Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.29624

Добавлен в вирусную базу Dr.Web: 2019-09-24

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Создает следующие файлы на съемном носителе
  • <Имя диска съемного носителя>:\correct.avi
  • <Имя диска съемного носителя>:\!!! all your files are encrypted !!!.txt
  • <Имя диска съемного носителя>:\join.avi
  • <Имя диска съемного носителя>:\000814251_video_01.avi
  • <Имя диска съемного носителя>:\toolbar.bmp
  • <Имя диска съемного носителя>:\coffee.bmp
  • <Имя диска съемного носителя>:\contoso_1.cer
  • <Имя диска съемного носителя>:\pmd.cer
  • <Имя диска съемного носителя>:\testcertificate.cer
  • <Имя диска съемного носителя>:\contoso.cer
  • <Имя диска съемного носителя>:\sdksampleprivdeveloper.cer
  • <Имя диска съемного носителя>:\gruenspecht_02172016.pptx
  • <Имя диска съемного носителя>:\samieee_obiee_presentation.pptx
  • <Имя диска съемного носителя>:\indogerman2010.pptx
  • <Имя диска съемного носителя>:\roozenedowebinar.pptx
Вредоносные функции
Для затруднения выявления своего присутствия в системе
удаляет теневые копии разделов.
Читает файлы, отвечающие за хранение паролей сторонними программами
  • %HOMEPATH%\desktop\210252809.jpeg
  • %HOMEPATH%\desktop\testee.cer
  • %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
  • %HOMEPATH%\desktop\sdkfailsafeemulator.cer
  • %HOMEPATH%\desktop\region-north-karelia.jpeg
  • %HOMEPATH%\desktop\pushkin.jpg
  • %HOMEPATH%\desktop\nwfieldnotes1966.docx
  • %HOMEPATH%\desktop\join.avi
  • %HOMEPATH%\desktop\howto-index.html
  • %HOMEPATH%\desktop\holycrosschurchinstructions.docx
  • %HOMEPATH%\desktop\hanni_umami_chapter.doc
  • %HOMEPATH%\desktop\garden.htm
  • %HOMEPATH%\desktop\tileimage.bmp
  • %HOMEPATH%\desktop\dashborder_120.bmp
  • %HOMEPATH%\desktop\contoso_1.cer
  • %HOMEPATH%\desktop\coffee.bmp
  • %HOMEPATH%\desktop\applicantform_en.doc
  • %HOMEPATH%\desktop\api-hashmap.html
  • %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
  • %HOMEPATH%\desktop\alert.html
  • %HOMEPATH%\desktop\adhd_and_obesity.docx
  • %HOMEPATH%\desktop\adadsi.html
  • %HOMEPATH%\desktop\about.html
  • %HOMEPATH%\desktop\4f0bf7ff71f28.jpeg
  • %HOMEPATH%\desktop\3.jpg
  • %HOMEPATH%\desktop\cveuropeo.doc
  • %HOMEPATH%\desktop\tree_view.htm
Изменения в файловой системе
Создает следующие файлы
  • C:\documents and settings\default user\cookies\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\mt\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ms\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\mr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\mo\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ml\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\mk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\lv\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\lt\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ku\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ko\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\kn\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\kk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\kab\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ka\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\es\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\jv\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\it\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\is\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\id\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\hu\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\hr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\hi\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\he\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\gu\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\gl\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\fy\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\fr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\fi\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\fa\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\eu\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ja\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\et\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\my\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ta\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\th\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\tr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\tw\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ug\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\uk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ur\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\vi\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\backends\win32\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\wae\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\zh_cn\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\zh_hk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\zh_tw\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\winboot\!!! all your files are encrypted !!!.txt
  • %TEMP%\temporary directory 1 for omni.ja_20150820125829.zip\chrome\en-gb\locale\branding\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ne\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\nb\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sv\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sq\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sl\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\shn\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ru\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ro\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\pt_br\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\pt\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\pl\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\oc\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\nn\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\nl\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\te\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\eo\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\en_gb\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\en_ca\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\encodings\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\ctypes\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\util\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\publickey\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\hash\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\cipher\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\bittorrent\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\data\images\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\data\custom-installation\hooks\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\data\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\!!! all your files are encrypted !!!.txt
  • %TEMP%\history\history.ie5\!!! all your files are encrypted !!!.txt
  • %TEMP%\2.9.0.1467 (partner)\chrome\en-gb\locale\browser-region\!!! all your files are encrypted !!!.txt
  • %TEMP%\2.9.0.1467 (partner)\chrome\en-gb\locale\branding\!!! all your files are encrypted !!!.txt
  • %TEMP%\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\local settings\history\history.ie5\mshist012017042620170427\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\favorites\links\яндекс.url
  • %HOMEPATH%\favorites\links\почта.url
  • %HOMEPATH%\favorites\links\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\favorites\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\desktop\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\cookies\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\!!! all your files are encrypted !!!.txt
  • C:\documents and settings\default user\templates\!!! all your files are encrypted !!!.txt
  • C:\documents and settings\default user\local settings\<INETFILES>\content.ie5\!!! all your files are encrypted !!!.txt
  • C:\documents and settings\default user\local settings\history\history.ie5\!!! all your files are encrypted !!!.txt
  • %TEMP%\cookies\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\sap\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\logging\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\sap\msg\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\en_au\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\as\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\en\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\el\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\de\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\da\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\cy\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\csb\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\cs\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\crh\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ca\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\bs\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\br\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\bo\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\bg\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ast\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ar\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\sap\pkt\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\af\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\xml\sax\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\xml\parsers\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\xml\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\frontends\win32\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\frontends\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\uz\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\backends\common\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\backends\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\winui\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\urlgrabber\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\sets\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\sap\util\!!! all your files are encrypted !!!.txt
  • %TEMP%\temporary directory 2 for omni.ja_20150820125829.zip\chrome\en-gb\locale\browser-region\!!! all your files are encrypted !!!.txt
  • %TEMP%\<INETFILES>\content.ie5\!!! all your files are encrypted !!!.txt
Перемещает следующие файлы
  • %HOMEPATH%\favorites\links\почта.url в %HOMEPATH%\favorites\links\почта.url.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\tl.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\tl.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\tr.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\tr.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\trash.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\trash.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnoffnotificationinacrobat.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnoffnotificationinacrobat.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnoffnotificationintray.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnoffnotificationintray.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnonnotificationinacrobat.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnonnotificationinacrobat.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_joined.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_joined.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnonnotificationintray.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnonnotificationintray.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\adobepistd.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\adobepistd.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-bold.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-bold.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-boldoblique.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-boldoblique.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-oblique.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-oblique.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-bold.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-bold.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\stop_collection_data.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\stop_collection_data.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\submission_history.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\submission_history.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_ok.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_ok.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_lg.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_lg.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_issue.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_issue.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_super.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_super.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\form_responses.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\form_responses.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\info.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\info.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\main.css в %ProgramFiles%\adobe\reader 10.0\reader\tracker\main.css.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\open_original_form.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\open_original_form.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\pdf.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\pdf.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-boldit.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-boldit.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\warning.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\warning.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviewers.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviewers.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_super.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_super.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_browser.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_browser.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_email.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_email.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_same_reviewers.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_same_reviewers.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_shared.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_shared.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\rss.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\rss.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_received.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_received.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_sent.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_sent.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-it.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-it.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-regular.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-regular.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-bold.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-bold.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can.hyp в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can.hyp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can03.ths в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can03.ths.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can129.hsp в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can129.hsp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can32.clx в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can32.clx.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\eng.hyp в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\eng.hyp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\eng32.clx в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\eng32.clx.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\engphon.env в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\engphon.env.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa03.hsp в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa03.hsp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_distributed.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_distributed.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa03.ths в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa03.ths.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa37.hyp в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa37.hyp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\saslprep\saslprepprofile_norm_bidi.spp в %ProgramFiles%\adobe\reader 10.0\resource\saslprep\saslprepprofile_norm_bidi.spp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\icu\icudt26l.dat в %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\icu\icudt26l.dat.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\symbol.txt в %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\symbol.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\zdingbat.txt в %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\zdingbat.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\centeuro.txt в %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\centeuro.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can.fca в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can.fca.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\zy______.pfm в %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\zy______.pfm.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt55.ths в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt55.ths.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\zx______.pfm в %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\zx______.pfm.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-boldit.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-boldit.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-it.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-it.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-regular.otf в %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-regular.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\sy______.pfb в %ProgramFiles%\adobe\reader 10.0\resource\font\sy______.pfb.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\zx______.pfb в %ProgramFiles%\adobe\reader 10.0\resource\font\zx______.pfb.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\zy______.pfb в %ProgramFiles%\adobe\reader 10.0\resource\font\zy______.pfb.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\sy______.pfm в %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\sy______.pfm.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\corpchar.txt в %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\corpchar.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt04.hsp в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt04.hsp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_ca.txt в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_ca.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb.txt в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb_euro.txt в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb_euro.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us.txt в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us_posix.txt в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us_posix.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt.fca в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt.fca.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt.hyp в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt.hyp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt32.clx в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt32.clx.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa.fca в %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa.fca.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\end_review.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\end_review.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\services\dexshare.spi в %ProgramFiles%\adobe\reader 10.0\reader\services\dexshare.spi.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\acrobat.com\meta-inf\air\hash в %ProgramFiles%\adobe\acrobat.com\meta-inf\air\hash.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\acrobat.com\meta-inf\air\publisherid в %ProgramFiles%\adobe\acrobat.com\meta-inf\air\publisherid.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\adobe.reader.dependencies.manifest в %ProgramFiles%\adobe\reader 10.0\reader\adobe.reader.dependencies.manifest.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\agmgpuoptin.ini в %ProgramFiles%\adobe\reader 10.0\reader\agmgpuoptin.ini.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\cryptocme2.sig в %ProgramFiles%\adobe\reader 10.0\reader\cryptocme2.sig.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\rtc.der в %ProgramFiles%\adobe\reader 10.0\reader\rtc.der.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_dotnetfx45_full_setup_decompression_log.txt в %TEMP%\dd_dotnetfx45_full_setup_decompression_log.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\javascripts\jsbytecodewin.bin в %ProgramFiles%\adobe\reader 10.0\reader\javascripts\jsbytecodewin.bin.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\accessibility.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\accessibility.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acrosign.prc в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acrosign.prc.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\annots.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\annots.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\checkers.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\checkers.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\digsig.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\digsig.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\acrobat.com\meta-inf\signatures.xml в %ProgramFiles%\adobe\acrobat.com\meta-inf\signatures.xml.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\acrobat.com\meta-inf\air\application.xml в %ProgramFiles%\adobe\acrobat.com\meta-inf\air\application.xml.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\acrobat.com\bin-debug\appcontainer.swf в %ProgramFiles%\adobe\acrobat.com\bin-debug\appcontainer.swf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\acrobat.com\version.xml в %ProgramFiles%\adobe\acrobat.com\version.xml.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\acrobat.com\mimetype в %ProgramFiles%\adobe\acrobat.com\mimetype.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\aucheck_parser.txt в %TEMP%\aucheck_parser.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_clwireg.txt в %TEMP%\dd_clwireg.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_depcheck_netfx20_exp_35.txt в %TEMP%\dd_depcheck_netfx20_exp_35.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_depcheck_netfx_exp_35.txt в %TEMP%\dd_depcheck_netfx_exp_35.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_dotnetfx20install.txt в %TEMP%\dd_dotnetfx20install.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_dotnetfx35install.txt в %TEMP%\dd_dotnetfx35install.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\dva.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\dva.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\legal\enu\eula.ini в %ProgramFiles%\adobe\reader 10.0\reader\legal\enu\eula.ini.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_dotnetfx40_full_x86_x64_decompression_log.txt в %TEMP%\dd_dotnetfx40_full_x86_x64_decompression_log.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_net_framework20_setup74f9.txt в %TEMP%\dd_net_framework20_setup74f9.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_net_framework30_setup7762.txt в %TEMP%\dd_net_framework30_setup7762.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_net_framework35_msi77c4.txt в %TEMP%\dd_net_framework35_msi77c4.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_wcf_retca4a2a.txt в %TEMP%\dd_wcf_retca4a2a.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_xps.txt в %TEMP%\dd_xps.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\uxeventlog.txt в %TEMP%\uxeventlog.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %HOMEPATH%\favorites\links\яндекс.url в %HOMEPATH%\favorites\links\яндекс.url.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %TEMP%\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt в %TEMP%\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ebook.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ebook.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\escript.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\escript.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ia32.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ia32.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\2d.x3d в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\2d.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\3difr.x3d в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\3difr.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\drvdx9.x3d в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\drvdx9.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\drvsoft.x3d в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\drvsoft.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\prcr.x3d в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\prcr.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\tesselate.x3d в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\tesselate.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\prc\myriadcad.otf в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\prc\myriadcad.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\services\services.cfg в %ProgramFiles%\adobe\reader 10.0\reader\services\services.cfg.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\ended_review_or_form.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\ended_review_or_form.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\spplugins\admplugin.apl в %ProgramFiles%\adobe\reader 10.0\reader\spplugins\admplugin.apl.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\add_reviewer.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\add_reviewer.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\bl.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\bl.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\br.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\br.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\create_form.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\create_form.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\distribute_form.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\distribute_form.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\email_all.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\email_all.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\windowsmedia.mpp в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\windowsmedia.mpp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\sendmail.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\sendmail.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\quicktime.mpp в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\quicktime.mpp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\search.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\search.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\makeaccessible.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\makeaccessible.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\pddom.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\pddom.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ppklite.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ppklite.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\readoutloud.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\readoutloud.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\reflow.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\reflow.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\saveasrtf.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\saveasrtf.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\tracker\email_initiator.gif в %ProgramFiles%\adobe\reader 10.0\reader\tracker\email_initiator.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\flash.mpp в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\flash.mpp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\spelling.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\spelling.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\updater.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\updater.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\weblink.api в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\weblink.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\adobepdf.xdc в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\adobepdf.xdc.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\adobepdf417.pmp в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\adobepdf417.pmp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\datamatrix.pmp в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\datamatrix.pmp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\qrcode.pmp в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\qrcode.pmp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\mcimpp.mpp в %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\mcimpp.mpp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\croatian.txt в %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\croatian.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
Изменяет множество файлов пользовательских данных (Trojan.Encoder).
Изменяет расширения файлов пользовательских данных (Trojan.Encoder).
Сетевая активность
UDP
  • DNS ASK ge###tool.com
  • DNS ASK ip##gger.ru
Другое
Создает и запускает на исполнение
  • '<SYSTEM32>\cmd.exe' /C bcdedit /set {default} bootstatuspolicy ignoreallfailures' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log System' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log Security' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log Application' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C del "%userprofile%\documents\Default.rdp"' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C attrib "%userprofile%\documents\Default.rdp" -s -h' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C vssadmin delete shadows /all /quiet' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C wmic shadowcopy delete' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete backup' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete systemstatebackup -keepversions:0' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete systemstatebackup' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete catalog -quiet' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C bcdedit /set {default} recoveryenabled no' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C sc config eventlog start=disabled' (со скрытым окном)
  • '<SYSTEM32>\cmd.exe' /C chcp 1250 && net view' (со скрытым окном)
Запускает на исполнение
  • '<SYSTEM32>\cmd.exe' /C bcdedit /set {default} bootstatuspolicy ignoreallfailures
  • '<SYSTEM32>\cmd.exe' /C chcp 1250 && net view
  • '<SYSTEM32>\sc.exe' config eventlog start=disabled
  • '<SYSTEM32>\cmd.exe' /C sc config eventlog start=disabled
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log System
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log Security
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log Application
  • '<SYSTEM32>\cmd.exe' /C del "%userprofile%\documents\Default.rdp"
  • '<SYSTEM32>\attrib.exe' "%HOMEPATH%\documents\Default.rdp" -s -h
  • '<SYSTEM32>\cmd.exe' /C attrib "%userprofile%\documents\Default.rdp" -s -h
  • '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"
  • '<SYSTEM32>\chcp.com' 1250
  • '<SYSTEM32>\cmd.exe' /C reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"
  • '<SYSTEM32>\cmd.exe' /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f
  • '<SYSTEM32>\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f
  • '<SYSTEM32>\cmd.exe' /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f
  • '<SYSTEM32>\cmd.exe' /C vssadmin delete shadows /all /quiet
  • '<SYSTEM32>\cmd.exe' /C wmic shadowcopy delete
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete backup
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete systemstatebackup -keepversions:0
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete systemstatebackup
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete catalog -quiet
  • '<SYSTEM32>\cmd.exe' /C bcdedit /set {default} recoveryenabled no
  • '<SYSTEM32>\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f
  • '<SYSTEM32>\net.exe' view

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке