Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Encoder.32544

Added to the Dr.Web virus database: 2020-09-12

Virus description added:

Technical Information

To ensure autorun and distribution
Creates the following files on removable media
  • <Drive name for removable media>:\correct.avi
  • <Drive name for removable media>:\productos.zip
  • <Drive name for removable media>:\2013_smccc_competition_points_jul2013.xlsx
  • <Drive name for removable media>:\cee_mmsprogram_summary_public.xlsx
  • <Drive name for removable media>:\national_autism_preparation_programs.xlsx
  • <Drive name for removable media>:\fiche_inscription_2015.zip
  • <Drive name for removable media>:\productos.xls
  • <Drive name for removable media>:\ksearch_esa_talk.ppt
  • <Drive name for removable media>:\writingcompletesarnarrative_1103.ppt
  • <Drive name for removable media>:\proposaltemplates.ppt
  • <Drive name for removable media>:\bg_search_box.png
  • <Drive name for removable media>:\arrow-down.png
  • <Drive name for removable media>:\dissolveanother.png
  • <Drive name for removable media>:\background.png
  • <Drive name for removable media>:\cleanlyrics.png
  • <Drive name for removable media>:\calibre.png
  • <Drive name for removable media>:\block.png
  • <Drive name for removable media>:\dualectls.pdf
  • <Drive name for removable media>:\ff_ot_user_guide.pdf
  • <Drive name for removable media>:\tunpersonalca1.pem
  • <Drive name for removable media>:\irgeek.pem
  • <Drive name for removable media>:\fil_20060629111052.pdf
  • <Drive name for removable media>:\systisoft.pem
  • <Drive name for removable media>:\server.pem
  • <Drive name for removable media>:\contractualdeadlines.xls
  • <Drive name for removable media>:\excel_example.xls
  • <Drive name for removable media>:\removedtitles_records.zip
  • <Drive name for removable media>:\excel_example.zip
  • <Drive name for removable media>:\waterresourcesag.pptx
  • <Drive name for removable media>:\military_callsigns_0311.rtf
  • <Drive name for removable media>:\fungalnameauthors.rtf
  • <Drive name for removable media>:\gruenspecht_02172016.pptx
  • <Drive name for removable media>:\waterlandhealthkano.rtf
  • <Drive name for removable media>:\pandp.rtf
  • <Drive name for removable media>:\roozenedowebinar.pptx
  • <Drive name for removable media>:\middaugh_keynote.pptx
  • <Drive name for removable media>:\babyboymaintonotesbackground_pal.wmv
  • <Drive name for removable media>:\removedtitles_records.xls
  • <Drive name for removable media>:\calculatorworksheet.xls
  • <Drive name for removable media>:\router_manual.rtf
  • <Drive name for removable media>:\schema.rdf
  • <Drive name for removable media>:\skos.rdf
  • <Drive name for removable media>:\sioc.rdf
  • <Drive name for removable media>:\babyboymaintoscenesbackground.wmv
  • <Drive name for removable media>:\passport_pal.wmv
  • <Drive name for removable media>:\elvisimp.rdf
  • <Drive name for removable media>:\al.xlsx
  • <Drive name for removable media>:\guide_reorganization_mapping.xls
  • <Drive name for removable media>:\price.zip
  • <Drive name for removable media>:\1sm_price.zip
  • <Drive name for removable media>:\price030215.xls
  • <Drive name for removable media>:\calculatorworksheet.zip
  • <Drive name for removable media>:\file1.ppt
  • <Drive name for removable media>:\delongcacert.pem
  • <Drive name for removable media>:\cert.pem
  • <Drive name for removable media>:\ck_ugo.pem
  • <Drive name for removable media>:\tree_view.htm
  • <Drive name for removable media>:\trivial-merge.htm
  • <Drive name for removable media>:\advice_process.htm
  • <Drive name for removable media>:\aoc_saq_d_v3_merchant.docx
  • <Drive name for removable media>:\ovp25012015.doc
  • <Drive name for removable media>:\cveuropeo.doc
  • <Drive name for removable media>:\about.htm
  • <Drive name for removable media>:\weeklysheet1215.doc
  • <Drive name for removable media>:\thlps_keeper_mayer_1965.docx
  • <Drive name for removable media>:\hanni_umami_chapter.doc
  • <Drive name for removable media>:\lisp_success.doc
  • <Drive name for removable media>:\testcertificate.cer
  • <Drive name for removable media>:\contoso.cer
  • <Drive name for removable media>:\testee.cer
  • <Drive name for removable media>:\contoso_1.cer
  • <Drive name for removable media>:\sdksampleprivdeveloper.cer
  • <Drive name for removable media>:\contosoroot.cer
  • <Drive name for removable media>:\dashborder_144.bmp
  • <Drive name for removable media>:\toolbar.bmp
  • <Drive name for removable media>:\tileimage.bmp
  • <Drive name for removable media>:\dashborder_96.bmp
  • <Drive name for removable media>:\cbc630-readme.txt
  • <Drive name for removable media>:\delete.avi
  • <Drive name for removable media>:\browse.html
  • <Drive name for removable media>:\trivial-merge.html
  • <Drive name for removable media>:\adadsi.html
  • <Drive name for removable media>:\tree_view.html
  • <Drive name for removable media>:\ck.pem
  • <Drive name for removable media>:\2015-02-patients-topic-work-related-asthma-jobs.pdf
  • <Drive name for removable media>:\51.mp4
  • <Drive name for removable media>:\d0068197bb5a41fea16a220c45390606.mp4
  • <Drive name for removable media>:\clip_480_5sec_6mbps_h264.mp4
  • <Drive name for removable media>:\2015-02-worms-nanoparticle-toxicity.pdf
  • <Drive name for removable media>:\scan.mov
  • <Drive name for removable media>:\etc6_m_1.mov
  • <Drive name for removable media>:\firefly1.mov
  • <Drive name for removable media>:\dag2_panel1_320_ref.mov
  • <Drive name for removable media>:\1189.jpg
  • <Drive name for removable media>:\210252809.jpg
  • <Drive name for removable media>:\region-north-karelia.jpg
  • <Drive name for removable media>:\168.jpg
  • <Drive name for removable media>:\13.jpg
  • <Drive name for removable media>:\parnas_01.jpg
  • <Drive name for removable media>:\3.jpeg
  • <Drive name for removable media>:\pushkin.jpeg
  • <Drive name for removable media>:\region-north-karelia.jpeg
  • <Drive name for removable media>:\210252809.jpeg
  • <Drive name for removable media>:\168.jpeg
  • <Drive name for removable media>:\parnas_01.jpeg
  • <Drive name for removable media>:\4f0bf7ff71f28.jpeg
  • <Drive name for removable media>:\iisstart.html
  • <Drive name for removable media>:\investmentbankca_ca8.pem
  • <Drive name for removable media>:\stoc13_ml_quoc_le.pptx
Modifies file system
Creates the following files
  • %TEMP%\ddrq2p7z.0.cs
  • C:\far2\plugins\proclist\cbc630-readme.txt
  • C:\far2\addons\colors\custom_highlighting\cbc630-readme.txt
  • C:\far2\plugins\compare\cbc630-readme.txt
  • %ProgramFiles(x86)%\microsoft office\office10\cbc630-readme.txt
  • C:\far2\plugins\align\cbc630-readme.txt
  • C:\far2\plugins\drawline\cbc630-readme.txt
  • C:\far2\plugins\autowrap\cbc630-readme.txt
  • C:\far2\plugins\emenu\cbc630-readme.txt
  • C:\far2\plugins\arclite\cbc630-readme.txt
  • C:\far2\plugins\brackets\cbc630-readme.txt
  • C:\far2\addons\macros\cbc630-readme.txt
  • C:\far2\plugins\filecase\cbc630-readme.txt
  • C:\far2\plugins\ftp\cbc630-readme.txt
  • C:\far2\addons\setup\cbc630-readme.txt
  • C:\far2\addons\shell\cbc630-readme.txt
  • C:\far2\addons\xlat\cbc630-readme.txt
  • C:\far2\addons\xlat\russian\cbc630-readme.txt
  • C:\far2\documentation\eng\cbc630-readme.txt
  • C:\far2\encyclopedia\tap\cbc630-readme.txt
  • C:\far2\documentation\rus\cbc630-readme.txt
  • C:\far2\plugins\farcmds\cbc630-readme.txt
  • %APPDATA%\icqm\icq\smiles\cbc630-readme.txt
  • C:\far2\addons\colors\cbc630-readme.txt
  • C:\far2\addons\colors\default_highlighting\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\big bento\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\plugins\avs\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\plugins\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\bento\window\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\bento\scripts\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\bento\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\big bento\about\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\microsoft.vc90.crt\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\system\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\components\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\protos\mra\util\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\cbc630-readme.txt
  • %ProgramFiles(x86)%\opera\assets\cbc630-readme.txt
  • C:\far2\plugins\network\cbc630-readme.txt
  • C:\far2\plugins\editcase\cbc630-readme.txt
  • C:\far2\plugins\tmppanel\cbc630-readme.txt
  • %ProgramFiles(x86)%\opera\29.0.1795.47\cbc630-readme.txt
  • %ALLUSERSPROFILE%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\plugins\avs\community picks\cbc630-readme.txt
  • %ProgramFiles%\winrar\cbc630-readme.txt
  • %ALLUSERSPROFILE%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\cbc630-readme.txt
  • %ProgramFiles(x86)%\qip 2012\cbc630-readme.txt
  • %ProgramFiles(x86)%\opera\cbc630-readme.txt
  • %ProgramFiles(x86)%\mirc\cbc630-readme.txt
  • C:\far2\fexcept\cbc630-readme.txt
  • C:\far2\addons\cbc630-readme.txt
  • C:\far2\encyclopedia\cbc630-readme.txt
  • C:\totalcmd\cbc630-readme.txt
  • C:\far2\cbc630-readme.txt
  • D:\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\cbc630-readme.txt
  • %TEMP%\se3lqkki.dll
  • %TEMP%\cscd73b.tmp
  • %TEMP%\se3lqkki.out
  • %TEMP%\se3lqkki.cmdline
  • %TEMP%\se3lqkki.0.cs
  • %TEMP%\ddrq2p7z.dll
  • %TEMP%\rescba8.tmp
  • %TEMP%\csccb88.tmp
  • %TEMP%\ddrq2p7z.out
  • %TEMP%\ddrq2p7z.cmdline
  • %TEMP%\resd74c.tmp
  • %ProgramFiles(x86)%\steam\cbc630-readme.txt
  • %ALLUSERSPROFILE%\cbc630-readme.txt
  • %ProgramFiles(x86)%\msbuild\cbc630-readme.txt
  • %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\cbc630-readme.txt
  • %APPDATA%\icqm\icq\smiles\flash\cbc630-readme.txt
  • %APPDATA%\icqm\icq\database\cbc630-readme.txt
  • %APPDATA%\icq-profile\update\cbc630-readme.txt
  • %APPDATA%\icq-profile\cbc630-readme.txt
  • %APPDATA%\icq-profile\base\cbc630-readme.txt
  • %APPDATA%\ghisler\cbc630-readme.txt
  • %APPDATA%\adobe\logtransport2\cbc630-readme.txt
  • %APPDATA%\adobe\acrobat\dc\cbc630-readme.txt
  • %APPDATA%\adobe\acrobat\dc\security\cbc630-readme.txt
  • %APPDATA%\adobe\acrobat\dc\preferences\cbc630-readme.txt
  • %HOMEPATH%\cbc630-readme.txt
  • %APPDATA%\adobe\acrobat\dc\jscache\cbc630-readme.txt
  • C:\totalcmd\language\cbc630-readme.txt
  • %ProgramFiles%\firefox\components\cbc630-readme.txt
  • %ProgramFiles%\firefox\cbc630-readme.txt
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\cbc630-readme.txt
  • %ProgramFiles%\foxit\cbc630-readme.txt
  • %ProgramFiles(x86)%\k-lite codec pack\cbc630-readme.txt
  • %ALLUSERSPROFILE%\microsoft help\cbc630-readme.txt
  • %ALLUSERSPROFILE%\microsoft toolkit\cbc630-readme.txt
  • %ALLUSERSPROFILE%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\cbc630-readme.txt
  • %ProgramFiles(x86)%\winamp\skins\big bento\scripts\cbc630-readme.txt
Deletes the following files
  • %TEMP%\rescba8.tmp
  • %TEMP%\csccb88.tmp
  • %TEMP%\ddrq2p7z.out
  • %TEMP%\ddrq2p7z.dll
  • %TEMP%\ddrq2p7z.pdb
  • %TEMP%\ddrq2p7z.0.cs
  • %TEMP%\ddrq2p7z.cmdline
  • %TEMP%\resd74c.tmp
  • %TEMP%\cscd73b.tmp
  • %TEMP%\se3lqkki.0.cs
  • %TEMP%\se3lqkki.out
  • %TEMP%\se3lqkki.dll
  • %TEMP%\se3lqkki.cmdline
  • %TEMP%\se3lqkki.pdb
Moves the following files
  • from %ProgramFiles(x86)%\mirc\ircintro.chm to %ProgramFiles(x86)%\mirc\2bb660311f0a.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_beejive.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\f2245cd013b5a6a.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-tr-tr.wlz to %ProgramFiles(x86)%\winamp\lang\f19229dc69e8c09c.cbc630
  • from %ProgramFiles(x86)%\winamp\system\aacdec.w5s to %ProgramFiles(x86)%\winamp\system\ec7d95c617.cbc630
  • from %ProgramFiles(x86)%\winamp\system\jpeg.w5s to %ProgramFiles(x86)%\winamp\system\629d917b.cbc630
  • from %ProgramFiles(x86)%\winamp\system\jnetlib.w5s to %ProgramFiles(x86)%\winamp\system\ec535ef7f4a.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-zh-tw.wlz to %ProgramFiles(x86)%\winamp\lang\10ff26c90d50af5e.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\sobaka_strelyaet.swf to %APPDATA%\icqm\icq\smiles\flash\88122dc67942898e9401.cbc630
  • from %ProgramFiles(x86)%\winamp\system\tagz.w5s to %ProgramFiles(x86)%\winamp\system\560ae514.cbc630
  • from %ProgramFiles(x86)%\winamp\system\playlist.w5s to %ProgramFiles(x86)%\winamp\system\66bce1b25d0a.cbc630
  • from %ProgramFiles(x86)%\winamp\system\adpcm.w5s to %ProgramFiles(x86)%\winamp\system\c128d7095.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-zh-cn.wlz to %ProgramFiles(x86)%\winamp\lang\1b74a789a89b604c.cbc630
  • from %ProgramFiles(x86)%\winamp\system\aacdec.wbm to %ProgramFiles(x86)%\winamp\system\bbeb5e9a7b.cbc630
  • from %ProgramFiles(x86)%\winamp\microsoft.vc90.crt\microsoft.vc90.crt.manifest to %ProgramFiles(x86)%\winamp\microsoft.vc90.crt\9d197b882735392a763cea2d70e.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-pt-br.wlz to %ProgramFiles(x86)%\winamp\lang\78998c38d4199593.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ab.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\6fe334.cbc630
  • from %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\sndtray.wav to %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\b6a2c68ecb1.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_glicq.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\e0c587ba20e08.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_adium.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\344cf5deaedbd.cbc630
  • from %ProgramFiles(x86)%\winamp\system\theora.wbm to %ProgramFiles(x86)%\winamp\system\70faaa52e0.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ai.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\e605e5.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_fring.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\e82513da22daa.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ah.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\b4ea7b.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_di_chat.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\044f8a0be16a4f0.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ag.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\68993e.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_digsby.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\46cba5e8df733e.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\af.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\5ce199.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_corepager.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\2648b64a918745cdb.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_citron.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\c25bb8b4631ff8.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ae.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\cfbd88.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_centericq.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\aaba7a4bb59cbc27a.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ad.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\66fe05.cbc630
  • from %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\_sounds.ini to %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\deb3a94f5d4.cbc630
  • from %ProgramFiles(x86)%\winamp\system\timer.w5s to %ProgramFiles(x86)%\winamp\system\8eedbeefd.cbc630
  • from %ProgramFiles(x86)%\qip 2012\protos\mra\util\qip2mra.ini to %ProgramFiles(x86)%\qip 2012\protos\mra\util\758ecd7e939.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-sv-se.wlz to %ProgramFiles(x86)%\winamp\lang\f92c613388d1c8e7.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\aa.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\e810b6.cbc630
  • from %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\sndservermsg.wav to %ProgramFiles(x86)%\qip 2012\sounds\qip sounds\190e469ca82e277d.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\aj.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\f5f1d4.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_hangover.png to %APPDATA%\icqm\icq\smiles\flash\ae6787eb2217b06a3.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_roses.png to %APPDATA%\icqm\icq\smiles\flash\b96cee9076c202.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_preview.png to %APPDATA%\icqm\icq\smiles\flash\7a42f35ea27e541e.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_maddog.png to %APPDATA%\icqm\icq\smiles\flash\475756f95e8debd.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_laugh.png to %APPDATA%\icqm\icq\smiles\flash\e429aa648d0bd9.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_kiss.png to %APPDATA%\icqm\icq\smiles\flash\e9616270ee54c.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_heart.png to %APPDATA%\icqm\icq\smiles\flash\21d2c2ef6e9bd1.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_girl.png to %APPDATA%\icqm\icq\smiles\flash\5fd039b70215f.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_working.png to %APPDATA%\icqm\icq\smiles\flash\8a2d196f232790f6.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_dog.png to %APPDATA%\icqm\icq\smiles\flash\bcda7e1d1b10.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_bored.png to %APPDATA%\icqm\icq\smiles\flash\60f6486cca958f.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_beer.png to %APPDATA%\icqm\icq\smiles\flash\974497907d79e.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.swf to %APPDATA%\icqm\icq\smiles\flash\f5122e3bccc1bbc43d.cbc630
  • from %ProgramFiles%\winrar\wincon.sfx to %ProgramFiles%\winrar\cdcfcc42ca.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\rabotaet.swf to %APPDATA%\icqm\icq\smiles\flash\1ab0f2e948b9.cbc630
  • from %ProgramFiles%\winrar\readme.txt to %ProgramFiles%\winrar\7e1a100f04.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\sorry.png to %APPDATA%\icqm\icq\smiles\flash\41f7c03ce.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\wf_love_srazila.swf to %APPDATA%\icqm\icq\smiles\flash\334e6f7a6c90087823f.cbc630
  • from %ProgramFiles(x86)%\winamp\components\ssdp.w6c to %ProgramFiles(x86)%\winamp\components\9340ab64.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\mult_shoot.png to %APPDATA%\icqm\icq\smiles\flash\d0f707071e27b9.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-de-de.wlz to %ProgramFiles(x86)%\winamp\lang\3ad9a094a3219b5a.cbc630
  • from %ProgramFiles(x86)%\winamp\lang\winamp-fr-fr.wlz to %ProgramFiles(x86)%\winamp\lang\165f6234fe7f16b7.cbc630
  • from %ProgramFiles(x86)%\opera\assets\70x70logo.scale-140.png to %ProgramFiles(x86)%\opera\assets\e7e2cc9683ef953fd2fd7f0.cbc630
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\snapshot_blob.bin to %ProgramFiles(x86)%\opera\29.0.1795.47\f3831f6bd01bd654e.cbc630
  • from %ProgramFiles(x86)%\opera\assets\70x70logo.scale-100_contrast-white.png to %ProgramFiles(x86)%\opera\assets\b4a3c83ccf9e87bb83113fd5c79f22f08e91ec.cbc630
  • from %ProgramFiles(x86)%\opera\assets\70x70logo.scale-100.png to %ProgramFiles(x86)%\opera\assets\7bb60c792d33ae13a0652a0.cbc630
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\opera_autoupdate.licenses to %ProgramFiles(x86)%\opera\29.0.1795.47\85d08b78550fb857a913f6015.cbc630
  • from %ProgramFiles(x86)%\opera\assets\150x150logo.scale-80_contrast-white.png to %ProgramFiles(x86)%\opera\assets\ba051d23767df6cbb464f4b05b9b7a38054bf89.cbc630
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\opera_125_percent.pak to %ProgramFiles(x86)%\opera\29.0.1795.47\c03cdd69ae2c9ee03ec9c.cbc630
  • from %ProgramFiles(x86)%\microsoft office\office10\trigram.lex to %ProgramFiles(x86)%\microsoft office\office10\a376afd2318.cbc630
  • from %ProgramFiles(x86)%\microsoft office\office10\thdic.lex to %ProgramFiles(x86)%\microsoft office\office10\0b8093ae8.cbc630
  • from %APPDATA%\icqm\icq\smiles\mrasmileslang_bg.xml to %APPDATA%\icqm\icq\smiles\5d03e57e81df8affabf9.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\zadolbal.swf to %APPDATA%\icqm\icq\smiles\flash\c9a04082db25.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\sorry.swf to %APPDATA%\icqm\icq\smiles\flash\fba43f743.cbc630
  • from %ProgramFiles%\winrar\wincon64.sfx to %ProgramFiles%\winrar\7cc67c7909d4.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_ichat.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\eb76cdbee2f6e.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\info2.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\c1fafd2b9.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\sammy.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\221f5b943.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\nibbles.xml to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\cbb05e639c7.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\seek.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\21822e708.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\shade.png to %ProgramFiles(x86)%\winamp\skins\bento\window\6004545fa.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\llama.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\319d0e33a.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\sc_alb_art.jpg to %ProgramFiles(x86)%\winamp\skins\bento\window\67b34619fd2670.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\seekshade.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\6eed48bef7117d.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\sui.png to %ProgramFiles(x86)%\winamp\skins\bento\window\1d58dd3.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\player.png to %ProgramFiles(x86)%\winamp\skins\bento\window\f85fdc4219.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\plmenu.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\dba51a14755.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level8.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\2f30d689b9.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\notifier.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\714fd14eb151b.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\numfont.png to %ProgramFiles(x86)%\winamp\skins\bento\window\b1929f368ca.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level7.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\6c67c56bcb.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\pltime.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\df8b627a692.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_view.png to %ProgramFiles(x86)%\winamp\skins\bento\window\1b702bcf643e8.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\vis_avs.dat to %ProgramFiles(x86)%\winamp\plugins\0a97999e891.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\duo - alienated (evilrice trinity tron remix).avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\c2c730f6c1413ad5b03ccdc2fc639ecc4484672b31741c420.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\duo - alien intercourse 4.avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\4a7965458647e82e19e89e040927b.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\degnic - spirit realm (plasmoid rmx).avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\dc0b23019f6f593e053b097103951bb26e6529ac.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\degnic - helium.avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\5f962ee7735873b8c4b.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\degnic - fury (extreme remix) by fsk.avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\3135e9e9444c1eae3497d8cc333ef3a5fe2ac2c2.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\degnic - fractal (slo-mo metallic) (u).avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\8acfe426ebf0a79b17b7a9a6a9ce6be8f25049f3e4.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\scripts\albumart.maki to %ProgramFiles(x86)%\winamp\skins\big bento\scripts\15a02a2089b56.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\amphirion - ex deux mechanica.avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\2a76b317a63b8db606b6e2efcb0c1ba95.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\shadesizepos.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\58a53af7bf9f5c423.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\al.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\e2d14c.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\community picks\acid - twitchy liquid shit (mixing plastics mix by tuggummi).avs to %ProgramFiles(x86)%\winamp\plugins\avs\community picks\7979ffd993c5fa90df6447682e0a4457ab5dc3c655ba1d13518a45894cf8a3ea.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\shadelinks.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\7da285cb29f48be.cbc630
  • from %ProgramFiles(x86)%\winamp\plugins\avs\colormap.ape to %ProgramFiles(x86)%\winamp\plugins\avs\6bdfacb5a804.cbc630
  • from %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\ak.gif to %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\c2c58b.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\screenshot.png to %ProgramFiles(x86)%\winamp\skins\big bento\2e229822df3a90.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level6.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\6df981ec38.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level9.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\903617379c.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\notifications_fade_times.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\74b83637de82d06f9068ff45da074.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level5.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\8f17139449.cbc630
  • from %ProgramFiles%\firefox\components\webbrowser_core.xpt to %ProgramFiles%\firefox\components\7ccf18e51c0febf4771.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_icq_2000.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\156580076ef3e22f.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\display.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\cf20138d4235.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\info.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\c949e907.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\aol_radio_alb_art.jpg to %ProgramFiles(x86)%\winamp\skins\bento\window\18512d549ad703391f7b6.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\crossfade.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\4a2fd3352219c4.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\fixedsys.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\a057196f6b98.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\configtarget.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\63651fb574254ff42.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\skin.xml to %ProgramFiles(x86)%\winamp\skins\bento\bcdb9fc4.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\about_fg.jpg to %ProgramFiles(x86)%\winamp\skins\big bento\about\e8e1dc7546f8.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\configtabs.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\879fb4f13ca2737.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\scripts\mcvcore.maki to %ProgramFiles(x86)%\winamp\skins\bento\scripts\a82272539ffd.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\about.xml to %ProgramFiles(x86)%\winamp\skins\big bento\about\e6e1248fe.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\beatvisualization.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\8cf1e10ed193467c64915a.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\screenshot.png to %ProgramFiles(x86)%\winamp\skins\bento\20c4d179029d58.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\albumart.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\4a4c75b1b1c36.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\config.png to %ProgramFiles(x86)%\winamp\skins\bento\window\c1d66f9a39.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\about.maki to %ProgramFiles(x86)%\winamp\skins\big bento\about\3831ed816e.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\eq.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\94401f8.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level1.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\8a28e41ba3.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\controls.png to %ProgramFiles(x86)%\winamp\skins\bento\window\2a6c298444c3.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\mute.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\e816869f5.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level4.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\e4bda83e7a.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_options.png to %ProgramFiles(x86)%\winamp\skins\bento\window\5edd3352ac550fc9.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\mlmenu.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\b214d0a2caf.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level3.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\d1a13f8368.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_help.png to %ProgramFiles(x86)%\winamp\skins\bento\window\2e9028def53c5.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\menualign.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\dc236ecddccbf5.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level2.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\3a2eef2798.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_file.png to %ProgramFiles(x86)%\winamp\skins\bento\window\44ca90a3afb20.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\mainmenuoverlay.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\7499f8eced9de7e0f9bc.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\equalizer.png to %ProgramFiles(x86)%\winamp\skins\bento\window\9cbb593c552be.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\level10.png to %ProgramFiles(x86)%\winamp\skins\big bento\about\nibbles\e71e2e15a24.cbc630
  • from %ProgramFiles(x86)%\winamp\system\xspf.w5s to %ProgramFiles(x86)%\winamp\system\a7c0c72d.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\mainmenu.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\0c1118bf84824.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\bento\window\menu_play.png to %ProgramFiles(x86)%\winamp\skins\bento\window\ef814fb4481b9.cbc630
  • from %ProgramFiles%\winrar\uninstall.lst to %ProgramFiles%\winrar\ae7e7d56a71b3.cbc630
  • from %ProgramFiles%\winrar\whatsnew.txt to %ProgramFiles%\winrar\2b257896de1a.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\love_bear_hugs.png to %APPDATA%\icqm\icq\smiles\flash\d3d5a30373b8d1a477.cbc630
  • from %ProgramFiles%\firefox\components\nsurlformatter.js to %ProgramFiles%\firefox\components\b93ef694b933b2507.cbc630
  • from %ProgramFiles%\firefox\components\nsurlclassifierlistmanager.js to %ProgramFiles%\firefox\components\122d48bf239ecaa978ae2c89f4413.cbc630
  • from %ProgramFiles%\firefox\components\nsurlclassifierlib.js to %ProgramFiles%\firefox\components\380f0195d655582c32f77.cbc630
  • from %ProgramFiles%\firefox\components\nsurlclassifier.manifest to %ProgramFiles%\firefox\components\ead3bab6708f47d28787eea7.cbc630
  • from %ProgramFiles%\firefox\components\nsupdatetimermanager.manifest to %ProgramFiles%\firefox\components\a051cacba50bfa4fc32f763e3022c.cbc630
  • from %ProgramFiles%\firefox\components\nswebhandlerapp.js to %ProgramFiles%\firefox\components\8db0823f30b7d9d299.cbc630
  • from %ProgramFiles%\firefox\components\parentalcontrols.xpt to %ProgramFiles%\firefox\components\33cb47de2b417c07290e.cbc630
  • from %ProgramFiles%\firefox\components\nsupdatetimermanager.js to %ProgramFiles%\firefox\components\7664b403af765412a6c95d1.cbc630
  • from %ProgramFiles%\firefox\components\nstrytoclose.js to %ProgramFiles%\firefox\components\67b26b8a6f23d9b.cbc630
  • from %ProgramFiles%\firefox\components\nstaggingservice.js to %ProgramFiles%\firefox\components\8b0cf39188e94e60921.cbc630
  • from %ProgramFiles%\firefox\components\nssidebar.js to %ProgramFiles%\firefox\components\dae131672a71.cbc630
  • from %ProgramFiles%\firefox\components\nssetdefaultbrowser.manifest to %ProgramFiles%\firefox\components\b0986cad9cdafa43707fba51a2f4.cbc630
  • from %ProgramFiles%\firefox\components\nssetdefaultbrowser.js to %ProgramFiles%\firefox\components\fef837f23eff30084d8945.cbc630
  • from %APPDATA%\adobe\acrobat\dc\jscache\globdata to %APPDATA%\adobe\acrobat\dc\jscache\5d056b93.cbc630
  • from %ProgramFiles%\firefox\components\nsupdateservicestub.js to %ProgramFiles%\firefox\components\f621c72ede356ee6fdfc60.cbc630
  • from %ProgramFiles%\firefox\components\txexsltregexfunctions.js to %ProgramFiles%\firefox\components\6a7240b64388dc5d4a72fc45.cbc630
  • from %ProgramFiles%\firefox\components\passwordmgr.manifest to %ProgramFiles%\firefox\components\178ab56aed713eb362b2.cbc630
  • from %ProgramFiles%\firefox\components\storage_legacy.js to %ProgramFiles%\firefox\components\1408dfee2029a2f9b.cbc630
  • from %ProgramFiles%\firefox\components\storage.xpt to %ProgramFiles%\firefox\components\aa532595fcd.cbc630
  • from %ProgramFiles%\firefox\components\startupcache.xpt to %ProgramFiles%\firefox\components\83344116424013e1.cbc630
  • from %ProgramFiles%\firefox\components\spellchecker.xpt to %ProgramFiles%\firefox\components\c13adc8f0dd2361e.cbc630
  • from %ProgramFiles%\firefox\components\shistory.xpt to %ProgramFiles%\firefox\components\96586cfbf711.cbc630
  • from %ProgramFiles%\firefox\components\pref.xpt to %ProgramFiles%\firefox\components\59af4437.cbc630
  • from %ProgramFiles%\firefox\components\pluginglue.manifest to %ProgramFiles%\firefox\components\916d5f772176a6c160d.cbc630
  • from %ProgramFiles%\firefox\components\plugin.xpt to %ProgramFiles%\firefox\components\6d358c46eb.cbc630
  • from %ProgramFiles%\firefox\components\placesprotocolhandler.js to %ProgramFiles%\firefox\components\eb8defcaa20c87d564dea0cb.cbc630
  • from %ProgramFiles%\firefox\components\placescategoriesstarter.js to %ProgramFiles%\firefox\components\0a2a7558e74a9d4d79df02546e.cbc630
  • from %ProgramFiles%\firefox\components\places.xpt to %ProgramFiles%\firefox\components\9e7a626e1c.cbc630
  • from %ProgramFiles%\firefox\components\pippki.xpt to %ProgramFiles%\firefox\components\ff53dcfcbc.cbc630
  • from %ProgramFiles%\firefox\components\pipnss.xpt to %ProgramFiles%\firefox\components\ea28ce4eba.cbc630
  • from %ProgramFiles%\firefox\components\pipboot.xpt to %ProgramFiles%\firefox\components\9f3809112d3.cbc630
  • from %ProgramFiles%\firefox\components\nssearchservice.js to %ProgramFiles%\firefox\components\c0113ff3544382f918.cbc630
  • from %ProgramFiles%\firefox\readme.txt to %ProgramFiles%\firefox\62d92e5cd2.cbc630
  • from %ProgramFiles%\firefox\components\nswebhandlerapp.manifest to %ProgramFiles%\firefox\components\cd471b6a523214868ce1e8bb.cbc630
  • from %ProgramFiles%\firefox\blocklist.xml to %ProgramFiles%\firefox\fab6d7d7f36ac.cbc630
  • from %ProgramFiles%\firefox\js.log to %ProgramFiles%\firefox\faf250.cbc630
  • from %ProgramFiles(x86)%\steam\libav_h264-56.dll.md5 to %ProgramFiles(x86)%\steam\8f5d3421245f9a99e1ee1.cbc630
  • from %ProgramFiles(x86)%\opera\resources.pri to %ProgramFiles(x86)%\opera\53e1150f43c1f.cbc630
  • from %ProgramFiles(x86)%\winamp\install.ini to %ProgramFiles(x86)%\winamp\c2f302d20ae.cbc630
  • from %ProgramFiles(x86)%\winamp\paths.ini to %ProgramFiles(x86)%\winamp\db6308bbc.cbc630
  • from %ProgramFiles(x86)%\winamp\pconfig.dcf to %ProgramFiles(x86)%\winamp\38bccef1b6b.cbc630
  • from %ProgramFiles(x86)%\qip 2012\unins000.msg to %ProgramFiles(x86)%\qip 2012\fa389a727774.cbc630
  • from %ProgramFiles(x86)%\qip 2012\unins000.dat to %ProgramFiles(x86)%\qip 2012\493153dfccc0.cbc630
  • from %ProgramFiles(x86)%\opera\server_tracking_data to %ProgramFiles(x86)%\opera\5b4169bbc7793d963c53.cbc630
  • from %ProgramFiles(x86)%\opera\launcher.visualelementsmanifest.xml to %ProgramFiles(x86)%\opera\6c60984d9cfafdc26a3b0d7f5eaa2e2e760.cbc630
  • from %APPDATA%\adobe\acrobat\dc\preferences\defaultheuristics.dat to %APPDATA%\adobe\acrobat\dc\preferences\33683db8663e55b16b716.cbc630
  • from %ProgramFiles(x86)%\opera\installation_status.xml to %ProgramFiles(x86)%\opera\b3b8e4e0056e71bbcede567.cbc630
  • from %ProgramFiles(x86)%\opera\installer_prefs.json to %ProgramFiles(x86)%\opera\3537a17aed0de6196787.cbc630
  • from %ProgramFiles(x86)%\mirc\versions.txt to %ProgramFiles(x86)%\mirc\bf6c1826b97c.cbc630
  • from %ProgramFiles(x86)%\mirc\mirc.chm to %ProgramFiles(x86)%\mirc\8e226948.cbc630
  • from %ProgramFiles(x86)%\mirc\readme.txt to %ProgramFiles(x86)%\mirc\319a091268.cbc630
  • from %ProgramFiles(x86)%\steam\libav_h264-56.dll.crypt to %ProgramFiles(x86)%\steam\fa29733654fa2ef621ae89b.cbc630
  • from %ProgramFiles(x86)%\steam\libx264-142.dll.md5 to %ProgramFiles(x86)%\steam\4e76fa2194434ab80a5.cbc630
  • from %ProgramFiles%\firefox\components\toolkitsearch.manifest to %ProgramFiles%\firefox\components\300b7c9a7c97795262e86e.cbc630
  • from %ProgramFiles(x86)%\steam\steam.exe.old to %ProgramFiles(x86)%\steam\3f9686bafc499.cbc630
  • from %ProgramFiles(x86)%\steam\libx264-142.dll.crypt to %ProgramFiles(x86)%\steam\a8f4326b5ec06317ee38a.cbc630
  • from %ProgramFiles(x86)%\winamp\whatsnew.txt to %ProgramFiles(x86)%\winamp\6b61cf7ed81e.cbc630
  • from %ProgramFiles%\firefox\crashreporter_override.ini to %ProgramFiles%\firefox\2663ba3c2773fcca56cac97fd0.cbc630
  • from %ProgramFiles%\firefox\nssdbm3.chk to %ProgramFiles%\firefox\1b5ad605106.cbc630
  • from %ProgramFiles%\firefox\platform.ini to %ProgramFiles%\firefox\be21697d3798.cbc630
  • from %ProgramFiles%\firefox\updater.ini to %ProgramFiles%\firefox\7eb6c7fdd9e.cbc630
  • from %ProgramFiles%\firefox\update.locale to %ProgramFiles%\firefox\8ea9738b40298.cbc630
  • from %ProgramFiles%\firefox\greprefs.js to %ProgramFiles%\firefox\69825418d84.cbc630
  • from %ProgramFiles%\firefox\freebl3.chk to %ProgramFiles%\firefox\30cded632d5.cbc630
  • from %ProgramFiles%\firefox\dependentlibs.list to %ProgramFiles%\firefox\63a9edc7bc1efae488.cbc630
  • from %ProgramFiles%\firefox\softokn3.chk to %ProgramFiles%\firefox\4e90ec735a29.cbc630
  • from %ProgramFiles%\firefox\chrome.manifest to %ProgramFiles%\firefox\aa233e8f6cb8c5c.cbc630
  • from %ProgramFiles%\foxit\foxit to %ProgramFiles%\foxit\6900e.cbc630
  • from %ProgramFiles%\firefox\application.ini to %ProgramFiles%\firefox\301a16ec47d6d7c.cbc630
  • from %ProgramFiles(x86)%\k-lite codec pack\unins000.dat to %ProgramFiles(x86)%\k-lite codec pack\619c834e5ed5.cbc630
  • from %ProgramFiles(x86)%\msbuild\microsoft.office.infopath.targets to %ProgramFiles(x86)%\msbuild\a1a88b230bbbd139aab105d88fb76c313.cbc630
  • from %ProgramFiles%\firefox\crashreporter.ini to %ProgramFiles%\firefox\608d3883ea9f4d7af.cbc630
  • from %ProgramFiles%\firefox\components\nsurlformatter.manifest to %ProgramFiles%\firefox\components\a553d15984733551c32ee55.cbc630
  • from %ProgramFiles%\firefox\components\txmgr.xpt to %ProgramFiles%\firefox\components\3ce70be8b.cbc630
  • from %ProgramFiles%\winrar\order.htm to %ProgramFiles%\winrar\6886b3019.cbc630
  • from %ProgramFiles%\firefox\components\zipwriter.xpt to %ProgramFiles%\firefox\components\7ff336324815b.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_cool.swf to %APPDATA%\icqm\icq\smiles\flash\a435b1883831.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_cool.png to %APPDATA%\icqm\icq\smiles\flash\5ca94e6d08a0.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kisses.swf to %APPDATA%\icqm\icq\smiles\flash\d8a2f801e0.cbc630
  • from %ProgramFiles%\winrar\license.txt to %ProgramFiles%\winrar\4838edf10d3.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kisses.png to %APPDATA%\icqm\icq\smiles\flash\08d7eaff46.cbc630
  • from %ProgramFiles%\winrar\descript.ion to %ProgramFiles%\winrar\864403881fc5.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\information.swf to %APPDATA%\icqm\icq\smiles\flash\927b1c01062a80c.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\gangsta.png to %APPDATA%\icqm\icq\smiles\flash\66e8cc79f0c.cbc630
  • from %ProgramFiles%\winrar\default64.sfx to %ProgramFiles%\winrar\96bfc68b08f84.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\drako_zombie.png to %APPDATA%\icqm\icq\smiles\flash\813dbf35728ae904.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\drako_srach.png to %APPDATA%\icqm\icq\smiles\flash\b4ad80c94e1c896.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\devochka.swf to %APPDATA%\icqm\icq\smiles\flash\6b114a4f81c9.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\boo.swf to %APPDATA%\icqm\icq\smiles\flash\7fcc9a1.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\akitaka.swf to %APPDATA%\icqm\icq\smiles\flash\ad9cfbbe703.cbc630
  • from %APPDATA%\adobe\acrobat\dc\security\addressbook.acrodata to %APPDATA%\adobe\acrobat\dc\security\9e69603c7f3009265b55.cbc630
  • from %ProgramFiles%\winrar\rarnew.dat to %ProgramFiles%\winrar\ea55587f8b.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.png to %APPDATA%\icqm\icq\smiles\flash\5a73917a08f65ba.cbc630
  • from %ProgramFiles%\winrar\rar.txt to %ProgramFiles%\winrar\75e193e.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_goodbye.swf to %APPDATA%\icqm\icq\smiles\flash\c54649c353ef3ed.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\likeu.png to %APPDATA%\icqm\icq\smiles\flash\f3fbbf397.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\laugh.swf to %APPDATA%\icqm\icq\smiles\flash\db26778b1.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\laugh.png to %APPDATA%\icqm\icq\smiles\flash\3195fcc09.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\krizis.swf to %APPDATA%\icqm\icq\smiles\flash\3e61f0f642.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\krizis.png to %APPDATA%\icqm\icq\smiles\flash\b4920ffbdb.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_wow.swf to %APPDATA%\icqm\icq\smiles\flash\15eabd721c7.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_wow.png to %APPDATA%\icqm\icq\smiles\flash\03b32f5f7f4.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.swf to %APPDATA%\icqm\icq\smiles\flash\a2f7a453e4f3ef1.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_spasibo.png to %APPDATA%\icqm\icq\smiles\flash\fca920f7b3b49bc.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_obida.swf to %APPDATA%\icqm\icq\smiles\flash\a3fbcb635d835.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_obida.png to %APPDATA%\icqm\icq\smiles\flash\c82c3a03d44cb.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.swf to %APPDATA%\icqm\icq\smiles\flash\6a77dda624cf766.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\kot_nedutza.png to %APPDATA%\icqm\icq\smiles\flash\d5ddbba1370bee6.cbc630
  • from %ProgramFiles%\winrar\rarfiles.lst to %ProgramFiles%\winrar\01d8c20eb077.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\likeu.swf to %APPDATA%\icqm\icq\smiles\flash\844e92363.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\shadecontrol.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\24941ace3d03f4d87.cbc630
  • from %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\songinfo.maki to %ProgramFiles(x86)%\winamp\skins\winamp modern\scripts\d0cecfdf8aea6.cbc630
  • from %ProgramFiles%\firefox\components\xulapp.xpt to %ProgramFiles%\firefox\components\b9e12cd3a1.cbc630
  • from %ProgramFiles%\firefox\components\uriloader.xpt to %ProgramFiles%\firefox\components\4ccead78f3405.cbc630
  • from %APPDATA%\icq-profile\installerlang.xml to %APPDATA%\icq-profile\95e2b31d9c4088480.cbc630
  • from %ProgramFiles%\firefox\components\webapps.xpt to %ProgramFiles%\firefox\components\50f31d8917c.cbc630
  • from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\2847313.cbc630
  • from %ProgramFiles%\firefox\components\url_classifier.xpt to %ProgramFiles%\firefox\components\297443427313f5b5e8.cbc630
  • from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\70b2990.cbc630
  • from %ProgramFiles%\firefox\components\urlformatter.xpt to %ProgramFiles%\firefox\components\cd2f04f6cbc8d03d.cbc630
  • from %ProgramFiles%\firefox\components\update.xpt to %ProgramFiles%\firefox\components\d961cd5290.cbc630
  • from %APPDATA%\icq-profile\update\languages.aff to %APPDATA%\icq-profile\update\abae367a55668.cbc630
  • from %APPDATA%\ghisler\wincmd.ini to %APPDATA%\ghisler\0fed482b13.cbc630
  • from %ProgramFiles%\firefox\components\unicharutil.xpt to %ProgramFiles%\firefox\components\15c8fb432b19b17.cbc630
  • from %APPDATA%\adobe\logtransport2\logtransport2.cfg to %APPDATA%\adobe\logtransport2\2a998fe207abf5223.cbc630
  • from %ProgramFiles%\firefox\components\uconv.xpt to %ProgramFiles%\firefox\components\12e4ca493.cbc630
  • from %APPDATA%\adobe\acrobat\dc\tmgrpprm.sav to %APPDATA%\adobe\acrobat\dc\b0cbb64a1492.cbc630
  • from %APPDATA%\adobe\acrobat\dc\tmdocs.sav to %APPDATA%\adobe\acrobat\dc\901bdd809e.cbc630
  • from %ProgramFiles%\firefox\components\xuldoc.xpt to %ProgramFiles%\firefox\components\d23dbba945.cbc630
  • from %ProgramFiles%\firefox\components\xultmpl.xpt to %ProgramFiles%\firefox\components\68fee3aac63.cbc630
  • from %APPDATA%\icq-profile\update\ver.txt to %APPDATA%\icq-profile\update\5398684.cbc630
  • from %ProgramFiles%\firefox\components\webshell_idls.xpt to %ProgramFiles%\firefox\components\d66958be7f0cad91f.cbc630
  • from %ProgramFiles%\firefox\components\webbrowserpersist.xpt to %ProgramFiles%\firefox\components\ae44632b62c79e9bf399c.cbc630
  • from %ProgramFiles%\firefox\components\xpconnect.xpt to %ProgramFiles%\firefox\components\a616af0b1402c.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_xpti.xpt to %ProgramFiles%\firefox\components\1aaf5a64b82c8f.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_threads.xpt to %ProgramFiles%\firefox\components\da5e44eedc3239214.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_system.xpt to %ProgramFiles%\firefox\components\47b5646321e7bbf9.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_io.xpt to %ProgramFiles%\firefox\components\a96c96457caf.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_ds.xpt to %ProgramFiles%\firefox\components\b40efe53e515.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_components.xpt to %ProgramFiles%\firefox\components\ba6b3c2c735e17a54caf.cbc630
  • from %ProgramFiles%\firefox\components\xpcom_base.xpt to %ProgramFiles%\firefox\components\81f7d284a3ea61.cbc630
  • from %APPDATA%\icqm\icq\smiles\flash\akitaka.png to %APPDATA%\icqm\icq\smiles\flash\08793d03711.cbc630
  • from %ProgramFiles%\firefox\components\windowwatcher.xpt to %ProgramFiles%\firefox\components\c551bdabb176b3a78.cbc630
  • from %ProgramFiles%\firefox\components\windowds.xpt to %ProgramFiles%\firefox\components\20d4a967358d.cbc630
  • from %APPDATA%\icqm\icq\database\citylist_kz.csv to %APPDATA%\icqm\icq\database\4a51ff20cac20ca.cbc630
  • from %ProgramFiles%\firefox\components\widget.xpt to %ProgramFiles%\firefox\components\020ed3de06.cbc630
  • from %APPDATA%\icqm\icq\database\citylist_en.csv to %APPDATA%\icqm\icq\database\dfed81e73c657fd.cbc630
  • from %ProgramFiles%\firefox\components\webcontentconverter.js to %ProgramFiles%\firefox\components\54add3a5eb41aad47d8086.cbc630
  • from %ProgramFiles(x86)%\qip 2012\skins\qip\clients\cli_icq_2002.png to %ProgramFiles(x86)%\qip 2012\skins\qip\clients\9f91dd698daa4e3b.cbc630
Modifies user data files (Trojan.Encoder).
Miscellaneous
Creates and executes the following
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ddrq2p7z.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCBA8.tmp" "%TEMP%\CSCCB88.tmp"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\se3lqkki.cmdline"' (with hidden window)
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD74C.tmp" "%TEMP%\CSCD73B.tmp"' (with hidden window)
Executes the following
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\ddrq2p7z.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCBA8.tmp" "%TEMP%\CSCCB88.tmp"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\se3lqkki.cmdline"
  • '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESD74C.tmp" "%TEMP%\CSCD73B.tmp"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android