Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\hwehlutoayztzhgcdwkaaj.locked
- <Drive name for removable media>:\bisswebzswrjhzskfjqatr.secure
- <Drive name for removable media>:\xefcvfsoocryyxdsdixfta.locked
- <Drive name for removable media>:\ktwvoompxckqadrjcadrqc.protected
- <Drive name for removable media>:\rmbizglvntjmgfytrqjtln.secure
- <Drive name for removable media>:\webeiqhkqsdxwahvdehost.protected
- <Drive name for removable media>:\cdsmvecysitvjtteyyufzg.locked
- <Drive name for removable media>:\glxazhfvxxcrjjumctoypx.locked
- <Drive name for removable media>:\mpndzgwqpwjdpjbkwjyhak.locked
- <Drive name for removable media>:\erfvpmxgcatdchrvzltaap.protected
- <Drive name for removable media>:\lbdtlsxcdnthtcjnajtnlp.locked
- <Drive name for removable media>:\onvhjdmjteodrivrtxrnxi.protected
- <Drive name for removable media>:\aaetxexrctiatzctgxyjqe.secure
- <Drive name for removable media>:\gwylbtcfjzvevzzeotgfpo.locked
- <Drive name for removable media>:\qtxnhjeicorocqadsdvhyg.secure
- <Drive name for removable media>:\jdodkjbynjzwqqkfwvjlna.protected
- <Drive name for removable media>:\rbtiajocuaubnbfwpdbcwy.locked
- <Drive name for removable media>:\rvseluciakacgbmyhiqzkc.protected
- <Drive name for removable media>:\jcamtonwpgkfoaqcmfmkym.protected
- <Drive name for removable media>:\bqookitggaepnbxbrbnspv.enc
- <Drive name for removable media>:\ulgsznwqtmtsrlnqimzmlk.locked
- <Drive name for removable media>:\frhqlubonuyqwvaqtcmccf.secure
- <Drive name for removable media>:\wfjtacvedtzaynsoelksal.secure
- <Drive name for removable media>:\kxbhizzigiazukqzacdczj.enc
- <Drive name for removable media>:\txagxngqwniipldjgfxrug.enc
- <Drive name for removable media>:\zwpgdjjbvvmyagutscpcxa.locked
- <Drive name for removable media>:\snluqkjmhasodvthspykmo.enc
- <Drive name for removable media>:\ofqjbvgsimrrhuiguziawh.secure
- <Drive name for removable media>:\tegmfcblnlloowsrrothzj.locked
- <Drive name for removable media>:\msqduhoyhqbfehgerzeoes.enc
- <Drive name for removable media>:\rgskhgvvvzsnboesjsnlgg.locked
- <Drive name for removable media>:\fupgvxjayczhfldetujpzi.protected
- <Drive name for removable media>:\ulmbiibwbhwbgrsvcshkqr.secure
- <Drive name for removable media>:\dybcayuxpsmbpqeshpckpl.enc
- <Drive name for removable media>:\jzkoirehzdlzahtmjwmseu.enc
- <Drive name for removable media>:\xmbrligxlsgzozwldfdhfs.secure
- <Drive name for removable media>:\kcspselnhuhwnrizaeyyvl.enc
- <Drive name for removable media>:\tnmexeicdnajbsjwirwzto.enc
- <Drive name for removable media>:\kkanxuhjrvwxefzstcpdnm.enc
- <Drive name for removable media>:\svgvernabbualuymoqffhi.secure
- <Drive name for removable media>:\hbfghmdlmwuiihfykscdtq.protected
- <Drive name for removable media>:\pirkrnahclrftktebfojuf.secure
- <Drive name for removable media>:\gtcddofysrpunmmaqarasz.protected
- <Drive name for removable media>:\hvcdlrymvyohsjzarpiuix.locked
- <Drive name for removable media>:\tplxqppfztiscmnfhvsoyx.secure
- <Drive name for removable media>:\ugeizccwsecvrragqeapty.protected
- <Drive name for removable media>:\swbbufgcbqhxofnqgkdbuw.protected
- <Drive name for removable media>:\aswldyqedhojyjbebapahr.protected
- <Drive name for removable media>:\mccgedftocdodsdqtrixqm.secure
- <Drive name for removable media>:\fzwguvvirpsoherpbvkzlb.enc
- <Drive name for removable media>:\wegsxjexuttixmlfkswjzk.protected
- <Drive name for removable media>:\fatzgcmgedaqdwvgjlxiho.enc
- <Drive name for removable media>:\cynnfznacntbvnztormeho.protected
- <Drive name for removable media>:\wizntenyvtsvqukkrfcktd.locked
- <Drive name for removable media>:\ioluvydthlitbhlwolwbqt.secure
- <Drive name for removable media>:\ufmzunforgogpzsyfgemid.protected
- <Drive name for removable media>:\rtbrzthlopxdyjgigumsbx.secure
- <Drive name for removable media>:\usgbeczpqkcdoliecqvzgi.protected
- <Drive name for removable media>:\ntnmvbpndgyeuijawscjkd.protected
- <Drive name for removable media>:\tezgnxrodbqeiuvfgvyfeh.enc
- <Drive name for removable media>:\kepszzrwtteievjugjhnrc.locked
- <Drive name for removable media>:\oteccqcpdzcrfdfbllermb.enc
- <Drive name for removable media>:\ipnvtrerbgbtapxqylrhfl.locked
- <Drive name for removable media>:\omxetqihxepowkfrsxopcb.locked
- <Drive name for removable media>:\anrebhedfclpadcphyjboa.protected
- <Drive name for removable media>:\maxaefjlhftuyixifystvb.secure
- <Drive name for removable media>:\cxzidbisjgagfxihsmghly.protected
- <Drive name for removable media>:\asvmqiurodjttkwxiomfze.enc
- <Drive name for removable media>:\fdcfxdqcsbdtvzpddjzvrm.secure
- <Drive name for removable media>:\weahefdktdwcyfyivkjnti.locked
- <Drive name for removable media>:\ghdpaafcmorzqhvkqlpwci.secure
- <Drive name for removable media>:\hynuaglhbzedobxoxurwuq.secure
- <Drive name for removable media>:\csalunrpxahixhxtsiufaf.enc
- <Drive name for removable media>:\sqnuewmpghfssjiheyutun.protected
- <Drive name for removable media>:\pxgievcgdiavczjbotgjiv.protected
- <Drive name for removable media>:\pplfmfisoufpizkkfiilmv.locked
- <Drive name for removable media>:\rbfqjgdgzmweilvcuntvfw.enc
- <Drive name for removable media>:\ffktxjjzpezogkjsldrrop.secure
- <Drive name for removable media>:\aqmjfyrbxbumlvywajzqmx.protected
- <Drive name for removable media>:\qfqkkvbvqtwssnjmwlxdmg.secure
- <Drive name for removable media>:\gzvwtzomyuefilwdismppw.protected
- <Drive name for removable media>:\rcfhecwknhsqlwareseunp.protected
- <Drive name for removable media>:\hfkwispfjfxltxkirzlsmz.enc
- <Drive name for removable media>:\qggpakgmuqrlgovewmjlcr.protected
- <Drive name for removable media>:\folpscnovnqowvippjjrhc.locked
- <Drive name for removable media>:\upyofsijhbpikbnpcylobw.secure
- <Drive name for removable media>:\xrlzcccvbiveihpayxtprd.secure
- <Drive name for removable media>:\pgxuhwzhehvezgvaozpsdo.enc
- <Drive name for removable media>:\oaxccugwjqzihpcrljvafj.enc
- <Drive name for removable media>:\ikwhcgklavnvvnmhdgteeo.secure
- <Drive name for removable media>:\ptutegmdjyfyfffqqnhhvm.locked
- <Drive name for removable media>:\sqphylglircxxmlnmmcnin.enc
- <Drive name for removable media>:\hwohpcfjwkawryeowkipbh.protected
- <Drive name for removable media>:\svhoyvlexzodfhjtnzmyhl.secure
- <Drive name for removable media>:\mqtcwdnpmmmvvxnswygtyp.protected
- <Drive name for removable media>:\eyqinonywxbqthfexybrxw.protected
- <Drive name for removable media>:\foqjsvmtcocbdxvkxplgpa.protected
- <Drive name for removable media>:\rdvgmswushxrbrlpburbvr.secure
- <Drive name for removable media>:\ggtmudyqsrihzyirnlqepx.protected
- <Drive name for removable media>:\buhvstbeoinaogimqtnpar.enc
- <Drive name for removable media>:\ktoektjmivmawlzwgxliuc.enc
- <Drive name for removable media>:\pmzjhpcuaeqouyvzvuzngi.enc
- <Drive name for removable media>:\ucmhwfirehgopnpalcqfle.enc
- <Drive name for removable media>:\vpiumcoylsoexgchjtnphm.secure
- <Drive name for removable media>:\ckajqqbkaboyruyukijhkl.protected
- <Drive name for removable media>:\ljqmrrxhcqukrstoeymxxx.protected
- <Drive name for removable media>:\esyaffyouoqnzumtenjhuq.protected
- <Drive name for removable media>:\jcgkxqudrcmjhkgtakzrnk.secure
- <Drive name for removable media>:\ivgeipvtiyyfqncrvuwwmr.enc
- <Drive name for removable media>:\sepkrokgegcmmgetxfpqwl.locked
- <Drive name for removable media>:\ttofydavfyyfhbrcyxshdd.enc
- <Drive name for removable media>:\fmkjchdwfcwgkivhkbjraa.protected
- <Drive name for removable media>:\ialefafciikyivizwfnzby.secure
- <Drive name for removable media>:\dipvwoxvaxghfmvyfpunmj.enc
- <Drive name for removable media>:\hlbvdhltjdgakowvsnobcb.enc
- <Drive name for removable media>:\system volume information\xkrmdggtjitexykaifiexn.locked
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
- '%WINDIR%\syswow64\net.exe' stop usbstor
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\1189.jpeg
- %HOMEPATH%\desktop\contosoroot_1.cer
- %HOMEPATH%\desktop\13.jpeg
- %HOMEPATH%\desktop\iisstart.htm
- %HOMEPATH%\desktop\dialmap.bmp
- %HOMEPATH%\desktop\about.html
- %HOMEPATH%\desktop\parnas_01.jpeg
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
- %HOMEPATH%\desktop\advice_process.htm
- %HOMEPATH%\desktop\coffee.bmp
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\testee.cer
- %HOMEPATH%\desktop\thlps_keeper_mayer_1965.docx
- %HOMEPATH%\desktop\tileimage.bmp
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- %HOMEPATH%\desktop\weeklysheet1215.doc
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = '127.0.0.1:9999'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyOverride' = 'www.bitpay.com;www.bitcoin.org;www.paybis.com;<local>'
- %TEMP%\original_wallpaper_path.txt
- %TEMP%\wallpaper.jpg
- %TEMP%\winapp2_filter.pac
- %LOCALAPPDATA%\nmrporvnb0sdixlex7\<File name>.exe_strongname_ll3mx3bhdqyk33x0wfxm3t4jncyyqmbo\1.0.0.0\vtusysgb.newcfg
- %HOMEPATH%\desktop\dgnonidrmcqgqwsgusihat.secure
- %HOMEPATH%\desktop\yaxcljvagxbfqbzfbzbdii.secure
- %HOMEPATH%\desktop\ohykvblemgrhvkwfdfshoc.locked
- %HOMEPATH%\desktop\jvcaudkjmqalpyjubgydij.protected
- %HOMEPATH%\desktop\zjjssuxhzdyoafvxclqiuy.enc
- %HOMEPATH%\desktop\kydsrfhuptbyhpwzdyrrbc.enc
- %HOMEPATH%\desktop\vwwdkjtbupgiudobzvaimr.enc
- %HOMEPATH%\desktop\lbvsdjwaknjmzdnktnsqei.protected
- %HOMEPATH%\desktop\rjizisafpdnnmonhersaia.protected
- %HOMEPATH%\desktop\qqsmeejebpaptmxosuidmv.protected
- %HOMEPATH%\desktop\bzahvfgoddkbmmmfeohggx.protected
- %HOMEPATH%\desktop\mlpyvqspdudfxdjxjtenzt.enc
- %HOMEPATH%\desktop\uualgpajdycslpwptqwdya.protected
- %HOMEPATH%\desktop\wcsjuofrfsrvbctqautkwd.secure
- %HOMEPATH%\desktop\vzgtqrpuluxehpbtatnhfy.locked
- %HOMEPATH%\desktop\gjhemiolmvkggtgqhiwtvb.protected
- %HOMEPATH%\desktop\nrvynvmqefthwediqcrvdl.secure
- %HOMEPATH%\desktop\erasdqiqghfwdczqteazak.enc
- %HOMEPATH%\desktop\azlkhgntsbfdlddiqgjrox.secure
- %HOMEPATH%\desktop\cldoceprbvlkpvaqlduifs.locked
- %HOMEPATH%\desktop\ifdhknndlhzdiamuycszgb.locked
- %HOMEPATH%\desktop\pnimalwgbnblkuabachahd.protected
- %HOMEPATH%\desktop\rnejcdgsjklceyimcuptaq.secure
- C:\$recycle.bin\s-1-5-21-4226853953-3309226944-3078887307-1000\qyznfditiqmgarwvnfqata.enc
- %APPDATA%\microsoft\windows\start menu\ixxvrbvteijimshzsplppo.enc
- %APPDATA%\microsoft\windows\start menu\programs\gkbcjeskqvzcsqkwsqmrum.secure
- %APPDATA%\microsoft\windows\start menu\programs\trcgnhorocruntboitdpxk.protected
- %APPDATA%\microsoft\windows\start menu\programs\accessibility\hphfmoswhiwdanlfkembgn.secure
- %APPDATA%\microsoft\windows\start menu\programs\accessibility\ddngpallwouttbcfqktqtf.locked
- %APPDATA%\microsoft\windows\start menu\programs\accessibility\oxlsnjudpztfkmftpoqsbn.locked
- %APPDATA%\microsoft\windows\start menu\programs\accessibility\yssraoihjmcbgpnijrwcny.locked
- %APPDATA%\microsoft\windows\start menu\programs\accessories\uupjsaiaqqvydxrnfcdlre.protected
- %APPDATA%\microsoft\windows\start menu\programs\accessories\ofxqbqqgwwqtphuadbjqxi.secure
- %APPDATA%\microsoft\windows\start menu\programs\administrative tools\yjwrclrmgjdftktswehbtv.locked
- %APPDATA%\microsoft\windows\start menu\programs\maintenance\jwfemjqfxnkjukqewnqtcx.locked
- %APPDATA%\microsoft\windows\start menu\programs\system tools\bllrgkcahdsgvaawczenfe.enc
- %APPDATA%\microsoft\windows\start menu\programs\system tools\hatiaatxsnjiwmbghijszh.protected
- %APPDATA%\microsoft\windows\start menu\programs\system tools\koqwrjyhccvnxccfjniwwp.secure
- %APPDATA%\microsoft\windows\start menu\programs\system tools\etaslkpykphqpqmzqgdaqj.protected
- %APPDATA%\microsoft\windows\start menu\programs\system tools\cdrumcqvqlfsxbmmrevysl.secure
- %APPDATA%\microsoft\windows\start menu\programs\system tools\ctiupqnleehhvbdbahiczb.protected
- %APPDATA%\microsoft\windows\start menu\programs\system tools\wqdyinlrzdwtkirlhxodgf.enc
- %APPDATA%\microsoft\windows\start menu\programs\telegram desktop\telfxqpzsnazyysbkxklpf.locked
- %APPDATA%\microsoft\windows\start menu\programs\telegram desktop\gowftqafnvxmrcmtknfcjf.locked
- %APPDATA%\microsoft\windows\start menu\programs\windows powershell\eokycsldphmqnbasjfvpvh.secure
- %APPDATA%\microsoft\windows\start menu\programs\windows powershell\nwfforhiypqvwmgsdoykdq.enc
- %APPDATA%\microsoft\windows\start menu\programs\winrar\iifpliejhvqomswglkzski.enc
- %APPDATA%\microsoft\windows\start menu\programs\winrar\bupyddkznozhitikxoyjiy.enc
- %APPDATA%\microsoft\windows\start menu\programs\winrar\lsukhxdegsfaotuynurjav.enc
- %APPDATA%\microsoft\windows\start menu\programs\winrar\idezomswlghsqyqutnawfs.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\taqijevpxjtolbnfzlxveo.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\jiltmvtzkzmnqrclxobwpw.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\bpjcyjjcjgdbilcfwhkhvv.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\qrwonastuyrualosnxcyhv.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\qtcgxdhsehjltcfmosnapq.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\nxlbjizmqnlcxxtyfqpvfr.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\ynkstznksfrzfooflctdnn.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\orvcpeyhpxrxdzazqrkrqi.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\bimfareqcunyrvxwowgpqm.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\wwfxwxvupioqvjaorjghbp.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\hgukgjootdiyuqidzhhwbh.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\erjqfmsjfnjuyhkpvuyijo.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mcaikfqembfufabenflfsm.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\qwumwdtivhbezeqtgpctfo.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\cwculskjkvscgywnomxums.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessibility\gmktkkxpupzczylzzkkppx.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessibility\nhkymuwufdhaobzhldnrpm.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\qwdltenjmqxwipmrjhsenl.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\uhbiimsquechjkbudqbegy.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\nasmbuitrmatlgipqqdgsg.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\owrrosmfgibrzqyozjrwak.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\vzgacbpepyjtvztbbmwibq.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\ndeagfbvkjgrqxtaojbpoc.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\qizjvppktlwgesemnlgema.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\aeuezychommcwjlzmnldyc.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\ehmztzwbgfnsnghsegnpve.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\kqduucdagzyeqhixzobvmh.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\jajbtririeuntlbeazisox.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\yflfhhmfzytrasyfrlunzx.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\ihgqmkqscnuciwwojpmmkc.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\jdqaobksomshstqsuzwrlv.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\lloegnhcsaszwapmherdln.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\ltrinnddvsuzfmzfsamhsa.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\qifzwezduursswozxnadug.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\wjauilnsxrqxwmflwvmzrb.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\kepmejeknnjrcxgxrkiloy.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\mmbhlncseinondbzgzcqad.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\buolkbmafpjqtfdlbzplvw.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\fnnqknfhvjsbrtqineamfx.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\aqtmdouoxhmvfhulpitwny.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\jfxswzukoogcmwuyrvwxzt.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\uymjtfvigyrrjucejycdft.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\ztziobfuizfwphncudfjls.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\cmjoutzslpjgcmthxotvdc.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\yktivfpelknpwvwcmyjclz.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\ouwzpyctbbgkxqtdfnuble.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\pythrlmonodxhuatucvbxz.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\yvoozpgcdhhydrqiafdpfi.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\dbjufeikhirqsbtcjyftrd.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\meycgreivngrlzjmomndby.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\ubqjbokpznbrsxplmdbmah.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\raintivnchuzrahjpwfoui.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\btjwjuwiiislsdgienyyjr.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\cpyijzzegptyronbommxlj.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\xjvqfyjscipntbgnzbzmwk.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\skkzafhdprlreikizaafpq.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\bwpfhdkhioytppkisacqil.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\htxvznwijfayzarfcqhtzi.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\peiivixvpnkaeuzvdeacgc.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\nheothjnzzekqrulkgvtzb.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\wxgmbpftihoyzpmvkdkxmk.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\mbovomhbccgylqihqohapt.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\ebafxlqjsgfbrkimxcbopc.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\ulpupleurwlpjuixqiwtme.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\steam\rkdbnpgkweduvlyjprxukc.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\system tools\kpxqpspkthprrismnkcbub.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\system tools\bextrirtoxeuopcjkvfehk.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows powershell\zoxmnpoajepnspmwhakzqy.enc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows powershell\oqrtvwemuxxjqzwtbwgeam.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows powershell\miefvsjdjxnzebjfvnwzqr.protected
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\jpaagjzfnxhaaxfqnimots.secure
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\xepdyykdbvkxybjrpkzjnj.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\kvzvffblkvgcfsnzsesnxc.locked
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\ubksyxlpeirepgpcpsynzf.protected
- D:\$recycle.bin\s-1-5-21-4226853953-3309226944-3078887307-1000\fmiqiihehbshypsxdihokq.secure
- from %LOCALAPPDATA%\nmrporvnb0sdixlex7\<File name>.exe_strongname_ll3mx3bhdqyk33x0wfxm3t4jncyyqmbo\1.0.0.0\vtusysgb.newcfg to %LOCALAPPDATA%\nmrporvnb0sdixlex7\<File name>.exe_strongname_ll3mx3bhdqyk33x0wfxm3t4jncyyqmbo\1.0.0.0\user.config
- %APPDATA%\microsoft\windows\themes\transcodedwallpaper
- %LOCALAPPDATA%\microsoft\windows\explorer\thumbcache_idx.db
- %APPDATA%\microsoft\windows\themes\cachedfiles\cachedimage_1152_864_pos2.jpg
- 'ap#.##legram.org':443
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org
- ClassName: 'Shell_traywnd' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c net stop usbstor
- '%WINDIR%\syswow64\net1.exe' stop usbstor