マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話

03-6550-8770

Profile

Trojan.MulDrop32.18802

Added to the Dr.Web virus database: 2025-07-10

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Gift For Ohanuna' = '%APPDATA%\Gift_For_Ohanuna\<File name>.exe'
  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Adobe Acrobat' = '%APPDATA%\Adobe Acrobat PDF Reader\AdobeAcrobat.exe'
Malicious functions
Launches a large number of processes
Modifies file system
Creates the following files
  • %APPDATA%\gift_for_ohanuna\<File name>.exe
  • %APPDATA%\adobe acrobat pdf reader\adobeacrobat.exe
Miscellaneous
Executes the following
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/pZ-oEuWMszs/maxresdefault.jpg?sqp=-oaymwEmCIAKENAF8quKqQMa8AEB-AH-CYAC0AWKAgwIABABGGUgUChJMA8=&rs=AOn4CLCjQ0eZYeOpYqqNF0MvtIcX4...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/pZ-oEuWMszs/maxresdefault.jpg?sqp=-oaymwEmCIAKENAF8quKqQMa8AEB-AH-CYAC0AWKAgwIABABGGUgUChJMA8=&rs=AOn4CLCjQ0eZYeOpYqqNF0MvtIcX46Qgyw' -OutFil...
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\E0fHFjzCwm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\bi78pdKieq1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/G8kPKJxg7HM/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhlIFAoUTAP&rs=AOn4CLDTRSC7T...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/G8kPKJxg7HM/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhlIFAoUTAP&rs=AOn4CLDTRSC7TU3Fk8aP6VpM8fn...
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\yNdycM6Fzx1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/0GRnTAWlvcc/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhnIGcoZzAP&rs=AOn4CLAKB5tjy...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/0GRnTAWlvcc/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhnIGcoZzAP&rs=AOn4CLAKB5tjyFSCM4roHCWUxBd...
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\syM7soQDbA1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Documents\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Documents\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Downloads\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Downloads\5wwS8f5Sq01.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\RdHvoOpbHW1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\4uSBAN1dWM1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gkRG7FUlmm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gCsEXMzK7C1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\5pTUmuluOp1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\6X3X4Y2r6N1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\uYZA46DPMB1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\LM7wPOs22w1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\rm2JBDGl7v1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\o3sWYK7S6L1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Documents\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Documents\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Downloads\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Downloads\FI5tEltlFm1.jpg\""
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/pZ-oEuWMszs/maxresdefault.jpg?sqp=-oaymwEmCIAKENAF8quKqQMa8AEB-AH-CYAC0AWKAgwIABABGGUgUChJMA8=&rs=AOn4CLCjQ0eZYeOpYqqNF0MvtIcX4...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\E0fHFjzCwm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\E0fHFjzCwm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/LnhVRMm1uFk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\E0fHFjzCwm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\bi78pdKieq1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\bi78pdKieq1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1yRSGhF1dvQ/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\bi78pdKieq1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/G8kPKJxg7HM/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhlIFAoUTAP&rs=AOn4CLDTRSC7T...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\yNdycM6Fzx1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\yNdycM6Fzx1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/R-778WfzHNU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\yNdycM6Fzx1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/0GRnTAWlvcc/hqdefault.jpg?sqp=-oaymwE2CNACELwBSFXyq4qpAygIARUAAIhCGAFwAcABBvABAfgB_gSAAuADigIMCAAQARhnIGcoZzAP&rs=AOn4CLAKB5tjy...' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\syM7soQDbA1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\syM7soQDbA1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/OqNxVjsP3Fk/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\syM7soQDbA1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5wwS8f5Sq01.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Documents\5wwS8f5Sq01.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i1.sndcdn.com/artworks-hFFkzJlpYdDBCU4u-y8fdHQ-t1080x1080.jpg' -OutFile \"%HOMEPATH%\Downloads\5wwS8f5Sq01.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\RdHvoOpbHW1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\RdHvoOpbHW1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/Bp5QZ3ScPZ8/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\RdHvoOpbHW1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\4uSBAN1dWM1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\4uSBAN1dWM1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/sPaQwB3IfQY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\4uSBAN1dWM1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gkRG7FUlmm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gkRG7FUlmm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/H3PetLTBkJU/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gkRG7FUlmm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\gCsEXMzK7C1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\gCsEXMzK7C1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/MtJRDtzGOg0/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\gCsEXMzK7C1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\5pTUmuluOp1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\5pTUmuluOp1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/7j55Ec8TqtY/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\5pTUmuluOp1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\6X3X4Y2r6N1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\6X3X4Y2r6N1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/1j35Mil-7Uc/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\6X3X4Y2r6N1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\uYZA46DPMB1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\uYZA46DPMB1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/vgu4o0x_SoM/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\uYZA46DPMB1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\LM7wPOs22w1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\LM7wPOs22w1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/4KV7x8ofsWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\LM7wPOs22w1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\rm2JBDGl7v1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\rm2JBDGl7v1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/2tcg7Xz5WWs/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\rm2JBDGl7v1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\o3sWYK7S6L1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Documents\o3sWYK7S6L1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://i.ytimg.com/vi/WIsHEt0c59w/hqdefault.jpg' -OutFile \"%HOMEPATH%\Downloads\o3sWYK7S6L1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"C:\Users\Dommo\JamaicaMeCrazy\FI5tEltlFm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Documents\FI5tEltlFm1.jpg\""' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest 'https://static.hudl.com/users/prod/11378082_c473f95a4f06455abc68511ab42e1ad5.jpg' -OutFile \"%HOMEPATH%\Downloads\FI5tEltlFm1.jpg\""' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android