Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '{272EBD3A-4F22-59D4-5635-61E7E0F572A6}' = '%APPDATA%\guide.exe'
- <Drive name for removable media>:\correct.avi
- <Drive name for removable media>:\contoso.cer
- <Drive name for removable media>:\pmd.cer
- <Drive name for removable media>:\contoso_1.cer
- <Drive name for removable media>:\sdkfailsafeemulator.cer
- <Drive name for removable media>:\sdksampleunprivdeveloper.cer
- <Drive name for removable media>:\testcertificate.cer
- <Drive name for removable media>:\sdksampleprivdeveloper.cer
- <Drive name for removable media>:\contosoroot_1.cer
- <Drive name for removable media>:\dashborder_192.bmp
- <Drive name for removable media>:\lisp_success.doc
- <Drive name for removable media>:\tileimage.bmp
- <Drive name for removable media>:\dial.bmp
- <Drive name for removable media>:\dashborder_96.bmp
- <Drive name for removable media>:\dashborder_120.bmp
- <Drive name for removable media>:\default.bmp
- <Drive name for removable media>:\dialmap.bmp
- <Drive name for removable media>:\delete.avi
- <Drive name for removable media>:\000814251_video_01.avi
- <Drive name for removable media>:\split.avi
- <Drive name for removable media>:\how to recover encrypted files.txt
- <Drive name for removable media>:\coffee.bmp
- <Drive name for removable media>:\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\contoso.cer
- %HOMEPATH%\desktop\contoso_1.cer
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\dashborder_144.bmp
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\fi51.doc
- %HOMEPATH%\desktop\glidescope_review_rev_010.docx
- %HOMEPATH%\desktop\pmd.cer
- %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
- %HOMEPATH%\desktop\sdszfo.docx
- %APPDATA%\guide.exe
- C:\far2\plugins\editcase\how to recover encrypted files.txt
- C:\far2\plugins\emenu\how to recover encrypted files.txt
- C:\far2\plugins\farcmds\how to recover encrypted files.txt
- C:\far2\plugins\filecase\how to recover encrypted files.txt
- C:\far2\plugins\ftp\how to recover encrypted files.txt
- C:\far2\plugins\ftp\lib\how to recover encrypted files.txt
- C:\far2\plugins\hlfviewer\how to recover encrypted files.txt
- %HOMEPATH%\searches\how to recover encrypted files.txt
- C:\far2\plugins\macroview\how to recover encrypted files.txt
- C:\far2\plugins\proclist\how to recover encrypted files.txt
- C:\far2\plugins\tmppanel\how to recover encrypted files.txt
- C:\far2\pluginsdk\headers.c\how to recover encrypted files.txt
- C:\far2\pluginsdk\headers.pas\how to recover encrypted files.txt
- C:\totalcmd\how to recover encrypted files.txt
- C:\users\public\music\sample music\how to recover encrypted files.txt
- C:\users\public\pictures\sample pictures\how to recover encrypted files.txt
- C:\far2\plugins\compare\how to recover encrypted files.txt
- C:\far2\plugins\drawline\how to recover encrypted files.txt
- C:\far2\plugins\brackets\how to recover encrypted files.txt
- C:\far2\plugins\autowrap\how to recover encrypted files.txt
- C:\far2\plugins\arclite\how to recover encrypted files.txt
- %HOMEPATH%\contacts\how to recover encrypted files.txt
- %HOMEPATH%\desktop\how to recover encrypted files.txt
- %HOMEPATH%\favorites\links\how to recover encrypted files.txt
- %HOMEPATH%\favorites\links for united states\how to recover encrypted files.txt
- %HOMEPATH%\favorites\microsoft websites\how to recover encrypted files.txt
- %HOMEPATH%\favorites\msn websites\how to recover encrypted files.txt
- %HOMEPATH%\favorites\windows live\how to recover encrypted files.txt
- C:\users\public\videos\sample videos\how to recover encrypted files.txt
- C:\far2\plugins\network\how to recover encrypted files.txt
- %HOMEPATH%\links\how to recover encrypted files.txt
- C:\far2\addons\how to recover encrypted files.txt
- C:\far2\addons\shell\how to recover encrypted files.txt
- C:\far2\documentation\eng\how to recover encrypted files.txt
- C:\far2\documentation\rus\how to recover encrypted files.txt
- C:\far2\encyclopedia\how to recover encrypted files.txt
- C:\far2\encyclopedia\tap\how to recover encrypted files.txt
- C:\far2\plugins\align\how to recover encrypted files.txt
- %TEMP%\{421a75c8-421a-421a-421a-421a75c85458}.bat
- C:\far2\how to recover encrypted files.txt
- D:\how to recover encrypted files.txt
- %APPDATA%\guide.exe
- %HOMEPATH%\contacts\user.contact
- %HOMEPATH%\favorites\msn websites\msn entertainment.url
- %HOMEPATH%\favorites\msn websites\msn autos.url
- %HOMEPATH%\favorites\microsoft websites\microsoft store.url
- %HOMEPATH%\favorites\microsoft websites\microsoft at work.url
- %HOMEPATH%\favorites\microsoft websites\microsoft at home.url
- %HOMEPATH%\favorites\microsoft websites\ie site on microsoft.com.url
- %HOMEPATH%\favorites\microsoft websites\ie add-on site.url
- %HOMEPATH%\favorites\links for united states\usa.gov.url
- %HOMEPATH%\favorites\links for united states\gobiernousa.gov.url
- %HOMEPATH%\favorites\links\web slice gallery.url
- %HOMEPATH%\favorites\links\suggested sites.url
- %HOMEPATH%\desktop\total commander 64 bit.lnk
- %HOMEPATH%\desktop\telegram.lnk
- %HOMEPATH%\desktop\qip 2012.lnk
- %HOMEPATH%\desktop\mail.ru agent.lnk
- %HOMEPATH%\desktop\icq.lnk
- %HOMEPATH%\desktop\fi51.doc
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\dashborder_144.bmp
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\contoso_1.cer
- %HOMEPATH%\desktop\contoso.cer
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\favorites\msn websites\msn money.url
- %HOMEPATH%\favorites\msn websites\msn sports.url
- %APPDATA%\guide.exe
- 'ip###ger.com':80
- 'ip###ger.org':443
- 'microsoft.com':80
- 'oc##.#ectigo.com':80
- 'ip###ger.com':443
- DNS ASK ip###ger.com
- DNS ASK ip###ger.org
- DNS ASK microsoft.com
- DNS ASK oc##.#ectigo.com
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\{421A75C8-421A-421A-421A-421A75C85458}.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /for=C: /All' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /for=D: /All' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /for=E: /All' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /for=F: /All' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c wmic SHADOWCOPY DELETE' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /All /Quiet' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} recoveryenabled No' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\{421A75C8-421A-421A-421A-421A75C85458}.bat
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /for=C: /All
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /for=D: /All
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /for=E: /All
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /for=F: /All
- '%WINDIR%\syswow64\cmd.exe' /c wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0
- '%WINDIR%\syswow64\cmd.exe' /c wmic SHADOWCOPY DELETE
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin Delete Shadows /All /Quiet
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} recoveryenabled No
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures