Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Encoder.29624

Добавлен в вирусную базу Dr.Web: 2019-09-24

Описание добавлено:

Technical Information

To ensure autorun and distribution
Creates the following files on removable media
  • <Drive name for removable media>:\correct.avi
  • <Drive name for removable media>:\!!! all your files are encrypted !!!.txt
  • <Drive name for removable media>:\join.avi
  • <Drive name for removable media>:\000814251_video_01.avi
  • <Drive name for removable media>:\toolbar.bmp
  • <Drive name for removable media>:\coffee.bmp
  • <Drive name for removable media>:\contoso_1.cer
  • <Drive name for removable media>:\pmd.cer
  • <Drive name for removable media>:\testcertificate.cer
  • <Drive name for removable media>:\contoso.cer
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer
  • <Drive name for removable media>:\gruenspecht_02172016.pptx
  • <Drive name for removable media>:\samieee_obiee_presentation.pptx
  • <Drive name for removable media>:\indogerman2010.pptx
  • <Drive name for removable media>:\roozenedowebinar.pptx
Malicious functions
To complicate detection of its presence in the operating system,
deletes volume shadow copies.
Reads files which store third party applications passwords
  • %HOMEPATH%\desktop\210252809.jpeg
  • %HOMEPATH%\desktop\testee.cer
  • %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
  • %HOMEPATH%\desktop\sdkfailsafeemulator.cer
  • %HOMEPATH%\desktop\region-north-karelia.jpeg
  • %HOMEPATH%\desktop\pushkin.jpg
  • %HOMEPATH%\desktop\nwfieldnotes1966.docx
  • %HOMEPATH%\desktop\join.avi
  • %HOMEPATH%\desktop\howto-index.html
  • %HOMEPATH%\desktop\holycrosschurchinstructions.docx
  • %HOMEPATH%\desktop\hanni_umami_chapter.doc
  • %HOMEPATH%\desktop\garden.htm
  • %HOMEPATH%\desktop\tileimage.bmp
  • %HOMEPATH%\desktop\dashborder_120.bmp
  • %HOMEPATH%\desktop\contoso_1.cer
  • %HOMEPATH%\desktop\coffee.bmp
  • %HOMEPATH%\desktop\applicantform_en.doc
  • %HOMEPATH%\desktop\api-hashmap.html
  • %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
  • %HOMEPATH%\desktop\alert.html
  • %HOMEPATH%\desktop\adhd_and_obesity.docx
  • %HOMEPATH%\desktop\adadsi.html
  • %HOMEPATH%\desktop\about.html
  • %HOMEPATH%\desktop\4f0bf7ff71f28.jpeg
  • %HOMEPATH%\desktop\3.jpg
  • %HOMEPATH%\desktop\cveuropeo.doc
  • %HOMEPATH%\desktop\tree_view.htm
Modifies file system
Creates the following files
  • C:\documents and settings\default user\cookies\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\mt\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ms\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\mr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\mo\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ml\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\mk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\lv\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\lt\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ku\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ko\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\kn\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\kk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\kab\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ka\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\es\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\jv\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\it\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\is\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\id\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\hu\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\hr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\hi\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\he\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\gu\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\gl\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\fy\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\fr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\fi\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\fa\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\eu\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ja\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\et\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\my\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ta\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\th\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\tr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\tw\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ug\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\uk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ur\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\vi\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\backends\win32\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\wae\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\zh_cn\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\zh_hk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\zh_tw\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\winboot\!!! all your files are encrypted !!!.txt
  • %TEMP%\temporary directory 1 for omni.ja_20150820125829.zip\chrome\en-gb\locale\branding\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ne\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\nb\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sv\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sr\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sq\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sl\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\sk\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\shn\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ru\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ro\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\pt_br\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\pt\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\pl\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\oc\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\nn\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\nl\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\te\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\eo\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\en_gb\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\en_ca\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\encodings\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\ctypes\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\util\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\publickey\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\hash\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\cipher\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\crypto\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\bittorrent\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\data\images\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\data\custom-installation\hooks\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\data\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\!!! all your files are encrypted !!!.txt
  • %TEMP%\history\history.ie5\!!! all your files are encrypted !!!.txt
  • %TEMP%\2.9.0.1467 (partner)\chrome\en-gb\locale\browser-region\!!! all your files are encrypted !!!.txt
  • %TEMP%\2.9.0.1467 (partner)\chrome\en-gb\locale\branding\!!! all your files are encrypted !!!.txt
  • %TEMP%\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\local settings\history\history.ie5\mshist012017042620170427\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\favorites\links\яндекс.url
  • %HOMEPATH%\favorites\links\почта.url
  • %HOMEPATH%\favorites\links\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\favorites\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\desktop\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\cookies\!!! all your files are encrypted !!!.txt
  • %HOMEPATH%\!!! all your files are encrypted !!!.txt
  • C:\documents and settings\default user\templates\!!! all your files are encrypted !!!.txt
  • C:\documents and settings\default user\local settings\<INETFILES>\content.ie5\!!! all your files are encrypted !!!.txt
  • C:\documents and settings\default user\local settings\history\history.ie5\!!! all your files are encrypted !!!.txt
  • %TEMP%\cookies\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\sap\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\logging\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\sap\msg\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\en_au\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\as\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\en\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\el\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\de\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\da\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\cy\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\csb\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\cs\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\crh\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ca\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\bs\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\br\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\bo\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\bg\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ast\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\ar\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\sap\pkt\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\af\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\xml\sax\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\xml\parsers\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\xml\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\frontends\win32\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\frontends\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\translations\uz\lc_messages\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\backends\common\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\backends\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\wubi\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\winui\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\urlgrabber\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\sets\!!! all your files are encrypted !!!.txt
  • %TEMP%\pyl1.tmp\lib\openpgp\sap\util\!!! all your files are encrypted !!!.txt
  • %TEMP%\temporary directory 2 for omni.ja_20150820125829.zip\chrome\en-gb\locale\browser-region\!!! all your files are encrypted !!!.txt
  • %TEMP%\<INETFILES>\content.ie5\!!! all your files are encrypted !!!.txt
Moves the following files
  • from %HOMEPATH%\favorites\links\почта.url to %HOMEPATH%\favorites\links\почта.url.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\tl.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\tl.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\tr.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\tr.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\trash.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\trash.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnoffnotificationinacrobat.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnoffnotificationinacrobat.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnoffnotificationintray.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnoffnotificationintray.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnonnotificationinacrobat.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnonnotificationinacrobat.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_joined.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_joined.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnonnotificationintray.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\turnonnotificationintray.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\adobepistd.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\adobepistd.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-bold.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-bold.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-boldoblique.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-boldoblique.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-oblique.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd-oblique.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\courierstd.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-bold.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-bold.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\stop_collection_data.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\stop_collection_data.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\submission_history.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\submission_history.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_ok.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_ok.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_lg.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_lg.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_issue.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\server_issue.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_super.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_super.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\form_responses.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\form_responses.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\info.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\info.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\main.css to %ProgramFiles%\adobe\reader 10.0\reader\tracker\main.css.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\open_original_form.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\open_original_form.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\pdf.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\pdf.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-boldit.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-boldit.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\warning.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\warning.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviewers.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviewers.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_super.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_super.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_browser.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_browser.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_email.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_email.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_same_reviewers.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_same_reviewers.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_shared.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\review_shared.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\rss.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\rss.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_received.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_received.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_sent.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\reviews_sent.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-it.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-it.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-regular.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\minionpro-regular.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-bold.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-bold.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can.hyp to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can.hyp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can03.ths to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can03.ths.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can129.hsp to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can129.hsp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can32.clx to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can32.clx.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\eng.hyp to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\eng.hyp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\eng32.clx to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\eng32.clx.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\engphon.env to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\engphon.env.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa03.hsp to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa03.hsp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_distributed.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\forms_distributed.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa03.ths to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa03.ths.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa37.hyp to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa37.hyp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\saslprep\saslprepprofile_norm_bidi.spp to %ProgramFiles%\adobe\reader 10.0\resource\saslprep\saslprepprofile_norm_bidi.spp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\icu\icudt26l.dat to %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\icu\icudt26l.dat.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\symbol.txt to %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\symbol.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\zdingbat.txt to %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\zdingbat.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\centeuro.txt to %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\centeuro.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can.fca to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\can.fca.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\zy______.pfm to %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\zy______.pfm.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt55.ths to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt55.ths.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\zx______.pfm to %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\zx______.pfm.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-boldit.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-boldit.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-it.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-it.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-regular.otf to %ProgramFiles%\adobe\reader 10.0\resource\font\myriadpro-regular.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\sy______.pfb to %ProgramFiles%\adobe\reader 10.0\resource\font\sy______.pfb.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\zx______.pfb to %ProgramFiles%\adobe\reader 10.0\resource\font\zx______.pfb.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\zy______.pfb to %ProgramFiles%\adobe\reader 10.0\resource\font\zy______.pfb.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\sy______.pfm to %ProgramFiles%\adobe\reader 10.0\resource\font\pfm\sy______.pfm.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\corpchar.txt to %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\corpchar.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt04.hsp to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt04.hsp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_ca.txt to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_ca.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb.txt to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb_euro.txt to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb_euro.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us.txt to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us_posix.txt to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us_posix.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt.fca to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt.fca.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt.hyp to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt.hyp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt32.clx to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\brt32.clx.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa.fca to %ProgramFiles%\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\usa.fca.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\end_review.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\end_review.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\services\dexshare.spi to %ProgramFiles%\adobe\reader 10.0\reader\services\dexshare.spi.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\acrobat.com\meta-inf\air\hash to %ProgramFiles%\adobe\acrobat.com\meta-inf\air\hash.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\acrobat.com\meta-inf\air\publisherid to %ProgramFiles%\adobe\acrobat.com\meta-inf\air\publisherid.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\adobe.reader.dependencies.manifest to %ProgramFiles%\adobe\reader 10.0\reader\adobe.reader.dependencies.manifest.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\agmgpuoptin.ini to %ProgramFiles%\adobe\reader 10.0\reader\agmgpuoptin.ini.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\cryptocme2.sig to %ProgramFiles%\adobe\reader 10.0\reader\cryptocme2.sig.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\rtc.der to %ProgramFiles%\adobe\reader 10.0\reader\rtc.der.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_dotnetfx45_full_setup_decompression_log.txt to %TEMP%\dd_dotnetfx45_full_setup_decompression_log.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\javascripts\jsbytecodewin.bin to %ProgramFiles%\adobe\reader 10.0\reader\javascripts\jsbytecodewin.bin.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\accessibility.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\accessibility.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acrosign.prc to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acrosign.prc.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\annots.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\annots.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\checkers.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\checkers.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\digsig.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\digsig.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\acrobat.com\meta-inf\signatures.xml to %ProgramFiles%\adobe\acrobat.com\meta-inf\signatures.xml.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\acrobat.com\meta-inf\air\application.xml to %ProgramFiles%\adobe\acrobat.com\meta-inf\air\application.xml.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\acrobat.com\bin-debug\appcontainer.swf to %ProgramFiles%\adobe\acrobat.com\bin-debug\appcontainer.swf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\acrobat.com\version.xml to %ProgramFiles%\adobe\acrobat.com\version.xml.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\acrobat.com\mimetype to %ProgramFiles%\adobe\acrobat.com\mimetype.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\aucheck_parser.txt to %TEMP%\aucheck_parser.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_clwireg.txt to %TEMP%\dd_clwireg.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_depcheck_netfx20_exp_35.txt to %TEMP%\dd_depcheck_netfx20_exp_35.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_depcheck_netfx_exp_35.txt to %TEMP%\dd_depcheck_netfx_exp_35.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_dotnetfx20install.txt to %TEMP%\dd_dotnetfx20install.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_dotnetfx35install.txt to %TEMP%\dd_dotnetfx35install.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\dva.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\dva.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\legal\enu\eula.ini to %ProgramFiles%\adobe\reader 10.0\reader\legal\enu\eula.ini.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_dotnetfx40_full_x86_x64_decompression_log.txt to %TEMP%\dd_dotnetfx40_full_x86_x64_decompression_log.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_net_framework20_setup74f9.txt to %TEMP%\dd_net_framework20_setup74f9.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_net_framework30_setup7762.txt to %TEMP%\dd_net_framework30_setup7762.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_net_framework35_msi77c4.txt to %TEMP%\dd_net_framework35_msi77c4.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_wcf_retca4a2a.txt to %TEMP%\dd_wcf_retca4a2a.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_xps.txt to %TEMP%\dd_xps.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\uxeventlog.txt to %TEMP%\uxeventlog.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %HOMEPATH%\favorites\links\яндекс.url to %HOMEPATH%\favorites\links\яндекс.url.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %TEMP%\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt to %TEMP%\dd_ndp452-kb2901907-x86-x64-allos-enu_decompression_log.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ebook.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ebook.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\escript.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\escript.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ia32.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ia32.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\2d.x3d to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\2d.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\3difr.x3d to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\3difr.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\drvdx9.x3d to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\drvdx9.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\drvsoft.x3d to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\drvsoft.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\prcr.x3d to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\prcr.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\tesselate.x3d to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\tesselate.x3d.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\prc\myriadcad.otf to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins3d\prc\myriadcad.otf.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\services\services.cfg to %ProgramFiles%\adobe\reader 10.0\reader\services\services.cfg.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\ended_review_or_form.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\ended_review_or_form.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\spplugins\admplugin.apl to %ProgramFiles%\adobe\reader 10.0\reader\spplugins\admplugin.apl.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\add_reviewer.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\add_reviewer.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\bl.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\bl.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\br.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\br.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\create_form.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\create_form.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\distribute_form.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\distribute_form.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\email_all.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\email_all.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\windowsmedia.mpp to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\windowsmedia.mpp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\sendmail.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\sendmail.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\quicktime.mpp to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\quicktime.mpp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\search.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\search.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\makeaccessible.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\makeaccessible.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\pddom.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\pddom.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ppklite.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\ppklite.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\readoutloud.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\readoutloud.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\reflow.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\reflow.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\saveasrtf.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\saveasrtf.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\tracker\email_initiator.gif to %ProgramFiles%\adobe\reader 10.0\reader\tracker\email_initiator.gif.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\flash.mpp to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\flash.mpp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\spelling.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\spelling.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\updater.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\updater.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\weblink.api to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\weblink.api.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\adobepdf.xdc to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\adobepdf.xdc.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\adobepdf417.pmp to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\adobepdf417.pmp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\datamatrix.pmp to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\datamatrix.pmp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\qrcode.pmp to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\acroform\pmp\qrcode.pmp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\mcimpp.mpp to %ProgramFiles%\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\mcimpp.mpp.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
  • from %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\croatian.txt to %ProgramFiles%\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\croatian.txt.[44844a35-42c0-cfb4-6d9e-a990a42ea2e7]
Modifies user data files (Trojan.Encoder).
Changes user data files extensions (Trojan.Encoder).
Network activity
UDP
  • DNS ASK ge###tool.com
  • DNS ASK ip##gger.ru
Miscellaneous
Creates and executes the following
  • '<SYSTEM32>\cmd.exe' /C bcdedit /set {default} bootstatuspolicy ignoreallfailures' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log System' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log Security' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log Application' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C del "%userprofile%\documents\Default.rdp"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C attrib "%userprofile%\documents\Default.rdp" -s -h' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C vssadmin delete shadows /all /quiet' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C wmic shadowcopy delete' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete backup' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete systemstatebackup -keepversions:0' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete systemstatebackup' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete catalog -quiet' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C bcdedit /set {default} recoveryenabled no' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C sc config eventlog start=disabled' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /C chcp 1250 && net view' (with hidden window)
Executes the following
  • '<SYSTEM32>\cmd.exe' /C bcdedit /set {default} bootstatuspolicy ignoreallfailures
  • '<SYSTEM32>\cmd.exe' /C chcp 1250 && net view
  • '<SYSTEM32>\sc.exe' config eventlog start=disabled
  • '<SYSTEM32>\cmd.exe' /C sc config eventlog start=disabled
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log System
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log Security
  • '<SYSTEM32>\cmd.exe' /C wevtutil.exe clear-log Application
  • '<SYSTEM32>\cmd.exe' /C del "%userprofile%\documents\Default.rdp"
  • '<SYSTEM32>\attrib.exe' "%HOMEPATH%\documents\Default.rdp" -s -h
  • '<SYSTEM32>\cmd.exe' /C attrib "%userprofile%\documents\Default.rdp" -s -h
  • '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"
  • '<SYSTEM32>\chcp.com' 1250
  • '<SYSTEM32>\cmd.exe' /C reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"
  • '<SYSTEM32>\cmd.exe' /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f
  • '<SYSTEM32>\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f
  • '<SYSTEM32>\cmd.exe' /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f
  • '<SYSTEM32>\cmd.exe' /C vssadmin delete shadows /all /quiet
  • '<SYSTEM32>\cmd.exe' /C wmic shadowcopy delete
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete backup
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete systemstatebackup -keepversions:0
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete systemstatebackup
  • '<SYSTEM32>\cmd.exe' /C wbadmin delete catalog -quiet
  • '<SYSTEM32>\cmd.exe' /C bcdedit /set {default} recoveryenabled no
  • '<SYSTEM32>\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f
  • '<SYSTEM32>\net.exe' view

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке