Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Trojan.PWS.Legmir.6230

Added to the Dr.Web virus database: 2013-08-18

Virus description added:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\rundl132.exe'
Malicious functions:
Creates and executes the following:
  • '<Full path to virus>'
  • '%WINDIR%\Logo1_.exe'
Executes the following:
  • '<SYSTEM32>\net1.exe' stop "Kingsoft AntiVirus Service"
  • '<SYSTEM32>\net.exe' stop "Kingsoft AntiVirus Service"
  • '<SYSTEM32>\cmd.exe' /c %TEMP%\$$a1.bat
Injects code into
the following system processes:
  • <SYSTEM32>\svchost.exe
the following user processes:
  • iexplore.exe
Searches for windows to
bypass different anti-viruses:
  • ClassName: 'AVP.Product_Notification' WindowName: '(null)'
  • ClassName: 'AVP.AlertDialog' WindowName: '???????? ????'
Modifies file system :
Creates the following files:
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\scrollbar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\splitter\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\printpreview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\radio\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\toolbar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\tree\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\alerts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\arrow\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\checkbox\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\icons\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\media\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\console\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\dirListing\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\handling\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\console\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\dirListing\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\arrow\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\checkbox\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\icons\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\radio\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\scrollbar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\media\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\printpreview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\passwordmgr\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\update\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\alerts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\viewsource\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\pippki\content\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\pippki\content\pippki\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\feedback\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\pippki\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\alerts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\cookie\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\necko\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\update\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\passwordmgr\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\services\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\pipnss\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\pippki\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\bindings\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\passwordmgr\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\update\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\satchel\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\xbl-marquee\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\res\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\xml\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\cpow\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\svg\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\handling\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\Microsoft\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\_desktop.ini
  • %PROGRAM_FILES%\MSN\_desktop.ini
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\MSN9Components\_desktop.ini
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\OOBE\_desktop.ini
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\_desktop.ini
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\MUI\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\MUI\0409\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\Connection Wizard\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\PLUGINS\_desktop.ini
  • %PROGRAM_FILES%\Microsoft.NET\RedistList\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\SIGNUP\_desktop.ini
  • %PROGRAM_FILES%\Microsoft.NET\_desktop.ini
  • %PROGRAM_FILES%\Online Services\_desktop.ini
  • %PROGRAM_FILES%\Windows Media Player\_desktop.ini
  • %PROGRAM_FILES%\Windows Media Player\Icons\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\_desktop.ini
  • %PROGRAM_FILES%\Uninstall Information\_desktop.ini
  • %PROGRAM_FILES%\Windows Media Player\Sample Playlists\_desktop.ini
  • C:\RECYCLER\_desktop.ini
  • C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\_desktop.ini
  • %PROGRAM_FILES%\xerox\_desktop.ini
  • %PROGRAM_FILES%\xerox\nwwia\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\_desktop.ini
  • %PROGRAM_FILES%\Outlook Express\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\update\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\viewsource\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\autoconfig\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\pref\_desktop.ini
  • %PROGRAM_FILES%\FireFox\components\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\tree\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\splitter\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\toolbar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\passwordmgr\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\handling\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\dtd\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\tabview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\entityTables\_desktop.ini
  • %PROGRAM_FILES%\FireFox\searchplugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\uninstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\fonts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\html\_desktop.ini
  • %PROGRAM_FILES%\FireFox\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\profile\chrome\_desktop.ini
  • %PROGRAM_FILES%\FireFox\dictionaries\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\services-sync\engines\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\services-sync\ext\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\services-crypto\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\services-sync\_desktop.ini
  • C:\Far2\Plugins\HlfViewer\_desktop.ini
  • C:\Far2\Plugins\MacroView\_desktop.ini
  • C:\Far2\Plugins\FTP\_desktop.ini
  • C:\Far2\Plugins\FTP\lib\_desktop.ini
  • C:\Far2\Plugins\Network\_desktop.ini
  • C:\Far2\Plugins\WinSCP\_desktop.ini
  • C:\Far2\Plugins\WinSCP\components\_desktop.ini
  • C:\Far2\Plugins\ProcList\_desktop.ini
  • C:\Far2\Plugins\TmpPanel\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\doc\_desktop.ini
  • C:\Far2\Plugins\EditCase\_desktop.ini
  • C:\Far2\Plugins\EMenu\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\keys\_desktop.ini
  • C:\Far2\Plugins\FarCmds\_desktop.ini
  • C:\Far2\Plugins\FileCase\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\sources\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\sources\RegExp\_desktop.ini
  • C:\Far2\Plugins\WinSCP\console\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\my\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\tb2k\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\dragndrop\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\filemng\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\tbx\_desktop.ini
  • C:\Far2\Plugins\WinSCP\putty\charset\_desktop.ini
  • C:\Far2\Plugins\WinSCP\release\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\theme\_desktop.ini
  • C:\Far2\Plugins\WinSCP\putty\_desktop.ini
  • C:\Far2\Plugins\WinSCP\far\_desktop.ini
  • C:\Far2\Plugins\WinSCP\fari\_desktop.ini
  • C:\Far2\Plugins\WinSCP\core\_desktop.ini
  • C:\Far2\Plugins\WinSCP\dragext\_desktop.ini
  • C:\Far2\Plugins\WinSCP\filezilla\_desktop.ini
  • C:\Far2\Plugins\WinSCP\lib\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\_desktop.ini
  • C:\Far2\Plugins\WinSCP\filezilla\misc\_desktop.ini
  • C:\Far2\Plugins\WinSCP\forms\_desktop.ini
  • C:\Far2\Addons\Macros\_desktop.ini
  • C:\Far2\Addons\SetUp\_desktop.ini
  • C:\Far2\Addons\Colors\Custom Highlighting\_desktop.ini
  • C:\Far2\Addons\Colors\Default Highlighting\_desktop.ini
  • C:\Far2\Addons\Shell\_desktop.ini
  • C:\Far2\Documentation\_desktop.ini
  • C:\Far2\Documentation\eng\_desktop.ini
  • C:\Far2\Addons\XLat\_desktop.ini
  • C:\Far2\Addons\XLat\Russian\_desktop.ini
  • %TEMP%\$$a1.bat
  • C:\_desktop.ini
  • %WINDIR%\rundl132.exe
  • %WINDIR%\Logo1_.exe
  • %WINDIR%\Dll.dll
  • C:\Far2\Addons\_desktop.ini
  • C:\Far2\Addons\Colors\_desktop.ini
  • <Current directory>\_desktop.ini
  • C:\Far2\_desktop.ini
  • C:\Far2\Documentation\rus\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrc\auto\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrc\auto\types\_desktop.ini
  • C:\Far2\Plugins\Colorer\bin\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrc\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrd\_desktop.ini
  • C:\Far2\Plugins\Compare\_desktop.ini
  • C:\Far2\Plugins\DrawLine\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrd\console\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrd\console\contrib\_desktop.ini
  • C:\Far2\Plugins\_desktop.ini
  • C:\Far2\Plugins\7-Zip\_desktop.ini
  • C:\Far2\Encyclopedia\_desktop.ini
  • C:\Far2\FExcept\_desktop.ini
  • C:\Far2\Plugins\Align\_desktop.ini
  • C:\Far2\Plugins\Brackets\_desktop.ini
  • C:\Far2\Plugins\Colorer\_desktop.ini
  • C:\Far2\Plugins\arclite\_desktop.ini
  • C:\Far2\Plugins\AutoWrap\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\sidebar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser-region\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\safebrowsing\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\cookie\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\alerts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\autoconfig\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\branding\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\communicator\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\migration\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\feeds\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\dom\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-region\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\unix\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\win\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\handling\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\security\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\svg\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\layout\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\search\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xml\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\mac\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xslt\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\bookmarks\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\branding\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\certerror\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\migration\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\pageinfo\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\feeds\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\history\_desktop.ini
  • C:\Far2\PluginSDK\Headers.c\_desktop.ini
  • C:\Far2\PluginSDK\Headers.pas\_desktop.ini
  • C:\Far2\Plugins\WinSCP\resource\_desktop.ini
  • C:\Far2\PluginSDK\_desktop.ini
  • <Auxiliary element>
  • %PROGRAM_FILES%\FireFox\chrome\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\_desktop.ini
  • %PROGRAM_FILES%\_desktop.ini
  • %PROGRAM_FILES%\FireFox\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\tabview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\tabbrowser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\feeds\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\tabbrowser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\tabview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\search\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\safebrowsing\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\feeds\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\_desktop.ini
Sets the 'hidden' attribute to the following files:
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\toolbar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\tree\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\scrollbar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\splitter\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\handling\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\passwordmgr\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\checkbox\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\console\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\alerts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\arrow\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\dirListing\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\printpreview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\radio\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\icons\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\media\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\dirListing\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\icons\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\checkbox\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\console\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\media\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\scrollbar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\splitter\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\printpreview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\radio\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\update\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\viewsource\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\alerts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\arrow\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\pippki\content\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\pippki\content\pippki\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\cookie\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\bindings\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\cpow\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\alerts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\passwordmgr\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\pipnss\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\necko\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\pippki\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\feedback\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\pippki\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\services\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\passwordmgr\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\satchel\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\update\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\xbl-marquee\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\res\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\svg\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\xml\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\handling\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\plugins\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\_desktop.ini
  • %PROGRAM_FILES%\MSN\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\_desktop.ini
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\_desktop.ini
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\OOBE\_desktop.ini
  • %PROGRAM_FILES%\Online Services\_desktop.ini
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\_desktop.ini
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\MSN9Components\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\MUI\0409\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\PLUGINS\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\Connection Wizard\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\MUI\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\SIGNUP\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\_desktop.ini
  • %PROGRAM_FILES%\MSBuild\Microsoft\_desktop.ini
  • %PROGRAM_FILES%\Microsoft.NET\_desktop.ini
  • %PROGRAM_FILES%\Microsoft.NET\RedistList\_desktop.ini
  • %PROGRAM_FILES%\Windows Media Player\_desktop.ini
  • %PROGRAM_FILES%\Windows Media Player\Icons\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\_desktop.ini
  • %PROGRAM_FILES%\Uninstall Information\_desktop.ini
  • %PROGRAM_FILES%\Windows Media Player\Sample Playlists\_desktop.ini
  • C:\RECYCLER\_desktop.ini
  • C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\_desktop.ini
  • %PROGRAM_FILES%\xerox\_desktop.ini
  • %PROGRAM_FILES%\xerox\nwwia\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\_desktop.ini
  • %PROGRAM_FILES%\Outlook Express\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\_desktop.ini
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\_desktop.ini
  • %PROGRAM_FILES%\Internet Explorer\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\viewsource\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\update\_desktop.ini
  • %PROGRAM_FILES%\FireFox\components\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\pref\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\autoconfig\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\toolbar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\tree\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\handling\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\passwordmgr\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\dtd\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\tabview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\entityTables\_desktop.ini
  • %PROGRAM_FILES%\FireFox\searchplugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\uninstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\fonts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\res\html\_desktop.ini
  • %PROGRAM_FILES%\FireFox\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\_desktop.ini
  • %PROGRAM_FILES%\FireFox\defaults\profile\chrome\_desktop.ini
  • %PROGRAM_FILES%\FireFox\dictionaries\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\services-sync\engines\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\services-sync\ext\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\services-crypto\_desktop.ini
  • %PROGRAM_FILES%\FireFox\modules\services-sync\_desktop.ini
  • C:\Far2\Plugins\TmpPanel\_desktop.ini
  • C:\Far2\Plugins\WinSCP\_desktop.ini
  • C:\Far2\Plugins\Network\_desktop.ini
  • C:\Far2\Plugins\ProcList\_desktop.ini
  • C:\Far2\Plugins\WinSCP\components\_desktop.ini
  • C:\Far2\Plugins\WinSCP\dragext\_desktop.ini
  • C:\Far2\Plugins\WinSCP\far\_desktop.ini
  • C:\Far2\Plugins\WinSCP\console\_desktop.ini
  • C:\Far2\Plugins\WinSCP\core\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\sources\RegExp\_desktop.ini
  • C:\Far2\Plugins\FarCmds\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\keys\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\sources\_desktop.ini
  • C:\Far2\Plugins\FileCase\_desktop.ini
  • C:\Far2\Plugins\HlfViewer\_desktop.ini
  • C:\Far2\Plugins\MacroView\_desktop.ini
  • C:\Far2\Plugins\FTP\_desktop.ini
  • C:\Far2\Plugins\FTP\lib\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\theme\_desktop.ini
  • C:\Far2\Plugins\WinSCP\putty\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\tb2k\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\tbx\_desktop.ini
  • C:\Far2\Plugins\WinSCP\putty\charset\_desktop.ini
  • C:\Far2\PluginSDK\_desktop.ini
  • C:\Far2\PluginSDK\Headers.c\_desktop.ini
  • C:\Far2\Plugins\WinSCP\release\_desktop.ini
  • C:\Far2\Plugins\WinSCP\resource\_desktop.ini
  • C:\Far2\Plugins\WinSCP\filezilla\misc\_desktop.ini
  • C:\Far2\Plugins\WinSCP\forms\_desktop.ini
  • C:\Far2\Plugins\WinSCP\fari\_desktop.ini
  • C:\Far2\Plugins\WinSCP\filezilla\_desktop.ini
  • C:\Far2\Plugins\WinSCP\lib\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\filemng\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\my\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\_desktop.ini
  • C:\Far2\Plugins\WinSCP\packages\dragndrop\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\doc\_desktop.ini
  • C:\Far2\Addons\XLat\Russian\_desktop.ini
  • C:\Far2\Documentation\_desktop.ini
  • C:\Far2\Addons\Shell\_desktop.ini
  • C:\Far2\Addons\XLat\_desktop.ini
  • C:\Far2\Documentation\eng\_desktop.ini
  • C:\Far2\FExcept\_desktop.ini
  • C:\Far2\Plugins\_desktop.ini
  • C:\Far2\Documentation\rus\_desktop.ini
  • C:\Far2\Encyclopedia\_desktop.ini
  • C:\Far2\_desktop.ini
  • C:\Far2\Addons\_desktop.ini
  • C:\_desktop.ini
  • <Current directory>\_desktop.ini
  • C:\Far2\Addons\Colors\_desktop.ini
  • C:\Far2\Addons\Macros\_desktop.ini
  • C:\Far2\Addons\SetUp\_desktop.ini
  • C:\Far2\Addons\Colors\Custom Highlighting\_desktop.ini
  • C:\Far2\Addons\Colors\Default Highlighting\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrd\console\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrd\console\contrib\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrc\auto\types\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrd\_desktop.ini
  • C:\Far2\Plugins\Compare\_desktop.ini
  • C:\Far2\Plugins\EMenu\_desktop.ini
  • C:\Far2\Plugins\ExtSearch\_desktop.ini
  • C:\Far2\Plugins\DrawLine\_desktop.ini
  • C:\Far2\Plugins\EditCase\_desktop.ini
  • C:\Far2\Plugins\arclite\_desktop.ini
  • C:\Far2\Plugins\AutoWrap\_desktop.ini
  • C:\Far2\Plugins\7-Zip\_desktop.ini
  • C:\Far2\Plugins\Align\_desktop.ini
  • C:\Far2\Plugins\Brackets\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrc\_desktop.ini
  • C:\Far2\Plugins\Colorer\hrc\auto\_desktop.ini
  • C:\Far2\Plugins\Colorer\_desktop.ini
  • C:\Far2\Plugins\Colorer\bin\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\alerts\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\autoconfig\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser-region\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\cookie\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\layout\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\search\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\dom\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\feeds\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\branding\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\migration\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\safebrowsing\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\sidebar\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\downloads\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\extensions\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-region\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\handling\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\profile\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\update\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\plugins\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xml\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xpinstall\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\security\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\svg\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xslt\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\unix\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\win\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\mac\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\feeds\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\history\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\bookmarks\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\certerror\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\migration\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\safebrowsing\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\pageinfo\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\places\_desktop.ini
  • %PROGRAM_FILES%\_desktop.ini
  • %PROGRAM_FILES%\FireFox\_desktop.ini
  • C:\Far2\PluginSDK\Headers.pas\_desktop.ini
  • <Auxiliary element>
  • %PROGRAM_FILES%\FireFox\chrome\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\branding\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\feeds\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\places\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\tabview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\communicator\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\en-US\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\tabbrowser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\tabview\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\search\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\preferences\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\tabbrowser\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\feeds\_desktop.ini
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\places\_desktop.ini
Moves the following files:
  • from <Full path to virus>.exe to <Full path to virus>
Deletes itself.
Network activity:
Connects to:
  • '<Private IP address>':80
  • '<Private IP address>':139
  • '<Private IP address>':445
Miscellaneous:
Searches for the following windows:
  • ClassName: 'RavMonClass' WindowName: 'RavMon.exe'

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android