Technical Information
- ClassName: 'OLLYDBG', WindowName: ''
- D:\users\user\ntuser.dat.log1
- D:\users\user\appdata\local\temp\cab4d3a.tmp
- D:\users\user\appdata\local\temp\tar4d4a.tmp
- D:\users\user\appdata\local\temp\cab4e35.tmp
- D:\users\user\appdata\local\temp\tar4e36.tmp
- D:\users\user\appdata\local\temp\cab4f21.tmp
- D:\users\user\appdata\local\temp\tar4f22.tmp
- D:\users\user\appdata\local\temp\cab4f52.tmp
- D:\users\user\appdata\local\temp\tar4f53.tmp
- D:\users\user\appdata\local\temp\cab503e.tmp
- D:\users\user\appdata\local\temp\tar503f.tmp
- D:\users\user\appdata\local\temp\cab50dc.tmp
- D:\users\user\appdata\local\temp\tar50dd.tmp
- D:\users\user\appdata\local\temp\cab51b8.tmp
- D:\users\user\appdata\local\temp\tar51b9.tmp
- D:\system volume information\syscache.hve.log1
- D:\system volume information\syscache.hve
- D:\windows\system32\winevt\logs\system.evtx
- D:\windows\system32\config\system.log1
- D:\windows\system32\config\system
- D:\windows\system32\winevt\logs\security.evtx
- D:\windows\system32\winevt\logs\microsoft-windows-networkprofile%4operational.evtx
- D:\windows\serviceprofiles\localservice\appdata\local\lastalive0.dat
- D:\windows\system32\config\software.log1
- D:\windows\system32\config\software
- D:\windows\system32\winevt\logs\application.evtx
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\c46e7b0f942663a1edc8d9d6d7869173_6043fc604a395e1485af7ac16d16b7ce
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\c46e7b0f942663a1edc8d9d6d7869173_6043fc604a395e1485af7ac16d16b7ce
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\ea618097e393409afa316f0f87e2c202_1e65fd33f74047223af4d58cbfd34bce
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\ea618097e393409afa316f0f87e2c202_1e65fd33f74047223af4d58cbfd34bce
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\bd1f759766d34f19146035da1ddbbef4
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\b3bb9c1ba2d19e090ae305b2683903a0_b89a63ac6877bd1ed812438ce82c3eb8
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\bd1f759766d34f19146035da1ddbbef4
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\103621de9cd5414cc2538780b4b75751
- D:\users\user\ntuser.dat
- D:\windows\appcompat\programs\recentfilecache.bcf
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\e0f5c59f9fa661f6f4c50b87fef3a15a
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\e0f5c59f9fa661f6f4c50b87fef3a15a
- D:\users\user\appdata\local\temp\cab427c.tmp
- D:\users\user\appdata\local\temp\tar427d.tmp
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\94308059b57b3142e455b38a6eb92015
- D:\users\user\appdata\local\temp\cab43f4.tmp
- D:\users\user\appdata\local\temp\tar43f5.tmp
- D:\users\user\appdata\local\temp\cab4444.tmp
- D:\users\user\appdata\local\temp\tar4445.tmp
- D:\users\user\appdata\local\temp\cab4465.tmp
- D:\users\user\appdata\local\temp\tar4466.tmp
- D:\users\user\appdata\local\temp\cab4486.tmp
- D:\users\user\appdata\local\temp\tar4497.tmp
- D:\users\user\appdata\local\temp\cab4582.tmp
- D:\users\user\appdata\local\temp\tar4583.tmp
- D:\users\user\appdata\local\temp\cab45c2.tmp
- D:\users\user\appdata\local\temp\tar45c3.tmp
- D:\users\user\appdata\local\temp\cab46be.tmp
- D:\users\user\appdata\local\temp\tar46bf.tmp
- D:\users\user\appdata\local\temp\cab46ef.tmp
- D:\users\user\appdata\local\temp\tar46f0.tmp
- D:\users\user\appdata\local\temp\cab47cb.tmp
- D:\users\user\appdata\local\temp\tar47cc.tmp
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\644b8874112055b5e195ecb0e8f243a4
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\644b8874112055b5e195ecb0e8f243a4
- D:\users\user\appdata\local\microsoft\windows\usrclass.dat.log1
- D:\users\user\appdata\local\microsoft\windows\usrclass.dat
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\103621de9cd5414cc2538780b4b75751
- D:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\b3bb9c1ba2d19e090ae305b2683903a0_b89a63ac6877bd1ed812438ce82c3eb8
- D:\users\user\appdata\local\temp\cab427c.tmp
- D:\users\user\appdata\local\temp\cab47cb.tmp
- D:\users\user\appdata\local\temp\tar47cc.tmp
- D:\users\user\appdata\local\temp\cab4d3a.tmp
- D:\users\user\appdata\local\temp\tar4d4a.tmp
- D:\users\user\appdata\local\temp\cab4e35.tmp
- D:\users\user\appdata\local\temp\tar4e36.tmp
- D:\users\user\appdata\local\temp\tar4f22.tmp
- D:\users\user\appdata\local\temp\cab4486.tmp
- D:\users\user\appdata\local\temp\cab4f52.tmp
- D:\users\user\appdata\local\temp\tar4f53.tmp
- D:\users\user\appdata\local\temp\cab503e.tmp
- D:\users\user\appdata\local\temp\tar503f.tmp
- D:\users\user\appdata\local\temp\cab50dc.tmp
- D:\users\user\appdata\local\temp\tar50dd.tmp
- D:\users\user\appdata\local\temp\tar46f0.tmp
- D:\users\user\appdata\local\temp\cab46ef.tmp
- D:\users\user\appdata\local\temp\tar46bf.tmp
- D:\users\user\appdata\local\temp\cab46be.tmp
- D:\users\user\appdata\local\temp\tar45c3.tmp
- D:\users\user\appdata\local\temp\cab45c2.tmp
- D:\users\user\appdata\local\temp\tar4583.tmp
- D:\users\user\appdata\local\temp\cab4582.tmp
- D:\users\user\appdata\local\temp\tar4497.tmp
- D:\users\user\appdata\local\temp\cab4f21.tmp
- D:\users\user\appdata\local\temp\tar4466.tmp
- D:\users\user\appdata\local\temp\cab4465.tmp
- D:\users\user\appdata\local\temp\tar4445.tmp
- D:\users\user\appdata\local\temp\cab4444.tmp
- D:\users\user\appdata\local\temp\tar43f5.tmp
- D:\users\user\appdata\local\temp\cab43f4.tmp
- D:\users\user\appdata\local\temp\tar427d.tmp
- D:\users\user\appdata\local\temp\cab51b8.tmp
- D:\users\user\appdata\local\temp\tar51b9.tmp
- 'google.com':80
- 'nf###game.ru':80
- 'nf###game.ru':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- http://nf###game.ru/load/0-0-0-647-20
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgNzlaoHKAvX7s9cX127JHd73A%3D%3D
- 'nf###game.ru':443
- 'localhost':49158
- '34.##1.73.144':443
- DNS ASK google.com
- DNS ASK no###.###nofiledownloader.com
- DNS ASK nf###game.ru
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- ClassName: 'SystemTray_Main' WindowName: ''
- 'D:\windows\syswow64\cmd.exe' /c sc stop WerSvc' (with hidden window)