt
  • %WINDIR%\Temp\KMSpico\sounds\affirmative.mp3
  • %WINDIR%\Temp\KMSpico\sounds\verified.mp3
  • %WINDIR%\Temp\KMSpico\sounds\warning.mp3
  • %WINDIR%\Temp\KMSpico\sounds\diagnostic.mp3
  • %WINDIR%\Temp\KMSpico\sounds\transfer.mp3
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\LicenseSetData._E13AC10E_75D0_4AFF_A0CD_764982CF541C.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\LicenseSetData._E13AC10E_75D0_4AFF_A0CD_764982CF541C.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\LicenseSetData._3E4294DD_A765_49BC_8DBD_CF8B62A4BD3D.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\LicenseSetData._E13AC10E_75D0_4AFF_A0CD_764982CF541C.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\Disable_SmartScreen.cmd
  • %WINDIR%\Temp\KMSpico\Install_Task.cmd
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Visio\visio.reg
  • %WINDIR%\Temp\KMSpico\Check_Activation_All.cmd
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\LicenseSetData._2B88C4F2_EA8F_43CD_805E_4D41346E18A7.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\WordVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\WordVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Word\Word_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\project.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Proplus\Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\LicenseSetData._4A5D124A_E620_44BA_B6FF_658961B33B9A.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\LicenseSetData._4A5D124A_E620_44BA_B6FF_658961B33B9A.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\LicenseSetData._4A5D124A_E620_44BA_B6FF_658961B33B9A.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\LicenseSetData._ED34DC89_1C27_4ECD_8B2F_63D0F4CEDC32.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\LicenseSetData._ED34DC89_1C27_4ECD_8B2F_63D0F4CEDC32.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\LicenseSetData._ED34DC89_1C27_4ECD_8B2F_63D0F4CEDC32.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2013\Project\LicenseSetData._ED34DC89_1C27_4ECD_8B2F_63D0F4CEDC32.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\Publisher_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPathVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPathVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPathVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\InfoPath\InfoPath_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\OutlookVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\OutlookVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\OutlookVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNoteVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNoteVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNoteVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\OneNote\OneNote_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\ExcelVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\AutoRun.cmd
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\AccessVLReg32.reg
  • %WINDIR%\Temp\KMSpico\AutoPico.exe
  • %WINDIR%\Temp\KMSpico\AutoPico.log
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\Access_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\AccessVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Access\AccessVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\ExcelVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\GrooveVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\GrooveVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\GrooveVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Groove\Groove_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\ExcelVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Excel\Excel_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_MAK2.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_MAK2.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlusAcad_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlusAcad_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_MAK2.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_MAK2.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStdVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStd_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlusAcad_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\PublisherVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\PublisherVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Publisher\PublisherVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlusVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlusVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlusAcad_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlusVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProPlus\ProPlus_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStdVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPointVLRegWOW.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPointVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPointVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\Outlook\Outlook_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_KMS_Client.RAC_Pub.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_MAK.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_KMS_Client.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_KMS_Client.RAC_Priv.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectStd\ProjectStdVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_MAK.PPDLIC.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectProVLReg32.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_MAK.PHN.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\PowerPoint\PowerPoint_MAK.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_KMS_Client.OOB.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectPro_KMS_Client.PL.xrm-ms
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectProVLReg64.reg
  • %WINDIR%\Temp\KMSpico\cert\kmscert2010\ProjectPro\ProjectProVLRegWOW.reg
Удаляет следующие файлы:
  • %WINDIR%\Temp\KMSpico\AutoPico.log
Другое:
Ищет следующие окна:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'EDIT' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке