Library
My library

+ Add to library

Profile

Trojan.DownLoader45.10826

Added to the Dr.Web virus database: 2022-08-14

Virus description added:

Technical Information

Modifies file system
Creates the following files
  • %TEMP%\is-r4r4u.tmp\is-pahha.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-m8sd1.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-154n4.tmp
  • %ProgramFiles(x86)%\viewfd\lsd\is-cbd9q.tmp
  • %ProgramFiles(x86)%\viewfd\lsd\is-ffr8f.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\is-f8o7v.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\language\is-0154r.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-sdphd.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-9eatg.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-id2s6.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-oh7mt.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-dt80t.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-170oo.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-q92vd.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-876o1.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-4vt7a.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-427ou.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-ut7bd.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-bj3av.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-0mdp3.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-9d2gr.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-jjtu3.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-188es.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-eefuv.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-va2pj.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-t6kpv.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-m657f.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-d4fjr.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-5hdju.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-c6tvm.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-6drij.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-dpiaf.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-o2q02.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-v0m36.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-43n74.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-mlktt.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-dhcgl.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-mjc01.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-9g98p.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-roa7a.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-o7ima.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-alnge.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\transition\is-osrva.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\wavehv\is-mmo72.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\wavergb\is-kcavu.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-fncnl.tmp
  • %ProgramFiles(x86)%\viewfd\ini\is-edgmg.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\shiftrgb\is-f6g18.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\textures\is-fmtch.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-6jeeg.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-qu9do.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-3m176.tmp
  • %ProgramFiles(x86)%\viewfd\url\soft\is-sti2c.tmp
  • %ProgramFiles(x86)%\viewfd\url\soft\is-ovpnc.tmp
  • %ProgramFiles(x86)%\viewfd\url\soft\is-amhmh.tmp
  • %ProgramFiles(x86)%\viewfd\wallpaper\is-a0a1j.tmp
  • %ProgramFiles(x86)%\viewfd\wallpaper\is-c0e56.tmp
  • %ProgramFiles(x86)%\viewfd\wallpaper\is-c1ukb.tmp
  • %ProgramFiles(x86)%\viewfd\wallpaper\is-7j4ie.tmp
  • %ProgramFiles(x86)%\viewfd\wallpaper\is-3jc43.tmp
  • %ProgramFiles(x86)%\viewfd\wallpaper\is-4bb4k.tmp
  • %ProgramFiles(x86)%\viewfd\wallpaper\is-l5cgh.tmp
  • %ProgramFiles(x86)%\viewfd\is-svfil.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\selection\is-r6cos.tmp
  • %ProgramFiles(x86)%\viewfd\is-aa1ge.tmp
  • %ProgramFiles(x86)%\viewfd\is-eclql.tmp
  • %ProgramFiles(x86)%\viewfd\is-ds8o1.tmp
  • %ProgramFiles(x86)%\viewfd\is-u8hu1.tmp
  • %ProgramFiles(x86)%\viewfd\is-0ossd.tmp
  • %ProgramFiles(x86)%\viewfd\is-1hclg.tmp
  • %ProgramFiles(x86)%\viewfd\is-on0p7.tmp
  • %ProgramFiles(x86)%\viewfd\is-sp7b1.tmp
  • %ProgramFiles(x86)%\viewfd\is-n9q09.tmp
  • %ProgramFiles(x86)%\viewfd\unins000.dat
  • %ProgramFiles(x86)%\viewfd\url\search\is-jksee.tmp
  • %ProgramFiles(x86)%\viewfd\search\is-4ihgf.tmp
  • %ProgramFiles(x86)%\viewfd\url\search\is-vmu0t.tmp
  • %ProgramFiles(x86)%\viewfd\search\is-kre6j.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-0pkom.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-s6dbc.tmp
  • %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-sf2h2.tmp
  • %ProgramFiles(x86)%\viewfd\programs\is-omnmo.tmp
  • %ProgramFiles(x86)%\viewfd\radio\is-ks21f.tmp
  • %ProgramFiles(x86)%\viewfd\radio\is-v7vua.tmp
  • %ProgramFiles(x86)%\viewfd\reports\is-c9gip.tmp
  • %ProgramFiles(x86)%\viewfd\search\is-eqje9.tmp
  • %ProgramFiles(x86)%\viewfd\search\is-qso21.tmp
  • %ProgramFiles(x86)%\viewfd\search\is-op6o3.tmp
  • %ProgramFiles(x86)%\viewfd\viewfd.exe
  • %ProgramFiles(x86)%\viewfd\url\search\is-jrjgf.tmp
  • %ProgramFiles(x86)%\viewfd\search\is-nb083.tmp
  • %ProgramFiles(x86)%\viewfd\soft\is-ic8te.tmp
  • %ProgramFiles(x86)%\viewfd\url\is-tsn4b.tmp
  • %ProgramFiles(x86)%\viewfd\url\is-g5kk5.tmp
  • %ProgramFiles(x86)%\viewfd\url\is-up05e.tmp
  • %ProgramFiles(x86)%\viewfd\url\is-65q73.tmp
  • %ProgramFiles(x86)%\viewfd\url\is-2l67n.tmp
  • %ProgramFiles(x86)%\viewfd\url\help\is-cer41.tmp
  • %ProgramFiles(x86)%\viewfd\url\help\is-cg7fp.tmp
  • %ProgramFiles(x86)%\viewfd\url\help\is-u311r.tmp
  • %ProgramFiles(x86)%\viewfd\url\search\is-0nkur.tmp
  • %ProgramFiles(x86)%\viewfd\is-e3qqb.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness2\is-a0tte.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\metallic\is-stp7b.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-nc7qh.tmp
  • %ProgramFiles(x86)%\viewfd\data\is-0gbsr.tmp
  • %ProgramFiles(x86)%\viewfd\forms\is-uhvhl.tmp
  • %ProgramFiles(x86)%\viewfd\formulas\is-3c680.tmp
  • %ProgramFiles(x86)%\viewfd\formulas\is-r05uv.tmp
  • %ProgramFiles(x86)%\viewfd\formulas\is-883m2.tmp
  • %ProgramFiles(x86)%\viewfd\formulas\is-5frum.tmp
  • %ProgramFiles(x86)%\viewfd\formulas\is-bkfk2.tmp
  • %ProgramFiles(x86)%\viewfd\formulas\is-miti8.tmp
  • %ProgramFiles(x86)%\viewfd\browser\is-mfoq2.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\3dturn\is-tb59c.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-49rdk.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-cd1p3.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-f18ek.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-5vk7i.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-lbb6f.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-jjic8.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-lk41g.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-vc94u.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-8haka.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-hcvkj.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-7mprn.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-ao7a1.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-r9mk5.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-ebj5e.tmp
  • %TEMP%\is-s2859.tmp\_isetup\_setup64.tmp
  • %TEMP%\is-s2859.tmp\_isetup\_shfoldr.dll
  • %TEMP%\is-s2859.tmp\_isetup\_iscrypt.dll
  • %ProgramFiles(x86)%\viewfd\is-703gj.tmp
  • %ProgramFiles(x86)%\viewfd\7-zip\lang\is-u73ac.tmp
  • %ProgramFiles(x86)%\viewfd\7-zip\is-1bthg.tmp
  • %ProgramFiles(x86)%\viewfd\7-zip\is-1rgkg.tmp
  • %ProgramFiles(x86)%\viewfd\7-zip\is-r67vm.tmp
  • %ProgramFiles(x86)%\viewfd\7-zip\is-4fs4t.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-qe1og.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-lctuc.tmp
  • %ProgramFiles(x86)%\viewfd\backup\is-8p617.tmp
  • %ProgramFiles(x86)%\viewfd\browser\is-p3mdl.tmp
  • %ProgramFiles(x86)%\viewfd\browser\is-aqc7u.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-l762m.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-qfesj.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-au93b.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-jgqve.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-qq6f4.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-mj2ds.tmp
  • %ProgramFiles(x86)%\viewfd\colourschemes\is-cq2oo.tmp
  • %TEMP%\is-s2859.tmp\_isetup\_regdll.tmp
  • %ProgramFiles(x86)%\viewfd\browser\is-ks5ee.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-3ec1o.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-cvol8.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-titgu.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-uq3p6.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-ovghm.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-5q33b.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-ls5fu.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-jklk5.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-9333e.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-iguj2.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-7u8hf.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-714qq.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-maevm.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\new\is-rd9pt.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-1ju60.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\radialrgb\is-kpnjt.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\saturation\is-4nb87.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-e2u8v.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-tlpkv.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-o0nq7.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-c812o.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-8ljkl.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-amdid.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-tn8sf.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-c8pp1.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\illuminance2\is-f1ndi.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour\is-j00ss.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\illuminance\is-a7g3f.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\cb\is-t0kne.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-p1quj.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\anyset\is-93fj5.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\barrgb\is-gn6b9.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\brightness\is-0cdq2.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\cb\is-ei7j8.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\cb\is-cgmtf.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\cb\is-k4jdo.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\cb\is-kmphf.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\cb\is-9llv8.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\cb\is-q71cd.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-okvr5.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\ellipsergb\is-m5mn7.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour\is-6fuva.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour\is-0e3fn.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour\is-ip8n2.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour\is-pkk62.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour\is-j1c46.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour\is-bg4r6.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour\is-addfd.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour2\is-ua1qo.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour2\is-jqtim.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\contour2\is-2uu6i.tmp
  • %ProgramFiles(x86)%\viewfd\graphic\grids\is-iq4cn.tmp
  • %TEMP%\lohkos.cab
Moves the following files
  • from %ProgramFiles(x86)%\viewfd\is-703gj.tmp to %ProgramFiles(x86)%\viewfd\unins000.exe
  • from %ProgramFiles(x86)%\viewfd\ini\is-m8sd1.tmp to %ProgramFiles(x86)%\viewfd\ini\picture.ini
  • from %ProgramFiles(x86)%\viewfd\ini\is-154n4.tmp to %ProgramFiles(x86)%\viewfd\ini\readme.txt
  • from %ProgramFiles(x86)%\viewfd\lsd\is-cbd9q.tmp to %ProgramFiles(x86)%\viewfd\lsd\default.lsd
  • from %ProgramFiles(x86)%\viewfd\lsd\is-ffr8f.tmp to %ProgramFiles(x86)%\viewfd\lsd\readme.txt
  • from %ProgramFiles(x86)%\viewfd\plugins\is-f8o7v.tmp to %ProgramFiles(x86)%\viewfd\plugins\readme.txt
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\language\is-0154r.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\language\russian.lng
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-sdphd.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\copying
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-9eatg.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\ark32.dll
  • from %ProgramFiles(x86)%\viewfd\ini\is-jjtu3.tmp to %ProgramFiles(x86)%\viewfd\ini\ms office.ini
  • from %ProgramFiles(x86)%\viewfd\ini\is-188es.tmp to %ProgramFiles(x86)%\viewfd\ini\owner.ini
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-id2s6.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\archive.plg
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-170oo.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\hv3.plg
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-q92vd.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\jbig.plg
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-876o1.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\jpeg2000.plg
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-4vt7a.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\openexr.plg
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-427ou.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\webp.plg
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-ut7bd.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\arklicense.txt
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-bj3av.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\dir.txt
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-0mdp3.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\imagine.chm
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-dt80t.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\dcraw.plg
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\is-dhcgl.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\plugin\hdphoto.plg
  • from %ProgramFiles(x86)%\viewfd\ini\is-eefuv.tmp to %ProgramFiles(x86)%\viewfd\ini\mp3 and wma.ini
  • from %ProgramFiles(x86)%\viewfd\ini\is-va2pj.tmp to %ProgramFiles(x86)%\viewfd\ini\example2.ini
  • from %ProgramFiles(x86)%\viewfd\ini\is-t6kpv.tmp to %ProgramFiles(x86)%\viewfd\ini\example1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-d4fjr.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\bricks.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-5hdju.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\embossing1.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-c6tvm.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\embossing2.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-6drij.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\embossing3.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-dpiaf.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\embossing4.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-o2q02.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\grid1.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-v0m36.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\grid2.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-43n74.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\line1.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-mjc01.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\line2.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-m657f.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\b-a-v.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-oh7mt.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\line3.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-9g98p.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\red.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-roa7a.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\viewfd.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-o7ima.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\y-r-v.bmp
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-alnge.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\transition\is-osrva.tmp to %ProgramFiles(x86)%\viewfd\graphic\transition\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\wavehv\is-mmo72.tmp to %ProgramFiles(x86)%\viewfd\graphic\wavehv\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\wavergb\is-kcavu.tmp to %ProgramFiles(x86)%\viewfd\graphic\wavergb\readme.txt
  • from %ProgramFiles(x86)%\viewfd\ini\is-fncnl.tmp to %ProgramFiles(x86)%\viewfd\ini\default.ini
  • from %ProgramFiles(x86)%\viewfd\ini\is-edgmg.tmp to %ProgramFiles(x86)%\viewfd\ini\description.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\textures\is-fmtch.tmp to %ProgramFiles(x86)%\viewfd\graphic\textures\purple.bmp
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-9d2gr.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\imagine.dll
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-mlktt.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\imagine.exe
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-6jeeg.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\pluginst.inf
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-qu9do.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\imagine.ini
  • from %ProgramFiles(x86)%\viewfd\url\search\is-vmu0t.tmp to %ProgramFiles(x86)%\viewfd\url\search\sputnik.url
  • from %ProgramFiles(x86)%\viewfd\url\search\is-jksee.tmp to %ProgramFiles(x86)%\viewfd\url\search\yandex.url
  • from %ProgramFiles(x86)%\viewfd\url\soft\is-sti2c.tmp to %ProgramFiles(x86)%\viewfd\url\soft\oszone.url
  • from %ProgramFiles(x86)%\viewfd\url\soft\is-ovpnc.tmp to %ProgramFiles(x86)%\viewfd\url\soft\softodrom.url
  • from %ProgramFiles(x86)%\viewfd\url\soft\is-amhmh.tmp to %ProgramFiles(x86)%\viewfd\url\soft\softportal.url
  • from %ProgramFiles(x86)%\viewfd\wallpaper\is-a0a1j.tmp to %ProgramFiles(x86)%\viewfd\wallpaper\blue.jpg
  • from %ProgramFiles(x86)%\viewfd\wallpaper\is-c0e56.tmp to %ProgramFiles(x86)%\viewfd\wallpaper\darkblue.jpg
  • from %ProgramFiles(x86)%\viewfd\wallpaper\is-c1ukb.tmp to %ProgramFiles(x86)%\viewfd\wallpaper\darkyellow.jpg
  • from %ProgramFiles(x86)%\viewfd\wallpaper\is-7j4ie.tmp to %ProgramFiles(x86)%\viewfd\wallpaper\silver.jpg
  • from %ProgramFiles(x86)%\viewfd\wallpaper\is-3jc43.tmp to %ProgramFiles(x86)%\viewfd\wallpaper\viewfd.jpg
  • from %ProgramFiles(x86)%\viewfd\wallpaper\is-4bb4k.tmp to %ProgramFiles(x86)%\viewfd\wallpaper\white.jpg
  • from %ProgramFiles(x86)%\viewfd\wallpaper\is-l5cgh.tmp to %ProgramFiles(x86)%\viewfd\wallpaper\readme.txt
  • from %ProgramFiles(x86)%\viewfd\is-e3qqb.tmp to %ProgramFiles(x86)%\viewfd\turbosearch.exe
  • from %ProgramFiles(x86)%\viewfd\is-svfil.tmp to %ProgramFiles(x86)%\viewfd\viewfd.exe
  • from %ProgramFiles(x86)%\viewfd\is-aa1ge.tmp to %ProgramFiles(x86)%\viewfd\bootfd.ini
  • from %ProgramFiles(x86)%\viewfd\is-eclql.tmp to %ProgramFiles(x86)%\viewfd\viewfd.ini
  • from %ProgramFiles(x86)%\viewfd\is-ds8o1.tmp to %ProgramFiles(x86)%\viewfd\viewfd2.ini
  • from %ProgramFiles(x86)%\viewfd\is-u8hu1.tmp to %ProgramFiles(x86)%\viewfd\viewfd home site.url
  • from %ProgramFiles(x86)%\viewfd\is-0ossd.tmp to %ProgramFiles(x86)%\viewfd\readme.html
  • from %ProgramFiles(x86)%\viewfd\is-1hclg.tmp to %ProgramFiles(x86)%\viewfd\keyboard.html
  • from %ProgramFiles(x86)%\viewfd\is-on0p7.tmp to %ProgramFiles(x86)%\viewfd\unrar.dll
  • from %ProgramFiles(x86)%\viewfd\url\search\is-0nkur.tmp to %ProgramFiles(x86)%\viewfd\url\search\google.url
  • from %ProgramFiles(x86)%\viewfd\url\help\is-u311r.tmp to %ProgramFiles(x86)%\viewfd\url\help\subtitles.url
  • from %ProgramFiles(x86)%\viewfd\url\search\is-jrjgf.tmp to %ProgramFiles(x86)%\viewfd\url\search\bing.url
  • from %ProgramFiles(x86)%\viewfd\url\help\is-cg7fp.tmp to %ProgramFiles(x86)%\viewfd\url\help\pictures.url
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-3m176.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\readme.txt
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-0pkom.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\whatsnew.txt
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-s6dbc.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\imagine.wcx
  • from %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\is-sf2h2.tmp to %ProgramFiles(x86)%\viewfd\plugins\wlx\imagine\imagine.wlx
  • from %ProgramFiles(x86)%\viewfd\programs\is-omnmo.tmp to %ProgramFiles(x86)%\viewfd\programs\readme.txt
  • from %ProgramFiles(x86)%\viewfd\radio\is-ks21f.tmp to %ProgramFiles(x86)%\viewfd\radio\stations.txt
  • from %ProgramFiles(x86)%\viewfd\radio\is-v7vua.tmp to %ProgramFiles(x86)%\viewfd\radio\readme.txt
  • from %ProgramFiles(x86)%\viewfd\reports\is-c9gip.tmp to %ProgramFiles(x86)%\viewfd\reports\readme.txt
  • from %ProgramFiles(x86)%\viewfd\search\is-eqje9.tmp to %ProgramFiles(x86)%\viewfd\search\1 hour.ini
  • from %ProgramFiles(x86)%\viewfd\search\is-qso21.tmp to %ProgramFiles(x86)%\viewfd\search\3 minutes.ini
  • from %ProgramFiles(x86)%\viewfd\search\is-op6o3.tmp to %ProgramFiles(x86)%\viewfd\search\picture.ini
  • from %ProgramFiles(x86)%\viewfd\search\is-kre6j.tmp to %ProgramFiles(x86)%\viewfd\search\sound.ini
  • from %ProgramFiles(x86)%\viewfd\search\is-4ihgf.tmp to %ProgramFiles(x86)%\viewfd\search\video.ini
  • from %ProgramFiles(x86)%\viewfd\search\is-nb083.tmp to %ProgramFiles(x86)%\viewfd\search\readme.txt
  • from %ProgramFiles(x86)%\viewfd\soft\is-ic8te.tmp to %ProgramFiles(x86)%\viewfd\soft\readme.txt
  • from %ProgramFiles(x86)%\viewfd\url\is-tsn4b.tmp to %ProgramFiles(x86)%\viewfd\url\demo.txt
  • from %ProgramFiles(x86)%\viewfd\url\is-g5kk5.tmp to %ProgramFiles(x86)%\viewfd\url\readme.txt
  • from %ProgramFiles(x86)%\viewfd\url\is-up05e.tmp to %ProgramFiles(x86)%\viewfd\url\contribute.url
  • from %ProgramFiles(x86)%\viewfd\url\is-65q73.tmp to %ProgramFiles(x86)%\viewfd\url\microsoft.url
  • from %ProgramFiles(x86)%\viewfd\url\is-2l67n.tmp to %ProgramFiles(x86)%\viewfd\url\virustotal.url
  • from %ProgramFiles(x86)%\viewfd\url\help\is-cer41.tmp to %ProgramFiles(x86)%\viewfd\url\help\iqcomp.url
  • from %ProgramFiles(x86)%\viewfd\is-sp7b1.tmp to %ProgramFiles(x86)%\viewfd\viewfd.md5
  • from %ProgramFiles(x86)%\viewfd\graphic\shiftrgb\is-f6g18.tmp to %ProgramFiles(x86)%\viewfd\graphic\shiftrgb\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\selection\is-r6cos.tmp to %ProgramFiles(x86)%\viewfd\graphic\selection\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness2\is-a0tte.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness2\readme.txt
  • from %ProgramFiles(x86)%\viewfd\formulas\is-r05uv.tmp to %ProgramFiles(x86)%\viewfd\formulas\heart.cfl
  • from %ProgramFiles(x86)%\viewfd\formulas\is-883m2.tmp to %ProgramFiles(x86)%\viewfd\formulas\hypocycloid.cfl
  • from %ProgramFiles(x86)%\viewfd\formulas\is-5frum.tmp to %ProgramFiles(x86)%\viewfd\formulas\lissajous.cfl
  • from %ProgramFiles(x86)%\viewfd\formulas\is-bkfk2.tmp to %ProgramFiles(x86)%\viewfd\formulas\pascal's limacon.cfl
  • from %ProgramFiles(x86)%\viewfd\formulas\is-miti8.tmp to %ProgramFiles(x86)%\viewfd\formulas\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\3dturn\is-tb59c.tmp to %ProgramFiles(x86)%\viewfd\graphic\3dturn\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-lctuc.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\blurring.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-49rdk.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\blurring1.ini
  • from %ProgramFiles(x86)%\viewfd\forms\is-uhvhl.tmp to %ProgramFiles(x86)%\viewfd\forms\readme.txt
  • from %ProgramFiles(x86)%\viewfd\formulas\is-3c680.tmp to %ProgramFiles(x86)%\viewfd\formulas\aastroid.cfl
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-cd1p3.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\blurring2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-lbb6f.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\contour.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-jjic8.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\contour1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-lk41g.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\contour2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-vc94u.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\negative.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-8haka.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\relief.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-qe1og.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\relief1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-3ec1o.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\relief2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-cvol8.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\sharpness.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-f18ek.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\brightness.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-5vk7i.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\ccontrast.ini
  • from %ProgramFiles(x86)%\viewfd\data\is-0gbsr.tmp to %ProgramFiles(x86)%\viewfd\data\readme.txt
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-nc7qh.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\readme.txt
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-7mprn.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\white2.ini
  • from %ProgramFiles(x86)%\viewfd\7-zip\is-1bthg.tmp to %ProgramFiles(x86)%\viewfd\7-zip\7-zip.chm
  • from %ProgramFiles(x86)%\viewfd\7-zip\is-1rgkg.tmp to %ProgramFiles(x86)%\viewfd\7-zip\7z.dll
  • from %ProgramFiles(x86)%\viewfd\7-zip\is-r67vm.tmp to %ProgramFiles(x86)%\viewfd\7-zip\7zg.exe
  • from %ProgramFiles(x86)%\viewfd\7-zip\is-4fs4t.tmp to %ProgramFiles(x86)%\viewfd\7-zip\7z.sfx
  • from %ProgramFiles(x86)%\viewfd\backup\is-8p617.tmp to %ProgramFiles(x86)%\viewfd\backup\readme.txt
  • from %ProgramFiles(x86)%\viewfd\browser\is-mfoq2.tmp to %ProgramFiles(x86)%\viewfd\browser\default.wbr1
  • from %ProgramFiles(x86)%\viewfd\browser\is-ks5ee.tmp to %ProgramFiles(x86)%\viewfd\browser\default.wbr2
  • from %ProgramFiles(x86)%\viewfd\browser\is-p3mdl.tmp to %ProgramFiles(x86)%\viewfd\browser\default.wbr4
  • from %ProgramFiles(x86)%\viewfd\browser\is-aqc7u.tmp to %ProgramFiles(x86)%\viewfd\browser\readme.txt
  • from %ProgramFiles(x86)%\viewfd\7-zip\lang\is-u73ac.tmp to %ProgramFiles(x86)%\viewfd\7-zip\lang\ru.txt
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-l762m.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\attributes.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-au93b.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\blue.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-jgqve.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\colours.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-qq6f4.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\colours2.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-mj2ds.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\colours3.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-cq2oo.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\darkblue.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-ebj5e.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\darkblue2.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-r9mk5.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\darkyellow.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-ao7a1.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\silver.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-hcvkj.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\white.ini
  • from %ProgramFiles(x86)%\viewfd\colourschemes\is-qfesj.tmp to %ProgramFiles(x86)%\viewfd\colourschemes\black.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-titgu.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\sharpness1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-p1quj.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\sharpness2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\anyset\is-93fj5.tmp to %ProgramFiles(x86)%\viewfd\graphic\anyset\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\barrgb\is-gn6b9.tmp to %ProgramFiles(x86)%\viewfd\graphic\barrgb\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-5q33b.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\viewfd1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-ls5fu.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\viewfd2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-jklk5.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\viewfd3.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-9333e.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\viewfd4.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-iguj2.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\viewfd5.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-7u8hf.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\viewfd6.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-714qq.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\viewfd7.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-maevm.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\metallic\is-stp7b.tmp to %ProgramFiles(x86)%\viewfd\graphic\metallic\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\new\is-rd9pt.tmp to %ProgramFiles(x86)%\viewfd\graphic\new\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\radialrgb\is-kpnjt.tmp to %ProgramFiles(x86)%\viewfd\graphic\radialrgb\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\saturation\is-4nb87.tmp to %ProgramFiles(x86)%\viewfd\graphic\saturation\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-e2u8v.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\blurring1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-tlpkv.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\blurring2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-o0nq7.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\blurring3.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-c812o.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\compromise1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-8ljkl.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\compromise2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-amdid.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\compromise3.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-tn8sf.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\sharpness1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-c8pp1.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\sharpness2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-okvr5.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\sharpness3.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-ovghm.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\copyright2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\illuminance2\is-f1ndi.tmp to %ProgramFiles(x86)%\viewfd\graphic\illuminance2\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\inscriptions\is-uq3p6.tmp to %ProgramFiles(x86)%\viewfd\graphic\inscriptions\copyright1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\illuminance\is-a7g3f.tmp to %ProgramFiles(x86)%\viewfd\graphic\illuminance\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\brightness\is-0cdq2.tmp to %ProgramFiles(x86)%\viewfd\graphic\brightness\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\cb\is-ei7j8.tmp to %ProgramFiles(x86)%\viewfd\graphic\cb\negative.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\cb\is-cgmtf.tmp to %ProgramFiles(x86)%\viewfd\graphic\cb\solarization1.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\cb\is-k4jdo.tmp to %ProgramFiles(x86)%\viewfd\graphic\cb\solarization2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\cb\is-kmphf.tmp to %ProgramFiles(x86)%\viewfd\graphic\cb\solarization3.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\cb\is-9llv8.tmp to %ProgramFiles(x86)%\viewfd\graphic\cb\solarization4.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\cb\is-q71cd.tmp to %ProgramFiles(x86)%\viewfd\graphic\cb\solarization5.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\cb\is-t0kne.tmp to %ProgramFiles(x86)%\viewfd\graphic\cb\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\contour\is-j00ss.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour\normal.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour\is-6fuva.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour\outlining.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour\is-0e3fn.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour\picture.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour\is-ip8n2.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour\picture2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour\is-pkk62.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour\picture3.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour\is-j1c46.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour\thick.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour\is-bg4r6.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour\thin.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour\is-addfd.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\contour2\is-ua1qo.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour2\picture.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour2\is-jqtim.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour2\picture2.ini
  • from %ProgramFiles(x86)%\viewfd\graphic\contour2\is-2uu6i.tmp to %ProgramFiles(x86)%\viewfd\graphic\contour2\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\ellipsergb\is-m5mn7.tmp to %ProgramFiles(x86)%\viewfd\graphic\ellipsergb\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\grids\is-iq4cn.tmp to %ProgramFiles(x86)%\viewfd\graphic\grids\readme.txt
  • from %ProgramFiles(x86)%\viewfd\graphic\sharpness\is-1ju60.tmp to %ProgramFiles(x86)%\viewfd\graphic\sharpness\readme.txt
  • from %ProgramFiles(x86)%\viewfd\is-n9q09.tmp to %ProgramFiles(x86)%\viewfd\viewfd.crc
Network activity
Connects to
  • 'so###como.gq':80
TCP
HTTP GET requests
  • http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?08######
HTTP POST requests
  • http://so###como.gq/new/net_api
UDP
  • DNS ASK so###como.gq
Miscellaneous
Searches for the following windows
  • ClassName: '{E611A93F-EC60-4AD7-A3C8-3D5DC3E02E40}' WindowName: ''
Creates and executes the following
  • '%TEMP%\is-r4r4u.tmp\is-pahha.tmp' /SL4 $11022C "<Full path to file>" 6936235 52736
  • '%ProgramFiles(x86)%\viewfd\viewfd.exe'
  • '%ProgramFiles(x86)%\viewfd\viewfd.exe' 65179a877938e9054d8d202f72bc7442
Executes the following
  • '%WINDIR%\syswow64\schtasks.exe' /Query
  • '%WINDIR%\syswow64\schtasks.exe' /Delete /F /TN "ViewFD_3.5.1.0"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android