Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.DownLoader22.30053

Добавлен в вирусную базу Dr.Web: 2016-09-01

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Classes\WinFrameICA\shell\open\command] '' = '"%ProgramFiles%\Citrix\ICA Client\wfica32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
  • [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
  • [<HKLM>\SOFTWARE\Classes\PROTOCOLS\Filter\ica] 'CLSID' = '{CFB6322E-CC85-4d1b-82C7-893888A236BC}'
  • [<HKLM>\SOFTWARE\Classes\Citrix.ICAClient.2.7\shell\open\command] '' = '"%ProgramFiles%\Citrix\ICA Client\wfcrun32.exe" "%1"'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ConnectionCenter' = '"%ProgramFiles%\Citrix\ICA Client\concentr.exe" /startup'
  • [<HKLM>\SOFTWARE\Classes\PROTOCOLS\Filter\application/x-ica] 'CLSID' = '{CFB6322E-CC85-4d1b-82C7-893888A236BC}'
Создает следующие сервисы:
  • [<HKLM>\SYSTEM\ControlSet001\Services\ctxusbm] 'ImagePath' = 'system32\DRIVERS\ctxusbm.sys'
  • [<HKLM>\SYSTEM\ControlSet001\Services\ctxusbm] 'Start' = '00000001'
Вредоносные функции:
Запускает на исполнение:
  • '<SYSTEM32>\runonce.exe' -r
  • '<SYSTEM32>\grpconv.exe' -o
  • '<SYSTEM32>\msiexec.exe' -Embedding D085E95127B79CE44EBB3449527C273B M Global\MSI0000
  • '%ProgramFiles%\Citrix\ICA Client\Drivers\usbinst.exe' InstallHinfSection "DefaultInstall 128 %ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbm\ctxusbm.inf"
  • '<SYSTEM32>\msiexec.exe' -Embedding F8C242FCAA75E438A0714D0337618CAE
  • '<SYSTEM32>\msiexec.exe' -Embedding 2BF5E586DCEEA1E1A3545EDEC2339663 M Global\MSI0000
  • '%ProgramFiles%\Citrix\ICA Client\Drivers\usbinst.exe' SetupCopyOEMInf "%ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbr\ctxusbr.inf"
  • '<SYSTEM32>\msiexec.exe' -Embedding 22280081D42905242EBBA81E2024F3DC
  • '%ProgramFiles%\Citrix\ICA Client\wfcrun32.exe' -Embedding
  • '<SYSTEM32>\msiexec.exe' -Embedding DC181B2463C7B612D0F50EF4BAD957DF
  • '<SYSTEM32>\msiexec.exe' -Embedding B19953A4894ECEF8315CFC2056EE2AD0 M Global\MSI0000
  • '%TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpress.exe' <Полный путь к вирусу>
  • '<SYSTEM32>\msiexec.exe' /V
  • '%ProgramFiles%\Citrix\ICA Client\icaconf.exe' import --replace -f -all "%ProgramFiles%\Citrix\ICA Client\Configuration"
  • '%ProgramFiles%\Citrix\ICA Client\concentr.exe' /startup
  • '%ProgramFiles%\Citrix\ICA Client\wfcrun32.exe' /regserver
  • '<SYSTEM32>\rundll32.exe' icaconfs.dll, ApplyConfigurationA import --replace -f -all "%ProgramFiles%\Citrix\ICA Client\Configuration" --RunAsAdmin
Изменения в файловой системе:
Создает следующие файлы:
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\wfcrun32.exe
  • %ProgramFiles%\Citrix\ICA Client\version.dat
  • %ProgramFiles%\Citrix\ICA Client\wfclient.ini
  • %ProgramFiles%\Citrix\ICA Client\wfclient.src
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\wfcwinn.dll
  • %ProgramFiles%\Citrix\ICA Client\Wfica.ocx
  • %ProgramFiles%\Citrix\ICA Client\resource\es\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\wfcrunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\vdtwin.dll
  • %ProgramFiles%\Citrix\ICA Client\vdtwn.dll
  • %ProgramFiles%\Citrix\ICA Client\vdzlcn.dll
  • %ProgramFiles%\Citrix\ICA Client\vdtw30n.dll
  • %ProgramFiles%\Citrix\ICA Client\vdspl30n.dll
  • %ProgramFiles%\Citrix\ICA Client\vdsspin.dll
  • %ProgramFiles%\Citrix\ICA Client\vdtuin.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\vdzlcnUI.dll
  • %ProgramFiles%\Citrix\ICA Client\XPSPrintHelper.exe
  • %WINDIR%\Installer\MSI11.tmp
  • %WINDIR%\Installer\MSI12.tmp
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\wficaUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\wficaUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\wficaUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\wficaUI.dll
  • %APPDATA%\ICAClient\WFCLIENT.INI
  • %WINDIR%\Installer\MSI15.tmp
  • %ProgramFiles%\Citrix\ICA Client\wfcwin32.log
  • %TEMP%\~DFC462.tmp
  • %WINDIR%\Installer\MSI14.tmp
  • %WINDIR%\Installer\25732.msi
  • %WINDIR%\Installer\{023D64D7-E7B4-47C7-BE6E-B7C2E8960D08}\liteico.exe.827545C6_7013_4DE1_8E6C_DAEE4C57F54A.exe
  • %WINDIR%\Installer\MSI13.tmp
  • %ProgramFiles%\Citrix\ICA Client\resource\en\wficaUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\wfica32.exe
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\wficaUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\wficaUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\wficaUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\wficaUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\wfica3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\WfIcaLib.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\statuin.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\srcflter.dll
  • %ProgramFiles%\Citrix\ICA Client\sslsdk_b.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\sslsdkUI.dll
  • %ProgramFiles%\Citrix\ICA Client\SetIntegrityLevel.exe
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\ProgressNotificationCommonUI.dll
  • %ProgramFiles%\Citrix\ICA Client\reducv3.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\regions.ini
  • %ProgramFiles%\Citrix\ICA Client\resource\es\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\vdcom30N.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\vdcpm30N.dll
  • %ProgramFiles%\Citrix\ICA Client\vdkbhook.dll
  • %ProgramFiles%\Citrix\ICA Client\vdmmn.dll
  • %ProgramFiles%\Citrix\ICA Client\vdscardn.dll
  • %ProgramFiles%\Citrix\ICA Client\vdfon30n.dll
  • %ProgramFiles%\Citrix\ICA Client\vdctln.dll
  • %ProgramFiles%\Citrix\ICA Client\vddvc0N.dll
  • %ProgramFiles%\Citrix\ICA Client\vdeuemn.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\TcpPServ.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\Trusted_Region.ini
  • %ProgramFiles%\Citrix\ICA Client\Configuration\usertemplate\Trusted_Region.ini
  • %ProgramFiles%\Citrix\ICA Client\TaskbarGrpXpVista.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\statuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\TaskbarGrpWin7.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\Unknown_Region.ini
  • %ProgramFiles%\Citrix\ICA Client\vdcdm30n.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\vdcdm3UI.dll
  • %ProgramFiles%\Citrix\ICA Client\vdcamN.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\usertemplate\Unknown_Region.ini
  • %ProgramFiles%\Citrix\ICA Client\Configuration\Untrusted_Region.ini
  • %ProgramFiles%\Citrix\ICA Client\Configuration\usertemplate\Untrusted_Region.ini
  • %APPDATA%\ICAClient\APPSRV.INI
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\vdflasUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\vdflasUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\vdflasUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\vdflasUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\vdflasUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\vdflasUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\vdflasUI.dll
  • %WINDIR%\Installer\25741.msi
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\dualpk.cab
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_de.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_en.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\DesktopViewer.msi
  • %WINDIR%\Installer\MSI29.tmp
  • %TEMP%\~DF4D7C.tmp
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\CitrixHDXMediaStreamForFlash-ClientInstall.msi
  • %ProgramFiles%\Citrix\ICA Client\resource\en\vdflasUI.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\en\HdxFlash-Client.adm
  • %ProgramFiles%\Citrix\ICA Client\Configuration\es\HdxFlash-Client.adm
  • %ProgramFiles%\Citrix\ICA Client\Configuration\fr\HdxFlash-Client.adm
  • %ProgramFiles%\Citrix\ICA Client\Configuration\de\HdxFlash-Client.adm
  • %TEMP%\~DFFCD3.tmp
  • %WINDIR%\Installer\MSI27.tmp
  • C:\Config.Msi\25740.rbs
  • %ProgramFiles%\Citrix\ICA Client\Configuration\ja\HdxFlash-Client.adm
  • %ProgramFiles%\Citrix\ICA Client\PseudoContainer.exe
  • %ProgramFiles%\Citrix\ICA Client\vdflash.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\vdflasUI.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\zh-TW\HdxFlash-Client.adm
  • %ProgramFiles%\Citrix\ICA Client\Configuration\ko\HdxFlash-Client.adm
  • %ProgramFiles%\Citrix\ICA Client\Configuration\ru\HdxFlash-Client.adm
  • %ProgramFiles%\Citrix\ICA Client\Configuration\zh-CN\HdxFlash-Client.adm
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\SideBarBackground.bmp
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpress.exe
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_de.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_zh-TW.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_ko.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_ru.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_zh-CN.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_en.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_ru.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_zh-CN.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_zh-TW.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_ko.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_es.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_fr.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\TrolleyExpressUI_ja.dll
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_ja.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_ru.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_zh-CN.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_zh-TW.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_ko.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_es.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_fr.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\EULA_ja.rtf
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\GenericUSB.msi
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_en.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_es.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_fr.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Localized_de.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\Global.xml
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\HeaderLogo.bmp
  • %ALLUSERSPROFILE%\Application Data\Citrix\Citrix online plug-in - web\ICAWebWrapper.msi
  • %WINDIR%\Installer\MSI1D.tmp
  • <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem4.CAT
  • %WINDIR%\inf\oem4.inf
  • <DRIVERS>\SET1C.tmp
  • <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem3.CAT
  • %WINDIR%\inf\oem3.inf
  • %WINDIR%\inf\oem3.PNF
  • %WINDIR%\inf\oem4.PNF
  • %WINDIR%\Installer\25738.msi
  • %WINDIR%\Installer\MSI21.tmp
  • %WINDIR%\Installer\2573a.ipi
  • %TEMP%\CtxInstall-DesktopViewer.log
  • %WINDIR%\Installer\25737.msi
  • %WINDIR%\Installer\{6F8EAC65-314D-4D86-9557-BC9312AACCB0}\ProductIcon
  • %TEMP%\~DFDDE2.tmp
  • %WINDIR%\Installer\MSI19.tmp
  • %WINDIR%\Installer\MSI17.tmp
  • C:\Config.Msi\25736.rbs
  • %ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbm\ctxusbm.cat
  • %TEMP%\~DFAB09.tmp
  • %TEMP%\CtxInstall-GenericUSB.log
  • %WINDIR%\Installer\25733.msi
  • %WINDIR%\Installer\25735.ipi
  • %ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbm\ctxusbm.inf
  • %ProgramFiles%\Citrix\ICA Client\Drivers\usbinst.exe
  • %ProgramFiles%\Citrix\ICA Client\vdgusbn.dll
  • %ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbr\WdfCoInstaller01007.dll
  • %ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbr\ctxusbr.sys
  • %ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbm\ctxusbm.sys
  • %ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbr\ctxusbr.cat
  • %ProgramFiles%\Citrix\ICA Client\Drivers\ctxusbr\ctxusbr.inf
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\zh-CN\DesktopViewer.resources.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\ru\DesktopViewer.resources.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\ko\DesktopViewer.resources.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\zh-TW\DesktopViewer.resources.dll
  • %WINDIR%\Installer\MSI25.tmp
  • %WINDIR%\Installer\MSI26.tmp
  • %WINDIR%\Installer\2573f.ipi
  • %WINDIR%\Installer\2573d.msi
  • %WINDIR%\Installer\2573c.msi
  • %TEMP%\~DF8464.tmp
  • %TEMP%\CtxInstall-CitrixHDXMediaStreamForFlash-ClientInstall.log
  • %ProgramFiles%\Citrix\ICA Client\ja\DesktopViewer.resources.dll
  • %ProgramFiles%\Citrix\ICA Client\CDViewer.exe.config
  • %ProgramFiles%\Citrix\ICA Client\resource\de\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\de\DesktopViewer.resources.dll
  • %ProgramFiles%\Citrix\ICA Client\CDViewer.exe
  • %TEMP%\~DF4F77.tmp
  • %WINDIR%\Installer\MSI22.tmp
  • C:\Config.Msi\2573b.rbs
  • %ProgramFiles%\Citrix\ICA Client\DesktopViewer.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\fr\DesktopViewer.resources.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\es\DesktopViewer.resources.dll
  • %ProgramFiles%\Citrix\ICA Client\DVLauncher.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\DVLaunUI.dll
  • %ProgramFiles%\Citrix\ICA Client\cgpcfg.dll
  • %ProgramFiles%\Citrix\ICA Client\CgpCore.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\CCMSDK.dll
  • %ProgramFiles%\Citrix\ICA Client\AxWfIcaLib.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\canonicalization.ini
  • %ProgramFiles%\Citrix\ICA Client\CCMProxy.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\resource\es\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\resource\de\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\resource\en\concentr.chm
  • %ProgramFiles%\Citrix\ICA Client\audcvtN.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\acrdlg.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\usertemplate\All_Regions.ini
  • %ProgramFiles%\Citrix\ICA Client\appsrv.ini
  • %ProgramFiles%\Citrix\ICA Client\appsrv.src
  • %ProgramFiles%\Citrix\ICA Client\Configuration\All_Regions.ini
  • %ProgramFiles%\Citrix\ICA Client\resource\es\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\acrdlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\adpcm.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\cst.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\cstUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\concentr.exe
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\CPViewUI.dll
  • %ProgramFiles%\Citrix\ICA Client\cpviewer.exe
  • %ProgramFiles%\Citrix\ICA Client\resource\es\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\concenUI.dll
  • %ProgramFiles%\Citrix\ICA Client\confmgr.dll
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\dualpk.cab
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\HeaderLogo.bmp
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\SideBarBackground.bmp
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Global.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_ru.rtf
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_zh-CN.rtf
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_zh-TW.rtf
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\GenericUSB.msi
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_de.dll
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_en.dll
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_es.dll
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpress.exe
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\DesktopViewer.msi
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\ICAWebWrapper.msi
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\CitrixHDXMediaStreamForFlash-ClientInstall.msi
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_ko.rtf
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_fr.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_ja.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_ko.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_es.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\CTX_UPDATE_PACKAGE
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_de.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_en.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_ru.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_es.rtf
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_fr.rtf
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_ja.rtf
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_en.rtf
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_zh-CN.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\Localized_zh-TW.xml
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\EULA_de.rtf
  • %WINDIR%\Installer\MSI8.tmp
  • %WINDIR%\Installer\MSI9.tmp
  • %WINDIR%\Installer\MSIA.tmp
  • %WINDIR%\Installer\MSI7.tmp
  • %WINDIR%\Installer\MSI4.tmp
  • %WINDIR%\Installer\MSI5.tmp
  • %WINDIR%\Installer\MSI6.tmp
  • %WINDIR%\Installer\MSIB.tmp
  • %WINDIR%\Installer\MSIE.tmp
  • C:\Config.Msi\25731.rbs
  • %WINDIR%\Installer\MSI10.tmp
  • %WINDIR%\Installer\MSID.tmp
  • %WINDIR%\Installer\MSIC.tmp
  • %WINDIR%\Installer\25730.ipi
  • %TEMP%\~DFB0C1.tmp
  • %WINDIR%\Installer\MSI3.tmp
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_zh-CN.dll
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_zh-TW.dll
  • %TEMP%\TrolleyExpress-20160901-152514.log
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_ru.dll
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_fr.dll
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_ja.dll
  • %TEMP%\Ctx-0559A784-D566-47AF-932D-78B8873A46CD\Extract\TrolleyExpressUI_ko.dll
  • %TEMP%\CtxInstall-ICAWebWrapper.log
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30
  • %WINDIR%\Installer\MSI1.tmp
  • %WINDIR%\Installer\MSI2.tmp
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30
  • %WINDIR%\Installer\2572e.msi
  • %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
  • %APPDATA%\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
  • %ProgramFiles%\Citrix\ICA Client\CtxDSSink.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\Microsoft.VC80.MFCLOC.manifest
  • %ProgramFiles%\Citrix\ICA Client\migrateN.exe
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\module.ini
  • %ProgramFiles%\Citrix\ICA Client\module.src
  • %ProgramFiles%\Citrix\ICA Client\Configuration\module_Wince.ini
  • %ProgramFiles%\Citrix\ICA Client\module.ini
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\migratUI.dll
  • %ProgramFiles%\Citrix\ICA Client\Microsoft.VC80.MFC.manifest
  • %ProgramFiles%\Citrix\ICA Client\MFC80DEU.dll
  • %ProgramFiles%\Citrix\ICA Client\MFC80ENU.dll
  • %ProgramFiles%\Citrix\ICA Client\MFC80ESP.dll
  • %ProgramFiles%\Citrix\ICA Client\MFC80CHT.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\License.txt
  • %ProgramFiles%\Citrix\ICA Client\mfc80.dll
  • %ProgramFiles%\Citrix\ICA Client\MFC80CHS.dll
  • %ProgramFiles%\Citrix\ICA Client\MFC80FRA.dll
  • %ProgramFiles%\Citrix\ICA Client\mfcm80.dll
  • %ProgramFiles%\Citrix\ICA Client\mfcm80u.dll
  • %ProgramFiles%\Citrix\ICA Client\Microsoft.VC80.CRT.manifest
  • %ProgramFiles%\Citrix\ICA Client\mfc80u.dll
  • %ProgramFiles%\Citrix\ICA Client\MFC80ITA.dll
  • %ProgramFiles%\Citrix\ICA Client\MFC80JPN.dll
  • %ProgramFiles%\Citrix\ICA Client\MFC80KOR.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\pdcompN.dll
  • %ProgramFiles%\Citrix\ICA Client\pdframeN.dll
  • %ProgramFiles%\Citrix\ICA Client\ProgressNotificationCommon.dll
  • %ProgramFiles%\Citrix\ICA Client\pdc128N.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\nrhttpUI.dll
  • %ProgramFiles%\Citrix\ICA Client\pcl2bmp.exe
  • %ProgramFiles%\Citrix\ICA Client\pcl4rast.dll
  • %ProgramFiles%\Citrix\ICA Client\nrhttpn.dll
  • %ProgramFiles%\Citrix\ICA Client\nenumn.dll
  • %ProgramFiles%\Citrix\ICA Client\npicaN.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\neHttpN.dll
  • %ProgramFiles%\Citrix\ICA Client\msvcm80.dll
  • %ProgramFiles%\Citrix\ICA Client\msvcp80.dll
  • %ProgramFiles%\Citrix\ICA Client\msvcr80.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\npicanUI.dll
  • %ProgramFiles%\Citrix\ICA Client\ctxspeex.dll
  • %ProgramFiles%\Citrix\ICA Client\CtxTwnPA.exe
  • %ProgramFiles%\Citrix\ICA Client\ctxvorbis.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\emfrendr.dll
  • %ProgramFiles%\Citrix\ICA Client\ICAClObj.class
  • %ProgramFiles%\Citrix\ICA Client\icaconf.exe
  • %ProgramFiles%\Citrix\ICA Client\icadlgn.dll
  • %ProgramFiles%\Citrix\ICA Client\IcaClientTraceProviders.ctl
  • %ProgramFiles%\Citrix\ICA Client\icaconfs.dll
  • %ProgramFiles%\Citrix\ICA Client\HdxRTTheora.dll
  • %ProgramFiles%\Citrix\ICA Client\Configuration\icaclient.adm
  • %ProgramFiles%\Citrix\ICA Client\resource\en\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\ctxlogging.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\ctxmuiUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\ctxlogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\ctxmui.dll
  • %ProgramFiles%\Citrix\ICA Client\IcaMimeFilter.dll
  • %ProgramFiles%\Citrix\ICA Client\icavern.dll
  • %ProgramFiles%\Citrix\ICA Client\IICAClient.xpt
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\License.txt
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\License.txt
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\License.txt
  • %ProgramFiles%\Citrix\ICA Client\resource\es\License.txt
  • %ProgramFiles%\Citrix\ICA Client\resource\en\License.txt
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\License.txt
  • %ProgramFiles%\Citrix\ICA Client\resource\de\License.txt
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\License.txt
  • %ProgramFiles%\Citrix\ICA Client\resource\en\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\en\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ko\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ja\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\es\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\ru\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\de\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\fr\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-CN\icalogUI.dll
  • %ProgramFiles%\Citrix\ICA Client\resource\zh-TW\icadlgUI.dll
  • %ProgramFiles%\Citrix\ICA Client\icafile.dll
  • %ProgramFiles%\Citrix\ICA Client\icalogon.dll
Присваивает атрибут 'скрытый' для следующих файлов:
  • <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem4.CAT
  • <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem3.CAT
Удаляет следующие файлы:
  • %WINDIR%\Installer\25733.msi
  • C:\Config.Msi\25736.rbs
  • %WINDIR%\Installer\25735.ipi
  • %WINDIR%\Installer\MSI22.tmp
  • %WINDIR%\Installer\MSI21.tmp
  • %WINDIR%\Installer\25730.ipi
  • %WINDIR%\Installer\2572e.msi
  • %WINDIR%\Installer\MSI19.tmp
  • %WINDIR%\Installer\MSI17.tmp
  • %WINDIR%\Installer\MSI1D.tmp
  • %WINDIR%\Installer\MSI27.tmp
  • %WINDIR%\Installer\MSI29.tmp
  • C:\Config.Msi\25740.rbs
  • %WINDIR%\Installer\2573f.ipi
  • %WINDIR%\Installer\2573d.msi
  • %WINDIR%\Installer\25738.msi
  • C:\Config.Msi\2573b.rbs
  • %WINDIR%\Installer\2573a.ipi
  • %WINDIR%\Installer\MSI26.tmp
  • %WINDIR%\Installer\MSI25.tmp
  • C:\Config.Msi\25731.rbs
  • %WINDIR%\Installer\MSI7.tmp
  • %WINDIR%\Installer\MSI6.tmp
  • %WINDIR%\Installer\MSI8.tmp
  • %WINDIR%\Installer\MSIA.tmp
  • %WINDIR%\Installer\MSI9.tmp
  • %WINDIR%\Installer\MSI2.tmp
  • %WINDIR%\Installer\MSI1.tmp
  • %WINDIR%\Installer\MSI3.tmp
  • %WINDIR%\Installer\MSI5.tmp
  • %WINDIR%\Installer\MSI4.tmp
  • %WINDIR%\Installer\MSI13.tmp
  • %WINDIR%\Installer\MSI12.tmp
  • %WINDIR%\Installer\MSI14.tmp
  • %WINDIR%\Installer\MSID.tmp
  • %WINDIR%\Installer\MSI15.tmp
  • %WINDIR%\Installer\MSIC.tmp
  • %WINDIR%\Installer\MSIB.tmp
  • %WINDIR%\Installer\MSIE.tmp
  • %WINDIR%\Installer\MSI11.tmp
  • %WINDIR%\Installer\MSI10.tmp
Перемещает следующие файлы:
  • <DRIVERS>\SET1C.tmp в <DRIVERS>\ctxusbm.sys
Сетевая активность:
Подключается к:
  • 'cs######4-crl.verisign.com':80
  • 'crl.verisign.com':80
  • 'wp#d':80
TCP:
Запросы HTTP GET:
  • http://CS######4-crl.verisign.com/CSC3-2004.crl via cs######4-crl.verisign.com
  • http://crl.verisign.com/pca3.crl
  • http://11#.#11.111.1/wpad.dat via wp#d
UDP:
  • DNS ASK cs######4-crl.verisign.com
  • DNS ASK crl.verisign.com
  • DNS ASK wp#d
Другое:
Ищет следующие окна:
  • ClassName: 'ICA Seamless Connection Center' WindowName: ''
  • ClassName: 'WFIcaClient' WindowName: ''
  • ClassName: 'MS_WINHELP' WindowName: ''
  • ClassName: 'WfICA32Class' WindowName: ''
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'WfcRun32Class' WindowName: ''
  • ClassName: 'WfcMgr32Class' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке