Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.35818

Добавлен в вирусную базу Dr.Web: 2022-09-10

Описание добавлено:

Техническая информация

Изменения в файловой системе
Создает следующие файлы
  • %HOMEPATH%\desktop\do_not_delete-purplecascade-cvxc-keys.txt
  • %CommonProgramFiles(x86)%\px storage engine\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\office14\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft visual studio 8\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\adobe\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\crashreports\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\speechengines\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\java\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\arm\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\setup\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\desktop\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %HOMEPATH%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\microsoft shared\dao\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2upd\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\favorites\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\documents\my music\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\px storage engine\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\music\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • %HOMEPATH%\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\documents\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\office10\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\downloads\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2start\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\application\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\favorites\all_of_your_files_are_encrypted_readme.txt
  • C:\users\default\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\services\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\adobe\arm\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\google\chrome\application\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\services\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\libraries\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\microsoft shared\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\libraries\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\microsoft shared\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\steam\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\microsoft\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\microsoft shared\help\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\microsoft help\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\recorded tv\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\google\update\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2upd\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\microsoft\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\music\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\documents\my videos\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\videos\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\mozilla thunderbird\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\mozilla\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\adobe\acrobat\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\adobe\helpcfg\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\microsoft toolkit\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\system\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\mirc\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mozilla firefox\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\oracle\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\microsoft toolkit\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\oracle\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft.net\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\documents\my pictures\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft.net\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\common7\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\update\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\microsoft shared\dao\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\steam\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\common7\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\mozilla\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\adobe\arm\reader_15.008.20082\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft office\office14\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\speechengines\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\crashreports\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\pictures\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2wizard\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\microsoft shared\information retrieval\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\mirc\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\adobe\arm\reader_15.007.20033\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\adobe\reader\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\google\chrome\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\downloads\all_of_your_files_are_encrypted_readme.txt
  • %WINDIR%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • D:\$recycle.bin\all_of_your_files_are_encrypted_readme.txt
  • C:\perflogs\admin\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\all_of_your_files_are_encrypted_readme.txt
  • D:\$recycle.bin\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\all_of_your_files_are_encrypted_readme.txt
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\perflogs\admin\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\internet explorer\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\google\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\360tray\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2guard\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2scan\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2cmd\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\k-lite codec pack\all_of_your_files_are_encrypted_readme.txt
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2hijackfree\all_of_your_files_are_encrypted_readme.txt
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\all_of_your_files_are_encrypted_readme.txt
  • C:\perflogs\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\all_of_your_files_are_encrypted_readme.txt
  • <Текущая директория>\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\all_of_your_files_are_encrypted_readme.txt
  • C:\totalcmd\all_of_your_files_are_encrypted_readme.txt
  • C:\far2\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all_of_your_files_are_encrypted_readme.txt
  • C:\$recycle.bin\all_of_your_files_are_encrypted_readme.txt
  • C:\perflogs\all_of_your_files_are_encrypted_readme.txt
  • C:\documents and settings\all_of_your_files_are_encrypted_readme.txt
  • C:\users\all_of_your_files_are_encrypted_readme.txt
  • C:\recovery\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\recovery\all_of_your_files_are_encrypted_readme.txt
  • %WINDIR%\all_of_your_files_are_encrypted_readme.txt
  • <Текущая директория>\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\$recycle.bin\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\totalcmd\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\far2\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\application data\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\adobe\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\adobe\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\default\all_of_your_files_are_encrypted_readme.txt
  • C:\users\default user\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\adobe\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2hijackfree\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\adobe\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft office\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\desktop\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\adobe\setup\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\google\chrome\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2start\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\favorites\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\documents\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\microsoft office\office10\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\all_of_your_files_are_encrypted_readme.txt
  • C:\users\public\desktop\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles(x86)%\k-lite codec pack\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\internet explorer\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\documents\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2service\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • %CommonProgramFiles(x86)%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt
  • %ProgramFiles%\a2guard\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2cmd\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2scan\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2service\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\all_of_your_files_are_encrypted_readme.txt
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\360tray\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\arm\{291aa914-a987-4ce9-bd63-ac0a92d435e5}\all_of_your_files_are_encrypted_readme.txt
Перемещает следующие системные файлы
  • %WINDIR%\bootstat.dat в %WINDIR%\bootstat.dat.prplcscd_cvxcv
  • %WINDIR%\directx.log в %WINDIR%\directx.log.prplcscd_cvxcv
  • %WINDIR%\dtcinstall.log в %WINDIR%\dtcinstall.log.prplcscd_cvxcv
  • %WINDIR%\enterprise.xml в %WINDIR%\enterprise.xml.prplcscd_cvxcv
  • %WINDIR%\ntbtlog.txt в %WINDIR%\ntbtlog.txt.prplcscd_cvxcv
  • %WINDIR%\ocsetup_cbs_uninstall_searchengine-client-package.txt в %WINDIR%\ocsetup_cbs_uninstall_searchengine-client-package.txt.prplcscd_cvxcv
  • %WINDIR%\ocsetup_uninstall_searchengine-client-package.etl в %WINDIR%\ocsetup_uninstall_searchengine-client-package.etl.prplcscd_cvxcv
Перемещает следующие файлы
  • <Текущая директория>\all_of_your_files_are_encrypted_readme.txt в <Текущая директория>\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mozilla thunderbird\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\mozilla thunderbird\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\adobe\helpcfg\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\adobe\helpcfg\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\42.0.2311.135.manifest в %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\42.0.2311.135.manifest.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\microsoft help\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\microsoft help\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\adobe\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mozilla firefox\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\mozilla firefox\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\pictures\all_of_your_files_are_encrypted_readme.txt в C:\users\public\pictures\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft visual studio 8\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft visual studio 8\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\java\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\java\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\videos\all_of_your_files_are_encrypted_readme.txt в C:\users\public\videos\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\recorded tv\all_of_your_files_are_encrypted_readme.txt в C:\users\public\recorded tv\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\microsoft shared\information retrieval\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\microsoft shared\information retrieval\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\adobe\acrobat\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\adobe\acrobat\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mirc\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\mirc\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\system\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\system\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\microsoft toolkit\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\microsoft toolkit\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\arm\reader_15.008.20082\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\adobe\arm\reader_15.008.20082\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\mozilla\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\mozilla\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\oracle\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\oracle\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\microsoft\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\microsoft\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2upd\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\a2upd\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\update\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\google\update\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\crashreports\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\google\crashreports\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\speechengines\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\speechengines\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\music\all_of_your_files_are_encrypted_readme.txt в C:\users\public\music\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\office14\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft office\office14\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\steam\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\steam\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\microsoft shared\help\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\microsoft shared\help\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mirc\ircintro.chm в %ProgramFiles(x86)%\mirc\ircintro.chm.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\office10\saext.dll в %ProgramFiles(x86)%\microsoft office\office10\saext.dll.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\setup\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\adobe\setup\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\arm\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\adobe\arm\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • %ProgramFiles(x86)%\qip 2012\unins000.msg в %ProgramFiles(x86)%\qip 2012\unins000.msg.prplcscd_cvxcv
  • %ProgramFiles(x86)%\msbuild\microsoft.office.infopath.targets в %ProgramFiles(x86)%\msbuild\microsoft.office.infopath.targets.prplcscd_cvxcv
  • %ProgramFiles(x86)%\k-lite codec pack\icons\delete.ico в %ProgramFiles(x86)%\k-lite codec pack\icons\delete.ico.prplcscd_cvxcv
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\adobepistd.otf в %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\adobepistd.otf.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\informix.xsl в %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\informix.xsl.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\msjet.xsl в %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\msjet.xsl.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mirc\versions.txt в %ProgramFiles(x86)%\mirc\versions.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\saslprep\saslprepprofile_norm_bidi.spp в %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\saslprep\saslprepprofile_norm_bidi.spp.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mozilla thunderbird\dependentlibs.list в %ProgramFiles(x86)%\mozilla thunderbird\dependentlibs.list.prplcscd_cvxcv
  • %ProgramFiles(x86)%\k-lite codec pack\icons\x264vfw.ico в %ProgramFiles(x86)%\k-lite codec pack\icons\x264vfw.ico.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\office10\seqchk10.dll в %ProgramFiles(x86)%\microsoft office\office10\seqchk10.dll.prplcscd_cvxcv
  • %ProgramFiles(x86)%\k-lite codec pack\info\faq.css в %ProgramFiles(x86)%\k-lite codec pack\info\faq.css.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\as90.xsl в %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\as90.xsl.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\arm\{291aa914-a987-4ce9-bd63-ac0a92d435e5}\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\adobe\arm\{291aa914-a987-4ce9-bd63-ac0a92d435e5}\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mirc\readme.txt в %ProgramFiles(x86)%\mirc\readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\mozilla\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\mozilla\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\oracle\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\oracle\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\office14\authzax.dll в %ProgramFiles(x86)%\microsoft office\office14\authzax.dll.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\microsoft toolkit\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\microsoft toolkit\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • %ProgramFiles(x86)%\k-lite codec pack\icons\config.ico в %ProgramFiles(x86)%\k-lite codec pack\icons\config.ico.prplcscd_cvxcv
  • %ProgramFiles(x86)%\k-lite codec pack\icaros\icaros license.txt в %ProgramFiles(x86)%\k-lite codec pack\icaros\icaros license.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\microsoft help\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\microsoft help\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\as80.xsl в %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\as80.xsl.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mirc\mirc.chm в %ProgramFiles(x86)%\mirc\mirc.chm.prplcscd_cvxcv
  • %ProgramFiles(x86)%\k-lite codec pack\icaros\ffmpeg license.txt в %ProgramFiles(x86)%\k-lite codec pack\icaros\ffmpeg license.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2wizard\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\a2wizard\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\adobe\reader\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\adobe\reader\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\microsoft shared\dao\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\microsoft shared\dao\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\microsoft\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\microsoft\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\common7\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft visual studio .net 2003\common7\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv в %ALLUSERSPROFILE%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\all_of_your_files_are_encrypted_readme.txt в D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2service\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\a2service\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2scan\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\a2scan\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2cmd\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\a2cmd\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\all_of_your_files_are_encrypted_readme.txt в C:\users\public\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2guard\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\a2guard\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\360tray\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\360tray\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\internet explorer\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\internet explorer\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\k-lite codec pack\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\k-lite codec pack\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\all_of_your_files_are_encrypted_readme.txt в C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\perflogs\admin\all_of_your_files_are_encrypted_readme.txt в C:\perflogs\admin\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • D:\$recycle.bin\all_of_your_files_are_encrypted_readme.txt в D:\$recycle.bin\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %WINDIR%\all_of_your_files_are_encrypted_readme.txt в %WINDIR%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\perflogs\all_of_your_files_are_encrypted_readme.txt в C:\perflogs\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\all_of_your_files_are_encrypted_readme.txt в C:\users\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\recovery\all_of_your_files_are_encrypted_readme.txt в C:\recovery\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\$recycle.bin\all_of_your_files_are_encrypted_readme.txt в C:\$recycle.bin\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\far2\all_of_your_files_are_encrypted_readme.txt в C:\far2\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\totalcmd\all_of_your_files_are_encrypted_readme.txt в C:\totalcmd\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\all_of_your_files_are_encrypted_readme.txt в C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft analysis services\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\adobe\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\google\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\libraries\all_of_your_files_are_encrypted_readme.txt в C:\users\public\libraries\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\application\debug.log в %ProgramFiles(x86)%\google\chrome\application\debug.log.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\services\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\services\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\microsoft shared\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\microsoft shared\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\px storage engine\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\px storage engine\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\adobe\acrobat reader dc\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\readme.htm в %ProgramFiles(x86)%\adobe\acrobat reader dc\readme.htm.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\arm\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\adobe\arm\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ALLUSERSPROFILE%\adobe\setup\all_of_your_files_are_encrypted_readme.txt в %ALLUSERSPROFILE%\adobe\setup\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\desktop\all_of_your_files_are_encrypted_readme.txt в C:\users\public\desktop\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %HOMEPATH%\all_of_your_files_are_encrypted_readme.txt в %HOMEPATH%\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\favorites\all_of_your_files_are_encrypted_readme.txt в C:\users\public\favorites\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\application\visualelementsmanifest.xml в %ProgramFiles(x86)%\google\chrome\application\visualelementsmanifest.xml.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\office10\msostyle.dll в %ProgramFiles(x86)%\microsoft office\office10\msostyle.dll.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\application\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\google\chrome\application\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %CommonProgramFiles(x86)%\adobe\all_of_your_files_are_encrypted_readme.txt в %CommonProgramFiles(x86)%\adobe\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt в C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2start\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\a2start\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\downloads\all_of_your_files_are_encrypted_readme.txt в C:\users\public\downloads\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\office10\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft office\office10\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\public\documents\all_of_your_files_are_encrypted_readme.txt в C:\users\public\documents\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\google\chrome\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft visual studio .net 2003\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft analysis services\as oledb\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • C:\users\default\all_of_your_files_are_encrypted_readme.txt в C:\users\default\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft office\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft office\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles%\a2hijackfree\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles%\a2hijackfree\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\adobe\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\adobe\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\microsoft.net\all_of_your_files_are_encrypted_readme.txt в %ProgramFiles(x86)%\microsoft.net\all_of_your_files_are_encrypted_readme.txt.prplcscd_cvxcv
  • %ProgramFiles(x86)%\mozilla firefox\dependentlibs.list в %ProgramFiles(x86)%\mozilla firefox\dependentlibs.list.prplcscd_cvxcv
Изменяет следующие файлы
  • D:\install.log.prplcscd_cvxcv
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\readme.htm.prplcscd_cvxcv
  • C:\far2\far.map.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\application\visualelementsmanifest.xml.prplcscd_cvxcv
  • C:\users\public\libraries\recordedtv.library-ms.prplcscd_cvxcv
  • %ProgramFiles(x86)%\google\chrome\application\debug.log.prplcscd_cvxcv
  • C:\totalcmd\no.bar.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\setup.xml.prplcscd_cvxcv
  • C:\far2\farcze.lng.prplcscd_cvxcv
  • C:\totalcmd\keyboard.txt.prplcscd_cvxcv
  • C:\totalcmd\history.txt.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.msi.prplcscd_cvxcv
  • C:\far2\clearpluginscache.cmd.prplcscd_cvxcv
  • C:\totalcmd\descript.ion.prplcscd_cvxcv
  • C:\totalcmd\default.bar.prplcscd_cvxcv
  • C:\far2\changelog_eng.prplcscd_cvxcv
  • C:\far2\changelog.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.xml.prplcscd_cvxcv
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proofing.msi.prplcscd_cvxcv
Подменяет следующие файлы
  • %ALLUSERSPROFILE%\all_of_your_files_are_encrypted_readme.txt
  • %ALLUSERSPROFILE%\adobe\all_of_your_files_are_encrypted_readme.txt
Изменяет расширения файлов пользовательских данных (Trojan.Encoder).
Сетевая активность
Подключается к
  • 'ip##pi.com':80
TCP
Запросы HTTP GET
  • http://ip##pi.com/line/?fi############
UDP
  • DNS ASK ip##pi.com

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке