Защити созданное

Другие наши ресурсы

  • free.drweb.kz — бесплатные утилиты, плагины, информеры
  • av-desk.com — интернет-сервис для поставщиков услуг Dr.Web AV-Desk
  • curenet.drweb.kz — сетевая лечащая утилита Dr.Web CureNet!
Закрыть

Библиотека
Моя библиотека

Чтобы добавить ресурс в библиотеку, войдите в аккаунт.

+ Добавить в библиотеку

Ресурсов: -

Последний: -

Моя библиотека

Поддержка
Круглосуточная поддержка | Правила обращения

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen9.57591

Добавлен в вирусную базу Dr.Web: 2020-07-10

Описание добавлено:

Technical Information

Malicious functions
Executes the following
  • '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="DriverPack aria2c.exe" dir=in action=allow program="%TEMP%\DriverPack-20200709133608\tools\aria2c.exe"
Modifies settings of Windows Internet Explorer
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1406' = '00000000'
Modifies file system
Creates the following files
  • %TEMP%\nsk519d.tmp
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\stories\technologies.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\stories\false-positive.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\stories\drivers.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\stories\about.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\waiting.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\successful-install.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\start.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\start-off.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\service-mode.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\second-browser-yandex.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\second-browser-tor.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\stories\why-free.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\stories\vpn.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\second-browser-firefox.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\second-browser-edge.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\second-browser-chrome.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\second-browser-chrome-blur.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\reviews-back.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\reliability.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\reliability-2.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\reboot.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-vpn.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-update.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\second-browser-opera.png
  • %TEMP%\driverpack-20200709133608\img\screens\checkbox.png
  • %TEMP%\driverpack-20200709133608\img\programs\arrow-collapse.png
  • %TEMP%\driverpack-20200709133608\img\screens\arrow-top.png
  • %TEMP%\driverpack-20200709133608\img\screens\arrow-start-screen-toggle.png
  • %TEMP%\driverpack-20200709133608\img\screens\arrow-bottom.png
  • %TEMP%\driverpack-20200709133608\img\programs\uninstall-single-loader.gif
  • %TEMP%\driverpack-20200709133608\img\programs\uninstall-all-loader.gif
  • %TEMP%\driverpack-20200709133608\img\programs\start_btn-icon.png
  • %TEMP%\driverpack-20200709133608\img\programs\start_arrow.png
  • %TEMP%\driverpack-20200709133608\img\programs\star-full.png
  • %TEMP%\driverpack-20200709133608\img\programs\star-full-protect.png
  • %TEMP%\driverpack-20200709133608\img\programs\star-empty.png
  • %TEMP%\driverpack-20200709133608\img\programs\star-empty-protect.png
  • %TEMP%\driverpack-20200709133608\img\programs\soft-bg.png
  • %TEMP%\driverpack-20200709133608\img\programs\scan.png
  • %TEMP%\driverpack-20200709133608\img\programs\rolling.gif
  • %TEMP%\driverpack-20200709133608\img\programs\rolling-remove-single.gif
  • %TEMP%\driverpack-20200709133608\img\programs\protector-bg.png
  • %TEMP%\driverpack-20200709133608\img\programs\installed-programs_info-warn.png
  • %TEMP%\driverpack-20200709133608\img\programs\installed-programs_info-success.png
  • %TEMP%\driverpack-20200709133608\img\programs\expand-all@2x.svg
  • %TEMP%\driverpack-20200709133608\img\programs\expand-all.png
  • %TEMP%\driverpack-20200709133608\img\programs\default-soft.png
  • %TEMP%\driverpack-20200709133608\img\programs\confirm-popup-deny.png
  • %TEMP%\driverpack-20200709133608\img\programs\confirm-popup-accept.png
  • %TEMP%\driverpack-20200709133608\img\programs\btn-icon.png
  • %TEMP%\driverpack-20200709133608\img\programs\btn-icon-install-all-soft.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-touch-top-right-block-right.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\second-browser-opera-blur.png
  • %TEMP%\driverpack-20200709133608\img\programs\arrow-expand.png
  • %TEMP%\driverpack-20200709133608\img\screens\backup-grey.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-touch-left.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\system.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\antiviruses.gif
  • %TEMP%\driverpack-20200709133608\img\no_internet\no_internet-step2.png
  • %TEMP%\driverpack-20200709133608\img\no_internet\no_internet-step1.png
  • %TEMP%\driverpack-20200709133608\img\no_internet\no_internet-connection.png
  • %TEMP%\driverpack-20200709133608\img\no_internet\no_internet-complete.png
  • %TEMP%\driverpack-20200709133608\img\installation\statuses\sleep.png
  • %TEMP%\driverpack-20200709133608\img\installation\statuses\progress.gif
  • %TEMP%\driverpack-20200709133608\img\installation\statuses\error.png
  • %TEMP%\driverpack-20200709133608\img\installation\statuses\done.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\viewer.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\cleaning.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\blocked.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\checking.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\internet.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\drivers.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\browser.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\backup.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\archiver.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\antivirus.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\zbad.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\wifi.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\webcamera.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\video.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\messenger.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\done.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-slow-connection.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-touch-sync.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\autostart.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-opened-browser-ram.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-notebook.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-mining.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-low-ram.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-chrome.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\hacker.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\drp-team.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\drp-team.gif
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\continuous.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\compilation.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\checking.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\awesome.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\average.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\assistant-off.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\antivirus.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\likes\up.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\likes\up-hover.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\likes\up-active.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\likes\down.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\likes\down-hover.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\likes\down-active.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\soft.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\social.png
  • %TEMP%\driverpack-20200709133608\img\onboarding\settings.png
  • %TEMP%\driverpack-20200709133608\img\onboarding-new\opera-touch-top-right-block-left.png
  • %TEMP%\driverpack-20200709133608\img\games\games-top-civilization.jpg
  • %TEMP%\driverpack-20200709133608\img\screens\configurator-btn-icon.png
  • %TEMP%\driverpack-20200709133608\languages\sq.js
  • %TEMP%\driverpack-20200709133608\languages\sl.js
  • %TEMP%\driverpack-20200709133608\languages\sk.js
  • %TEMP%\driverpack-20200709133608\languages\ru.js
  • %TEMP%\driverpack-20200709133608\languages\ro.js
  • %TEMP%\driverpack-20200709133608\languages\pt-pt.js
  • %TEMP%\driverpack-20200709133608\languages\pt-br.js
  • %TEMP%\driverpack-20200709133608\languages\ps.js
  • %TEMP%\driverpack-20200709133608\languages\pl.js
  • %TEMP%\driverpack-20200709133608\languages\om.js
  • %TEMP%\driverpack-20200709133608\languages\no.js
  • %TEMP%\driverpack-20200709133608\languages\sr.js
  • %TEMP%\driverpack-20200709133608\languages\ta.js
  • %TEMP%\driverpack-20200709133608\languages\nl.js
  • %TEMP%\driverpack-20200709133608\languages\ka.js
  • %TEMP%\driverpack-20200709133608\languages\it.js
  • %TEMP%\driverpack-20200709133608\languages\id.js
  • %TEMP%\driverpack-20200709133608\languages\hy.js
  • %TEMP%\driverpack-20200709133608\languages\hu.js
  • %TEMP%\driverpack-20200709133608\languages\hi.js
  • %TEMP%\driverpack-20200709133608\languages\he.js
  • %TEMP%\driverpack-20200709133608\languages\gu.js
  • %TEMP%\driverpack-20200709133608\languages\fr.js
  • %TEMP%\driverpack-20200709133608\languages\fil.js
  • %TEMP%\driverpack-20200709133608\languages\ku.js
  • %TEMP%\driverpack-20200709133608\languages\ko.js
  • %TEMP%\driverpack-20200709133608\img\screens\configurator-loader.gif
  • %TEMP%\driverpack-20200709133608\languages\te.js
  • %TEMP%\k0ljji2u.out
  • %TEMP%\k0ljji2u.cmdline
  • %TEMP%\k0ljji2u.0.cs
  • %TEMP%\driverpack-20200709133608\tools\3jb28tom.part
  • %APPDATA%\drpsu\temp\run_command_36809.txt
  • %APPDATA%\drpsu\temp\run_command_79239.txt
  • %APPDATA%\drpsu\logs\log___2020-07-09-13-36-31.html
  • %APPDATA%\drpsu\temp\ps.kcf94ibf.3x35d.ps1
  • %APPDATA%\drpsu\temp\ps.kcf94i2b.q6kus.cmd.txt
  • %TEMP%\driverpack-20200709133608\programs\downloader_elements.exe
  • %TEMP%\driverpack-20200709133608\programs\downloader_browser_tr.exe
  • %TEMP%\driverpack-20200709133608\programs\downloader_browser.exe
  • %TEMP%\driverpack-20200709133608\programs\avastantivirusworldwidea.exe
  • %TEMP%\driverpack-20200709133608\programs\avastantivirusa.exe
  • %TEMP%\driverpack-20200709133608\languages\zh.js
  • %TEMP%\driverpack-20200709133608\languages\zh-cn.js
  • %TEMP%\driverpack-20200709133608\languages\yo.js
  • %TEMP%\driverpack-20200709133608\languages\vi.js
  • %TEMP%\driverpack-20200709133608\languages\uz.js
  • %TEMP%\driverpack-20200709133608\languages\ur.js
  • %TEMP%\driverpack-20200709133608\languages\uk.js
  • %TEMP%\driverpack-20200709133608\languages\tr.js
  • %TEMP%\driverpack-20200709133608\languages\th.js
  • %TEMP%\driverpack-20200709133608\languages\tg.js
  • %TEMP%\driverpack-20200709133608\languages\fa.js
  • %TEMP%\driverpack-20200709133608\languages\et.js
  • %TEMP%\driverpack-20200709133608\languages\sw.js
  • %TEMP%\driverpack-20200709133608\languages\es.js
  • %TEMP%\driverpack-20200709133608\languages\es-419.js
  • %TEMP%\driverpack-20200709133608\img\screens\menu-software.png
  • %TEMP%\driverpack-20200709133608\img\screens\kebab-icon.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-report-icon.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-protect.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-offline.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-lang-icon.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-lang-arrow.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-games.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-drivers.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-diagnostics.png
  • %TEMP%\driverpack-20200709133608\img\screens\load-screen-server.png
  • %TEMP%\driverpack-20200709133608\img\screens\language-arrow_hover.png
  • %TEMP%\driverpack-20200709133608\img\screens\language-arrow.png
  • %TEMP%\driverpack-20200709133608\img\screens\install-programs-grey.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\vendor.png
  • %TEMP%\driverpack-20200709133608\img\screens\icon-system-restore.png
  • %TEMP%\driverpack-20200709133608\img\screens\icon-support.png
  • %TEMP%\driverpack-20200709133608\img\screens\icon-driver-row-collapse.png
  • %TEMP%\driverpack-20200709133608\img\screens\icon-device-manager.png
  • %TEMP%\driverpack-20200709133608\img\screens\globe_normal.png
  • %TEMP%\driverpack-20200709133608\img\screens\globe_hover.png
  • %TEMP%\driverpack-20200709133608\img\screens\expert_normal.png
  • %TEMP%\driverpack-20200709133608\img\screens\expert_hover.png
  • %TEMP%\driverpack-20200709133608\img\screens\driver-filter-arrow.png
  • %TEMP%\driverpack-20200709133608\img\screens\control-panel-grey.png
  • %TEMP%\driverpack-20200709133608\img\screens\move-to-top_arrow.png
  • %TEMP%\driverpack-20200709133608\img\screens\new-logo.png
  • %TEMP%\driverpack-20200709133608\img\installation\soft\player.png
  • %TEMP%\driverpack-20200709133608\img\screens\start-info.png
  • %TEMP%\driverpack-20200709133608\img\screens\settings-bg.png
  • %TEMP%\driverpack-20200709133608\img\screens\menu-settings-icon.png
  • %TEMP%\driverpack-20200709133608\languages\el.js
  • %TEMP%\driverpack-20200709133608\languages\de.js
  • %TEMP%\driverpack-20200709133608\languages\cs.js
  • %TEMP%\driverpack-20200709133608\languages\ca.js
  • %TEMP%\driverpack-20200709133608\languages\bn.js
  • %TEMP%\driverpack-20200709133608\languages\bg.js
  • %TEMP%\driverpack-20200709133608\languages\be.js
  • %TEMP%\driverpack-20200709133608\languages\az.js
  • %TEMP%\driverpack-20200709133608\languages\ar.js
  • %TEMP%\driverpack-20200709133608\js\soft.js
  • %TEMP%\driverpack-20200709133608\img\server_err_no_internet\vpn.png
  • %TEMP%\driverpack-20200709133608\img\server_err_no_internet\torrent.png
  • %TEMP%\driverpack-20200709133608\img\server_err_no_internet\no_internet-connection-cat.png
  • %TEMP%\driverpack-20200709133608\img\server_err_no_internet\flash.png
  • %TEMP%\driverpack-20200709133608\img\server_err_no_internet\firewall.png
  • %TEMP%\driverpack-20200709133608\img\server_err_no_internet\connect.png
  • %TEMP%\driverpack-20200709133608\img\server_err_no_internet\browser.png
  • %TEMP%\driverpack-20200709133608\img\screens\zero-drivers_logo.png
  • %TEMP%\driverpack-20200709133608\img\screens\zero-drivers_button-arrow.png
  • %TEMP%\driverpack-20200709133608\img\screens\trusted_hover.png
  • %TEMP%\driverpack-20200709133608\img\screens\trusted.png
  • %TEMP%\driverpack-20200709133608\img\screens\startscreen-slider-oval.png
  • %TEMP%\driverpack-20200709133608\img\screens\startscreen-slider-oval-yellow-hover.png
  • %TEMP%\driverpack-20200709133608\img\screens\startscreen-slider-oval-hover.png
  • %TEMP%\driverpack-20200709133608\languages\en.js
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\tvtuner.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\sound.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\restore_point.png
  • %TEMP%\driverpack-20200709133608\img\med_logo.png
  • %TEMP%\driverpack-20200709133608\img\assistant-chat\netframework.png
  • %TEMP%\driverpack-20200709133608\img\assistant-chat\directx.png
  • %TEMP%\driverpack-20200709133608\img\assistant-chat\chat-icon.png
  • %TEMP%\driverpack-20200709133608\img\wifi.png
  • %TEMP%\driverpack-20200709133608\img\wifi-disabled.png
  • %TEMP%\driverpack-20200709133608\img\start-loader.gif
  • %TEMP%\driverpack-20200709133608\img\speaker.png
  • %TEMP%\driverpack-20200709133608\img\new-logo.png
  • %TEMP%\driverpack-20200709133608\img\med_logo_ui2.png
  • %TEMP%\driverpack-20200709133608\img\med_logo_dark.png
  • %TEMP%\driverpack-20200709133608\img\assistant-chat\systemlib.png
  • %TEMP%\driverpack-20200709133608\img\assistant-chat\no-sound.png
  • %TEMP%\driverpack-20200709133608\img\assistant-chat\sound.png
  • %TEMP%\driverpack-20200709133608\img\loading-finish.png
  • %TEMP%\driverpack-20200709133608\img\installation-loader.gif
  • %TEMP%\driverpack-20200709133608\img\info.png
  • %TEMP%\driverpack-20200709133608\img\driver-row-arrow.png
  • %TEMP%\driverpack-20200709133608\img\device-generic.png
  • %TEMP%\driverpack-20200709133608\img\cam.png
  • %TEMP%\driverpack-20200709133608\img\btn-icon-admin-mode.png
  • %TEMP%\driverpack-20200709133608\img\blank.gif
  • %TEMP%\driverpack-20200709133608\css\fonts\roboto\roboto-thin-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\roboto\roboto-thin-webfont.eot
  • %TEMP%\driverpack-20200709133608\img\loading-spiner.gif
  • %TEMP%\driverpack-20200709133608\img\assistant-chat\visualc.png
  • %TEMP%\driverpack-20200709133608\img\device-class\chipset.png
  • %TEMP%\driverpack-20200709133608\css\fonts\roboto\roboto-regular-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\roboto\roboto-light-webfont.ttf
  • %TEMP%\driverpack-20200709133608\img\device-class\cardreader.png
  • %TEMP%\driverpack-20200709133608\img\device-class\bluetooth.png
  • %TEMP%\driverpack-20200709133608\img\charms\toolkit.png
  • %TEMP%\driverpack-20200709133608\img\charms\store.png
  • %TEMP%\driverpack-20200709133608\img\charms\setup.png
  • %TEMP%\driverpack-20200709133608\img\charms\setup.jpg
  • %TEMP%\driverpack-20200709133608\img\charms\reload-sm.png
  • %TEMP%\driverpack-20200709133608\img\charms\programms.png
  • %TEMP%\driverpack-20200709133608\img\charms\pc.jpg
  • %TEMP%\driverpack-20200709133608\img\charms\line.jpg
  • %TEMP%\driverpack-20200709133608\img\charms\info.png
  • %TEMP%\driverpack-20200709133608\img\charms\help.png
  • %TEMP%\driverpack-20200709133608\img\charms\gears.png
  • %TEMP%\driverpack-20200709133608\img\charms\download.png
  • %TEMP%\driverpack-20200709133608\img\charms\download.jpg
  • %TEMP%\driverpack-20200709133608\img\charms\computer.png
  • %TEMP%\driverpack-20200709133608\img\charms\arrow.png
  • %TEMP%\driverpack-20200709133608\img\charms\apps.jpg
  • %TEMP%\driverpack-20200709133608\img\burger\auto_installation.png
  • %TEMP%\driverpack-20200709133608\img\bugreport\bugreport_loader.gif
  • %TEMP%\driverpack-20200709133608\img\bugreport\bugreport_icon_skip.png
  • %TEMP%\driverpack-20200709133608\img\bugreport\bugreport_icon_previous.png
  • %TEMP%\driverpack-20200709133608\img\bugreport\bugreport_icon_ie.png
  • %TEMP%\driverpack-20200709133608\img\bugreport\bugreport_icon_alert.png
  • %TEMP%\driverpack-20200709133608\img\loading.gif
  • %TEMP%\driverpack-20200709133608\css\fonts\roboto\roboto-regular-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\roboto\roboto-light-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\drpcheckbox\drpcheckbox.ttf
  • %TEMP%\driverpack-20200709133608\css\blank.gif
  • %TEMP%\driverpack-20200709133608\css\roboto.css
  • %TEMP%\driverpack-20200709133608\css\proximanova.css
  • %TEMP%\driverpack-20200709133608\css\open-sans.css
  • %TEMP%\driverpack-20200709133608\css\normalize.min.css
  • %TEMP%\driverpack-20200709133608\css\lte-ie9.css
  • %TEMP%\driverpack-20200709133608\css\lte-ie8.css
  • %TEMP%\driverpack-20200709133608\css\ie7.css
  • %TEMP%\driverpack-20200709133608\css\ie6.css
  • %TEMP%\driverpack-20200709133608\css\icons.css
  • %TEMP%\driverpack-20200709133608\css\icons-checkbox.css
  • %TEMP%\driverpack-20200709133608\css\custom-control.css
  • %TEMP%\driverpack-20200709133608\tools\modules\bugreport.hta
  • %TEMP%\driverpack-20200709133608\css\fonts\drpcheckbox\drpcheckbox.eot
  • %TEMP%\driverpack-20200709133608\tools\run.hta
  • %TEMP%\driverpack-20200709133608\tools\patch.reg
  • %TEMP%\driverpack-20200709133608\tools\load8.gif
  • %TEMP%\driverpack-20200709133608\tools\icon.ico
  • %TEMP%\driverpack-20200709133608\run.hta
  • %TEMP%\driverpack-20200709133608\drp.js
  • %TEMP%\driverpack-20200709133608\drp.css
  • %TEMP%\driverpack-20200709133608\config.js
  • %TEMP%\driverpack-20200709133608\driverpacksolution.html
  • %TEMP%\nsa51ae.tmp\modern-header.bmp
  • %TEMP%\nsa51ae.tmp\system.dll
  • %TEMP%\driverpack-20200709133608\img\device-class\default.png
  • %TEMP%\res5458.tmp
  • %TEMP%\driverpack-20200709133608\css\fonts\drpcheckbox\drpcheckbox.svg
  • %TEMP%\driverpack-20200709133608\css\fonts\drpicons\drpicons-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\style.css
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_semibold-webfont.woff
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_semibold-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_semibold-webfont.svg
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_semibold-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_regular-webfont.woff
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_regular-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_regular-webfont.svg
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_regular-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_light-webfont.woff
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_light-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_light-webfont.svg
  • %TEMP%\driverpack-20200709133608\css\fonts\proximanova\proxima_nova_light-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\opensans-semibold-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\opensans-semibold-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\opensans-regular-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\opensans-regular-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\opensans-italic-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\opensans-italic-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\opensans-bold-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\opensans-bold-webfont.eot
  • %TEMP%\driverpack-20200709133608\css\fonts\open-sans\generator_config.txt
  • %TEMP%\driverpack-20200709133608\css\fonts\drpicons\drpicons-webfont.woff
  • %TEMP%\driverpack-20200709133608\css\fonts\drpicons\drpicons-webfont.ttf
  • %TEMP%\driverpack-20200709133608\css\fonts\drpicons\drpicons-webfont.svg
  • %TEMP%\driverpack-20200709133608\css\fonts\drpcheckbox\drpcheckbox.woff
  • %TEMP%\csc5418.tmp
  • %TEMP%\driverpack-20200709133608\img\device-class\inputdev.png
  • %TEMP%\driverpack-20200709133608\img\device-class\modem.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\less_normal.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\info_normal.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\info_hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\close_hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\close.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\cancel_hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\cancel_disable.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\cancel.png
  • %TEMP%\driverpack-20200709133608\img\installation\icon-installed.png
  • %TEMP%\driverpack-20200709133608\img\installation\icon-install.png
  • %TEMP%\driverpack-20200709133608\img\installation\icon-details.png
  • %TEMP%\driverpack-20200709133608\img\assistant-chat\no-sound-hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\confirm-popup-check-mark.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_yandex.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_virus-bg.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_social-vk.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_social-fb.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_social-bg-ru.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_social-bg-en.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_restore-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_protect-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_protect-bg-ru.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_protect-bg-pt-br.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_protect-bg-fr.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\controls\less_hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\more_hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\printer.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_protect-bg-en.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\controls\more_normal.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\phone.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\other.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\monitor.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\modem.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\massstorage.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\lan.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\inputdev.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\chipset.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\cardreader.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\bluetooth.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\scanner.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\notebook.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\dp_xusb.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\dp_touchpad.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\dp_tv_dvb.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\dp_printer.png
  • %TEMP%\driverpack-20200709133608\img\installation\drivers\dp_biometric.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\reload_hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\reload_disable.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\reload.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\play_hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\play.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\pause_hover.png
  • %TEMP%\driverpack-20200709133608\img\installation\controls\pause.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_protect-bg-es.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_win-10-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_protect-bg-de.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_opera-bg.gif
  • %TEMP%\driverpack-20200709133608\img\device-class\lan.png
  • %TEMP%\driverpack-20200709133608\img\fake-installation\connect.png
  • %TEMP%\driverpack-20200709133608\img\games\games-button-icon-green.png
  • %TEMP%\driverpack-20200709133608\img\games\games-bottom-logo.png
  • %TEMP%\driverpack-20200709133608\img\final\final_success$2x.png
  • %TEMP%\driverpack-20200709133608\img\final\final_partial-success$2x.png
  • %TEMP%\driverpack-20200709133608\img\final\final_main-cta-arrow$2x.png
  • %TEMP%\driverpack-20200709133608\img\final\final_failure$2x.png
  • %TEMP%\driverpack-20200709133608\img\final\final_button-warning$2x.png
  • %TEMP%\driverpack-20200709133608\img\final\final_aside-failure$2x.png
  • %TEMP%\driverpack-20200709133608\img\fake-installation\vpn.png
  • %TEMP%\driverpack-20200709133608\img\fake-installation\torrent.png
  • %TEMP%\driverpack-20200709133608\img\fake-installation\firewall.png
  • %TEMP%\driverpack-20200709133608\img\fake-installation\browser.png
  • %TEMP%\driverpack-20200709133608\img\games\games-cloud-big.png
  • %TEMP%\driverpack-20200709133608\img\device-class\wifi.png
  • %TEMP%\driverpack-20200709133608\img\device-class\webcamera.png
  • %TEMP%\driverpack-20200709133608\img\device-class\video.png
  • %TEMP%\driverpack-20200709133608\img\device-class\undefined-device.png
  • %TEMP%\driverpack-20200709133608\img\device-class\tvtuner.png
  • %TEMP%\driverpack-20200709133608\img\device-class\sound.png
  • %TEMP%\driverpack-20200709133608\img\device-class\printer.png
  • %TEMP%\driverpack-20200709133608\img\device-class\phone.png
  • %TEMP%\driverpack-20200709133608\img\device-class\other.png
  • %TEMP%\driverpack-20200709133608\img\device-class\monitor.png
  • %TEMP%\driverpack-20200709133608\img\games\games-cloud.png
  • %TEMP%\driverpack-20200709133608\img\device-class\massstorage.png
  • %TEMP%\driverpack-20200709133608\img\games\games-top-doom-large.jpg
  • %TEMP%\driverpack-20200709133608\img\games\games-top-gta.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_istart-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\games\games-button-icon-white.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_how-it-works-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_driverpack-for-all-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_cloud-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_catalog-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_catalog-bg-ru.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_catalog-bg-pt-br.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_catalog-bg-en.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_bullit-empty.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_bullit-active.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner_browsers-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_avast-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner_auth-bg.jpg
  • %TEMP%\driverpack-20200709133608\img\installation\banner-arrow-right.png
  • %TEMP%\driverpack-20200709133608\img\installation\banner-arrow-left.png
  • %TEMP%\driverpack-20200709133608\img\header\header-logo.png
  • %TEMP%\driverpack-20200709133608\img\header\header-logo$2x.png
  • %TEMP%\driverpack-20200709133608\img\header\header-bell.png
  • %TEMP%\driverpack-20200709133608\img\games\games-top-witcher.jpg
  • %TEMP%\driverpack-20200709133608\img\games\games-top-witcher-large.jpg
  • %TEMP%\driverpack-20200709133608\img\games\games-top-resident-evil.jpg
  • %TEMP%\driverpack-20200709133608\img\games\games-top-overwatch.jpg
  • %TEMP%\driverpack-20200709133608\img\games\games-top-mafia.jpg
  • %TEMP%\driverpack-20200709133608\img\games\games-top-hitman.jpg
  • %TEMP%\driverpack-20200709133608\img\games\games-top-doom.jpg
  • %TEMP%\k0ljji2u.dll
Deletes the following files
  • %TEMP%\nsa51ae.tmp\modern-header.bmp
  • %TEMP%\nsa51ae.tmp\system.dll
  • %TEMP%\res5458.tmp
  • %TEMP%\csc5418.tmp
  • %TEMP%\k0ljji2u.0.cs
  • %TEMP%\k0ljji2u.out
  • %TEMP%\k0ljji2u.cmdline
  • %TEMP%\k0ljji2u.dll
  • %TEMP%\k0ljji2u.pdb
Moves the following files
  • from %TEMP%\driverpack-20200709133608\tools\3jb28tom.part to %TEMP%\driverpack-20200709133608\tools\driverpack-wget.exe
Network activity
TCP
HTTP GET requests
  • http://al##ont.ru/allfont.css?fo##################
  • http://al##ont.ru/cache/css/lucida-console.css
  • http://do###oad.drp.su/updates/beetle/driverpack-wget.exe
  • http://up###e.drp.su/
  • http://up###e.drp.su/v2/soft/?ca######
  • http://www.go#####analytics.com/collect?v=#######################################################################################################################################################...
HTTP POST requests
  • http://au##.drp.su/api/session
  • http://up###e.drp.su/api/logs
  • 'mc.yandex.ru':443
  • UDP
    • DNS ASK al##ont.ru
    • DNS ASK au##.drp.su
    • DNS ASK up###e.drp.su
    • DNS ASK mc.yandex.ru
    • DNS ASK do###oad.drp.su
    • DNS ASK go#####analytics.com
    Miscellaneous
    Searches for the following windows
    • ClassName: 'MS_AutodialMonitor' WindowName: ''
    • ClassName: 'MS_WebCheckMonitor' WindowName: ''
    • ClassName: 'HTML Application Host Window Class' WindowName: ''
    Creates and executes the following
    • '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content '%APPDATA%\DRPSu\temp\ps.kcf94i2b.q6kus.cmd.txt' -Wait | Invoke-Expression"
    • '%WINDIR%\syswow64\cmd.exe' /C powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content '%APPDATA%\DRPSu\temp\ps.kcf94i2b.q6kus.cmd.txt' -Wait | Invoke-Expression" > "%APPDATA%\DRPSu\temp\ps.kcf9...' (with hidden window)
    • '%WINDIR%\syswow64\cmd.exe' /c "netsh advfirewall firewall delete rule name="DriverPack aria2c.exe" || echo Done & call echo Done %^errorLevel% > "%APPDATA%\DRPSu\temp\run_command_79239.txt""' (with hidden window)
    • '%WINDIR%\syswow64\cmd.exe' /c "netsh advfirewall firewall add rule name="DriverPack aria2c.exe" dir=in action=allow program="%TEMP%\DriverPack-20200709133608\tools\aria2c.exe" || echo Done & call echo Done %^errorLevel% ...' (with hidden window)
    • '%WINDIR%\syswow64\net.exe' start wscsvc' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\k0ljji2u.cmdline"' (with hidden window)
    • '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5458.tmp" "%TEMP%\CSC5418.tmp"' (with hidden window)
    Executes the following
    • '%WINDIR%\syswow64\reg.exe' import "%TEMP%\DriverPack-20200709133608\Tools\patch.reg"
    • '%WINDIR%\syswow64\mshta.exe' "%TEMP%\DriverPack-20200709133608\run.hta" --sfx "<File name>.exe"
    • '%WINDIR%\syswow64\cmd.exe' /C powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content '%APPDATA%\DRPSu\temp\ps.kcf94i2b.q6kus.cmd.txt' -Wait | Invoke-Expression" > "%APPDATA%\DRPSu\temp\ps.kcf9...
    • '%WINDIR%\syswow64\cmd.exe' /c "netsh advfirewall firewall delete rule name="DriverPack aria2c.exe" || echo Done & call echo Done %^errorLevel% > "%APPDATA%\DRPSu\temp\run_command_79239.txt""
    • '%WINDIR%\syswow64\netsh.exe' advfirewall firewall delete rule name="DriverPack aria2c.exe"
    • '%WINDIR%\syswow64\cmd.exe' /c "netsh advfirewall firewall add rule name="DriverPack aria2c.exe" dir=in action=allow program="%TEMP%\DriverPack-20200709133608\tools\aria2c.exe" || echo Done & call echo Done %^errorLevel% ...
    • '%WINDIR%\syswow64\net.exe' start wscsvc
    • '%WINDIR%\syswow64\net1.exe' start wscsvc
    • '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\k0ljji2u.cmdline"
    • '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5458.tmp" "%TEMP%\CSC5418.tmp"

    Рекомендации по лечению

    1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
    2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
    Скачать Dr.Web

    По серийному номеру

    Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

    На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

    Скачать Dr.Web

    По серийному номеру

    1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
    2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
      • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
      • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
      • выключите устройство и включите его в обычном режиме.

    Подробнее о Dr.Web для Android

    Демо бесплатно на 14 дней

    Выдаётся при установке