Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'LAC-KID' = '<Full path to file>'
- <Drive name for removable media>:\000814251_video_01.avi.lonleyencryptedfile
- <Drive name for removable media>:\join.avi.lonleyencryptedfile
- <Drive name for removable media>:\coffee.bmp.lonleyencryptedfile
- <Drive name for removable media>:\dialmap.bmp.lonleyencryptedfile
- <Drive name for removable media>:\default.bmp.lonleyencryptedfile
- <Drive name for removable media>:\dashborder_96.bmp.lonleyencryptedfile
- <Drive name for removable media>:\dashborder_120.bmp.lonleyencryptedfile
- <Drive name for removable media>:\tileimage.bmp.lonleyencryptedfile
- <Drive name for removable media>:\dial.bmp.lonleyencryptedfile
- <Drive name for removable media>:\pmd.cer.lonleyencryptedfile
- <Drive name for removable media>:\testee.cer.lonleyencryptedfile
- <Drive name for removable media>:\contoso.cer.lonleyencryptedfile
- <Drive name for removable media>:\february_catalogue__2015.doc.lonleyencryptedfile
- <Drive name for removable media>:\applicantform_en.doc.lonleyencryptedfile
- %HOMEPATH%\desktop\advice_process.htm
- %HOMEPATH%\desktop\alert.htm
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\dashborder_192.bmp
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\delete.avi
- %HOMEPATH%\desktop\garden.htm
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\ovp25012015.doc
- %HOMEPATH%\desktop\pmd.cer
- %HOMEPATH%\desktop\testee.cer
- <Current directory>\zzzz.bmp
- %WINDIR%\syswow64\12520850.cpx.lonleyencryptedfile
- C:\users.lonleyencryptedfile
- %WINDIR%\syswow64\aaclient.dll.lonleyencryptedfile
- C:\$recycle.bin\..lonleyencryptedfile
- C:\$recycle.bin\...lonleyencryptedfile
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001.lonleyencryptedfile
- %WINDIR%\syswow64\ac3acm.acm.lonleyencryptedfile
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\..lonleyencryptedfile
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\...lonleyencryptedfile
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\desktop.ini.lonleyencryptedfile
- %WINDIR%\syswow64\accessibilitycpl.dll.lonleyencryptedfile
- C:\far2\changelog.lonleyencryptedfile
- %WINDIR%\syswow64\12520437.cpx.lonleyencryptedfile
- C:\systemtool.exe.lonleyencryptedfile
- %WINDIR%\syswow64\acctres.dll.lonleyencryptedfile
- %WINDIR%\bitlockerdiscoveryvolumecontents.lonleyencryptedfile
- %WINDIR%\syswow64\acledit.dll.lonleyencryptedfile
- %WINDIR%\bootstat.dat.lonleyencryptedfile
- %WINDIR%\syswow64\aclui.dll.lonleyencryptedfile
- %WINDIR%\directx.log.lonleyencryptedfile
- %WINDIR%\syswow64\acppage.dll.lonleyencryptedfile
- %WINDIR%\dtcinstall.log.lonleyencryptedfile
- %WINDIR%\syswow64\actioncenter.dll.lonleyencryptedfile
- C:\far2\clearpluginscache.cmd.lonleyencryptedfile
- %WINDIR%\enterprise.xml.lonleyencryptedfile
- C:\far2\far.exe.lonleyencryptedfile
- C:\far2\far.map.lonleyencryptedfile
- C:\far2\changelog_eng.lonleyencryptedfile
- %WINDIR%\bfsvc.exe.lonleyencryptedfile
- C:\system volume information.lonleyencryptedfile
- C:\recovery.lonleyencryptedfile
- %PROGRAMDATA%.lonleyencryptedfile
- %HOMEPATH%\documents\lac-core.exe
- D:\$recycle.bin.lonleyencryptedfile
- D:\install.log.lonleyencryptedfile
- D:\system volume information.lonleyencryptedfile
- D:\$recycle.bin\..lonleyencryptedfile
- D:\$recycle.bin\...lonleyencryptedfile
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001.lonleyencryptedfile
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\..lonleyencryptedfile
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\...lonleyencryptedfile
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\desktop.ini.lonleyencryptedfile
- %WINDIR%\assembly.lonleyencryptedfile
- %HOMEPATH%\desktop\..lonleyencryptedfile
- %HOMEPATH%\desktop\...lonleyencryptedfile
- C:\systemtool.exe
- %HOMEPATH%\desktop\000814251_video_01.avi.lonleyencryptedfile
- %HOMEPATH%\desktop\icq.lnk.lonleyencryptedfile
- %HOMEPATH%\desktop\mail.ru agent.lnk.lonleyencryptedfile
- %HOMEPATH%\desktop\qip 2012.lnk.lonleyencryptedfile
- %HOMEPATH%\desktop\skypesetup.exe.lonleyencryptedfile
- %HOMEPATH%\desktop\telegram.lnk.lonleyencryptedfile
- %HOMEPATH%\desktop\total commander 64 bit.lnk.lonleyencryptedfile
- %HOMEPATH%\desktop\wrar520.exe.lonleyencryptedfile
- C:\$recycle.bin.lonleyencryptedfile
- C:\documents and settings.lonleyencryptedfile
- C:\msocache.lonleyencryptedfile
- C:\pagefile.sys.lonleyencryptedfile
- %ProgramFiles%.lonleyencryptedfile
- %ProgramFiles(x86)%.lonleyencryptedfile
- %HOMEPATH%\desktop\desktop.ini.lonleyencryptedfile
- %WINDIR%\explorer.exe.lonleyencryptedfile
- C:\far2\farcze.lng.lonleyencryptedfile
- C:\systemtool.exe
- C:\systemtool.exe
- %WINDIR%\syswow64\ac3acm.acm
- %WINDIR%\bootstat.dat
- %WINDIR%\directx.log
- %WINDIR%\dtcinstall.log
- %WINDIR%\enterprise.xml
- %WINDIR%\flash_sa.exe
- %WINDIR%\msdfmap.ini
- %WINDIR%\ntbtlog.txt
- %WINDIR%\pfro.log
- %WINDIR%\setupact.log
- %WINDIR%\setuperr.log
- %WINDIR%\starter.xml
- %WINDIR%\system.ini
- %WINDIR%\tssysprep.log
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: '' WindowName: 'Taskmgr.exe'
- ClassName: '' WindowName: 'CMD.exe'
- 'C:\systemtool.exe'
- '%HOMEPATH%\documents\lac-core.exe'