Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Encoder.22525

Добавлен в вирусную базу Dr.Web: 2017-12-05

Описание добавлено:

Technical Information

To ensure autorun and distribution:
Modifies the following registry keys:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'zkBujohS' = '"<LS_APPDATA>\Microsoft\mfEhmvsZ.exe"'
Creates or modifies the following files:
  • %HOMEPATH%\Start Menu\Programs\Startup\zkBujohS.lnk
Infects the following executable files:
  • %CommonProgramFiles%\System\ado\msado27.tlb
  • %CommonProgramFiles%\System\Ole DB\sqloledb.rll
  • %CommonProgramFiles%\System\ado\msado25.tlb
  • %CommonProgramFiles%\System\ado\msado20.tlb
  • %CommonProgramFiles%\System\ado\msado21.tlb
  • %ProgramFiles%\Windows NT\Accessories\mswrd6.wpc
  • %ProgramFiles%\Windows NT\Accessories\write.wpc
  • %ProgramFiles%\Windows NT\Accessories\mswrd8.wpc
  • %CommonProgramFiles%\System\Ole DB\sqlxmlx.rll
  • %CommonProgramFiles%\System\ado\msado26.tlb
  • %CommonProgramFiles%\Microsoft Shared\TextConv\html32.cnv
  • C:\Far2\Plugins\arclite\7zS2con.sfx
  • C:\Far2\Plugins\arclite\7zSD.sfx
  • C:\Far2\Plugins\arclite\7zS2.sfx
  • C:\Far2\Plugins\arclite\7z.sfx
  • C:\Far2\Plugins\arclite\7zCon.sfx
  • %CommonProgramFiles%\Microsoft Shared\TextConv\mswrd832.cnv
  • %CommonProgramFiles%\Microsoft Shared\TextConv\mswrd632.wpc
  • %CommonProgramFiles%\Microsoft Shared\TextConv\write32.wpc
  • C:\Far2\Plugins\FTP\lib\ftpDirList.fll
  • C:\Far2\Plugins\FTP\lib\ftpProgress.fll
Malicious functions:
To complicate detection of its presence in the operating system,
deletes volume shadow copies.
Modifies file system:
Creates the following files:
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001119.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001109.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001115.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001110.rbf
  • %CommonProgramFiles%\System\ado\msado27.tlb.new
  • %CommonProgramFiles%\System\ado\msado26.tlb.new
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001120.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001126.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001107.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001123.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001204.msi
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001159.gpd
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001121.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001152.gpd
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001157.cat
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001111.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001112.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001114.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001095.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001108.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001104.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001087.config
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001116.rbf
  • %CommonProgramFiles%\System\ado\msado21.tlb.new
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001118.rbf
  • %CommonProgramFiles%\System\ado\msado25.tlb.new
  • <SYSTEM32>\dllcache\sam.sdf.new
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001117.rbf
  • %CommonProgramFiles%\System\ado\msado20.tlb.new
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001113.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001209.msi
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\RestorePointSize
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.5
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\$WinMgmt.CFG
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001083.config
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.7
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\ComDb.Dat
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.8
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\FS\INDEX.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\_REGISTRY_MACHINE_SOFTWARE
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\FS\MAPPING1.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\_REGISTRY_USER_.DEFAULT
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\_REGISTRY_MACHINE_SECURITY
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\FS\OBJECTS.DATA
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\_REGISTRY_MACHINE_SAM
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\FS\OBJECTS.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.2
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.10
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001205.msi
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001206.msi
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001150.cat
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001122.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001207.msi
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.6
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001208.msi
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.1
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.3
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.9
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.4
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001096.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001124.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001106.rbf
  • C:\Muldrop\dmp_0xffffffff_0x161dc1
  • C:\Muldrop\dmp_0xffffffff_0x16a444
  • C:\Muldrop\dmp_0xffffffff_0x1699e9
  • C:\Muldrop\dmp_0xffffffff_0x15e9eb
  • C:\Muldrop\dmp_0xffffffff_0x163cb6
  • C:\Muldrop\dmp_0xffffffff_0x16325b
  • C:\Muldrop\dmp_0xffffffff_0x161da5
  • C:\Muldrop\dmp_0xffffffff_0x165bef
  • C:\Muldrop\dmp_0xffffffff_0x16516c
  • C:\Muldrop\dmp_0xffffffff_0x170185
  • C:\Muldrop\dmp_0xffffffff_0x17bbf3
  • C:\Muldrop\dmp_0xffffffff_0x164711
  • C:\Muldrop\dmp_0xffffffff_0x17b198
  • C:\Muldrop\dmp_0xffffffff_0x16134a
  • C:\Muldrop\dmp_0xffffffff_0x165194
  • %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\6c335eea-3706-4e0b-a414-0dbe32944fd9
  • %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
  • C:\Muldrop\316dbb4fd95fg271f1191b8404d8bdbe_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_0
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\316caa4ec95ef271e1191a8404c8acad_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • <LS_APPDATA>\Microsoft\mfEhmvsZ.exe
  • %APPDATA%\Microsoft\Protect\CREDHIST
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d9f6c67dd28240b5a5de7fa4b29827e4_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • C:\Muldrop\alBvkpiS.mol_0
  • C:\Muldrop\dmp_0xffffffff_0x15f446
  • C:\Muldrop\dmp_0x298_0x20000
  • C:\Muldrop\dmp_0xffffffff_0x162800
  • C:\Muldrop\dmp_0xffffffff_0x15d528
  • C:\Muldrop\316dbb4fd95fg271f1191b8404d8bdbe_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_1
  • C:\Muldrop\dmp_0x298_0x10000
  • C:\Muldrop\dmp_0x298_0x30000
  • C:\Muldrop\dmp_0xffffffff_0x17f890
  • C:\System Volume Information\tracking.log
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\fifo.log
  • C:\System Volume Information\Chkdsk\Chkdsk20130604131154.log
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\drivetable.txt
  • C:\Muldrop\dmp_0xffffffff_0x1802eb
  • C:\Muldrop\ngEinwtZ.fyf_0
  • %CommonProgramFiles%\SpeechEngines\Microsoft\TTS\1033\sam.sdf.new
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001085.mof
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001084.config
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001094.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001105.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001103.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001086.config
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001093.rbf
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001097.rbf
  • C:\Muldrop\dmp_0xffffffff_0x17ee35
  • C:\Muldrop\dmp_0xffffffff_0x17d97f
  • C:\Muldrop\dmp_0xffffffff_0x17e3da
  • C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_0
  • C:\Muldrop\dmp_0xffffffff_0x168f8e
  • C:\Muldrop\dmp_0xffffffff_0x180d46
  • C:\Muldrop\dmp_0xffffffff_0x182c57
  • C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_3
  • C:\Muldrop\dmp_0xffffffff_0x16f72a
  • C:\Muldrop\dmp_0xffffffff_0x1817a1
  • C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_1
  • C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_2
  • C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_4
  • C:\Muldrop\dmp_0xffffffff_0x1821fc
  • C:\Muldrop\dmp_0xffffffff_0x165bc7
Sets the 'hidden' attribute to the following files:
  • %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\6c335eea-3706-4e0b-a414-0dbe32944fd9!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • %APPDATA%\Microsoft\Protect\CREDHIST!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • C:\System Volume Information\tracking.log
  • %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • %APPDATA%\Microsoft\Protect\CREDHIST
  • %HOMEPATH%\Start Menu\Programs\Startup\zkBujohS.lnk
  • %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
  • %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\6c335eea-3706-4e0b-a414-0dbe32944fd9
Deletes the following files:
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\316caa4ec95ef271e1191a8404c8acad_23ef5514-3059-436f-a4a7-4cefaab20eb1
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d9f6c67dd28240b5a5de7fa4b29827e4_23ef5514-3059-436f-a4a7-4cefaab20eb1
Moves the following files:
  • from %ProgramFiles%\Windows NT\Pinball\SOUND43.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND43.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND8.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND8.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND713.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND713.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND38.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND38.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND563.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND563.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Movie Maker\Shared\news.png to %ProgramFiles%\Movie Maker\Shared\news.png!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND999.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND999.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND54.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND54.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND4.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND4.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND65.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND65.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND42.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND42.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND55.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND55.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND735.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND735.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\ngEinwtZ.fyf_0 to C:\Muldrop\ngEinwtZ.fyf_0!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND57.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND57.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND68.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND68.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND528.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND528.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND560.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND560.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\fifo.log to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\fifo.log!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND9.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND9.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\drivetable.txt to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\drivetable.txt!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\Chkdsk\Chkdsk20130604131154.log to C:\System Volume Information\Chkdsk\Chkdsk20130604131154.log!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND12.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND12.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Accessories\write.wpc to %ProgramFiles%\Windows NT\Accessories\write.wpc!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND5.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND5.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\NetMeeting\TestSnd.wav to %ProgramFiles%\NetMeeting\TestSnd.wav!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND28.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND28.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND35.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND35.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND45.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND45.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND181.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND181.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND19.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND19.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND27.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND27.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND243.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND243.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND25.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND25.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND49.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND49.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows Media Player\Skins\Revert.wmz to %ProgramFiles%\Windows Media Player\Skins\Revert.wmz!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND3.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND3.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND29.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND29.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND50.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND50.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND36.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND36.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND6.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND6.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND1.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND1.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\NetMeeting\netmeet.htm to %ProgramFiles%\NetMeeting\netmeet.htm!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND30.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND30.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND49D.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND49D.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Messenger\xpmsgr.chm to %ProgramFiles%\Messenger\xpmsgr.chm!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND53.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND53.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND58.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND58.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.9 to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.9!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001122.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001122.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.4 to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.4!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.7 to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.7!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows Media Player\Skins\compact.wmz to %ProgramFiles%\Windows Media Player\Skins\compact.wmz!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.6 to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.6!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001123.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001123.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001150.cat to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001150.cat!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001107.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001107.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\MSN\MSNCoreFiles\OOBE\market.mar to %ProgramFiles%\MSN\MSNCoreFiles\OOBE\market.mar!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.2 to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.2!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.10 to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.10!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001111.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001111.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001083.config to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001083.config!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\FS\INDEX.MAP to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\FS\INDEX.MAP!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001103.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001103.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\ComDb.Dat to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\ComDb.Dat!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\FS\OBJECTS.MAP to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\FS\OBJECTS.MAP!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001108.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001108.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001124.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001124.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Accessories\mswrd6.wpc to %ProgramFiles%\Windows NT\Accessories\mswrd6.wpc!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\$WinMgmt.CFG to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\snapshot\Repository\$WinMgmt.CFG!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.8 to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\change.log.8!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\RestorePointSize to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\RestorePointSize!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001113.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001113.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001117.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001117.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001116.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001116.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001118.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001118.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001085.mof to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001085.mof!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001086.config to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001086.config!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND39.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND39.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001084.config to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001084.config!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND7.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND7.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001114.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001114.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\tracking.log to C:\System Volume Information\tracking.log!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001112.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001112.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001087.config to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001087.config!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001106.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001106.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND827.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND827.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001105.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001105.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001121.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001121.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001157.cat to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001157.cat!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001119.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001119.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001120.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001120.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\PINBALL.MID to %ProgramFiles%\Windows NT\Pinball\PINBALL.MID!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001159.gpd to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001159.gpd!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001115.rbf to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001115.rbf!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001152.gpd to C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\A0001152.gpd!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_4 to C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_4!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_3 to C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_3!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x168f8e to C:\Muldrop\dmp_0xffffffff_0x168f8e!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x17ee35 to C:\Muldrop\dmp_0xffffffff_0x17ee35!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x182c57 to C:\Muldrop\dmp_0xffffffff_0x182c57!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x180d46 to C:\Muldrop\dmp_0xffffffff_0x180d46!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x170185 to C:\Muldrop\dmp_0xffffffff_0x170185!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x164711 to C:\Muldrop\dmp_0xffffffff_0x164711!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x16516c to C:\Muldrop\dmp_0xffffffff_0x16516c!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x17f890 to C:\Muldrop\dmp_0xffffffff_0x17f890!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_0 to C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_0!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x17bbf3 to C:\Muldrop\dmp_0xffffffff_0x17bbf3!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x1817a1 to C:\Muldrop\dmp_0xffffffff_0x1817a1!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %APPDATA%\Microsoft\Address Book\%USERNAME%.wab~ to %APPDATA%\Microsoft\Address Book\%USERNAME%.wab~!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_1 to C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_1!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Messenger\online.wav to %ProgramFiles%\Messenger\online.wav!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %APPDATA%\Microsoft\Address Book\%USERNAME%.wab to %APPDATA%\Microsoft\Address Book\%USERNAME%.wab!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x1802eb to C:\Muldrop\dmp_0xffffffff_0x1802eb!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x17e3da to C:\Muldrop\dmp_0xffffffff_0x17e3da!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x1821fc to C:\Muldrop\dmp_0xffffffff_0x1821fc!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x17d97f to C:\Muldrop\dmp_0xffffffff_0x17d97f!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x16f72a to C:\Muldrop\dmp_0xffffffff_0x16f72a!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x165bc7 to C:\Muldrop\dmp_0xffffffff_0x165bc7!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_2 to C:\Muldrop\e9g6d67ee28240c5b5ef7gb4c29827f4_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_2!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0x298_0x10000 to C:\Muldrop\dmp_0x298_0x10000!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0x298_0x30000 to C:\Muldrop\dmp_0x298_0x30000!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\316dbb4fd95fg271f1191b8404d8bdbe_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_1 to C:\Muldrop\316dbb4fd95fg271f1191b8404d8bdbe_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_1!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x15f446 to C:\Muldrop\dmp_0xffffffff_0x15f446!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0x298_0x20000 to C:\Muldrop\dmp_0x298_0x20000!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x15d528 to C:\Muldrop\dmp_0xffffffff_0x15d528!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\6c335eea-3706-4e0b-a414-0dbe32944fd9 to %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\6c335eea-3706-4e0b-a414-0dbe32944fd9!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %APPDATA%\Microsoft\Media Player\0007F0B7.wpl to %APPDATA%\Microsoft\Media Player\0007F0B7.wpl!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %APPDATA%\Microsoft\Protect\CREDHIST to %APPDATA%\Microsoft\Protect\CREDHIST!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\alBvkpiS.mol_0 to C:\Muldrop\alBvkpiS.mol_0!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\316dbb4fd95fg271f1191b8404d8bdbe_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_0 to C:\Muldrop\316dbb4fd95fg271f1191b8404d8bdbe_23fg5514-3059-436g-b4b7-4dfgbbc20fc1_0!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred to %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x165bef to C:\Muldrop\dmp_0xffffffff_0x165bef!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x1699e9 to C:\Muldrop\dmp_0xffffffff_0x1699e9!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x16a444 to C:\Muldrop\dmp_0xffffffff_0x16a444!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x165194 to C:\Muldrop\dmp_0xffffffff_0x165194!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x17b198 to C:\Muldrop\dmp_0xffffffff_0x17b198!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x16134a to C:\Muldrop\dmp_0xffffffff_0x16134a!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x16325b to C:\Muldrop\dmp_0xffffffff_0x16325b!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x163cb6 to C:\Muldrop\dmp_0xffffffff_0x163cb6!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x162800 to C:\Muldrop\dmp_0xffffffff_0x162800!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x161dc1 to C:\Muldrop\dmp_0xffffffff_0x161dc1!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x15e9eb to C:\Muldrop\dmp_0xffffffff_0x15e9eb!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from C:\Muldrop\dmp_0xffffffff_0x161da5 to C:\Muldrop\dmp_0xffffffff_0x161da5!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND131.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND131.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND104.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND104.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND112.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND112.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Movie Maker\Shared\Sample2.jpg to %ProgramFiles%\Movie Maker\Shared\Sample2.jpg!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND105.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND105.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\PINBALL2.MID to %ProgramFiles%\Windows NT\Pinball\PINBALL2.MID!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml to %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows Media Player\npds.zip to %ProgramFiles%\Windows Media Player\npds.zip!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND108.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND108.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND13.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND13.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Movie Maker\Shared\paint.png to %ProgramFiles%\Movie Maker\Shared\paint.png!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND16.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND16.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND240.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND240.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND34.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND34.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND136.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND136.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND14.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND14.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND24.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND24.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND22.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND22.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Movie Maker\Shared\Sample1.jpg to %ProgramFiles%\Movie Maker\Shared\Sample1.jpg!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND18.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND18.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND17.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND17.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND26.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND26.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND20.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND20.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND21.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND21.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets to %ProgramFiles%\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Messenger\lvback.gif to %ProgramFiles%\Messenger\lvback.gif!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Microsoft.NET\RedistList\AssemblyList_4_client.xml to %ProgramFiles%\Microsoft.NET\RedistList\AssemblyList_4_client.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Movie Maker\Shared\Empty.txt to %ProgramFiles%\Movie Maker\Shared\Empty.txt!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets to %ProgramFiles%\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets to %ProgramFiles%\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Messenger\newemail.wav to %ProgramFiles%\Messenger\newemail.wav!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Movie Maker\Shared\Filters.xml to %ProgramFiles%\Movie Maker\Shared\Filters.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Messenger\newalert.wav to %ProgramFiles%\Messenger\newalert.wav!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Messenger\logowin.gif to %ProgramFiles%\Messenger\logowin.gif!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets to %ProgramFiles%\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Microsoft.NET\RedistList\AssemblyList_4_extended.xml to %ProgramFiles%\Microsoft.NET\RedistList\AssemblyList_4_extended.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml to %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml to %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\Client.xml to %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\Client.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\SOUND111.WAV to %ProgramFiles%\Windows NT\Pinball\SOUND111.WAV!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows NT\Pinball\FONT.DAT to %ProgramFiles%\Windows NT\Pinball\FONT.DAT!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\NetMeeting\Blip.wav to %ProgramFiles%\NetMeeting\Blip.wav!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\MSN\MSNCoreFiles\Install\xfp.xml to %ProgramFiles%\MSN\MSNCoreFiles\Install\xfp.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Messenger\type.wav to %ProgramFiles%\Messenger\type.wav!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Movie Maker\Shared\Profiles\Blank.txt to %ProgramFiles%\Movie Maker\Shared\Profiles\Blank.txt!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\Client.xml to %ProgramFiles%\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\Client.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\Windows Media Player\npdrmv2.zip to %ProgramFiles%\Windows Media Player\npdrmv2.zip!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
  • from %ProgramFiles%\MSN\MSNCoreFiles\Install\cinfo.xml to %ProgramFiles%\MSN\MSNCoreFiles\Install\cinfo.xml!________GEKTORg@PROTONMAIL.COM________.GEXOGEN
Substitutes the following files:
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\d9f6c67dd28240b5a5de7fa4b29827e4_23ef5514-3059-436f-a4a7-4cefaab20eb1
Modifies user data files (Trojan.Encoder).

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке