Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.Encoder.32544

Added to the Dr.Web virus database: 2020-09-12

Virus description added:

Technical Information

To ensure autorun and distribution
Creates the following files on removable media
  • <Drive name for removable media>:\correct.avi
  • <Drive name for removable media>:\productos.zip
  • <Drive name for removable media>:\2013_smccc_competition_points_jul2013.xlsx
  • <Drive name for removable media>:\cee_mmsprogram_summary_public.xlsx
  • <Drive name for removable media>:\national_autism_preparation_programs.xlsx
  • <Drive name for removable media>:\fiche_inscription_2015.zip
  • <Drive name for removable media>:\productos.xls
  • <Drive name for removable media>:\ksearch_esa_talk.ppt
  • <Drive name for removable media>:\writingcompletesarnarrative_1103.ppt
  • <Drive name for removable media>:\proposaltemplates.ppt
  • <Drive name for removable media>:\bg_search_box.png
  • <Drive name for removable media>:\arrow-down.png
  • <Drive name for removable media>:\dissolveanother.png
  • <Drive name for removable media>:\background.png
  • <Drive name for removable media>:\cleanlyrics.png
  • <Drive name for removable media>:\calibre.png
  • <Drive name for removable media>:\block.png
  • <Drive name for removable media>:\dualectls.pdf
  • <Drive name for removable media>:\ff_ot_user_guide.pdf
  • <Drive name for removable media>:\tunpersonalca1.pem
  • <Drive name for removable media>:\irgeek.pem
  • <Drive name for removable media>:\fil_20060629111052.pdf
  • <Drive name for removable media>:\systisoft.pem
  • <Drive name for removable media>:\server.pem
  • <Drive name for removable media>:\contractualdeadlines.xls
  • <Drive name for removable media>:\excel_example.xls
  • <Drive name for removable media>:\removedtitles_records.zip
  • <Drive name for removable media>:\excel_example.zip
  • <Drive name for removable media>:\waterresourcesag.pptx
  • <Drive name for removable media>:\military_callsigns_0311.rtf
  • <Drive name for removable media>:\fungalnameauthors.rtf
  • <Drive name for removable media>:\gruenspecht_02172016.pptx
  • <Drive name for removable media>:\waterlandhealthkano.rtf
  • <Drive name for removable media>:\pandp.rtf
  • <Drive name for removable media>:\roozenedowebinar.pptx
  • <Drive name for removable media>:\middaugh_keynote.pptx
  • <Drive name for removable media>:\babyboymaintonotesbackground_pal.wmv
  • <Drive name for removable media>:\removedtitles_records.xls
  • <Drive name for removable media>:\calculatorworksheet.xls
  • <Drive name for removable media>:\router_manual.rtf
  • <Drive name for removable media>:\schema.rdf
  • <Drive name for removable media>:\skos.rdf
  • <Drive name for removable media>:\sioc.rdf
  • <Drive name for removable media>:\babyboymaintoscenesbackground.wmv
  • <Drive name for removable media>:\passport_pal.wmv
  • <Drive name for removable media>:\elvisimp.rdf
  • <Drive name for removable media>:\al.xlsx
  • <Drive name for removable media>:\guide_reorganization_mapping.xls
  • <Drive name for removable media>:\price.zip
  • <Drive name for removable media>:\1sm_price.zip
  • <Drive name for removable media>:\price030215.xls
  • <Drive name for removable media>:\calculatorworksheet.zip
  • <Drive name for removable media>:\file1.ppt
  • <Drive name for removable media>:\delongcacert.pem
  • <Drive name for removable media>:\cert.pem
  • <Drive name for removable media>:\ck_ugo.pem
  • <Drive name for removable media>:\tree_view.htm
  • <Drive name for removable media>:\trivial-merge.htm
  • <Drive name for removable media>:\advice_process.htm
  • <Drive name for removable media>:\aoc_saq_d_v3_merchant.docx
  • <Drive name for removable media>:\ovp25012015.doc
  • <Drive name for removable media>:\cveuropeo.doc
  • <Drive name for removable media>:\about.htm
  • <Drive name for removable media>:\weeklysheet1215.doc
  • <Drive name for removable media>:\thlps_keeper_mayer_1965.docx
  • <Drive name for removable media>:\hanni_umami_chapter.doc
  • <Drive name for removable media>:\lisp_success.doc
  • <Drive name for removable media>:\testcertificate.cer
  • <Drive name for removable media>:\contoso.cer
  • <Drive name for removable media>:\testee.cer
  • <Drive name for removable media>:\contoso_1.cer
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer
  • <Drive name for removable media>:\contosoroot.cer
  • <Drive name for removable media>:\dashborder_144.bmp
  • <Drive name for removable media>:\toolbar.bmp
  • <Drive name for removable media>:\tileimage.bmp
  • <Drive name for removable media>:\dashborder_96.bmp
  • <Drive name for removable media>:\cbc630-readme.txt
  • <Drive name for removable media>:\delete.avi
  • <Drive name for removable media>:\browse.html
  • <Drive name for removable media>:\trivial-merge.html
  • <Drive name for removable media>:\adadsi.html
  • <Drive name for removable media>:\tree_view.html
  • <Drive name for removable media>:\ck.pem
  • <Drive name for removable media>:\2015-02-patients-topic-work-related-asthma-jobs.pdf
  • <Drive name for removable media>:\51.mp4
  • <Drive name for removable media>:\d0068197bb5a41fea16a220c45390606.mp4
  • <Drive name for removable media>:\clip_480_5sec_6mbps_h264.mp4
  • <Drive name for removable media>:\2015-02-worms-nanoparticle-toxicity.pdf
  • <Drive name for removable media>:\scan.mov
  • <Drive name for removable media>:\etc6_m_1.mov
  • <Drive name for removable media>:\firefly1.mov
  • <Drive name for removable media>:\dag2_panel1_320_ref.mov
  • <Drive name for removable media>:\1189.jpg
  • <Drive name for removable media>:\210252809.jpg
  • <Drive name for removable media>:\region-north-karelia.jpg
  • <Drive name for removable media>:\168.jpg
  • <Drive name for removable media>:\13.jpg
  • <Drive name for removable media>:\parnas_01.jpg
  • <Drive name for removable media>:\3.jpeg
  • <Drive name for removable media>:\pushkin.jpeg
  • <Drive name for removable media>:\region-north-karelia.jpeg
  • <Drive name for removable media>:\210252809.jpeg
  • <Drive name for removable media>:\168.jpeg
  • <Drive name for removable media>:\parnas_01.jpeg
  • <Drive name for removable media>:\4f0bf7ff71f28.jpeg
  • <Drive name for removable media>:\iisstart.html
  • <Drive name for removable media>:\investmentbankca_ca8.pem
  • <Drive name for removable media>:\stoc13_ml_quoc_le.pptx
Modifies file system
Creates the following files
  • %TEMP%\ddrq2p7z.0.cs
  • C:\far2\plugins\proclist\cbc630-readme.txt
  • C:\far2\addons\colors\custom_highlighting\cbc630-readme.txt
  • C:\far2\plugins\compare\cbc630-readme.txt
  • %ProgramFiles(x86)%\microsoft office\office10\cbc630-readme.txt
  • C:\far2\plugins\align\cbc630-readme.txt
  • C:\far2\plugins\drawline\cbc630-readme.txt
  • C:\far2\plugins\autowrap\cbc630-readme.txt
  • C:\far2\plugins\emenu\cbc630-readme.txt
  • C:\far2\plugins\arclite\cbc630-readme.txt
  • C:\far2\plugins\brackets\cbc630-readme.txt
  • C:\far2\addons\macros\cbc630-readme.txt
  • C:\far2\plugins\filecase\cbc630-readme.txt
  • C:\far2\plugins\ftp\cbc630-readme.txt
  • C:\far2\addons\setup\cbc630-readme.txt
  • C:\far2\addons\shell\cbc630-readme.txt
  • C:\far2\addons\xlat\cbc630-readme.txt
  • C:\far2\addons\xlat\russian\cbc630-readme.txt
  • C:\far2\documentation\eng\cbc630-readme.txt
  • C:\far2\encyclopedia\tap\cbc630-readme.txt
  • C:\far2\documentation\rus\cbc630-readme.txt
  • C:\far2\plugins\farcmds\cbc630-readme.txt
  • %APPDATA%\icqm\icq\smiles\cbc630-readme.txt
  • C:\far2\addons\colors\cbc630-readme.txt
  • C:\far2\addons\colors\default_highlighting\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\big bento\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\plugins\avs\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\plugins\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\bento\window\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\bento\scripts\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\bento\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\big bento\about\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\microsoft.vc90.crt\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\system\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\components\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\protos\mra\util\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\cbc630-readme.txt
  • %ProgramFiles(x86)%\opera\assets\cbc630-readme.txt
  • C:\far2\plugins\network\cbc630-readme.txt
  • C:\far2\plugins\editcase\cbc630-readme.txt
  • C:\far2\plugins\tmppanel\cbc630-readme.txt
  • %ProgramFiles(x86)%\opera\29.0.1795.47\cbc630-readme.txt
  • %ALLUSERSPROFILE%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\plugins\avs\community picks\cbc630-readme.txt
  • %ProgramFiles%\winrar\cbc630-readme.txt
  • %ALLUSERSPROFILE%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\cbc630-readme.txt
  • %ProgramFiles(x86)%\opera\cbc630-readme.txt
  • %ProgramFiles(x86)%\mirc\cbc630-readme.txt
  • C:\far2\fexcept\cbc630-readme.txt
  • C:\far2\addons\cbc630-readme.txt
  • C:\far2\encyclopedia\cbc630-readme.txt
  • C:\totalcmd\cbc630-readme.txt
  • C:\far2\cbc630-readme.txt
  • D:\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\cbc630-readme.txt
  • %TEMP%\se3lqkki.dll
  • %TEMP%\cscd73b.tmp
  • %TEMP%\se3lqkki.out
  • %TEMP%\se3lqkki.cmdline
  • %TEMP%\se3lqkki.0.cs
  • %TEMP%\ddrq2p7z.dll
  • %TEMP%\rescba8.tmp
  • %TEMP%\csccb88.tmp
  • %TEMP%\ddrq2p7z.out
  • %TEMP%\ddrq2p7z.cmdline
  • %TEMP%\resd74c.tmp
  • %ProgramFiles(x86)%\steam\cbc630-readme.txt
  • %ALLUSERSPROFILE%\cbc630-readme.txt
  • %ProgramFiles(x86)%\msbuild\cbc630-readme.txt
  • %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\cbc630-readme.txt
  • %APPDATA%\icqm\icq\smiles\flash\cbc630-readme.txt
  • %APPDATA%\icqm\icq\database\cbc630-readme.txt
  • %APPDATA%\icq-profile\update\cbc630-readme.txt
  • %APPDATA%\icq-profile\cbc630-readme.txt
  • %APPDATA%\icq-profile\base\cbc630-readme.txt
  • %APPDATA%\ghisler\cbc630-readme.txt
  • %APPDATA%\adobe\logtransport2\cbc630-readme.txt
  • %APPDATA%\adobe\acrobat\dc\cbc630-readme.txt
  • %APPDATA%\adobe\acrobat\dc\security\cbc630-readme.txt
  • %APPDATA%\adobe\acrobat\dc\preferences\cbc630-readme.txt
  • %HOMEPATH%\cbc630-readme.txt
  • %APPDATA%\adobe\acrobat\dc\jscache\cbc630-readme.txt
  • C:\totalcmd\language\cbc630-readme.txt
  • %ProgramFiles%\firefox\components\cbc630-readme.txt
  • %ProgramFiles%\firefox\cbc630-readme.txt
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\cbc630-readme.txt
  • %ProgramFiles%\foxit\cbc630-readme.txt
  • %ProgramFiles(x86)%\k-lite codec pack\cbc630-readme.txt
  • %ALLUSERSPROFILE%\microsoft help\cbc630-readme.txt
  • %ALLUSERSPROFILE%\microsoft toolkit\cbc630-readme.txt
  • %ALLUSERSPROFILE%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\big bento\scripts\cbc630-readme.txt
Deletes the following files
  • %TEMP%\rescba8.tmp
  • %TEMP%\csccb88.tmp
  • %TEMP%\ddrq2p7z.out
  • %TEMP%\ddrq2p7z.dll
  • %TEMP%\ddrq2p7z.pdb
  • %TEMP%\ddrq2p7z.0.cs
  • %TEMP%\ddrq2p7z.cmdline
  • %TEMP%\resd74c.tmp
  • %TEMP%\cscd73b.tmp
  • %TEMP%\se3lqkki.0.cs
  • %TEMP%\se3lqkki.out
  • %TEMP%\se3lqkki.dll
  • %TEMP%\se3lqkki.cmdline
  • %TEMP%\se3lqkki.pdb
Moves the following files
  • from %ProgramFiles(x86)%\mirc\ircintro.chm to %ProgramFiles(x86)%\mirc\2bb660311f0a.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_beejive.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\f2245cd013b5a6a.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-tr-tr.wlz to %ProgramFiles(x86)%\winamp\lang\f19229dc69e8c09c.cbc630
  • from %ProgramFiles(x86)%\winamp\system\aacdec.w5s to %ProgramFiles(x86)%\winamp\system\ec7d95c617.cbc630
  • from %ProgramFiles(x86)%\winamp\system\jpeg.w5s to %ProgramFiles(x86)%\winamp\system\629d917b.cbc630
  • from %ProgramFiles(x86)%\winamp\system\jnetlib.w5s to %ProgramFiles(x86)%\winamp\system\ec535ef7f4a.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-zh-tw.wlz to %ProgramFiles(x86)%\winamp\lang\10ff26c90d50af5e.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf to %APPDATA%\icqm\icq\smiles\flash\88122dc67942898e9401.cbc630
  • from %ProgramFiles(x86)%\winamp\system\tagz.w5s to %ProgramFiles(x86)%\winamp\system\560ae514.cbc630
  • from %ProgramFiles(x86)%\winamp\system\playlist.w5s to %ProgramFiles(x86)%\winamp\system\66bce1b25d0a.cbc630
  • from %ProgramFiles(x86)%\winamp\system\adpcm.w5s to %ProgramFiles(x86)%\winamp\system\c128d7095.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-zh-cn.wlz to %ProgramFiles(x86)%\winamp\lang\1b74a789a89b604c.cbc630
  • from %ProgramFiles(x86)%\winamp\system\aacdec.wbm to %ProgramFiles(x86)%\winamp\system\bbeb5e9a7b.cbc630
  • from %ProgramFiles(x86)%\winamp\microsoft.vc90.crt\microsoft.vc90.crt.manifest to %ProgramFiles(x86)%\winamp\microsoft.vc90.crt\9d197b882735392a763cea2d70e.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-pt-br.wlz to %ProgramFiles(x86)%\winamp\lang\78998c38d4199593.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ab.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\6fe334.cbc630
  • from %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\sndtray.wav to %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\b6a2c68ecb1.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_glicq.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\e0c587ba20e08.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_adium.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\344cf5deaedbd.cbc630
  • from %ProgramFiles(x86)%\winamp\system\theora.wbm to %ProgramFiles(x86)%\winamp\system\70faaa52e0.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ai.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\e605e5.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_fring.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\e82513da22daa.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ah.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\b4ea7b.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_di_chat.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\044f8a0be16a4f0.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ag.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\68993e.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_digsby.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\46cba5e8df733e.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\af.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\5ce199.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_corepager.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\2648b64a918745cdb.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_citron.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\c25bb8b4631ff8.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ae.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\cfbd88.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_centericq.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\aaba7a4bb59cbc27a.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ad.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\66fe05.cbc630
  • from %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\_sounds.ini to %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\deb3a94f5d4.cbc630
  • from %ProgramFiles(x86)%\winamp\system\timer.w5s to %ProgramFiles(x86)%\winamp\system\8eedbeefd.cbc630
  • from %ProgramFiles(x86)%\qip 2012\protos\mra\util\qip2mra.ini to %ProgramFiles(x86)%\qip 2012\protos\mra\util\758ecd7e939.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-sv-se.wlz to %ProgramFiles(x86)%\winamp\lang\f92c613388d1c8e7.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\aa.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\e810b6.cbc630
  • from %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\sndservermsg.wav to %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\190e469ca82e277d.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\aj.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\f5f1d4.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_hangover.png to %APPDATA%\icqm\icq\smiles\flash\ae6787eb2217b06a3.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_roses.png to %APPDATA%\icqm\icq\smiles\flash\b96cee9076c202.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_preview.png to %APPDATA%\icqm\icq\smiles\flash\7a42f35ea27e541e.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_maddog.png to %APPDATA%\icqm\icq\smiles\flash\475756f95e8debd.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_laugh.png to %APPDATA%\icqm\icq\smiles\flash\e429aa648d0bd9.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_kiss.png to %APPDATA%\icqm\icq\smiles\flash\e9616270ee54c.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_heart.png to %APPDATA%\icqm\icq\smiles\flash\21d2c2ef6e9bd1.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_girl.png to %APPDATA%\icqm\icq\smiles\flash\5fd039b70215f.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_working.png to %APPDATA%\icqm\icq\smiles\flash\8a2d196f232790f6.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_dog.png to %APPDATA%\icqm\icq\smiles\flash\bcda7e1d1b10.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_bored.png to %APPDATA%\icqm\icq\smiles\flash\60f6486cca958f.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_beer.png to %APPDATA%\icqm\icq\smiles\flash\974497907d79e.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf to %APPDATA%\icqm\icq\smiles\flash\f5122e3bccc1bbc43d.cbc630
  • from %ProgramFiles%\winrar\wincon.sfx to %ProgramFiles%\winrar\cdcfcc42ca.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf to %APPDATA%\icqm\icq\smiles\flash\1ab0f2e948b9.cbc630
  • from %ProgramFiles%\winrar\readme.txt to %ProgramFiles%\winrar\7e1a100f04.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\sorry.png to %APPDATA%\icqm\icq\smiles\flash\41f7c03ce.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf to %APPDATA%\icqm\icq\smiles\flash\334e6f7a6c90087823f.cbc630
  • from %ProgramFiles(x86)%\winamp\components\ssdp.w6c to %ProgramFiles(x86)%\winamp\components\9340ab64.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_shoot.png to %APPDATA%\icqm\icq\smiles\flash\d0f707071e27b9.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-de-de.wlz to %ProgramFiles(x86)%\winamp\lang\3ad9a094a3219b5a.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-fr-fr.wlz to %ProgramFiles(x86)%\winamp\lang\165f6234fe7f16b7.cbc630
  • from %ProgramFiles(x86)%\opera\assets\70x70logo.scale-140.png to %ProgramFiles(x86)%\opera\assets\e7e2cc9683ef953fd2fd7f0.cbc630
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\snapshot_blob.bin to %ProgramFiles(x86)%\opera\29.0.1795.47\f3831f6bd01bd654e.cbc630
  • from %ProgramFiles(x86)%\opera\assets\70x70logo.scale-100_contrast-white.png to %ProgramFiles(x86)%\opera\assets\b4a3c83ccf9e87bb83113fd5c79f22f08e91ec.cbc630
  • from %ProgramFiles(x86)%\opera\assets\70x70logo.scale-100.png to %ProgramFiles(x86)%\opera\assets\7bb60c792d33ae13a0652a0.cbc630
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\opera_autoupdate.licenses to %ProgramFiles(x86)%\opera\29.0.1795.47\85d08b78550fb857a913f6015.cbc630
  • from %ProgramFiles(x86)%\opera\assets\150x150logo.scale-80_contrast-white.png to %ProgramFiles(x86)%\opera\assets\ba051d23767df6cbb464f4b05b9b7a38054bf89.cbc630
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\opera_125_percent.pak to %ProgramFiles(x86)%\opera\29.0.1795.47\c03cdd69ae2c9ee03ec9c.cbc630
  • from %ProgramFiles(x86)%\microsoft office\office10\trigram.lex to %ProgramFiles(x86)%\microsoft office\office10\a376afd2318.cbc630
  • from %ProgramFiles(x86)%\microsoft office\office10\thdic.lex to %ProgramFiles(x86)%\microsoft office\office10\0b8093ae8.cbc630
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_bg.xml to %APPDATA%\icqm\icq\smiles\5d03e57e81df8affabf9.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf to %APPDATA%\icqm\icq\smiles\flash\c9a04082db25.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\sorry.swf to %APPDATA%\icqm\icq\smiles\flash\fba43f743.cbc630
  • from %ProgramFiles%\winrar\wincon64.sfx to %ProgramFiles%\winrar\7cc67c7909d4.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_ichat.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\eb76cdbee2f6e.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\info2.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\c1fafd2b9.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\sammy.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\221f5b943.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\nibbles.xml to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\cbb05e639c7.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\seek.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\21822e708.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\shade.png to %ProgramFiles(x86)%\winamp\skins\bento\window\6004545fa.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\llama.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\319d0e33a.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\sc_alb_art.jpg to %ProgramFiles(x86)%\winamp\skins\bento\window\67b34619fd2670.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\seekshade.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\6eed48bef7117d.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\sui.png to %ProgramFiles(x86)%\winamp\skins\bento\window\1d58dd3.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\player.png to %ProgramFiles(x86)%\winamp\skins\bento\window\f85fdc4219.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\plmenu.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\dba51a14755.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level8.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\2f30d689b9.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\notifier.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\714fd14eb151b.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\numfont.png to %ProgramFiles(x86)%\winamp\skins\bento\window\b1929f368ca.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level7.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\6c67c56bcb.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\pltime.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\df8b627a692.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_view.png to %ProgramFiles(x86)%\winamp\skins\bento\window\1b702bcf643e8.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\vis_avs.dat to %ProgramFiles(x86)%\winamp\plugins\0a97999e891.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\duo - alienated (evilrice trinity tron remix).avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\c2c730f6c1413ad5b03ccdc2fc639ecc4484672b31741c420.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\duo - alien intercourse 4.avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\4a7965458647e82e19e89e040927b.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\degnic - spirit realm (plasmoid rmx).avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\dc0b23019f6f593e053b097103951bb26e6529ac.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\degnic - helium.avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\5f962ee7735873b8c4b.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\degnic - fury (extreme remix) by fsk.avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\3135e9e9444c1eae3497d8cc333ef3a5fe2ac2c2.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\degnic - fractal (slo-mo metallic) (u).avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\8acfe426ebf0a79b17b7a9a6a9ce6be8f25049f3e4.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\scripts\albumart.maki to %ProgramFiles(x86)%\winamp\skins\big bento\scripts\15a02a2089b56.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\amphirion - ex deux mechanica.avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\2a76b317a63b8db606b6e2efcb0c1ba95.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\shadesizepos.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\58a53af7bf9f5c423.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\al.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\e2d14c.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\acid - twitchy liquid shit (mixing plastics mix by tuggummi).avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\7979ffd993c5fa90df6447682e0a4457ab5dc3c655ba1d13518a45894cf8a3ea.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\shadelinks.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\7da285cb29f48be.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\colormap.ape to %ProgramFiles(x86)%\winamp\plugins\avs\6bdfacb5a804.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ak.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\c2c58b.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\screenshot.png to %ProgramFiles(x86)%\winamp\skins\big bento\2e229822df3a90.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level6.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\6df981ec38.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level9.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\903617379c.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\notifications_fade_times.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\74b83637de82d06f9068ff45da074.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level5.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\8f17139449.cbc630
  • from %ProgramFiles%\firefox\components\webbrowser_core.xpt to %ProgramFiles%\firefox\components\7ccf18e51c0febf4771.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_icq_2000.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\156580076ef3e22f.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\display.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\cf20138d4235.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\info.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\c949e907.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\aol_radio_alb_art.jpg to %ProgramFiles(x86)%\winamp\skins\bento\window\18512d549ad703391f7b6.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\crossfade.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\4a2fd3352219c4.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\fixedsys.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\a057196f6b98.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\configtarget.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\63651fb574254ff42.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\skin.xml to %ProgramFiles(x86)%\winamp\skins\bento\bcdb9fc4.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\about_fg.jpg to %ProgramFiles(x86)%\winamp\skins\big bento\about\e8e1dc7546f8.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\configtabs.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\879fb4f13ca2737.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\scripts\mcvcore.maki to %ProgramFiles(x86)%\winamp\skins\bento\scripts\a82272539ffd.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\about.xml to %ProgramFiles(x86)%\winamp\skins\big bento\about\e6e1248fe.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\beatvisualization.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\8cf1e10ed193467c64915a.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\screenshot.png to %ProgramFiles(x86)%\winamp\skins\bento\20c4d179029d58.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\albumart.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\4a4c75b1b1c36.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\config.png to %ProgramFiles(x86)%\winamp\skins\bento\window\c1d66f9a39.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\about.maki to %ProgramFiles(x86)%\winamp\skins\big bento\about\3831ed816e.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\eq.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\94401f8.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level1.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\8a28e41ba3.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\controls.png to %ProgramFiles(x86)%\winamp\skins\bento\window\2a6c298444c3.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\mute.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\e816869f5.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level4.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\e4bda83e7a.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_options.png to %ProgramFiles(x86)%\winamp\skins\bento\window\5edd3352ac550fc9.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\mlmenu.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\b214d0a2caf.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level3.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\d1a13f8368.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_help.png to %ProgramFiles(x86)%\winamp\skins\bento\window\2e9028def53c5.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\menualign.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\dc236ecddccbf5.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level2.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\3a2eef2798.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_file.png to %ProgramFiles(x86)%\winamp\skins\bento\window\44ca90a3afb20.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\mainmenuoverlay.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\7499f8eced9de7e0f9bc.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\equalizer.png to %ProgramFiles(x86)%\winamp\skins\bento\window\9cbb593c552be.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level10.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\e71e2e15a24.cbc630
  • from %ProgramFiles(x86)%\winamp\system\xspf.w5s to %ProgramFiles(x86)%\winamp\system\a7c0c72d.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\mainmenu.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\0c1118bf84824.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_play.png to %ProgramFiles(x86)%\winamp\skins\bento\window\ef814fb4481b9.cbc630
  • from %ProgramFiles%\winrar\uninstall.lst to %ProgramFiles%\winrar\ae7e7d56a71b3.cbc630
  • from %ProgramFiles%\winrar\whatsnew.txt to %ProgramFiles%\winrar\2b257896de1a.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.png to %APPDATA%\icqm\icq\smiles\flash\d3d5a30373b8d1a477.cbc630
  • from %ProgramFiles%\firefox\components\nsurlformatter.js to %ProgramFiles%\firefox\components\b93ef694b933b2507.cbc630
  • from %ProgramFiles%\firefox\components\nsurlclassifierlistmanager.js to %ProgramFiles%\firefox\components\122d48bf239ecaa978ae2c89f4413.cbc630
  • from %ProgramFiles%\firefox\components\nsurlclassifierlib.js to %ProgramFiles%\firefox\components\380f0195d655582c32f77.cbc630
  • from %ProgramFiles%\firefox\components\nsurlclassifier.manifest to %ProgramFiles%\firefox\components\ead3bab6708f47d28787eea7.cbc630
  • from %ProgramFiles%\firefox\components\nsupdatetimermanager.manifest to %ProgramFiles%\firefox\components\a051cacba50bfa4fc32f763e3022c.cbc630
  • from %ProgramFiles%\firefox\components\nswebhandlerapp.js to %ProgramFiles%\firefox\components\8db0823f30b7d9d299.cbc630
  • from %ProgramFiles%\firefox\components\parentalcontrols.xpt to %ProgramFiles%\firefox\components\33cb47de2b417c07290e.cbc630
  • from %ProgramFiles%\firefox\components\nsupdatetimermanager.js to %ProgramFiles%\firefox\components\7664b403af765412a6c95d1.cbc630
  • from %ProgramFiles%\firefox\components\nstrytoclose.js to %ProgramFiles%\firefox\components\67b26b8a6f23d9b.cbc630
  • from %ProgramFiles%\firefox\components\nstaggingservice.js to %ProgramFiles%\firefox\components\8b0cf39188e94e60921.cbc630
  • from %ProgramFiles%\firefox\components\nssidebar.js to %ProgramFiles%\firefox\components\dae131672a71.cbc630
  • from %ProgramFiles%\firefox\components\nssetdefaultbrowser.manifest to %ProgramFiles%\firefox\components\b0986cad9cdafa43707fba51a2f4.cbc630
  • from %ProgramFiles%\firefox\components\nssetdefaultbrowser.js to %ProgramFiles%\firefox\components\fef837f23eff30084d8945.cbc630
  • from %APPDATA%\adobe\acrobat\dc\jscache\globdata to %APPDATA%\adobe\acrobat\dc\jscache\5d056b93.cbc630
  • from %ProgramFiles%\firefox\components\nsupdateservicestub.js to %ProgramFiles%\firefox\components\f621c72ede356ee6fdfc60.cbc630
  • from %ProgramFiles%\firefox\components\txexsltregexfunctions.js to %ProgramFiles%\firefox\components\6a7240b64388dc5d4a72fc45.cbc630
  • from %ProgramFiles%\firefox\components\passwordmgr.manifest to %ProgramFiles%\firefox\components\178ab56aed713eb362b2.cbc630
  • from %ProgramFiles%\firefox\components\storage_legacy.js to %ProgramFiles%\firefox\components\1408dfee2029a2f9b.cbc630
  • from %ProgramFiles%\firefox\components\storage.xpt to %ProgramFiles%\firefox\components\aa532595fcd.cbc630
  • from %ProgramFiles%\firefox\components\startupcache.xpt to %ProgramFiles%\firefox\components\83344116424013e1.cbc630
  • from %ProgramFiles%\firefox\components\spellchecker.xpt to %ProgramFiles%\firefox\components\c13adc8f0dd2361e.cbc630
  • from %ProgramFiles%\firefox\components\shistory.xpt to %ProgramFiles%\firefox\components\96586cfbf711.cbc630
  • from %ProgramFiles%\firefox\components\pref.xpt to %ProgramFiles%\firefox\components\59af4437.cbc630
  • from %ProgramFiles%\firefox\components\pluginglue.manifest to %ProgramFiles%\firefox\components\916d5f772176a6c160d.cbc630
  • from %ProgramFiles%\firefox\components\plugin.xpt to %ProgramFiles%\firefox\components\6d358c46eb.cbc630
  • from %ProgramFiles%\firefox\components\placesprotocolhandler.js to %ProgramFiles%\firefox\components\eb8defcaa20c87d564dea0cb.cbc630
  • from %ProgramFiles%\firefox\components\placescategoriesstarter.js to %ProgramFiles%\firefox\components\0a2a7558e74a9d4d79df02546e.cbc630
  • from %ProgramFiles%\firefox\components\places.xpt to %ProgramFiles%\firefox\components\9e7a626e1c.cbc630
  • from %ProgramFiles%\firefox\components\pippki.xpt to %ProgramFiles%\firefox\components\ff53dcfcbc.cbc630
  • from %ProgramFiles%\firefox\components\pipnss.xpt to %ProgramFiles%\firefox\components\ea28ce4eba.cbc630
  • from %ProgramFiles%\firefox\components\pipboot.xpt to %ProgramFiles%\firefox\components\9f3809112d3.cbc630
  • from %ProgramFiles%\firefox\components\nssearchservice.js to %ProgramFiles%\firefox\components\c0113ff3544382f918.cbc630
  • from %ProgramFiles%\firefox\readme.txt to %ProgramFiles%\firefox\62d92e5cd2.cbc630
  • from %ProgramFiles%\firefox\components\nswebhandlerapp.manifest to %ProgramFiles%\firefox\components\cd471b6a523214868ce1e8bb.cbc630
  • from %ProgramFiles%\firefox\blocklist.xml to %ProgramFiles%\firefox\fab6d7d7f36ac.cbc630
  • from %ProgramFiles%\firefox\js.log to %ProgramFiles%\firefox\faf250.cbc630
  • from %ProgramFiles(x86)%\steam\libav_h264-56.dll.md5 to %ProgramFiles(x86)%\steam\8f5d3421245f9a99e1ee1.cbc630
  • from %ProgramFiles(x86)%\opera\resources.pri to %ProgramFiles(x86)%\opera\53e1150f43c1f.cbc630
  • from %ProgramFiles(x86)%\winamp\install.ini to %ProgramFiles(x86)%\winamp\c2f302d20ae.cbc630
  • from %ProgramFiles(x86)%\winamp\paths.ini to %ProgramFiles(x86)%\winamp\db6308bbc.cbc630
  • from %ProgramFiles(x86)%\winamp\pconfig.dcf to %ProgramFiles(x86)%\winamp\38bccef1b6b.cbc630
  • from %ProgramFiles(x86)%\qip 2012\unins000.msg to %ProgramFiles(x86)%\qip 2012\fa389a727774.cbc630
  • from %ProgramFiles(x86)%\qip 2012\unins000.dat to %ProgramFiles(x86)%\qip 2012\493153dfccc0.cbc630
  • from %ProgramFiles(x86)%\opera\server_tracking_data to %ProgramFiles(x86)%\opera\5b4169bbc7793d963c53.cbc630
  • from %ProgramFiles(x86)%\opera\launcher.visualelementsmanifest.xml to %ProgramFiles(x86)%\opera\6c60984d9cfafdc26a3b0d7f5eaa2e2e760.cbc630
  • from %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat to %APPDATA%\adobe\acrobat\dc\preferences\33683db8663e55b16b716.cbc630
  • from %ProgramFiles(x86)%\opera\installation_status.xml to %ProgramFiles(x86)%\opera\b3b8e4e0056e71bbcede567.cbc630
  • from %ProgramFiles(x86)%\opera\installer_prefs.json to %ProgramFiles(x86)%\opera\3537a17aed0de6196787.cbc630
  • from %ProgramFiles(x86)%\mirc\versions.txt to %ProgramFiles(x86)%\mirc\bf6c1826b97c.cbc630
  • from %ProgramFiles(x86)%\mirc\mirc.chm to %ProgramFiles(x86)%\mirc\8e226948.cbc630
  • from %ProgramFiles(x86)%\mirc\readme.txt to %ProgramFiles(x86)%\mirc\319a091268.cbc630
  • from %ProgramFiles(x86)%\steam\libav_h264-56.dll.crypt to %ProgramFiles(x86)%\steam\fa29733654fa2ef621ae89b.cbc630
  • from %ProgramFiles(x86)%\steam\libx264-142.dll.md5 to %ProgramFiles(x86)%\steam\4e76fa2194434ab80a5.cbc630
  • from %ProgramFiles%\firefox\components\toolkitsearch.manifest to %ProgramFiles%\firefox\components\300b7c9a7c97795262e86e.cbc630
  • from %ProgramFiles(x86)%\steam\steam.exe.old to %ProgramFiles(x86)%\steam\3f9686bafc499.cbc630
  • from %ProgramFiles(x86)%\steam\libx264-142.dll.crypt to %ProgramFiles(x86)%\steam\a8f4326b5ec06317ee38a.cbc630
  • from %ProgramFiles(x86)%\winamp\whatsnew.txt to %ProgramFiles(x86)%\winamp\6b61cf7ed81e.cbc630
  • from %ProgramFiles%\firefox\crashreporter_override.ini to %ProgramFiles%\firefox\2663ba3c2773fcca56cac97fd0.cbc630
  • from %ProgramFiles%\firefox\nssdbm3.chk to %ProgramFiles%\firefox\1b5ad605106.cbc630
  • from %ProgramFiles%\firefox\platform.ini to %ProgramFiles%\firefox\be21697d3798.cbc630
  • from %ProgramFiles%\firefox\updater.ini to %ProgramFiles%\firefox\7eb6c7fdd9e.cbc630
  • from %ProgramFiles%\firefox\update.locale to %ProgramFiles%\firefox\8ea9738b40298.cbc630
  • from %ProgramFiles%\firefox\greprefs.js to %ProgramFiles%\firefox\69825418d84.cbc630
  • from %ProgramFiles%\firefox\freebl3.chk to %ProgramFiles%\firefox\30cded632d5.cbc630
  • from %ProgramFiles%\firefox\dependentlibs.list to %ProgramFiles%\firefox\63a9edc7bc1efae488.cbc630
  • from %ProgramFiles%\firefox\softokn3.chk to %ProgramFiles%\firefox\4e90ec735a29.cbc630
  • from %ProgramFiles%\firefox\chrome.manifest to %ProgramFiles%\firefox\aa233e8f6cb8c5c.cbc630
  • from %ProgramFiles%\foxit\foxit to %ProgramFiles%\foxit\6900e.cbc630
  • from %ProgramFiles%\firefox\application.ini to %ProgramFiles%\firefox\301a16ec47d6d7c.cbc630
  • from %ProgramFiles(x86)%\k-lite codec pack\unins000.dat to %ProgramFiles(x86)%\k-lite codec pack\619c834e5ed5.cbc630
  • from %ProgramFiles(x86)%\msbuild\microsoft.office.infopath.targets to %ProgramFiles(x86)%\msbuild\a1a88b230bbbd139aab105d88fb76c313.cbc630
  • from %ProgramFiles%\firefox\crashreporter.ini to %ProgramFiles%\firefox\608d3883ea9f4d7af.cbc630
  • from %ProgramFiles%\firefox\components\nsurlformatter.manifest to %ProgramFiles%\firefox\components\a553d15984733551c32ee55.cbc630
  • from %ProgramFiles%\firefox\components\txmgr.xpt to %ProgramFiles%\firefox\components\3ce70be8b.cbc630
  • from %ProgramFiles%\winrar\order.htm to %ProgramFiles%\winrar\6886b3019.cbc630
  • from %ProgramFiles%\firefox\components\zipwriter.xpt to %ProgramFiles%\firefox\components\7ff336324815b.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf to %APPDATA%\icqm\icq\smiles\flash\a435b1883831.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_cool.png to %APPDATA%\icqm\icq\smiles\flash\5ca94e6d08a0.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kisses.swf to %APPDATA%\icqm\icq\smiles\flash\d8a2f801e0.cbc630
  • from %ProgramFiles%\winrar\license.txt to %ProgramFiles%\winrar\4838edf10d3.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kisses.png to %APPDATA%\icqm\icq\smiles\flash\08d7eaff46.cbc630
  • from %ProgramFiles%\winrar\descript.ion to %ProgramFiles%\winrar\864403881fc5.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\information.swf to %APPDATA%\icqm\icq\smiles\flash\927b1c01062a80c.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\gangsta.png to %APPDATA%\icqm\icq\smiles\flash\66e8cc79f0c.cbc630
  • from %ProgramFiles%\winrar\default64.sfx to %ProgramFiles%\winrar\96bfc68b08f84.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\drako_zombie.png to %APPDATA%\icqm\icq\smiles\flash\813dbf35728ae904.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\drako_srach.png to %APPDATA%\icqm\icq\smiles\flash\b4ad80c94e1c896.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\devochka.swf to %APPDATA%\icqm\icq\smiles\flash\6b114a4f81c9.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\boo.swf to %APPDATA%\icqm\icq\smiles\flash\7fcc9a1.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\akitaka.swf to %APPDATA%\icqm\icq\smiles\flash\ad9cfbbe703.cbc630
  • from %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata to %APPDATA%\adobe\acrobat\dc\security\9e69603c7f3009265b55.cbc630
  • from %ProgramFiles%\winrar\rarnew.dat to %ProgramFiles%\winrar\ea55587f8b.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.png to %APPDATA%\icqm\icq\smiles\flash\5a73917a08f65ba.cbc630
  • from %ProgramFiles%\winrar\rar.txt to %ProgramFiles%\winrar\75e193e.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf to %APPDATA%\icqm\icq\smiles\flash\c54649c353ef3ed.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\likeu.png to %APPDATA%\icqm\icq\smiles\flash\f3fbbf397.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\laugh.swf to %APPDATA%\icqm\icq\smiles\flash\db26778b1.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\laugh.png to %APPDATA%\icqm\icq\smiles\flash\3195fcc09.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\krizis.swf to %APPDATA%\icqm\icq\smiles\flash\3e61f0f642.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\krizis.png to %APPDATA%\icqm\icq\smiles\flash\b4920ffbdb.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf to %APPDATA%\icqm\icq\smiles\flash\15eabd721c7.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_wow.png to %APPDATA%\icqm\icq\smiles\flash\03b32f5f7f4.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf to %APPDATA%\icqm\icq\smiles\flash\a2f7a453e4f3ef1.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.png to %APPDATA%\icqm\icq\smiles\flash\fca920f7b3b49bc.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf to %APPDATA%\icqm\icq\smiles\flash\a3fbcb635d835.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_obida.png to %APPDATA%\icqm\icq\smiles\flash\c82c3a03d44cb.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf to %APPDATA%\icqm\icq\smiles\flash\6a77dda624cf766.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.png to %APPDATA%\icqm\icq\smiles\flash\d5ddbba1370bee6.cbc630
  • from %ProgramFiles%\winrar\rarfiles.lst to %ProgramFiles%\winrar\01d8c20eb077.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\likeu.swf to %APPDATA%\icqm\icq\smiles\flash\844e92363.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\shadecontrol.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\24941ace3d03f4d87.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\songinfo.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\d0cecfdf8aea6.cbc630
  • from %ProgramFiles%\firefox\components\xulapp.xpt to %ProgramFiles%\firefox\components\b9e12cd3a1.cbc630
  • from %ProgramFiles%\firefox\components\uriloader.xpt to %ProgramFiles%\firefox\components\4ccead78f3405.cbc630
  • from %APPDATA%\icq-profile\installerlang.xml to %APPDATA%\icq-profile\95e2b31d9c4088480.cbc630
  • from %ProgramFiles%\firefox\components\webapps.xpt to %ProgramFiles%\firefox\components\50f31d8917c.cbc630
  • from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\2847313.cbc630
  • from %ProgramFiles%\firefox\components\url_classifier.xpt to %ProgramFiles%\firefox\components\297443427313f5b5e8.cbc630
  • from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\70b2990.cbc630
  • from %ProgramFiles%\firefox\components\urlformatter.xpt to %ProgramFiles%\firefox\components\cd2f04f6cbc8d03d.cbc630
  • from %ProgramFiles%\firefox\components\update.xpt to %ProgramFiles%\firefox\components\d961cd5290.cbc630
  • from %APPDATA%\icq-profile\update\languages.aff to %APPDATA%\icq-profile\update\abae367a55668.cbc630
  • from %APPDATA%\ghisler\wincmd.ini to %APPDATA%\ghisler\0fed482b13.cbc630
  • from %ProgramFiles%\firefox\components\unicharutil.xpt to %ProgramFiles%\firefox\components\15c8fb432b19b17.cbc630
  • from %APPDATA%\adobe\logtransport2\logtransport2.cfg to %APPDATA%\adobe\logtransport2\2a998fe207abf5223.cbc630
  • from %ProgramFiles%\firefox\components\uconv.xpt to %ProgramFiles%\firefox\components\12e4ca493.cbc630
  • from %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav to %APPDATA%\adobe\acrobat\dc\b0cbb64a1492.cbc630
  • from %APPDATA%\adobe\acrobat\dc\tmdocs.sav to %APPDATA%\adobe\acrobat\dc\901bdd809e.cbc630
  • from %ProgramFiles%\firefox\components\xuldoc.xpt to %ProgramFiles%\firefox\components\d23dbba945.cbc630
  • from %ProgramFiles%\firefox\components\xultmpl.xpt to %ProgramFiles%\firefox\components\68fee3aac63.cbc630
  • from %APPDATA%\icq-profile\update\ver.txt to %APPDATA%\icq-profile\update\5398684.cbc630
  • from %ProgramFiles%\firefox\components\webshell_idls.xpt to %ProgramFiles%\firefox\components\d66958be7f0cad91f.cbc630
  • from %ProgramFiles%\firefox\components\webbrowserpersist.xpt to %ProgramFiles%\firefox\components\ae44632b62c79e9bf399c.cbc630
  • from %ProgramFiles%\firefox\components\xpconnect.xpt to %ProgramFiles%\firefox\components\a616af0b1402c.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_xpti.xpt to %ProgramFiles%\firefox\components\1aaf5a64b82c8f.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_threads.xpt to %ProgramFiles%\firefox\components\da5e44eedc3239214.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_system.xpt to %ProgramFiles%\firefox\components\47b5646321e7bbf9.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_io.xpt to %ProgramFiles%\firefox\components\a96c96457caf.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_ds.xpt to %ProgramFiles%\firefox\components\b40efe53e515.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_components.xpt to %ProgramFiles%\firefox\components\ba6b3c2c735e17a54caf.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_base.xpt to %ProgramFiles%\firefox\components\81f7d284a3ea61.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\akitaka.png to %APPDATA%\icqm\icq\smiles\flash\08793d03711.cbc630
  • from %ProgramFiles%\firefox\components\windowwatcher.xpt to %ProgramFiles%\firefox\components\c551bdabb176b3a78.cbc630
  • from %ProgramFiles%\firefox\components\windowds.xpt to %ProgramFiles%\firefox\components\20d4a967358d.cbc630
  • from %APPDATA%\icqm\icq\database\citylist_kz.csv to %APPDATA%\icqm\icq\database\4a51ff20cac20ca.cbc630
  • from %ProgramFiles%\firefox\components\widget.xpt to %ProgramFiles%\firefox\components\020ed3de06.cbc630
  • from %APPDATA%\icqm\icq\database\citylist_en.csv to %APPDATA%\icqm\icq\database\dfed81e73c657fd.cbc630
  • from %ProgramFiles%\firefox\components\webcontentconverter.js to %ProgramFiles%\firefox\components\54add3a5eb41aad47d8086.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_icq_2002.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\9f91dd698daa4e3b.cbc630
Modifies user data files (Trojan.Encoder).
Miscellaneous
Creates and executes the following
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ddrq2p7z.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCBA8.tmp" "%TEMP%\CSCCB88.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\se3lqkki.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD74C.tmp" "%TEMP%\CSCD73B.tmp"' (with hidden window)
Executes the following
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ddrq2p7z.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCBA8.tmp" "%TEMP%\CSCCB88.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\se3lqkki.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD74C.tmp" "%TEMP%\CSCD73B.tmp"

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android