Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.24772

Добавлен в вирусную базу Dr.Web: 2018-03-01

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender' = '<SYSTEM32>\BlackRuby\wininit.exe'
Создает или изменяет следующие файлы:
  • %HOMEPATH%\Start Menu\Programs\Startup\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\HOW-TO-DECRYPT-FILES.txt
Изменения в файловой системе:
Создает следующие файлы:
  • %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\AppPatch\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\$NtUninstallKB942288-v3$\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\$NtUninstallWIC$\spuninst\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ntvdm\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\oncbcli\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\opera\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\netxray\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\nod\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\nod32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\outpost\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Ragexe\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\RagFree\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\rclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\pidgin\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\putty\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\qip\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\lotroclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\magent\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\maplestory\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\l2\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\lin\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\loadmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\MCAGENT\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\msn6\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\msnmsgr\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\NAVAPW32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Mir3Game\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\miranda32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\mpftray\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\safari\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\wow\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\wsm\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\YahooMessenger\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\webmoney\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\winbaram\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\woool\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ybclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ZZ__cd75efb816b2cc__\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\__cd75efb816b2cc__\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\zapro\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\zlclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ZONEALARM\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\so3d\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\spidernt\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\sro_client\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\sgbclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\skype\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\smc\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\startclient7\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\TwelveSky2\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\UniStream\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\wclnt\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\tiny\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\translink\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\trillian\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Net\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Management.Instrumentation\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Xml.Linq\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5917eb5b\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_27b9fd4f\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_cd264933\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b50667e9\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Extensions.Design\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Entity.Design\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\HOW-TO-DECRYPT-FILES.txt
  • %WINDIR%\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\kb_cli\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Cookies\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Favorites\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Mozilla\Firefox\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\bookmarkbackups\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Favorites\Links\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\Cache\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\startupCache\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\VMware\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\HOW-TO-DECRYPT-FILES.txt
  • <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\History\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\MOE00UY1\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\NetworkService\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\History\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Colors\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Colors\Custom Highlighting\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Colors\Default Highlighting\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Templates\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Macros\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\XLat\Russian\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Documentation\eng\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Documentation\rus\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\SetUp\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\Shell\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Addons\XLat\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\My Documents\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\My Documents\My Music\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\My Documents\My Pictures\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\History\History.IE5\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\History\History.IE5\MSHist012011111020111111\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Local Settings\<INETFILES>\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Recent\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\Programs\Accessories\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\SendTo\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\HOW-TO-DECRYPT-FILES.txt
  • %HOMEPATH%\Start Menu\Programs\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Application Data\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Cookies\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Start Menu\Programs\Games\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\HOW-TO-DECRYPT-FILES.txt
  • <Текущая директория>\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Application Data\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\HOW-TO-DECRYPT-FILES.txt
  • %APPDATA%\Microsoft\Protect\CREDHIST
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\646b4734ff976121ee336cd64d3901d4_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • C:\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Music\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Videos\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\DRM\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Music\Sample Music\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\HOW-TO-DECRYPT-FILES.txt
  • %ALLUSERSPROFILE%\Documents\My Pictures\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\History\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Cookies\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\Application Data\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Templates\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\History\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\BGGTYMH1\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\CJCTQ25G\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\LBMMC3H3\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\History\History.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\SendTo\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\HOW-TO-DECRYPT-FILES.txt
  • C:\Documents and Settings\Default User\Start Menu\Programs\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Encyclopedia\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\clmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\clntw32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\contactNG\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ClamWin\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\clbank\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\client7\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\dekaron\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\drweb386\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Drwebupw\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Drwebwcl\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\dnf\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\drweb\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\Drweb32w\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bdagent\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bdss\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bdsubmit\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\BBClient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bc_loader\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bk\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\cbsmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ccapp\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\chrome\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\cabalmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\cbank\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\cbmain\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ecmd\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\httplook\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ICQ\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\iexplore\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\GUARD\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\GVOnline\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\gw\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\inbank-start-ff\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ISClient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\java\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\javaw\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\InphaseNXD\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\intpro\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\iscc\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\elementclient\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\el_cli\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\firefox\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\egni\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ekrn\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\elbank\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\fsav\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\gc\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ge\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\googletalk\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\fsav32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\fsavaui\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\fsavgui\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\EditCase\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\EMenu\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrd\console\contrib\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Compare\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\DrawLine\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\doc\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\FarCmds\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\FileCase\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\FTP\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\keys\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\sources\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ExtSearch\sources\RegExp\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\arclite\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\AutoWrap\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Brackets\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\FExcept\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\7-Zip\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Align\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrc\auto\types\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrd\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrd\console\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\bin\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrc\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Colorer\hrc\auto\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\FTP\lib\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ashAvSrv\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\avgcc\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVGCC32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\aion\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ash\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ashAvast\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVGCTRL\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVPM\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVSYNMGR\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\bankcl\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVP\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVP32\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\AVPCC\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\ProcList\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\TmpPanel\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\WinSCP\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\HlfViewer\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\MacroView\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\Plugins\Network\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\PluginSDK\Headers.c\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\360tray\HOW-TO-DECRYPT-FILES.txt
  • <STUBS_DIR>\ageofconan\HOW-TO-DECRYPT-FILES.txt
  • C:\Far2\PluginSDK\Headers.pas\HOW-TO-DECRYPT-FILES.txt
  • C:\Muldrop\HOW-TO-DECRYPT-FILES.txt
  • C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\HOW-TO-DECRYPT-FILES.txt
Удаляет следующие файлы:
  • %WINDIR%\winnt.bmp
  • %WINDIR%\winnt256.bmp
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\646b4734ff976121ee336cd64d3901d4_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %WINDIR%\bootstat.dat
Перемещает следующие системные файлы:
  • %WINDIR%\setupapi.log в %WINDIR%\Encrypted_X5P3ygvM1X3D5W91Fk1qaajT1GrZVgWsXgzyJESvemEoMv.BlackRuby
  • %WINDIR%\setupact.log в %WINDIR%\Encrypted_43xauSKZm9quIQmWB3bT8wiIU7pBlQvYxgFnNRgY0j7bsUt.BlackRuby
  • %WINDIR%\setuplog.txt в %WINDIR%\Encrypted_9mTT8n6zfnQpyJpWWIOKeTZgT67XDNHgtV4q.BlackRuby
  • %WINDIR%\spupdsvc.log в %WINDIR%\Encrypted_toluRhLHCjD59VG7FVn4uq5yoCldqyNPoyo4h4Pq7o.BlackRuby
  • %WINDIR%\Soap Bubbles.bmp в %WINDIR%\Encrypted_PmKSOTkUyJ3lMPucBoPgSC4oH3jE8im6Ey6slGdTblO.BlackRuby
  • %WINDIR%\sessmgr.setup.log в %WINDIR%\Encrypted_AWJNkVBu2fxHio5jpvP7zlTfJ3UdxcNB1RsBE6O.BlackRuby
  • %WINDIR%\regopt.log в %WINDIR%\Encrypted_VxMjGfnxjGGQy2wNkbn2aDjjorV1VEk69jjL.BlackRuby
  • %WINDIR%\Prairie Wind.bmp в %WINDIR%\Encrypted_dQiW6ifJxnNnOQDaOUbeR2T6enBSgRCiBVMjbeE.BlackRuby
  • %WINDIR%\Rhododendron.bmp в %WINDIR%\Encrypted_JoOxKiNm4txjQvH9tr1G800K3GdyLa8zJ0lHm5D8W8.BlackRuby
  • %WINDIR%\Santa Fe Stucco.bmp в %WINDIR%\Encrypted_NfH0gSb7g3GyGviygeCrSo446dNe7H1Hp3qFC3haQDxh.BlackRuby
  • %WINDIR%\River Sumida.bmp в %WINDIR%\Encrypted_BK4AUfVQpMrM1W1uFyCcFLOyDKxWANfLHO0twQV.BlackRuby
  • %WINDIR%\Zapotec.bmp в %WINDIR%\Encrypted_Up9rYgKnKYTQq6E5bAbriWzdZ0tHLMcqInsqb3aZg.BlackRuby
  • %WINDIR%\wmsetup.log в %WINDIR%\Encrypted_hz7eUcky1vm8OCsJTtPcBaZ2KkmIU1Fw8OpuZzuUdcba9e7.BlackRuby
  • %WINDIR%\_default.pif в %WINDIR%\Encrypted_gANrjSQSCEs46Ux84qc7v1ehRSJPHFxmrSYCqenAuzw49j.BlackRuby
  • %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.txt в %WINDIR%\$NtUninstallWIC$\spuninst\Encrypted_mXUmsWpe34BQNxX3XIDaw9fx2hN0JZHA4HJ7XJZpSeF.BlackRuby
  • %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.txt в %WINDIR%\$NtUninstallKB942288-v3$\spuninst\Encrypted_vdJ9CtK2tz6wOlgb2HbFJ7FxdCyOvIJ9dvUuocVaEIl9Bln.BlackRuby
  • %WINDIR%\WindowsUpdate.log в %WINDIR%\Encrypted_ElOzAYShaDUsunS1pEolzVTAhrCnyVwmoKNR.BlackRuby
  • %WINDIR%\tsoc.log в %WINDIR%\Encrypted_ZCSLgh4kIoo1A1KdktCfaxjECgD0W8IgwcEbsSNopKfXb.BlackRuby
  • %WINDIR%\tabletoc.log в %WINDIR%\Encrypted_601tcTSx4PchOuy0gCoI9Jj4gVBlmrhLMcVQwfbRKHXJ86.BlackRuby
  • %WINDIR%\updspapi.log в %WINDIR%\Encrypted_lXgLrUAQ0UDdQP3hBZDunROJ6zdHS1dcUGvx95.BlackRuby
  • %WINDIR%\wiaservc.log в %WINDIR%\Encrypted_3QA1zlL3iX6FeOkwOYnWm3p6pYmf3cbqFgg67u3qck9D.BlackRuby
  • %WINDIR%\wiadebug.log в %WINDIR%\Encrypted_FZ9mvilDNuOwCVOBFHbHF6PTb0fgBGDw5Ge05.BlackRuby
  • %WINDIR%\OEWABLog.txt в %WINDIR%\Encrypted_pagI2e6VdBgUwWspFDOPu64TQN4Tp6op16JnZbY5jheC.BlackRuby
  • %WINDIR%\FaxSetup.log в %WINDIR%\Encrypted_J8t2HYXQeurfG04GbFOuiGx8PgmnHix5t0M4.BlackRuby
  • %WINDIR%\DtcInstall.log в %WINDIR%\Encrypted_o5RaEKvdPUgLU4imYY1XGcxwsWkPYRMjJ0dsI.BlackRuby
  • %WINDIR%\FeatherTexture.bmp в %WINDIR%\Encrypted_UR82TKd7VaGHWYmJ4vP9vkcBHzCvDbHzRn3QTKEr.BlackRuby
  • %WINDIR%\Greenstone.bmp в %WINDIR%\Encrypted_mLbgbcpi5d0ukYTYFuzluK4y2YLJoCGECDoXRAhINammYe.BlackRuby
  • %WINDIR%\Gone Fishing.bmp в %WINDIR%\Encrypted_HI0EXODvqDxayS95BCbOSg3nVOJu5wftcD6LVNvwrYeY6DI.BlackRuby
  • %WINDIR%\comsetup.log в %WINDIR%\Encrypted_djDa4XpyYoHjEfzi7rzI49Ir1DKHcY2nlVwW3J4IrfAB.BlackRuby
  • %WINDIR%\clock.avi в %WINDIR%\Encrypted_MfTifPxsnTIBIMEeKwCCJ8mO0vdmFiLjG3S7nni.BlackRuby
  • %WINDIR%\Blue Lace 16.bmp в %WINDIR%\Encrypted_OTCVPaGObACFa50pkzziZhhi3C7gSTdtXyjoV9oU.BlackRuby
  • %WINDIR%\cmsetacl.log в %WINDIR%\Encrypted_AVVwjTXg87zUkGZPTDORq5C1NKkl74idRRU3prOF5GhVX6.BlackRuby
  • %WINDIR%\COM+.log в %WINDIR%\Encrypted_ptBNyUF0DCaQmldxybn4WCsGmnCIlDetZ6ua1.BlackRuby
  • %WINDIR%\Coffee Bean.bmp в %WINDIR%\Encrypted_eYwNnh9UMWAnWMvtWvnoJiDBtUnApJJx2RDEkdAcZIpi2.BlackRuby
  • %WINDIR%\netfxocm.log в %WINDIR%\Encrypted_UpKQXdfZRzVdsXjjFRbCapiycR0QUnxIjnTiC.BlackRuby
  • %WINDIR%\msmqinst.log в %WINDIR%\Encrypted_gyICTa6k8MoJQdOy7AOw4tIMO33RdRaOYORmAku5Dm.BlackRuby
  • %WINDIR%\ntdtcsetup.log в %WINDIR%\Encrypted_MMydianDDSOFS9SWbYnYi2ycnVUxJaVeh3rKL0t2xIBWZI.BlackRuby
  • %WINDIR%\ocmsn.log в %WINDIR%\Encrypted_LXFqxQThPlUBAQWLBV13SR4ItD256pDUQ6acdomiEeWzY.BlackRuby
  • %WINDIR%\ocgen.log в %WINDIR%\Encrypted_AC1rmeN3X66Yu3nHkp1nFxOE2ubwAwtYsRtGNCZ7.BlackRuby
  • %WINDIR%\msgsocm.log в %WINDIR%\Encrypted_7HElKTv8S8QhWqgTpc1Sz1S0vDnTwkpaCZNu7eXu7.BlackRuby
  • %WINDIR%\imsins.BAK в %WINDIR%\Encrypted_kWstqSVCGvFpSqYNprCEek8e9HtQaRy4wGXpjpayex7FY.BlackRuby
  • %WINDIR%\iis6.log в %WINDIR%\Encrypted_xfqfmOvNvJYW1wCcga1z8oh4urlRk7aAlrVthmt.BlackRuby
  • %WINDIR%\imsins.log в %WINDIR%\Encrypted_FZJKug8zULQ0EwtrtZab7O9peRvpKhZOWGG2fcML01ES.BlackRuby
  • %WINDIR%\MedCtrOC.log в %WINDIR%\Encrypted_DkaYAWnTgeW5wFygTWn6qpDVl0Sv8wHEFKzIwIF2RMZv.BlackRuby
  • %WINDIR%\KB942288-v3.log в %WINDIR%\Encrypted_3PLYyjgopy8SgqFc2pnrdLYRtq3nB4wIhgIwhf3.BlackRuby
Перемещает следующие файлы:
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\secmod.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_32mLxFRy1pbOA6hfZT2lTvpjh64dvS1CE9n8aESzVmh.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\sessionstore.bak в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_W4En2T4mEFmhwB40dBQ9vapuDG62fibXo9WJW2DM1.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\search.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_0U99nIJKEMhlaUzsDMpOKkZ6X3i67fSqHtPWQsA7q0rdZ6.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\pluginreg.dat в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_5dFvSZ51cEPWkUY2PZcnz6fMUfyPMyaXl1LX2tfdw42p.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\prefs.js в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_GyUvdMBgTuo01tH6rFc2CZKRMyOXIsvTKe2uG.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\userChrome-example.css в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\Encrypted_SVe7dbdK6gLBuyskuUcpJi1cT2E3hiDrRFQGxv.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\userContent-example.css в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\Encrypted_9sKXscLnAmw8wTwIPs2RzqgssUgZNr09Ztqo9LWPJA.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\webappsstore.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_6wYRQRtt6nGFYHpUUg27jtknnnr70f5Au1JTrmUCPy.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\sessionstore.js в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_iOSmCG0R6vBJCalD5rQM94Uz7ZV0bbwTMmDfmdQxEIqfK0.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\signons.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_CQuEFUlEKLNdyg8h9ZojahV0cjXYKrXnwmwrhQCJkLyso.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\places.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_J2fQmURX52JCZSbtYAnrAWixlf6roOS9GT3bIo.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\content-prefs.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_D08Fr8Yit6yTn5MGiloAebsoaGRuMzJCviyvkim.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cookies.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_7glS25gMeYr7Nf535s1Xnn8SkKmSBmrZtwMX.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chromeappsstore.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_2otFgLR32PZrXgdCH6nwR9Dkix3nQ7zGN5IZU6ZSPjDKxn.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\bookmarks.html в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_rPlNO89mhuncj6EAi11xKMXJnKYr2gTffP0pNtp9BAw.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cert8.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_XmRod8qFnzNYlZIiDOPZzUCZBnzOgqOwn5YNYJn7ug68UMf.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\key3.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_wSZmYJi650EHDlYc9MC8agS95RiuFKJQjFvoDfnEGu.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\permissions.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_pyEzjGqjpc8tnMGPUTPUisimFU3S59rngTJQM25.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\formhistory.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_SQ9KV67Iqj3xRfC95eok83SxYGgWW5i70FCcHs2rlrL.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\downloads.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_gNptBCqzJnFiHTmYMQP2qgxgD02QsUcMFlQOx.BlackRuby
  • %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions.sqlite в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\Encrypted_ZuU8L9ye5G0Lr5ULiXbOzrDKNCLyhHAjC1o18Wjz7EWpjx.BlackRuby
Изменяет множество файлов пользовательских данных (Trojan.Encoder).
Сетевая активность:
Подключается к:
  • 'gi##ub.com':443
  • 'fr###eoip.net':80
  • 'wp#d':80
TCP:
Запросы HTTP GET:
  • http://fr###eoip.net/json/
  • http://11#.#11.111.1/wpad.dat via wp#d
UDP:
  • DNS ASK gi##ub.com
  • DNS ASK fr###eoip.net
  • DNS ASK wp#d

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке