Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '7d121307917b3668f9790d0b6cf4e26ee75bc92b70302f552e9d79d23845c241' = '"<Full path to file>" 0c14c8f875ef350f67b51aa0e4b2a7dec2...
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '7d121307917b3668f9790d0b6cf4e26ee75bc92b70302f552e9d79d23845c241' = '"<Full path to file>" 0c14c8f875ef350f67b51aa0e4b2a7dec2b0312617993f...
- <Drive name for removable media>:\__lock_xxx__
- <Drive name for removable media>:\!!!read_me_first!!!.txt
- %ALLUSERSPROFILE%\0c14c8f875ef350f67b51aa0e4b2a7dec2b0312617993f24263cacc18665f1f4
- %LOCALAPPDATA%\applicationhistory\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\applicationhistory\__lock_xxx__
- %LOCALAPPDATA%\adobe\color\profiles\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\color\profiles\__lock_xxx__
- %LOCALAPPDATA%\adobe\color\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\color\__lock_xxx__
- %LOCALAPPDATA%\cef\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\!!!read_me_first!!!.txt
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\!!!read_me_first!!!.txt
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\__lock_xxx__
- D:\$recycle.bin\!!!read_me_first!!!.txt
- D:\$recycle.bin\__lock_xxx__
- D:\!!!read_me_first!!!.txt
- D:\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\user data\default\cache\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\google\chrome\user data\default\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\google\chrome\user data\default\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\user data\caps\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\google\chrome\user data\caps\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\user data\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\google\chrome\user data\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\google\chrome\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\google\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\google\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\widevinecdm\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\cef\user data\widevinecdm\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\dictionaries\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\cef\user data\dictionaries\__lock_xxx__
- %LOCALAPPDATA%\cef\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\cef\user data\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\__lock_xxx__
- %LOCALAPPDATA%\__lock_xxx__
- %HOMEPATH%\!!!read_me_first!!!.txt
- %HOMEPATH%\__lock_xxx__
- %HOMEPATH%\documents\my videos\!!!read_me_first!!!.txt
- %HOMEPATH%\documents\my videos\__lock_xxx__
- %HOMEPATH%\documents\my pictures\!!!read_me_first!!!.txt
- %HOMEPATH%\documents\my pictures\__lock_xxx__
- %HOMEPATH%\appdata\__lock_xxx__
- %HOMEPATH%\documents\my music\!!!read_me_first!!!.txt
- %HOMEPATH%\documents\!!!read_me_first!!!.txt
- %HOMEPATH%\documents\__lock_xxx__
- %HOMEPATH%\desktop\__lock_xxx__
- <Current directory>\!!!read_me_first!!!.txt
- <Current directory>\__lock_xxx__
- %HOMEPATH%\desktop\!!!read_me_first!!!.txt
- %HOMEPATH%\documents\my music\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\dc\cache\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\__lock_xxx__
- %LOCALAPPDATA%\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\acrocef\dc\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\acrocef\dc\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\acrocef\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\dc\toolssearchcacherdr\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\acrobat\dc\toolssearchcacherdr\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\acrobat\dc\cache\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\acrobat\dc\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\acrobat\dc\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\acrobat\__lock_xxx__
- %LOCALAPPDATA%\adobe\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\adobe\__lock_xxx__
- %HOMEPATH%\appdata\!!!read_me_first!!!.txt
- %LOCALAPPDATA%\google\chrome\user data\default\cache\!!!read_me_first!!!.txt
- <Current directory>\__lock_xxx__
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\__lock_xxx__
- %LOCALAPPDATA%\adobe\color\__lock_xxx__
- %LOCALAPPDATA%\adobe\color\profiles\__lock_xxx__
- %LOCALAPPDATA%\applicationhistory\__lock_xxx__
- <Drive name for removable media>:\__lock_xxx__
- D:\$recycle.bin\__lock_xxx__
- %LOCALAPPDATA%\cef\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\widevinecdm\__lock_xxx__
- %LOCALAPPDATA%\google\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\user data\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\user data\caps\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\dictionaries\__lock_xxx__
- D:\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\__lock_xxx__
- %HOMEPATH%\documents\__lock_xxx__
- %HOMEPATH%\documents\my music\__lock_xxx__
- %HOMEPATH%\documents\my pictures\__lock_xxx__
- %HOMEPATH%\documents\my videos\__lock_xxx__
- %HOMEPATH%\__lock_xxx__
- %HOMEPATH%\appdata\__lock_xxx__
- %HOMEPATH%\desktop\__lock_xxx__
- %LOCALAPPDATA%\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\dc\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\dc\cache\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\dc\toolssearchcacherdr\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\__lock_xxx__
- %LOCALAPPDATA%\adobe\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\user data\default\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\user data\default\cache\__lock_xxx__
- <Current directory>\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\widevinecdm\__lock_xxx__
- %LOCALAPPDATA%\cef\user data\dictionaries\__lock_xxx__
- %LOCALAPPDATA%\applicationhistory\__lock_xxx__
- %LOCALAPPDATA%\adobe\__lock_xxx__
- %LOCALAPPDATA%\adobe\color\__lock_xxx__
- %LOCALAPPDATA%\adobe\color\profiles\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\__lock_xxx__
- %LOCALAPPDATA%\cef\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\__lock_xxx__
- D:\$recycle.bin\__lock_xxx__
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\dc\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\dc\toolssearchcacherdr\__lock_xxx__
- %LOCALAPPDATA%\adobe\acrobat\dc\cache\__lock_xxx__
- %HOMEPATH%\documents\__lock_xxx__
- %HOMEPATH%\documents\my videos\__lock_xxx__
- %HOMEPATH%\documents\my pictures\__lock_xxx__
- %HOMEPATH%\documents\my music\__lock_xxx__
- %HOMEPATH%\desktop\__lock_xxx__
- D:\__lock_xxx__
- %LOCALAPPDATA%\google\chrome\user data\caps\__lock_xxx__
- %HOMEPATH%\desktop\1189.jpeg.dragon
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies.dragon
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\index.dragon
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_3.dragon
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_2.dragon
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_1.dragon
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_0.dragon
- D:\install.log.dragon
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\desktop.ini.dragon
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\chromedwritefontcache.dragon
- %LOCALAPPDATA%\adobe\acrobat\dc\usercache.bin.dragon
- %LOCALAPPDATA%\adobe\acrobat\dc\shareddataevents.dragon
- %LOCALAPPDATA%\adobe\acrobat\dc\cache\acrofnt15.lst.dragon
- %LOCALAPPDATA%\adobe\acrobat\dc\adobesysfnt15.lst.dragon
- %LOCALAPPDATA%\adobe\acrobat\dc\adobecmapfnt15.lst.dragon
- %HOMEPATH%\documents\desktop.ini.dragon
- %HOMEPATH%\desktop\total commander 64 bit.lnk.dragon
- %HOMEPATH%\desktop\telegram.lnk.dragon
- %HOMEPATH%\desktop\qip 2012.lnk.dragon
- %HOMEPATH%\desktop\mail.ru agent.lnk.dragon
- %HOMEPATH%\desktop\icq.lnk.dragon
- %HOMEPATH%\desktop\desktop.ini.dragon
- %HOMEPATH%\desktop\advice_process.htm.dragon
- %HOMEPATH%\desktop\adhd_and_obesity.docx.dragon
- %HOMEPATH%\desktop\about.htm.dragon
- %HOMEPATH%\desktop\210252809.jpg.dragon
- %HOMEPATH%\desktop\2.jpeg.dragon
- %HOMEPATH%\desktop\13.jpeg.dragon
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies-journal.dragon
- %LOCALAPPDATA%\adobe\color\acecache11.lst.dragon