マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.MulDrop8.26943

Added to the Dr.Web virus database: 2018-06-20

Virus description added:

Technical Information

Malicious functions:
To bypass firewall, removes or modifies the following registry keys:
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] '%TEMP%\instream00000001\InStream2.app\instream.exe' = '%TEMP%\instream00...
  • [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\instream00000001\InStream2.app\instream.exe' = '%TEMP%\instream...
Executes the following:
  • '<SYSTEM32>\netsh.exe' firewall add allowedprogram program="%TEMP%\instream00000001\InStream2.app\instream.exe" name="InStream2.app/instream" scope=ALL profile=ALL mode=ENABLE
Modifies file system:
Creates the following files:
  • %TEMP%\instream00000001\InStream2.app\avcodec-57.dll
  • %TEMP%\instream00000001\InStream2.app\graphics\iconfile.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconfolder.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconinfo.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconquestion.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconstop.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\icontime.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconunknown.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconwarning.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-1-1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconexplanation.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\Haivision-watermark.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC708.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-HD.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-lock.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-ms.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-SAP.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\instream-logo.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-0-0.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-0-1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-1-0.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC2.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC4.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-2-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC3.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\checkbox-1-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-3-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-3-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-splitscreen-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-splitscreen-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-splitscreen-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-stop-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-stop-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-stop-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\checkbox-0-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\guide-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\Haivision-logo.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\guidebutton-background.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\column-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\column-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\dialog.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\grid-box-0.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\grid-box-1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\grid-box-2.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\grid-box-3.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\guide-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\guide-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\checkbox-0-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\checkbox-1-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-3-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-2-0.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\message-bar.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-back.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-chapter.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-fill.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-handle-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-handle-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-hotmark.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\search-icon.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\secondary-window.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-x-back.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-up-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-up-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-x-handle-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-y-handle-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-y-handle-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\talkback-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\talkback-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\talkback-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\textbox-bg-black.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\textbox-bg.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\tree-collapse.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\tree-expand.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-x-handle-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-y-back.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\loading.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-2-1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-handle-m.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_bottom-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_bottom-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_left-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_left-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_right-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_right-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_top-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_top-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-handle-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\menucheck.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-handle-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-controls.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-window-dashboard.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-window-solid.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-window.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\recording-active.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\resize-handle.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-bg.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-down-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-down-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-dashboard-full.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-dashboard.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-vod-controls.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-2-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-2-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-1-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dropdown-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-1X-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-1X-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-1X-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-2X-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-2X-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-2X-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dropdown-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-light-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dropdown-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fullscreen-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-grey-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-hotmark-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-hotmark-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-hotmark-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-info-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-info-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-info-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-left-arrow.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fullscreen-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fullscreen-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dialog-close-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\arrow-up.vfi
  • %TEMP%\instream00000001\InStream2.app\avfilter-6.dll
  • %TEMP%\instream00000001\InStream2.app\avformat-57.dll
  • %TEMP%\instream00000001\InStream2.app\avutil-55.dll
  • %TEMP%\instream00000001\InStream2.app\datares.xml
  • %TEMP%\instream00000001\InStream2.app\instream.exe
  • %TEMP%\instream00000001\InStream2.app\libgcc_s_seh-1.dll
  • %TEMP%\instream00000001\InStream2.app\libwinpthread-1.dll
  • %TEMP%\instream00000001\InStream2.app\swresample-2.dll
  • %TEMP%\instream00000001\InStream2.app\swscale-4.dll
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dialog-close-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-light-o.vfi
  • %TEMP%\instream00000001\InStream2.app\avdevice-57.dll
  • %TEMP%\instream00000001\InStream2.app\graphics\black-tv.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\bookmark-tooltip.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-black-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-black-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-black-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-black-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-close-app-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-close-app-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-close-app-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\arrow-right.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\arrow-down.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dropdown-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-light-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-1X-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-1X-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-2X-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-2X-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-2X-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-right-arrow.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-restore-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-restore-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-1X-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-settings-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-snapshot-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-snapshot-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-off-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-off-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-off-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-off-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-1-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-1-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-settings-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-settings-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-snapshot-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-restore-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-stop-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-maximize-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-maximize-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-minimize-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-minimize-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-minimize-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-next-chapter-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-next-chapter-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-next-chapter-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-pause-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-pause-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-pause-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-maximize-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-play-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-play-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-previous-chapter-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-previous-chapter-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-previous-chapter-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-stop-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-stop-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-play-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\vf-asset.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\vf-icon.vfi
Deletes the following files:
  • %TEMP%\instream00000001\InStream2.app\avcodec-57.dll
  • %TEMP%\instream00000001\InStream2.app\graphics\iconfile.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconfolder.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconinfo.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconquestion.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconstop.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\icontime.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconunknown.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconwarning.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-1-1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\iconexplanation.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\Haivision-watermark.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC708.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-HD.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-lock.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-ms.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-SAP.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\instream-logo.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-0-0.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-0-1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-1-0.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC2.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC4.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-2-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\indicator-CC3.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\checkbox-1-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-3-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-3-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-splitscreen-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-splitscreen-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-splitscreen-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-stop-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-stop-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-stop-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\checkbox-0-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\guide-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\Haivision-logo.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\guidebutton-background.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\column-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\column-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\dialog.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\grid-box-0.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\grid-box-1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\grid-box-2.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\grid-box-3.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\guide-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\guide-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\checkbox-0-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\checkbox-1-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-3-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-2-0.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\message-bar.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-back.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-chapter.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-fill.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-handle-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-handle-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scrubbar-hotmark.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\search-icon.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\secondary-window.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-x-back.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-up-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-up-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-x-handle-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-y-handle-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-y-handle-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\talkback-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\talkback-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\talkback-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\textbox-bg-black.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\textbox-bg.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\tree-collapse.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\tree-expand.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-x-handle-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\slider-y-back.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\loading.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\layout-2-1.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-handle-m.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_bottom-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_bottom-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_left-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_left-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_right-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_right-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_top-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\paperclip_top-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-handle-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\menucheck.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-handle-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-controls.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-window-dashboard.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-window-solid.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-window.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\recording-active.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\resize-handle.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-bg.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-down-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\scroll-y-down-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-dashboard-full.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-dashboard.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\player-vod-controls.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-2-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-2-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-1-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dropdown-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-1X-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-1X-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-1X-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-2X-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-2X-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-2X-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dropdown-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-light-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dropdown-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fullscreen-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-grey-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-hotmark-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-hotmark-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-hotmark-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-info-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-info-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-info-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-left-arrow.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fullscreen-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fastforward-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-fullscreen-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dialog-close-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\arrow-up.vfi
  • %TEMP%\instream00000001\InStream2.app\avfilter-6.dll
  • %TEMP%\instream00000001\InStream2.app\avformat-57.dll
  • %TEMP%\instream00000001\InStream2.app\avutil-55.dll
  • %TEMP%\instream00000001\InStream2.app\datares.xml
  • %TEMP%\instream00000001\InStream2.app\instream.exe
  • %TEMP%\instream00000001\InStream2.app\libgcc_s_seh-1.dll
  • %TEMP%\instream00000001\InStream2.app\libwinpthread-1.dll
  • %TEMP%\instream00000001\InStream2.app\swresample-2.dll
  • %TEMP%\instream00000001\InStream2.app\swscale-4.dll
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dialog-close-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-light-o.vfi
  • %TEMP%\instream00000001\InStream2.app\avdevice-57.dll
  • %TEMP%\instream00000001\InStream2.app\graphics\black-tv.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\bookmark-tooltip.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-black-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-black-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-black-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-black-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-close-app-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-close-app-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-close-app-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\arrow-right.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\arrow-down.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-dropdown-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-light-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-1X-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-1X-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-2X-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-2X-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-2X-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-right-arrow.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-restore-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-restore-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rewind-1X-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-settings-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-snapshot-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-snapshot-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-off-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-off-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-off-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-off-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-1-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-speaker-on-1-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-settings-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-settings-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-snapshot-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-restore-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-stop-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-maximize-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-maximize-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-minimize-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-minimize-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-minimize-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-next-chapter-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-next-chapter-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-next-chapter-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-pause-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-pause-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-pause-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-maximize-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-play-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-play-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-previous-chapter-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-previous-chapter-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-previous-chapter-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-d.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-p.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-stop-n.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-rec-stop-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\btn-play-o.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\vf-asset.vfi
  • %TEMP%\instream00000001\InStream2.app\graphics\vf-icon.vfi
Miscellaneous:
Executes the following:
  • '<SYSTEM32>\netsh.exe' firewall delete allowedprogram program="%TEMP%\instream00000001\InStream2.app\instream.exe"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android