Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.5654

Добавлен в вирусную базу Dr.Web: 2016-08-22

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Создает или изменяет следующие файлы
  • %ALLUSERSPROFILE%\start menu\programs\startup\decrypt_your_files.html
Вредоносные функции
Для затруднения выявления своего присутствия в системе
блокирует запуск следующих системных утилит:
  • Диспетчера задач (Taskmgr)
Изменения в файловой системе
Создает следующие файлы
  • %TEMP%\windowsupdate.exe
  • C:\documents and settings\networkservice\local settings\<INETFILES>\content.ie5\etuaii8e\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\<INETFILES>\content.ie5\ee7gwdg8\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\temp\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\history\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\history\history.ie5\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\<INETFILES>\content.ie5\z9pmdpek\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\application data\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\application data\microsoft\windows\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\application data\microsoft\credentials\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\application data\microsoft\credentials\s-1-5-20\decrypt_your_files.html
  • C:\documents and settings\networkservice\cookies\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\application data\microsoft\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\9.0\javascripts\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\<INETFILES>\content.ie5\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\10.0\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\10.0\security\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\10.0\security\crlcache\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\10.0\javascripts\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\10.0\forms\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\10.0\collab\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\systemcertificates\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\<INETFILES>\content.ie5\h8mbgrq8\decrypt_your_files.html
  • %APPDATA%\.purple\certificates\decrypt_your_files.html
  • %APPDATA%\.purple\certificates\x509\decrypt_your_files.html
  • %APPDATA%\.purple\certificates\x509\tls_peers\decrypt_your_files.html
  • %HOMEPATH%\.oracle_jre_usage\decrypt_your_files.html
  • C:\documents and settings\networkservice\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\decrypt_your_files.html
  • %APPDATA%\.purple\smileys\decrypt_your_files.html
  • C:\documents and settings\networkservice\local settings\<INETFILES>\decrypt_your_files.html
  • %APPDATA%\.purple\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\9.0\forms\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\systemcertificates\my\crls\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\systemcertificates\my\certificates\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\systemcertificates\my\crls\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\systemcertificates\my\ctls\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\systemcertificates\my\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\systemcertificates\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\decrypt_your_files.html
  • C:\documents and settings\localservice\cookies\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\application data\microsoft\credentials\s-1-5-19\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\application data\microsoft\credentials\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\application data\microsoft\windows\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\application data\microsoft\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\application data\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\history\history.ie5\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\history\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\systemcertificates\my\certificates\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\<INETFILES>\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\media player\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\internet explorer\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\credentials\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\credentials\s-1-5-20\decrypt_your_files.html
  • C:\documents and settings\localservice\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\systemcertificates\my\decrypt_your_files.html
  • C:\documents and settings\networkservice\application data\microsoft\systemcertificates\my\ctls\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\internet explorer\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\<INETFILES>\content.ie5\qiszf4kx\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\<INETFILES>\content.ie5\o4q6sqop\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\<INETFILES>\content.ie5\mqraz07n\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\<INETFILES>\content.ie5\9stcdn6y\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\temp\decrypt_your_files.html
  • C:\documents and settings\localservice\local settings\<INETFILES>\content.ie5\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\winrar\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\9.0\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\en\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\ru\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\ru\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\ru\jabber\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\ru\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\pt\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\tr\jabber\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\pt\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\pt\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\kz\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\kz\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\kz\jabber\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\kz\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\en\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\pt\jabber\decrypt_your_files.html
  • %APPDATA%\adobe\acrobat\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\tr\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\smiles\flash\decrypt_your_files.html
  • %APPDATA%\icqm\icq\skin_cache\decrypt_your_files.html
  • %APPDATA%\icqm\icq\skin\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\uz\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\en\jabber\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\uz\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\tr\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\ua\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\ua\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\ua\jabber\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\ua\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\tr\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\uz\jabber\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\en\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\smiles\smiles\8march\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\de\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\de\loading\decrypt_your_files.html
  • %APPDATA%\icq-profile\base\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\credentials\decrypt_your_files.html
  • %APPDATA%\adobe\linguistics\dictionaries\adobe custom dictionary\can\decrypt_your_files.html
  • %APPDATA%\adobe\flash player\assetcache\mc4yk349\decrypt_your_files.html
  • %APPDATA%\adobe\flash player\assetcache\decrypt_your_files.html
  • %APPDATA%\adobe\flash player\decrypt_your_files.html
  • %APPDATA%\adobe\headlights\decrypt_your_files.html
  • %APPDATA%\icq-profile\update\decrypt_your_files.html
  • %APPDATA%\adobe\linguistics\dictionaries\adobe custom dictionary\all\decrypt_your_files.html
  • %APPDATA%\adobe\linguistics\dictionaries\adobe custom dictionary\eng\decrypt_your_files.html
  • %APPDATA%\icq-profile\update\splash_banner\decrypt_your_files.html
  • %APPDATA%\adobe\linguistics\dictionaries\adobe custom dictionary\decrypt_your_files.html
  • %APPDATA%\adobe\linguistics\dictionaries\decrypt_your_files.html
  • %APPDATA%\adobe\linguistics\decrypt_your_files.html
  • %APPDATA%\adobe\logtransport2\decrypt_your_files.html
  • %APPDATA%\adobe\linguistics\dictionaries\adobe custom dictionary\brt\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\media player\decrypt_your_files.html
  • %APPDATA%\icqm\icq\database\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\bg\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\bg\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\de\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\cz\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\cz\loading\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\cz\jabber\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\cz\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\de\jabber\decrypt_your_files.html
  • %APPDATA%\icq-profile\decrypt_your_files.html
  • %APPDATA%\adobe\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\bg\error\decrypt_your_files.html
  • %APPDATA%\icqm\icq\graphics\decrypt_your_files.html
  • %APPDATA%\icqm\icq\graphics\phone\decrypt_your_files.html
  • %APPDATA%\icqm\icq\fonts\decrypt_your_files.html
  • %APPDATA%\icqm\icq\dll\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\bg\jabber\decrypt_your_files.html
  • C:\documents and settings\localservice\application data\microsoft\credentials\s-1-5-19\decrypt_your_files.html
  • C:\documents and settings\default user\decrypt_your_files.html
  • C:\documents and settings\default user\templates\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\network\connections\cm\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\network\connections\pbk\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\network\connections\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\network\downloader\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\network\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\office\data\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\office\groove\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\office\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\user account pictures\default pictures\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\user account pictures\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft help\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\oracle\java\installcache\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\oracle\java\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\oracle\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\sun\java\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{a2563e55-3bec-3828-8d67-e5e8b9e8b675}v14.0.23026\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{be960c1c-7bad-3de6-8b1a-2616fe532845}v14.0.23026\packages\vcruntimeadditional_x86\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\sun\java\java update\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{be960c1c-7bad-3de6-8b1a-2616fe532845}v14.0.23026\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{be960c1c-7bad-3de6-8b1a-2616fe532845}v14.0.23026\packages\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\2052\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{a2563e55-3bec-3828-8d67-e5e8b9e8b675}v14.0.23026\packages\vcruntimeminimum_x86\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\package cache\{a2563e55-3bec-3828-8d67-e5e8b9e8b675}v14.0.23026\packages\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\3082\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1050\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1031\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\setup\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\acrobat\10.0\replicate\security\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\acrobat\10.0\replicate\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\acrobat\10.0\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\acrobat\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\arm\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\sun\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\setup\{ac76ba86-7ad7-1033-7b44-aa1000000001}\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\crypto\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\crypto\dss\machinekeys\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\crypto\dss\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\crypto\rsa\machinekeys\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\crypto\rsa\s-1-5-18\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\adobe\updater6\decrypt_your_files.html
  • %APPDATA%\icqm\icq\smiles\smiles\animated\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\dbgclr\7.1\1033\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\html help\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\dbgclr\7.1\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1049\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1046\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1042\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1041\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1040\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\dbgclr\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1036\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\crypto\rsa\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1028\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdaipp\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdaipp\offline\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\media player\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\media index\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\7.0\1033\decrypt_your_files.html
  • %APPDATA%\icqm\icq\html\uz\error\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\accessories\entertainment\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\history\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\history\history.ie5\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\application data\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\application data\microsoft\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\<INETFILES>\content.ie5\etuaii8e\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\application data\microsoft\windows media\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\application data\microsoft\media player\decrypt_your_files.html
  • C:\documents and settings\default user\favorites\decrypt_your_files.html
  • C:\documents and settings\default user\desktop\decrypt_your_files.html
  • C:\documents and settings\default user\cookies\decrypt_your_files.html
  • C:\documents and settings\default user\application data\decrypt_your_files.html
  • C:\documents and settings\default user\application data\microsoft\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\application data\microsoft\windows media\9.0\decrypt_your_files.html
  • %ALLUSERSPROFILE%\application data\microsoft\msdn\8.0\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\<INETFILES>\content.ie5\h8mbgrq8\decrypt_your_files.html
  • C:\documents and settings\default user\start menu\decrypt_your_files.html
  • C:\documents and settings\default user\recent\decrypt_your_files.html
  • C:\documents and settings\default user\sendto\decrypt_your_files.html
  • C:\documents and settings\default user\start menu\programs\decrypt_your_files.html
  • C:\documents and settings\default user\start menu\programs\startup\decrypt_your_files.html
  • C:\documents and settings\default user\start menu\programs\accessories\decrypt_your_files.html
  • C:\documents and settings\default user\start menu\programs\accessories\entertainment\decrypt_your_files.html
  • C:\documents and settings\default user\start menu\programs\accessories\accessibility\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\temp\decrypt_your_files.html
  • C:\documents and settings\default user\application data\microsoft\systemcertificates\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\<INETFILES>\content.ie5\z9pmdpek\decrypt_your_files.html
  • C:\documents and settings\default user\nethood\decrypt_your_files.html
  • C:\documents and settings\default user\my documents\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\<INETFILES>\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\<INETFILES>\content.ie5\decrypt_your_files.html
  • C:\documents and settings\default user\printhood\decrypt_your_files.html
  • C:\documents and settings\default user\local settings\<INETFILES>\content.ie5\ee7gwdg8\decrypt_your_files.html
  • C:\documents and settings\default user\application data\microsoft\systemcertificates\my\decrypt_your_files.html
  • C:\documents and settings\default user\application data\microsoft\systemcertificates\my\ctls\decrypt_your_files.html
  • %ALLUSERSPROFILE%\desktop\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\my videos\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\my music\sample music\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\my music\sample playlists\00107ff6\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\my music\sample playlists\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\my music\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\administrative tools\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\my pictures\sample pictures\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\accessories\decrypt_your_files.html
  • %ALLUSERSPROFILE%\drm\decrypt_your_files.html
  • %ALLUSERSPROFILE%\favorites\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\accessories\accessibility\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\accessories\communications\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\my pictures\decrypt_your_files.html
  • %ALLUSERSPROFILE%\documents\my music\my playlists\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\google chrome\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\microsoft office\microsoft office tools\decrypt_your_files.html
  • C:\documents and settings\default user\application data\microsoft\systemcertificates\my\crls\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\games\decrypt_your_files.html
  • C:\documents and settings\default user\application data\microsoft\systemcertificates\my\certificates\decrypt_your_files.html
  • C:\documents and settings\default user\application data\microsoft\media player\decrypt_your_files.html
  • C:\documents and settings\default user\application data\microsoft\internet explorer\decrypt_your_files.html
  • %ALLUSERSPROFILE%\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\microsoft .net framework sdk v1.1\decrypt_your_files.html
  • %ALLUSERSPROFILE%\templates\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\accessories\system tools\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\steam\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\qip 2012\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\mirc\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\programs\microsoft office\decrypt_your_files.html
  • %ALLUSERSPROFILE%\start menu\decrypt_your_files.html
  • %APPDATA%\icqm\icq\smiles\smiles\cat\decrypt_your_files.html
Перемещает следующие файлы
  • %APPDATA%\.purple\prefs.xml в %APPDATA%\.purple\prefs.xml.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\doll.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\doll.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\drink.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\drink.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\flowers.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\flowers.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\hug.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\hug.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\joy.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\joy.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\love.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\love.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\new_dress.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\new_dress.gif.fantom
  • %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf в %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\perfume.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\perfume.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\ring.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\ring.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\shoes.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\shoes.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\sunburn.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\sunburn.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\angel.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\angel.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\appl.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\appl.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\cookie.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\cookie.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\cat.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\cat.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\car.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\car.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\s008.gif в %APPDATA%\icqm\icq\smiles\smiles\s008.gif.fantom
  • %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf в %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf в %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\wf_love_sdaus.swf в %APPDATA%\icqm\icq\smiles\flash\wf_love_sdaus.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\tank.swf в %APPDATA%\icqm\icq\smiles\flash\tank.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\sorry.swf в %APPDATA%\icqm\icq\smiles\flash\sorry.swf.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\8march\mad.gif в %APPDATA%\icqm\icq\smiles\smiles\8march\mad.gif.fantom
  • %APPDATA%\icqm\icq\smiles\flash\sobaka.swf в %APPDATA%\icqm\icq\smiles\flash\sobaka.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\smeh.swf в %APPDATA%\icqm\icq\smiles\flash\smeh.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\skratch.swf в %APPDATA%\icqm\icq\smiles\flash\skratch.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\serdze.swf в %APPDATA%\icqm\icq\smiles\flash\serdze.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\rosy.swf в %APPDATA%\icqm\icq\smiles\flash\rosy.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf в %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\missyou.swf в %APPDATA%\icqm\icq\smiles\flash\missyou.swf.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\beauty.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\beauty.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\flowr.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\flowr.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\cat\cat_mouse.gif в %APPDATA%\icqm\icq\smiles\smiles\cat\cat_mouse.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\book.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\book.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\rainbow.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\rainbow.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\red.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\red.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\sad.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\sad.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\sing.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\sing.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\skuka.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\skuka.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\sleep.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\sleep.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\tongue.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\tongue.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\beer.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\beer.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\victory.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\victory.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\wonder.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\wonder.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\cat\cat_attack.gif в %APPDATA%\icqm\icq\smiles\smiles\cat\cat_attack.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\cat\cat_hand.gif в %APPDATA%\icqm\icq\smiles\smiles\cat\cat_hand.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\cat\cat_lick.gif в %APPDATA%\icqm\icq\smiles\smiles\cat\cat_lick.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\cat\cat_meow.gif в %APPDATA%\icqm\icq\smiles\smiles\cat\cat_meow.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\poison.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\poison.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\pistolet.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\pistolet.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\love.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\love.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\kiss.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\kiss.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\hungry.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\hungry.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\history.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\history.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\gift.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\gift.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\gg2.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\gg2.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\gg.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\gg.gif.fantom
  • %APPDATA%\icqm\icq\smiles\flash\mad dog.swf в %APPDATA%\icqm\icq\smiles\flash\mad dog.swf.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\fingal.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\fingal.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\fight.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\fight.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\eat.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\eat.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\devil.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\devil.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\dance.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\dance.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\cry.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\cry.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\could.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\could.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\blew.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\blew.gif.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\animated\smile.gif в %APPDATA%\icqm\icq\smiles\smiles\animated\smile.gif.fantom
  • %APPDATA%\icqm\icq\smiles\flash\love_bear_rose.swf в %APPDATA%\icqm\icq\smiles\flash\love_bear_rose.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf в %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf.fantom
  • %APPDATA%\icqm\icq\html\en\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\en\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\html\kz\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\kz\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\html\pt\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\pt\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\html\ru\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\ru\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\html\tr\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\tr\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\html\ua\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\ua\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_bg.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_bg.xml.fantom
  • %APPDATA%\icq-profile\installerlang.xml в %APPDATA%\icq-profile\installerlang.xml.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_cz.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_cz.xml.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_de.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_de.xml.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_en.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_en.xml.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_kz.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_kz.xml.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_pt.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_pt.xml.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_ru.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_ru.xml.fantom
  • %APPDATA%\icqm\icq\html\de\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\de\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\html\cz\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\cz\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\html\bg\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\bg\loading\progress_agent.gif.fantom
  • %APPDATA%\icqm\icq\database\citylist_uz.csv в %APPDATA%\icqm\icq\database\citylist_uz.csv.fantom
  • %APPDATA%\icqm\icq\database\citylist_ua.csv в %APPDATA%\icqm\icq\database\citylist_ua.csv.fantom
  • %APPDATA%\icqm\icq\database\citylist_tr.csv в %APPDATA%\icqm\icq\database\citylist_tr.csv.fantom
  • %APPDATA%\icqm\icq\database\citylist_ru.csv в %APPDATA%\icqm\icq\database\citylist_ru.csv.fantom
  • %APPDATA%\icqm\icq\database\citylist_kz.csv в %APPDATA%\icqm\icq\database\citylist_kz.csv.fantom
  • %APPDATA%\icqm\icq\database\citylist_en.csv в %APPDATA%\icqm\icq\database\citylist_en.csv.fantom
  • %APPDATA%\icqm\icq\html\uz\loading\progress_agent.gif в %APPDATA%\icqm\icq\html\uz\loading\progress_agent.gif.fantom
  • %APPDATA%\adobe\acrobat\9.0\javascripts\glob.settings.js в %APPDATA%\adobe\acrobat\9.0\javascripts\glob.settings.js.fantom
  • %APPDATA%\adobe\acrobat\9.0\javascripts\glob.js в %APPDATA%\adobe\acrobat\9.0\javascripts\glob.js.fantom
  • %APPDATA%\adobe\acrobat\10.0\javascripts\glob.settings.js в %APPDATA%\adobe\acrobat\10.0\javascripts\glob.settings.js.fantom
  • %APPDATA%\adobe\acrobat\10.0\javascripts\glob.js в %APPDATA%\adobe\acrobat\10.0\javascripts\glob.js.fantom
  • %APPDATA%\adobe\acrobat\10.0\tmgrpprm.sav в %APPDATA%\adobe\acrobat\10.0\tmgrpprm.sav.fantom
  • %APPDATA%\adobe\acrobat\10.0\tmdocs.sav в %APPDATA%\adobe\acrobat\10.0\tmdocs.sav.fantom
  • %APPDATA%\.purple\status.xml в %APPDATA%\.purple\status.xml.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_tr.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_tr.xml.fantom
  • %APPDATA%\icqm\icq\smiles\flash\canthearu.swf в %APPDATA%\icqm\icq\smiles\flash\canthearu.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf в %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf.fantom
  • %APPDATA%\icqm\icq\smiles\skin.txt в %APPDATA%\icqm\icq\smiles\skin.txt.fantom
  • %APPDATA%\icqm\icq\smiles\flash\gangsta.swf в %APPDATA%\icqm\icq\smiles\flash\gangsta.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\guby.swf в %APPDATA%\icqm\icq\smiles\flash\guby.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\information.swf в %APPDATA%\icqm\icq\smiles\flash\information.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\joy.swf в %APPDATA%\icqm\icq\smiles\flash\joy.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\kisses.swf в %APPDATA%\icqm\icq\smiles\flash\kisses.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf в %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf в %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_ua.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_ua.xml.fantom
  • %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf в %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf в %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf в %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\krizis.swf в %APPDATA%\icqm\icq\smiles\flash\krizis.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\laugh.swf в %APPDATA%\icqm\icq\smiles\flash\laugh.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\likeu.swf в %APPDATA%\icqm\icq\smiles\flash\likeu.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\duh.swf в %APPDATA%\icqm\icq\smiles\flash\duh.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\drako_zombie.swf в %APPDATA%\icqm\icq\smiles\flash\drako_zombie.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\drako_snegyrka.swf в %APPDATA%\icqm\icq\smiles\flash\drako_snegyrka.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\drako_opyatnica.swf в %APPDATA%\icqm\icq\smiles\flash\drako_opyatnica.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\drako_love.swf в %APPDATA%\icqm\icq\smiles\flash\drako_love.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\drako_koster.swf в %APPDATA%\icqm\icq\smiles\flash\drako_koster.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\drako_bolnoy.swf в %APPDATA%\icqm\icq\smiles\flash\drako_bolnoy.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\devochka.swf в %APPDATA%\icqm\icq\smiles\flash\devochka.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\chillout.swf в %APPDATA%\icqm\icq\smiles\flash\chillout.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\love_bear_kiss.swf в %APPDATA%\icqm\icq\smiles\flash\love_bear_kiss.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\boo.swf в %APPDATA%\icqm\icq\smiles\flash\boo.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\bodun.swf в %APPDATA%\icqm\icq\smiles\flash\bodun.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\beer.swf в %APPDATA%\icqm\icq\smiles\flash\beer.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\beback.swf в %APPDATA%\icqm\icq\smiles\flash\beback.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\bad_cold.swf в %APPDATA%\icqm\icq\smiles\flash\bad_cold.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\angel.swf в %APPDATA%\icqm\icq\smiles\flash\angel.swf.fantom
  • %APPDATA%\icqm\icq\smiles\flash\akitaka.swf в %APPDATA%\icqm\icq\smiles\flash\akitaka.swf.fantom
  • %APPDATA%\icqm\icq\smiles\mrasmileslang_uz.xml в %APPDATA%\icqm\icq\smiles\mrasmileslang_uz.xml.fantom
  • %APPDATA%\icqm\icq\smiles\smiles\cat\cat_paper.gif в %APPDATA%\icqm\icq\smiles\smiles\cat\cat_paper.gif.fantom
Изменяет множество файлов пользовательских данных (Trojan.Encoder).
Изменяет расширения файлов пользовательских данных (Trojan.Encoder).
Сетевая активность
TCP
Запросы HTTP GET
  • http://po#####olsforyou.com/themes/prestashop/cache/stats.php
UDP
  • DNS ASK po#####olsforyou.com
Другое
Создает и запускает на исполнение
  • '%TEMP%\windowsupdate.exe'

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке