Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Encoder.34129

Добавлен в вирусную базу Dr.Web: 2021-07-09

Описание добавлено:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Task Scheduler' = '%APPDATA%\Microsoft\Windows\Templates\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master18' = '%APPDATA%\Adobe\LogTransport2\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master17' = '%APPDATA%\Adobe\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master16' = '%APPDATA%\Adobe\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master15' = '%APPDATA%\Adobe\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master14' = '%APPDATA%\Adobe\Flash Player\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master13' = '%APPDATA%\Adobe\Flash Player\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master12' = '%APPDATA%\Adobe\Flash Player\AssetCache\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master11' = '%APPDATA%\Adobe\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master10' = '%APPDATA%\Adobe\Acrobat\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master19' = '%APPDATA%\Adobe\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master9' = '%APPDATA%\Adobe\Acrobat\DC\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master7' = '%APPDATA%\Adobe\Acrobat\DC\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master6' = '%APPDATA%\Adobe\Acrobat\DC\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master5' = '%APPDATA%\Adobe\Acrobat\DC\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master4' = '%APPDATA%\Adobe\Acrobat\DC\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master3' = '%HOMEPATH%\Documents\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master2' = '%HOMEPATH%\Documents\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master1' = '%HOMEPATH%\Documents\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master0' = 'D:\$RECYCLE.BIN\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows AntiMalware Service' = '%APPDATA%\Windows AntiMalware Update.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master8' = '%APPDATA%\Adobe\Acrobat\DC\Security\<File name>.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Task Master20' = '%APPDATA%\<File name>.exe'
Creates or modifies the following files
  • %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
Malicious functions
Reads files which store third party applications passwords
  • %HOMEPATH%\desktop\000814251_video_01.avi
  • %HOMEPATH%\desktop\applicantform_en.doc
  • %HOMEPATH%\desktop\contoso_1.cer
  • %HOMEPATH%\desktop\correct.avi
  • %HOMEPATH%\desktop\dashborder_120.bmp
  • %HOMEPATH%\desktop\dashborder_192.bmp
  • %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
  • %HOMEPATH%\desktop\lisp_success.doc
  • %HOMEPATH%\desktop\ovp25012015.doc
  • %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
  • %HOMEPATH%\desktop\sdszfo.docx
  • %HOMEPATH%\desktop\tileimage.bmp
  • %HOMEPATH%\desktop\toolbar.bmp
  • %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
Modifies file system
Creates the following files
  • %APPDATA%\sam83ransomware_unique_id\unique_id.txt
  • %APPDATA%\icqm\icq\html\en\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\en\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\kz\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\kz\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\kz\error\rmap.txt
  • %APPDATA%\icqm\icq\html\kz\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\kz\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\kz\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\ru\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\pt\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\pt\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\pt\error\rmap.txt
  • %APPDATA%\icqm\icq\html\pt\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\pt\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\pt\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\pt\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\en\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\kz\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\en\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\cz\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\bg\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\cz\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\cz\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\cz\error\rmap.txt
  • %APPDATA%\icqm\icq\html\cz\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\cz\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\cz\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\de\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\en\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\de\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\de\error\rmap.txt
  • %APPDATA%\icqm\icq\html\de\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\de\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\de\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\de\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\en\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\en\error\rmap.txt
  • %APPDATA%\icqm\icq\html\tr\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\smiles\smiles\cat\rmap.txt
  • %APPDATA%\icqm\icq\html\ru\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\uz\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\uz\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\uz\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\uz\loading\rmap.txt
  • %APPDATA%\icqm\icq\skin\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\skin_cache\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\smiles\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\smiles\flash\rmap.txt
  • %APPDATA%\icqm\icq\html\ru\error\rmap.txt
  • %APPDATA%\icqm\icq\smiles\smiles\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\smiles\smiles\rmap.txt
  • %APPDATA%\icqm\icq\smiles\smiles\8march\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\smiles\smiles\8march\rmap.txt
  • %APPDATA%\icqm\icq\smiles\smiles\animated\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\smiles\smiles\animated\rmap.txt
  • %APPDATA%\icqm\icq\smiles\smiles\cat\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\uz\error\rmap.txt
  • %APPDATA%\icqm\icq\html\bg\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\uz\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\tr\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\ru\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\ru\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\ru\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\tr\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\tr\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\tr\error\rmap.txt
  • %APPDATA%\icqm\icq\html\tr\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\ru\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\ua\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\tr\loading\rmap.txt
  • %APPDATA%\icqm\icq\html\ua\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\ua\error\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\ua\error\rmap.txt
  • %APPDATA%\icqm\icq\html\ua\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\ua\jabber\rmap.txt
  • %APPDATA%\icqm\icq\html\ua\loading\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\uz\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\smiles\flash\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\bg\jabber\rmap.txt
  • %APPDATA%\icqm\icq\dll\rmap.txt
  • %HOMEPATH%\documents\my videos\sam83 ransomware text message.txt
  • %APPDATA%\sam83 ransomware text message.txt
  • %APPDATA%\adobe\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\dc\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\dc\rmap.txt
  • %APPDATA%\adobe\acrobat\dc\collab\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\dc\forms\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\dc\security\crlcache\rmap.txt
  • %APPDATA%\adobe\acrobat\dc\jscache\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\dc\jscache\rmap.txt
  • %APPDATA%\adobe\acrobat\dc\preferences\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\dc\preferences\rmap.txt
  • %APPDATA%\adobe\acrobat\dc\security\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\dc\security\rmap.txt
  • %APPDATA%\adobe\acrobat\dc\security\crlcache\sam83 ransomware text message.txt
  • %HOMEPATH%\documents\my pictures\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\dc\<File name>.exe
  • %HOMEPATH%\documents\<File name>.exe
  • %APPDATA%\cscc4f3.tmp
  • %APPDATA%\microsoft\windows\templates\sam83ransomware_unique_id\unique_id.txt
  • %APPDATA%\microsoft\windows\templates\sam83 ransomware text message.txt
  • %APPDATA%\microsoft\windows\templates\<File name>.exe
  • %APPDATA%\windows antimalware update.exe
  • %TEMP%\zvlz1rpc.0.cs
  • %TEMP%\zvlz1rpc.cmdline
  • %TEMP%\zvlz1rpc.out
  • %TEMP%\resc4f4.tmp
  • %HOMEPATH%\documents\sam83 ransomware text message.txt
  • %APPDATA%\svchost.exe
  • %APPDATA%\microsoftupdateserverip.txt
  • D:\$recycle.bin\sam83 ransomware text message.txt
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\sam83 ransomware text message.txt
  • D:\$recycle.bin\<File name>.exe
  • %HOMEPATH%\desktop\sam83 ransomware text message.txt
  • %HOMEPATH%\desktop\rmap.txt
  • %HOMEPATH%\documents\my music\sam83 ransomware text message.txt
  • %APPDATA%\adobe\linguistics\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\bg\error\rmap.txt
  • %APPDATA%\adobe\<File name>.exe
  • %APPDATA%\icq-profile\update\splash_banner\sam83 ransomware text message.txt
  • %APPDATA%\icqm\sam83 ransomware text message.txt
  • %APPDATA%\icqm\rmap.txt
  • %APPDATA%\icqm\icq\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\database\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\database\rmap.txt
  • %APPDATA%\icqm\icq\dll\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\fonts\sam83 ransomware text message.txt
  • %APPDATA%\adobe\acrobat\<File name>.exe
  • %APPDATA%\icqm\icq\fonts\rmap.txt
  • %APPDATA%\icqm\icq\graphics\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\graphics\phone\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\graphics\phone\rmap.txt
  • %APPDATA%\icqm\icq\html\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\bg\sam83 ransomware text message.txt
  • %APPDATA%\icqm\icq\html\bg\error\sam83 ransomware text message.txt
  • %APPDATA%\icq-profile\update\rmap.txt
  • %APPDATA%\icqm\icq\html\bg\jabber\sam83 ransomware text message.txt
  • %APPDATA%\icq-profile\update\sam83 ransomware text message.txt
  • %APPDATA%\adobe\headlights\sam83 ransomware text message.txt
  • %APPDATA%\adobe\flash player\sam83 ransomware text message.txt
  • %APPDATA%\adobe\flash player\assetcache\sam83 ransomware text message.txt
  • %APPDATA%\adobe\flash player\assetcache\reehzff2\sam83 ransomware text message.txt
  • %APPDATA%\adobe\flash player\assetcache\<File name>.exe
  • %APPDATA%\adobe\flash player\<File name>.exe
  • %APPDATA%\adobe\flash player\nativecache\sam83 ransomware text message.txt
  • %APPDATA%\adobe\flash player\nativecache\rmap.txt
  • %APPDATA%\adobe\acrobat\dc\security\<File name>.exe
  • %APPDATA%\icq-profile\base\sam83 ransomware text message.txt
  • %APPDATA%\adobe\logtransport2\sam83 ransomware text message.txt
  • %APPDATA%\adobe\logtransport2\rmap.txt
  • %APPDATA%\adobe\logtransport2\logs\sam83 ransomware text message.txt
  • %APPDATA%\adobe\logtransport2\<File name>.exe
  • %APPDATA%\<File name>.exe
  • %APPDATA%\ghisler\sam83 ransomware text message.txt
  • %APPDATA%\icq-profile\sam83 ransomware text message.txt
  • %APPDATA%\icq-profile\base\rmap.txt
  • %APPDATA%\icqm\icq\smiles\smiles\emoji\sam83 ransomware text message.txt
Deletes the following files
  • %TEMP%\resc4f4.tmp
  • %APPDATA%\cscc4f3.tmp
  • %TEMP%\zvlz1rpc.0.cs
  • %TEMP%\zvlz1rpc.out
  • %TEMP%\zvlz1rpc.cmdline
Moves the following files
  • from %HOMEPATH%\desktop\rmap.txt to %HOMEPATH%\desktop\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\flash\serdze.swf to %APPDATA%\icqm\icq\smiles\flash\serdze.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\skratch.swf to %APPDATA%\icqm\icq\smiles\flash\skratch.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\smeh.swf to %APPDATA%\icqm\icq\smiles\flash\smeh.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\sobaka.swf to %APPDATA%\icqm\icq\smiles\flash\sobaka.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf to %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\sorry.swf to %APPDATA%\icqm\icq\smiles\flash\sorry.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\tank.swf to %APPDATA%\icqm\icq\smiles\flash\tank.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\wf_love_sdaus.swf to %APPDATA%\icqm\icq\smiles\flash\wf_love_sdaus.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf to %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\rmap.txt to %APPDATA%\icqm\icq\smiles\flash\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\joy.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\joy.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\s008.gif to %APPDATA%\icqm\icq\smiles\smiles\s008.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\rmap.txt to %APPDATA%\icqm\icq\smiles\smiles\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\car.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\car.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\cat.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\cat.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\cookie.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\cookie.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\doll.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\doll.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\drink.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\drink.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\flowers.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\flowers.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\hug.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\hug.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\rosy.swf to %APPDATA%\icqm\icq\smiles\flash\rosy.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf to %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf to %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf to %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\drako_snegyrka.swf to %APPDATA%\icqm\icq\smiles\flash\drako_snegyrka.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\drako_zombie.swf to %APPDATA%\icqm\icq\smiles\flash\drako_zombie.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\duh.swf to %APPDATA%\icqm\icq\smiles\flash\duh.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\gangsta.swf to %APPDATA%\icqm\icq\smiles\flash\gangsta.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\guby.swf to %APPDATA%\icqm\icq\smiles\flash\guby.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\information.swf to %APPDATA%\icqm\icq\smiles\flash\information.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\joy.swf to %APPDATA%\icqm\icq\smiles\flash\joy.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\kisses.swf to %APPDATA%\icqm\icq\smiles\flash\kisses.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf to %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf to %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\mad dog.swf to %APPDATA%\icqm\icq\smiles\flash\mad dog.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf to %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf to %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf to %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\krizis.swf to %APPDATA%\icqm\icq\smiles\flash\krizis.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\laugh.swf to %APPDATA%\icqm\icq\smiles\flash\laugh.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\likeu.swf to %APPDATA%\icqm\icq\smiles\flash\likeu.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_kiss.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_kiss.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_rose.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_rose.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\missyou.swf to %APPDATA%\icqm\icq\smiles\flash\missyou.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\book.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\book.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_paper.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_paper.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\new_dress.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\new_dress.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\kiss.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\kiss.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\love.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\love.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\pistolet.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\pistolet.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\poison.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\poison.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\rainbow.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\rainbow.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\red.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\red.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\sad.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sad.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\sing.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sing.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\skuka.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\skuka.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\smile.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\smile.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\mad.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\mad.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\tongue.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\tongue.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\victory.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\victory.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\wonder.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\wonder.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\rmap.txt to %APPDATA%\icqm\icq\smiles\smiles\animated\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_attack.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_attack.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_hand.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_hand.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_lick.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_lick.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_meow.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_meow.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_mouse.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_mouse.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\hungry.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\hungry.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\drako_opyatnica.swf to %APPDATA%\icqm\icq\smiles\flash\drako_opyatnica.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\history.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\history.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\blew.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\blew.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\perfume.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\perfume.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\ring.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\ring.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\shoes.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\shoes.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\sunburn.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\sunburn.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\rmap.txt to %APPDATA%\icqm\icq\smiles\smiles\8march\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\angel.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\angel.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\appl.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\appl.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\beauty.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\beauty.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\beer.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\beer.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\8march\love.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\love.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\gg2.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gg2.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\could.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\could.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\cry.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\cry.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\dance.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\dance.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\devil.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\devil.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\eat.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\eat.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\fight.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\fight.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\fingal.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\fingal.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\flowr.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\flowr.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\gg.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gg.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\gift.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gift.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\smiles\animated\sleep.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sleep.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\drako_love.swf to %APPDATA%\icqm\icq\smiles\flash\drako_love.swf.sam83
  • from %APPDATA%\icqm\icq\html\uz\loading\rmap.txt to %APPDATA%\icqm\icq\html\uz\loading\rmap.txt
  • from %APPDATA%\icqm\mrainplaceviewer.dll to %APPDATA%\icqm\mrainplaceviewer.dll.sam83
  • from %APPDATA%\icqm\sciter32.dll to %APPDATA%\icqm\sciter32.dll.sam83
  • from %APPDATA%\icqm\vivo.dll to %APPDATA%\icqm\vivo.dll.sam83
  • from %APPDATA%\icqm\rmap.txt to %APPDATA%\icqm\rmap.txt
  • from %APPDATA%\icqm\icq\database\citylist_en.csv to %APPDATA%\icqm\icq\database\citylist_en.csv.sam83
  • from %APPDATA%\icqm\icq\database\citylist_kz.csv to %APPDATA%\icqm\icq\database\citylist_kz.csv.sam83
  • from %APPDATA%\icqm\icq\database\citylist_ru.csv to %APPDATA%\icqm\icq\database\citylist_ru.csv.sam83
  • from %APPDATA%\icqm\icq\database\citylist_tr.csv to %APPDATA%\icqm\icq\database\citylist_tr.csv.sam83
  • from %APPDATA%\icqm\icq\database\citylist_ua.csv to %APPDATA%\icqm\icq\database\citylist_ua.csv.sam83
  • from %APPDATA%\icqm\icq\database\rmap.txt to %APPDATA%\icqm\icq\database\rmap.txt
  • from %APPDATA%\icqm\icq\html\bg\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\bg\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\dll\altergeo.msi to %APPDATA%\icqm\icq\dll\altergeo.msi.sam83
  • from %APPDATA%\icqm\icq\dll\mousephone.dll to %APPDATA%\icqm\icq\dll\mousephone.dll.sam83
  • from %APPDATA%\icqm\icq\dll\mratag.dll to %APPDATA%\icqm\icq\dll\mratag.dll.sam83
  • from %APPDATA%\icqm\icq\dll\rmap.txt to %APPDATA%\icqm\icq\dll\rmap.txt
  • from %APPDATA%\icqm\icq\fonts\segoesc.ttf to %APPDATA%\icqm\icq\fonts\segoesc.ttf.sam83
  • from %APPDATA%\icqm\icq\fonts\rmap.txt to %APPDATA%\icqm\icq\fonts\rmap.txt
  • from %APPDATA%\icqm\icq\graphics\phone\rmap.txt to %APPDATA%\icqm\icq\graphics\phone\rmap.txt
  • from %APPDATA%\icqm\icq\html\bg\error\rmap.txt to %APPDATA%\icqm\icq\html\bg\error\rmap.txt
  • from %APPDATA%\icqm\icq\html\bg\jabber\rmap.txt to %APPDATA%\icqm\icq\html\bg\jabber\rmap.txt
  • from %APPDATA%\icqm\libvoip_x86.dll to %APPDATA%\icqm\libvoip_x86.dll.sam83
  • from %APPDATA%\icqm\icq\database\citylist_uz.csv to %APPDATA%\icqm\icq\database\citylist_uz.csv.sam83
  • from %APPDATA%\icq-profile\update\rmap.txt to %APPDATA%\icq-profile\update\rmap.txt
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl.sam83
  • from %APPDATA%\adobe\acrobat\dc\tmdocs.sav to %APPDATA%\adobe\acrobat\dc\tmdocs.sav.sam83
  • from %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav to %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav.sam83
  • from %APPDATA%\adobe\acrobat\dc\rmap.txt to %APPDATA%\adobe\acrobat\dc\rmap.txt
  • from %APPDATA%\adobe\acrobat\dc\jscache\globdata to %APPDATA%\adobe\acrobat\dc\jscache\globdata.sam83
  • from %APPDATA%\adobe\acrobat\dc\jscache\globsettings to %APPDATA%\adobe\acrobat\dc\jscache\globsettings.sam83
  • from %APPDATA%\adobe\acrobat\dc\jscache\rmap.txt to %APPDATA%\adobe\acrobat\dc\jscache\rmap.txt
  • from %APPDATA%\adobe\acrobat\dc\preferences\rmap.txt to %APPDATA%\adobe\acrobat\dc\preferences\rmap.txt
  • from %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata to %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata.sam83
  • from %APPDATA%\adobe\acrobat\dc\security\rmap.txt to %APPDATA%\adobe\acrobat\dc\security\rmap.txt
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl.sam83
  • from %APPDATA%\icq-profile\update\languages.dict to %APPDATA%\icq-profile\update\languages.dict.sam83
  • from %APPDATA%\adobe\acrobat\dc\security\crlcache\rmap.txt to %APPDATA%\adobe\acrobat\dc\security\crlcache\rmap.txt
  • from %APPDATA%\adobe\flash player\nativecache\nativecache.directory to %APPDATA%\adobe\flash player\nativecache\nativecache.directory.sam83
  • from %APPDATA%\adobe\flash player\nativecache\rmap.txt to %APPDATA%\adobe\flash player\nativecache\rmap.txt
  • from %APPDATA%\adobe\logtransport2\logtransport2.cfg to %APPDATA%\adobe\logtransport2\logtransport2.cfg.sam83
  • from %APPDATA%\adobe\logtransport2\rmap.txt to %APPDATA%\adobe\logtransport2\rmap.txt
  • from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\mra.dbs.sam83
  • from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\opt.dbs.sam83
  • from %APPDATA%\icq-profile\base\rmap.txt to %APPDATA%\icq-profile\base\rmap.txt
  • from %APPDATA%\icq-profile\update\languages.aff to %APPDATA%\icq-profile\update\languages.aff.sam83
  • from %APPDATA%\icq-profile\update\languages.hash to %APPDATA%\icq-profile\update\languages.hash.sam83
  • from %APPDATA%\icqm\icq\html\kz\error\rmap.txt to %APPDATA%\icqm\icq\html\kz\error\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\flash\drako_bolnoy.swf to %APPDATA%\icqm\icq\smiles\flash\drako_bolnoy.swf.sam83
  • from %APPDATA%\icqm\icq\html\cz\jabber\rmap.txt to %APPDATA%\icqm\icq\html\cz\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\html\tr\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\tr\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\html\tr\loading\rmap.txt to %APPDATA%\icqm\icq\html\tr\loading\rmap.txt
  • from %APPDATA%\icqm\icq\html\ua\error\rmap.txt to %APPDATA%\icqm\icq\html\ua\error\rmap.txt
  • from %APPDATA%\icqm\icq\html\ua\jabber\rmap.txt to %APPDATA%\icqm\icq\html\ua\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\html\ua\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\ua\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\html\ua\loading\rmap.txt to %APPDATA%\icqm\icq\html\ua\loading\rmap.txt
  • from %APPDATA%\icqm\icq\html\uz\error\rmap.txt to %APPDATA%\icqm\icq\html\uz\error\rmap.txt
  • from %APPDATA%\icqm\icq\html\uz\jabber\rmap.txt to %APPDATA%\icqm\icq\html\uz\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\html\uz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\uz\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\akitaka.swf to %APPDATA%\icqm\icq\smiles\flash\akitaka.swf.sam83
  • from %APPDATA%\icqm\icq\html\cz\error\rmap.txt to %APPDATA%\icqm\icq\html\cz\error\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\flash\angel.swf to %APPDATA%\icqm\icq\smiles\flash\angel.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\bad_cold.swf to %APPDATA%\icqm\icq\smiles\flash\bad_cold.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\beback.swf to %APPDATA%\icqm\icq\smiles\flash\beback.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\beer.swf to %APPDATA%\icqm\icq\smiles\flash\beer.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\bodun.swf to %APPDATA%\icqm\icq\smiles\flash\bodun.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\boo.swf to %APPDATA%\icqm\icq\smiles\flash\boo.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\canthearu.swf to %APPDATA%\icqm\icq\smiles\flash\canthearu.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\chillout.swf to %APPDATA%\icqm\icq\smiles\flash\chillout.swf.sam83
  • from %APPDATA%\icqm\icq\smiles\flash\devochka.swf to %APPDATA%\icqm\icq\smiles\flash\devochka.swf.sam83
  • from %APPDATA%\icqm\icq\html\tr\jabber\rmap.txt to %APPDATA%\icqm\icq\html\tr\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\flash\drako_koster.swf to %APPDATA%\icqm\icq\smiles\flash\drako_koster.swf.sam83
  • from %APPDATA%\icqm\icq\html\tr\error\rmap.txt to %APPDATA%\icqm\icq\html\tr\error\rmap.txt
  • from %APPDATA%\icqm\icq\html\en\loading\rmap.txt to %APPDATA%\icqm\icq\html\en\loading\rmap.txt
  • from %APPDATA%\icqm\icq\html\cz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\cz\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\html\cz\loading\rmap.txt to %APPDATA%\icqm\icq\html\cz\loading\rmap.txt
  • from %APPDATA%\icqm\icq\html\de\error\rmap.txt to %APPDATA%\icqm\icq\html\de\error\rmap.txt
  • from %APPDATA%\icqm\icq\html\de\jabber\rmap.txt to %APPDATA%\icqm\icq\html\de\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\html\de\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\de\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\html\de\loading\rmap.txt to %APPDATA%\icqm\icq\html\de\loading\rmap.txt
  • from %APPDATA%\icqm\icq\html\en\error\rmap.txt to %APPDATA%\icqm\icq\html\en\error\rmap.txt
  • from %APPDATA%\icqm\icq\html\en\jabber\rmap.txt to %APPDATA%\icqm\icq\html\en\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\html\en\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\en\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\html\bg\loading\rmap.txt to %APPDATA%\icqm\icq\html\bg\loading\rmap.txt
  • from %APPDATA%\icqm\icq\html\ru\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\ru\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\html\kz\jabber\rmap.txt to %APPDATA%\icqm\icq\html\kz\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\html\kz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\kz\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\html\kz\loading\rmap.txt to %APPDATA%\icqm\icq\html\kz\loading\rmap.txt
  • from %APPDATA%\icqm\icq\html\pt\error\rmap.txt to %APPDATA%\icqm\icq\html\pt\error\rmap.txt
  • from %APPDATA%\icqm\icq\html\pt\jabber\rmap.txt to %APPDATA%\icqm\icq\html\pt\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\html\pt\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\pt\loading\progress_agent.gif.sam83
  • from %APPDATA%\icqm\icq\html\pt\loading\rmap.txt to %APPDATA%\icqm\icq\html\pt\loading\rmap.txt
  • from %APPDATA%\icqm\icq\html\ru\error\rmap.txt to %APPDATA%\icqm\icq\html\ru\error\rmap.txt
  • from %APPDATA%\icqm\icq\html\ru\jabber\rmap.txt to %APPDATA%\icqm\icq\html\ru\jabber\rmap.txt
  • from %APPDATA%\icqm\icq\html\ru\loading\rmap.txt to %APPDATA%\icqm\icq\html\ru\loading\rmap.txt
  • from %APPDATA%\icqm\icq\smiles\smiles\cat\rmap.txt to %APPDATA%\icqm\icq\smiles\smiles\cat\rmap.txt
Modifies the following files
  • %HOMEPATH%\desktop\000814251_video_01.avi
  • %APPDATA%\adobe\acrobat\dc\jscache\globdata.sam83
  • %APPDATA%\adobe\acrobat\dc\jscache\globdata
  • %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav.sam83
  • %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav
  • %APPDATA%\adobe\acrobat\dc\tmdocs.sav.sam83
  • %APPDATA%\adobe\acrobat\dc\tmdocs.sav
  • %HOMEPATH%\desktop\total commander 64 bit.lnk.sam83
  • %HOMEPATH%\desktop\total commander 64 bit.lnk
  • %HOMEPATH%\desktop\telegram.lnk.sam83
  • %HOMEPATH%\desktop\telegram.lnk
  • %HOMEPATH%\desktop\qip 2012.lnk.sam83
  • %HOMEPATH%\desktop\qip 2012.lnk
  • %HOMEPATH%\desktop\mail.ru agent.lnk.sam83
  • %HOMEPATH%\desktop\mail.ru agent.lnk
  • %HOMEPATH%\desktop\icq.lnk.sam83
  • %HOMEPATH%\desktop\icq.lnk
  • %HOMEPATH%\desktop\dashborder_192.bmp.sam83
  • %HOMEPATH%\desktop\dashborder_192.bmp
  • %HOMEPATH%\desktop\dashborder_120.bmp.sam83
  • %HOMEPATH%\desktop\dashborder_120.bmp
  • %HOMEPATH%\desktop\correct.avi.sam83
  • %HOMEPATH%\desktop\correct.avi
  • %HOMEPATH%\desktop\contoso_1.cer.sam83
  • %HOMEPATH%\desktop\contoso_1.cer
  • %HOMEPATH%\desktop\applicantform_en.doc.sam83
  • %HOMEPATH%\desktop\applicantform_en.doc
  • %HOMEPATH%\desktop\000814251_video_01.avi.sam83
  • %APPDATA%\adobe\acrobat\dc\jscache\globsettings
  • %APPDATA%\adobe\acrobat\dc\jscache\globsettings.sam83
Modifies multiple files.
Modifies user data files (Trojan.Encoder).
Changes user data files extensions (Trojan.Encoder).
Network activity
Connects to
  • '1.#.0.0':445
  • '1.#.1.58':445
  • '1.#.1.86':445
  • '1.#.1.85':445
  • '1.#.1.84':445
  • '1.#.1.83':445
  • '1.#.1.82':445
  • '1.#.1.81':445
  • '1.#.1.80':445
  • '1.#.1.79':445
  • '1.#.1.78':445
  • '1.#.1.77':445
  • '1.#.1.76':445
  • '1.#.1.75':445
  • '1.#.1.74':445
  • '1.#.1.73':445
  • '1.#.1.72':445
  • '1.#.1.71':445
  • '1.#.1.70':445
  • '1.#.1.69':445
  • '1.#.1.68':445
  • '1.#.1.67':445
  • '1.#.1.66':445
  • '1.#.1.65':445
  • '1.#.1.64':445
  • '1.#.1.63':445
  • '1.#.1.62':445
  • '1.#.1.61':445
  • '1.#.1.87':445
  • '1.#.1.60':445
  • '1.#.1.89':445
  • '1.#.1.90':445
  • '1.#.1.103':445
  • '1.#.1.116':445
  • '1.#.1.115':445
  • '1.#.1.114':445
  • '1.#.1.113':445
  • '1.#.1.112':445
  • '1.#.1.111':445
  • '1.#.1.110':445
  • '1.#.1.109':445
  • '1.#.1.108':445
  • '1.#.1.107':445
  • '1.#.1.106':445
  • '1.#.1.105':445
  • '1.#.1.104':445
  • '1.#.1.102':445
  • '1.#.1.40':445
  • '1.#.1.101':445
  • '1.#.1.100':445
  • '1.#.1.99':445
  • '1.#.1.98':445
  • '1.#.1.97':445
  • '1.#.1.96':445
  • '1.#.1.95':445
  • '1.#.1.94':445
  • '1.#.1.93':445
  • '1.#.1.92':445
  • '1.#.1.91':445
  • '1.#.1.88':445
  • '1.#.1.59':445
  • '1.#.1.57':445
  • '1.#.1.56':445
  • '1.#.1.24':445
  • '1.#.1.21':445
  • '1.#.1.20':445
  • '1.#.1.19':445
  • '1.#.1.18':445
  • '1.#.1.17':445
  • '1.#.1.16':445
  • '1.#.1.15':445
  • '1.#.1.14':445
  • '1.#.1.13':445
  • '1.#.1.12':445
  • '1.#.1.11':445
  • '1.#.1.10':445
  • '1.#.1.9':445
  • '1.#.1.8':445
  • '1.#.1.7':445
  • '1.#.1.6':445
  • '1.#.1.5':445
  • '1.#.1.4':445
  • '1.#.1.3':445
  • '1.#.1.2':445
  • '1.#.1.1':445
  • '1.#.1.0':445
  • '1.#.0.255':445
  • '1.#.0.254':445
  • '1.#.0.253':445
  • '1.#.0.252':445
  • '1.#.1.22':445
  • '1.#.1.25':445
  • '1.#.1.54':445
  • '1.#.1.27':445
  • '1.#.1.55':445
  • '1.#.1.26':445
  • '1.#.1.53':445
  • '1.#.1.52':445
  • '1.#.1.51':445
  • '1.#.1.50':445
  • '1.#.1.49':445
  • '1.#.1.48':445
  • '1.#.1.47':445
  • '1.#.1.46':445
  • '1.#.1.45':445
  • '1.#.1.44':445
  • '1.#.1.43':445
  • '1.#.0.251':445
  • '1.#.1.42':445
  • '1.#.1.41':445
  • '1.#.1.39':445
  • '1.#.1.38':445
  • '1.#.1.37':445
  • '1.#.1.36':445
  • '1.#.1.35':445
  • '1.#.1.34':445
  • '1.#.1.33':445
  • '1.#.1.32':445
  • '1.#.1.31':445
  • '1.#.1.30':445
  • '1.#.1.29':445
  • '1.#.1.28':445
  • '1.#.1.117':445
  • '1.#.1.23':445
  • '1.#.1.118':445
  • '1.#.1.148':445
  • '1.#.1.211':445
  • '1.#.1.210':445
  • '1.#.1.209':445
  • '1.#.1.208':445
  • '1.#.1.207':445
  • '1.#.1.206':445
  • '1.#.1.205':445
  • '1.#.1.204':445
  • '1.#.1.203':445
  • '1.#.1.202':445
  • '1.#.1.201':445
  • '1.#.1.200':445
  • '1.#.1.199':445
  • '1.#.1.198':445
  • '1.#.1.197':445
  • '1.#.1.196':445
  • '1.#.1.195':445
  • '1.#.1.194':445
  • '1.#.1.193':445
  • '1.#.1.192':445
  • '1.#.1.191':445
  • '1.#.1.190':445
  • '1.#.1.189':445
  • '1.#.1.188':445
  • '1.#.1.187':445
  • '1.#.1.186':445
  • '1.#.1.185':445
  • '1.#.1.183':445
  • '1.#.1.184':445
  • '1.#.1.212':445
  • '1.#.1.213':445
  • '1.#.1.241':445
  • '1.#.1.240':445
  • '1.#.1.239':445
  • '1.#.1.238':445
  • '1.#.1.237':445
  • '1.#.1.236':445
  • '1.#.1.235':445
  • '1.#.1.234':445
  • '1.#.1.233':445
  • '1.#.1.232':445
  • '1.#.1.231':445
  • '1.#.1.230':445
  • '1.#.1.229':445
  • '1.#.1.227':445
  • '1.#.1.181':445
  • '1.#.1.226':445
  • '1.#.1.225':445
  • '1.#.1.224':445
  • '1.#.1.223':445
  • '1.#.1.222':445
  • '1.#.1.221':445
  • '1.#.1.220':445
  • '1.#.1.219':445
  • '1.#.1.218':445
  • '1.#.1.217':445
  • '1.#.1.216':445
  • '1.#.1.215':445
  • '1.#.1.214':445
  • '1.#.1.182':445
  • '1.#.1.180':445
  • '1.#.0.170':445
  • '1.#.1.149':445
  • '1.#.1.146':445
  • '1.#.1.145':445
  • '1.#.1.144':445
  • '1.#.1.143':445
  • '1.#.1.142':445
  • '1.#.1.141':445
  • '1.#.1.140':445
  • '1.#.1.139':445
  • '1.#.1.138':445
  • '1.#.1.137':445
  • '1.#.1.136':445
  • '1.#.1.135':445
  • '1.#.1.134':445
  • '1.#.1.133':445
  • '1.#.1.132':445
  • '1.#.1.131':445
  • '1.#.1.130':445
  • '1.#.1.129':445
  • '1.#.1.128':445
  • '1.#.1.127':445
  • '1.#.1.126':445
  • '1.#.1.125':445
  • '1.#.1.124':445
  • '1.#.1.123':445
  • '1.#.1.122':445
  • '1.#.1.121':445
  • '1.#.1.150':445
  • '1.#.1.151':445
  • '1.#.1.179':445
  • '1.#.1.165':445
  • '1.#.1.166':445
  • '1.#.1.178':445
  • '1.#.1.177':445
  • '1.#.1.176':445
  • '1.#.1.175':445
  • '1.#.1.174':445
  • '1.#.1.173':445
  • '1.#.1.172':445
  • '1.#.1.171':445
  • '1.#.1.170':445
  • '1.#.1.169':445
  • '1.#.1.168':445
  • '1.#.1.167':445
  • '1.#.1.120':445
  • '1.#.1.119':445
  • '1.#.1.147':445
  • '1.#.1.163':445
  • '1.#.1.162':445
  • '1.#.1.161':445
  • '1.#.1.160':445
  • '1.#.1.159':445
  • '1.#.1.158':445
  • '1.#.1.157':445
  • '1.#.1.156':445
  • '1.#.1.155':445
  • '1.#.1.154':445
  • '1.#.1.153':445
  • '1.#.1.152':445
  • '1.#.1.164':445
  • '1.#.0.250':445
  • '1.#.0.249':445
  • '1.#.0.248':445
  • '1.#.0.63':445
  • '1.#.0.89':445
  • '1.#.0.88':445
  • '1.#.0.87':445
  • '1.#.0.86':445
  • '1.#.0.85':445
  • '1.#.0.84':445
  • '1.#.0.83':445
  • '1.#.0.82':445
  • '1.#.0.81':445
  • '1.#.0.80':445
  • '1.#.0.79':445
  • '1.#.0.78':445
  • '1.#.0.77':445
  • '1.#.0.76':445
  • '1.#.0.75':445
  • '1.#.0.74':445
  • '1.#.0.73':445
  • '1.#.0.72':445
  • '1.#.0.71':445
  • '1.#.0.70':445
  • '1.#.0.69':445
  • '1.#.0.68':445
  • '1.#.0.67':445
  • '1.#.0.66':445
  • '1.#.0.65':445
  • '1.#.0.64':445
  • '1.#.0.92':445
  • '1.#.0.91':445
  • '1.#.0.94':445
  • '1.#.0.62':445
  • '1.#.0.120':445
  • '1.#.0.119':445
  • '1.#.0.118':445
  • '1.#.0.117':445
  • '1.#.0.116':445
  • '1.#.0.115':445
  • '1.#.0.114':445
  • '1.#.0.113':445
  • '1.#.0.112':445
  • '1.#.0.111':445
  • '1.#.0.110':445
  • '1.#.0.109':445
  • '1.#.0.108':445
  • '1.#.0.106':445
  • '1.#.0.123':445
  • '1.#.0.105':445
  • '1.#.0.104':445
  • '1.#.0.103':445
  • '1.#.0.102':445
  • '1.#.0.101':445
  • '1.#.0.100':445
  • '1.#.0.99':445
  • '1.#.0.98':445
  • '1.#.0.97':445
  • '1.#.0.96':445
  • '1.#.0.95':445
  • '1.#.0.93':445
  • '1.#.0.121':445
  • '1.#.0.61':445
  • '1.#.0.60':445
  • '1.#.0.27':445
  • '1.#.0.25':445
  • '1.#.0.24':445
  • '1.#.0.23':445
  • '1.#.0.22':445
  • '1.#.0.21':445
  • '1.#.0.20':445
  • '1.#.0.19':445
  • '1.#.0.18':445
  • '1.#.0.17':445
  • '1.#.0.16':445
  • '1.#.0.15':445
  • '1.#.0.14':445
  • '1.#.0.13':445
  • '1.#.0.12':445
  • '1.#.0.11':445
  • '1.#.0.10':445
  • '1.#.0.9':445
  • '1.#.0.8':445
  • '1.#.0.7':445
  • '1.#.0.6':445
  • '1.#.0.5':445
  • '1.#.0.4':445
  • '1.#.0.3':445
  • '1.#.0.2':445
  • '1.#.0.1':445
  • '1.#.0.28':445
  • '1.#.0.29':445
  • '1.#.0.30':445
  • '1.#.0.26':445
  • '1.#.0.31':445
  • '1.#.0.58':445
  • '1.#.0.59':445
  • '1.#.0.57':445
  • '1.#.0.56':445
  • '1.#.0.55':445
  • '1.#.0.54':445
  • '1.#.0.53':445
  • '1.#.0.52':445
  • '1.#.0.51':445
  • '1.#.0.50':445
  • '1.#.0.49':445
  • '1.#.0.48':445
  • '1.#.0.47':445
  • '1.#.0.122':445
  • '1.#.0.107':445
  • '1.#.0.46':445
  • '1.#.0.43':445
  • '1.#.0.42':445
  • '1.#.0.41':445
  • '1.#.0.40':445
  • '1.#.0.39':445
  • '1.#.0.38':445
  • '1.#.0.37':445
  • '1.#.0.36':445
  • '1.#.0.35':445
  • '1.#.0.34':445
  • '1.#.0.33':445
  • '1.#.0.32':445
  • '1.#.0.45':445
  • '1.#.0.44':445
  • '1.#.0.90':445
  • '1.#.0.124':445
  • '1.#.0.215':445
  • '1.#.0.217':445
  • '1.#.0.214':445
  • '1.#.0.213':445
  • '1.#.0.212':445
  • '1.#.0.211':445
  • '1.#.0.210':445
  • '1.#.0.209':445
  • '1.#.0.208':445
  • '1.#.0.207':445
  • '1.#.0.206':445
  • '1.#.0.205':445
  • '1.#.0.204':445
  • '1.#.0.203':445
  • '1.#.0.202':445
  • '1.#.0.201':445
  • '1.#.0.200':445
  • '1.#.0.199':445
  • '1.#.0.198':445
  • '1.#.0.197':445
  • '1.#.0.196':445
  • '1.#.0.195':445
  • '1.#.0.194':445
  • '1.#.0.193':445
  • '1.#.0.192':445
  • '1.#.0.191':445
  • '1.#.0.190':445
  • '1.#.0.189':445
  • '1.#.0.218':445
  • '1.#.0.219':445
  • '1.#.0.247':445
  • '1.#.0.233':445
  • '1.#.0.234':445
  • '1.#.0.246':445
  • '1.#.0.245':445
  • '1.#.0.244':445
  • '1.#.0.243':445
  • '1.#.0.242':445
  • '1.#.0.241':445
  • '1.#.0.240':445
  • '1.#.0.239':445
  • '1.#.0.238':445
  • '1.#.0.237':445
  • '1.#.0.236':445
  • '1.#.0.235':445
  • '1.#.0.216':445
  • '1.#.0.188':445
  • '1.#.0.125':445
  • '1.#.0.231':445
  • '1.#.0.230':445
  • '1.#.0.229':445
  • '1.#.0.228':445
  • '1.#.0.227':445
  • '1.#.0.226':445
  • '1.#.0.225':445
  • '1.#.0.224':445
  • '1.#.0.223':445
  • '1.#.0.222':445
  • '1.#.0.221':445
  • '1.#.0.220':445
  • '1.#.0.232':445
  • '1.#.1.228':445
  • '1.#.1.242':445
  • '1.#.0.185':445
  • '1.#.0.151':445
  • '1.#.0.150':445
  • '1.#.0.149':445
  • '1.#.0.148':445
  • '1.#.0.147':445
  • '1.#.0.146':445
  • '1.#.0.145':445
  • '1.#.0.144':445
  • '1.#.0.143':445
  • '1.#.0.142':445
  • '1.#.0.141':445
  • '1.#.0.140':445
  • '1.#.0.139':445
  • '1.#.0.138':445
  • '1.#.0.137':445
  • '1.#.0.136':445
  • '1.#.0.135':445
  • '1.#.0.134':445
  • '1.#.0.133':445
  • '1.#.0.132':445
  • '1.#.0.131':445
  • '1.#.0.130':445
  • '1.#.0.129':445
  • '1.#.0.128':445
  • '1.#.0.127':445
  • '1.#.0.126':445
  • '1.#.0.153':445
  • '1.#.0.154':445
  • '1.#.0.152':445
  • '1.#.0.155':445
  • '1.#.0.184':445
  • '1.#.0.156':445
  • '1.#.0.183':445
  • '1.#.0.182':445
  • '1.#.0.181':445
  • '1.#.0.180':445
  • '1.#.0.179':445
  • '1.#.0.178':445
  • '1.#.0.177':445
  • '1.#.0.176':445
  • '1.#.0.175':445
  • '1.#.0.174':445
  • '1.#.0.173':445
  • '1.#.0.172':445
  • '1.#.0.187':445
  • '1.#.0.186':445
  • '1.#.0.169':445
  • '1.#.0.168':445
  • '1.#.0.167':445
  • '1.#.0.166':445
  • '1.#.0.165':445
  • '1.#.0.164':445
  • '1.#.0.163':445
  • '1.#.0.162':445
  • '1.#.0.161':445
  • '1.#.0.160':445
  • '1.#.0.159':445
  • '1.#.0.158':445
  • '1.#.0.157':445
  • '1.#.0.171':445
  • '1.#.1.243':445
Miscellaneous
Creates and executes the following
  • '%APPDATA%\svchost.exe'
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC4F4.tmp" "%APPDATA%\CSCC4F3.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\zvlz1rpc.cmdline"' (with hidden window)
Executes the following
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\zvlz1rpc.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC4F4.tmp" "%APPDATA%\CSCC4F3.tmp"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке