Arrival Details. This Trojan may be dropped by the following malware: Installation. This Trojan drops the following copies of itself into the affected system and executes them: %UserProfile%\Application Data{GUID}{random filename}.exe. It drops the following files: %Desktop%\YOUR_FILES_ARE_ENCRYPTED.