Защити созданное

Другие наши ресурсы

  • free.drweb.uz — бесплатные утилиты, плагины, информеры
  • av-desk.com — интернет-сервис для поставщиков услуг Dr.Web AV-Desk
  • curenet.drweb.uz — сетевая лечащая утилита Dr.Web CureNet!
  • www.drweb.uz/web-iq — ВебIQметр
Закрыть

Библиотека
Моя библиотека

Чтобы добавить ресурс в библиотеку, войдите в аккаунт.

+ Добавить в библиотеку

Ресурсов: -

Последний: -

Моя библиотека

Поддержка
Круглосуточная поддержка | Правила обращения

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.DownLoader26.57891

Добавлен в вирусную базу Dr.Web: 2018-07-15

Описание добавлено:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'uTorrent' = '"%TEMP%\RarSFX0\App\uTorrent\uTorrent.exe" /MINIMIZED'
Malicious functions:
To bypass firewall, removes or modifies the following registry keys:
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\RarSFX0\App\uTorrent\uTorrent.exe' = '%TEMP%\RarSFX0\App\uTorre...
Modifies file system:
Creates the following files:
  • %TEMP%\RarSFX0\App\AppInfo\appicon.ico
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libalphamask_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libadjust_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_chroma\libyuy2_i422_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_chroma\libyuy2_i420_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_chroma\librv32_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_chroma\libi422_yuy2_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_chroma\libi422_i420_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_chroma\libi420_yuy2_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_chroma\libi420_rgb_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_chroma\libgrey_yuv_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\text_renderer\libtdummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\text_renderer\libfreetype_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_transcode_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_standard_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_smem_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_setid_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_select_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_record_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_rtp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libantiflicker_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libatmo_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libinvert_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libgrain_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libgradient_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libgradfun_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libgaussianblur_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libextract_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\liberase_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libdeinterlace_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libcolorthres_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_filter\libstream_filter_record_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libclone_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libchain_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libcanvas_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libbluescreen_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libblend_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libblendbench_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libball_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libaudiobargraph_v_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_raop_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_langfromtelx_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\packetizer\libpacketizer_h264_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\packetizer\libpacketizer_flac_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\packetizer\libpacketizer_dirac_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\packetizer\libpacketizer_copy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\notify\libmsn_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mux\libmux_ps_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mux\libmux_ogg_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mux\libmux_mpjpeg_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mux\libmux_mp4_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mux\libmux_dummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mux\libmux_avi_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mmxext\libmemcpymmxext_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mmx\libmemcpymmx_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mmx\libi422_yuy2_mmx_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mmx\libi420_yuy2_mmx_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\mmx\libi420_rgb_mmx_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\packetizer\libpacketizer_mpeg4audio_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\packetizer\libpacketizer_mpeg4video_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\packetizer\libpacketizer_mlp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\packetizer\libpacketizer_mpegvideo_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_gather_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\services_discovery\libmediadirs_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_es_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_duplicate_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_dummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_display_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_description_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_delay_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_bridge_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libcroppadd_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\liblogo_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_filter\libstream_filter_httplive_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\sse2\libi422_yuy2_sse2_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\sse2\libi420_yuy2_sse2_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\sse2\libi420_rgb_sse2_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\services_discovery\libwindrive_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\services_discovery\libupnp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\services_discovery\libsap_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\services_discovery\libpodcast_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\stream_out\libstream_out_autodel_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libvdummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\maindoc.ico
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libmirror_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\updates.dat
  • %TEMP%\RarSFX0\App\uTorrent\updates\3.5.4_44498.exe
  • %HOMEPATH%\Cookies\%USERNAME%@localhost[1].txt
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\b82e6275c282c20b8250755f226cfe32_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Protect\CREDHIST
  • %TEMP%\RarSFX0\Data\PortableApps.comLauncherRuntimeData-uTorrentPROPortable.ini
  • %TEMP%\RarSFX0\Data\settings\uTorrentPROPortableSettings.ini
  • %TEMP%\RarSFX0\Data\settings\apps\welcome-upsell.btapp
  • %TEMP%\RarSFX0\Data\settings\apps\plus.btapp
  • %TEMP%\RarSFX0\Data\settings\apps\player.btapp
  • %TEMP%\RarSFX0\Data\settings\apps\featuredContent.btapp
  • %TEMP%\RarSFX0\Data\settings\uTorrentPortableSettings.ini
  • %TEMP%\RarSFX0\Data\settings\settings.dat
  • %TEMP%\RarSFX0\Data\settings\rss.dat
  • %TEMP%\RarSFX0\Data\settings\resume.dat
  • %TEMP%\RarSFX0\Data\settings\dht_feed.dat
  • %TEMP%\RarSFX0\Data\settings\dht.dat
  • %TEMP%\RarSFX0\uTorrentPROPortable.exe
  • %TEMP%\nsu2.tmp
  • %TEMP%\RarSFX0\App\uTorrent\settings.dat.new
  • %TEMP%\RarSFX0\App\uTorrent\apps\9D1685A791FDE8335C27D20650E32136BC84646F\btapp
  • %TEMP%\RarSFX0\App\uTorrent\apps\D944B3378FAB35793B7951FA53E41B2AB9CC462B\x.png
  • %TEMP%\RarSFX0\App\uTorrent\apps\D944B3378FAB35793B7951FA53E41B2AB9CC462B\vid_thumb.jpg
  • %TEMP%\RarSFX0\App\uTorrent\apps\D944B3378FAB35793B7951FA53E41B2AB9CC462B\main.css
  • %TEMP%\RarSFX0\App\uTorrent\apps\D944B3378FAB35793B7951FA53E41B2AB9CC462B\info_icon.png
  • %TEMP%\RarSFX0\App\uTorrent\apps\D944B3378FAB35793B7951FA53E41B2AB9CC462B\index.html
  • %TEMP%\RarSFX0\App\uTorrent\apps\D944B3378FAB35793B7951FA53E41B2AB9CC462B\empty_movie.gif
  • %TEMP%\RarSFX0\App\uTorrent\apps\D944B3378FAB35793B7951FA53E41B2AB9CC462B\btapp
  • %TEMP%\RarSFX0\App\uTorrent\apps\B63870F0CCF06210E0E969B2BF50C38CF8D73B4A\package.json
  • %TEMP%\RarSFX0\App\uTorrent\apps\B63870F0CCF06210E0E969B2BF50C38CF8D73B4A\icon.bmp
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libmagnify_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\apps\B63870F0CCF06210E0E969B2BF50C38CF8D73B4A\btapp
  • %TEMP%\RarSFX0\App\uTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\index.js
  • %TEMP%\RarSFX0\App\uTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\index.html
  • %TEMP%\RarSFX0\App\uTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\icon.bmp
  • %TEMP%\RarSFX0\App\uTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\main.css
  • %TEMP%\RarSFX0\App\uTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\btapp
  • %TEMP%\RarSFX0\App\uTorrent\apps\9D1685A791FDE8335C27D20650E32136BC84646F\main.js
  • %TEMP%\RarSFX0\App\uTorrent\apps\9D1685A791FDE8335C27D20650E32136BC84646F\index.html
  • %TEMP%\RarSFX0\App\uTorrent\VirusGuard\scan.dll
  • %TEMP%\RarSFX0\App\uTorrent\VirusGuard\BitTorrentAntivirus.exe
  • %TEMP%\RarSFX0\App\uTorrent\VirusGuard\BDUpdateServiceCom.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libsepia_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libscene_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libscale_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\librss_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\librotate_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libripple_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libremoteosd_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libpuzzle_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libpsychedelic_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libpostproc_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libposterize_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libpanoramix_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libosdmenu_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libmotiondetect_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libmotionblur_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libmosaic_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libsubsdelay_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libswscale_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libsharpen_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libtransform_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\VirusGuard\avxdisk.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libwall_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\utorrent.lng
  • %TEMP%\RarSFX0\App\uTorrent\uTorrent.exe
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\visualization\libvisual_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\visualization\libprojectm_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\visualization\libgoom_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libyuv_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libwingdi_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\misc\libxml_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libmarq_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libglwin32_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libdrawable_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libdirectx_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libdirect3d_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libdirect2d_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libcaca_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libyuvp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_filter\libwave_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\video_output\libvmem_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\apps\B63870F0CCF06210E0E969B2BF50C38CF8D73B4A\index.html
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\misc\libstats_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\gui\libqt4_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libaudiobargraph_a_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\liba52tospdif_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\liba52tofloat32_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access_output\libaccess_output_udp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access_output\libaccess_output_shout_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access_output\libaccess_output_livehttp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access_output\libaccess_output_http_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access_output\libaccess_output_file_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access_output\libaccess_output_dummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libzip_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libvcd_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libstream_filter_rar_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libsdp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libscreen_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\librtp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\liblibbluray_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libidummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libdvdread_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libfilesystem_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libaudio_format_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libchorus_flanger_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libugly_resampler_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libtrivial_channel_mixer_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libspeex_resampler_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libspatializer_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libsimple_channel_mixer_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libscaletempo_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libsamplerate_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libparam_eq_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libmpgatofixed32_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_http_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libmono_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libkaraoke_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libheadphone_channel_mixer_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libequalizer_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libdtstospdif_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libdtstofloat32_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libconverter_fixed_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libcompressor_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libdvdnav_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libdtv_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libdshow_plugin.dll
  • %TEMP%\RarSFX0\App\DefaultData\settings\dht.dat
  • %TEMP%\RarSFX0\App\DefaultData\settings\apps\welcome-upsell.btapp
  • %TEMP%\RarSFX0\App\DefaultData\settings\apps\plus.btapp
  • %TEMP%\RarSFX0\App\DefaultData\settings\apps\player.btapp
  • %TEMP%\RarSFX0\App\DefaultData\settings\apps\featuredContent.btapp
  • %TEMP%\RarSFX0\App\AppInfo\pac_installer_log.ini
  • %TEMP%\RarSFX0\App\AppInfo\Launcher\uTorrentPROPortable.ini
  • %TEMP%\RarSFX0\App\AppInfo\Launcher\splash.jpg
  • %TEMP%\RarSFX0\App\AppInfo\Launcher\Custom.nsh
  • %TEMP%\RarSFX0\App\AppInfo\installer.ini
  • %TEMP%\RarSFX0\App\AppInfo\EULA.txt
  • %TEMP%\RarSFX0\App\AppInfo\appinfo.ini
  • %TEMP%\RarSFX0\App\AppInfo\appicon_32.png
  • %TEMP%\RarSFX0\App\AppInfo\appicon_256.png
  • %TEMP%\RarSFX0\App\AppInfo\appicon_16.png
  • %TEMP%\RarSFX0\App\AppInfo\appicon_128.png
  • %TEMP%\RarSFX0\App\DefaultData\settings\resume.dat
  • %TEMP%\RarSFX0\App\DefaultData\settings\rss.dat
  • %TEMP%\RarSFX0\App\DefaultData\settings\dht_feed.dat
  • %TEMP%\RarSFX0\App\DefaultData\settings\settings.dat
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libcdda_plugin.dll
  • %TEMP%\RarSFX0\App\DefaultData\settings\uTorrentPortableSettings.ini
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_vdr_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_udp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_tcp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_smb_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_realrtsp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_rar_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_mms_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_filter\libnormvol_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_mixer\libfixed32_mixer_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_ftp_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_bd_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_attachment_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\3dnow\libmemcpy3dn_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\libvlccore.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\libvlc.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\btinstall.txt
  • %TEMP%\RarSFX0\App\Readme.txt
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\access\libaccess_imem_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\control\libntservice_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\misc\libmemcpy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_output\libamem_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\librawvid_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\librawdv_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\librawaud_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libpva_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libps_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libplaylist_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libogg_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libnuv_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libnsv_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libnsc_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libmpgv_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libmpc_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libmp4_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libmod_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libmkv_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libmjpeg_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\liblive555_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libh264_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libimage_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libreal_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libsid_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\misc\liblogger_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\misc\libgnutls_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\misc\libexport_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\misc\libaudioscrobbler_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\meta_engine\libtaglib_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\meta_engine\libfolder_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\lua\liblua_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\gui\libskins2_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libxa_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_mixer\libfloat32_mixer_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libwav_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libvoc_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libvc1_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libty_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libtta_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libts_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libsubtitle_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libsmf_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libgme_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libflacsys_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libes_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libmpeg_audio_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\liblibmpeg2_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\liblibass_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libkate_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libflac_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libfaad_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libedummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libdmo_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libddummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libavcodec_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libaraw_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libaes3_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\liba52_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_output\libwaveout_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_output\libaout_file_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_output\libaout_directx_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libquicktime_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\librawvideo_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libpng_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libschroedinger_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libdirac_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libspeex_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libdemux_stl_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libdemux_cdg_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libdemuxdump_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libavi_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libau_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libasf_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\demux\libaiff_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\misc\libosd_parser_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\audio_output\libadummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\control\libnetsync_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\control\libhotkeys_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\control\libglobalhotkeys_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\control\libgestures_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\control\libdummy_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libx264_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libvorbis_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\codec\libtheora_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\player\plugins\control\liboldrc_plugin.dll
  • %TEMP%\RarSFX0\App\uTorrent\apps\featuredContent.btapp.new
Sets the 'hidden' attribute to the following files:
  • %TEMP%\RarSFX0\App\AppInfo\Launcher\splash.jpg
Moves the following files:
  • from %TEMP%\RarSFX0\Data\settings\dht.dat to %TEMP%\RarSFX0\App\uTorrent\dht.dat
  • from %TEMP%\RarSFX0\Data\settings\dht_feed.dat to %TEMP%\RarSFX0\App\uTorrent\dht_feed.dat
  • from %TEMP%\RarSFX0\Data\settings\resume.dat to %TEMP%\RarSFX0\App\uTorrent\resume.dat
  • from %TEMP%\RarSFX0\Data\settings\rss.dat to %TEMP%\RarSFX0\App\uTorrent\rss.dat
  • from %TEMP%\RarSFX0\Data\settings\settings.dat to %TEMP%\RarSFX0\App\uTorrent\settings.dat
  • from %TEMP%\RarSFX0\App\uTorrent\settings.dat to %TEMP%\RarSFX0\App\uTorrent\settings.dat.old
  • from %TEMP%\RarSFX0\App\uTorrent\apps\featuredContent.btapp.new to %TEMP%\RarSFX0\App\uTorrent\apps\featuredContent.btapp
Substitutes the following files:
  • %TEMP%\RarSFX0\App\uTorrent\settings.dat
  • %TEMP%\RarSFX0\App\uTorrent\settings.dat.new
Network activity:
Connects to:
  • 'i-##.#####98.ut.bench.utorrent.com':80
  • 'no#.bt.co':80
  • 'th####atebay.org':443
  • 'up####.bittorrent.com':80
TCP:
HTTP GET requests:
  • http://no#.bt.co/inclient
  • http://up####.bittorrent.com/time.php
HTTP POST requests:
  • http://i-##.#####98.ut.bench.utorrent.com/e?i=##
UDP:
  • DNS ASK ro####.bittorrent.com
  • DNS ASK ro####.utorrent.com
  • DNS ASK i-##.#####98.ut.bench.utorrent.com
  • DNS ASK no#.bt.co
  • DNS ASK cd#.##.bittorrent.com
  • DNS ASK th####atebay.org
  • DNS ASK up####.bittorrent.com
  • DNS ASK ka##r.co
  • DNS ASK www.dn##d.me
  • DNS ASK i-###.####498.ut.bench.utorrent.com
  • '<LOCALNET_GATEWAY>':5351
  • 'ro####.bittorrent.com':6881
  • '23#.#55.255.250':1900
  • 'ro####.utorrent.com':6881
Miscellaneous:
Searches for the following windows:
  • ClassName: 'EDIT' WindowName: ''
  • ClassName: '?Torrent4823DF041B09' WindowName: ''
  • ClassName: 'µTorrent4823DF041B09' WindowName: ''
  • ClassName: 'avhelper4823DF041B0' WindowName: ''
Creates and executes the following:
  • '%TEMP%\RarSFX0\uTorrentPROPortable.exe'
  • '%TEMP%\RarSFX0\App\uTorrent\uTorrent.exe'

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке