La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Trojan.Encoder.35975

Aggiunto al database dei virus Dr.Web: 2022-09-30

La descrizione è stata aggiunta:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'End.ex3' = '"%LOCALAPPDATA%\{319AEC34-0102-D9C9-277E-433995B84567}\End.ex3.exe" -e all -sd -crc '
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tv_x64.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tv_w32.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TeamViewer_Service.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TeamViewer.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbirdconfig.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Sysmon64.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Sysmon.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ssms.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlwriter.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlservr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlmangr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlbrowser.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlagent.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sql.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqbcoreservice.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SimplyConnectionManager.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\raw_agent_svc.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tomcat6.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsnapvss.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vxmon.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wdswfsafe.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shutdown.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\logoff.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perfmon.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsqmcons.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CompatTelRunner.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SearchProtocolHost.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SearchApp.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SearchIndexer.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlservrs.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SystemExplorer.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\r.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xfssvccon.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wxServerView.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wxServer.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsa_service.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\Software\Classes\mimicfile\shell\open\command] '' = 'notepad.exe "%LOCALAPPDATA%\ID.txt"'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAgui.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VeeamDeploymentSvc.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RaccineSettings.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msftesql.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsDtSrvr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isqlplussvc.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\httpd.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fdlauncher.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fdhost.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fbserver.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fbguard.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EnterpriseClient.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\encsvc.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dbsnmp.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dbeng50.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Creative Cloud.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKCU>\Software\Classes\exefile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\Software\Classes\exefile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mydesktopqos.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mydesktopservice.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysqld.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysqld-nt.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Raccine_x86.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Raccine.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBW64.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBW32.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qbupdate.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBIDPService.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBDBMgrN.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBDBMgr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\python.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wpython.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\java.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\node.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pvlsvr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oracle.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocssd.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocomm.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocautoupds.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysqld-opt.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RaccineElevatedCfg.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\Software\Classes\.com] '' = 'mimicfile'
Malicious functions
To complicate detection of its presence in the operating system,
blocks execution of the following system utilities:
  • Windows Update
  • Windows Defender
blocks the following features:
  • User Account Control (UAC)
modifies the following system settings:
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'StartMenuLogOff' = '00000001'
Modifies file system
Creates the following files
  • %TEMP%\7zipsfx.000\7za.exe
  • %TEMP%\7zsfx000.cmd
  • %TEMP%\bvaelxc
  • %TEMP%\autc419.tmp
  • C:\temp\session.tmp
  • C:\id.txt
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\session.tmp
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\sdel64.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\sdel.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything64.dll
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything32.dll
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything2.ini
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything.ini
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\dc.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\7za.exe
  • %TEMP%\7zipsfx.000\sdel64.exe
  • %TEMP%\7zipsfx.000\sdel.exe
  • %TEMP%\7zipsfx.000\end.ex3.exe
  • %TEMP%\7zipsfx.000\dc.exe
  • %TEMP%\7zipsfx.000\everything2.ini
  • %TEMP%\7zipsfx.000\everything.ini
  • %TEMP%\7zipsfx.000\everything64.dll
  • %TEMP%\7zipsfx.000\everything32.dll
  • %TEMP%\7zipsfx.000\everything.exe
  • %LOCALAPPDATA%\id.txt
  • C:\temp\hashlist.txt
Deletes the following files
  • %TEMP%\autc419.tmp
  • %TEMP%\bvaelxc
  • %TEMP%\7zipsfx.000\7za.exe
  • %TEMP%\7zipsfx.000\dc.exe
  • %TEMP%\7zipsfx.000\end.ex3.exe
  • %TEMP%\7zipsfx.000\everything.exe
  • %TEMP%\7zipsfx.000\everything.ini
  • %TEMP%\7zipsfx.000\everything2.ini
  • %TEMP%\7zipsfx.000\everything32.dll
  • %TEMP%\7zipsfx.000\everything64.dll
  • %TEMP%\7zipsfx.000\sdel.exe
  • %TEMP%\7zipsfx.000\sdel64.exe
  • %TEMP%\7zsfx000.cmd
Moves the following files
  • from %APPDATA%\telegram desktop\tdata\90ef50e22e92cb8c0 to %APPDATA%\telegram desktop\tdata\90ef50e22e92cb8c0.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_controllerhud.webm to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_controllerhud.webm.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_gyro.webm to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_gyro.webm.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_english.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_english.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_shortcuts.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_shortcuts.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_moystick.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_moystick.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_mouseregions.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_mouseregions.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_hometheater.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_hometheater.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_gyro_touchmenu.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_gyro_touchmenu.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_thai.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_thai.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_hungarian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_hungarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_tchinese.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_tchinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_koreana.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_koreana.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_korean.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_korean.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_danish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_danish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_czech.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_czech.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\styles\steamstyles.css to %ProgramFiles(x86)%\steam\tenfoot\resource\styles\steamstyles.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_ukrainian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_ukrainian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_norwegian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_norwegian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\styles\library\library.css to %ProgramFiles(x86)%\steam\tenfoot\resource\styles\library\library.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_japanese.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_japanese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_schinese.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_schinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_danish.txt to %ProgramFiles(x86)%\steam\friends\trackerui_danish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_russian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_russian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_italian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_italian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_japanese.txt to %ProgramFiles(x86)%\steam\public\steamui_japanese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\accessibility.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\accessibility.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\3difr.x3d to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\3difr.x3d.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\1494870c-9912-c184-4cc9-b401-a53f4d8de290.pdf to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\1494870c-9912-c184-4cc9-b401-a53f4d8de290.pdf.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\qip 2012\unins000.dat to %ProgramFiles(x86)%\qip 2012\unins000.dat.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_turkish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_turkish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_swedish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_swedish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_spanish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_spanish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_romanian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_romanian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_portuguese.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_portuguese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_polish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_polish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_greek.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_greek.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_german.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_german.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_french.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_french.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_finnish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_finnish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_dutch.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_dutch.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_brazilian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_brazilian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_thai.txt to %ProgramFiles(x86)%\steam\public\steamui_thai.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_spanish.txt to %ProgramFiles(x86)%\steam\public\steamui_spanish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_schinese.txt to %ProgramFiles(x86)%\steam\public\steamui_schinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_german.txt to %ProgramFiles(x86)%\steam\public\steamui_german.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\annots.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\annots.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_danish.txt to %ProgramFiles(x86)%\steam\public\steamui_danish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\remoteui_all.zip.ba22fb168ed139d9979cdd1cefbd911e3ed3529c to %ProgramFiles(x86)%\steam\package\remoteui_all.zip.ba22fb168ed139d9979cdd1cefbd911e3ed3529c.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_bulgarian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_bulgarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_bulgarian.txt to %ProgramFiles(x86)%\steam\friends\trackerui_bulgarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_portuguese.txt to %ProgramFiles(x86)%\steam\friends\trackerui_portuguese.txt.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\zip64.sfx to %ProgramFiles%\winrar\zip64.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\zip.sfx to %ProgramFiles%\winrar\zip.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\default64.sfx to %ProgramFiles%\winrar\default64.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\default.sfx to %ProgramFiles%\winrar\default.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\wincon64.sfx to %ProgramFiles%\winrar\wincon64.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\wincon.sfx to %ProgramFiles%\winrar\wincon.sfx.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\te.pak to %ProgramFiles(x86)%\steam\bin\locales\te.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\ta.pak to %ProgramFiles(x86)%\steam\bin\locales\ta.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_ukrainian.txt to %ProgramFiles(x86)%\steam\public\steamui_ukrainian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\natives_blob.bin to %ProgramFiles(x86)%\steam\bin\natives_blob.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\ml.pak to %ProgramFiles(x86)%\steam\bin\locales\ml.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\kn.pak to %ProgramFiles(x86)%\steam\bin\locales\kn.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\devtools_resources.pak to %ProgramFiles(x86)%\steam\bin\devtools_resources.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\content_resources.pak to %ProgramFiles(x86)%\steam\bin\content_resources.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\component_extension_resources.pak to %ProgramFiles(x86)%\steam\bin\component_extension_resources.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\cef_extensions.pak to %ProgramFiles(x86)%\steam\bin\cef_extensions.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\cef_200_percent.pak to %ProgramFiles(x86)%\steam\bin\cef_200_percent.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\cef_100_percent.pak to %ProgramFiles(x86)%\steam\bin\cef_100_percent.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_schinese.txt to %ProgramFiles(x86)%\steam\friends\trackerui_schinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_spanish.txt to %ProgramFiles(x86)%\steam\friends\trackerui_spanish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_thai.txt to %ProgramFiles(x86)%\steam\friends\trackerui_thai.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_turkish.txt to %ProgramFiles(x86)%\steam\friends\trackerui_turkish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_english.txt to %ProgramFiles(x86)%\steam\public\steamui_english.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_turkish.txt to %ProgramFiles(x86)%\steam\public\steamui_turkish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_swedish.txt to %ProgramFiles(x86)%\steam\public\steamui_swedish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_russian.txt to %ProgramFiles(x86)%\steam\public\steamui_russian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_romanian.txt to %ProgramFiles(x86)%\steam\public\steamui_romanian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_portuguese.txt to %ProgramFiles(x86)%\steam\public\steamui_portuguese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_polish.txt to %ProgramFiles(x86)%\steam\public\steamui_polish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_norwegian.txt to %ProgramFiles(x86)%\steam\public\steamui_norwegian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_koreana.txt to %ProgramFiles(x86)%\steam\public\steamui_koreana.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_korean.txt to %ProgramFiles(x86)%\steam\public\steamui_korean.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\checkers.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\checkers.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_italian.txt to %ProgramFiles(x86)%\steam\public\steamui_italian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_greek.txt to %ProgramFiles(x86)%\steam\public\steamui_greek.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_finnish.txt to %ProgramFiles(x86)%\steam\public\steamui_finnish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_dutch.txt to %ProgramFiles(x86)%\steam\public\steamui_dutch.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_czech.txt to %ProgramFiles(x86)%\steam\public\steamui_czech.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_bulgarian.txt to %ProgramFiles(x86)%\steam\public\steamui_bulgarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_brazilian.txt to %ProgramFiles(x86)%\steam\public\steamui_brazilian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_russian.txt to %ProgramFiles(x86)%\steam\friends\trackerui_russian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_german.txt to %ProgramFiles(x86)%\steam\friends\trackerui_german.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_czech.txt to %ProgramFiles(x86)%\steam\friends\trackerui_czech.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_hungarian.txt to %ProgramFiles(x86)%\steam\public\steamui_hungarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_tchinese.txt to %ProgramFiles(x86)%\steam\public\steamui_tchinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_french.txt to %ProgramFiles(x86)%\steam\public\steamui_french.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\digsig.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\digsig.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\dropboxstorage.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\dropboxstorage.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\drvdx9.x3d to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\drvdx9.x3d.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\main.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\main.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\main-high-contrast.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\main-high-contrast.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\js\faf-main.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\js\faf-main.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\css\faf-main.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\css\faf-main.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\tool\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\tool\plugin.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\home-view\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\home-view\plugin.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\css\main.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\css\main.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\exportpdf-tool-view.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\exportpdf-tool-view.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\exportpdf-rna-tool-view.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\exportpdf-rna-tool-view.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\exportpdf-rna-selector.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\exportpdf-rna-selector.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\convertpdf-rna-tool-view.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\convertpdf-rna-tool-view.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\convertpdf-rna-selector.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\convertpdf-rna-selector.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\convertpdf-tool-view.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\convertpdf-tool-view.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\convertpdf-selector.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\convertpdf-selector.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\exportpdf-selector.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\exportpdf-selector.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\more-inside-2x.png to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\more-inside-2x.png.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\unified-e-signature-2x.png to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\unified-e-signature-2x.png.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\get-e-signatures-2x.png to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\get-e-signatures-2x.png.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\new-features-have-arrived-2x.png to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\new-features-have-arrived-2x.png.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\installer\chrome.7z to %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\installer\chrome.7z.fortguardseven@gmail.com
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\content-prefs.sqlite to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\content-prefs.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\session.dbak to %APPDATA%\opera software\opera stable\session.dbak.fortguardseven@gmail.com
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\permissions.sqlite to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\permissions.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\opt.dbs.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\permissions.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\permissions.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\bookmarksextras to %APPDATA%\opera software\opera stable\bookmarksextras.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\visited links to %APPDATA%\opera software\opera stable\visited links.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\history to %APPDATA%\opera software\opera stable\history.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\session.db to %APPDATA%\opera software\opera stable\session.db.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\webappsstore.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\webappsstore.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\cert8.db to %APPDATA%\thunderbird\profiles\wjj9aet2.default\cert8.db.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\places.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\places.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\cookies.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\cookies.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\global-messages-db.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\global-messages-db.sqlite.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\js\plugin.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\cef.pak to %ProgramFiles(x86)%\steam\bin\cef.pak.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\blist.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\blist.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\storage\ext\sync-login\def\gpucache\data_1 to %APPDATA%\opera software\opera stable\storage\ext\sync-login\def\gpucache\data_1.fortguardseven@gmail.com
  • from %APPDATA%\mra\base\mra.dbs to %APPDATA%\mra\base\mra.dbs.fortguardseven@gmail.com
  • from %APPDATA%\mra\base\opt.dbs to %APPDATA%\mra\base\opt.dbs.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\thumbnails.db to %APPDATA%\opera software\opera stable\thumbnails.db.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\favorites.db to %APPDATA%\opera software\opera stable\favorites.db.fortguardseven@gmail.com
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\healthreport.sqlite to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\healthreport.sqlite.fortguardseven@gmail.com
  • from %ProgramFiles%\java\jre1.8.0_45\lib\security\cacerts to %ProgramFiles%\java\jre1.8.0_45\lib\security\cacerts.fortguardseven@gmail.com
  • from %ProgramFiles%\java\jre1.8.0_45\lib\classlist to %ProgramFiles%\java\jre1.8.0_45\lib\classlist.fortguardseven@gmail.com
  • from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\mra.dbs.fortguardseven@gmail.com
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\storage\ext\sync-login\def\gpucache\index to %APPDATA%\opera software\opera stable\storage\ext\sync-login\def\gpucache\index.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\snapshot_blob.bin to %ProgramFiles(x86)%\steam\bin\snapshot_blob.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\images\edit_pdf_poster2x.jpg to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\images\edit_pdf_poster2x.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\bins_misc_win32.zip.1db89a4dcad9b10b32243aa6a9de7c4d71d7fce7 to %ProgramFiles(x86)%\steam\package\bins_misc_win32.zip.1db89a4dcad9b10b32243aa6a9de7c4d71d7fce7.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef_100_percent.pak to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef_100_percent.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef.pak to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\weblink.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\weblink.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\updater.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\updater.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\spelling.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\spelling.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\sendmail.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\sendmail.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\search.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\search.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\saveasrtf.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\saveasrtf.api.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\local storage\https_www.yandex.ru_0.localstorage to %APPDATA%\opera software\opera stable\local storage\https_www.yandex.ru_0.localstorage.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\reflow.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\reflow.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\prcr.x3d to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\prcr.x3d.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\ppklite.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\ppklite.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\pddom.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\pddom.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\multimedia.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\multimedia.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\makeaccessible.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\makeaccessible.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\ia32.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\ia32.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\escript.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\escript.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\dva.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\dva.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\drvsoft.x3d to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\drvsoft.x3d.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\javascripts\jsbytecodewin.bin to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\javascripts\jsbytecodewin.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\readoutloud.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\readoutloud.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef_200_percent.pak to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef_200_percent.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\icudtl.dat to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\icudtl.dat.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\natives_blob.bin to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\natives_blob.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\snapshot_blob.bin to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\snapshot_blob.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\bins_win32.zip.c3ecb4b509fab15dec05a4686a38071da3f5b32a to %ProgramFiles(x86)%\steam\package\bins_win32.zip.c3ecb4b509fab15dec05a4686a38071da3f5b32a.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\steam_win32.zip.08396f3b6b20aee64f6e22dd2eff32b5be16b930 to %ProgramFiles(x86)%\steam\package\steam_win32.zip.08396f3b6b20aee64f6e22dd2eff32b5be16b930.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\ssa_win32.zip.adc4b0a71d32370b39174c74c7ff563113b1116f to %ProgramFiles(x86)%\steam\package\ssa_win32.zip.adc4b0a71d32370b39174c74c7ff563113b1116f.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\bins_cef_win32.zip.4447a3d2f9ac1e2fbc533033cf235404866a27a7 to %ProgramFiles(x86)%\steam\package\bins_cef_win32.zip.4447a3d2f9ac1e2fbc533033cf235404866a27a7.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\strings_all.zip.53f00b54cffc710742dd4bd3e60f27417582fee5 to %ProgramFiles(x86)%\steam\package\strings_all.zip.53f00b54cffc710742dd4bd3e60f27417582fee5.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_all.zip.bd1519d47a9aed716a567a0661bf80bddc2883c4 to %ProgramFiles(x86)%\steam\package\tenfoot_all.zip.bd1519d47a9aed716a567a0661bf80bddc2883c4.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\resources_misc_all.zip.6b98785251045457e56ce493e4974efc336c1912 to %ProgramFiles(x86)%\steam\package\resources_misc_all.zip.6b98785251045457e56ce493e4974efc336c1912.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\resources_all.zip.e13bd8e3ea04b9ccbdd9cdb20ffa3a3ed0c55841 to %ProgramFiles(x86)%\steam\package\resources_all.zip.e13bd8e3ea04b9ccbdd9cdb20ffa3a3ed0c55841.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\rna-main.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\rna-main.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\strings_en_all.zip.cb080e501f60c33549dc909fc83e724c03bb3b87 to %ProgramFiles(x86)%\steam\package\strings_en_all.zip.cb080e501f60c33549dc909fc83e724c03bb3b87.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\steam_client_win32.installed to %ProgramFiles(x86)%\steam\package\steam_client_win32.installed.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\public_all.zip.cead2b93e0927b8f764d31fa410ac5f1e8c39233 to %ProgramFiles(x86)%\steam\package\public_all.zip.cead2b93e0927b8f764d31fa410ac5f1e8c39233.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\bins_codecs_win32.zip.4d5d0cec7d7c337abfbd8be9d020c06e6928b1c2 to %ProgramFiles(x86)%\steam\package\bins_codecs_win32.zip.4d5d0cec7d7c337abfbd8be9d020c06e6928b1c2.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_images_all.zip.3f5109256d433f180d0ea066398bbad9804ba276 to %ProgramFiles(x86)%\steam\package\tenfoot_images_all.zip.3f5109256d433f180d0ea066398bbad9804ba276.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_dicts_all.zip.c74a3a9beb77a280cfd8761b901a80ed0f6a3173 to %ProgramFiles(x86)%\steam\package\tenfoot_dicts_all.zip.c74a3a9beb77a280cfd8761b901a80ed0f6a3173.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_fonts_all.zip.505590f6014431a95a9750073e466372f3e98d88 to %ProgramFiles(x86)%\steam\package\tenfoot_fonts_all.zip.505590f6014431a95a9750073e466372f3e98d88.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_ambientsounds_all.zip.20ccff954777943069dd2c57576216f5f1db7389 to %ProgramFiles(x86)%\steam\package\tenfoot_ambientsounds_all.zip.20ccff954777943069dd2c57576216f5f1db7389.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_sounds_all.zip.843f5376c132f306d1b21dc564b3fe2057104e24 to %ProgramFiles(x86)%\steam\package\tenfoot_sounds_all.zip.843f5376c132f306d1b21dc564b3fe2057104e24.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_misc_all.zip.b9c015520018655499338cfc2c3a3159e28bbe14 to %ProgramFiles(x86)%\steam\package\tenfoot_misc_all.zip.b9c015520018655499338cfc2c3a3159e28bbe14.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\ssa\ssa_german_bigpicture.html to %ProgramFiles(x86)%\steam\public\ssa\ssa_german_bigpicture.html.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\ssa_noarch.zip.7cb02fff8f34cc739f6b7098cf1a36494a94653e to %ProgramFiles(x86)%\steam\package\ssa_noarch.zip.7cb02fff8f34cc739f6b7098cf1a36494a94653e.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\ssa_german.htm to %ProgramFiles(x86)%\steam\public\ssa_german.htm.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\gamesforwindows_win32.zip.2cbf7a087f4452016065bb75c9b025dbc6885e32 to %ProgramFiles(x86)%\steam\package\gamesforwindows_win32.zip.2cbf7a087f4452016065bb75c9b025dbc6885e32.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\bn.pak to %ProgramFiles(x86)%\steam\bin\locales\bn.pak.fortguardseven@gmail.com
Modifies the following files
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\34ece1f12cc26ee8ef9e091457d83bac5b3b6057.fortguardseven@gmail.com
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\index.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\f_000003.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\f_000004.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\f_000005.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\f_000009.fortguardseven@gmail.com
  • %APPDATA%\opera software\opera stable\session.db.fortguardseven@gmail.com
  • %APPDATA%\opera software\opera stable\history.fortguardseven@gmail.com
  • %APPDATA%\opera software\opera stable\visited links.fortguardseven@gmail.com
  • %APPDATA%\opera software\opera stable\bookmarksextras.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\data_1.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\data_3.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\data_2.fortguardseven@gmail.com
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_1.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\78e4fac58387fa4f0dd1f2e8a2c06aa8dbd296c8.fortguardseven@gmail.com
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\e5295e9fb3c5b25aaabdb3bc390b4fa47f284a34.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\97e0383f498a11b436ed828ab238348bcc54c26e.fortguardseven@gmail.com
  • %APPDATA%\telegram desktop\tdata\90ef50e22e92cb8c0.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\0c7045d9422d72e7f733934ceb30e7bd2de19729.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\10387b4ee0914a9aec44e27c64e82d6036936184.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\021a161175a596c8f58806e6b2013541f300826b.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\0e6c99412d117599a7b3e2c7a37ee511a84ef921.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\30c9e630fc5c8d218210b63d5cab97c59a7c9fc1.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\25cd45c284737fdff18ae1c1c47e9e1d70748a7d.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\37cbab75615b4f3cfe982f627f85eaa80ca9ad64.fortguardseven@gmail.com
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\chromedwritefontcache.fortguardseven@gmail.com
  • %LOCALAPPDATA%\steam\htmlcache\chromedwritefontcache.fortguardseven@gmail.com
Modifies multiple files.
Substitutes the following files
  • %ALLUSERSPROFILE%\ntuser.pol
  • %HOMEPATH%\ntuser.pol
  • %ALLUSERSPROFILE%\tempntuser.pol
Deletes itself.
Network activity
Connects to
  • '<LOCALNET>.28.0':445
  • '<LOCALNET>.28.161':445
  • '<LOCALNET>.28.162':445
  • '<LOCALNET>.28.163':445
  • '<LOCALNET>.28.164':445
  • '<LOCALNET>.28.165':445
  • '<LOCALNET>.28.166':445
  • '<LOCALNET>.28.167':445
  • '<LOCALNET>.28.168':445
  • '<LOCALNET>.28.169':445
  • '<LOCALNET>.28.170':445
  • '<LOCALNET>.28.171':445
  • '<LOCALNET>.28.172':445
  • '<LOCALNET>.28.173':445
  • '<LOCALNET>.28.175':445
  • '<LOCALNET>.28.189':445
  • '<LOCALNET>.28.176':445
  • '<LOCALNET>.28.177':445
  • '<LOCALNET>.28.178':445
  • '<LOCALNET>.28.179':445
  • '<LOCALNET>.28.180':445
  • '<LOCALNET>.28.181':445
  • '<LOCALNET>.28.182':445
  • '<LOCALNET>.28.183':445
  • '<LOCALNET>.28.184':445
  • '<LOCALNET>.28.185':445
  • '<LOCALNET>.28.186':445
  • '<LOCALNET>.28.187':445
  • '<LOCALNET>.28.188':445
  • '<LOCALNET>.28.160':445
  • '<LOCALNET>.28.174':445
  • '<LOCALNET>.28.159':445
  • '<LOCALNET>.28.142':445
  • '<LOCALNET>.28.129':445
  • '<LOCALNET>.28.130':445
  • '<LOCALNET>.28.131':445
  • '<LOCALNET>.28.132':445
  • '<LOCALNET>.28.133':445
  • '<LOCALNET>.28.134':445
  • '<LOCALNET>.28.135':445
  • '<LOCALNET>.28.136':445
  • '<LOCALNET>.28.137':445
  • '<LOCALNET>.28.138':445
  • '<LOCALNET>.28.139':445
  • '<LOCALNET>.28.140':445
  • '<LOCALNET>.28.141':445
  • '<LOCALNET>.28.143':445
  • '<LOCALNET>.28.157':445
  • '<LOCALNET>.28.144':445
  • '<LOCALNET>.28.145':445
  • '<LOCALNET>.28.146':445
  • '<LOCALNET>.28.147':445
  • '<LOCALNET>.28.148':445
  • '<LOCALNET>.28.149':445
  • '<LOCALNET>.28.150':445
  • '<LOCALNET>.28.151':445
  • '<LOCALNET>.28.152':445
  • '<LOCALNET>.28.153':445
  • '<LOCALNET>.28.154':445
  • '<LOCALNET>.28.155':445
  • '<LOCALNET>.28.156':445
  • '<LOCALNET>.28.158':445
  • '<LOCALNET>.28.207':445
  • '<LOCALNET>.28.253':445
  • '<LOCALNET>.28.192':445
  • '<LOCALNET>.28.225':445
  • '<LOCALNET>.28.226':445
  • '<LOCALNET>.28.227':445
  • '<LOCALNET>.28.228':445
  • '<LOCALNET>.28.229':445
  • '<LOCALNET>.28.230':445
  • '<LOCALNET>.28.231':445
  • '<LOCALNET>.28.232':445
  • '<LOCALNET>.28.233':445
  • '<LOCALNET>.28.234':445
  • '<LOCALNET>.28.235':445
  • '<LOCALNET>.28.236':445
  • '<LOCALNET>.28.237':445
  • '<LOCALNET>.28.239':445
  • '<LOCALNET>.28.191':445
  • '<LOCALNET>.28.240':445
  • '<LOCALNET>.28.241':445
  • '<LOCALNET>.28.242':445
  • '<LOCALNET>.28.243':445
  • '<LOCALNET>.28.244':445
  • '<LOCALNET>.28.245':445
  • '<LOCALNET>.28.246':445
  • '<LOCALNET>.28.247':445
  • '<LOCALNET>.28.248':445
  • '<LOCALNET>.28.249':445
  • '<LOCALNET>.28.250':445
  • '<LOCALNET>.28.251':445
  • '<LOCALNET>.28.252':445
  • '<LOCALNET>.28.224':445
  • '<LOCALNET>.28.128':445
  • '<LOCALNET>.28.223':445
  • '<LOCALNET>.28.206':445
  • '<LOCALNET>.28.193':445
  • '<LOCALNET>.28.194':445
  • '<LOCALNET>.28.195':445
  • '<LOCALNET>.28.196':445
  • '<LOCALNET>.28.197':445
  • '<LOCALNET>.28.198':445
  • '<LOCALNET>.28.199':445
  • '<LOCALNET>.28.200':445
  • '<LOCALNET>.28.201':445
  • '<LOCALNET>.28.202':445
  • '<LOCALNET>.28.203':445
  • '<LOCALNET>.28.204':445
  • '<LOCALNET>.28.205':445
  • '<LOCALNET>.28.190':445
  • '<LOCALNET>.28.221':445
  • '<LOCALNET>.28.208':445
  • '<LOCALNET>.28.209':445
  • '<LOCALNET>.28.210':445
  • '<LOCALNET>.28.211':445
  • '<LOCALNET>.28.212':445
  • '<LOCALNET>.28.213':445
  • '<LOCALNET>.28.214':445
  • '<LOCALNET>.28.215':445
  • '<LOCALNET>.28.216':445
  • '<LOCALNET>.28.217':445
  • '<LOCALNET>.28.218':445
  • '<LOCALNET>.28.219':445
  • '<LOCALNET>.28.220':445
  • '<LOCALNET>.28.222':445
  • '<LOCALNET>.28.238':445
  • '<LOCALNET>.28.127':445
  • '<LOCALNET>.28.110':445
  • '<LOCALNET>.28.33':445
  • '<LOCALNET>.28.34':445
  • '<LOCALNET>.28.35':445
  • '<LOCALNET>.28.36':445
  • '<LOCALNET>.28.37':445
  • '<LOCALNET>.28.38':445
  • '<LOCALNET>.28.39':445
  • '<LOCALNET>.28.40':445
  • '<LOCALNET>.28.41':445
  • '<LOCALNET>.28.42':445
  • '<LOCALNET>.28.43':445
  • '<LOCALNET>.28.44':445
  • '<LOCALNET>.28.45':445
  • '<LOCALNET>.28.47':445
  • '<LOCALNET>.28.61':445
  • '<LOCALNET>.28.48':445
  • '<LOCALNET>.28.49':445
  • '<LOCALNET>.28.50':445
  • '<LOCALNET>.28.51':445
  • '<LOCALNET>.28.52':445
  • '<LOCALNET>.28.53':445
  • '<LOCALNET>.28.54':445
  • '<LOCALNET>.28.55':445
  • '<LOCALNET>.28.56':445
  • '<LOCALNET>.28.57':445
  • '<LOCALNET>.28.58':445
  • '<LOCALNET>.28.59':445
  • '<LOCALNET>.28.60':445
  • '<LOCALNET>.28.32':445
  • '<LOCALNET>.28.46':445
  • '<LOCALNET>.28.31':445
  • '<LOCALNET>.28.14':445
  • '<LOCALNET>.28.1':445
  • '<LOCALNET>.28.2':445
  • '<LOCALNET>.28.3':445
  • '<LOCALNET>.28.4':445
  • '<LOCALNET>.28.5':445
  • '<LOCALNET>.28.6':445
  • '<LOCALNET>.28.7':445
  • '<LOCALNET>.28.8':445
  • '<LOCALNET>.28.9':445
  • '<LOCALNET>.28.10':445
  • '<LOCALNET>.28.11':445
  • '<LOCALNET>.28.12':445
  • '<LOCALNET>.28.13':445
  • '<LOCALNET>.28.15':445
  • '<LOCALNET>.28.29':445
  • '<LOCALNET>.28.16':445
  • '<LOCALNET>.28.17':445
  • '<LOCALNET>.28.18':445
  • '<LOCALNET>.28.19':445
  • '<LOCALNET>.28.20':445
  • '<LOCALNET>.28.21':445
  • '<LOCALNET>.28.22':445
  • '<LOCALNET>.28.23':445
  • '<LOCALNET>.28.24':445
  • '<LOCALNET>.28.25':445
  • '<LOCALNET>.28.26':445
  • '<LOCALNET>.28.27':445
  • '<LOCALNET>.28.28':445
  • '<LOCALNET>.28.30':445
  • '<LOCALNET>.28.79':445
  • '<LOCALNET>.28.125':445
  • '<LOCALNET>.28.64':445
  • '<LOCALNET>.28.97':445
  • '<LOCALNET>.28.98':445
  • '<LOCALNET>.28.99':445
  • '<LOCALNET>.28.100':445
  • '<LOCALNET>.28.101':445
  • '<LOCALNET>.28.102':445
  • '<LOCALNET>.28.103':445
  • '<LOCALNET>.28.104':445
  • '<LOCALNET>.28.105':445
  • '<LOCALNET>.28.106':445
  • '<LOCALNET>.28.107':445
  • '<LOCALNET>.28.108':445
  • '<LOCALNET>.28.109':445
  • '<LOCALNET>.28.111':445
  • '<LOCALNET>.28.63':445
  • '<LOCALNET>.28.112':445
  • '<LOCALNET>.28.113':445
  • '<LOCALNET>.28.114':445
  • '<LOCALNET>.28.115':445
  • '<LOCALNET>.28.116':445
  • '<LOCALNET>.28.117':445
  • '<LOCALNET>.28.118':445
  • '<LOCALNET>.28.119':445
  • '<LOCALNET>.28.120':445
  • '<LOCALNET>.28.121':445
  • '<LOCALNET>.28.122':445
  • '<LOCALNET>.28.123':445
  • '<LOCALNET>.28.124':445
  • '<LOCALNET>.28.96':445
  • '<LOCALNET>.28.126':445
  • '<LOCALNET>.28.95':445
  • '<LOCALNET>.28.78':445
  • '<LOCALNET>.28.65':445
  • '<LOCALNET>.28.66':445
  • '<LOCALNET>.28.67':445
  • '<LOCALNET>.28.68':445
  • '<LOCALNET>.28.69':445
  • '<LOCALNET>.28.70':445
  • '<LOCALNET>.28.71':445
  • '<LOCALNET>.28.72':445
  • '<LOCALNET>.28.73':445
  • '<LOCALNET>.28.74':445
  • '<LOCALNET>.28.75':445
  • '<LOCALNET>.28.76':445
  • '<LOCALNET>.28.77':445
  • '<LOCALNET>.28.62':445
  • '<LOCALNET>.28.93':445
  • '<LOCALNET>.28.80':445
  • '<LOCALNET>.28.81':445
  • '<LOCALNET>.28.82':445
  • '<LOCALNET>.28.83':445
  • '<LOCALNET>.28.84':445
  • '<LOCALNET>.28.85':445
  • '<LOCALNET>.28.86':445
  • '<LOCALNET>.28.87':445
  • '<LOCALNET>.28.88':445
  • '<LOCALNET>.28.89':445
  • '<LOCALNET>.28.90':445
  • '<LOCALNET>.28.91':445
  • '<LOCALNET>.28.92':445
  • '<LOCALNET>.28.94':445
  • '<LOCALNET>.28.254':445
Miscellaneous
Searches for the following windows
  • ClassName: 'EVERYTHING_TASKBAR_NOTIFICATION' WindowName: ''
Creates and executes the following
  • '%TEMP%\7zipsfx.000\7za.exe' i
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything.exe' -startup
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e ul2
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e ul1
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\dc.exe' /D
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e all -sd -crc
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e watch -pid 2636 -! -e all -sd -crc
  • '%TEMP%\7zipsfx.000\end.ex3.exe' -e all -sd -crc
  • '%TEMP%\7zipsfx.000\7za.exe' x -y -p1979423435475512243 Everything64.dll
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-VM | Stop-VM"' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -S e9a42b02-d5df-448d-aa00-03f14749eb61' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -S 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e watch -pid 2636 -! -e all -sd -crc' (with hidden window)
  • '%TEMP%\7zipsfx.000\7za.exe' i' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0' (with hidden window)
  • '%TEMP%\7zipsfx.000\end.ex3.exe' -e all -sd -crc' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e all -sd -crc' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\dc.exe' /D' (with hidden window)
  • '%TEMP%\7zipsfx.000\7za.exe' x -y -p1979423435475512243 Everything64.dll' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e ul1' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e ul2' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything.exe' -startup' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-VM | Select-Object vmid | Get-VHD | %{Get-DiskImage -ImagePath $_.Path; Get-DiskImage -ImagePath $_.ParentPath} | Dismount-DiskImage"' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -H off' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-Volume | Get-DiskImage | Dismount-DiskImage"' (with hidden window)
Executes the following
  • '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-VM | Stop-VM"
  • '<SYSTEM32>\powercfg.exe' -S e9a42b02-d5df-448d-aa00-03f14749eb61
  • '<SYSTEM32>\powercfg.exe' -S 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-VM | Select-Object vmid | Get-VHD | %{Get-DiskImage -ImagePath $_.Path; Get-DiskImage -ImagePath $_.ParentPath} | Dismount-DiskImage"
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0
  • '<SYSTEM32>\powercfg.exe' -H off
  • '<SYSTEM32>\raserver.exe' /offerraupdate
  • '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-Volume | Get-DiskImage | Dismount-DiskImage"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android