Immediately uppon client call me (tuesday afternoon)and tell they cannot open files from server and name of files changes, i search internet and found this forum, where I see Hrenki post link to Kaspersky utility. And on Kaspersky description i see note about .oshit file and that the file may be deleted. I boot infected PC from Hiren's Boot DVD and I try find the .oshit file manualy and then listed all deleted files in R-Studio, but nothing helpful was found. I want leave source PC untouched, in case I will must pay ransom to criminals.