Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'MSFEEditor' = '"<Full path to file>" e'
- <SYSTEM32>\tasks\adobe acrobat update task
- <SYSTEM32>\tasks\adobe acrobat update task.inprocess
- <SYSTEM32>\tasks\!!!how_to_decrypt!!!.mht
- <SYSTEM32>\tasks\opera scheduled autoupdate 1694565166
- <SYSTEM32>\tasks\opera scheduled autoupdate 1694565166.inprocess
- <Drive name for removable media>:\split.avi
- <Drive name for removable media>:\february_catalogue__2015.doc
- <Drive name for removable media>:\testcertificate.cer.inprocess
- <Drive name for removable media>:\testcertificate.cer
- <Drive name for removable media>:\testee.cer.inprocess
- <Drive name for removable media>:\testee.cer
- <Drive name for removable media>:\sdksampleunprivdeveloper.cer.inprocess
- <Drive name for removable media>:\sdksampleunprivdeveloper.cer
- <Drive name for removable media>:\pmd.cer.inprocess
- <Drive name for removable media>:\pmd.cer
- <Drive name for removable media>:\contoso_1.cer.inprocess
- <Drive name for removable media>:\contoso_1.cer
- <Drive name for removable media>:\contosoroot.cer.inprocess
- <Drive name for removable media>:\contosoroot.cer
- <Drive name for removable media>:\tileimage.bmp.inprocess
- <Drive name for removable media>:\tileimage.bmp
- <Drive name for removable media>:\dialmap.bmp.inprocess
- <Drive name for removable media>:\dialmap.bmp
- <Drive name for removable media>:\dashborder_192.bmp.inprocess
- <Drive name for removable media>:\dashborder_192.bmp
- <Drive name for removable media>:\dashborder_120.bmp.inprocess
- <Drive name for removable media>:\dashborder_120.bmp
- <Drive name for removable media>:\coffee.bmp.inprocess
- <Drive name for removable media>:\coffee.bmp
- <Drive name for removable media>:\join.avi.inprocess
- <Drive name for removable media>:\join.avi
- <Drive name for removable media>:\!!!how_to_decrypt!!!.mht
- <Drive name for removable media>:\split.avi.inprocess
- <Drive name for removable media>:\february_catalogue__2015.doc.inprocess
- <Drive name for removable media>:\cveuropeo.doc
- System Restore (SR)
- %APPDATA%\key.file
- g:\boot\de-de\!!!how_to_decrypt!!!.mht
- g:\boot\el-gr\!!!how_to_decrypt!!!.mht
- g:\boot\en-us\!!!how_to_decrypt!!!.mht
- g:\boot\es-es\!!!how_to_decrypt!!!.mht
- g:\boot\fi-fi\!!!how_to_decrypt!!!.mht
- g:\boot\fonts\!!!how_to_decrypt!!!.mht
- g:\boot\fr-fr\!!!how_to_decrypt!!!.mht
- g:\boot\hu-hu\!!!how_to_decrypt!!!.mht
- g:\boot\it-it\!!!how_to_decrypt!!!.mht
- g:\boot\ja-jp\!!!how_to_decrypt!!!.mht
- g:\boot\ko-kr\!!!how_to_decrypt!!!.mht
- %HOMEPATH%\!!!how_to_decrypt!!!.mht
- g:\boot\nb-no\!!!how_to_decrypt!!!.mht
- g:\boot\pl-pl\!!!how_to_decrypt!!!.mht
- g:\boot\pt-br\!!!how_to_decrypt!!!.mht
- g:\boot\pt-pt\!!!how_to_decrypt!!!.mht
- g:\boot\ru-ru\!!!how_to_decrypt!!!.mht
- g:\boot\sv-se\!!!how_to_decrypt!!!.mht
- g:\boot\tr-tr\!!!how_to_decrypt!!!.mht
- g:\boot\zh-cn\!!!how_to_decrypt!!!.mht
- g:\boot\zh-hk\!!!how_to_decrypt!!!.mht
- g:\boot\zh-tw\!!!how_to_decrypt!!!.mht
- C:\users\public\libraries\!!!how_to_decrypt!!!.mht
- %HOMEPATH%\contacts\!!!how_to_decrypt!!!.mht
- g:\boot\cs-cz\!!!how_to_decrypt!!!.mht
- g:\boot\da-dk\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- %HOMEPATH%\desktop\readme_lock.txt
- g:\$recycle.bin\s-1-5-21-3150914307-1777937420-491476919-1000\desktop.ini
- C:\!!!how_to_decrypt!!!.mht
- C:\users\public\desktop\!!!how_to_decrypt!!!.mht
- D:\!!!how_to_decrypt!!!.mht
- C:\kms\!!!how_to_decrypt!!!.mht
- g:\!!!how_to_decrypt!!!.mht
- g:\bootsect.bak.inprocess
- g:\boot\!!!how_to_decrypt!!!.mht
- %ProgramFiles%\mozilla firefox\!!!how_to_decrypt!!!.mht
- %ProgramFiles%\mozilla thunderbird\!!!how_to_decrypt!!!.mht
- %HOMEPATH%\searches\!!!how_to_decrypt!!!.mht
- g:\boot\nl-nl\!!!how_to_decrypt!!!.mht
- C:\users\default\!!!how_to_decrypt!!!.mht
- %WINDIR%\panther\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\!!!how_to_decrypt!!!.mht
- %HOMEPATH%\desktop\!!!how_to_decrypt!!!.mht
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\!!!how_to_decrypt!!!.mht
- <SYSTEM32>\config\!!!how_to_decrypt!!!.mht
- g:\bootsect.bak.1btc
- from %WINDIR%\panther\setupinfo to %WINDIR%\panther\setupinfo.inprocess
- from %WINDIR%\panther\setupinfo.inprocess to %WINDIR%\panther\setupinfo.1btc
- from <SYSTEM32>\config\bcd-template to <SYSTEM32>\config\bcd-template.inprocess
- from <SYSTEM32>\config\bcd-template.inprocess to <SYSTEM32>\config\bcd-template.1btc
- from <SYSTEM32>\config\components to <SYSTEM32>\config\components.inprocess
- from <SYSTEM32>\config\components.inprocess to <SYSTEM32>\config\components.1btc
- from g:\bootsect.bak.inprocess to g:\bootsect.bak.1btc
- from %ProgramFiles%\mozilla firefox\precomplete to %ProgramFiles%\mozilla firefox\precomplete.inprocess
- from %ProgramFiles%\mozilla firefox\precomplete.inprocess to %ProgramFiles%\mozilla firefox\precomplete.1btc
- from %ProgramFiles%\mozilla thunderbird\precomplete to %ProgramFiles%\mozilla thunderbird\precomplete.inprocess
- from %ProgramFiles%\mozilla firefox\removed-files to %ProgramFiles%\mozilla firefox\removed-files.inprocess
- from %ProgramFiles%\mozilla firefox\removed-files.inprocess to %ProgramFiles%\mozilla firefox\removed-files.1btc
- from %ProgramFiles%\mozilla thunderbird\precomplete.inprocess to %ProgramFiles%\mozilla thunderbird\precomplete.1btc
- from %ProgramFiles%\mozilla thunderbird\removed-files to %ProgramFiles%\mozilla thunderbird\removed-files.inprocess
- from %ProgramFiles%\mozilla thunderbird\removed-files.inprocess to %ProgramFiles%\mozilla thunderbird\removed-files.1btc
- C:\kms\kms_vl_all_aio.cmd.inprocess
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\winre.wim.inprocess
- C:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tmcontainer00000000000000000001.regtrans-ms.inprocess
- C:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tm.blf.inprocess
- C:\users\default\ntuser.dat.log1.inprocess
- C:\users\default\ntuser.dat.log.inprocess
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\boot.sdi.inprocess
- <Drive name for removable media>:\cveuropeo.doc.inprocess
- %ProgramFiles%\mozilla thunderbird\removed-files.inprocess
- <Drive name for removable media>:\february_catalogue__2015.doc.inprocess
- %ProgramFiles%\mozilla thunderbird\precomplete.inprocess
- %ProgramFiles%\mozilla firefox\removed-files.inprocess
- %ProgramFiles%\mozilla firefox\precomplete.inprocess
- <Drive name for removable media>:\testcertificate.cer.inprocess
- <Drive name for removable media>:\testee.cer.inprocess
- <Drive name for removable media>:\sdksampleunprivdeveloper.cer.inprocess
- <Drive name for removable media>:\pmd.cer.inprocess
- <Drive name for removable media>:\contoso_1.cer.inprocess
- <Drive name for removable media>:\contosoroot.cer.inprocess
- <Drive name for removable media>:\tileimage.bmp.inprocess
- <Drive name for removable media>:\dialmap.bmp.inprocess
- <Drive name for removable media>:\dashborder_192.bmp.inprocess
- <Drive name for removable media>:\dashborder_120.bmp.inprocess
- <Drive name for removable media>:\coffee.bmp.inprocess
- <Drive name for removable media>:\join.avi.inprocess
- C:\kms\kms_vl_all_aio_debug.log.inprocess
- <Drive name for removable media>:\split.avi.inprocess
- D:\install.log.inprocess
- C:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tmcontainer00000000000000000002.regtrans-ms.inprocess
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excellr.cab.inprocess
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=c: /on=c: /maxsize=401MB
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=c: /on=c: /maxsize=unbounded
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=d: /on=d: /maxsize=401MB
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=d: /on=d: /maxsize=unbounded
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=e: /on=e: /maxsize=401MB
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=e: /on=e: /maxsize=unbounded
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=f: /on=f: /maxsize=401MB
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=f: /on=f: /maxsize=unbounded
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=g: /on=g: /maxsize=401MB
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=g: /on=g: /maxsize=unbounded
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=h: /on=h: /maxsize=401MB
- '<SYSTEM32>\vssadmin.exe' Resize ShadowStorage /for=h: /on=h: /maxsize=unbounded
- '<SYSTEM32>\bcdedit.exe' /set {default} bootstatuspolicy ignoreallfailures
- '<SYSTEM32>\wbadmin.exe' DELETE SYSTEMSTATEBACKUP
- '<SYSTEM32>\wbadmin.exe' DELETE SYSTEMSTATEBACKUP -deleteOldest
- '<SYSTEM32>\wbem\wmic.exe' SHADOWCOPY /nointeractive