Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{224E7F0F-64CE-CC69-DD0F-472B4153759D}]
- %TEMP%\3b252c52\_shnficv.dat
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\guest\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\guest\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\guest\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\homegroupuser$\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- %LOCALAPPDATA%\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- %LOCALAPPDATA%\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- %LOCALAPPDATA%\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- %LOCALAPPDATA%\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- %LOCALAPPDATA%\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\administrator\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\administrator\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\aspnet\appdata\local\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- %LOCALAPPDATA%\torch\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\auecg2g@ewda.net\bootstrap.js
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\auecg2g@ewda.net\chrome.manifest
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\auecg2g@ewda.net\content\bg.js
- %ALLUSERSPROFILE%\savemasss\_shnficv.dat
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\staged\auecg2g@ewda.net\install.rdf
- %ProgramFiles(x86)%\savemasss\fn6geik.tlb
- %ProgramFiles(x86)%\savemasss\fn6geik.dat
- %LOCALAPPDATA%low\{224e7f0f-64ce-cc69-dd0f-472b4153759d}\savemasss.2.9.dat
- %ProgramFiles(x86)%\savemasss\fn6geik.x64.dll
- %LOCALAPPDATA%\packages\windows_ie_ac_001\ac\{224e7f0f-64ce-cc69-dd0f-472b4153759d}\savemasss.2.9.dat
- %ALLUSERSPROFILE%\savemasss\_shnficv.exe
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- %LOCALAPPDATA%\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\aspnet\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\homegroupuser$\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\administrator\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\guest\appdata\local\chromatic browser\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- %ProgramFiles(x86)%\savemasss\fn6geik.dll
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\guest\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\homegroupuser$\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\aspnet\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- %TEMP%\3b252c52\_shnficv.exe
- %TEMP%\3b252c52\fn6geik.x64.dll
- %TEMP%\3b252c52\fn6geik.tlb
- %TEMP%\3b252c52\fn6geik.dll
- %TEMP%\3b252c52\auecg2g@ewda.net\content\bg.js
- %TEMP%\3b252c52\auecg2g@ewda.net\install.rdf
- %TEMP%\3b252c52\auecg2g@ewda.net\chrome.manifest
- %TEMP%\3b252c52\auecg2g@ewda.net\bootstrap.js
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\lsdb.js
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\content.js
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\manifest.json
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\background.html
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\u.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\administrator\appdata\local\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\administrator\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\aspnet\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- %LOCALAPPDATA%\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\guest\appdata\local\google\chrome sxs\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\content.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\lsdb.js
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\manifest.json
- C:\users\guest\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- C:\users\homegroupuser$\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\administrator\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\background.html
- C:\users\aspnet\appdata\local\comodo\dragon\user data\default\extensions\ggnldmgdeimonbbpafogjgndlpfmpecl\1.0\u.js
- %ALLUSERSPROFILE%\76197d8cb38d064c\{f7ffe175-e3d6-2e86-0226-1d3ae4905e40}.20220618231914
- %TEMP%\3b252c52\_shnficv.dat
- %TEMP%\3b252c52\_shnficv.exe
- %TEMP%\3b252c52\fn6geik.x64.dll
- %TEMP%\3b252c52\fn6geik.tlb
- %TEMP%\3b252c52\fn6geik.dll
- %TEMP%\3b252c52\auecg2g@ewda.net\content\bg.js
- %TEMP%\3b252c52\auecg2g@ewda.net\install.rdf
- %TEMP%\3b252c52\auecg2g@ewda.net\chrome.manifest
- %TEMP%\3b252c52\auecg2g@ewda.net\bootstrap.js
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\lsdb.js
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\content.js
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\manifest.json
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\background.html
- %TEMP%\3b252c52\ggnldmgdeimonbbpafogjgndlpfmpecl\u.js
- %LOCALAPPDATA%\google\chrome\user data\local state
- %LOCALAPPDATA%\google\chrome\user data\default\preferences
- %ALLUSERSPROFILE%\ntuser.pol
- '%TEMP%\3b252c52\_shnficv.exe'
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\SaveMasss\FN6geIk.x64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\SaveMasss\FN6geIk.x64.dll"
- '<SYSTEM32>\raserver.exe' /offerraupdate