Защити созданное

Другие наши ресурсы

  • free.drweb.kz — бесплатные утилиты, плагины, информеры
  • av-desk.com — интернет-сервис для поставщиков услуг Dr.Web AV-Desk
  • curenet.drweb.kz — сетевая лечащая утилита Dr.Web CureNet!
Закрыть

Библиотека
Моя библиотека

Чтобы добавить ресурс в библиотеку, войдите в аккаунт.

+ Добавить в библиотеку

Ресурсов: -

Последний: -

Моя библиотека

Поддержка
Круглосуточная поддержка | Правила обращения

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen18.55108

Добавлен в вирусную базу Dr.Web: 2022-10-05

Описание добавлено:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\Software\Classes\Applications\resize.exe\shell\open\command] '' = '%ProgramFiles(x86)%\ObviousIdea\Light Image Resizer 6\Resize.exe %L'
Modifies file system
Creates the following files
  • %TEMP%\rarsfx0\light_image_resizer6_setup.exe
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-q4sdu.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-q25n6.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-otdpm.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-fsqil.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-9tgv3.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-4l0or.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-mdp2k.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-49mak.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-00ju3.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-f63d7.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-47sig.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-itnk0.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-kkhfq.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-2jka5.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-4q6aj.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-5dcf1.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-tepmi.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-togba.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-bom04.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-26vvu.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-dhuai.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-bmhdh.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-di6sc.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-s3sf0.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-5e91c.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-sibjg.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-96rql.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-aejer.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\unins000.dat
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-mk5vb.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\unins000.msg
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\resize.url
  • %ALLUSERSPROFILE%\microsoft\internet explorer\quick launch\light image resizer 6.lnk
  • C:\users\public\desktop\light image resizer 6.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\obviousidea\light image resizer 6\how to resize pictures with light image resizer 6.url
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\obviousidea\light image resizer 6\command line options.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\obviousidea\light image resizer 6\digital frame wizard.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\obviousidea\light image resizer 6\uninstall light image resizer 6.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\obviousidea\light image resizer 6\light image resizer 6 on the web.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\obviousidea\light image resizer 6\light image resizer 6.lnk
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-u4hpo.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-lks5o.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-22psi.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-1lr1k.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-94suh.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-ok5ra.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-gpiuh.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-nrm7k.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-2jf0s.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-or40c.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-1m784.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-pf7ch.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-bh1s2.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-nnq77.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-l73rn.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-0h19r.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-j5kaf.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-d2a63.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-5id8e.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-plr0o.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-ah5a5.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-oorhr.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-n01me.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-v5826.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-t0t80.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-a5lp7.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-8evmt.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-1q3l9.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-96jsd.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-e7fl3.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-cp953.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-qpn1h.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-rf8g0.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-bdjil.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-bpee7.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-drn35.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-up5a0.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-f8gnd.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-k47jh.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-d2jqd.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-54all.tmp
  • %TEMP%\is-1qgeb.tmp\_isetup\_setup64.tmp
  • %TEMP%\is-6j50d.tmp\light_image_resizer6_setup.tmp
  • %TEMP%\rarsfx0\crack.7z
  • %TEMP%\rarsfx0\replace.exe
  • %TEMP%\rarsfx0\cybermania.url
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-to37o.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-73mn3.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-mfpjf.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-7p6bl.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-civhv.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-o90sg.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-4s78f.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-dim7n.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-3k21q.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-9iavf.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-n5hj8.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-1deef.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-r9f5b.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-c269j.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-ju3ls.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-r0ja0.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-ol7a8.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-sf29s.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-g09fj.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-7rc0h.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-rcegi.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-kgb87.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-hbnjj.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-md7sb.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-858en.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-t0018.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-m2597.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-0ogbl.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-rmgdj.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-k20ae.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-bgsad.tmp
  • %ProgramFiles(x86)%\obviousidea\light image resizer 6\resize.exe
Deletes the following files
  • %TEMP%\is-1qgeb.tmp\_isetup\_setup64.tmp
  • %TEMP%\is-6j50d.tmp\light_image_resizer6_setup.tmp
  • %TEMP%\rarsfx0\crack.7z
  • %TEMP%\rarsfx0\cybermania.url
  • %TEMP%\rarsfx0\light_image_resizer6_setup.exe
  • %TEMP%\rarsfx0\replace.exe
Moves the following files
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-54all.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\unins000.exe
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-00ju3.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_saudi arabia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-f63d7.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_russia.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-47sig.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_russia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-itnk0.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_russia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-2jka5.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_romania.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-96rql.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_romania.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-4q6aj.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_portugal.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-5dcf1.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_portugal.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-tepmi.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_portugal.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-togba.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_poland.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-bom04.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_poland.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-26vvu.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_poland.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-dhuai.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_chinese.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-bmhdh.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_people's republic of china.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-di6sc.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_people's republic of china.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-s3sf0.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_norway.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-5e91c.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_norway.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-sibjg.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_norway.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-22psi.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_dutch.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-5id8e.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_netherlands.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-ol7a8.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_netherlands.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-49mak.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_saudi arabia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-mdp2k.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_arabic.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-4l0or.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_serbia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-9tgv3.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_serbia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-1lr1k.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_united states.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-aejer.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_great_britain.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-94suh.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_united kingdom.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-ok5ra.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_ukraine.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-gpiuh.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_ukraine.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-nrm7k.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_turkey.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-2jf0s.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_turkey.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-or40c.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_taiwan.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-1m784.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_taiwan.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-pf7ch.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_taiwan.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-nnq77.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_sweden.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-bh1s2.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_sweden.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-l73rn.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_sweden.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-0h19r.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_spain.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-mk5vb.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_spain.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-d2a63.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_spain.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-j5kaf.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_slovenia.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-kkhfq.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_slovenia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-q4sdu.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_slovenia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-q25n6.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_slovakia.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-otdpm.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_slovakia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-fsqil.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_serbia.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-lks5o.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_united states.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-mfpjf.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_korea.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-civhv.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_korea.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-o90sg.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_korea.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-rf8g0.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_denmark.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-ah5a5.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_czech_republic.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-oorhr.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_czech republic.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-n01me.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_czech republic.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-v5826.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_croatian.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-t0t80.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_croatia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-a5lp7.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_brazil.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-8evmt.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_brazil.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-1q3l9.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_brazil.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-96jsd.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_original.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-e7fl3.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_original.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-cp953.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\editloc.exe
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-qpn1h.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\profiles.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-bdjil.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\libwebp.dll
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-to37o.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\faq.txt
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-bpee7.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\history.txt
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-drn35.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\switches.txt
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-up5a0.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\ielib32.dll
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-f8gnd.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\optipng.exe
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-k47jh.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\digitalframewizard.exe
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\is-d2jqd.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\resize.exe
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-bgsad.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_denmark.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-plr0o.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_denmark.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-7p6bl.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_estonia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-k20ae.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_estonia.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-dim7n.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_japan.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-3k21q.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_japan.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-9iavf.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_italy.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-n5hj8.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_italy.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-1deef.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_italy.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-r9f5b.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_hungary.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-c269j.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_hungary.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-ju3ls.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_hungary.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-r0ja0.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_greece.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-sf29s.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_greece.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-g09fj.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_german.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-73mn3.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_greece.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-7rc0h.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_germany.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-rcegi.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_germany.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-kgb87.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_georgia.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-hbnjj.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_georgia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-md7sb.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_georgia.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-858en.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_french.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-t0018.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\dfw_france.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-m2597.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_france.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-0ogbl.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_finland.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-rmgdj.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\rsz_finland.ini
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-4s78f.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_japan.png
  • from %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\is-u4hpo.tmp to %ProgramFiles(x86)%\obviousidea\light image resizer 6\lang\flag_usa.png
Network activity
Connects to
  • 'su#####.obviousidea.com':80
  • 'cy###mania.ws':443
TCP
HTTP GET requests
  • http://su#####.obviousidea.com/generateEvent.php?ca##############################################################################################
  • http://su#####.obviousidea.com/generateEvent.php?ca###############################################################################################
Other
  • 'cy###mania.ws':443
UDP
  • DNS ASK su#####.obviousidea.com
  • DNS ASK cy###mania.ws
  • DNS ASK microsoft.com
Miscellaneous
Searches for the following windows
  • ClassName: 'EDIT' WindowName: ''
  • ClassName: 'Static' WindowName: ''
  • ClassName: 'MS_AutodialMonitor' WindowName: ''
  • ClassName: 'MS_WebCheckMonitor' WindowName: ''
Creates and executes the following
  • '%TEMP%\rarsfx0\light_image_resizer6_setup.exe' /silent
  • '%TEMP%\is-6j50d.tmp\light_image_resizer6_setup.tmp' /SL5="$10242,9630718,121344,%TEMP%\RarSFX0\light_image_resizer6_setup.exe" /silent
  • '%TEMP%\rarsfx0\replace.exe'
Executes the following
  • '%WINDIR%\syswow64\reg.exe' add "HKCU\Software\ObviousIdea\ImageResizer\6.0" /v "CheckForUpdates" /t REG_DWORD /d "0" /f
  • '%WINDIR%\syswow64\reg.exe' add "HKCU\Software\ObviousIdea\ImageResizer\6.0" /v "CollectUsageInfo" /t REG_DWORD /d "0" /f

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке