Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Encoder.35975

Добавлен в вирусную базу Dr.Web: 2022-09-30

Описание добавлено:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'End.ex3' = '"%LOCALAPPDATA%\{319AEC34-0102-D9C9-277E-433995B84567}\End.ex3.exe" -e all -sd -crc '
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tv_x64.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tv_w32.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TeamViewer_Service.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TeamViewer.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbirdconfig.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Sysmon64.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Sysmon.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ssms.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlwriter.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlservr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlmangr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlbrowser.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlagent.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sql.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqbcoreservice.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SimplyConnectionManager.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\raw_agent_svc.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tomcat6.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsnapvss.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vxmon.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wdswfsafe.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shutdown.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\logoff.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perfmon.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsqmcons.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CompatTelRunner.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SearchProtocolHost.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SearchApp.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SearchIndexer.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sqlservrs.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SystemExplorer.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\r.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xfssvccon.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wxServerView.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wxServer.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsa_service.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\Software\Classes\mimicfile\shell\open\command] '' = 'notepad.exe "%LOCALAPPDATA%\ID.txt"'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAgui.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VeeamDeploymentSvc.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RaccineSettings.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msftesql.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsDtSrvr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isqlplussvc.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\httpd.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fdlauncher.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fdhost.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fbserver.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fbguard.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EnterpriseClient.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\encsvc.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dbsnmp.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dbeng50.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Creative Cloud.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKCU>\Software\Classes\exefile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\Software\Classes\exefile\shell\open\command] '' = '"%1" %*'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mydesktopqos.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mydesktopservice.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysqld.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysqld-nt.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Raccine_x86.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Raccine.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBW64.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBW32.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qbupdate.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBIDPService.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBDBMgrN.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QBDBMgr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\python.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wpython.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\java.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\node.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pvlsvr.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oracle.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocssd.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocomm.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocautoupds.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysqld-opt.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RaccineElevatedCfg.exe] 'Debugger' = '<SYSTEM32>\Systray.exe'
  • [<HKLM>\Software\Classes\.com] '' = 'mimicfile'
Malicious functions
To complicate detection of its presence in the operating system,
blocks execution of the following system utilities:
  • Windows Update
  • Windows Defender
blocks the following features:
  • User Account Control (UAC)
modifies the following system settings:
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
  • [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'StartMenuLogOff' = '00000001'
Modifies file system
Creates the following files
  • %TEMP%\7zipsfx.000\7za.exe
  • %TEMP%\7zsfx000.cmd
  • %TEMP%\bvaelxc
  • %TEMP%\autc419.tmp
  • C:\temp\session.tmp
  • C:\id.txt
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\session.tmp
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\sdel64.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\sdel.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything64.dll
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything32.dll
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything2.ini
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything.ini
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\dc.exe
  • %LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\7za.exe
  • %TEMP%\7zipsfx.000\sdel64.exe
  • %TEMP%\7zipsfx.000\sdel.exe
  • %TEMP%\7zipsfx.000\end.ex3.exe
  • %TEMP%\7zipsfx.000\dc.exe
  • %TEMP%\7zipsfx.000\everything2.ini
  • %TEMP%\7zipsfx.000\everything.ini
  • %TEMP%\7zipsfx.000\everything64.dll
  • %TEMP%\7zipsfx.000\everything32.dll
  • %TEMP%\7zipsfx.000\everything.exe
  • %LOCALAPPDATA%\id.txt
  • C:\temp\hashlist.txt
Deletes the following files
  • %TEMP%\autc419.tmp
  • %TEMP%\bvaelxc
  • %TEMP%\7zipsfx.000\7za.exe
  • %TEMP%\7zipsfx.000\dc.exe
  • %TEMP%\7zipsfx.000\end.ex3.exe
  • %TEMP%\7zipsfx.000\everything.exe
  • %TEMP%\7zipsfx.000\everything.ini
  • %TEMP%\7zipsfx.000\everything2.ini
  • %TEMP%\7zipsfx.000\everything32.dll
  • %TEMP%\7zipsfx.000\everything64.dll
  • %TEMP%\7zipsfx.000\sdel.exe
  • %TEMP%\7zipsfx.000\sdel64.exe
  • %TEMP%\7zsfx000.cmd
Moves the following files
  • from %APPDATA%\telegram desktop\tdata\90ef50e22e92cb8c0 to %APPDATA%\telegram desktop\tdata\90ef50e22e92cb8c0.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_controllerhud.webm to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_controllerhud.webm.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_gyro.webm to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_gyro.webm.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_english.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_english.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_shortcuts.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_shortcuts.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_moystick.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_moystick.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_mouseregions.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_mouseregions.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_hometheater.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_hometheater.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_gyro_touchmenu.jpg to %ProgramFiles(x86)%\steam\tenfoot\resource\images\welcomeupdates\controller_update_gyro_touchmenu.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_thai.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_thai.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_hungarian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_hungarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_tchinese.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_tchinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_koreana.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_koreana.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_korean.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_korean.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_danish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_danish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_czech.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_czech.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\styles\steamstyles.css to %ProgramFiles(x86)%\steam\tenfoot\resource\styles\steamstyles.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_ukrainian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_ukrainian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_norwegian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_norwegian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\styles\library\library.css to %ProgramFiles(x86)%\steam\tenfoot\resource\styles\library\library.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_japanese.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_japanese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_schinese.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_schinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_danish.txt to %ProgramFiles(x86)%\steam\friends\trackerui_danish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_russian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_russian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_italian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_italian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_japanese.txt to %ProgramFiles(x86)%\steam\public\steamui_japanese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\accessibility.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\accessibility.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\3difr.x3d to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\3difr.x3d.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\1494870c-9912-c184-4cc9-b401-a53f4d8de290.pdf to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\1494870c-9912-c184-4cc9-b401-a53f4d8de290.pdf.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\qip 2012\unins000.dat to %ProgramFiles(x86)%\qip 2012\unins000.dat.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_turkish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_turkish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_swedish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_swedish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_spanish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_spanish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_romanian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_romanian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_portuguese.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_portuguese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_polish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_polish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_greek.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_greek.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_german.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_german.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_french.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_french.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_finnish.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_finnish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_dutch.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_dutch.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_brazilian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_brazilian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_thai.txt to %ProgramFiles(x86)%\steam\public\steamui_thai.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_spanish.txt to %ProgramFiles(x86)%\steam\public\steamui_spanish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_schinese.txt to %ProgramFiles(x86)%\steam\public\steamui_schinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_german.txt to %ProgramFiles(x86)%\steam\public\steamui_german.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\annots.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\annots.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_danish.txt to %ProgramFiles(x86)%\steam\public\steamui_danish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\remoteui_all.zip.ba22fb168ed139d9979cdd1cefbd911e3ed3529c to %ProgramFiles(x86)%\steam\package\remoteui_all.zip.ba22fb168ed139d9979cdd1cefbd911e3ed3529c.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_bulgarian.txt to %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_bulgarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_bulgarian.txt to %ProgramFiles(x86)%\steam\friends\trackerui_bulgarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_portuguese.txt to %ProgramFiles(x86)%\steam\friends\trackerui_portuguese.txt.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\zip64.sfx to %ProgramFiles%\winrar\zip64.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\zip.sfx to %ProgramFiles%\winrar\zip.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\default64.sfx to %ProgramFiles%\winrar\default64.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\default.sfx to %ProgramFiles%\winrar\default.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\wincon64.sfx to %ProgramFiles%\winrar\wincon64.sfx.fortguardseven@gmail.com
  • from %ProgramFiles%\winrar\wincon.sfx to %ProgramFiles%\winrar\wincon.sfx.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\te.pak to %ProgramFiles(x86)%\steam\bin\locales\te.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\ta.pak to %ProgramFiles(x86)%\steam\bin\locales\ta.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_ukrainian.txt to %ProgramFiles(x86)%\steam\public\steamui_ukrainian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\natives_blob.bin to %ProgramFiles(x86)%\steam\bin\natives_blob.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\ml.pak to %ProgramFiles(x86)%\steam\bin\locales\ml.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\kn.pak to %ProgramFiles(x86)%\steam\bin\locales\kn.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\devtools_resources.pak to %ProgramFiles(x86)%\steam\bin\devtools_resources.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\content_resources.pak to %ProgramFiles(x86)%\steam\bin\content_resources.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\component_extension_resources.pak to %ProgramFiles(x86)%\steam\bin\component_extension_resources.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\cef_extensions.pak to %ProgramFiles(x86)%\steam\bin\cef_extensions.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\cef_200_percent.pak to %ProgramFiles(x86)%\steam\bin\cef_200_percent.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\cef_100_percent.pak to %ProgramFiles(x86)%\steam\bin\cef_100_percent.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_schinese.txt to %ProgramFiles(x86)%\steam\friends\trackerui_schinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_spanish.txt to %ProgramFiles(x86)%\steam\friends\trackerui_spanish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_thai.txt to %ProgramFiles(x86)%\steam\friends\trackerui_thai.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_turkish.txt to %ProgramFiles(x86)%\steam\friends\trackerui_turkish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_english.txt to %ProgramFiles(x86)%\steam\public\steamui_english.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_turkish.txt to %ProgramFiles(x86)%\steam\public\steamui_turkish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_swedish.txt to %ProgramFiles(x86)%\steam\public\steamui_swedish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_russian.txt to %ProgramFiles(x86)%\steam\public\steamui_russian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_romanian.txt to %ProgramFiles(x86)%\steam\public\steamui_romanian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_portuguese.txt to %ProgramFiles(x86)%\steam\public\steamui_portuguese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_polish.txt to %ProgramFiles(x86)%\steam\public\steamui_polish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_norwegian.txt to %ProgramFiles(x86)%\steam\public\steamui_norwegian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_koreana.txt to %ProgramFiles(x86)%\steam\public\steamui_koreana.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_korean.txt to %ProgramFiles(x86)%\steam\public\steamui_korean.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\checkers.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\checkers.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_italian.txt to %ProgramFiles(x86)%\steam\public\steamui_italian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_greek.txt to %ProgramFiles(x86)%\steam\public\steamui_greek.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_finnish.txt to %ProgramFiles(x86)%\steam\public\steamui_finnish.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_dutch.txt to %ProgramFiles(x86)%\steam\public\steamui_dutch.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_czech.txt to %ProgramFiles(x86)%\steam\public\steamui_czech.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_bulgarian.txt to %ProgramFiles(x86)%\steam\public\steamui_bulgarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_brazilian.txt to %ProgramFiles(x86)%\steam\public\steamui_brazilian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_russian.txt to %ProgramFiles(x86)%\steam\friends\trackerui_russian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_german.txt to %ProgramFiles(x86)%\steam\friends\trackerui_german.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\friends\trackerui_czech.txt to %ProgramFiles(x86)%\steam\friends\trackerui_czech.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_hungarian.txt to %ProgramFiles(x86)%\steam\public\steamui_hungarian.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_tchinese.txt to %ProgramFiles(x86)%\steam\public\steamui_tchinese.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\steamui_french.txt to %ProgramFiles(x86)%\steam\public\steamui_french.txt.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\digsig.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\digsig.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\dropboxstorage.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\dropboxstorage.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\drvdx9.x3d to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\drvdx9.x3d.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\main.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\main.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\main-high-contrast.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\main-high-contrast.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\js\faf-main.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\js\faf-main.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\css\faf-main.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\css\faf-main.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\tool\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\tool\plugin.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\home-view\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\home-view\plugin.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\css\main.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\css\main.css.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\exportpdf-tool-view.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\exportpdf-tool-view.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\exportpdf-rna-tool-view.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\exportpdf-rna-tool-view.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\exportpdf-rna-selector.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\exportpdf-rna-selector.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\convertpdf-rna-tool-view.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\convertpdf-rna-tool-view.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\convertpdf-rna-selector.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\rhp\convertpdf-rna-selector.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\convertpdf-tool-view.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\convertpdf-tool-view.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\convertpdf-selector.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\convertpdf-selector.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\exportpdf-selector.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\js\plugins\exportpdf-selector.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\more-inside-2x.png to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\more-inside-2x.png.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\unified-e-signature-2x.png to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\unified-e-signature-2x.png.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\get-e-signatures-2x.png to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\get-e-signatures-2x.png.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\new-features-have-arrived-2x.png to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\images\new-features-have-arrived-2x.png.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\installer\chrome.7z to %ProgramFiles(x86)%\google\chrome\application\42.0.2311.135\installer\chrome.7z.fortguardseven@gmail.com
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\content-prefs.sqlite to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\content-prefs.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\session.dbak to %APPDATA%\opera software\opera stable\session.dbak.fortguardseven@gmail.com
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\permissions.sqlite to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\permissions.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\icq-profile\base\opt.dbs to %APPDATA%\icq-profile\base\opt.dbs.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\permissions.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\permissions.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\bookmarksextras to %APPDATA%\opera software\opera stable\bookmarksextras.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\visited links to %APPDATA%\opera software\opera stable\visited links.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\history to %APPDATA%\opera software\opera stable\history.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\session.db to %APPDATA%\opera software\opera stable\session.db.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\webappsstore.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\webappsstore.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\cert8.db to %APPDATA%\thunderbird\profiles\wjj9aet2.default\cert8.db.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\places.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\places.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\cookies.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\cookies.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\global-messages-db.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\global-messages-db.sqlite.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\js\plugin.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\cef.pak to %ProgramFiles(x86)%\steam\bin\cef.pak.fortguardseven@gmail.com
  • from %APPDATA%\thunderbird\profiles\wjj9aet2.default\blist.sqlite to %APPDATA%\thunderbird\profiles\wjj9aet2.default\blist.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\storage\ext\sync-login\def\gpucache\data_1 to %APPDATA%\opera software\opera stable\storage\ext\sync-login\def\gpucache\data_1.fortguardseven@gmail.com
  • from %APPDATA%\mra\base\mra.dbs to %APPDATA%\mra\base\mra.dbs.fortguardseven@gmail.com
  • from %APPDATA%\mra\base\opt.dbs to %APPDATA%\mra\base\opt.dbs.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\thumbnails.db to %APPDATA%\opera software\opera stable\thumbnails.db.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\favorites.db to %APPDATA%\opera software\opera stable\favorites.db.fortguardseven@gmail.com
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\healthreport.sqlite to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\healthreport.sqlite.fortguardseven@gmail.com
  • from %ProgramFiles%\java\jre1.8.0_45\lib\security\cacerts to %ProgramFiles%\java\jre1.8.0_45\lib\security\cacerts.fortguardseven@gmail.com
  • from %ProgramFiles%\java\jre1.8.0_45\lib\classlist to %ProgramFiles%\java\jre1.8.0_45\lib\classlist.fortguardseven@gmail.com
  • from %APPDATA%\icq-profile\base\mra.dbs to %APPDATA%\icq-profile\base\mra.dbs.fortguardseven@gmail.com
  • from %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite to %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\storage\ext\sync-login\def\gpucache\index to %APPDATA%\opera software\opera stable\storage\ext\sync-login\def\gpucache\index.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\snapshot_blob.bin to %ProgramFiles(x86)%\steam\bin\snapshot_blob.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\images\edit_pdf_poster2x.jpg to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\images\edit_pdf_poster2x.jpg.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\bins_misc_win32.zip.1db89a4dcad9b10b32243aa6a9de7c4d71d7fce7 to %ProgramFiles(x86)%\steam\package\bins_misc_win32.zip.1db89a4dcad9b10b32243aa6a9de7c4d71d7fce7.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef_100_percent.pak to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef_100_percent.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef.pak to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\weblink.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\weblink.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\updater.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\updater.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\spelling.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\spelling.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\sendmail.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\sendmail.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\search.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\search.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\saveasrtf.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\saveasrtf.api.fortguardseven@gmail.com
  • from %APPDATA%\opera software\opera stable\local storage\https_www.yandex.ru_0.localstorage to %APPDATA%\opera software\opera stable\local storage\https_www.yandex.ru_0.localstorage.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\reflow.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\reflow.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\prcr.x3d to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\prcr.x3d.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\ppklite.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\ppklite.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\pddom.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\pddom.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\multimedia.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\multimedia.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\makeaccessible.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\makeaccessible.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\ia32.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\ia32.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\escript.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\escript.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\dva.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\dva.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\drvsoft.x3d to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\drvsoft.x3d.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\javascripts\jsbytecodewin.bin to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\javascripts\jsbytecodewin.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\readoutloud.api to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\readoutloud.api.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef_200_percent.pak to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\cef_200_percent.pak.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\icudtl.dat to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\icudtl.dat.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\natives_blob.bin to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\natives_blob.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\snapshot_blob.bin to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\snapshot_blob.bin.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\bins_win32.zip.c3ecb4b509fab15dec05a4686a38071da3f5b32a to %ProgramFiles(x86)%\steam\package\bins_win32.zip.c3ecb4b509fab15dec05a4686a38071da3f5b32a.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\steam_win32.zip.08396f3b6b20aee64f6e22dd2eff32b5be16b930 to %ProgramFiles(x86)%\steam\package\steam_win32.zip.08396f3b6b20aee64f6e22dd2eff32b5be16b930.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\ssa_win32.zip.adc4b0a71d32370b39174c74c7ff563113b1116f to %ProgramFiles(x86)%\steam\package\ssa_win32.zip.adc4b0a71d32370b39174c74c7ff563113b1116f.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\bins_cef_win32.zip.4447a3d2f9ac1e2fbc533033cf235404866a27a7 to %ProgramFiles(x86)%\steam\package\bins_cef_win32.zip.4447a3d2f9ac1e2fbc533033cf235404866a27a7.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\strings_all.zip.53f00b54cffc710742dd4bd3e60f27417582fee5 to %ProgramFiles(x86)%\steam\package\strings_all.zip.53f00b54cffc710742dd4bd3e60f27417582fee5.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_all.zip.bd1519d47a9aed716a567a0661bf80bddc2883c4 to %ProgramFiles(x86)%\steam\package\tenfoot_all.zip.bd1519d47a9aed716a567a0661bf80bddc2883c4.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\resources_misc_all.zip.6b98785251045457e56ce493e4974efc336c1912 to %ProgramFiles(x86)%\steam\package\resources_misc_all.zip.6b98785251045457e56ce493e4974efc336c1912.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\resources_all.zip.e13bd8e3ea04b9ccbdd9cdb20ffa3a3ed0c55841 to %ProgramFiles(x86)%\steam\package\resources_all.zip.e13bd8e3ea04b9ccbdd9cdb20ffa3a3ed0c55841.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\rna-main.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\rna-main.js.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\strings_en_all.zip.cb080e501f60c33549dc909fc83e724c03bb3b87 to %ProgramFiles(x86)%\steam\package\strings_en_all.zip.cb080e501f60c33549dc909fc83e724c03bb3b87.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\steam_client_win32.installed to %ProgramFiles(x86)%\steam\package\steam_client_win32.installed.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\public_all.zip.cead2b93e0927b8f764d31fa410ac5f1e8c39233 to %ProgramFiles(x86)%\steam\package\public_all.zip.cead2b93e0927b8f764d31fa410ac5f1e8c39233.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\bins_codecs_win32.zip.4d5d0cec7d7c337abfbd8be9d020c06e6928b1c2 to %ProgramFiles(x86)%\steam\package\bins_codecs_win32.zip.4d5d0cec7d7c337abfbd8be9d020c06e6928b1c2.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_images_all.zip.3f5109256d433f180d0ea066398bbad9804ba276 to %ProgramFiles(x86)%\steam\package\tenfoot_images_all.zip.3f5109256d433f180d0ea066398bbad9804ba276.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_dicts_all.zip.c74a3a9beb77a280cfd8761b901a80ed0f6a3173 to %ProgramFiles(x86)%\steam\package\tenfoot_dicts_all.zip.c74a3a9beb77a280cfd8761b901a80ed0f6a3173.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_fonts_all.zip.505590f6014431a95a9750073e466372f3e98d88 to %ProgramFiles(x86)%\steam\package\tenfoot_fonts_all.zip.505590f6014431a95a9750073e466372f3e98d88.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_ambientsounds_all.zip.20ccff954777943069dd2c57576216f5f1db7389 to %ProgramFiles(x86)%\steam\package\tenfoot_ambientsounds_all.zip.20ccff954777943069dd2c57576216f5f1db7389.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_sounds_all.zip.843f5376c132f306d1b21dc564b3fe2057104e24 to %ProgramFiles(x86)%\steam\package\tenfoot_sounds_all.zip.843f5376c132f306d1b21dc564b3fe2057104e24.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\tenfoot_misc_all.zip.b9c015520018655499338cfc2c3a3159e28bbe14 to %ProgramFiles(x86)%\steam\package\tenfoot_misc_all.zip.b9c015520018655499338cfc2c3a3159e28bbe14.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\ssa\ssa_german_bigpicture.html to %ProgramFiles(x86)%\steam\public\ssa\ssa_german_bigpicture.html.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\ssa_noarch.zip.7cb02fff8f34cc739f6b7098cf1a36494a94653e to %ProgramFiles(x86)%\steam\package\ssa_noarch.zip.7cb02fff8f34cc739f6b7098cf1a36494a94653e.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\public\ssa_german.htm to %ProgramFiles(x86)%\steam\public\ssa_german.htm.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\package\gamesforwindows_win32.zip.2cbf7a087f4452016065bb75c9b025dbc6885e32 to %ProgramFiles(x86)%\steam\package\gamesforwindows_win32.zip.2cbf7a087f4452016065bb75c9b025dbc6885e32.fortguardseven@gmail.com
  • from %ProgramFiles(x86)%\steam\bin\locales\bn.pak to %ProgramFiles(x86)%\steam\bin\locales\bn.pak.fortguardseven@gmail.com
Modifies the following files
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\34ece1f12cc26ee8ef9e091457d83bac5b3b6057.fortguardseven@gmail.com
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\index.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\f_000003.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\f_000004.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\f_000005.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\f_000009.fortguardseven@gmail.com
  • %APPDATA%\opera software\opera stable\session.db.fortguardseven@gmail.com
  • %APPDATA%\opera software\opera stable\history.fortguardseven@gmail.com
  • %APPDATA%\opera software\opera stable\visited links.fortguardseven@gmail.com
  • %APPDATA%\opera software\opera stable\bookmarksextras.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\data_1.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\data_3.fortguardseven@gmail.com
  • %LOCALAPPDATA%\opera software\opera stable\cache\data_2.fortguardseven@gmail.com
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_1.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\78e4fac58387fa4f0dd1f2e8a2c06aa8dbd296c8.fortguardseven@gmail.com
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\e5295e9fb3c5b25aaabdb3bc390b4fa47f284a34.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\97e0383f498a11b436ed828ab238348bcc54c26e.fortguardseven@gmail.com
  • %APPDATA%\telegram desktop\tdata\90ef50e22e92cb8c0.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\0c7045d9422d72e7f733934ceb30e7bd2de19729.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\10387b4ee0914a9aec44e27c64e82d6036936184.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\021a161175a596c8f58806e6b2013541f300826b.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\0e6c99412d117599a7b3e2c7a37ee511a84ef921.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\30c9e630fc5c8d218210b63d5cab97c59a7c9fc1.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\25cd45c284737fdff18ae1c1c47e9e1d70748a7d.fortguardseven@gmail.com
  • %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2\entries\37cbab75615b4f3cfe982f627f85eaa80ca9ad64.fortguardseven@gmail.com
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\chromedwritefontcache.fortguardseven@gmail.com
  • %LOCALAPPDATA%\steam\htmlcache\chromedwritefontcache.fortguardseven@gmail.com
Modifies multiple files.
Substitutes the following files
  • %ALLUSERSPROFILE%\ntuser.pol
  • %HOMEPATH%\ntuser.pol
  • %ALLUSERSPROFILE%\tempntuser.pol
Deletes itself.
Network activity
Connects to
  • '<LOCALNET>.28.0':445
  • '<LOCALNET>.28.161':445
  • '<LOCALNET>.28.162':445
  • '<LOCALNET>.28.163':445
  • '<LOCALNET>.28.164':445
  • '<LOCALNET>.28.165':445
  • '<LOCALNET>.28.166':445
  • '<LOCALNET>.28.167':445
  • '<LOCALNET>.28.168':445
  • '<LOCALNET>.28.169':445
  • '<LOCALNET>.28.170':445
  • '<LOCALNET>.28.171':445
  • '<LOCALNET>.28.172':445
  • '<LOCALNET>.28.173':445
  • '<LOCALNET>.28.175':445
  • '<LOCALNET>.28.189':445
  • '<LOCALNET>.28.176':445
  • '<LOCALNET>.28.177':445
  • '<LOCALNET>.28.178':445
  • '<LOCALNET>.28.179':445
  • '<LOCALNET>.28.180':445
  • '<LOCALNET>.28.181':445
  • '<LOCALNET>.28.182':445
  • '<LOCALNET>.28.183':445
  • '<LOCALNET>.28.184':445
  • '<LOCALNET>.28.185':445
  • '<LOCALNET>.28.186':445
  • '<LOCALNET>.28.187':445
  • '<LOCALNET>.28.188':445
  • '<LOCALNET>.28.160':445
  • '<LOCALNET>.28.174':445
  • '<LOCALNET>.28.159':445
  • '<LOCALNET>.28.142':445
  • '<LOCALNET>.28.129':445
  • '<LOCALNET>.28.130':445
  • '<LOCALNET>.28.131':445
  • '<LOCALNET>.28.132':445
  • '<LOCALNET>.28.133':445
  • '<LOCALNET>.28.134':445
  • '<LOCALNET>.28.135':445
  • '<LOCALNET>.28.136':445
  • '<LOCALNET>.28.137':445
  • '<LOCALNET>.28.138':445
  • '<LOCALNET>.28.139':445
  • '<LOCALNET>.28.140':445
  • '<LOCALNET>.28.141':445
  • '<LOCALNET>.28.143':445
  • '<LOCALNET>.28.157':445
  • '<LOCALNET>.28.144':445
  • '<LOCALNET>.28.145':445
  • '<LOCALNET>.28.146':445
  • '<LOCALNET>.28.147':445
  • '<LOCALNET>.28.148':445
  • '<LOCALNET>.28.149':445
  • '<LOCALNET>.28.150':445
  • '<LOCALNET>.28.151':445
  • '<LOCALNET>.28.152':445
  • '<LOCALNET>.28.153':445
  • '<LOCALNET>.28.154':445
  • '<LOCALNET>.28.155':445
  • '<LOCALNET>.28.156':445
  • '<LOCALNET>.28.158':445
  • '<LOCALNET>.28.207':445
  • '<LOCALNET>.28.253':445
  • '<LOCALNET>.28.192':445
  • '<LOCALNET>.28.225':445
  • '<LOCALNET>.28.226':445
  • '<LOCALNET>.28.227':445
  • '<LOCALNET>.28.228':445
  • '<LOCALNET>.28.229':445
  • '<LOCALNET>.28.230':445
  • '<LOCALNET>.28.231':445
  • '<LOCALNET>.28.232':445
  • '<LOCALNET>.28.233':445
  • '<LOCALNET>.28.234':445
  • '<LOCALNET>.28.235':445
  • '<LOCALNET>.28.236':445
  • '<LOCALNET>.28.237':445
  • '<LOCALNET>.28.239':445
  • '<LOCALNET>.28.191':445
  • '<LOCALNET>.28.240':445
  • '<LOCALNET>.28.241':445
  • '<LOCALNET>.28.242':445
  • '<LOCALNET>.28.243':445
  • '<LOCALNET>.28.244':445
  • '<LOCALNET>.28.245':445
  • '<LOCALNET>.28.246':445
  • '<LOCALNET>.28.247':445
  • '<LOCALNET>.28.248':445
  • '<LOCALNET>.28.249':445
  • '<LOCALNET>.28.250':445
  • '<LOCALNET>.28.251':445
  • '<LOCALNET>.28.252':445
  • '<LOCALNET>.28.224':445
  • '<LOCALNET>.28.128':445
  • '<LOCALNET>.28.223':445
  • '<LOCALNET>.28.206':445
  • '<LOCALNET>.28.193':445
  • '<LOCALNET>.28.194':445
  • '<LOCALNET>.28.195':445
  • '<LOCALNET>.28.196':445
  • '<LOCALNET>.28.197':445
  • '<LOCALNET>.28.198':445
  • '<LOCALNET>.28.199':445
  • '<LOCALNET>.28.200':445
  • '<LOCALNET>.28.201':445
  • '<LOCALNET>.28.202':445
  • '<LOCALNET>.28.203':445
  • '<LOCALNET>.28.204':445
  • '<LOCALNET>.28.205':445
  • '<LOCALNET>.28.190':445
  • '<LOCALNET>.28.221':445
  • '<LOCALNET>.28.208':445
  • '<LOCALNET>.28.209':445
  • '<LOCALNET>.28.210':445
  • '<LOCALNET>.28.211':445
  • '<LOCALNET>.28.212':445
  • '<LOCALNET>.28.213':445
  • '<LOCALNET>.28.214':445
  • '<LOCALNET>.28.215':445
  • '<LOCALNET>.28.216':445
  • '<LOCALNET>.28.217':445
  • '<LOCALNET>.28.218':445
  • '<LOCALNET>.28.219':445
  • '<LOCALNET>.28.220':445
  • '<LOCALNET>.28.222':445
  • '<LOCALNET>.28.238':445
  • '<LOCALNET>.28.127':445
  • '<LOCALNET>.28.110':445
  • '<LOCALNET>.28.33':445
  • '<LOCALNET>.28.34':445
  • '<LOCALNET>.28.35':445
  • '<LOCALNET>.28.36':445
  • '<LOCALNET>.28.37':445
  • '<LOCALNET>.28.38':445
  • '<LOCALNET>.28.39':445
  • '<LOCALNET>.28.40':445
  • '<LOCALNET>.28.41':445
  • '<LOCALNET>.28.42':445
  • '<LOCALNET>.28.43':445
  • '<LOCALNET>.28.44':445
  • '<LOCALNET>.28.45':445
  • '<LOCALNET>.28.47':445
  • '<LOCALNET>.28.61':445
  • '<LOCALNET>.28.48':445
  • '<LOCALNET>.28.49':445
  • '<LOCALNET>.28.50':445
  • '<LOCALNET>.28.51':445
  • '<LOCALNET>.28.52':445
  • '<LOCALNET>.28.53':445
  • '<LOCALNET>.28.54':445
  • '<LOCALNET>.28.55':445
  • '<LOCALNET>.28.56':445
  • '<LOCALNET>.28.57':445
  • '<LOCALNET>.28.58':445
  • '<LOCALNET>.28.59':445
  • '<LOCALNET>.28.60':445
  • '<LOCALNET>.28.32':445
  • '<LOCALNET>.28.46':445
  • '<LOCALNET>.28.31':445
  • '<LOCALNET>.28.14':445
  • '<LOCALNET>.28.1':445
  • '<LOCALNET>.28.2':445
  • '<LOCALNET>.28.3':445
  • '<LOCALNET>.28.4':445
  • '<LOCALNET>.28.5':445
  • '<LOCALNET>.28.6':445
  • '<LOCALNET>.28.7':445
  • '<LOCALNET>.28.8':445
  • '<LOCALNET>.28.9':445
  • '<LOCALNET>.28.10':445
  • '<LOCALNET>.28.11':445
  • '<LOCALNET>.28.12':445
  • '<LOCALNET>.28.13':445
  • '<LOCALNET>.28.15':445
  • '<LOCALNET>.28.29':445
  • '<LOCALNET>.28.16':445
  • '<LOCALNET>.28.17':445
  • '<LOCALNET>.28.18':445
  • '<LOCALNET>.28.19':445
  • '<LOCALNET>.28.20':445
  • '<LOCALNET>.28.21':445
  • '<LOCALNET>.28.22':445
  • '<LOCALNET>.28.23':445
  • '<LOCALNET>.28.24':445
  • '<LOCALNET>.28.25':445
  • '<LOCALNET>.28.26':445
  • '<LOCALNET>.28.27':445
  • '<LOCALNET>.28.28':445
  • '<LOCALNET>.28.30':445
  • '<LOCALNET>.28.79':445
  • '<LOCALNET>.28.125':445
  • '<LOCALNET>.28.64':445
  • '<LOCALNET>.28.97':445
  • '<LOCALNET>.28.98':445
  • '<LOCALNET>.28.99':445
  • '<LOCALNET>.28.100':445
  • '<LOCALNET>.28.101':445
  • '<LOCALNET>.28.102':445
  • '<LOCALNET>.28.103':445
  • '<LOCALNET>.28.104':445
  • '<LOCALNET>.28.105':445
  • '<LOCALNET>.28.106':445
  • '<LOCALNET>.28.107':445
  • '<LOCALNET>.28.108':445
  • '<LOCALNET>.28.109':445
  • '<LOCALNET>.28.111':445
  • '<LOCALNET>.28.63':445
  • '<LOCALNET>.28.112':445
  • '<LOCALNET>.28.113':445
  • '<LOCALNET>.28.114':445
  • '<LOCALNET>.28.115':445
  • '<LOCALNET>.28.116':445
  • '<LOCALNET>.28.117':445
  • '<LOCALNET>.28.118':445
  • '<LOCALNET>.28.119':445
  • '<LOCALNET>.28.120':445
  • '<LOCALNET>.28.121':445
  • '<LOCALNET>.28.122':445
  • '<LOCALNET>.28.123':445
  • '<LOCALNET>.28.124':445
  • '<LOCALNET>.28.96':445
  • '<LOCALNET>.28.126':445
  • '<LOCALNET>.28.95':445
  • '<LOCALNET>.28.78':445
  • '<LOCALNET>.28.65':445
  • '<LOCALNET>.28.66':445
  • '<LOCALNET>.28.67':445
  • '<LOCALNET>.28.68':445
  • '<LOCALNET>.28.69':445
  • '<LOCALNET>.28.70':445
  • '<LOCALNET>.28.71':445
  • '<LOCALNET>.28.72':445
  • '<LOCALNET>.28.73':445
  • '<LOCALNET>.28.74':445
  • '<LOCALNET>.28.75':445
  • '<LOCALNET>.28.76':445
  • '<LOCALNET>.28.77':445
  • '<LOCALNET>.28.62':445
  • '<LOCALNET>.28.93':445
  • '<LOCALNET>.28.80':445
  • '<LOCALNET>.28.81':445
  • '<LOCALNET>.28.82':445
  • '<LOCALNET>.28.83':445
  • '<LOCALNET>.28.84':445
  • '<LOCALNET>.28.85':445
  • '<LOCALNET>.28.86':445
  • '<LOCALNET>.28.87':445
  • '<LOCALNET>.28.88':445
  • '<LOCALNET>.28.89':445
  • '<LOCALNET>.28.90':445
  • '<LOCALNET>.28.91':445
  • '<LOCALNET>.28.92':445
  • '<LOCALNET>.28.94':445
  • '<LOCALNET>.28.254':445
Miscellaneous
Searches for the following windows
  • ClassName: 'EVERYTHING_TASKBAR_NOTIFICATION' WindowName: ''
Creates and executes the following
  • '%TEMP%\7zipsfx.000\7za.exe' i
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything.exe' -startup
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e ul2
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e ul1
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\dc.exe' /D
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e all -sd -crc
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e watch -pid 2636 -! -e all -sd -crc
  • '%TEMP%\7zipsfx.000\end.ex3.exe' -e all -sd -crc
  • '%TEMP%\7zipsfx.000\7za.exe' x -y -p1979423435475512243 Everything64.dll
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-VM | Stop-VM"' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -S e9a42b02-d5df-448d-aa00-03f14749eb61' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -S 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e watch -pid 2636 -! -e all -sd -crc' (with hidden window)
  • '%TEMP%\7zipsfx.000\7za.exe' i' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0' (with hidden window)
  • '%TEMP%\7zipsfx.000\end.ex3.exe' -e all -sd -crc' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e all -sd -crc' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\dc.exe' /D' (with hidden window)
  • '%TEMP%\7zipsfx.000\7za.exe' x -y -p1979423435475512243 Everything64.dll' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e ul1' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\end.ex3.exe' -e ul2' (with hidden window)
  • '%LOCALAPPDATA%\{319aec34-0102-d9c9-277e-433995b84567}\everything.exe' -startup' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-VM | Select-Object vmid | Get-VHD | %{Get-DiskImage -ImagePath $_.Path; Get-DiskImage -ImagePath $_.ParentPath} | Dismount-DiskImage"' (with hidden window)
  • '<SYSTEM32>\powercfg.exe' -H off' (with hidden window)
  • '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-Volume | Get-DiskImage | Dismount-DiskImage"' (with hidden window)
Executes the following
  • '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-VM | Stop-VM"
  • '<SYSTEM32>\powercfg.exe' -S e9a42b02-d5df-448d-aa00-03f14749eb61
  • '<SYSTEM32>\powercfg.exe' -S 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-VM | Select-Object vmid | Get-VHD | %{Get-DiskImage -ImagePath $_.Path; Get-DiskImage -ImagePath $_.ParentPath} | Dismount-DiskImage"
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0
  • '<SYSTEM32>\powercfg.exe' -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0
  • '<SYSTEM32>\powercfg.exe' -H off
  • '<SYSTEM32>\raserver.exe' /offerraupdate
  • '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "
  • '<SYSTEM32>\powercfg.exe' -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass "Get-Volume | Get-DiskImage | Dismount-DiskImage"

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке