マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.DownLoader12.59852

Added to the Dr.Web virus database: 2015-04-13

Virus description added:

Technical Information

Malicious functions:
Creates and executes the following:
  • '<Current directory>\App\local\stubexe\0x87EA078272763A26\ArtipicBatchProcessing.exe' \\.\pipe\ArtipicBatchProcessing
  • '<Current directory>\App\local\stubexe\0xEFCBC15840532F22\Artipic.exe'
Executes the following:
  • '<SYSTEM32>\taskhost.exe'
Modifies file system :
Creates the following files:
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\Microsoft.VC90.CRT.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcm90.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcp90.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\ATL90.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\Microsoft.VC90.ATL.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\x86_Microsoft.VC90.ATL@9.0.21022.8.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcr90.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfcm90.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfcm90u.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\Microsoft.VC90.MFC.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\x86_Microsoft.VC90.CRT@9.0.21022.8.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfc90.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfc90u.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtNetwork4.dll_0x3b5573d1fa3745713adc15aff43f46e8.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtOpenGL4.dll_0xe99fed48d984da6f07191f8d50855e45.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtracegraphicssystem4.dll_0xe5eaf892462af8a338598afb93cd3bac.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtga4.dll_0x3b5068eeba89266857e28b001939aa97.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtGui4.dll_0xc0d63c8a7820ed295f376a55ee0d5434.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtiff4.dll_0xf869375bda0e9f96b132293dc2d56ecf.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtwcodecs4.dll_0xad9bde8c70815745e41a4d800353b5f8.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\TwainPlugin.dll_0x00d9c32d915bb99407c424c398888dde.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\UndoRedoEngine.dll_0x8d703902684cfbeb8fb10f315a7f2f38.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\zlib1.dll_0x4d13e45bdbadb1edb143c7ab6ab1bc5f.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtXml4.dll_0xe520e4fc4cdbb6e9f042eea44541eae6.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\RawFileWorker.dll_0x505f8bb6fde6322aed6df736cf39b413.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\TiffFileWorker.dll_0x3fe22c2cdd0afd29c3a7d7b9929a1c43.2.manifest.__tmp__
  • <Current directory>\App\local\temp\@APPDATALOCAL@\Artipic\artipic.ini
  • <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\artipic.ini.__meta__.__tmp__
  • <Current directory>\App\roaming\modified\@APPDATALOCAL@\Artipic\artipic.ini
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\Microsoft.VC90.OpenMP.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\vcomp90.dll.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\x86_Microsoft.VC90.OpenMP@9.0.21022.8.manifest.__tmp__
  • <Current directory>\App\local\temp\@APPDATALOCAL@\Artipic\log\10-04-2015_09-23-04.txt
  • <Current directory>\App\local\temp\@APPDATALOCAL@\Artipic\batchlog\10-04-2015_09-23-05.txt
  • <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\batchlog\10-04-2015_09-23-05.txt.__meta__.__tmp__
  • <Current directory>\App\roaming\modified\@APPDATALOCAL@\Artipic\batchlog\13-04-2015_07-12-22.txt
  • <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\log\10-04-2015_09-23-04.txt.__meta__.__tmp__
  • <Current directory>\App\local\stubexe\0x87EA078272763A26\ArtipicBatchProcessing.exe.__tmp__
  • <Current directory>\App\roaming\modified\@APPDATALOCAL@\Artipic\log\13-04-2015_07-12-14.txt
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90DEU.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ENU.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ESN.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\x86_Microsoft.VC90.MFC@9.0.21022.8.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90CHS.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90CHT.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ESP.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90KOR.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\Microsoft.VC90.MFCLOC.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\x86_Microsoft.VC90.MFCLOC@9.0.21022.8.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90FRA.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ITA.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90JPN.DLL.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\JpegFileWorker.dll_0x6b3ec35e52911d427744109b76b94662.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\LayerEngine.dll_0x10d1e0db726d091d5ae0a661a797edd2.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\lcms2.dll_0x3a44c5ecb0f1a7cce19dee9457a236c0.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\geometryengine.dll_0xb736f49511e981c6cacc56beb4361f24.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ImageAdjustment.dll_0x8e0d38871f922cabab7cab56807a5e10.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ImageFilter.dll_0x2293ba9c7cf0f6bf6c9d562c2f2821e2.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\libraw.dll_0xb209ba56cc8a093b8bb2ba6f278ce603.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.CRT.manifest_0x6bb5d2aad0ae1b4a82e7ddf7cf58802a.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.MFC.manifest_0xce3ab3bd3ff80fce88dcb0ea3d48a0c9.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.MFCLOC.manifest_0x6439b46d6d9cb337ddf2d8e643455951.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\mfc90.dll_0x462ddcc5eb88f34aed991416f8e354b2.1000.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\mfc90u.dll_0xb9030d821e099c79de1c9125b790e2da.1000.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.ATL.manifest_0xb41644a01c05740576b4e77662c7e86c.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Artipic.exe_0xfd9515ce613142e79f579aed366bb703.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ArtipicBatchProcessing.exe_0x6e52ea75809dba3ad1321c559d32783c.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BaseFileWorker.dll_0x5ccb7685903a9e5c2e952b655c9b8270.2.manifest.__tmp__
  • <Current directory>\App\xsandbox.bin.__tmp__
  • <Current directory>\App\local\stubexe\0xEFCBC15840532F22\Artipic.exe.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Artipic.exe.bak_0xd1f2ff35c389485ef849257657a9cc21.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BasicTools.dll_0xab58499be86f8ed35366a1f89b8c7837.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\exif.dll_0x33430a5f5eea19fd3087629601bfeef9.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ExrFileWorker.dll_0xdf67e6cc1ef4ac0a0a58146bbe133fc7.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\FSIOPlugin.dll_0x6a3e98851956da09fa2d51dfadcbfcd8.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BatchClient.dll_0x4edeb116d6d22ce5ca9e28cba3294cdc.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BrushContainer.dll_0xc722b21fb8fca08d460e8f3d41a8c55f.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\CLEngine.dll_0xb6b686ef6414a0c9e5bef65a217bc77e.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qgif4.dll_0x568a6601a0384f02f3d2316a8ba9659a.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qglgraphicssystem4.dll_0x77b4dc6c464c27cce438b3ab91937e4a.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qico4.dll_0x80c47d9220ec6130114c8160aa63a89b.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Patch.exe_0xec448770f8c5d94840a64e0412c5753b.1.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\PngFileWorker.dll_0xebc1cbe1fe4047bbceeb431b37e2fa05.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qcncodecs4.dll_0x5adf21d233b43dc2f31772978e0683d1.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qjpcodecs4.dll_0xb0b16ee271209ff9d10aee88f3fa8beb.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qsvg4.dll_0x5c7755479d52a9c33f6a888c315f708d.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qsvgicon4.dll_0xed8c895abf483f239e149a1e72de6f2d.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtCore4.dll_0x91cba5df981891337dc0db35cb8bcd62.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qjpeg4.dll_0xde0f8856a74e0839420c5a1c54f28498.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qkrcodecs4.dll_0x62f62fa3121e98546c3d7be06867f1f7.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qmng4.dll_0x8a35082dfc181ffa6f7e18fc7419ab12.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiDocument.dll_0xf92c831f921004d29dde3da41b39b55c.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiFileWorker.dll_0x6f480edc52ca8bc88cbc4b7c8be96fd7.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiGlobal.dll_0xaf11ca6fa8556d928a5346fae2fa2cfc.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.OpenMP.manifest_0x42ce4dbd016591c45bcb95524c6718dd.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiAdjustmentContainer.dll_0xc4399bcd00a7487f595aecaf0894579d.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiBatchCore.dll_0x9e9221299443372f2c339ef8421bf1d9.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Optigui.dll_0xccfd780b650546f471fd539eae5bfc10.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiResource.dll_0xd075783ce31a830f6b05769b5982c316.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiStyleCore.dll_0xfc8cf53134e6134c427f04546dc33d04.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiUtils.dll_0xf849926f2834f2be4a5fa6aae3647035.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiGuiCore.dll_0x47d1832ff122bb1069b7b4f7f5838284.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiImage.dll_0x96adabda3e1f496d0b7ab54aeddd607e.2.manifest.__tmp__
  • %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiPlugin.dll_0xe4b2ab98a538c9785aa2b2714f93ce45.2.manifest.__tmp__
Deletes the following files:
  • <Current directory>\App\roaming\modified\@APPDATALOCAL@\Artipic\batchlog\10-04-2015_09-23-05.txt
  • <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\batchlog\10-04-2015_09-23-05.txt.__meta__
  • <SYSTEM32>\spool\drivers\w32x86\3\mxdwdui.BUD
  • <Current directory>\App\roaming\modified\@APPDATALOCAL@\Artipic\log\10-04-2015_09-23-04.txt
  • <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\log\10-04-2015_09-23-04.txt.__meta__
Moves the following files:
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\x86_Microsoft.VC90.ATL@9.0.21022.8.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\x86_Microsoft.VC90.ATL@9.0.21022.8.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\Microsoft.VC90.CRT.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\Microsoft.VC90.CRT.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcm90.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcm90.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\zlib1.dll_0x4d13e45bdbadb1edb143c7ab6ab1bc5f.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\zlib1.dll_0x4d13e45bdbadb1edb143c7ab6ab1bc5f.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\ATL90.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\ATL90.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\Microsoft.VC90.ATL.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.ATL@9.0.21022.8\Microsoft.VC90.ATL.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfc90.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfc90.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfc90u.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfc90u.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfcm90.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfcm90.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcp90.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcp90.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcr90.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\msvcr90.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\x86_Microsoft.VC90.CRT@9.0.21022.8.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.CRT@9.0.21022.8\x86_Microsoft.VC90.CRT@9.0.21022.8.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\UndoRedoEngine.dll_0x8d703902684cfbeb8fb10f315a7f2f38.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\UndoRedoEngine.dll_0x8d703902684cfbeb8fb10f315a7f2f38.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtiff4.dll_0xf869375bda0e9f96b132293dc2d56ecf.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtiff4.dll_0xf869375bda0e9f96b132293dc2d56ecf.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtNetwork4.dll_0x3b5573d1fa3745713adc15aff43f46e8.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtNetwork4.dll_0x3b5573d1fa3745713adc15aff43f46e8.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtOpenGL4.dll_0xe99fed48d984da6f07191f8d50855e45.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtOpenGL4.dll_0xe99fed48d984da6f07191f8d50855e45.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtCore4.dll_0x91cba5df981891337dc0db35cb8bcd62.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtCore4.dll_0x91cba5df981891337dc0db35cb8bcd62.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtga4.dll_0x3b5068eeba89266857e28b001939aa97.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtga4.dll_0x3b5068eeba89266857e28b001939aa97.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtGui4.dll_0xc0d63c8a7820ed295f376a55ee0d5434.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtGui4.dll_0xc0d63c8a7820ed295f376a55ee0d5434.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\RawFileWorker.dll_0x505f8bb6fde6322aed6df736cf39b413.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\RawFileWorker.dll_0x505f8bb6fde6322aed6df736cf39b413.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\TiffFileWorker.dll_0x3fe22c2cdd0afd29c3a7d7b9929a1c43.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\TiffFileWorker.dll_0x3fe22c2cdd0afd29c3a7d7b9929a1c43.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\TwainPlugin.dll_0x00d9c32d915bb99407c424c398888dde.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\TwainPlugin.dll_0x00d9c32d915bb99407c424c398888dde.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtracegraphicssystem4.dll_0xe5eaf892462af8a338598afb93cd3bac.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtracegraphicssystem4.dll_0xe5eaf892462af8a338598afb93cd3bac.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtwcodecs4.dll_0xad9bde8c70815745e41a4d800353b5f8.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qtwcodecs4.dll_0xad9bde8c70815745e41a4d800353b5f8.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtXml4.dll_0xe520e4fc4cdbb6e9f042eea44541eae6.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\QtXml4.dll_0xe520e4fc4cdbb6e9f042eea44541eae6.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\vcomp90.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\vcomp90.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\x86_Microsoft.VC90.OpenMP@9.0.21022.8.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\x86_Microsoft.VC90.OpenMP@9.0.21022.8.manifest
  • from <Current directory>\App\local\temp\@APPDATALOCAL@\Artipic\artipic.ini to <Current directory>\App\roaming\modified\@APPDATALOCAL@\Artipic\artipic.ini
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\Microsoft.VC90.MFCLOC.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\Microsoft.VC90.MFCLOC.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\x86_Microsoft.VC90.MFCLOC@9.0.21022.8.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\x86_Microsoft.VC90.MFCLOC@9.0.21022.8.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\Microsoft.VC90.OpenMP.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.OpenMP@9.0.21022.8\Microsoft.VC90.OpenMP.manifest
  • from <Current directory>\App\local\stubexe\0x87EA078272763A26\ArtipicBatchProcessing.exe.__tmp__ to <Current directory>\App\local\stubexe\0x87EA078272763A26\ArtipicBatchProcessing.exe
  • from <Current directory>\App\local\temp\@APPDATALOCAL@\Artipic\batchlog\10-04-2015_09-23-05.txt to <Current directory>\App\roaming\modified\@APPDATALOCAL@\Artipic\batchlog\10-04-2015_09-23-05.txt
  • from <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\batchlog\10-04-2015_09-23-05.txt.__meta__.__tmp__ to <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\batchlog\10-04-2015_09-23-05.txt.__meta__
  • from <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\artipic.ini.__meta__.__tmp__ to <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\artipic.ini.__meta__
  • from <Current directory>\App\local\temp\@APPDATALOCAL@\Artipic\log\10-04-2015_09-23-04.txt to <Current directory>\App\roaming\modified\@APPDATALOCAL@\Artipic\log\10-04-2015_09-23-04.txt
  • from <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\log\10-04-2015_09-23-04.txt.__meta__.__tmp__ to <Current directory>\App\roaming\meta\@APPDATALOCAL@\Artipic\log\10-04-2015_09-23-04.txt.__meta__
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90KOR.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90KOR.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90CHS.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90CHS.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90CHT.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90CHT.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90DEU.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90DEU.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfcm90u.dll.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\mfcm90u.dll
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\Microsoft.VC90.MFC.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\Microsoft.VC90.MFC.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\x86_Microsoft.VC90.MFC@9.0.21022.8.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFC@9.0.21022.8\x86_Microsoft.VC90.MFC@9.0.21022.8.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90FRA.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90FRA.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ITA.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ITA.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90JPN.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90JPN.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ENU.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ENU.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ESN.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ESN.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ESP.DLL.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\x86_Microsoft.VC90.MFCLOC@9.0.21022.8\MFC90ESP.DLL
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qsvgicon4.dll_0xed8c895abf483f239e149a1e72de6f2d.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qsvgicon4.dll_0xed8c895abf483f239e149a1e72de6f2d.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\JpegFileWorker.dll_0x6b3ec35e52911d427744109b76b94662.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\JpegFileWorker.dll_0x6b3ec35e52911d427744109b76b94662.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\LayerEngine.dll_0x10d1e0db726d091d5ae0a661a797edd2.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\LayerEngine.dll_0x10d1e0db726d091d5ae0a661a797edd2.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\lcms2.dll_0x3a44c5ecb0f1a7cce19dee9457a236c0.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\lcms2.dll_0x3a44c5ecb0f1a7cce19dee9457a236c0.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\geometryengine.dll_0xb736f49511e981c6cacc56beb4361f24.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\geometryengine.dll_0xb736f49511e981c6cacc56beb4361f24.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ImageAdjustment.dll_0x8e0d38871f922cabab7cab56807a5e10.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ImageAdjustment.dll_0x8e0d38871f922cabab7cab56807a5e10.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ImageFilter.dll_0x2293ba9c7cf0f6bf6c9d562c2f2821e2.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ImageFilter.dll_0x2293ba9c7cf0f6bf6c9d562c2f2821e2.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.ATL.manifest_0xb41644a01c05740576b4e77662c7e86c.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.ATL.manifest_0xb41644a01c05740576b4e77662c7e86c.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.CRT.manifest_0x6bb5d2aad0ae1b4a82e7ddf7cf58802a.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.CRT.manifest_0x6bb5d2aad0ae1b4a82e7ddf7cf58802a.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.MFC.manifest_0xce3ab3bd3ff80fce88dcb0ea3d48a0c9.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.MFC.manifest_0xce3ab3bd3ff80fce88dcb0ea3d48a0c9.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\libraw.dll_0xb209ba56cc8a093b8bb2ba6f278ce603.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\libraw.dll_0xb209ba56cc8a093b8bb2ba6f278ce603.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\mfc90.dll_0x462ddcc5eb88f34aed991416f8e354b2.1000.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\mfc90.dll_0x462ddcc5eb88f34aed991416f8e354b2.1000.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\mfc90u.dll_0xb9030d821e099c79de1c9125b790e2da.1000.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\mfc90u.dll_0xb9030d821e099c79de1c9125b790e2da.1000.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\FSIOPlugin.dll_0x6a3e98851956da09fa2d51dfadcbfcd8.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\FSIOPlugin.dll_0x6a3e98851956da09fa2d51dfadcbfcd8.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Artipic.exe_0xfd9515ce613142e79f579aed366bb703.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Artipic.exe_0xfd9515ce613142e79f579aed366bb703.1.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ArtipicBatchProcessing.exe_0x6e52ea75809dba3ad1321c559d32783c.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ArtipicBatchProcessing.exe_0x6e52ea75809dba3ad1321c559d32783c.1.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BaseFileWorker.dll_0x5ccb7685903a9e5c2e952b655c9b8270.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BaseFileWorker.dll_0x5ccb7685903a9e5c2e952b655c9b8270.2.manifest
  • from <Current directory>\App\xsandbox.bin.__tmp__ to <Current directory>\App\xsandbox.bin
  • from <Current directory>\App\local\stubexe\0xEFCBC15840532F22\Artipic.exe.__tmp__ to <Current directory>\App\local\stubexe\0xEFCBC15840532F22\Artipic.exe
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Artipic.exe.bak_0xd1f2ff35c389485ef849257657a9cc21.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Artipic.exe.bak_0xd1f2ff35c389485ef849257657a9cc21.1.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\CLEngine.dll_0xb6b686ef6414a0c9e5bef65a217bc77e.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\CLEngine.dll_0xb6b686ef6414a0c9e5bef65a217bc77e.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\exif.dll_0x33430a5f5eea19fd3087629601bfeef9.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\exif.dll_0x33430a5f5eea19fd3087629601bfeef9.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ExrFileWorker.dll_0xdf67e6cc1ef4ac0a0a58146bbe133fc7.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\ExrFileWorker.dll_0xdf67e6cc1ef4ac0a0a58146bbe133fc7.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BasicTools.dll_0xab58499be86f8ed35366a1f89b8c7837.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BasicTools.dll_0xab58499be86f8ed35366a1f89b8c7837.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BatchClient.dll_0x4edeb116d6d22ce5ca9e28cba3294cdc.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BatchClient.dll_0x4edeb116d6d22ce5ca9e28cba3294cdc.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BrushContainer.dll_0xc722b21fb8fca08d460e8f3d41a8c55f.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\BrushContainer.dll_0xc722b21fb8fca08d460e8f3d41a8c55f.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qcncodecs4.dll_0x5adf21d233b43dc2f31772978e0683d1.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qcncodecs4.dll_0x5adf21d233b43dc2f31772978e0683d1.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qgif4.dll_0x568a6601a0384f02f3d2316a8ba9659a.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qgif4.dll_0x568a6601a0384f02f3d2316a8ba9659a.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qglgraphicssystem4.dll_0x77b4dc6c464c27cce438b3ab91937e4a.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qglgraphicssystem4.dll_0x77b4dc6c464c27cce438b3ab91937e4a.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiUtils.dll_0xf849926f2834f2be4a5fa6aae3647035.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiUtils.dll_0xf849926f2834f2be4a5fa6aae3647035.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Patch.exe_0xec448770f8c5d94840a64e0412c5753b.1.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Patch.exe_0xec448770f8c5d94840a64e0412c5753b.1.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\PngFileWorker.dll_0xebc1cbe1fe4047bbceeb431b37e2fa05.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\PngFileWorker.dll_0xebc1cbe1fe4047bbceeb431b37e2fa05.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qkrcodecs4.dll_0x62f62fa3121e98546c3d7be06867f1f7.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qkrcodecs4.dll_0x62f62fa3121e98546c3d7be06867f1f7.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qmng4.dll_0x8a35082dfc181ffa6f7e18fc7419ab12.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qmng4.dll_0x8a35082dfc181ffa6f7e18fc7419ab12.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qsvg4.dll_0x5c7755479d52a9c33f6a888c315f708d.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qsvg4.dll_0x5c7755479d52a9c33f6a888c315f708d.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qico4.dll_0x80c47d9220ec6130114c8160aa63a89b.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qico4.dll_0x80c47d9220ec6130114c8160aa63a89b.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qjpcodecs4.dll_0xb0b16ee271209ff9d10aee88f3fa8beb.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qjpcodecs4.dll_0xb0b16ee271209ff9d10aee88f3fa8beb.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qjpeg4.dll_0xde0f8856a74e0839420c5a1c54f28498.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\qjpeg4.dll_0xde0f8856a74e0839420c5a1c54f28498.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiStyleCore.dll_0xfc8cf53134e6134c427f04546dc33d04.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiStyleCore.dll_0xfc8cf53134e6134c427f04546dc33d04.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiBatchCore.dll_0x9e9221299443372f2c339ef8421bf1d9.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiBatchCore.dll_0x9e9221299443372f2c339ef8421bf1d9.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiDocument.dll_0xf92c831f921004d29dde3da41b39b55c.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiDocument.dll_0xf92c831f921004d29dde3da41b39b55c.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiFileWorker.dll_0x6f480edc52ca8bc88cbc4b7c8be96fd7.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiFileWorker.dll_0x6f480edc52ca8bc88cbc4b7c8be96fd7.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.MFCLOC.manifest_0x6439b46d6d9cb337ddf2d8e643455951.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.MFCLOC.manifest_0x6439b46d6d9cb337ddf2d8e643455951.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.OpenMP.manifest_0x42ce4dbd016591c45bcb95524c6718dd.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Microsoft.VC90.OpenMP.manifest_0x42ce4dbd016591c45bcb95524c6718dd.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiAdjustmentContainer.dll_0xc4399bcd00a7487f595aecaf0894579d.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiAdjustmentContainer.dll_0xc4399bcd00a7487f595aecaf0894579d.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiImage.dll_0x96adabda3e1f496d0b7ab54aeddd607e.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiImage.dll_0x96adabda3e1f496d0b7ab54aeddd607e.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiPlugin.dll_0xe4b2ab98a538c9785aa2b2714f93ce45.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiPlugin.dll_0xe4b2ab98a538c9785aa2b2714f93ce45.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiResource.dll_0xd075783ce31a830f6b05769b5982c316.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiResource.dll_0xd075783ce31a830f6b05769b5982c316.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiGlobal.dll_0xaf11ca6fa8556d928a5346fae2fa2cfc.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiGlobal.dll_0xaf11ca6fa8556d928a5346fae2fa2cfc.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Optigui.dll_0xccfd780b650546f471fd539eae5bfc10.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\Optigui.dll_0xccfd780b650546f471fd539eae5bfc10.2.manifest
  • from %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiGuiCore.dll_0x47d1832ff122bb1069b7b4f7f5838284.2.manifest.__tmp__ to %TEMP%\SPOON\CACHE\0xE81C7361DE9808B8\sxs\Manifests\OptiGuiCore.dll_0x47d1832ff122bb1069b7b4f7f5838284.2.manifest
Network activity:
UDP:
  • DNS ASK dn#.##ftncsi.com
  • DNS ASK st###.spoon.net
Miscellaneous:
Searches for the following windows:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'OleMainThreadWndClass' WindowName: ''

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android