Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Encoder.28123

Добавлен в вирусную базу Dr.Web: 2019-05-15

Описание добавлено:

Technical Information

Modifies file system
Creates the following files
  • C:\xfsdeyxx-manual.txt
  • C:\users\public\pictures\sample pictures\xfsdeyxx-manual.txt
  • C:\users\public\music\sample music\xfsdeyxx-manual.txt
  • C:\users\public\libraries\xfsdeyxx-manual.txt
  • C:\users\public\favorites\xfsdeyxx-manual.txt
  • C:\users\public\downloads\xfsdeyxx-manual.txt
  • C:\users\public\documents\my videos\xfsdeyxx-manual.txt
  • C:\users\public\documents\my pictures\xfsdeyxx-manual.txt
  • C:\users\public\documents\my music\xfsdeyxx-manual.txt
  • C:\users\public\documents\xfsdeyxx-manual.txt
  • C:\users\public\desktop\xfsdeyxx-manual.txt
  • C:\users\public\xfsdeyxx-manual.txt
  • C:\users\default\templates\xfsdeyxx-manual.txt
  • C:\users\default\start menu\xfsdeyxx-manual.txt
  • C:\users\default\saved games\xfsdeyxx-manual.txt
  • C:\users\public\recorded tv\sample media\xfsdeyxx-manual.txt
  • C:\users\default\recent\xfsdeyxx-manual.txt
  • C:\users\default\printhood\xfsdeyxx-manual.txt
  • C:\users\default\nethood\xfsdeyxx-manual.txt
  • C:\users\default\links\xfsdeyxx-manual.txt
  • C:\users\default\favorites\xfsdeyxx-manual.txt
  • C:\users\default\downloads\xfsdeyxx-manual.txt
  • C:\users\default\documents\my videos\xfsdeyxx-manual.txt
  • C:\users\default\documents\my pictures\xfsdeyxx-manual.txt
  • C:\users\default\documents\my music\xfsdeyxx-manual.txt
  • C:\users\default\documents\xfsdeyxx-manual.txt
  • C:\users\default\desktop\xfsdeyxx-manual.txt
  • C:\users\default\cookies\xfsdeyxx-manual.txt
  • C:\users\default\sendto\xfsdeyxx-manual.txt
  • %ProgramFiles%\microsoft sql server compact edition\v3.5\xfsdeyxx-manual.txt
  • C:\users\public\videos\sample videos\xfsdeyxx-manual.txt
  • %APPDATA%\icqm\icq\dll\xfsdeyxx-manual.txt
  • %APPDATA%\icqm\icq\database\xfsdeyxx-manual.txt
  • %APPDATA%\icqm\icq\xfsdeyxx-manual.txt
  • %APPDATA%\icqm\xfsdeyxx-manual.txt
  • %APPDATA%\icq-profile\update\splash_banner\xfsdeyxx-manual.txt
  • %APPDATA%\icq-profile\update\xfsdeyxx-manual.txt
  • %APPDATA%\icq-profile\base\xfsdeyxx-manual.txt
  • %APPDATA%\icq-profile\xfsdeyxx-manual.txt
  • %APPDATA%\ghisler\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\logtransport2\logs\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\logtransport2\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\linguistics\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\headlights\xfsdeyxx-manual.txt
  • C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\xfsdeyxx-manual.txt
  • C:\users\public\recorded tv\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\flash player\assetcache\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\flash player\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\acrobat\dc\security\crlcache\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\acrobat\dc\security\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\acrobat\dc\preferences\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\acrobat\dc\jscache\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\acrobat\dc\forms\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\acrobat\dc\collab\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\acrobat\dc\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\acrobat\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\xfsdeyxx-manual.txt
  • %APPDATA%\xfsdeyxx-manual.txt
  • %HOMEPATH%\appdata\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\flash player\assetcache\reehzff2\xfsdeyxx-manual.txt
  • %HOMEPATH%\xfsdeyxx-manual.txt
  • C:\users\default\appdata\roaming\microsoft\internet explorer\xfsdeyxx-manual.txt
  • C:\users\default\appdata\roaming\microsoft\xfsdeyxx-manual.txt
  • C:\users\default\appdata\roaming\media center programs\xfsdeyxx-manual.txt
  • C:\far2\documentation\xfsdeyxx-manual.txt
  • C:\far2\plugins\editcase\xfsdeyxx-manual.txt
  • C:\far2\plugins\drawline\xfsdeyxx-manual.txt
  • C:\far2\plugins\compare\xfsdeyxx-manual.txt
  • C:\far2\plugins\brackets\xfsdeyxx-manual.txt
  • C:\far2\plugins\autowrap\xfsdeyxx-manual.txt
  • C:\far2\plugins\arclite\xfsdeyxx-manual.txt
  • C:\far2\plugins\align\xfsdeyxx-manual.txt
  • C:\far2\plugins\xfsdeyxx-manual.txt
  • C:\far2\fexcept\xfsdeyxx-manual.txt
  • C:\far2\encyclopedia\tap\xfsdeyxx-manual.txt
  • C:\far2\encyclopedia\xfsdeyxx-manual.txt
  • C:\far2\documentation\rus\xfsdeyxx-manual.txt
  • %APPDATA%\icqm\icq\fonts\xfsdeyxx-manual.txt
  • C:\far2\plugins\farcmds\xfsdeyxx-manual.txt
  • C:\far2\addons\xlat\russian\xfsdeyxx-manual.txt
  • C:\far2\addons\xlat\xfsdeyxx-manual.txt
  • C:\far2\addons\shell\xfsdeyxx-manual.txt
  • C:\far2\addons\setup\xfsdeyxx-manual.txt
  • C:\far2\addons\macros\xfsdeyxx-manual.txt
  • C:\far2\addons\colors\default_highlighting\xfsdeyxx-manual.txt
  • C:\far2\addons\colors\custom_highlighting\xfsdeyxx-manual.txt
  • C:\far2\addons\colors\xfsdeyxx-manual.txt
  • C:\far2\addons\xfsdeyxx-manual.txt
  • C:\far2\xfsdeyxx-manual.txt
  • C:\documents and settings\xfsdeyxx-manual.txt
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\xfsdeyxx-manual.txt
  • C:\$recycle.bin\xfsdeyxx-manual.txt
  • C:\far2\documentation\eng\xfsdeyxx-manual.txt
  • %APPDATA%\adobe\flash player\nativecache\xfsdeyxx-manual.txt
  • C:\far2\plugins\filecase\xfsdeyxx-manual.txt
  • C:\far2\plugins\hlfviewer\xfsdeyxx-manual.txt
  • C:\far2\plugins\ftp\xfsdeyxx-manual.txt
  • C:\users\default\appdata\roaming\xfsdeyxx-manual.txt
  • C:\users\default\appdata\local\<INETFILES>\xfsdeyxx-manual.txt
  • C:\users\default\appdata\local\temp\xfsdeyxx-manual.txt
  • C:\users\default\appdata\local\microsoft\xfsdeyxx-manual.txt
  • C:\users\default\appdata\local\history\xfsdeyxx-manual.txt
  • C:\users\default\appdata\local\xfsdeyxx-manual.txt
  • C:\users\default\appdata\xfsdeyxx-manual.txt
  • C:\users\default\xfsdeyxx-manual.txt
  • C:\totalcmd\language\xfsdeyxx-manual.txt
  • C:\totalcmd\xfsdeyxx-manual.txt
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\xfsdeyxx-manual.txt
  • C:\recovery\xfsdeyxx-manual.txt
  • C:\far2\plugins\ftp\lib\xfsdeyxx-manual.txt
  • %ProgramFiles(x86)%\xfsdeyxx-manual.txt
  • C:\far2\plugins\emenu\xfsdeyxx-manual.txt
  • %ProgramFiles%\microsoft sql server compact edition\xfsdeyxx-manual.txt
  • %ProgramFiles%\xfsdeyxx-manual.txt
  • C:\perflogs\admin\xfsdeyxx-manual.txt
  • C:\perflogs\xfsdeyxx-manual.txt
  • C:\msocache\xfsdeyxx-manual.txt
  • C:\far2\pluginsdk\headers.pas\xfsdeyxx-manual.txt
  • C:\far2\pluginsdk\headers.c\xfsdeyxx-manual.txt
  • C:\far2\pluginsdk\xfsdeyxx-manual.txt
  • C:\far2\plugins\tmppanel\xfsdeyxx-manual.txt
  • C:\far2\plugins\proclist\xfsdeyxx-manual.txt
  • C:\far2\plugins\network\xfsdeyxx-manual.txt
  • C:\far2\plugins\macroview\xfsdeyxx-manual.txt
  • %ProgramFiles%\microsoft sql server compact edition\v3.5\desktop\xfsdeyxx-manual.txt
  • %APPDATA%\icqm\icq\graphics\xfsdeyxx-manual.txt
Moves the following files
  • from %APPDATA%\adobe\acrobat\dc\jscache\globdata to %APPDATA%\adobe\acrobat\dc\jscache\globdata.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_ru.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_ru.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_tr.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_tr.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_ua.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_ua.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_uz.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_uz.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\skin.txt to %APPDATA%\icqm\icq\smiles\skin.txt.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\car.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\car.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_kz.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_kz.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_pt.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_pt.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\cat.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\cat.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\drink.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\drink.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\flowers.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\flowers.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\hug.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\hug.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\joy.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\joy.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\love.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\love.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\mad.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\mad.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\cookie.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\cookie.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\doll.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\doll.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_en.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_en.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_cz.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_cz.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\perfume.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\perfume.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\mad dog.swf to %APPDATA%\icqm\icq\smiles\flash\mad dog.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\missyou.swf to %APPDATA%\icqm\icq\smiles\flash\missyou.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf to %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\rosy.swf to %APPDATA%\icqm\icq\smiles\flash\rosy.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\serdze.swf to %APPDATA%\icqm\icq\smiles\flash\serdze.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\skratch.swf to %APPDATA%\icqm\icq\smiles\flash\skratch.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\smeh.swf to %APPDATA%\icqm\icq\smiles\flash\smeh.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\sobaka.swf to %APPDATA%\icqm\icq\smiles\flash\sobaka.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf to %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\sorry.swf to %APPDATA%\icqm\icq\smiles\flash\sorry.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\tank.swf to %APPDATA%\icqm\icq\smiles\flash\tank.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\wf_love_sdaus.swf to %APPDATA%\icqm\icq\smiles\flash\wf_love_sdaus.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf to %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf to %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_bg.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_bg.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\new_dress.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\new_dress.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_kiss.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_kiss.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_de.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_de.xml.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\chillout.swf to %APPDATA%\icqm\icq\smiles\flash\chillout.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\ring.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\ring.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\love.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\love.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\pistolet.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\pistolet.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\poison.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\poison.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\rainbow.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\rainbow.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\red.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\red.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\sad.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sad.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\sing.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sing.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\skuka.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\skuka.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\sleep.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sleep.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\smile.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\smile.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\tongue.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\tongue.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\victory.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\victory.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\wonder.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\wonder.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_attack.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_attack.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_hand.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_hand.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_lick.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_lick.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_meow.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_meow.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\kiss.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\kiss.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_rose.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_rose.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\gift.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gift.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\sunburn.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\sunburn.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\angel.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\angel.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\appl.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\appl.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\beauty.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\beauty.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\beer.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\beer.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\blew.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\blew.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\book.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\book.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\could.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\could.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\cry.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\cry.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\dance.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\dance.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\devil.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\devil.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\eat.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\eat.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\fight.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\fight.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\fingal.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\fingal.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\flowr.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\flowr.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\gg.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gg.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\gg2.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gg2.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\history.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\history.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\shoes.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\shoes.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\likeu.swf to %APPDATA%\icqm\icq\smiles\flash\likeu.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\laugh.swf to %APPDATA%\icqm\icq\smiles\flash\laugh.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\krizis.swf to %APPDATA%\icqm\icq\smiles\flash\krizis.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\fonts\segoesc.ttf to %APPDATA%\icqm\icq\fonts\segoesc.ttf.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\agent_offline.bmp to %APPDATA%\icqm\icq\graphics\phone\agent_offline.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\agent_offline_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\agent_offline_inv.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\agent_online.bmp to %APPDATA%\icqm\icq\graphics\phone\agent_online.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\agent_online_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\agent_online_inv.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\icq_offline.bmp to %APPDATA%\icqm\icq\graphics\phone\icq_offline.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\icq_offline_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\icq_offline_inv.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\icq_online.bmp to %APPDATA%\icqm\icq\graphics\phone\icq_online.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\icq_online_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\icq_online_inv.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\phone.bmp to %APPDATA%\icqm\icq\graphics\phone\phone.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\phone_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\phone_inv.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\screen-busy-mouse.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-busy-mouse.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\screen-busy.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-busy.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\screen-decline-mouse.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-decline-mouse.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\screen-decline.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-decline.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\database\citylist_ua.csv to %APPDATA%\icqm\icq\database\citylist_ua.csv.xfsdeyxx
  • from %APPDATA%\icqm\icq\database\citylist_ru.csv to %APPDATA%\icqm\icq\database\citylist_ru.csv.xfsdeyxx
  • from %APPDATA%\icqm\icq\dll\altergeo.msi to %APPDATA%\icqm\icq\dll\altergeo.msi.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_mouse.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_mouse.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\screen-offline-inv.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-offline-inv.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\database\citylist_kz.csv to %APPDATA%\icqm\icq\database\citylist_kz.csv.xfsdeyxx
  • from %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat to %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat.xfsdeyxx
  • from %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata to %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata.xfsdeyxx
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl.xfsdeyxx
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl.xfsdeyxx
  • from %APPDATA%\adobe\acrobat\dc\tmdocs.sav to %APPDATA%\adobe\acrobat\dc\tmdocs.sav.xfsdeyxx
  • from %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav to %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav.xfsdeyxx
  • from %APPDATA%\adobe\logtransport2\logtransport2.cfg to %APPDATA%\adobe\logtransport2\logtransport2.cfg.xfsdeyxx
  • from %APPDATA%\adobe\acrobat\dc\jscache\globsettings to %APPDATA%\adobe\acrobat\dc\jscache\globsettings.xfsdeyxx
  • from %APPDATA%\ghisler\wincmd.ini to %APPDATA%\ghisler\wincmd.ini.xfsdeyxx
  • from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\opt.dbs.xfsdeyxx
  • from %APPDATA%\icq-profile\installerlang.xml to %APPDATA%\icq-profile\installerlang.xml.xfsdeyxx
  • from %APPDATA%\icq-profile\update\languages.aff to %APPDATA%\icq-profile\update\languages.aff.xfsdeyxx
  • from %APPDATA%\icq-profile\update\languages.dict to %APPDATA%\icq-profile\update\languages.dict.xfsdeyxx
  • from %APPDATA%\icq-profile\update\languages.hash to %APPDATA%\icq-profile\update\languages.hash.xfsdeyxx
  • from %APPDATA%\icq-profile\update\ver.txt to %APPDATA%\icq-profile\update\ver.txt.xfsdeyxx
  • from %APPDATA%\icqm\icq\database\citylist_en.csv to %APPDATA%\icqm\icq\database\citylist_en.csv.xfsdeyxx
  • from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\mra.dbs.xfsdeyxx
  • from %APPDATA%\icqm\icq\database\citylist_tr.csv to %APPDATA%\icqm\icq\database\citylist_tr.csv.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\hungry.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\hungry.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\screen-offline.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-offline.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\bg\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\bg\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\drako_love.swf to %APPDATA%\icqm\icq\smiles\flash\drako_love.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\drako_opyatnica.swf to %APPDATA%\icqm\icq\smiles\flash\drako_opyatnica.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\drako_snegyrka.swf to %APPDATA%\icqm\icq\smiles\flash\drako_snegyrka.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\drako_zombie.swf to %APPDATA%\icqm\icq\smiles\flash\drako_zombie.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\duh.swf to %APPDATA%\icqm\icq\smiles\flash\duh.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\gangsta.swf to %APPDATA%\icqm\icq\smiles\flash\gangsta.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\guby.swf to %APPDATA%\icqm\icq\smiles\flash\guby.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\information.swf to %APPDATA%\icqm\icq\smiles\flash\information.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\joy.swf to %APPDATA%\icqm\icq\smiles\flash\joy.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\kisses.swf to %APPDATA%\icqm\icq\smiles\flash\kisses.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf to %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf to %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf to %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf to %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf to %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf to %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\screen-online-inv.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-online-inv.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\drako_koster.swf to %APPDATA%\icqm\icq\smiles\flash\drako_koster.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\graphics\phone\screen-online.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-online.bmp.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\drako_bolnoy.swf to %APPDATA%\icqm\icq\smiles\flash\drako_bolnoy.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\database\citylist_uz.csv to %APPDATA%\icqm\icq\database\citylist_uz.csv.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\cz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\cz\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\de\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\de\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\en\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\en\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\kz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\kz\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\pt\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\pt\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\ru\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\ru\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\tr\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\tr\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\ua\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\ua\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\html\uz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\uz\loading\progress_agent.gif.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\akitaka.swf to %APPDATA%\icqm\icq\smiles\flash\akitaka.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\angel.swf to %APPDATA%\icqm\icq\smiles\flash\angel.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\bad_cold.swf to %APPDATA%\icqm\icq\smiles\flash\bad_cold.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\beback.swf to %APPDATA%\icqm\icq\smiles\flash\beback.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\beer.swf to %APPDATA%\icqm\icq\smiles\flash\beer.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\bodun.swf to %APPDATA%\icqm\icq\smiles\flash\bodun.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\boo.swf to %APPDATA%\icqm\icq\smiles\flash\boo.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\canthearu.swf to %APPDATA%\icqm\icq\smiles\flash\canthearu.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\flash\devochka.swf to %APPDATA%\icqm\icq\smiles\flash\devochka.swf.xfsdeyxx
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_paper.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_paper.gif.xfsdeyxx
Changes user data files extensions (Trojan.Encoder).
Miscellaneous
Creates and executes the following
  • '%WINDIR%\syswow64\cmd.exe' /C type nul > "<Full path to file>:Zone.Identifier"' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /C type nul > "<Full path to file>:Zone.Identifier"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке