Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.24601

Добавлен в вирусную базу Dr.Web: 2018-02-14

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender' = '<SYSTEM32>\BlackRuby\WindowsUI.exe'
Создает или изменяет следующие файлы:
  • %HOMEPATH%\Start Menu\Programs\Startup\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\HOW-TO-DECRYPT-FILES.txt
Изменения в файловой системе:
Создает следующие файлы:
  • <STUBS_DIR>\maplestory\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\MCAGENT\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\magent\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\loadmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\lotroclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\msn6\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\msnmsgr\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\mpftray\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Mir3Game\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\miranda32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\iscc\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ISClient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\intpro\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\inbank-start-ff\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\InphaseNXD\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\l2\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\lin\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\kb_cli\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\java\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\javaw\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\NAVAPW32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\safari\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\sgbclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\rclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Ragexe\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\RagFree\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\spidernt\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\sro_client\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\so3d\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\skype\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\smc\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ntvdm\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\oncbcli\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\nod32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\netxray\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\nod\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\putty\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\qip\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\pidgin\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\opera\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\outpost\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\iexplore\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\clntw32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\contactNG\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\clmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\clbank\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\client7\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Drweb32w\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\drweb386\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\drweb\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\dekaron\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\dnf\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\cabalmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\cbank\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bk\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bdss\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bdsubmit\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\chrome\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ClamWin\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ccapp\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\cbmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\cbsmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Drwebupw\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ge\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\googletalk\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\gc\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\fsavaui\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\fsavgui\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\httplook\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ICQ\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\gw\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\GUARD\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\GVOnline\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ekrn\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\elbank\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\egni\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Drwebwcl\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ecmd\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\fsav\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\fsav32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\firefox\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\elementclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\el_cli\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\startclient7\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\zapro\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\zlclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ybclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\wsm\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\YahooMessenger\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\$NtUninstallKB942288-v3$\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\__cd75efb816b2cc__\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ZONEALARM\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ZZ__cd75efb816b2cc__\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\TwelveSky2\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\UniStream\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\trillian\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\tiny\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\translink\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\woool\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\wow\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\winbaram\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\wclnt\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\webmoney\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\$NtUninstallWIC$\spuninst\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\AppPatch\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bdagent\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\CJCTQ25G\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\LBMMC3H3\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\BGGTYMH1\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\History\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\MOE00UY1\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Templates\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\History\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\Application Data\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Cookies\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Favorites\Links\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Favorites\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Cookies\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\startupCache\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\VMware\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\Cache\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\bookmarkbackups\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Mozilla\Firefox\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Pictures\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Music\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Music\Sample Music\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Videos\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\DRM\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\dcb92e4d0d8626326c0d3b5feb3fec0f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %TEMP%\dw.log
  • %APPDATA%\Microsoft\Protect\CREDHIST
  • <SYSTEM32>\BlackRuby\WindowsUI.exe
  • <SYSTEM32>\BlackRuby\Svchost.exe
  • %ALLUSERSPROFILE%\Application Data\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\HOW-TO-DECRYPT-FILES.txt
  • <Текущая директория>\HOW-TO-DECRYPT-FILES.txt
  • %TEMP%\21BEA.dmp
  • C:\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\History\History.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\SendTo\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Games\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\History\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Cookies\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Application Data\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\History\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\MacroView\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Network\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\HlfViewer\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\FTP\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\FTP\lib\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\PluginSDK\Headers.c\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\PluginSDK\Headers.pas\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\WinSCP\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ProcList\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\TmpPanel\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\doc\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\EMenu\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\DrawLine\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\EditCase\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\FarCmds\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\FileCase\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\sources\RegExp\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\keys\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\sources\HOW-TO-DECRYPT-FILES.txt
  • C:\Muldrop\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVPCC\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVPM\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVP32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVGCTRL\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVP\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bc_loader\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\BBClient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVSYNMGR\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bankcl\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ageofconan\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\aion\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\360tray\HOW-TO-DECRYPT-FILES.txt
  • C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\avgcc\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVGCC32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ashAvSrv\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ash\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ashAvast\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Compare\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Templates\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\Programs\Accessories\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Colors\Default Highlighting\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Macros\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Colors\Custom Highlighting\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Colors\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\My Documents\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\My Documents\My Music\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\<INETFILES>\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\History\History.IE5\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\History\History.IE5\MSHist012011111020111111\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\Programs\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\SendTo\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\My Documents\My Pictures\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Recent\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\SetUp\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\bin\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrc\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\AutoWrap\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Brackets\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrd\console\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrd\console\contrib\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrd\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrc\auto\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrc\auto\types\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Documentation\eng\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Documentation\rus\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\XLat\Russian\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Shell\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\XLat\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Align\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\arclite\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\7-Zip\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Encyclopedia\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\FExcept\HOW-TO-DECRYPT-FILES.txt
Удаляет следующие файлы:
  • %WINDIR%\winnt.bmp
  • %WINDIR%\winnt256.bmp
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\dcb92e4d0d8626326c0d3b5feb3fec0f_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %WINDIR%\bootstat.dat
Перемещает следующие системные файлы:
  • %WINDIR%\setupapi.log в %WINDIR%\Encrypted_A76HZopUsMMWm7sOxk8VvoVOZHzIitiojmLnE.BlackRuby
  • %WINDIR%\setupact.log в %WINDIR%\Encrypted_aO2qQhfrD7ytsIBsfCi2rvfB8SkK1Bw1NxHv.BlackRuby
  • %WINDIR%\setuplog.txt в %WINDIR%\Encrypted_ko0jivz8Xck9gtauEIVzzhLb36EGQaTb6bQfIm8.BlackRuby
  • %WINDIR%\spupdsvc.log в %WINDIR%\Encrypted_tPXoG1zr4QdJCn5kNKVSrt6i4RGIcEh3XJIghdlEH.BlackRuby
  • %WINDIR%\Soap Bubbles.bmp в %WINDIR%\Encrypted_JhUN8tpEOAFhIzME6n8yn1FVbc2KuXwFBUDodXN.BlackRuby
  • %WINDIR%\sessmgr.setup.log в %WINDIR%\Encrypted_JOBr021MuaNxUC7m1ghf4DA5IV8e8qSc4UFtneZVh.BlackRuby
  • %WINDIR%\regopt.log в %WINDIR%\Encrypted_flKKYjPpANJUCDGSowJpjMPmkz5DBwcq2mdgS109.BlackRuby
  • %WINDIR%\Prairie Wind.bmp в %WINDIR%\Encrypted_64HsPbFCV8vrIQZwXOuKfTZZIApFTFr4fxZpOum.BlackRuby
  • %WINDIR%\Rhododendron.bmp в %WINDIR%\Encrypted_YHzXigXTvpD7mozFA4VBrYeQv4Ol1kADy22Ib.BlackRuby
  • %WINDIR%\Santa Fe Stucco.bmp в %WINDIR%\Encrypted_2VhC2kpkLYULGDPXoi835ckHYvyGWFTNI6Tm.BlackRuby
  • %WINDIR%\River Sumida.bmp в %WINDIR%\Encrypted_9z4yrnh7a6bjgbglSbugvRUdNrdihRv1Kq7AfSo.BlackRuby
  • %WINDIR%\Zapotec.bmp в %WINDIR%\Encrypted_6RHjUxvtK691cx2g6d84SGw1aKWbb1CtWyOFVb9h.BlackRuby
  • %WINDIR%\wmsetup.log в %WINDIR%\Encrypted_cDZ5BtdbuMql9YbOSyWCGCq0xSx66VtjDuwmI0Tef.BlackRuby
  • %WINDIR%\_default.pif в %WINDIR%\Encrypted_f0LAd56WzKWcWkiCNAWYW0mD30lZJhxhsnS8ZhVrZ.BlackRuby
  • %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.txt в %WINDIR%\$NtUninstallWIC$\spuninst\Encrypted_g0Ace7kjstUQTJDWjtWDfq3szrVQAGcFRnrFywVHyxTcRz.BlackRuby
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.txt в %WINDIR%\$NtUninstallKB942288-v3$\spuninst\Encrypted_xqh6xvaMhpEd4c2AJJ8GklSYUhFQHvc2dGuMVyU8LF.BlackRuby
  • %WINDIR%\WindowsUpdate.log в %WINDIR%\Encrypted_nEVYOovOISOfaA4zoY89jsQnWdTXEij3dYeD.BlackRuby
  • %WINDIR%\tsoc.log в %WINDIR%\Encrypted_l8SFgnn11BcrUgrMJOuJjUQ3KD8xDGxEEcOa9.BlackRuby
  • %WINDIR%\tabletoc.log в %WINDIR%\Encrypted_BPOnXfdNLwEFat0q3qWofbapsPszVZCRsnKi.BlackRuby
  • %WINDIR%\updspapi.log в %WINDIR%\Encrypted_31wuo5zcZEVUigYbVNVvi6qo6nHKnsvTz2Ah7VOFnr4.BlackRuby
  • %WINDIR%\wiaservc.log в %WINDIR%\Encrypted_DXR7FhmldD13gNLTX1idfzaa5oEZW1yEHjZLdmUWJhPL95V.BlackRuby
  • %WINDIR%\wiadebug.log в %WINDIR%\Encrypted_vWa8y28GKhO7IHGOsUiHrG7SFrcscgTqwGXJGrg8.BlackRuby
  • %WINDIR%\OEWABLog.txt в %WINDIR%\Encrypted_CXcfFf8Xje3Fior0AHiyXIJv97UhfRJgijBDEYU6uq.BlackRuby
  • %WINDIR%\FaxSetup.log в %WINDIR%\Encrypted_gZGfHr486VFkWMhJsH7fqF4RhYnFX9GSjiXG.BlackRuby
  • %WINDIR%\DtcInstall.log в %WINDIR%\Encrypted_7rCE9juUQFr9cZ1najhBmMDEFkXHqRVfNtSOh1tssGk3Xma.BlackRuby
  • %WINDIR%\FeatherTexture.bmp в %WINDIR%\Encrypted_xZ7eYWicN2rguSmPXn73fyYYWWPvRTkr4CYI926QqGu.BlackRuby
  • %WINDIR%\Greenstone.bmp в %WINDIR%\Encrypted_DeqWweai9MpEqkYSJiu9Oz42No7QoKRvYf4h.BlackRuby
  • %WINDIR%\Gone Fishing.bmp в %WINDIR%\Encrypted_XHA6hdsF3HFJoGUvoLVWjrOmyLet0BWfQ2dAC8Sax3YCz.BlackRuby
  • %WINDIR%\comsetup.log в %WINDIR%\Encrypted_DLX1ynmpemyV3yH1EcUoeBya5gDj2exIQf5mXe.BlackRuby
  • %WINDIR%\clock.avi в %WINDIR%\Encrypted_Ht8hMeCHoLP25BSPxJI8F4nspv5iyeLynYAp7jHud.BlackRuby
  • %WINDIR%\Blue Lace 16.bmp в %WINDIR%\Encrypted_ofP33auzNd8mam37JehG4yi2C3VCS03nTUiMtHcrrPX.BlackRuby
  • %WINDIR%\cmsetacl.log в %WINDIR%\Encrypted_raB9VmLuTbneyy0vEqhbJwd6HkJggL7l0NFhApf5lbd.BlackRuby
  • %WINDIR%\COM+.log в %WINDIR%\Encrypted_KotnoqdBtK5tSNZDsVISV1jwuctBCqPwSQhAOIK8X.BlackRuby
  • %WINDIR%\Coffee Bean.bmp в %WINDIR%\Encrypted_RIFZetVX9rBGslrQWO66NpTIkYYdN4rZVCJZEv3EsNHf.BlackRuby
  • %WINDIR%\netfxocm.log в %WINDIR%\Encrypted_mvNaQvSIvKY9opIDNjh0qO5hHnqyZTarwYH0Rl4hYihk3.BlackRuby
  • %WINDIR%\msmqinst.log в %WINDIR%\Encrypted_tPjNGyKeArfWEEZQ1cVniCp48jWRkf3UyJuX.BlackRuby
  • %WINDIR%\ntdtcsetup.log в %WINDIR%\Encrypted_SI42evAl2Q05qKMls87lWVkxgGIVFcW85Chhd.BlackRuby
  • %WINDIR%\ocmsn.log в %WINDIR%\Encrypted_J1yS5iztyB9c9D9MoAVbO85Hx3A0qemJlUob5CCDED1Fn.BlackRuby
  • %WINDIR%\ocgen.log в %WINDIR%\Encrypted_LpiEpsIPms3gQv5YEEI8ehzbqKd44P5U2Q6JnWJXxrfmna.BlackRuby
  • %WINDIR%\msgsocm.log в %WINDIR%\Encrypted_Jhfv8rA2VbHtKRsuj57IeJzqevHT4yHgcUpgEJOelIE4Yzy.BlackRuby
  • %WINDIR%\imsins.BAK в %WINDIR%\Encrypted_ZODOPf1dJY17ukgYJUhLjEOWAk1T0cISoxtnlLNT9az.BlackRuby
  • %WINDIR%\iis6.log в %WINDIR%\Encrypted_bCwBApK08FuACScjjXVrzoJq53TMNNad6tAVTgUnrEeR.BlackRuby
  • %WINDIR%\imsins.log в %WINDIR%\Encrypted_A7HqZmAGynOioXO5a37qm8EjdZFRrK4GBmxfpRkeFNcT1.BlackRuby
  • %WINDIR%\MedCtrOC.log в %WINDIR%\Encrypted_izbUxj1OqMtHQdAOSWhoaQ0dC73VLGWtGfloAD2UeWbVm.BlackRuby
  • %WINDIR%\KB942288-v3.log в %WINDIR%\Encrypted_koLHitKte4mLiL7asZVKq15x6OUOZ2o4Xb3WtX8oM0G3nv.BlackRuby
Перемещает следующие файлы:
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\secmod.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_mdXPcIQEeTjuOY0T5Ap29oVUUODJcUU5Afivt5HjbPi6.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\sessionstore.bak в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_MKbqlQZrJj8WIMrzLiEVChLhwCSHJCFrWUmnxAetiCLea.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\search.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_85bk9S2HM533el28zpDvjGlYzCDgA7rxIxZ7Q1P6b.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\pluginreg.dat в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_proZ3J2nKSIhcz4QikD11sFLvVAbmoO7PXp4c.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\prefs.js в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_YAG7jVBAVWYU3fFm9KcxvxqePfRbfANKD5mw6E0F.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\userChrome-example.css в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\Encrypted_xLynsOYMSYMs1wqxiM2J1NGLh0avoaVI2Jpar0qcItlOb.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\userContent-example.css в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\Encrypted_8l7gAdrdm498oXFzGRpH90wlcm5rEz2tjxzJzMawXS3WAuz.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\webappsstore.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_Im20OY0QAAg1G0hbd2QDbqWPCxbIMCrC0bhkO6yyI1.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\sessionstore.js в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_dD6VthlTslz0WMYEYgo8BIlThmbfuoE7HtYuv17.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\signons.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_vEwUANQyAHb6uSdKDCpT11GaVjELo9jUcMaxIwuj8LKgMM.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\places.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_JWFA1BwtjuHr6XwADEPeekt5AVVeOJea9XjoQNYiCrXAHeF.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\content-prefs.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_4wvYOMZRJgKedAqpmF1lRVDUuNONRXl5m1XC4JVLbHe4C.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cookies.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_39CleCGvVzQaLSueMCCFBvIB16vTDmTtV5GULyO2sezW.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chromeappsstore.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_NZF80MryDakibfmHHrb0mNYFVuwqlOqneM8eruWOs.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\bookmarks.html в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_KdT2hBQ58c5rDTeTMfboWQcAQC8NXBmpyTbJaMUByZ.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cert8.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_nrBg1FiLYLM7hs5lzJCfiUi336hs4g61HX4moo0D.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\key3.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_RoKjaP9lm9HJneAYHA1om9Yktjd1mHOORFduzLN.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\permissions.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_2VOBjWHOROfvhRr5YiPIq2OxLXsyUy0Co5hm4RkK.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\formhistory.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_Avq5S8w0D7PgZeTJ5BPBnX9y90UcCfQAgprn2VvigwvZj.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\downloads.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_VMuQxGYCvhipprKxzqo7N1N3dyUzkHm5p8ixYR45f4.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_UXAdD7Eg81olX0OlZn1a8QSikg37WWUtYBRFq7wkxQ.BlackRuby
Изменяет множество файлов пользовательских данных (Trojan.Encoder).
Сетевая активность:
Подключается к:
  • 'fr###eoip.net':80
  • 'wp#d':80
TCP:
Запросы HTTP GET:
  • http://fr###eoip.net/json/
  • http://11#.#11.111.1/wpad.dat via wp#d
UDP:
  • DNS ASK fr###eoip.net
  • DNS ASK wp#d
Другое:
Запускает на исполнение:
  • '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 856

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке