Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.MulDrop32.18802

Добавлен в вирусную базу Dr.Web: 2025-07-10

Описание добавлено:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Gift For Ohanuna' = '%APPDATA%\Gift_For_Ohanuna\<File name>.exe'
  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Adobe Acrobat' = '%APPDATA%\Adobe Acrobat PDF Reader\AdobeAcrobat.exe'
Malicious functions
Launches a large number of processes
Modifies file system
Creates the following files
  • %APPDATA%\gift_for_ohanuna\<File name>.exe
  • %APPDATA%\adobe acrobat pdf reader\adobeacrobat.exe
Miscellaneous
Executes the following
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/pZ-oEuWMszs/maxresdefault.jpg?sqp=-oaymwEmCIAKENAF8quKqQMa8AEB-AH-CYAC0AWKAgwIABABGGUgUChJMA8=&rs=AOn4CLCjQ0eZYeOpYqqNF0MvtIcX4...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/pZ-oEuWMszs/maxresdefault.jpg?sqp=-oaymwEmCIAKENAF8quKqQMa8AEB-AH-CYAC0AWKAgwIABABGGUgUChJMA8=&rs=AOn4CLCjQ0eZYeOpYqqNF0MvtIcX46Qgyw' -OutFil...
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/G8kPKJxg7HM/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhlIFAoUTAP&rs=AOn4CLDTRSC7T...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/G8kPKJxg7HM/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhlIFAoUTAP&rs=AOn4CLDTRSC7TU3Fk8aP6VpM8fn...
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/0GRnTAWlvcc/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhnIGcoZzAP&rs=AOn4CLAKB5tjy...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/0GRnTAWlvcc/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhnIGcoZzAP&rs=AOn4CLAKB5tjyFSCM4roHCWUxBd...
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Documents\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Documents\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Downloads\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Downloads\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Documents\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Documents\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Downloads\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Downloads\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/pZ-oEuWMszs/maxresdefault.jpg?sqp=-oaymwEmCIAKENAF8quKqQMa8AEB-AH-CYAC0AWKAgwIABABGGUgUChJMA8=&rs=AOn4CLCjQ0eZYeOpYqqNF0MvtIcX4...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\E0fHFjzCwm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\E0fHFjzCwm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\E0fHFjzCwm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\bi78pdKieq1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\bi78pdKieq1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\bi78pdKieq1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/G8kPKJxg7HM/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhlIFAoUTAP&rs=AOn4CLDTRSC7T...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\yNdycM6Fzx1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\yNdycM6Fzx1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\yNdycM6Fzx1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/0GRnTAWlvcc/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhnIGcoZzAP&rs=AOn4CLAKB5tjy...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\syM7soQDbA1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\syM7soQDbA1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\syM7soQDbA1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5wwS8f5Sq01.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Documents\5wwS8f5Sq01.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Downloads\5wwS8f5Sq01.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\RdHvoOpbHW1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\RdHvoOpbHW1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\RdHvoOpbHW1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\4uSBAN1dWM1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\4uSBAN1dWM1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\4uSBAN1dWM1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gkRG7FUlmm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gkRG7FUlmm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gkRG7FUlmm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gCsEXMzK7C1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gCsEXMzK7C1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gCsEXMzK7C1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5pTUmuluOp1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\5pTUmuluOp1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\5pTUmuluOp1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\6X3X4Y2r6N1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\6X3X4Y2r6N1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\6X3X4Y2r6N1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\uYZA46DPMB1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\uYZA46DPMB1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\uYZA46DPMB1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\LM7wPOs22w1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\LM7wPOs22w1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\LM7wPOs22w1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\rm2JBDGl7v1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\rm2JBDGl7v1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\rm2JBDGl7v1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\o3sWYK7S6L1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\o3sWYK7S6L1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\o3sWYK7S6L1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\FI5tEltlFm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Documents\FI5tEltlFm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Downloads\FI5tEltlFm1.jpg\""' (with hidden window)

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке