Защити созданное

Другие наши ресурсы

  • free.drweb.kz — бесплатные утилиты, плагины, информеры
  • av-desk.com — интернет-сервис для поставщиков услуг Dr.Web AV-Desk
  • curenet.drweb.kz — сетевая лечащая утилита Dr.Web CureNet!
Закрыть

Библиотека
Моя библиотека

Чтобы добавить ресурс в библиотеку, войдите в аккаунт.

+ Добавить в библиотеку

Ресурсов: -

Последний: -

Моя библиотека

Поддержка
Круглосуточная поддержка | Правила обращения

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen18.17419

Добавлен в вирусную базу Dr.Web: 2022-07-02

Описание добавлено:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'CSRSS' = '"%ALLUSERSPROFILE%\Drivers\csrss.exe"'
Modifies file system
Creates the following files
  • %ALLUSERSPROFILE%\drivers\csrss.exe
  • %TEMP%\4kpv6a~1\state.tmp
  • %TEMP%\4kpv6a~1\unverified-microdesc-consensus.tmp
  • %TEMP%\4kpv6a~1\cached-certs.tmp
  • %TEMP%\4kpv6a~1\cached-microdesc-consensus.tmp
  • %TEMP%\4kpv6a~1\cached-microdescs.new
Sets the 'hidden' attribute to the following files
  • %ALLUSERSPROFILE%\drivers\csrss.exe
Deletes the following files
  • %TEMP%\4kpv6a~1\unverified-microdesc-consensus
  • %TEMP%\4kpv6a~1\state
Moves the following files
  • from %TEMP%\4kpv6a~1\state.tmp to %TEMP%\4kpv6a~1\state
  • from %TEMP%\4kpv6a~1\unverified-microdesc-consensus.tmp to %TEMP%\4kpv6a~1\unverified-microdesc-consensus
  • from %TEMP%\4kpv6a~1\cached-certs.tmp to %TEMP%\4kpv6a~1\cached-certs
  • from %TEMP%\4kpv6a~1\cached-microdesc-consensus.tmp to %TEMP%\4kpv6a~1\cached-microdesc-consensus
Substitutes the following files
  • %TEMP%\4kpv6a~1\state.tmp
  • %TEMP%\4kpv6a~1\state
Network activity
Connects to
  • 'localhost':49174
  • 'so####alemfire.com':443
  • 'pm###king.com':443
  • 'vh###eative.com':443
  • 'ep#####e-etancheite.fr':80
  • '12#.ac':443
  • 'pe####sion.co.nz':80
  • 'ml##bco.com':80
  • 'tr###shaus.com':80
  • 'to####learning.com':443
  • 'ma###cox.com':443
  • 'bl###n.com.ar':80
  • 'ph#####teeshirts.com':80
  • 'ex#####vecompany.com':80
  • 'ap###nsion.com':80
  • 'gs######ltingservices.com':80
  • 'mp##let.com':80
  • 'tr####usefarm.com':80
  • 'pg###nomides.eu':80
  • 'zh###aner.me':80
  • 'ib##480.org':80
  • 'fi#####passport.com.au':80
  • 'ko###.com.iki.kr':80
  • 'ha##ate.com':80
  • 'cc####ellcpa.com':80
  • 'gr#####vesgagnon.com':80
  • 'kr#####rundgarten.de':80
  • 'oc####apital.com':80
  • 're###ngtile.com':443
  • 'kc##s.com':443
  • '5s####enceco.com':443
  • 'ra###marine.com':443
  • 'tw###as.com.au':443
  • 'ab######ly-organized.com':443
  • 'eb####struction.net':443
  • 'ar###vance.com':443
  • 'ma#####onstruction.com':443
  • 'ex#####vecompany.com':443
  • 'pa#####gsbylizzie.com':80
  • 'ar###vance.com':80
  • 'sites.google.com':443
  • 'be#.kr':80
  • 'cl##by.com':443
  • 'br###jar.com':80
  • 'bl###n.com.ar':443
  • 'hu###omains.com':443
  • 'ml##bco.com':443
  • 'fi#####passport.com.au':443
  • 'sites.google.com':80
  • 'tr####usefarm.com':443
  • 'kr#####rundgarten.de':443
  • 'ep#####e-etancheite.fr':443
  • 'gr####nmocosta.com':443
  • 'pg###nomides.eu':443
  • 'jc##ft.com':443
  • 'jo###-lee.com':443
  • 'yh##s.com':80
  • 'eb####struction.net':80
  • 'sh#r.ps':80
  • 'ya####stersinc.com':80
  • 'sc####ofence.com':80
  • 'di####tobject.com':80
  • 'pm###king.com':80
  • 've####lisation.pro':80
  • 'so#####nbackwoods.com':80
  • 'to###alms.com':80
  • 'my####tyzone.com':80
  • 'ba###ome.com':80
  • 'je###ectric.com':80
  • 'ma###cox.com':80
  • 'st####orcela.com':80
  • 'fa###azaman.com':80
  • 'mi####iologist.net':80
  • 'ma####olinari.com':80
  • 'ak#.net.au':80
  • '10#.uk':80
  • 'un#####alformtops.com':80
  • 'jo####nline.com.au':80
  • 'localhost':40080
  • '23.##0.14.226':443
  • '5.###.134.99':9001
  • '14#.#39.66.236':9001
  • '62.##0.123.24':443
  • 'pe###harben.com':80
  • 'bl###asellc.com':80
  • 'cl##by.com':80
  • '5s####enceco.com':80
  • 'ab######ly-organized.com':80
  • 'no####lemppc.com':80
  • 'vi###moto.com':80
  • 'arwindows.com':80
  • 'ho#####rgs-maleri.se':80
  • 'ma##iny.com':80
  • 'kc##s.com':80
  • '12#.ac':80
  • 'so####alemfire.com':80
  • 'gr####nmocosta.com':80
  • 'pr####eenville.com':80
  • 're###ngtile.com':80
  • 'si##ert.com':80
  • 'am##cs.com':443
  • 'me#####cerecords.com':443
  • 'vh###eative.com':80
  • 'yb##k.com':80
  • 'pa######oastplumbing.com.au':80
  • 'ou####lerock.com':80
  • 'ne####ventures.com':80
  • 'fa###rano.net':80
  • 'me#####cerecords.com':80
  • 'de###r.co.za':80
  • 'jo###-lee.com':80
  • 'th#####woodfamily.com':80
  • 'ra###marine.com':80
  • 'tw###as.com.au':80
  • 'am##cs.com':80
  • 'ba###ome.com':443
TCP
HTTP GET requests
  • http://x5###############dj2m6eq4amkkpndbqyvmvaz6yl4mmfco6oqxsqd.onion/upd.php?n=#################################################################################################################...
  • http://my####tyzone.com/admin/
  • http://sc####ofence.com/admin
  • http://no####lemppc.com/admin/
  • http://tr####usefarm.com/wp-admin/
  • http://10#.uk/admin/
  • http://mp##let.com/admin
  • http://so#####nbackwoods.com/admin/
  • http://di####tobject.com/admin/
  • http://fa###azaman.com/wp-admin/
  • http://vh###eative.com/wp-admin/
  • http://ja######bsassociates.com/wp-admin/
  • http://fi#####passport.com.au/administrator/index.php
  • http://cs####design.com/admin
  • http://zh###aner.me/wp-admin/
  • http://jo###-lee.com/wp-login.php
  • http://www.gr#####vesgagnon.com/administrator/
  • http://ja######bsassociates.com/wp-login.php
  • http://arwindows.com/admin/
  • http://12#.ac/wp-login.php
  • http://ak#.net.au/admin
  • http://pm###king.com/wp-login.php
  • http://to###alms.com/admin.php
  • http://ex#####vecompany.com/administrator/index.php
  • http://kr#####rundgarten.de/wp-admin/
  • http://br###jar.com/admin.php
  • http://ne####ventures.com/admin
  • http://me#####cerecords.com/wp-login.php
  • http://gs######ltingservices.com/admin
  • http://ha##ate.com/admin/
  • http://kc##s.com/administrator/index.php
  • http://bl###n.com.ar/wp-login.php
  • http://tr###shaus.com/wp-admin/
  • http://je###ectric.com/admin/
  • http://ww##.#hijianer.me/wp-admin/
  • http://cc####ellcpa.com/admin
  • http://ra###marine.com/wp-login.php
  • http://in####orbymd.com/admin.php
  • http://us###eys.com/wp-login.php
  • http://kc##s.com/wp-login.php
  • http://www.ma##iny.com/wp-login.php
  • http://jo###-lee.com/wp-admin/
  • http://tr###shaus.com/wp-login.php
  • http://jo####nline.com.au/admin
  • http://ma##iny.com/wp-admin/
  • http://ph#####teeshirts.com/admin.php
  • http://yb##k.com/admin
  • http://mi####iologist.net/admin/
  • http://ib##480.org/admin
  • http://ma#####onstruction.com/wp-login.php
  • http://ho#####rgs-maleri.se/admin/
  • http://vi###moto.com/admin
  • http://ml##bco.com/wp-login.php
  • http://oc####apital.com/admin
  • http://si##ert.com/admin/
  • http://kr#####rundgarten.de/admin.php
  • http://fa###rano.net/admin/
  • http://ya####stersinc.com/wp-login.php
  • http://ba###ome.com/wp-login.php
  • http://ab######ly-organized.com/wp-login.php
  • http://my####tyzone.com/admin
  • http://st####orcela.com/wp-admin/
  • http://be#.kr/
  • http://ar###vance.com/
  • http://tw###as.com.au/wp-login.php
  • http://5s####enceco.com/wp-admin/
  • http://ja######bsassociates.com/administrator/index.php
  • http://www.pa#####gsbylizzie.com/
  • http://st####orcela.com/wp-login.php
  • http://jo####nline.com.au/admin.php
  • http://jc##ft.com/wp-admin/
  • http://to###alms.com/wp-admin/
  • http://in####orbymd.com/wp-login.php
  • http://mi####iologist.net/admin
  • http://10#.uk/admin
  • http://ve####lisation.pro/wp-login.php
  • http://vh###eative.com/wp-login.php
  • http://ml##bco.com/administrator/index.php
  • http://kr#####rundgarten.de/wp-login.php
  • http://arwindows.com/admin
  • http://ha##ate.com/admin
  • http://jc##ft.com/wp-login.php
  • http://si##ert.com/admin
  • http://ho#####rgs-maleri.se/admin
  • http://sh#r.ps/admin.php
  • http://cs####design.com/admin.php
  • http://eb####struction.net/wp-login.php
  • http://tw###as.com.au/wp-admin/
  • http://bl###n.com.ar/administrator/index.php
  • http://pe###harben.com/admin
  • http://pg###nomides.eu/wp-login.php
  • http://yb##k.com/admin.php
  • http://vi###moto.com/admin.php
  • http://cc####ellcpa.com/admin.php
  • http://bl###asellc.com/admin
  • http://oc####apital.com/admin.php
  • http://ma####olinari.com/admin
  • http://sh#r.ps/admin
  • http://zh###aner.me/wp-login.php
  • http://sc####ofence.com/admin.php
  • http://so####alemfire.com/wp-login.php
  • http://fa###azaman.com/wp-login.php
  • http://ma##iny.com/wp-login.php
  • http://yh##s.com/wp-login.php
  • http://ib##480.org/admin.php
  • http://gr####nmocosta.com/wp-login.php
  • http://in####orbymd.com/wp-admin/
  • http://un#####alformtops.com/admin
  • http://gs######ltingservices.com/admin.php
  • http://je###ectric.com/admin
  • http://re###ngtile.com/wp-login.php
  • http://ep#####e-etancheite.fr/wp-login.php
  • http://ma#####onstruction.com/administrator/index.php
  • http://mp##let.com/admin.php
  • http://us###eys.com/administrator/index.php
  • http://www.ko###.com.iki.kr/administrator/index.php
  • http://ww##.#hijianer.me/administrator/index.php
  • http://cs####design.com/admin/
  • http://kr#####rundgarten.de/admin
  • http://gr####nmocosta.com/admin
  • http://www.ko###.com.iki.kr/admin.php
  • http://pm###king.com/admin
  • http://so####alemfire.com/admin
  • http://fi#####passport.com.au/wp-login.php
  • http://12#.ac/admin
  • http://pg###nomides.eu/admin
  • http://ex#####vecompany.com/wp-admin/
  • http://vh###eative.com/admin
  • http://www.ma##iny.com/admin
  • http://in####orbymd.com/admin/
  • http://tr###shaus.com/admin
  • http://12#.ac/admin.php
  • http://us###eys.com/admin.php
  • http://www.ko###.com.iki.kr/wp-admin/
  • http://tr####usefarm.com/admin
  • http://gr#####vesgagnon.com/wp-login.php
  • http://ma##iny.com/admin
  • http://ja######bsassociates.com/admin
  • http://st####orcela.com/admin
  • http://th#####woodfamily.com/wp-login.php
  • http://to###alms.com/admin/
  • http://us###eys.com/wp-admin/
  • http://jo####nline.com.au/admin/
  • http://ph#####teeshirts.com/admin/
  • http://ww##.#hijianer.me/admin
  • http://sh#r.ps/wp-login.php
  • http://br###jar.com/admin/
  • http://pg###nomides.eu/admin/
  • http://vh###eative.com/admin/
  • http://ve####lisation.pro/admin.php
  • http://th#####woodfamily.com/admin.php
  • http://us###eys.com/admin
  • http://ex#####vecompany.com/admin
  • http://tr####usefarm.com/admin/
  • http://www.ma##iny.com/admin/
  • http://5s####enceco.com/admin.php
  • http://tr###shaus.com/admin/
  • http://pe####sion.co.nz/admin.php
  • http://ja######bsassociates.com/admin/
  • http://jo###-lee.com/admin
  • http://www.sa#####gnessdesign.com/admin/
  • http://th#####woodfamily.com/wp-admin/
  • http://ww##.#hijianer.me/admin/
  • http://ep#####e-etancheite.fr/wp-admin
  • http://zh###aner.me/admin/
  • http://ve####lisation.pro/wp-admin/
  • http://kr#####rundgarten.de/admin/
  • http://jc##ft.com/admin/
  • http://am##cs.com/wp-login.php
  • http://pe####sion.co.nz/wp-admin/
  • http://re###ngtile.com/admin
  • http://ex#####vecompany.com/admin.php
  • http://ma#####onstruction.com/admin
  • http://www.ko###.com.iki.kr/admin
  • http://cl##by.com/wp-login.php
  • http://gr#####vesgagnon.com/administrator/index.php
  • http://pe####sion.co.nz/administrator/index.php
  • http://pe####sion.co.nz/wp-login.php
  • http://vh###eative.com/admin.php
  • http://ma###cox.com/wp-login.php
  • http://st####orcela.com/admin.php
  • http://ak#.net.au/admin/
  • http://br###jar.com/admin
  • http://jo###-lee.com/admin.php
  • http://fa###azaman.com/admin.php
  • http://www.ko###.com.iki.kr/wp-login.php
  • http://zh###aner.me/admin.php
  • http://bl###asellc.com/admin/
  • http://cl########.fitnesspassport.com.au/administrator/
  • http://sh#r.ps/admin/
  • http://ma####olinari.com/admin/
  • http://ja######bsassociates.com/admin.php
  • http://gr####nmocosta.com/wp-admin/
  • http://un#####alformtops.com/admin/
  • http://pm###king.com/wp-admin/
  • http://ex#####vecompany.com/wp-login.php
  • http://jc##ft.com/admin.php
  • http://so####alemfire.com/wp-admin/
  • http://to###alms.com/admin
  • http://www.ma##iny.com/wp-admin/
  • http://re###ngtile.com/wp-admin/
  • http://ma#####onstruction.com/wp-admin/
  • http://pg###nomides.eu/wp-admin/
  • http://pe###harben.com/admin/
  • http://pg###nomides.eu/admin.php
  • http://pm###king.com/admin.php
  • http://yb##k.com/admin/
  • http://jc##ft.com/admin
  • http://ma#####onstruction.com/admin.php
  • http://so####alemfire.com/admin.php
  • http://cl##by.com/administrator/index.php
  • http://www.sa#####gnessdesign.com/admin
  • http://vi###moto.com/admin/
  • http://sc####ofence.com/admin/
  • http://re###ngtile.com/admin.php
  • http://www.ma##iny.com/admin.php
  • http://gr####nmocosta.com/admin.php
  • http://cc####ellcpa.com/admin/
  • http://mp##let.com/admin/
  • http://fa###azaman.com/admin
  • http://zh###aner.me/admin
  • http://tr####usefarm.com/admin.php
  • http://ib##480.org/admin/
  • http://gs######ltingservices.com/admin/
  • http://12#.ac/wp-admin/
  • http://ww##.#hijianer.me/admin.php
  • http://am##cs.com/administrator/index.php
  • http://ma##iny.com/admin.php
  • http://in####orbymd.com/admin
  • http://th#####woodfamily.com/administrator/index.php
  • http://tr###shaus.com/admin.php
  • http://ne####ventures.com/admin/
  • http://ph#####teeshirts.com/admin
  • http://oc####apital.com/admin/
  • http://pe###harben.com/admin.php
  • http://ak#.net.au/admin.php
  • http://fa###rano.net/admin
  • http://so#####nbackwoods.com/administrator/
  • http://yh##s.com/administrator/
  • http://br###jar.com/administrator/index.php
  • http://pe###harben.com/administrator/index.php
  • http://cc####ellcpa.com/administrator/
  • http://ha##ate.com/administrator/index.php
  • http://si##ert.com/administrator/index.php
  • http://sh#r.ps/administrator/
  • http://vi###moto.com/administrator/
  • http://oc####apital.com/administrator/
  • http://st####orcela.com/administrator/
  • http://eb####struction.net/administrator/
  • http://gr#####vesgagnon.com/administrator/
  • http://arwindows.com/administrator/index.php
  • http://bl###asellc.com/administrator/index.php
  • http://ak#.net.au/administrator/index.php
  • http://ma##iny.com/administrator/
  • http://ab######ly-organized.com/administrator/
  • http://pr####eenville.com/administrator/
  • http://ho#####rgs-maleri.se/administrator/index.php
  • http://kc##s.com/administrator/
  • http://jo###-lee.com/administrator/
  • http://ha##ate.com/administrator/
  • http://re###ngtile.com/administrator/
  • http://th#####woodfamily.com/administrator/
  • http://pg###nomides.eu/administrator/
  • http://my####tyzone.com/wp-login.php
  • http://ib##480.org/administrator/
  • http://fa###rano.net/wp-login.php
  • http://ph#####teeshirts.com/administrator/index.php
  • http://mi####iologist.net/wp-admin/
  • http://ep#####e-etancheite.fr/administrator
  • http://mp##let.com/administrator/index.php
  • http://ib##480.org/administrator/index.php
  • http://tr###shaus.com/administrator/
  • http://arwindows.com/wp-login.php
  • http://gs######ltingservices.com/administrator/index.php
  • http://mi####iologist.net/wp-login.php
  • http://sc####ofence.com/administrator/index.php
  • http://10#.uk/wp-login.php
  • http://tw###as.com.au/administrator/
  • http://10#.uk/wp-admin/
  • http://ph#####teeshirts.com/administrator/
  • http://vi###moto.com/administrator/index.php
  • http://www.ko###.com.iki.kr/administrator/
  • http://yb##k.com/administrator/index.php
  • http://my####tyzone.com/wp-admin/
  • http://fi#####passport.com.au/administrator/
  • http://zh###aner.me/administrator/
  • http://oc####apital.com/administrator/index.php
  • http://mp##let.com/administrator/
  • http://gs######ltingservices.com/administrator/
  • http://tr####usefarm.com/administrator/
  • http://so#####nbackwoods.com/administrator/index.php
  • http://sh#r.ps/administrator/index.php
  • http://no####lemppc.com/administrator/index.php
  • http://www.us###eys.com/
  • http://ne####ventures.com/administrator/index.php
  • http://ja######bsassociates.com/administrator/
  • http://us###eys.com/administrator/
  • http://no####lemppc.com/administrator/
  • http://cs####design.com/administrator/index.php
  • http://jc##ft.com/administrator/
  • http://in####orbymd.com/administrator/
  • http://di####tobject.com/administrator/
  • http://pm###king.com/administrator/
  • http://10#.uk/administrator/index.php
  • http://ak#.net.au/administrator/
  • http://ve####lisation.pro/administrator/
  • http://my####tyzone.com/administrator/
  • http://to###alms.com/administrator/
  • http://mi####iologist.net/administrator/index.php
  • http://ma###cox.com/administrator/
  • http://cs####design.com/administrator/
  • http://un#####alformtops.com/administrator/index.php
  • http://ma####olinari.com/administrator/
  • http://jo####nline.com.au/administrator/
  • http://je###ectric.com/administrator/
  • http://mi####iologist.net/administrator/
  • http://10#.uk/administrator/
  • http://un#####alformtops.com/administrator/
  • http://x5###############dj2m6eq4amkkpndbqyvmvaz6yl4mmfco6oqxsqd.onion/reg.php?n=#####################################################
  • http://x5###############dj2m6eq4amkkpndbqyvmvaz6yl4mmfco6oqxsqd.onion/task.php?n=################################################################################################################...
  • http://di####tobject.com/administrator/index.php
  • http://je###ectric.com/administrator/index.php
  • http://ma####olinari.com/administrator/index.php
  • http://fa###rano.net/administrator/
  • http://fa###rano.net/administrator/index.php
  • http://kr#####rundgarten.de/administrator/
  • http://so####alemfire.com/administrator/
  • http://ma#####onstruction.com/administrator/
  • http://yb##k.com/administrator/
  • http://vh###eative.com/administrator/
  • http://jo####nline.com.au/administrator/index.php
  • http://me#####cerecords.com/administrator/
  • http://cl##by.com/administrator/
  • http://pe###harben.com/administrator/
  • http://sc####ofence.com/administrator/
  • http://ya####stersinc.com/administrator/
  • http://fa###azaman.com/administrator/
  • http://ba###ome.com/administrator/index.php
  • http://5s####enceco.com/administrator/
  • http://ho#####rgs-maleri.se/administrator/
  • http://si##ert.com/administrator/
  • http://arwindows.com/administrator/
  • http://gr####nmocosta.com/administrator/
  • http://ra###marine.com/administrator/
  • http://bl###asellc.com/administrator/
  • http://12#.ac/administrator/
  • http://x5###############dj2m6eq4amkkpndbqyvmvaz6yl4mmfco6oqxsqd.onion/hb.php?n=#############################
  • http://am##cs.com/administrator/
  • http://ba###ome.com/administrator/
  • http://ne####ventures.com/administrator/
  • http://br###jar.com/administrator/
  • http://my####tyzone.com/administrator/index.php
  • http://ex#####vecompany.com/administrator/
  • http://ml##bco.com/administrator/
  • http://www.ma##iny.com/administrator/index.php
  • http://ph#####teeshirts.com/wp-admin/
  • http://sites.google.com/a/thekirkwoodfamily.com/www/The-Kirkwood-Family
  • http://di####tobject.com/admin.php
  • http://gs######ltingservices.com/wp-login.php
  • http://pg###nomides.eu/administrator/index.php
  • http://si##ert.com/admin.php
  • http://ab######ly-organized.com/administrator/index.php
  • http://mp##let.com/wp-login.php
  • http://ib##480.org/wp-login.php
  • http://vi###moto.com/wp-login.php
  • http://so####alemfire.com/administrator/index.php
  • http://ne####ventures.com/admin.php
  • http://mi####iologist.net/admin.php
  • http://cc####ellcpa.com/wp-login.php
  • http://re###ngtile.com/administrator/index.php
  • http://tr####usefarm.com/administrator/index.php
  • http://oc####apital.com/wp-login.php
  • http://arwindows.com/admin.php
  • http://ha##ate.com/admin.php
  • http://yb##k.com/wp-login.php
  • http://ph#####teeshirts.com/wp-login.php
  • http://ww##.#hijianer.me/administrator/
  • http://st####orcela.com/administrator/index.php
  • http://ma##iny.com/administrator/index.php
  • http://to###alms.com/wp-login.php
  • http://yh##s.com/administrator/index.php
  • http://yb##k.com/wp-admin/
  • http://tr####usefarm.com/wp-login.php
  • http://zh###aner.me/administrator/index.php
  • http://12#.ac/administrator/index.php
  • http://ra###marine.com/administrator/index.php
  • http://jo###-lee.com/administrator/index.php
  • http://di####tobject.com/admin
  • http://so#####nbackwoods.com/admin
  • http://ma###cox.com/administrator/index.php
  • http://5s####enceco.com/wp-login.php
  • http://bl###asellc.com/admin.php
  • http://cc####ellcpa.com/wp-admin/
  • http://ma####olinari.com/admin.php
  • http://no####lemppc.com/admin
  • http://fa###azaman.com/administrator/index.php
  • http://oc####apital.com/wp-admin/
  • http://jo####nline.com.au/wp-admin/
  • http://10#.uk/admin.php
  • http://pm###king.com/administrator/index.php
  • http://vi###moto.com/wp-admin/
  • http://tr###shaus.com/administrator/index.php
  • http://gs######ltingservices.com/wp-admin/
  • http://ib##480.org/wp-admin/
  • http://un#####alformtops.com/admin.php
  • http://gr####nmocosta.com/administrator/index.php
  • http://sc####ofence.com/wp-admin/
  • http://mp##let.com/wp-admin/
  • http://so#####nbackwoods.com/admin.php
  • http://fa###rano.net/admin.php
  • http://je###ectric.com/admin.php
  • http://ho#####rgs-maleri.se/admin.php
  • http://tw###as.com.au/administrator/index.php
  • http://cc####ellcpa.com/administrator/index.php
  • http://cs####design.com/wp-admin/
  • http://ha##ate.com/wp-admin/
  • http://ya####stersinc.com/administrator/index.php
  • http://ho#####rgs-maleri.se/wp-admin/
  • http://je###ectric.com/wp-admin/
  • http://no####lemppc.com/wp-admin/
  • http://www.sa#####gnessdesign.com/administrator/
  • http://so#####nbackwoods.com/wp-login.php
  • http://my####tyzone.com/admin.php
  • http://si##ert.com/wp-login.php
  • http://ha##ate.com/wp-login.php
  • http://un#####alformtops.com/wp-login.php
  • http://st####orcela.com/admin/
  • http://in####orbymd.com/administrator/index.php
  • http://ho#####rgs-maleri.se/wp-login.php
  • http://fa###rano.net/wp-admin/
  • http://di####tobject.com/wp-admin/
  • http://pe####sion.co.nz/administrator/
  • http://cs####design.com/wp-login.php
  • http://to###alms.com/administrator/index.php
  • http://arwindows.com/wp-admin/
  • http://di####tobject.com/wp-login.php
  • http://je###ectric.com/wp-login.php
  • http://no####lemppc.com/wp-login.php
  • http://5s####enceco.com/administrator/index.php
  • http://bl###n.com.ar/administrator/
  • http://ne####ventures.com/wp-login.php
  • http://ma##iny.com/admin/
  • http://br###jar.com/wp-login.php
  • http://ma####olinari.com/wp-login.php
  • http://eb####struction.net/administrator/index.php
  • http://no####lemppc.com/admin.php
  • http://sc####ofence.com/wp-login.php
  • http://sh#r.ps/wp-admin/
  • http://ep#####e-etancheite.fr/administrator/index.php
  • http://vh###eative.com/administrator/index.php
  • http://ak#.net.au/wp-admin/
  • http://www.ra###marine.com/administrator/
  • http://www.ma##iny.com/administrator/
  • http://sites.google.com/a/usdaveys.com/sites/system/app/pages/meta/domainWelcome
  • http://kr#####rundgarten.de/administrator/index.php
  • http://ve####lisation.pro/administrator/index.php
  • http://bl###asellc.com/wp-login.php
  • http://pe###harben.com/wp-admin/
  • http://so#####nbackwoods.com/wp-admin/
  • http://jo####nline.com.au/wp-login.php
  • http://me#####cerecords.com/administrator/index.php
  • http://bl###asellc.com/wp-admin/
  • http://ma####olinari.com/wp-admin/
  • http://br###jar.com/wp-admin/
  • http://ak#.net.au/wp-login.php
  • http://un#####alformtops.com/wp-admin/
  • http://www.th#####woodfamily.com/
  • http://pe###harben.com/wp-login.php
  • http://ne####ventures.com/wp-admin/
  • http://si##ert.com/wp-admin/
  • http://jc##ft.com/administrator/index.php
  • http://pm###king.com/admin/
HTTP POST requests
  • http://ya####stersinc.com/wp-login.php
  • http://yh##s.com/wp-login.php
  • http://www.gr#####vesgagnon.com/wp-login.php
Other
  • '62.##0.123.24':443
  • 'localhost':49709
  • 'localhost':49718
  • 'localhost':49716
  • 'localhost':49719
  • 'localhost':49697
  • 'localhost':49723
  • 'localhost':49703
  • 'localhost':49728
  • 'localhost':49730
  • 'localhost':49754
  • 'localhost':49755
  • 'localhost':49756
  • 'localhost':49726
  • 'localhost':49758
  • 'localhost':49732
  • 'localhost':49700
  • 'localhost':49693
  • 'localhost':49689
  • 'localhost':49596
  • 'localhost':49599
  • 'localhost':49632
  • 'localhost':49634
  • 'localhost':49633
  • 'localhost':49595
  • 'localhost':49635
  • 'localhost':49644
  • 'localhost':49646
  • 'localhost':49643
  • 'localhost':49649
  • 'localhost':49668
  • 'localhost':49680
  • 'localhost':49639
  • 'localhost':49687
  • 'localhost':49591
  • 'localhost':49594
  • 'localhost':49759
  • 'localhost':49778
  • 'localhost':49837
  • 'localhost':49840
  • 'localhost':49838
  • 'localhost':49839
  • 'localhost':49841
  • 'localhost':49835
  • 'localhost':49836
  • 'localhost':49842
  • 'localhost':49845
  • 'localhost':49847
  • 'localhost':49848
  • 'localhost':49853
  • 'localhost':49868
  • 'localhost':49843
  • 'localhost':49844
  • 'localhost':49833
  • 'localhost':49827
  • 'tw###as.com.au':443
  • 'localhost':49785
  • 'localhost':49783
  • 'localhost':49787
  • 'localhost':49790
  • 'localhost':49797
  • 'localhost':49801
  • 'localhost':49815
  • 'localhost':49821
  • 'localhost':49817
  • 'localhost':49823
  • 'localhost':49824
  • 'localhost':49825
  • 'localhost':49826
  • 'localhost':49764
  • 'localhost':49771
  • 'localhost':49765
  • 'ba###ome.com':443
  • 'localhost':49592
  • 'localhost':49590
  • 're###ngtile.com':443
  • 'in####orbymd.com':443
  • 'tr####usefarm.com':443
  • 'hu###omains.com':443
  • 'kr#####rundgarten.de':443
  • 'ml##bco.com':443
  • 'gr####nmocosta.com':443
  • 'bl###n.com.ar':443
  • 'am##cs.com':443
  • 'sites.google.com':443
  • 'ex#####vecompany.com':443
  • 'ma#####onstruction.com':443
  • 'fi#####passport.com.au':443
  • 'so####alemfire.com':443
  • 'cl##by.com':443
  • 'pg###nomides.eu':443
  • 'ep#####e-etancheite.fr':443
  • '14#.#39.66.236':9001
  • '23.##0.14.226':443
  • 'localhost':40080
  • 'localhost':49181
  • 'localhost':49183
  • 'localhost':49184
  • 'localhost':49185
  • '5.###.134.99':9001
  • 'localhost':49186
  • 'to####learning.com':443
  • '12#.ac':443
  • 'pm###king.com':443
  • 'vh###eative.com':443
  • 'jc##ft.com':443
  • 'localhost':49404
  • 'ma###cox.com':443
  • 'localhost':49433
  • 'kc##s.com':443
  • 'localhost':49436
  • 'localhost':49528
  • 'localhost':49530
  • 'localhost':49531
  • 'localhost':49518
  • 'localhost':49535
  • 'localhost':49547
  • 'localhost':49548
  • 'localhost':49575
  • 'ra###marine.com':443
  • 'google.com':443
  • '5s####enceco.com':443
  • 'localhost':49589
  • 'cl########.fitnesspassport.com.au':443
  • 'me#####cerecords.com':443
  • 'localhost':49527
  • 'localhost':49441
  • 'localhost':49529
  • 'localhost':49829
  • 'localhost':49865
  • 'localhost':49520
  • 'localhost':49450
  • 'localhost':49451
  • 'localhost':49489
  • 'localhost':49492
  • 'localhost':49484
  • 'eb####struction.net':443
  • 'ar###vance.com':443
  • 'localhost':49500
  • 'localhost':49495
  • 'ab######ly-organized.com':443
  • 'localhost':49506
  • 'localhost':49516
  • 'localhost':49519
  • 'localhost':49523
  • 'localhost':49499
  • 'localhost':49526
  • 'localhost':49869
UDP
  • DNS ASK ho#####rgs-maleri.se
  • DNS ASK ra####.k12.wi.us
  • DNS ASK tr###shaus.com
  • DNS ASK pa######oastplumbing.com.au
  • DNS ASK cg###ranite.com
  • DNS ASK bp####.yahoo.com
  • DNS ASK pe###harben.com
  • DNS ASK ph#####teeshirts.com
  • DNS ASK no####lemppc.com
  • DNS ASK gr####nmocosta.com
  • DNS ASK gm.###vs.hc.edu.tw
  • DNS ASK so####alemfire.com
  • DNS ASK bl###24555.com
  • DNS ASK 12#.ac
  • DNS ASK tr####usefarm.com
  • DNS ASK st####ussell.com
  • DNS ASK si##ert.com
  • DNS ASK de###r.co.za
  • DNS ASK fa###azaman.com
  • DNS ASK us###eys.com
  • DNS ASK tw###as.com.au
  • DNS ASK cl##by.com
  • DNS ASK ra###marine.com
  • DNS ASK di####tobject.com
  • DNS ASK zh###aner.me
  • DNS ASK ja######bsassociates.com
  • DNS ASK gs######ltingservices.com
  • DNS ASK google.com
  • DNS ASK br###jar.com
  • DNS ASK pa#####gsbylizzie.com
  • DNS ASK ar###vance.com
  • DNS ASK be#.kr
  • DNS ASK hu###omains.com
  • DNS ASK ww##.#hijianer.me
  • DNS ASK sites.google.com
  • DNS ASK st######ceproductions.com
  • DNS ASK sa#####gnessdesign.com
  • DNS ASK ep#####e-etancheite.fr
  • DNS ASK to####learning.com
  • DNS ASK ou####lerock.com
  • DNS ASK ye###ldings.com
  • DNS ASK th#####woodfamily.com
  • DNS ASK ex#####vecompany.com
  • DNS ASK so#####nbackwoods.com
  • DNS ASK pr####eenville.com
  • DNS ASK ri######velopments.com.au
  • DNS ASK ap###nsion.com
  • DNS ASK ml##bco.com
  • DNS ASK jo###-lee.com
  • DNS ASK pe####sion.co.nz
  • DNS ASK fa###rano.net
  • DNS ASK mp##let.com
  • DNS ASK re###ngtile.com
  • DNS ASK ne####ventures.com
  • DNS ASK fr#.#tn.edu.ar
  • DNS ASK kc##s.com
  • DNS ASK tw####nesalberta.ca
  • DNS ASK ab######ly-organized.com
  • DNS ASK vh###eative.com
  • DNS ASK ha##ate.com
  • DNS ASK oc####apital.com
  • DNS ASK vi###moto.com
  • DNS ASK mi####iologist.net
  • DNS ASK pm###king.com
  • DNS ASK ma#####onstruction.com
  • DNS ASK ag###biker.com
  • DNS ASK je###ectric.com
  • DNS ASK tt##i0g.com
  • DNS ASK cs####design.com
  • DNS ASK me#####cerecords.com
  • DNS ASK st####orcela.com
  • DNS ASK arwindows.com
  • DNS ASK ma##iny.com
  • DNS ASK ma#####lassoc.plus.com
  • DNS ASK ma####olinari.com
  • DNS ASK in####orbymd.com
  • DNS ASK 10#.uk
  • DNS ASK jo####nline.com.au
  • DNS ASK jc##ft.com
  • DNS ASK un#####alformtops.com
  • DNS ASK ak#.net.au
  • DNS ASK yb##k.com
  • DNS ASK ko###.com.iki.kr
  • DNS ASK ja#####nredningar.se
  • DNS ASK gr#####vesgagnon.com
  • DNS ASK ve####lisation.pro
  • DNS ASK to###alms.com
  • DNS ASK to######nerichardson.com
  • DNS ASK kl#####nt.kptm.edu.my
  • DNS ASK bl###n.com.ar
  • DNS ASK ib##480.org
  • DNS ASK ba###ome.com
  • DNS ASK pg###nomides.eu
  • DNS ASK ya####stersinc.com
  • DNS ASK gs.##.energy.gov.ua
  • DNS ASK ma###cox.com
  • DNS ASK bl###asellc.com
  • DNS ASK sc####ofence.com
  • DNS ASK fi#####passport.com.au
  • DNS ASK 5s####enceco.com
  • DNS ASK yh##s.com
  • DNS ASK li###e.co.uk
  • DNS ASK my####tyzone.com
  • DNS ASK ue##.ac.ae
  • DNS ASK bl#####chidstudio.ca
  • DNS ASK eb####struction.net
  • DNS ASK sh#r.ps
  • DNS ASK cc####ellcpa.com
  • DNS ASK kr#####rundgarten.de
  • DNS ASK am##cs.com
  • DNS ASK cl########.fitnesspassport.com.au

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке