Technical Information
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'MssHostEngine' = '%APPDATA%\msshost.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'MssHostEngine' = '%APPDATA%\msshost.exe'
- System Restore (SR)
- '<SYSTEM32>\taskkill.exe' /f /im MSExchange*
- '<SYSTEM32>\taskkill.exe' /f /im Microsoft.Exchange.*
- '<SYSTEM32>\taskkill.exe' /f /im sqlserver.exe
- '<SYSTEM32>\taskkill.exe' /f /im sqlwriter.exe
- <SYSTEM32>\vds.exe
- %HOMEPATH%\desktop\168.jpeg
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- %HOMEPATH%\desktop\tree_view.htm
- %HOMEPATH%\desktop\split.avi
- %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
- %HOMEPATH%\desktop\sdkfailsafeemulator.cer
- %HOMEPATH%\desktop\region-north-karelia.jpeg
- %HOMEPATH%\desktop\nwfieldnotes1966.docx
- %HOMEPATH%\desktop\join.avi
- %HOMEPATH%\desktop\ituneshelpunavailable.htm
- %HOMEPATH%\desktop\iisstart.html
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\glidescope_review_rev_010.docx
- %HOMEPATH%\desktop\garden.htm
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\fi51.doc
- %HOMEPATH%\desktop\dialmap.bmp
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\dashborder_144.bmp
- %HOMEPATH%\desktop\contoso.cer
- %HOMEPATH%\desktop\applicantform_en.doc
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\about.htm
- %HOMEPATH%\desktop\2.jpeg
- %APPDATA%\mozilla\firefox\profiles.ini
- %APPDATA%\thunderbird\profiles.ini
- %APPDATA%\msshost.exe
- C:\users\public\pictures\sample pictures\readme_decryptor.txt
- C:\users\public\music\sample music\readme_decryptor.txt
- C:\users\public\libraries\readme_decryptor.txt
- C:\users\default\readme_decryptor.txt
- C:\users\default\appdata\roaming\microsoft\windows\sendto\readme_decryptor.txt
- %ALLUSERSPROFILE%\sun\java\java update\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\packages\vcruntimeadditional_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{ec9807de-b577-47b1-a024-0251805acf24}v14.29.30133\packages\vcruntimeminimum_x86\readme_decryptor.txt
- C:\users\public\recorded tv\sample media\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{bd95a8cd-1d9f-35ad-981a-3e7925026ebb}v11.0.61030\packages\vcruntimeminimum_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{7258184a-ec44-4b1a-a7d3-68d85a35bfd0}v14.16.27024\packages\vcruntimeadditional_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{5eefcefb-e5f7-4c82-99a5-813f04aa4fbd}v14.16.27024\packages\vcruntimeminimum_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{42667d2e-b054-46c1-9d46-2ee1332c14c1}v14.29.30133\packages\vcruntimeadditional_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{39e28474-b67b-4209-af1b-e9ad0a83d8ca}\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{38b2c744-ad08-4d5b-91a2-3fb6f739ff3e}\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\d4036846864773e3d647f421dfe7f6ca536e307b\packages\patch\x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\564f02e6419b9858949b0cd5a65e2c8c0944dd88\packages\patch\x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\readme_decryptor.txt
- C:\users\public\videos\sample videos\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\crash reports\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\readme_decryptor.txt
- %HOMEPATH%\favorites\msn websites\readme_decryptor.txt
- %HOMEPATH%\favorites\microsoft websites\readme_decryptor.txt
- %HOMEPATH%\favorites\links for united states\readme_decryptor.txt
- %HOMEPATH%\favorites\links\readme_decryptor.txt
- %HOMEPATH%\contacts\readme_decryptor.txt
- %APPDATA%\thunderbird\readme_decryptor.txt
- %APPDATA%\thunderbird\profiles\5sfumjqc.default\readme_decryptor.txt
- %APPDATA%\thunderbird\profiles\5sfumjqc.default\crashes\readme_decryptor.txt
- %APPDATA%\thunderbird\crash reports\readme_decryptor.txt
- %APPDATA%\telegram desktop\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\crashes\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\bookmarkbackups\readme_decryptor.txt
- %ALLUSERSPROFILE%\mozilla\updates\308046b0af4a39cb\readme_decryptor.txt
- %HOMEPATH%\favorites\windows live\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft help\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x86_6bf2947c61eb2a806ee6756bfbdda581aa113e_cab_014d8101\readme_decryptor.txt
- %ALLUSERSPROFILE%\adobe\acrobat\11.0\replicate\security\readme_decryptor.txt
- C:\msocache\all users\{90140000-0117-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0117-0409-0000-0000000ff1ce}-c\access.en-us\readme_decryptor.txt
- C:\msocache\all users\{90140000-0115-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-00ba-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-00a1-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0044-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.fr\readme_decryptor.txt
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ab0000000001}\readme_decryptor.txt
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.es\readme_decryptor.txt
- C:\msocache\all users\{90140000-001b-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-001a-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0019-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0018-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0016-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0011-0000-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\kms\readme_decryptor.txt
- %HOMEPATH%\desktop\readme_decryptor.txt
- D:\readme_decryptor.txt
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.en\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\mf\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\network\downloader\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x86_3d7e2448614bf82912853ac5f0bc80ae562b9024_cab_07be08dd\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x86_289f42c8c0a9db05e4274a776fcf89f6ceaaf2_cab_014d811f\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_cab_0f381c73\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_06f0d010\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_cab_0a342f7e\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_0984e33a\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\steam\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\ringtones\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\caches\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\user account pictures\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\secstore\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\propmap\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\gatherlogs\systemindex\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\rac\statedata\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\rac\publisheddata\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\cache\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\office\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows defender\support\readme_decryptor.txt
- C:\readme_decryptor.txt
- from %APPDATA%\mozilla\firefox\crash reports\installtime20190813150448 to %APPDATA%\mozilla\firefox\crash reports\installtime20190813150448.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\abook.mab to %APPDATA%\thunderbird\profiles\5sfumjqc.default\abook.mab.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\crashes\store.json.mozlz4 to %APPDATA%\thunderbird\profiles\5sfumjqc.default\crashes\store.json.mozlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\crash reports\installtime20150507114201 to %APPDATA%\thunderbird\crash reports\installtime20150507114201.[decryptor@cock.li].dcrtr
- from %APPDATA%\telegram desktop\unins000.dat to %APPDATA%\telegram desktop\unins000.dat.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles.ini to %APPDATA%\mozilla\firefox\profiles.ini.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\installs.ini to %APPDATA%\mozilla\firefox\installs.ini.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\xulstore.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\xulstore.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\addons.json to %APPDATA%\thunderbird\profiles\5sfumjqc.default\addons.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\user.js to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\user.js.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sitesecurityservicestate.txt to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sitesecurityservicestate.txt.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessioncheckpoints.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessioncheckpoints.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\search.json.mozlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\search.json.mozlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\prefs.js to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\prefs.js.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\pluginreg.dat to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\pluginreg.dat.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\pkcs11.txt to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\pkcs11.txt.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\times.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\times.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\blist.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\blist.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\blocklist.xml to %APPDATA%\thunderbird\profiles\5sfumjqc.default\blocklist.xml.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\cert8.db to %APPDATA%\thunderbird\profiles\5sfumjqc.default\cert8.db.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\times.json to %APPDATA%\thunderbird\profiles\5sfumjqc.default\times.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\sessioncheckpoints.json to %APPDATA%\thunderbird\profiles\5sfumjqc.default\sessioncheckpoints.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\secmod.db to %APPDATA%\thunderbird\profiles\5sfumjqc.default\secmod.db.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\prefs.js to %APPDATA%\thunderbird\profiles\5sfumjqc.default\prefs.js.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\pluginreg.dat to %APPDATA%\thunderbird\profiles\5sfumjqc.default\pluginreg.dat.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\places.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\places.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\permissions.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\permissions.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\mailviews.dat to %APPDATA%\thunderbird\profiles\5sfumjqc.default\mailviews.dat.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\localstore.rdf to %APPDATA%\thunderbird\profiles\5sfumjqc.default\localstore.rdf.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\key3.db to %APPDATA%\thunderbird\profiles\5sfumjqc.default\key3.db.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\history.mab to %APPDATA%\thunderbird\profiles\5sfumjqc.default\history.mab.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\global-messages-db.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\global-messages-db.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\formhistory.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\formhistory.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\extensions.json to %APPDATA%\thunderbird\profiles\5sfumjqc.default\extensions.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\extensions.ini to %APPDATA%\thunderbird\profiles\5sfumjqc.default\extensions.ini.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\cookies.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\cookies.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\compatibility.ini to %APPDATA%\thunderbird\profiles\5sfumjqc.default\compatibility.ini.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\handlers.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\handlers.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\virtualfolders.dat to %APPDATA%\thunderbird\profiles\5sfumjqc.default\virtualfolders.dat.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extensions.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extensions.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\content-prefs.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\content-prefs.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.sig to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.sig.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.lib to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.lib.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\manifest.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\manifest.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\license.txt to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\license.txt.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\state.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\state.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\session-state.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\session-state.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050106.58d05602-57c3-43da-8c92-63c175048e33.first-shutdown.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050106.58d05602-57c3-43da-8c92-63c175048e33.first-shutdown.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\136d2301-e9c9-4685-88a8-34350d6f8b5f to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\136d2301-e9c9-4685-88a8-34350d6f8b5f.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050105.38b30436-e66d-47e7-ad31-6c8f4f754428.main.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050105.38b30436-e66d-47e7-ad31-6c8f4f754428.main.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050005.97485753-1b2b-4e3b-953d-ac3ea5457f3d.new-profile.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050005.97485753-1b2b-4e3b-953d-ac3ea5457f3d.new-profile.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013537.136d2301-e9c9-4685-88a8-34350d6f8b5f.health.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013537.136d2301-e9c9-4685-88a8-34350d6f8b5f.health.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013430.39c8d187-e7b6-41f0-8919-3c3ad3614730.modules.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013430.39c8d187-e7b6-41f0-8919-3c3ad3614730.modules.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\crashes\store.json.mozlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\crashes\store.json.mozlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\bookmarkbackups\bookmarks-2023-06-28_11_ukwbceqzcyihwn6n3vgyrg==.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\bookmarkbackups\bookmarks-2023-06-28_11_ukwbceqzcyihwn6n3vgyrg==.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\user.js to %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\user.js.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\times.json to %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\times.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050073.b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25.event.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050073.b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25.event.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\38b30436-e66d-47e7-ad31-6c8f4f754428 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\38b30436-e66d-47e7-ad31-6c8f4f754428.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\39c8d187-e7b6-41f0-8919-3c3ad3614730 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\39c8d187-e7b6-41f0-8919-3c3ad3614730.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\58d05602-57c3-43da-8c92-63c175048e33 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\58d05602-57c3-43da-8c92-63c175048e33.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\containers.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\containers.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\compatibility.ini to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\compatibility.ini.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\broadcast-listeners.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\broadcast-listeners.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addonstartup.json.lz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addonstartup.json.lz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addons.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addons.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\.metadata-v2 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\.metadata-v2.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\upgrade.jsonlz4-20190813150448 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\upgrade.jsonlz4-20190813150448.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\recovery.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\recovery.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\recovery.baklz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\recovery.baklz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\previous.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\previous.jsonlz4.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\97485753-1b2b-4e3b-953d-ac3ea5457f3d to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\97485753-1b2b-4e3b-953d-ac3ea5457f3d.[decryptor@cock.li].dcrtr
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extension-preferences.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extension-preferences.json.[decryptor@cock.li].dcrtr
- from %APPDATA%\thunderbird\profiles.ini to %APPDATA%\thunderbird\profiles.ini.[decryptor@cock.li].dcrtr
- D:\install.log
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.es\proof.msi
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.es\proof.cab
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.en\proof.msi
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.en\proof.cab
- C:\msocache\all users\{90140000-001b-0409-0000-0000000ff1ce}-c\wordmui.msi
- C:\msocache\all users\{90140000-001b-0409-0000-0000000ff1ce}-c\wordlr.cab
- C:\msocache\all users\{90140000-001a-0409-0000-0000000ff1ce}-c\outlookmui.msi
- C:\msocache\all users\{90140000-001a-0409-0000-0000000ff1ce}-c\outlklr.cab
- C:\msocache\all users\{90140000-0019-0409-0000-0000000ff1ce}-c\publr.cab
- C:\msocache\all users\{90140000-0019-0409-0000-0000000ff1ce}-c\publishermui.msi
- C:\msocache\all users\{90140000-0018-0409-0000-0000000ff1ce}-c\pptlr.cab
- C:\msocache\all users\{90140000-0018-0409-0000-0000000ff1ce}-c\powerpointmui.msi
- C:\msocache\all users\{90140000-0016-0409-0000-0000000ff1ce}-c\excelmui.msi
- C:\msocache\all users\{90140000-0016-0409-0000-0000000ff1ce}-c\excellr.cab
- C:\msocache\all users\{90140000-0011-0000-0000-0000000ff1ce}-c\propsww2.cab
- C:\msocache\all users\{90140000-0011-0000-0000-0000000ff1ce}-c\propsww.cab
- C:\msocache\all users\{90140000-0011-0000-0000-0000000ff1ce}-c\proplusww.msi
- C:\msocache\all users\{90140000-0011-0000-0000-0000000ff1ce}-c\pkeyconfig-office.xrm-ms
- C:\msocache\all users\{90140000-0011-0000-0000-0000000ff1ce}-c\owow64ww.cab
- C:\msocache\all users\{90140000-0011-0000-0000-0000000ff1ce}-c\office64ww.msi
- C:\kms\kms_vl_all_aio_debug.log
- C:\kms\kms_vl_all_aio.cmd
- %HOMEPATH%\desktop\applicantform_en.doc
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\about.htm
- %HOMEPATH%\desktop\2.jpeg
- %HOMEPATH%\desktop\168.jpeg
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.fr\proof.cab
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.fr\proof.msi
- ClassName: '' WindowName: ''
- '%APPDATA%\msshost.exe'
- '<SYSTEM32>\taskkill.exe' /f /im Microsoft.Exchange.*' (with hidden window)
- '<SYSTEM32>\taskkill.exe' /f /im MSExchange*' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wbadmin delete catalog -quiet' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wmic shadowcopy delete' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c vssadmin delete shadows /all /quiet' (with hidden window)
- '<SYSTEM32>\sc.exe' stop WerSvc' (with hidden window)
- '<SYSTEM32>\taskkill.exe' /f /im sqlserver.exe' (with hidden window)
- '<SYSTEM32>\sc.exe' stop BITS' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {default} recoveryenabled No' (with hidden window)
- '<SYSTEM32>\sc.exe' stop ERSvc' (with hidden window)
- '<SYSTEM32>\sc.exe' stop wuauserv' (with hidden window)
- '<SYSTEM32>\sc.exe' stop WinDefend' (with hidden window)
- '<SYSTEM32>\sc.exe' stop wscsvc' (with hidden window)
- '%APPDATA%\msshost.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures' (with hidden window)
- '<SYSTEM32>\taskkill.exe' /f /im sqlwriter.exe' (with hidden window)
- '<SYSTEM32>\sc.exe' stop wscsvc
- '<SYSTEM32>\sc.exe' stop WinDefend
- '<SYSTEM32>\sc.exe' stop wuauserv
- '<SYSTEM32>\sc.exe' stop ERSvc
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {default} recoveryenabled No
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures
- '<SYSTEM32>\sc.exe' stop BITS
- '<SYSTEM32>\sc.exe' stop WerSvc
- '<SYSTEM32>\cmd.exe' /c vssadmin delete shadows /all /quiet
- '<SYSTEM32>\cmd.exe' /c wmic shadowcopy delete
- '<SYSTEM32>\cmd.exe' /c wbadmin delete catalog -quiet
- '<SYSTEM32>\bcdedit.exe' /set {default} bootstatuspolicy ignoreallfailures
- '<SYSTEM32>\wbadmin.exe' delete catalog -quiet
- '<SYSTEM32>\wbengine.exe'
- '<SYSTEM32>\vds.exe'