Technical Information
- %PROGRAMDATA%\data1.tmp
- C:\far2\plugins\compare\decrypt-files.txt
- C:\far2\plugins\drawline\decrypt-files.txt
- C:\far2\plugins\editcase\decrypt-files.txt
- C:\far2\plugins\emenu\decrypt-files.txt
- C:\far2\plugins\farcmds\decrypt-files.txt
- C:\far2\plugins\filecase\decrypt-files.txt
- C:\far2\plugins\ftp\decrypt-files.txt
- C:\far2\plugins\ftp\lib\decrypt-files.txt
- C:\far2\plugins\hlfviewer\decrypt-files.txt
- C:\far2\plugins\macroview\decrypt-files.txt
- C:\far2\plugins\network\decrypt-files.txt
- C:\far2\plugins\tmppanel\decrypt-files.txt
- C:\recovery\decrypt-files.txt
- C:\far2\pluginsdk\decrypt-files.txt
- C:\far2\pluginsdk\headers.c\decrypt-files.txt
- C:\far2\pluginsdk\headers.pas\decrypt-files.txt
- C:\msocache\decrypt-files.txt
- C:\perflogs\decrypt-files.txt
- C:\perflogs\admin\decrypt-files.txt
- %ProgramFiles%\decrypt-files.txt
- %ProgramFiles%\microsoft sql server compact edition\decrypt-files.txt
- %ProgramFiles%\microsoft sql server compact edition\v3.5\decrypt-files.txt
- %ProgramFiles%\microsoft sql server compact edition\v3.5\desktop\decrypt-files.txt
- %ProgramFiles(x86)%\decrypt-files.txt
- C:\far2\plugins\brackets\decrypt-files.txt
- C:\far2\plugins\proclist\decrypt-files.txt
- C:\far2\plugins\autowrap\decrypt-files.txt
- C:\far2\addons\colors\default_highlighting\decrypt-files.txt
- C:\decrypt-files.txt
- D:\decrypt-files.txt
- D:\$recycle.bin\decrypt-files.txt
- C:\$recycle.bin\decrypt-files.txt
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\decrypt-files.txt
- C:\documents and settings\decrypt-files.txt
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\decrypt-files.txt
- C:\far2\decrypt-files.txt
- C:\far2\addons\decrypt-files.txt
- C:\far2\addons\colors\decrypt-files.txt
- C:\far2\addons\colors\custom_highlighting\decrypt-files.txt
- C:\far2\addons\macros\decrypt-files.txt
- C:\far2\plugins\align\decrypt-files.txt
- C:\far2\addons\setup\decrypt-files.txt
- C:\far2\addons\shell\decrypt-files.txt
- C:\far2\addons\xlat\decrypt-files.txt
- C:\far2\addons\xlat\russian\decrypt-files.txt
- C:\far2\documentation\decrypt-files.txt
- C:\far2\documentation\eng\decrypt-files.txt
- C:\far2\documentation\rus\decrypt-files.txt
- C:\far2\encyclopedia\decrypt-files.txt
- C:\far2\encyclopedia\tap\decrypt-files.txt
- C:\far2\fexcept\decrypt-files.txt
- C:\far2\plugins\decrypt-files.txt
- C:\far2\plugins\arclite\decrypt-files.txt
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\decrypt-files.txt
- from %APPDATA%\adobe\acrobat\dc\jscache\globdata to %APPDATA%\adobe\acrobat\dc\jscache\globdata.j4tgb
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_ru.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_ru.xml.hrdryh
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_tr.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_tr.xml.lbmixco
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_ua.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_ua.xml.cjdhd
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_uz.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_uz.xml.cjdhd
- from %APPDATA%\icqm\icq\smiles\skin.txt to %APPDATA%\icqm\icq\smiles\skin.txt.giuzj
- from %APPDATA%\icqm\icq\smiles\smiles\8march\car.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\car.gif.q9ddhn
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_kz.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_kz.xml.hrdryh
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_pt.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_pt.xml.hrdryh
- from %APPDATA%\icqm\icq\smiles\smiles\8march\cat.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\cat.gif.jw42op
- from %APPDATA%\icqm\icq\smiles\smiles\8march\drink.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\drink.gif.44au3xp
- from %APPDATA%\icqm\icq\smiles\smiles\8march\flowers.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\flowers.gif.44au3xp
- from %APPDATA%\icqm\icq\smiles\smiles\8march\hug.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\hug.gif.44au3xp
- from %APPDATA%\icqm\icq\smiles\smiles\8march\joy.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\joy.gif.44au3xp
- from %APPDATA%\icqm\icq\smiles\smiles\8march\love.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\love.gif.zxh0
- from %APPDATA%\icqm\icq\smiles\smiles\8march\mad.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\mad.gif.zxh0
- from %APPDATA%\icqm\icq\smiles\smiles\8march\cookie.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\cookie.gif.jw42op
- from %APPDATA%\icqm\icq\smiles\smiles\8march\doll.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\doll.gif.jw42op
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_en.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_en.xml.0s6gs8
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_cz.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_cz.xml.fx1cd
- from %APPDATA%\icqm\icq\smiles\smiles\8march\perfume.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\perfume.gif.6f3g
- from %APPDATA%\icqm\icq\smiles\flash\mad dog.swf to %APPDATA%\icqm\icq\smiles\flash\mad dog.swf.8149y
- from %APPDATA%\icqm\icq\smiles\flash\missyou.swf to %APPDATA%\icqm\icq\smiles\flash\missyou.swf.8149y
- from %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf to %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf.75bl
- from %APPDATA%\icqm\icq\smiles\flash\rosy.swf to %APPDATA%\icqm\icq\smiles\flash\rosy.swf.75bl
- from %APPDATA%\icqm\icq\smiles\flash\serdze.swf to %APPDATA%\icqm\icq\smiles\flash\serdze.swf.75bl
- from %APPDATA%\icqm\icq\smiles\flash\skratch.swf to %APPDATA%\icqm\icq\smiles\flash\skratch.swf.dbt8p
- from %APPDATA%\icqm\icq\smiles\flash\smeh.swf to %APPDATA%\icqm\icq\smiles\flash\smeh.swf.dbt8p
- from %APPDATA%\icqm\icq\smiles\flash\sobaka.swf to %APPDATA%\icqm\icq\smiles\flash\sobaka.swf.9fpvor
- from %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf to %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf.9fpvor
- from %APPDATA%\icqm\icq\smiles\flash\sorry.swf to %APPDATA%\icqm\icq\smiles\flash\sorry.swf.2pr1c6
- from %APPDATA%\icqm\icq\smiles\flash\tank.swf to %APPDATA%\icqm\icq\smiles\flash\tank.swf.k0pzjqf
- from %APPDATA%\icqm\icq\smiles\flash\wf_love_sdaus.swf to %APPDATA%\icqm\icq\smiles\flash\wf_love_sdaus.swf.5919ash
- from %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf to %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf.xl72
- from %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf to %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf.7kfu4
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_bg.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_bg.xml.7kfu4
- from %APPDATA%\icqm\icq\smiles\smiles\8march\new_dress.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\new_dress.gif.6f3g
- from %APPDATA%\icqm\icq\smiles\flash\love_bear_kiss.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_kiss.swf.6uu1
- from %APPDATA%\icqm\icq\smiles\mrasmileslang_de.xml to %APPDATA%\icqm\icq\smiles\mrasmileslang_de.xml.0s6gs8
- from %APPDATA%\icqm\icq\smiles\flash\chillout.swf to %APPDATA%\icqm\icq\smiles\flash\chillout.swf.1ywyxr
- from %APPDATA%\icqm\icq\smiles\smiles\8march\ring.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\ring.gif.6f3g
- from %APPDATA%\icqm\icq\smiles\smiles\animated\love.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\love.gif.7apd
- from %APPDATA%\icqm\icq\smiles\smiles\animated\pistolet.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\pistolet.gif.7apd
- from %APPDATA%\icqm\icq\smiles\smiles\animated\poison.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\poison.gif.7apd
- from %APPDATA%\icqm\icq\smiles\smiles\animated\rainbow.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\rainbow.gif.vwgtz
- from %APPDATA%\icqm\icq\smiles\smiles\animated\red.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\red.gif.vwgtz
- from %APPDATA%\icqm\icq\smiles\smiles\animated\sad.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sad.gif.056ze
- from %APPDATA%\icqm\icq\smiles\smiles\animated\sing.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sing.gif.wfl2cd
- from %APPDATA%\icqm\icq\smiles\smiles\animated\skuka.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\skuka.gif.zrstlln
- from %APPDATA%\icqm\icq\smiles\smiles\animated\sleep.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\sleep.gif.9gsb
- from %APPDATA%\icqm\icq\smiles\smiles\animated\smile.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\smile.gif.nykhj
- from %APPDATA%\icqm\icq\smiles\smiles\animated\tongue.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\tongue.gif.q89yq
- from %APPDATA%\icqm\icq\smiles\smiles\animated\victory.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\victory.gif.q89yq
- from %APPDATA%\icqm\icq\smiles\smiles\animated\wonder.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\wonder.gif.1nrb04
- from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_attack.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_attack.gif.1nrb04
- from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_hand.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_hand.gif.1nrb04
- from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_lick.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_lick.gif.rbxdzt
- from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_meow.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_meow.gif.rbxdzt
- from %APPDATA%\icqm\icq\smiles\smiles\animated\kiss.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\kiss.gif.7apd
- from %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf.ltms
- from %APPDATA%\icqm\icq\smiles\flash\love_bear_rose.swf to %APPDATA%\icqm\icq\smiles\flash\love_bear_rose.swf.s0buu
- from %APPDATA%\icqm\icq\smiles\smiles\animated\gift.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gift.gif.5kvt6st
- from %APPDATA%\icqm\icq\smiles\smiles\8march\sunburn.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\sunburn.gif.cr9uh
- from %APPDATA%\icqm\icq\smiles\smiles\animated\angel.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\angel.gif.cr9uh
- from %APPDATA%\icqm\icq\smiles\smiles\animated\appl.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\appl.gif.9uhv0
- from %APPDATA%\icqm\icq\smiles\smiles\animated\beauty.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\beauty.gif.9uhv0
- from %APPDATA%\icqm\icq\smiles\smiles\animated\beer.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\beer.gif.9uhv0
- from %APPDATA%\icqm\icq\smiles\smiles\animated\blew.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\blew.gif.9uhv0
- from %APPDATA%\icqm\icq\smiles\smiles\animated\book.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\book.gif.9uhv0
- from %APPDATA%\icqm\icq\smiles\smiles\animated\could.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\could.gif.gyvsz
- from %APPDATA%\icqm\icq\smiles\smiles\animated\cry.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\cry.gif.gyvsz
- from %APPDATA%\icqm\icq\smiles\smiles\animated\dance.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\dance.gif.gyvsz
- from %APPDATA%\icqm\icq\smiles\smiles\animated\devil.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\devil.gif.gyvsz
- from %APPDATA%\icqm\icq\smiles\smiles\animated\eat.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\eat.gif.wme0ll
- from %APPDATA%\icqm\icq\smiles\smiles\animated\fight.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\fight.gif.wme0ll
- from %APPDATA%\icqm\icq\smiles\smiles\animated\fingal.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\fingal.gif.wme0ll
- from %APPDATA%\icqm\icq\smiles\smiles\animated\flowr.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\flowr.gif.wme0ll
- from %APPDATA%\icqm\icq\smiles\smiles\animated\gg.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gg.gif.knphsr9
- from %APPDATA%\icqm\icq\smiles\smiles\animated\gg2.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\gg2.gif.5kvt6st
- from %APPDATA%\icqm\icq\smiles\smiles\animated\history.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\history.gif.5kvt6st
- from %APPDATA%\icqm\icq\smiles\smiles\8march\shoes.gif to %APPDATA%\icqm\icq\smiles\smiles\8march\shoes.gif.6f3g
- from %APPDATA%\icqm\icq\smiles\flash\likeu.swf to %APPDATA%\icqm\icq\smiles\flash\likeu.swf.ltms
- from %APPDATA%\icqm\icq\smiles\flash\laugh.swf to %APPDATA%\icqm\icq\smiles\flash\laugh.swf.3fxztb4
- from %APPDATA%\icqm\icq\smiles\flash\krizis.swf to %APPDATA%\icqm\icq\smiles\flash\krizis.swf.jxirasn
- from %APPDATA%\icqm\icq\fonts\segoesc.ttf to %APPDATA%\icqm\icq\fonts\segoesc.ttf.zlfsc
- from %APPDATA%\icqm\icq\graphics\phone\agent_offline.bmp to %APPDATA%\icqm\icq\graphics\phone\agent_offline.bmp.pezt1c
- from %APPDATA%\icqm\icq\graphics\phone\agent_offline_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\agent_offline_inv.bmp.pezt1c
- from %APPDATA%\icqm\icq\graphics\phone\agent_online.bmp to %APPDATA%\icqm\icq\graphics\phone\agent_online.bmp.cw7zpe
- from %APPDATA%\icqm\icq\graphics\phone\agent_online_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\agent_online_inv.bmp.cw7zpe
- from %APPDATA%\icqm\icq\graphics\phone\icq_offline.bmp to %APPDATA%\icqm\icq\graphics\phone\icq_offline.bmp.cw7zpe
- from %APPDATA%\icqm\icq\graphics\phone\icq_offline_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\icq_offline_inv.bmp.cw7zpe
- from %APPDATA%\icqm\icq\graphics\phone\icq_online.bmp to %APPDATA%\icqm\icq\graphics\phone\icq_online.bmp.etforf
- from %APPDATA%\icqm\icq\graphics\phone\icq_online_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\icq_online_inv.bmp.etforf
- from %APPDATA%\icqm\icq\graphics\phone\phone.bmp to %APPDATA%\icqm\icq\graphics\phone\phone.bmp.etforf
- from %APPDATA%\icqm\icq\graphics\phone\phone_inv.bmp to %APPDATA%\icqm\icq\graphics\phone\phone_inv.bmp.etforf
- from %APPDATA%\icqm\icq\graphics\phone\screen-busy-mouse.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-busy-mouse.bmp.etforf
- from %APPDATA%\icqm\icq\graphics\phone\screen-busy.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-busy.bmp.etforf
- from %APPDATA%\icqm\icq\graphics\phone\screen-decline-mouse.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-decline-mouse.bmp.nxlwelz
- from %APPDATA%\icqm\icq\graphics\phone\screen-decline.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-decline.bmp.nxlwelz
- from %APPDATA%\icqm\icq\database\citylist_ua.csv to %APPDATA%\icqm\icq\database\citylist_ua.csv.re4qhy0
- from %APPDATA%\icqm\icq\database\citylist_ru.csv to %APPDATA%\icqm\icq\database\citylist_ru.csv.qzalbm
- from %APPDATA%\icqm\icq\dll\altergeo.msi to %APPDATA%\icqm\icq\dll\altergeo.msi.xgp6ud
- from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_mouse.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_mouse.gif.zhw3dv
- from %APPDATA%\icqm\icq\graphics\phone\screen-offline-inv.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-offline-inv.bmp.nxlwelz
- from %APPDATA%\icqm\icq\database\citylist_kz.csv to %APPDATA%\icqm\icq\database\citylist_kz.csv.qzalbm
- from %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat to %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat.ld2lym
- from %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata to %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata.mhtimw
- from %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\0fded5ceb68c302b1cdb2bddd9d0000e76539cb0.crl.mhtimw
- from %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl to %APPDATA%\adobe\acrobat\dc\security\crlcache\ce338828149963dcea4cd26bb86f0363b4ca0ba5.crl.mhtimw
- from %APPDATA%\adobe\acrobat\dc\tmdocs.sav to %APPDATA%\adobe\acrobat\dc\tmdocs.sav.socvzl
- from %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav to %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav.socvzl
- from %APPDATA%\adobe\logtransport2\logtransport2.cfg to %APPDATA%\adobe\logtransport2\logtransport2.cfg.g8o5wn5
- from %APPDATA%\adobe\acrobat\dc\jscache\globsettings to %APPDATA%\adobe\acrobat\dc\jscache\globsettings.vvc4u
- from %APPDATA%\ghisler\wincmd.ini to %APPDATA%\ghisler\wincmd.ini.tlfb
- from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\opt.dbs.dywgvd
- from %APPDATA%\icq-profile\installerlang.xml to %APPDATA%\icq-profile\installerlang.xml.eviicsz
- from %APPDATA%\icq-profile\update\languages.aff to %APPDATA%\icq-profile\update\languages.aff.hmnv
- from %APPDATA%\icq-profile\update\languages.dict to %APPDATA%\icq-profile\update\languages.dict.nttij
- from %APPDATA%\icq-profile\update\languages.hash to %APPDATA%\icq-profile\update\languages.hash.k8im
- from %APPDATA%\icq-profile\update\ver.txt to %APPDATA%\icq-profile\update\ver.txt.indnz
- from %APPDATA%\icqm\icq\database\citylist_en.csv to %APPDATA%\icqm\icq\database\citylist_en.csv.xj4rr
- from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\mra.dbs.bzika
- from %APPDATA%\icqm\icq\database\citylist_tr.csv to %APPDATA%\icqm\icq\database\citylist_tr.csv.re4qhy0
- from %APPDATA%\icqm\icq\smiles\smiles\animated\hungry.gif to %APPDATA%\icqm\icq\smiles\smiles\animated\hungry.gif.5kvt6st
- from %APPDATA%\icqm\icq\graphics\phone\screen-offline.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-offline.bmp.nxlwelz
- from %APPDATA%\icqm\icq\html\bg\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\bg\loading\progress_agent.gif.e247uo
- from %APPDATA%\icqm\icq\smiles\flash\drako_love.swf to %APPDATA%\icqm\icq\smiles\flash\drako_love.swf.pbwe
- from %APPDATA%\icqm\icq\smiles\flash\drako_opyatnica.swf to %APPDATA%\icqm\icq\smiles\flash\drako_opyatnica.swf.6fuc6
- from %APPDATA%\icqm\icq\smiles\flash\drako_snegyrka.swf to %APPDATA%\icqm\icq\smiles\flash\drako_snegyrka.swf.nptmo
- from %APPDATA%\icqm\icq\smiles\flash\drako_zombie.swf to %APPDATA%\icqm\icq\smiles\flash\drako_zombie.swf.g0alrk
- from %APPDATA%\icqm\icq\smiles\flash\duh.swf to %APPDATA%\icqm\icq\smiles\flash\duh.swf.2ek8b9t
- from %APPDATA%\icqm\icq\smiles\flash\gangsta.swf to %APPDATA%\icqm\icq\smiles\flash\gangsta.swf.kzbv
- from %APPDATA%\icqm\icq\smiles\flash\guby.swf to %APPDATA%\icqm\icq\smiles\flash\guby.swf.kzbv
- from %APPDATA%\icqm\icq\smiles\flash\information.swf to %APPDATA%\icqm\icq\smiles\flash\information.swf.4cay
- from %APPDATA%\icqm\icq\smiles\flash\joy.swf to %APPDATA%\icqm\icq\smiles\flash\joy.swf.7ybz9
- from %APPDATA%\icqm\icq\smiles\flash\kisses.swf to %APPDATA%\icqm\icq\smiles\flash\kisses.swf.dtt9l
- from %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf to %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf.mucfdd
- from %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf to %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf.adil
- from %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf to %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf.8efae
- from %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf to %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf.8efae
- from %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf to %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf.f6x1c6
- from %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf to %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf.15iyhi
- from %APPDATA%\icqm\icq\graphics\phone\screen-online-inv.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-online-inv.bmp.tbmjv4n
- from %APPDATA%\icqm\icq\smiles\flash\drako_koster.swf to %APPDATA%\icqm\icq\smiles\flash\drako_koster.swf.3nnf
- from %APPDATA%\icqm\icq\graphics\phone\screen-online.bmp to %APPDATA%\icqm\icq\graphics\phone\screen-online.bmp.kju6
- from %APPDATA%\icqm\icq\smiles\flash\drako_bolnoy.swf to %APPDATA%\icqm\icq\smiles\flash\drako_bolnoy.swf.j6i9zee
- from %APPDATA%\icqm\icq\database\citylist_uz.csv to %APPDATA%\icqm\icq\database\citylist_uz.csv.hwah0jy
- from %APPDATA%\icqm\icq\html\cz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\cz\loading\progress_agent.gif.tdmsf7a
- from %APPDATA%\icqm\icq\html\de\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\de\loading\progress_agent.gif.vldjt
- from %APPDATA%\icqm\icq\html\en\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\en\loading\progress_agent.gif.iz9k
- from %APPDATA%\icqm\icq\html\kz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\kz\loading\progress_agent.gif.f7o8uml
- from %APPDATA%\icqm\icq\html\pt\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\pt\loading\progress_agent.gif.3lox
- from %APPDATA%\icqm\icq\html\ru\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\ru\loading\progress_agent.gif.begean
- from %APPDATA%\icqm\icq\html\tr\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\tr\loading\progress_agent.gif.4ynk
- from %APPDATA%\icqm\icq\html\ua\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\ua\loading\progress_agent.gif.gaaldgf
- from %APPDATA%\icqm\icq\html\uz\loading\progress_agent.gif to %APPDATA%\icqm\icq\html\uz\loading\progress_agent.gif.dhte8e
- from %APPDATA%\icqm\icq\smiles\flash\akitaka.swf to %APPDATA%\icqm\icq\smiles\flash\akitaka.swf.ho1ajoo
- from %APPDATA%\icqm\icq\smiles\flash\angel.swf to %APPDATA%\icqm\icq\smiles\flash\angel.swf.3iimpmf
- from %APPDATA%\icqm\icq\smiles\flash\bad_cold.swf to %APPDATA%\icqm\icq\smiles\flash\bad_cold.swf.51x83
- from %APPDATA%\icqm\icq\smiles\flash\beback.swf to %APPDATA%\icqm\icq\smiles\flash\beback.swf.51x83
- from %APPDATA%\icqm\icq\smiles\flash\beer.swf to %APPDATA%\icqm\icq\smiles\flash\beer.swf.szidd
- from %APPDATA%\icqm\icq\smiles\flash\bodun.swf to %APPDATA%\icqm\icq\smiles\flash\bodun.swf.bcgwy
- from %APPDATA%\icqm\icq\smiles\flash\boo.swf to %APPDATA%\icqm\icq\smiles\flash\boo.swf.bcgwy
- from %APPDATA%\icqm\icq\smiles\flash\canthearu.swf to %APPDATA%\icqm\icq\smiles\flash\canthearu.swf.fdx1qv
- from %APPDATA%\icqm\icq\smiles\flash\devochka.swf to %APPDATA%\icqm\icq\smiles\flash\devochka.swf.1ywyxr
- from %APPDATA%\icqm\icq\smiles\smiles\cat\cat_paper.gif to %APPDATA%\icqm\icq\smiles\smiles\cat\cat_paper.gif.zhw3dv
- '91.##8.114.31':80
- http://91.##8.114.4/webauth/payout/ucmj.php?yt###############################
- http://91.##8.114.11/transfer/login/erxgiwxj.php?v=#############################
- http://91.##8.114.25/view/rngp.php
- http://91.##8.114.26/s.action
- '<SYSTEM32>\wbem\wmic.exe' shadowcopy delete' (with hidden window)
- '<SYSTEM32>\vssvc.exe'
- '<SYSTEM32>\svchost.exe' -k swprv