Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Encoder.38117

Добавлен в вирусную базу Dr.Web: 2023-10-12

Описание добавлено:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'DP_Main' = '%APPDATA%\DP\DP_Main.exe'
Infects the following executable files
  • <Drive name for removable media>:\winmine.exe
  • %CommonProgramFiles%\microsoft shared\office14\1033\msointl.rest.idx_dll
  • %CommonProgramFiles%\microsoft shared\office14\1033\msointl.dll
  • %CommonProgramFiles%\microsoft shared\office14\1033\alrtintl.dll
  • %CommonProgramFiles%\microsoft shared\office14\1033\acewstr.dll
  • %CommonProgramFiles%\microsoft shared\office14\1033\aceintl.dll
  • %CommonProgramFiles%\microsoft shared\office14\wisc30.dll
  • %CommonProgramFiles%\microsoft shared\office14\usp10.dll
  • %CommonProgramFiles%\microsoft shared\office14\riched20.dll
  • %CommonProgramFiles%\microsoft shared\office14\oarpmany.exe
  • %CommonProgramFiles%\microsoft shared\office14\expsrv.dll
  • %CommonProgramFiles%\microsoft shared\office14\mssoap30.dll
  • %CommonProgramFiles%\microsoft shared\office14\msoxmled.exe
  • %CommonProgramFiles%\microsoft shared\office14\msoshext.dll
  • %CommonProgramFiles%\microsoft shared\office14\msores.dll
  • %CommonProgramFiles%\microsoft shared\office14\msoicons.exe
  • %CommonProgramFiles%\microsoft shared\office14\mso.dll
  • %CommonProgramFiles%\microsoft shared\office14\liclua.exe
  • %CommonProgramFiles%\microsoft shared\office14\iacom2.dll
  • %CommonProgramFiles%\microsoft shared\office14\fltldr.exe
  • %CommonProgramFiles%\microsoft shared\office14\exp_xps.dll
  • %CommonProgramFiles%\microsoft shared\office14\msptls.dll
  • %CommonProgramFiles%\microsoft shared\office14\exp_pdf.dll
  • %CommonProgramFiles%\microsoft shared\office14\1033\xlsrvintl.dll
  • %CommonProgramFiles%\microsoft shared\smart tag\fbiblio.dll
  • %CommonProgramFiles%\microsoft shared\textconv\msconv97.dll
  • %CommonProgramFiles%\microsoft shared\source engine\ose.exe
  • %CommonProgramFiles%\microsoft shared\smart tag\mofl.dll
  • %CommonProgramFiles%\microsoft shared\smart tag\metconv.dll
  • %CommonProgramFiles%\microsoft shared\smart tag\imcontact.dll
  • %CommonProgramFiles%\microsoft shared\smart tag\ietag.dll
  • %CommonProgramFiles%\microsoft shared\smart tag\fstock.dll
  • %CommonProgramFiles%\microsoft shared\smart tag\fplace.dll
  • %CommonProgramFiles%\microsoft shared\smart tag\fperson.dll
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\osetup.dll
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\odeploy.exe
  • %CommonProgramFiles%\microsoft shared\proof\mslid.dll
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\osppwmi.dll
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\osppobjs.dll
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\osppcext.dll
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\osppc.dll
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office.en-us\osetupui.dll
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\setup.exe
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\pidgenx.dll
  • %CommonProgramFiles%\microsoft shared\smart tag\fdate.dll
  • %CommonProgramFiles%\microsoft shared\office14\csisoap.dll
  • %CommonProgramFiles%\microsoft shared\office14\csi.dll
  • %CommonProgramFiles%\microsoft shared\office14\acexbe.dll
  • %CommonProgramFiles%\microsoft shared\dw\dwtrig20.exe
  • %CommonProgramFiles%\microsoft shared\dw\dw20.exe
  • %CommonProgramFiles%\microsoft shared\dw\dbghelp.dll
  • %CommonProgramFiles%\designer\msaddndr.dll
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\1033\dwintl20.dll
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\osetupui.dll
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\msvcr90.dll
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dwtrig20.exe
  • %CommonProgramFiles%\microsoft shared\filters\odffilt.dll
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dwdcw20.dll
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.exe
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\pidgenx.dll
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\osetup.dll
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\ose.exe
  • <Drive name for removable media>:\wrar520.exe
  • <Drive name for removable media>:\utorrent.exe
  • <Drive name for removable media>:\dotnetfx45_full_setup.exe
  • <Drive name for removable media>:\notepad.exe
  • <Drive name for removable media>:\skypesetup.exe
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe
  • %CommonProgramFiles%\microsoft shared\filters\offfiltx.dll
  • %CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe
  • %CommonProgramFiles%\microsoft shared\grphflt\cgmimp32.flt
  • %CommonProgramFiles%\microsoft shared\office14\acewss.dll
  • %CommonProgramFiles%\microsoft shared\office14\acedao.dll
  • %CommonProgramFiles%\microsoft shared\office14\acewdat.dll
  • %CommonProgramFiles%\microsoft shared\office14\acetxt.dll
  • %CommonProgramFiles%\microsoft shared\office14\acerep.dll
  • %CommonProgramFiles%\microsoft shared\office14\acer3x.dll
  • %CommonProgramFiles%\microsoft shared\office14\aceoledb.dll
  • %CommonProgramFiles%\microsoft shared\office14\aceodbc.dll
  • %CommonProgramFiles%\microsoft shared\office14\aceexcl.dll
  • %CommonProgramFiles%\microsoft shared\office14\aceexch.dll
  • %CommonProgramFiles%\microsoft shared\office14\acees.dll
  • %CommonProgramFiles%\microsoft shared\office14\acecore.dll
  • %CommonProgramFiles%\microsoft shared\grphflt\epsimp32.flt
  • %CommonProgramFiles%\microsoft shared\msclientdatamgr\mscdm.dll
  • %CommonProgramFiles%\microsoft shared\help\msitss55.dll
  • %CommonProgramFiles%\microsoft shared\help\itircl55.dll
  • %CommonProgramFiles%\microsoft shared\help\hxds.dll
  • %CommonProgramFiles%\microsoft shared\grphflt\wpgimp32.flt
  • %CommonProgramFiles%\microsoft shared\grphflt\png32.flt
  • %CommonProgramFiles%\microsoft shared\grphflt\pictim32.flt
  • %CommonProgramFiles%\microsoft shared\grphflt\jpegim32.flt
  • %CommonProgramFiles%\microsoft shared\grphflt\gifimp32.flt
  • %CommonProgramFiles%\microsoft shared\textconv\wpft532.cnv
  • %CommonProgramFiles%\microsoft shared\textconv\wpft632.cnv
Creates the following files on removable media
  • <Drive name for removable media>:\000814251_video_01.avi
  • <Drive name for removable media>:\hypothyroidism_slides.pptx
  • <Drive name for removable media>:\ksearch_esa_talk.ppt
  • <Drive name for removable media>:\file1.ppt
  • <Drive name for removable media>:\sacs_presentation_sacs_qep_improving_rt_education_final.ppt
  • <Drive name for removable media>:\accountsreceivable.ppt
  • <Drive name for removable media>:\ppswamp.ppt
  • <Drive name for removable media>:\writingcompletesarnarrative_1103.ppt
  • <Drive name for removable media>:\proposaltemplates.ppt
  • <Drive name for removable media>:\sim_gametheory_to_finance.ppt
  • <Drive name for removable media>:\metac.ppt
  • <Drive name for removable media>:\dissolveanother.png
  • <Drive name for removable media>:\cleanlyrics.png
  • <Drive name for removable media>:\breakpoint.png
  • <Drive name for removable media>:\tunpersonalca1.pem
  • <Drive name for removable media>:\irgeek.pem
  • <Drive name for removable media>:\systisoft.pem
  • <Drive name for removable media>:\server.pem
  • <Drive name for removable media>:\ck.pem
  • <Drive name for removable media>:\10thingscondoms.pdf
  • <Drive name for removable media>:\lom602.pdf
  • <Drive name for removable media>:\2015-02-patients-topic-work-related-asthma-jobs.pdf
  • <Drive name for removable media>:\ff_ot_user_guide.pdf
  • <Drive name for removable media>:\2015-02-worms-nanoparticle-toxicity.pdf
  • <Drive name for removable media>:\clip_480_5sec_6mbps_h264.mp4
  • <Drive name for removable media>:\video_1.mp4
  • <Drive name for removable media>:\stoc13_ml_quoc_le.pptx
  • <Drive name for removable media>:\asaprojectcompetition.pptx
  • <Drive name for removable media>:\price.zip
  • <Drive name for removable media>:\removedtitles_records.zip
  • <Drive name for removable media>:\excel_example.zip
  • <Drive name for removable media>:\2013_smccc_competition_points_jul2013.xlsx
  • <Drive name for removable media>:\highly_cited_2001.xlsx
  • <Drive name for removable media>:\trtf_matrix2012_oct.xlsx
  • <Drive name for removable media>:\disclosuredetails.xlsx
  • <Drive name for removable media>:\subjectclassification.xls
  • <Drive name for removable media>:\productos.xls
  • <Drive name for removable media>:\calculatorworksheet.xls
  • <Drive name for removable media>:\guide_reorganization_mapping.xls
  • <Drive name for removable media>:\removedtitles_records.xls
  • <Drive name for removable media>:\3.jpeg
  • <Drive name for removable media>:\passport_pal.wmv
  • <Drive name for removable media>:\babyboymaintonotesbackground_pal.wmv
  • <Drive name for removable media>:\phytoremediation.rtf
  • <Drive name for removable media>:\router_manual.rtf
  • <Drive name for removable media>:\military_callsigns_0311.rtf
  • <Drive name for removable media>:\krsweden.rtf
  • <Drive name for removable media>:\skos.rdf
  • <Drive name for removable media>:\digest.rdf
  • <Drive name for removable media>:\swc_2009-03-02.rdf
  • <Drive name for removable media>:\schema.rdf
  • <Drive name for removable media>:\20140114.rdf
  • <Drive name for removable media>:\51.mp4
  • <Drive name for removable media>:\clip_1080_5sec_10mbps_h264.mp4
  • <Drive name for removable media>:\d0068197bb5a41fea16a220c45390606.mp4
  • <Drive name for removable media>:\winmine.exe
  • <Drive name for removable media>:\glidescope_review_rev_010.docx
  • <Drive name for removable media>:\holycrosschurchinstructions.docx
  • <Drive name for removable media>:\adhd_and_obesity.docx
  • <Drive name for removable media>:\aoc_saq_d_v3_merchant.docx
  • <Drive name for removable media>:\thlps_keeper_mayer_1965.docx
  • <Drive name for removable media>:\issi2013_template_for_posters.docx
  • <Drive name for removable media>:\applicantform_en.doc
  • <Drive name for removable media>:\february_catalogue__2015.doc
  • <Drive name for removable media>:\cveuropeo.doc
  • <Drive name for removable media>:\ovp25012015.doc
  • <Drive name for removable media>:\sdksampleunprivdeveloper.cer
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer
  • <Drive name for removable media>:\pmd.cer
  • <Drive name for removable media>:\contosoroot_1.cer
  • <Drive name for removable media>:\sdkfailsafeemulator.cer
  • <Drive name for removable media>:\dashborder_96.bmp
  • <Drive name for removable media>:\tileimage.bmp
  • <Drive name for removable media>:\dialmap.bmp
  • <Drive name for removable media>:\dial.bmp
  • <Drive name for removable media>:\archer.avi
  • <Drive name for removable media>:\correct.avi
  • <Drive name for removable media>:\notepad.exe
  • <Drive name for removable media>:\dotnetfx45_full_setup.exe
  • <Drive name for removable media>:\skypesetup.exe
  • <Drive name for removable media>:\utorrent.exe
  • <Drive name for removable media>:\firefly1.mov
  • <Drive name for removable media>:\wrar520.exe
  • <Drive name for removable media>:\dag2_panel1_320_ref.mov
  • <Drive name for removable media>:\spanner.mov
  • <Drive name for removable media>:\region-north-karelia.jpg
  • <Drive name for removable media>:\3.jpg
  • <Drive name for removable media>:\210252809.jpg
  • <Drive name for removable media>:\2.jpg
  • <Drive name for removable media>:\parnas_01.jpeg
  • <Drive name for removable media>:\4f0bf7ff71f28.jpeg
  • <Drive name for removable media>:\2.jpeg
  • <Drive name for removable media>:\168.jpeg
  • <Drive name for removable media>:\price030215.xls
  • <Drive name for removable media>:\calculatorworksheet.zip
  • <Drive name for removable media>:\ituneshelpunavailable.html
  • <Drive name for removable media>:\adadsi.html
  • <Drive name for removable media>:\browse.html
  • <Drive name for removable media>:\howto-index.html
  • <Drive name for removable media>:\iisstart.html
  • <Drive name for removable media>:\alert.html
  • <Drive name for removable media>:\alert.htm
  • <Drive name for removable media>:\trivial-merge.htm
  • <Drive name for removable media>:\ituneshelpunavailable.htm
  • <Drive name for removable media>:\garden.htm
  • <Drive name for removable media>:\64bit_notes.htm
  • <Drive name for removable media>:\pushkin.jpeg
  • <Drive name for removable media>:\#decrypt my files#.html
Modifies file system
Creates the following files
  • %APPDATA%\dp\runasadmin.dp
  • %CommonProgramFiles%\microsoft shared\themes14\level\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\network\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\papyrus\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\pixel\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\profile\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\quad\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\radial\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\refined\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\ricepapr\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\ripple\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\rmnsque\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\translat\esen\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\layers\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\journal\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\sonora\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\spring\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\strtedge\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\studio\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\sumipntg\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\water\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\watermar\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\translat\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\translat\arfr\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\translat\enes\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\translat\enfr\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\satin\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\slate\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\smart tag\1033\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\sky\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\boldstri\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\smart tag\lists\1033\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\source engine\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\stationery\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\textconv\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\textconv\en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\aftrnoon\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\arctic\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\axis\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\blends\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\bluecalm\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\ice\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\iris\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\indust\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\canyon\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\capsules\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\cascade\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\compass\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\concrete\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\deepblue\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\echo\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\eclipse\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\edge\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\evrgreen\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\expeditn\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\blueprnt\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\themes14\breeze\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\smart tag\lists\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\translat\frar\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\vba\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\babyboy\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\babygirl\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\flippage\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\full\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\huecycle\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\layeredtitles\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\memories\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\oldage\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\performance\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\en-us\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\pets\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\resizingpanels\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\shatter\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\specialoccasion\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\sports\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\stacking\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\travel\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\videowall\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\vignette\#decrypt my files#.html
  • %ProgramFiles%\internet explorer\#decrypt my files#.html
  • %ProgramFiles%\internet explorer\en-us\#decrypt my files#.html
  • %ProgramFiles%\internet explorer\signup\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\push\#decrypt my files#.html
  • %ProgramFiles%\dvd maker\shared\dvdstyles\rectangles\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\triedit\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\translat\fren\#decrypt my files#.html
  • %CommonProgramFiles%\system\ole db\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\vba\vba7\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\vba\vba7\1033\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\vc\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\vgx\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\vsto\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\1033\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\web folders\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\web folders\1033\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\web server extensions\#decrypt my files#.html
  • %CommonProgramFiles%\system\ole db\en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\triedit\en-us\#decrypt my files#.html
  • %ProgramFiles%\dp\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\#decrypt my files#.html
  • %CommonProgramFiles%\speechengines\#decrypt my files#.html
  • %CommonProgramFiles%\speechengines\microsoft\#decrypt my files#.html
  • %CommonProgramFiles%\system\#decrypt my files#.html
  • %CommonProgramFiles%\system\ado\#decrypt my files#.html
  • %CommonProgramFiles%\system\ado\en-us\#decrypt my files#.html
  • %CommonProgramFiles%\system\en-us\#decrypt my files#.html
  • %CommonProgramFiles%\system\msadc\#decrypt my files#.html
  • %CommonProgramFiles%\system\msadc\en-us\#decrypt my files#.html
  • %CommonProgramFiles%\system\msmapi\#decrypt my files#.html
  • %CommonProgramFiles%\system\msmapi\1033\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\1033\#decrypt my files#.html
  • %CommonProgramFiles%\services\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\smart tag\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\proof\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\#decrypt my files#.html
  • C:\perflogs\#decrypt my files#.html
  • C:\perflogs\admin\#decrypt my files#.html
  • %ProgramFiles%\#decrypt my files#.html
  • %CommonProgramFiles%\#decrypt my files#.html
  • %CommonProgramFiles%\designer\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\dw\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\equation\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\equation\1033\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fi-fi\#decrypt my files#.html
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\help\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\ar-sa\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\bg-bg\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\cs-cz\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\da-dk\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\de-de\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\el-gr\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\es-es\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\et-ee\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\filters\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\euro\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\grphflt\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\#decrypt my files#.html
  • %HOMEPATH%\documents\decryptioninfo.auth
  • %ProgramFiles%\dp\decryptioninfo.auth
  • %APPDATA%\dp\dp_main.exe
  • <Current directory>\#decrypt my files#.html
  • D:\#decrypt my files#.html
  • D:\$recycle.bin\#decrypt my files#.html
  • D:\$recycle.bin\s-1-5-21-1238866942-1249195528-555854008-1000\#decrypt my files#.html
  • C:\#decrypt my files#.html
  • C:\$recycle.bin\#decrypt my files#.html
  • C:\$recycle.bin\s-1-5-21-1238866942-1249195528-555854008-1000\#decrypt my files#.html
  • C:\documents and settings\#decrypt my files#.html
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fr-fr\#decrypt my files#.html
  • <Current directory>\id.dp
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\#decrypt my files#.html
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\#decrypt my files#.html
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\#decrypt my files#.html
  • C:\msocache\#decrypt my files#.html
  • C:\kms\#decrypt my files#.html
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\1033\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\zh-cn\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\msclientdatamgr\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\msinfo\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\msinfo\en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\1033\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\cultures\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\access.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\excel.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\groove.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\uk-ua\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\th-th\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\zh-tw\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\infopath.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\onenote.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\outlook.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\powerpoint.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.en\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.es\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.fr\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proofing.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proplus\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\publisher.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\word.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office32.en-us\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office32.ww\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\tr-tr\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\sv-se\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\auxpad\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\numbers\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskmenu\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\osknumpad\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskpred\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\symbols\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\web\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\he-il\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\hr-hr\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\hu-hu\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\hwrcustomization\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\it-it\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\keypad\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\ja-jp\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\lt-lt\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\lv-lv\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\nb-no\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\nl-nl\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\pl-pl\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\pt-br\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\pt-pt\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\ro-ro\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\ru-ru\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\sk-sk\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\sl-si\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\sr-latn-cs\#decrypt my files#.html
  • %CommonProgramFiles%\microsoft shared\ink\ko-kr\#decrypt my files#.html
  • %ProgramFiles%\java\#decrypt my files#.html
  • %ProgramFiles%\java\jre1.8.0_45\#decrypt my files#.html
Moves the following files
  • from %ProgramFiles%\desktop.ini to %ProgramFiles%\desktop.ini[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\net.dll to %ProgramFiles%\java\jre1.8.0_45\bin\net.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\msvcr100.dll to %ProgramFiles%\java\jre1.8.0_45\bin\msvcr100.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\mlib_image.dll to %ProgramFiles%\java\jre1.8.0_45\bin\mlib_image.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\management.dll to %ProgramFiles%\java\jre1.8.0_45\bin\management.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\lcms.dll to %ProgramFiles%\java\jre1.8.0_45\bin\lcms.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\ktab.exe to %ProgramFiles%\java\jre1.8.0_45\bin\ktab.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\klist.exe to %ProgramFiles%\java\jre1.8.0_45\bin\klist.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\kinit.exe to %ProgramFiles%\java\jre1.8.0_45\bin\kinit.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\keytool.exe to %ProgramFiles%\java\jre1.8.0_45\bin\keytool.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\kcms.dll to %ProgramFiles%\java\jre1.8.0_45\bin\kcms.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jsoundds.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jsoundds.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jsound.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jsound.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jsdt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jsdt.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jpeg.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jpeg.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jp2ssv.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jp2ssv.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jp2native.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jp2native.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jp2launcher.exe to %ProgramFiles%\java\jre1.8.0_45\bin\jp2launcher.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jp2iexp.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jp2iexp.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jli.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jli.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\nio.dll to %ProgramFiles%\java\jre1.8.0_45\bin\nio.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\orbd.exe to %ProgramFiles%\java\jre1.8.0_45\bin\orbd.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\w2k_lsa_auth.dll to %ProgramFiles%\java\jre1.8.0_45\bin\w2k_lsa_auth.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\pack200.exe to %ProgramFiles%\java\jre1.8.0_45\bin\pack200.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\verify.dll to %ProgramFiles%\java\jre1.8.0_45\bin\verify.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\unpack200.exe to %ProgramFiles%\java\jre1.8.0_45\bin\unpack200.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\unpack.dll to %ProgramFiles%\java\jre1.8.0_45\bin\unpack.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\tnameserv.exe to %ProgramFiles%\java\jre1.8.0_45\bin\tnameserv.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\t2k.dll to %ProgramFiles%\java\jre1.8.0_45\bin\t2k.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\sunmscapi.dll to %ProgramFiles%\java\jre1.8.0_45\bin\sunmscapi.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\sunec.dll to %ProgramFiles%\java\jre1.8.0_45\bin\sunec.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\ssvagent.exe to %ProgramFiles%\java\jre1.8.0_45\bin\ssvagent.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\ssv.dll to %ProgramFiles%\java\jre1.8.0_45\bin\ssv.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\splashscreen.dll to %ProgramFiles%\java\jre1.8.0_45\bin\splashscreen.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\servertool.exe to %ProgramFiles%\java\jre1.8.0_45\bin\servertool.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\rmiregistry.exe to %ProgramFiles%\java\jre1.8.0_45\bin\rmiregistry.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\rmid.exe to %ProgramFiles%\java\jre1.8.0_45\bin\rmid.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\resource.dll to %ProgramFiles%\java\jre1.8.0_45\bin\resource.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\prism_sw.dll to %ProgramFiles%\java\jre1.8.0_45\bin\prism_sw.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\prism_es2.dll to %ProgramFiles%\java\jre1.8.0_45\bin\prism_es2.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\prism_d3d.dll to %ProgramFiles%\java\jre1.8.0_45\bin\prism_d3d.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\prism_common.dll to %ProgramFiles%\java\jre1.8.0_45\bin\prism_common.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\policytool.exe to %ProgramFiles%\java\jre1.8.0_45\bin\policytool.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jjs.exe to %ProgramFiles%\java\jre1.8.0_45\bin\jjs.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\npt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\npt.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jfxwebkit.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jfxwebkit.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\gstreamer-lite.dll to %ProgramFiles%\java\jre1.8.0_45\bin\gstreamer-lite.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\glass.dll to %ProgramFiles%\java\jre1.8.0_45\bin\glass.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\fxplugins.dll to %ProgramFiles%\java\jre1.8.0_45\bin\fxplugins.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\fontmanager.dll to %ProgramFiles%\java\jre1.8.0_45\bin\fontmanager.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\eula.dll to %ProgramFiles%\java\jre1.8.0_45\bin\eula.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\dt_socket.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dt_socket.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\dt_shmem.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dt_shmem.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\deploy.dll to %ProgramFiles%\java\jre1.8.0_45\bin\deploy.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\decora_sse.dll to %ProgramFiles%\java\jre1.8.0_45\bin\decora_sse.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\dcpr.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dcpr.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\bci.dll to %ProgramFiles%\java\jre1.8.0_45\bin\bci.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\awt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\awt.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\welcome.html to %ProgramFiles%\java\jre1.8.0_45\welcome.html[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme.txt to %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme.txt[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt to %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\release to %ProgramFiles%\java\jre1.8.0_45\release[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\readme.txt to %ProgramFiles%\java\jre1.8.0_45\readme.txt[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\license to %ProgramFiles%\java\jre1.8.0_45\license[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\copyright to %ProgramFiles%\java\jre1.8.0_45\copyright[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\internet explorer\signup\install.ins to %ProgramFiles%\internet explorer\signup\install.ins[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\glib-lite.dll to %ProgramFiles%\java\jre1.8.0_45\bin\glib-lite.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\hprof.dll to %ProgramFiles%\java\jre1.8.0_45\bin\hprof.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jfr.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jfr.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\instrument.dll to %ProgramFiles%\java\jre1.8.0_45\bin\instrument.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jdwp.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jdwp.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jawtaccessbridge-64.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jawtaccessbridge-64.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jawt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jawt.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\java_crw_demo.dll to %ProgramFiles%\java\jre1.8.0_45\bin\java_crw_demo.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\javaws.exe to %ProgramFiles%\java\jre1.8.0_45\bin\javaws.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe to %ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\javafx_iio.dll to %ProgramFiles%\java\jre1.8.0_45\bin\javafx_iio.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\javafx_font_t2k.dll to %ProgramFiles%\java\jre1.8.0_45\bin\javafx_font_t2k.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\javafx_font.dll to %ProgramFiles%\java\jre1.8.0_45\bin\javafx_font.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.exe to %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.cpl to %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.cpl[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\javaaccessbridge-64.dll to %ProgramFiles%\java\jre1.8.0_45\bin\javaaccessbridge-64.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\java.exe to %ProgramFiles%\java\jre1.8.0_45\bin\java.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\java.dll to %ProgramFiles%\java\jre1.8.0_45\bin\java.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\java-rmi.exe to %ProgramFiles%\java\jre1.8.0_45\bin\java-rmi.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jabswitch.exe to %ProgramFiles%\java\jre1.8.0_45\bin\jabswitch.exe[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jaas_nt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jaas_nt.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\j2pkcs11.dll to %ProgramFiles%\java\jre1.8.0_45\bin\j2pkcs11.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\j2pcsc.dll to %ProgramFiles%\java\jre1.8.0_45\bin\j2pcsc.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\jfxmedia.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jfxmedia.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
  • from %ProgramFiles%\java\jre1.8.0_45\bin\windowsaccessbridge-64.dll to %ProgramFiles%\java\jre1.8.0_45\bin\windowsaccessbridge-64.dll[id-t6tizhwx].[ghzsr@onionmail.org].lf
Modifies the following files
  • D:\install.log
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\proplusww.msi
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\pkeyconfig-office.xrm-ms
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\owow32ww.cab
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.msi
  • C:\kms\kms_vl_all_aio_debug.log
  • C:\kms\kms_vl_all_aio.cmd
  • C:\$recycle.bin\s-1-5-21-1238866942-1249195528-555854008-1000\desktop.ini
  • <Drive name for removable media>:\asaprojectcompetition.pptx
  • <Drive name for removable media>:\stoc13_ml_quoc_le.pptx
  • <Drive name for removable media>:\hypothyroidism_slides.pptx
  • <Drive name for removable media>:\applicantform_en.doc
  • <Drive name for removable media>:\february_catalogue__2015.doc
  • <Drive name for removable media>:\cveuropeo.doc
  • <Drive name for removable media>:\ovp25012015.doc
  • <Drive name for removable media>:\sdksampleunprivdeveloper.cer
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer
  • <Drive name for removable media>:\pmd.cer
  • <Drive name for removable media>:\contosoroot_1.cer
  • <Drive name for removable media>:\sdkfailsafeemulator.cer
  • <Drive name for removable media>:\dashborder_96.bmp
  • <Drive name for removable media>:\tileimage.bmp
  • <Drive name for removable media>:\dialmap.bmp
  • <Drive name for removable media>:\dial.bmp
  • <Drive name for removable media>:\archer.avi
  • <Drive name for removable media>:\correct.avi
  • <Drive name for removable media>:\000814251_video_01.avi
  • D:\$recycle.bin\s-1-5-21-1238866942-1249195528-555854008-1000\desktop.ini
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\propsww.cab
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\propsww2.cab
Modifies multiple files.
Modifies user data files (Trojan.Encoder).
Miscellaneous
Executes the following
  • '<SYSTEM32>\cmd.exe' /C sc delete VSS
  • '<SYSTEM32>\sc.exe' delete VSS

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке