Technical Information
- Windows Defender
- %HOMEPATH%\desktop\contosoroot_1.cer
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\contoso_1.cer
- %HOMEPATH%\desktop\dashborder_120.bmp
- %HOMEPATH%\desktop\sdkfailsafeemulator.cer
- %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
- %HOMEPATH%\desktop\testcertificate.cer
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- <Current directory>\task_list_tmp.txt
- %HOMEPATH%\desktop\recover_instructions.html
- <Current directory>\task_list_tmp.txt
- <SYSTEM32>\tasks\adobe acrobat update task
- <SYSTEM32>\tasks\opera scheduled autoupdate 1723415083
- <SYSTEM32>\tasks\microsoft\windows defender\mpidletask
- <SYSTEM32>\tasks\mozilla\firefox default browser agent 308046b0af4a39cb
- <SYSTEM32>\tasks\officesoftwareprotectionplatform\svcrestarttask
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\abook.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\abook.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\alternateservices.txt to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\alternateservices.txt.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\blist.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\blist.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\cookies.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\cookies.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\enigmail.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\enigmail.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\favicons.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\favicons.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\formhistory.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\formhistory.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\global-messages-db.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\global-messages-db.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\history.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\history.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\openpgp.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\openpgp.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\permissions.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\permissions.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\pkcs11.txt to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\pkcs11.txt.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\places.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\places.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\prefs.js to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\prefs.js.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\securitypreloadstate.txt to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\securitypreloadstate.txt.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\sitesecurityservicestate.txt to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\sitesecurityservicestate.txt.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\webappsstore.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\webappsstore.sqlite.thsrx
- from %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite to %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.thsrx
- from %APPDATA%\telegram desktop\telegram.exe to %APPDATA%\telegram desktop\telegram.exe.thsrx
- from %APPDATA%\telegram desktop\unins000.exe to %APPDATA%\telegram desktop\unins000.exe.thsrx
- from %APPDATA%\telegram desktop\updater.exe to %APPDATA%\telegram desktop\updater.exe.thsrx
- from %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\user.js to %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\user.js.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\alternateservices.txt to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\alternateservices.txt.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\pkcs11.txt to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\pkcs11.txt.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\prefs.js to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\prefs.js.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\securitypreloadstate.txt to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\securitypreloadstate.txt.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\sitesecurityservicestate.txt to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\sitesecurityservicestate.txt.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\trrblacklist.txt to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\trrblacklist.txt.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\user.js to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\user.js.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.thsrx
- from %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\default\moz-extension+++d6b3ddfc-c8d2-4cb7-a730-29f01af6f4b1^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.sql... to %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\default\moz-extension+++d6b3ddfc-c8d2-4cb7-a730-29f01af6f4b1^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.sql...
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\contosoroot_1.cer
- %HOMEPATH%\desktop\contoso_1.cer
- %HOMEPATH%\desktop\dashborder_120.bmp
- %HOMEPATH%\desktop\sdkfailsafeemulator.cer
- %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
- %HOMEPATH%\desktop\testcertificate.cer
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\abook.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\blist.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\cookies.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\enigmail.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\favicons.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\formhistory.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\global-messages-db.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\history.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\openpgp.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\permissions.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\pkcs11.txt
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\places.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\prefs.js
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\webappsstore.sqlite
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
- %APPDATA%\mozilla\firefox\profiles\q0evdndb.default\user.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\pkcs11.txt
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\prefs.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\sitesecurityservicestate.txt
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\user.js
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin delete shadows /all /quiet
- '%WINDIR%\syswow64\cmd.exe' /c wmic shadowcopy delete
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command "Get-WmiObject Win32_ShadowCopy | ForEach-Object { $_.Delete() }"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "Get-WmiObject Win32_ShadowCopy | ForEach-Object { $_.Delete() }"
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /query /fo LIST /v > "task_list_tmp.txt"
- '%WINDIR%\syswow64\schtasks.exe' /query /fo LIST /v
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /f /tn "\Adobe Acrobat Update Task"
- '%WINDIR%\syswow64\schtasks.exe' /delete /f /tn "\Adobe Acrobat Update Task"
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /f /tn "\Opera scheduled Autoupdate 1723415083"
- '%WINDIR%\syswow64\schtasks.exe' /delete /f /tn "\Opera scheduled Autoupdate 1723415083"
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /f /tn "\Microsoft\Windows Defender\MP Scheduled Scan"
- '%WINDIR%\syswow64\schtasks.exe' /delete /f /tn "\Microsoft\Windows Defender\MP Scheduled Scan"
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /f /tn "\Microsoft\Windows Defender\MpIdleTask"
- '%WINDIR%\syswow64\schtasks.exe' /delete /f /tn "\Microsoft\Windows Defender\MpIdleTask"
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "%HOMEPATH%\Desktop\RECOVER_INSTRUCTIONS.html"
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /f /tn "\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB"
- '%WINDIR%\syswow64\schtasks.exe' /delete /f /tn "\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB"
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /delete /f /tn "\OfficeSoftwareProtectionPlatform\SvcRestartTask"
- '%WINDIR%\syswow64\schtasks.exe' /delete /f /tn "\OfficeSoftwareProtectionPlatform\SvcRestartTask"
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- "%HOMEPATH%\Desktop\RECOVER_INSTRUCTIONS.html"
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- "%HOMEPATH%\Desktop\RECOVER_INSTRUCTIONS.html" /crash-reporter-parent-id=1272
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="1272.0.420994192\278749545" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu-...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --disable-client-side-phishing-...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --extension-process --enable-we...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1272.4.1835225231\422567442" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1272.5.1265129432\1706895735" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1272.6.1732732319\1979720183" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1272.7.2119663176\1965293104" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1272.8.332711756\785662030" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1272.9.1649331978\452471797" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' --type=utility --channel="1272.4.1835225231\422567442" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001 /crash-reporter-parent-id=2008
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="1272.10.1516296615\483399537" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin delete shadows /all /quiet' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c wmic shadowcopy delete' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command "Get-WmiObject Win32_ShadowCopy | ForEach-Object { $_.Delete() }"' (with hidden window)