Library
My library

+ Add to library

Profile

Trojan.DownLoader38.39556

Added to the Dr.Web virus database: 2021-05-01

Virus description added:

Technical Information

Modifies file system
Creates the following files
  • <Current directory>\updates\temp\8c856ada-219a-4d97-8af6-9eaa4b2d282c
  • <Current directory>\updates\temp\1d7943b1-52e4-4595-9ae1-901594f06d21
  • <Current directory>\updates\temp\01a1db87-77be-4777-97c6-5d2ec527ce8f
  • <Current directory>\updates\temp\daee4970-6f08-4094-b067-92fab18186ee
  • <Current directory>\updates\temp\73192fac-14c5-4154-8784-e8693985d479
  • <Current directory>\updates\temp\47c35bbb-da3e-49e2-82a5-57cd2fff9824
  • <Current directory>\updates\temp\6c64ca89-a6f6-4a0f-a5ef-c15d5fcee975
  • <Current directory>\updates\temp\69cab0f8-fca6-4a03-94fe-c3abce000f19
  • <Current directory>\updates\temp\c6c2d517-3534-4556-907e-13ad8ee637d2
  • <Current directory>\updates\temp\9a0276f2-530e-4ff0-a1b4-8ef37bef23a2
  • <Current directory>\updates\temp\5faf3496-36f2-445e-b2df-76c083f029d3
  • <Current directory>\updates\temp\67354f22-83c4-4eeb-8599-72fe1b241d24
  • <Current directory>\updates\temp\0f443b32-5402-49a2-aa67-5b232827ac68
  • <Current directory>\updates\temp\505b149b-dfde-49f6-a290-d9a63271323a
  • <Current directory>\updates\temp\fe5bbdec-e767-4978-9e82-e5a6f03b9499
  • <Current directory>\updates\addons.xml
  • <Current directory>\updates\temp\fc4798f8-f66b-4919-b2ac-039dedd8fd5c
  • <Current directory>\updates\temp\9d10c847-9494-497a-b8d8-abea35cb004d
  • <Current directory>\plugins\libs\socket\core.dll.tmp
  • <Current directory>\plugins\libs\mime\core.dll.tmp
  • <Current directory>\updates\temp\b7b97168-c6b8-4356-ac11-ab9d5acb0d88
  • <Current directory>\updates\temp\879bf745-8a38-4c60-a51e-51eb039f8d47
  • <Current directory>\updates\temp\6c741abc-aeb1-4193-9a97-74165b7f043e
  • <Current directory>\updates\temp\7bf30b8f-512d-45c8-9c5c-6472f30eb94d
  • <Current directory>\updates\temp\47ac02dc-6710-448c-8334-9556fdfa72d6
  • <Current directory>\updates\temp\88fbf87f-bcc0-4eb8-a2c8-18e6a0fa500b
  • <Current directory>\updates\temp\85aae74b-2edf-4dc0-824b-711febd92896
  • <Current directory>\updates\temp\09ad7556-4bab-4fdf-8b45-e7993791ebd2
  • <Current directory>\updates\temp\fe7914c7-4d55-475a-a3ba-ce44b787c9c6
  • <Current directory>\updates\temp\b4d8115a-0cca-480b-9b3b-3d40aa509d5c
  • <Current directory>\updates\temp\af6ccbad-242a-4b7d-a39c-6fccfa4ae445
  • <Current directory>\updates\temp\7bbfa84e-5a68-416f-ab74-9db29c6f58a4
  • <Current directory>\updates\temp\e48d54d5-d620-4f89-bc9b-90281728de5a
  • <Current directory>\updates\temp\7a454324-db16-4f2c-b8df-20d77c43dbf4
  • <Current directory>\updates\temp\78a57e8b-ff3e-4814-9425-012ffc561bbe
  • <Current directory>\updates\temp\16380db9-cf63-4c2b-83eb-69e6286cb78f
  • <Current directory>\updates\temp\84d524fe-e325-4312-9e31-6fccb13fc877
  • <Current directory>\updates\temp\30bb3782-4f56-4b5b-b8d8-71cbe359f283
  • <Current directory>\updates\temp\32c3a16c-ad0e-43ab-8f4c-a180c4d6a6c9
  • <Current directory>\updates\temp\bd3b3016-ce34-4251-b2ab-9507a51b5117
  • <Current directory>\updates\temp\0effaa1c-8279-456b-84bc-2c04ee3607a4
  • <Current directory>\updates\temp\dfbe4e5b-1855-41f5-a719-9edd35f0d72a
  • <Current directory>\updates\temp\cd704fe4-e201-48bc-ba69-93bb3434378c
  • <Current directory>\updates\temp\5fde2fa7-876c-408d-b3ec-ced4cefb25c3
  • <Current directory>\updates\temp\d56a81b3-e20c-4ac7-89d2-eabac49f0430
  • <Current directory>\updates\temp\a53b0380-acce-4462-bb02-f4360c8fc641
  • <Current directory>\updates\temp\38720455-383c-4da5-a7b5-2c9ebbc54fb7
  • <Current directory>\updates\temp\006ea956-4e4d-4120-9bcf-7ba7647c3acd
  • <Current directory>\updates\temp\d4198b04-8c5f-43da-8d61-a31aadf5c091
  • <Current directory>\updates\temp\2e992ee7-346e-4660-a8a5-891cfea83358
  • <Current directory>\updates\temp\52d0e76e-103e-4155-aab4-ec8de3c41b1e
  • <Current directory>\updates\temp\48b46c08-11f5-4961-92bd-2d4d3d0990e1
  • <Current directory>\updates\temp\7320bbd2-1ccb-4cbb-92e9-e6adbb96c3e9
  • <Current directory>\updates\temp\11fedc10-689d-4b9b-a08a-361fc66fdaa4
  • <Current directory>\updates\temp\c9d82c50-7f8d-476c-b76f-f169afc74c9c
  • <Current directory>\updates\temp\fd34c351-a212-4adc-b8cb-7d653eff6eed
  • <Current directory>\updates\temp\51d56b20-e33f-45e8-a7ac-bc087c9e7524
  • <Current directory>\updates\temp\55db5ab1-f3ae-490e-8074-379ca04cbb25
  • <Current directory>\updates\temp\a39c4d5c-fadc-4534-9fab-4ae40541030a
  • <Current directory>\updates\temp\c781b8a2-2292-4183-9447-0396ee946a55
  • <Current directory>\updates\temp\80463b5c-ecdf-4b85-a914-df6ab1d88ed4
  • <Current directory>\updates\temp\d76a846e-dccb-440d-b631-f7ae30a97632
  • <Current directory>\updates\temp\9b78c2c5-6bb4-47f0-bd54-685367d194ff
  • <Current directory>\updates\temp\a67511c7-007b-43c0-8344-645bfeddaa5d
  • <Current directory>\updates\temp\534a30c4-d61d-417a-a43d-9514f318e884
  • <Current directory>\updates\temp\a943f842-9978-41b1-8ee8-34b782ff0e73
  • <Current directory>\updates\temp\fd7e174c-3635-4a9f-945f-3fd550a908c4
  • <Current directory>\updates\temp\4cbc3bfa-3092-412e-a02c-246417ec7fd0
  • <Current directory>\settings.xml
  • <Current directory>\updates\temp\5521b038-6b0d-4dca-b611-d9e934d1cdba
  • <Current directory>\updates\temp\e9dd0bd8-26d9-4aa0-8987-80ed6ae42a69
  • <Current directory>\updates\temp\a03c9082-2e2f-41b3-ae0d-c25b672e4834
  • <Current directory>\updates\temp\5f36bbb5-f6c4-48f1-a293-ff4a318a5adc
  • <Current directory>\updates\temp\da05cd7e-ac50-4399-b9d9-edf070765af3
  • <Current directory>\updates\temp\93bf98d3-1e30-4b1a-9b1b-f6e22c9bb73f
  • <Current directory>\updates\temp\e116e461-9be2-4387-9f3d-5fc4bdceded2
  • <Current directory>\updates\temp\1cc64efa-60c0-4c8a-bd00-2144cada870f
  • <Current directory>\updates\temp\3c84d34a-6531-4ea1-bbee-40392522044b
  • <Current directory>\updates\temp\2a637d12-6bf6-428f-8e98-ef41fc0feb43
  • <Current directory>\updates\temp\231d0c05-22e0-4b7c-be2f-2fc738bd8418
  • <Current directory>\updates\temp\ddf2f998-6a1b-4d45-9111-7b6d626edac4
  • <Current directory>\updates\temp\ac7c7cfc-a1bb-4d09-9705-55a4b2d2ed1d
  • <Current directory>\updates\temp\9c334357-89e8-448c-bdcc-a3170ac34d1f
  • <Current directory>\updates\temp\8162f06a-e0ad-4ea2-bb72-e270f8d892fb
  • <Current directory>\updates\temp\bfc7a8fa-1f25-41e8-a069-bc3ecf0cb09e
  • <Current directory>\updates\temp\1f680a08-20a4-444b-801e-82520d229f7c
  • <Current directory>\updates\temp\0fd99674-1dba-4588-a911-2e2975dba8a1
  • <Current directory>\updates\temp\28621e62-8054-4abb-b7b0-f6ecab7341a7
  • <Current directory>\updates\temp\3dc4ca9a-0a90-4a02-8e70-5d4b34e6720e
  • <Current directory>\updates\temp\584e5ae0-73f8-4228-bcef-c5a0b8256594
  • <Current directory>\updates\temp\105e51fb-a7b5-497b-97c3-f7f9e3cf091a
  • <Current directory>\updates\temp\0a6463ba-ed9b-4e81-bd32-5a64b8944c58
  • <Current directory>\updates\temp\7da4d2c5-4259-4156-af65-6adcd60ff15a
  • <Current directory>\updates\temp\61d0457d-0338-44b8-b8f6-6c2fd272e970
  • <Current directory>\updates\temp\a87f6c49-e39e-4363-8f03-d76422b2b5ae
  • <Current directory>\updates\temp\094ffc22-fd4f-4985-bfb7-849b7ade6c7c
  • <Current directory>\updates\temp\2cfc70ec-220e-4c70-8099-5b33dca5b074
Deletes the following files
  • <Current directory>\updates\temp\b7b97168-c6b8-4356-ac11-ab9d5acb0d88
Moves the following files
  • from <Current directory>\updates\temp\8c856ada-219a-4d97-8af6-9eaa4b2d282c to <Current directory>\updates\manifest.xml
  • from <Current directory>\updates\temp\6c741abc-aeb1-4193-9a97-74165b7f043e to <Current directory>\addons\libs\ltn12.lua
  • from <Current directory>\updates\temp\5faf3496-36f2-445e-b2df-76c083f029d3 to <Current directory>\addons\libs\logger.xml
  • from <Current directory>\updates\temp\1d7943b1-52e4-4595-9ae1-901594f06d21 to <Current directory>\addons\libs\logger.lua
  • from <Current directory>\updates\temp\01a1db87-77be-4777-97c6-5d2ec527ce8f to <Current directory>\addons\libs\lists.lua
  • from <Current directory>\updates\temp\daee4970-6f08-4094-b067-92fab18186ee to <Current directory>\addons\libs\json.lua
  • from <Current directory>\updates\temp\73192fac-14c5-4154-8784-e8693985d479 to <Current directory>\addons\libs\images.lua
  • from <Current directory>\updates\temp\47c35bbb-da3e-49e2-82a5-57cd2fff9824 to <Current directory>\addons\libs\functions.lua
  • from <Current directory>\updates\temp\6c64ca89-a6f6-4a0f-a5ef-c15d5fcee975 to <Current directory>\addons\libs\files.lua
  • from <Current directory>\updates\temp\69cab0f8-fca6-4a03-94fe-c3abce000f19 to <Current directory>\addons\libs\extdata.lua
  • from <Current directory>\updates\temp\9a0276f2-530e-4ff0-a1b4-8ef37bef23a2 to <Current directory>\addons\libs\chat\icons.lua
  • from <Current directory>\updates\temp\47ac02dc-6710-448c-8334-9556fdfa72d6 to <Current directory>\addons\libs\maths.lua
  • from <Current directory>\updates\temp\67354f22-83c4-4eeb-8599-72fe1b241d24 to <Current directory>\addons\libs\chat\controls.lua
  • from <Current directory>\updates\temp\879bf745-8a38-4c60-a51e-51eb039f8d47 to <Current directory>\addons\libs\chat\colors.lua
  • from <Current directory>\updates\temp\0f443b32-5402-49a2-aa67-5b232827ac68 to <Current directory>\addons\libs\chat\chars.lua
  • from <Current directory>\updates\temp\505b149b-dfde-49f6-a290-d9a63271323a to <Current directory>\addons\libs\chat.lua
  • from <Current directory>\updates\temp\fe5bbdec-e767-4978-9e82-e5a6f03b9499 to <Current directory>\addons\libs\actions.lua
  • from <Current directory>\updates\temp\fc4798f8-f66b-4919-b2ac-039dedd8fd5c to <Current directory>\updates\addons
  • from <Current directory>\updates\temp\9d10c847-9494-497a-b8d8-abea35cb004d to <Current directory>\updates\temp\addons.json
  • from <Current directory>\plugins\libs\socket\core.dll.tmp to <Current directory>\plugins\libs\socket\core.dll
  • from <Current directory>\updates\temp\c6c2d517-3534-4556-907e-13ad8ee637d2 to <Current directory>\addons\libs\config.lua
  • from <Current directory>\updates\temp\8162f06a-e0ad-4ea2-bb72-e270f8d892fb to <Current directory>\res\statuses.lua
  • from <Current directory>\updates\temp\a53b0380-acce-4462-bb02-f4360c8fc641 to <Current directory>\addons\libs\matrices.lua
  • from <Current directory>\updates\temp\006ea956-4e4d-4120-9bcf-7ba7647c3acd to <Current directory>\addons\libs\vectors.lua
  • from <Current directory>\updates\temp\88fbf87f-bcc0-4eb8-a2c8-18e6a0fa500b to <Current directory>\addons\libs\timeit.lua
  • from <Current directory>\updates\temp\85aae74b-2edf-4dc0-824b-711febd92896 to <Current directory>\addons\libs\texts.lua
  • from <Current directory>\updates\temp\09ad7556-4bab-4fdf-8b45-e7993791ebd2 to <Current directory>\addons\libs\tables.lua
  • from <Current directory>\updates\temp\fe7914c7-4d55-475a-a3ba-ce44b787c9c6 to <Current directory>\addons\libs\strings.lua
  • from <Current directory>\updates\temp\b4d8115a-0cca-480b-9b3b-3d40aa509d5c to <Current directory>\addons\libs\socket\url.lua
  • from <Current directory>\updates\temp\af6ccbad-242a-4b7d-a39c-6fccfa4ae445 to <Current directory>\addons\libs\socket\tp.lua
  • from <Current directory>\updates\temp\7bbfa84e-5a68-416f-ab74-9db29c6f58a4 to <Current directory>\addons\libs\socket\smtp.lua
  • from <Current directory>\updates\temp\e48d54d5-d620-4f89-bc9b-90281728de5a to <Current directory>\addons\libs\socket\http.lua
  • from <Current directory>\plugins\libs\mime\core.dll.tmp to <Current directory>\plugins\libs\mime\core.dll
  • from <Current directory>\updates\temp\7bf30b8f-512d-45c8-9c5c-6472f30eb94d to <Current directory>\addons\libs\luau.lua
  • from <Current directory>\updates\temp\16380db9-cf63-4c2b-83eb-69e6286cb78f to <Current directory>\addons\libs\socket.lua
  • from <Current directory>\updates\temp\84d524fe-e325-4312-9e31-6fccb13fc877 to <Current directory>\addons\libs\slips.lua
  • from <Current directory>\updates\temp\30bb3782-4f56-4b5b-b8d8-71cbe359f283 to <Current directory>\addons\libs\sets.lua
  • from <Current directory>\updates\temp\32c3a16c-ad0e-43ab-8f4c-a180c4d6a6c9 to <Current directory>\addons\libs\resources.lua
  • from <Current directory>\updates\temp\bd3b3016-ce34-4251-b2ab-9507a51b5117 to <Current directory>\addons\libs\readme.md
  • from <Current directory>\updates\temp\0effaa1c-8279-456b-84bc-2c04ee3607a4 to <Current directory>\addons\libs\queues.lua
  • from <Current directory>\updates\temp\dfbe4e5b-1855-41f5-a719-9edd35f0d72a to <Current directory>\addons\libs\packets\fields.lua
  • from <Current directory>\updates\temp\cd704fe4-e201-48bc-ba69-93bb3434378c to <Current directory>\addons\libs\packets\data.lua
  • from <Current directory>\updates\temp\5fde2fa7-876c-408d-b3ec-ced4cefb25c3 to <Current directory>\addons\libs\packets.lua
  • from <Current directory>\updates\temp\78a57e8b-ff3e-4814-9425-012ffc561bbe to <Current directory>\addons\libs\socket\ftp.lua
  • from <Current directory>\updates\temp\d56a81b3-e20c-4ac7-89d2-eabac49f0430 to <Current directory>\addons\libs\mime.lua
  • from <Current directory>\updates\temp\38720455-383c-4da5-a7b5-2c9ebbc54fb7 to <Current directory>\plugins\luacore.dll
  • from <Current directory>\updates\temp\d4198b04-8c5f-43da-8d61-a31aadf5c091 to <Current directory>\plugins\resources\status.xml
  • from <Current directory>\updates\temp\094ffc22-fd4f-4985-bfb7-849b7ade6c7c to <Current directory>\plugins\resources\spells.xml
  • from <Current directory>\updates\temp\a39c4d5c-fadc-4534-9fab-4ae40541030a to <Current directory>\res\check_ratings.lua
  • from <Current directory>\updates\temp\c781b8a2-2292-4183-9447-0396ee946a55 to <Current directory>\res\job_points.lua
  • from <Current directory>\updates\temp\52d0e76e-103e-4155-aab4-ec8de3c41b1e to <Current directory>\res\job_abilities.lua
  • from <Current directory>\updates\temp\48b46c08-11f5-4961-92bd-2d4d3d0990e1 to <Current directory>\res\items_grammar.lua
  • from <Current directory>\updates\temp\7320bbd2-1ccb-4cbb-92e9-e6adbb96c3e9 to <Current directory>\res\items.lua
  • from <Current directory>\updates\temp\11fedc10-689d-4b9b-a08a-361fc66fdaa4 to <Current directory>\res\item_descriptions.lua
  • from <Current directory>\updates\temp\c9d82c50-7f8d-476c-b76f-f169afc74c9c to <Current directory>\res\encumbrance.lua
  • from <Current directory>\updates\temp\fd34c351-a212-4adc-b8cb-7d653eff6eed to <Current directory>\res\emotes.lua
  • from <Current directory>\updates\temp\51d56b20-e33f-45e8-a7ac-bc087c9e7524 to <Current directory>\res\elements.lua
  • from <Current directory>\updates\temp\2cfc70ec-220e-4c70-8099-5b33dca5b074 to <Current directory>\addons\libs\xml.lua
  • from <Current directory>\updates\temp\5f36bbb5-f6c4-48f1-a293-ff4a318a5adc to <Current directory>\res\jobs.lua
  • from <Current directory>\updates\temp\80463b5c-ecdf-4b85-a914-df6ab1d88ed4 to <Current directory>\res\chat.lua
  • from <Current directory>\updates\temp\e9dd0bd8-26d9-4aa0-8987-80ed6ae42a69 to <Current directory>\res\buffs.lua
  • from <Current directory>\updates\temp\d76a846e-dccb-440d-b631-f7ae30a97632 to <Current directory>\res\bags.lua
  • from <Current directory>\updates\temp\9b78c2c5-6bb4-47f0-bd54-685367d194ff to <Current directory>\res\auto_translates.lua
  • from <Current directory>\updates\temp\a67511c7-007b-43c0-8344-645bfeddaa5d to <Current directory>\res\augments.lua
  • from <Current directory>\updates\temp\534a30c4-d61d-417a-a43d-9514f318e884 to <Current directory>\res\action_messages.lua
  • from <Current directory>\updates\temp\a943f842-9978-41b1-8ee8-34b782ff0e73 to <Current directory>\res\ability_recasts.lua
  • from <Current directory>\updates\temp\fd7e174c-3635-4a9f-945f-3fd550a908c4 to <Current directory>\updates\resources.xml
  • from <Current directory>\updates\temp\4cbc3bfa-3092-412e-a02c-246417ec7fd0 to <Current directory>\hook.dll
  • from <Current directory>\updates\temp\55db5ab1-f3ae-490e-8074-379ca04cbb25 to <Current directory>\res\days.lua
  • from <Current directory>\updates\temp\7a454324-db16-4f2c-b8df-20d77c43dbf4 to <Current directory>\addons\libs\socket\headers.lua
  • from <Current directory>\updates\temp\da05cd7e-ac50-4399-b9d9-edf070765af3 to <Current directory>\res\key_items.lua
  • from <Current directory>\updates\temp\7da4d2c5-4259-4156-af65-6adcd60ff15a to <Current directory>\res\monstrosity.lua
  • from <Current directory>\updates\temp\a87f6c49-e39e-4363-8f03-d76422b2b5ae to <Current directory>\res\merit_points.lua
  • from <Current directory>\updates\temp\2e992ee7-346e-4660-a8a5-891cfea83358 to <Current directory>\plugins\resources\items_weapons.xml
  • from <Current directory>\updates\temp\93bf98d3-1e30-4b1a-9b1b-f6e22c9bb73f to <Current directory>\plugins\resources\items_general.xml
  • from <Current directory>\updates\temp\e116e461-9be2-4387-9f3d-5fc4bdceded2 to <Current directory>\plugins\resources\items_armor.xml
  • from <Current directory>\updates\temp\1cc64efa-60c0-4c8a-bd00-2144cada870f to <Current directory>\plugins\resources\areas.xml
  • from <Current directory>\updates\temp\3c84d34a-6531-4ea1-bbee-40392522044b to <Current directory>\plugins\resources\abils.xml
  • from <Current directory>\updates\temp\2a637d12-6bf6-428f-8e98-ef41fc0feb43 to <Current directory>\res\zones.lua
  • from <Current directory>\updates\temp\231d0c05-22e0-4b7c-be2f-2fc738bd8418 to <Current directory>\res\weather.lua
  • from <Current directory>\updates\temp\ddf2f998-6a1b-4d45-9111-7b6d626edac4 to <Current directory>\res\weapon_skills.lua
  • from <Current directory>\updates\temp\61d0457d-0338-44b8-b8f6-6c2fd272e970 to <Current directory>\res\monster_abilities.lua
  • from <Current directory>\updates\temp\ac7c7cfc-a1bb-4d09-9705-55a4b2d2ed1d to <Current directory>\res\titles.lua
  • from <Current directory>\updates\temp\a03c9082-2e2f-41b3-ae0d-c25b672e4834 to <Current directory>\res\job_traits.lua
  • from <Current directory>\updates\temp\bfc7a8fa-1f25-41e8-a069-bc3ecf0cb09e to <Current directory>\res\spells.lua
  • from <Current directory>\updates\temp\1f680a08-20a4-444b-801e-82520d229f7c to <Current directory>\res\slots.lua
  • from <Current directory>\updates\temp\0fd99674-1dba-4588-a911-2e2975dba8a1 to <Current directory>\res\skills.lua
  • from <Current directory>\updates\temp\28621e62-8054-4abb-b7b0-f6ecab7341a7 to <Current directory>\res\servers.lua
  • from <Current directory>\updates\temp\3dc4ca9a-0a90-4a02-8e70-5d4b34e6720e to <Current directory>\res\regions.lua
  • from <Current directory>\updates\temp\584e5ae0-73f8-4228-bcef-c5a0b8256594 to <Current directory>\res\races.lua
  • from <Current directory>\updates\temp\105e51fb-a7b5-497b-97c3-f7f9e3cf091a to <Current directory>\res\mounts.lua
  • from <Current directory>\updates\temp\0a6463ba-ed9b-4e81-bd32-5a64b8944c58 to <Current directory>\res\moon_phases.lua
  • from <Current directory>\updates\temp\9c334357-89e8-448c-bdcc-a3170ac34d1f to <Current directory>\res\synth_ranks.lua
  • from <Current directory>\updates\temp\addons.json to <Current directory>\updates\addons.json
Substitutes the following executable files
  • <Full path to file>
Moves itself
  • from <Full path to file> to <Current directory>\updates\temp\2a8d2021-1966-49f0-b091-1a6949f4548c
Deletes itself.
Network activity
Connects to
  • 'ss#.####le-analytics.com':443
  • 'up####.windower.net':80
  • 'up####.windower.net':443
  • 'ap#.#ithub.com':443
TCP
HTTP GET requests
  • http://up####.windower.net/dev//Windower.exe
  • http://up####.windower.net/resources/lua/moon_phases.lua
  • http://up####.windower.net/resources/lua/mounts.lua
  • http://up####.windower.net/resources/lua/races.lua
  • http://up####.windower.net/resources/lua/regions.lua
  • http://up####.windower.net/resources/lua/servers.lua
  • http://up####.windower.net/resources/lua/skills.lua
  • http://up####.windower.net/resources/lua/slots.lua
  • http://up####.windower.net/resources/lua/spells.lua
  • http://up####.windower.net/resources/lua/statuses.lua
  • http://up####.windower.net/resources/lua/synth_ranks.lua
  • http://up####.windower.net/resources/lua/titles.lua
  • http://up####.windower.net/resources/lua/weapon_skills.lua
  • http://up####.windower.net/resources/lua/weather.lua
  • http://up####.windower.net/resources/lua/zones.lua
  • http://up####.windower.net/resources/data/abils.xml
  • http://up####.windower.net/resources/data/areas.xml
  • http://up####.windower.net/resources/data/items_armor.xml
  • http://up####.windower.net/resources/data/items_general.xml
  • http://up####.windower.net/resources/data/items_weapons.xml
  • http://up####.windower.net/resources/data/spells.xml
  • http://up####.windower.net/resources/data/status.xml
  • http://up####.windower.net/resources/lua/monstrosity.lua
  • http://up####.windower.net/dev/plugins/LuaCore.dll
  • http://up####.windower.net/resources/lua/monster_abilities.lua
  • http://up####.windower.net/resources/lua/key_items.lua
  • http://up####.windower.net/dev/Hook.dll
  • http://up####.windower.net/resources/manifest.xml
  • http://up####.windower.net/resources/lua/ability_recasts.lua
  • http://up####.windower.net/resources/lua/action_messages.lua
  • http://up####.windower.net/resources/lua/augments.lua
  • http://up####.windower.net/resources/lua/auto_translates.lua
  • http://up####.windower.net/resources/lua/bags.lua
  • http://up####.windower.net/resources/lua/buffs.lua
  • http://up####.windower.net/resources/lua/chat.lua
  • http://up####.windower.net/resources/lua/check_ratings.lua
  • http://up####.windower.net/resources/lua/days.lua
  • http://up####.windower.net/resources/lua/elements.lua
  • http://up####.windower.net/resources/lua/emotes.lua
  • http://up####.windower.net/resources/lua/encumbrance.lua
  • http://up####.windower.net/resources/lua/item_descriptions.lua
  • http://up####.windower.net/resources/lua/items.lua
  • http://up####.windower.net/resources/lua/items_grammar.lua
  • http://up####.windower.net/resources/lua/job_abilities.lua
  • http://up####.windower.net/resources/lua/job_points.lua
  • http://up####.windower.net/resources/lua/job_traits.lua
  • http://up####.windower.net/resources/lua/jobs.lua
  • http://up####.windower.net/resources/lua/merit_points.lua
  • http://up####.windower.net/dev/zips/LuaCore.zip
  • 'ss#.####le-analytics.com':443
  • 'up####.windower.net':443
  • 'ap#.#ithub.com':443
  • 'gi##ub.com':443
  • 'co####ad.github.com':443
  • UDP
    • DNS ASK ss#.####le-analytics.com
    • DNS ASK up####.windower.net
    • DNS ASK ap#.#ithub.com
    • DNS ASK gi##ub.com
    • DNS ASK co####ad.github.com
    Miscellaneous
    Creates and executes the following
    • '<Full path to file>' "<Full path to file>"

    Curing recommendations

    1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
    2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
    Download Dr.Web

    Download by serial number

    Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

    After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

    Download Dr.Web

    Download by serial number

    1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
    2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
      • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
      • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
      • Switch off your device and turn it on as normal.

    Find out more about Dr.Web for Android