Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen33.64682

Добавлен в вирусную базу Dr.Web: 2026-09-04

Описание добавлено:

Technical Information

To ensure autorun and distribution
Sets the following service settings
  • [HKLM\SYSTEM\CurrentControlSet\Services\winsvc] 'Start' = '00000002'
  • [HKLM\SYSTEM\CurrentControlSet\Services\winsvc] 'ImagePath' = '<SYSTEM32>\winsvc.exe'
Creates the following services
  • 'winsvc' <SYSTEM32>\winsvc.exe
Malicious functions
Executes the following
  • '<SYSTEM32>\taskkill.exe' "/F" "/IM" "winnet.exe"
  • '<SYSTEM32>\taskkill.exe' "/F" "/IM" "wincfg.exe"
Modifies file system
Creates the following files
  • %TEMP%\<File name>-49f2233b2c1097df\<File name>.exe
  • %TEMP%\<File name>-eb3411beaf08b1ad\<File name>.exe
  • <SYSTEM32>\.cob660.tmp
  • %TEMP%\temp-64f5f60f54ae594a\o
  • %TEMP%\temp-9b2f5c12dbd2b989\o
  • %TEMP%\temp-0664bdecc45cfd59\o
  • %TEMP%\temp-e8b6759838b8b562\o
  • %WINDIR%\temp\__psscriptpolicytest_prbcoi4a.w02.ps1
  • %WINDIR%\temp\__psscriptpolicytest_jenzitmx.ycv.psm1
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-16-956.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-165.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-243.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-387.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-418.dump
  • %WINDIR%\temp\__psscriptpolicytest_5zj103ta.2hr.ps1
  • %WINDIR%\temp\__psscriptpolicytest_ridlgbd4.r0o.psm1
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-604.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-635.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-673.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-767.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-17-905.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-18-122.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-18-269.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-18-291.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-18-323.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-18-354.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-18-376.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-18-407.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-18-423.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-19-057.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-19-126.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-19-157.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-19-195.dump
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-19-227.dump
  • %WINDIR%\temp\temp-2eada4dcb4619c93\e
  • %WINDIR%\temp\content\3456-1128-powershell.exe-16-55-19-273.dump
  • <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
  • %WINDIR%\temp\__psscriptpolicytest_2aahfdm3.s3i.ps1
  • %WINDIR%\temp\__psscriptpolicytest_u1hqj15t.pm2.psm1
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-20-779.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-062.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-159.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-291.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-313.dump
  • %WINDIR%\temp\__psscriptpolicytest_hdcnq1gr.s4b.ps1
  • %WINDIR%\temp\__psscriptpolicytest_saucajt5.1kg.psm1
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-445.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-476.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-514.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-617.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-712.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-790.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-906.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-936.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-966.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-21-989.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-018.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-041.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-070.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-419.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-488.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-504.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-520.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-551.dump
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-566.dump
  • %WINDIR%\temp\temp-c078fa6ec473b235\e
  • %WINDIR%\temp\content\576-1092-powershell.exe-16-55-22-604.dump
  • %WINDIR%\temp\__psscriptpolicytest_qpdb4jkq.2kt.ps1
  • %WINDIR%\temp\__psscriptpolicytest_t5q5vbje.51a.psm1
  • %WINDIR%\temp\content\400-2320-powershell.exe-16-55-24-465.dump
  • %WINDIR%\temp\content\400-2320-powershell.exe-16-55-24-941.dump
  • %WINDIR%\temp\__psscriptpolicytest_dypq0sjl.4i0.ps1
  • %WINDIR%\temp\__psscriptpolicytest_mx2ct5hd.mlu.psm1
  • %WINDIR%\temp\content\1532-3808-powershell.exe-16-55-27-152.dump
  • %WINDIR%\temp\content\1532-3808-powershell.exe-16-55-27-671.dump
  • %WINDIR%\temp\__psscriptpolicytest_gac3yi3v.gtn.ps1
  • %WINDIR%\temp\__psscriptpolicytest_tmoempud.liu.psm1
  • %WINDIR%\temp\content\4508-2204-powershell.exe-16-55-29-057.dump
  • %WINDIR%\temp\content\4508-2204-powershell.exe-16-55-29-542.dump
  • %WINDIR%\temp\__psscriptpolicytest_hp0jv1nr.ikl.ps1
  • %WINDIR%\temp\__psscriptpolicytest_55y14chz.owp.psm1
  • %WINDIR%\temp\content\3512-3076-powershell.exe-16-55-30-897.dump
  • %WINDIR%\temp\content\3512-3076-powershell.exe-16-55-31-407.dump
  • %WINDIR%\temp\__psscriptpolicytest_55kxjpek.qti.ps1
  • %WINDIR%\temp\__psscriptpolicytest_3pixaxma.bvs.psm1
  • %WINDIR%\temp\content\4460-1664-powershell.exe-16-55-32-710.dump
  • %WINDIR%\temp\content\4460-1664-powershell.exe-16-55-33-564.dump
  • %WINDIR%\temp\temp-31639aec3e3b989e\e
  • %WINDIR%\temp\temp-a42dc2b745bc2ebf\e
  • %WINDIR%\temp\temp-ccebe03154c39688\e
  • %WINDIR%\temp\temp-5e478625a7af09ae\e
  • <SYSTEM32>\winnet.exe
  • <SYSTEM32>\wincfg.exe
  • %WINDIR%\temp\__psscriptpolicytest_0gg3wbtu.elp.ps1
  • %WINDIR%\temp\__psscriptpolicytest_1yvanp3f.eii.psm1
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-38-625.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-38-848.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-38-926.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-049.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-080.dump
  • %WINDIR%\temp\__psscriptpolicytest_niw1u2py.qpz.ps1
  • %WINDIR%\temp\__psscriptpolicytest_g4uyyz3l.acj.psm1
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-212.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-228.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-266.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-344.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-451.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-614.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-651.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-730.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-752.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-39-799.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-131.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-185.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-316.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-370.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-602.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-756.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-819.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-856.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-872.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-903.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-919.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-957.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-40-988.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-004.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-051.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-089.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-173.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-205.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-251.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-274.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-305.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-336.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-358.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-374.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-405.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-421.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-41-660.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-43-461.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-44-198.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-44-219.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-44-230.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-44-260.dump
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-44-283.dump
  • %WINDIR%\temp\temp-88ebbe2839f1c167\e
  • %WINDIR%\temp\content\4796-4196-powershell.exe-16-55-44-314.dump
  • %WINDIR%\temp\__psscriptpolicytest_nesptbw4.icz.ps1
  • %WINDIR%\temp\__psscriptpolicytest_x4oab53o.jlk.psm1
  • %WINDIR%\temp\content\740-2240-powershell.exe-16-55-45-776.dump
  • %WINDIR%\temp\content\740-2240-powershell.exe-16-55-45-977.dump
  • %WINDIR%\temp\content\740-2240-powershell.exe-16-55-46-423.dump
  • %WINDIR%\temp\content\740-2240-powershell.exe-16-55-46-744.dump
  • %WINDIR%\temp\content\740-2240-powershell.exe-16-55-46-786.dump
  • %WINDIR%\temp\__psscriptpolicytest_wzyiqkl0.uth.ps1
  • %WINDIR%\temp\__psscriptpolicytest_gqlfar3s.l1z.psm1
  • %WINDIR%\temp\content\740-2240-powershell.exe-16-55-46-923.dump
  • %WINDIR%\temp\content\740-2240-powershell.exe-16-55-46-954.dump
  • %WINDIR%\temp\content\740-2240-powershell.exe-16-55-46-992.dump
Deletes following files that it created itself
  • %TEMP%\<File name>-eb3411beaf08b1ad\<File name>.exe
  • %TEMP%\<File name>-49f2233b2c1097df\<File name>.exe
  • %TEMP%\temp-64f5f60f54ae594a\o
  • %TEMP%\temp-9b2f5c12dbd2b989\o
  • %TEMP%\temp-0664bdecc45cfd59\o
  • %TEMP%\temp-e8b6759838b8b562\o
  • %WINDIR%\temp\__psscriptpolicytest_prbcoi4a.w02.ps1
  • %WINDIR%\temp\__psscriptpolicytest_jenzitmx.ycv.psm1
  • %WINDIR%\temp\__psscriptpolicytest_5zj103ta.2hr.ps1
  • %WINDIR%\temp\__psscriptpolicytest_ridlgbd4.r0o.psm1
  • %WINDIR%\temp\temp-2eada4dcb4619c93\e
  • %WINDIR%\temp\__psscriptpolicytest_2aahfdm3.s3i.ps1
  • %WINDIR%\temp\__psscriptpolicytest_u1hqj15t.pm2.psm1
  • %WINDIR%\temp\__psscriptpolicytest_hdcnq1gr.s4b.ps1
  • %WINDIR%\temp\__psscriptpolicytest_saucajt5.1kg.psm1
  • %WINDIR%\temp\temp-c078fa6ec473b235\e
  • %WINDIR%\temp\__psscriptpolicytest_qpdb4jkq.2kt.ps1
  • %WINDIR%\temp\__psscriptpolicytest_t5q5vbje.51a.psm1
  • %WINDIR%\temp\__psscriptpolicytest_dypq0sjl.4i0.ps1
  • %WINDIR%\temp\__psscriptpolicytest_mx2ct5hd.mlu.psm1
  • %WINDIR%\temp\__psscriptpolicytest_gac3yi3v.gtn.ps1
  • %WINDIR%\temp\__psscriptpolicytest_tmoempud.liu.psm1
  • %WINDIR%\temp\__psscriptpolicytest_hp0jv1nr.ikl.ps1
  • %WINDIR%\temp\__psscriptpolicytest_55y14chz.owp.psm1
  • %WINDIR%\temp\__psscriptpolicytest_55kxjpek.qti.ps1
  • %WINDIR%\temp\__psscriptpolicytest_3pixaxma.bvs.psm1
  • %WINDIR%\temp\temp-31639aec3e3b989e\e
  • %WINDIR%\temp\temp-a42dc2b745bc2ebf\e
  • %WINDIR%\temp\temp-ccebe03154c39688\e
  • %WINDIR%\temp\temp-5e478625a7af09ae\e
  • %WINDIR%\temp\__psscriptpolicytest_0gg3wbtu.elp.ps1
  • %WINDIR%\temp\__psscriptpolicytest_1yvanp3f.eii.psm1
  • %WINDIR%\temp\__psscriptpolicytest_niw1u2py.qpz.ps1
  • %WINDIR%\temp\__psscriptpolicytest_g4uyyz3l.acj.psm1
  • %WINDIR%\temp\temp-88ebbe2839f1c167\e
  • %WINDIR%\temp\__psscriptpolicytest_nesptbw4.icz.ps1
  • %WINDIR%\temp\__psscriptpolicytest_x4oab53o.jlk.psm1
  • %WINDIR%\temp\__psscriptpolicytest_wzyiqkl0.uth.ps1
  • %WINDIR%\temp\__psscriptpolicytest_gqlfar3s.l1z.psm1
Moves the following files
  • from <SYSTEM32>\.cob660.tmp to <SYSTEM32>\winsvc.exe
Miscellaneous
Searches for the following windows
  • ClassName: '' WindowName: ''
Creates and executes the following
  • '%TEMP%\<File name>-49f2233b2c1097df\<File name>.exe'
  • '%TEMP%\<File name>-eb3411beaf08b1ad\<File name>.exe'
  • '<SYSTEM32>\winsvc.exe' "%TEMP%\<File name>-49f2233b2c1097df\<File name>.exe"
  • '<SYSTEM32>\winsvc.exe'
Executes the following
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "create" "winsvc" "type=own" "start=auto" "error=ignore" "binPath=\"<SYSTEM32>\winsvc.exe\"" "DisplayName=\"Windows System Service...
  • '<SYSTEM32>\sc.exe' create winsvc type=own start=auto error=ignore binPath=<SYSTEM32>\winsvc.exe "DisplayName=Windows System Service"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "failure" "winsvc" "reset=0" "actions=restart/0/restart/0/restart/0"
  • '<SYSTEM32>\sc.exe' failure winsvc reset=0 actions=restart/0/restart/0/restart/0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "description" "winsvc" "\"Windows System Service is the main system supervision service.\""
  • '<SYSTEM32>\sc.exe' description winsvc "Windows System Service is the main system supervision service."
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "start" "winsvc"
  • '<SYSTEM32>\sc.exe' start winsvc
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Add-MpPreference" "-ExclusionPath" "\"<SYSTEM32>\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Add-MpPreference" "-ExclusionPath" "\"%WINDIR%\Temp\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-SETACTIVE" "8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c"
  • '<SYSTEM32>\powercfg.exe' -SETACTIVE 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "standby-timeout-ac" "0"
  • '<SYSTEM32>\powercfg.exe' -change standby-timeout-ac 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "standby-timeout-dc" "0"
  • '<SYSTEM32>\powercfg.exe' -change standby-timeout-dc 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "hibernate-timeout-ac" "0"
  • '<SYSTEM32>\powercfg.exe' -change hibernate-timeout-ac 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "hibernate-timeout-dc" "0"
  • '<SYSTEM32>\powercfg.exe' -change hibernate-timeout-dc 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Remove-NetFirewallRule" "-DisplayName" "\"Windows Network Manager\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "New-NetFirewallRule" "-DisplayName" "\"Windows Network Manager\"" "-Program" "\"<SYSTEM32>\winnet.exe\"" "-Action" "Allow" "-Direction" "Inbound" "-EdgeTrave...

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке