Jump to content

RAT Blocks MalwareBytes installation and run


Recommended Posts

Hi, so i'm facing this infection with this virus that creates 2 processes named audiolog.exe that reopen when both terminated + in the bar there is a NanoCore icon,  i did some research and it is a rat program. So i tried to install malwarebytes but it crashes the installer with all sorts of errors. If you need logs or anything i will provide them as fast as i can :) This is kinda urgent because this is my workstation and many files are in risk. Thanks in advance 

Link to post
Share on other sites

Hi lucaro :)

My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.

  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens;
  • As long as I'm assisting you on Malwarebytes Forums, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you;
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system;
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!;
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off;
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced;
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against Malwarebytes Forums's rules;
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process;
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone;
    This being said, I have a full time job, and I also have night classes on Mondays and Wednesdays, which means that if you reply during these two days, it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread;


This being said, it's time to clean-up some malware, so let's get started, shall we? :)

In order to get started, I'll need you to provide me a set of FRST logs. Follow the instructions in the thread below, and copy/paste the content of both FRST.txt and Addition.txt in your next reply(ies).

https://forums.malwarebytes.org/topic/9573-im-infected-what-do-i-do-now/

 

Link to post
Share on other sites

As you said, you are indeed infected with a backdoor trojan.

Backdoor Trojans, Botnets, and IRCBots are very dangerous because they compromise system integrity by making changes that allow it to be used by the attacker for malicious purposes. They can disable your anti-virus and security tools to prevent detection and removal. Remote attackers use backdoors as a means of accessing and taking control of a computer that bypasses security mechanisms. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is then sent back to the hacker. Read Danger: Remote Access Trojans.

You should disconnect the computer from the Internet and from any networked computers until it is cleaned. If your computer was used for online banking, paying bills, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for taxes, email, eBay, paypal and any other online activities. You should consider them to be compromised and change passwords from a clean computer, not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified immediately of the possible security breach. Failure to notify your financial institution and local law enforcement can result in refusal to reimburse funds lost due to fraud or similar criminal activity. If using a router, you need to reset it with a strong logon/password before connecting again.

Although the infection has been identified and may be removed, your machine has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot be successfully cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:



Whenever a system has been compromised by a backdoor payload, it is impossible to know if or how much the backdoor has been used to affect your system...There are only a few ways to return a compromised system to a confident security configuration. These include:

 
  • Reimaging the system
  • Restoring the entire system using a full system backup from before the backdoor infection
  • Reformatting and reinstalling the system


Backdoors and What They Mean to You

This is what Jesper M. Johansson, Security Program Manager at Microsoft TechNet has to say: Help: I Got Hacked. Now What Do I Do?.


The only way to clean a compromised system is to flatten and rebuild. Thats right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).

There's no guarantee that your system will be clean at 100% after being infected with a backdoor trojan, so you have two choices: either do a nuke and pave (format and reinstall Windows), or go forward with the clean-up. I'll assist you in both cases.

This being said, I noticed traces of pirated software in your logs: for Microsoft Office, Windows and even Malwarebytes software. As we do not condone piracy, I'll ask you to please remove every software, tweak, etc. you use/set in order to use these software illegally, before we go forward with the clean-up.

Link to post
Share on other sites

Sorry for the delay, I had to verify something before replying to your thread.

 

warning.gifP2P Program Warning!
Going over your logs I noticed that you have uTorrent installed.

  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.


It is pretty much certain that if you continue to use P2P programs, you will get infected again.
I would recommend that you uninstall uTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Start > Control Panel > Add/Remove Programs.
If you wish to keep it, please do not use it until your computer is cleaned.

Are you aware that a keylogger and a dynamic DNS program are installed and running on your system?

Shortcut: C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\?rd?m?x Keylogger 4.5\?rd?m?x Keylogger 4.5.lnk -> H:\hax\URR\URR.exe ()
Shortcut: C:\Users\Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\?rdam?x K?ylogger 4.5\?rdam?x K?ylogger 4.5.lnk -> H:\hax\URR\URR.exe ()
2015-07-20 17:34 - 2015-07-20 17:34 - 00012288 _____ () H:\No-IP\ducservice.exe
2015-07-20 17:34 - 2015-07-20 17:34 - 00073728 _____ () H:\No-IP\ducapi.dll

Now, we'll run a first fix with FRST, and this should allow you to download, install and run Malwarebytes afterward. After running the FRST fix, a file called Upload.zip will appear on your desktop. Please upload it to the link below.

www.bleepingcomputer.com/submit-malware.php?channel=194

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located);
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Click on the Fix button;
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad;
  • Copy and paste its content in your next reply;

0isDeWa.pngMalwarebytes Anti-Malware - Clean Mode

  • Download and install the free version of Malwarebytes Anti-Malware
    Note: It's your choice if you want to enable the free trial of Malwarebytes Premium or not. Enabling it will give you real-time protection from the program, as well as access to all the Premium features.
    Note: If you have Malwarebytes already installed, you don't need to install it again. Simply start from the next bullet point;
  • Once Malwarebytes is installed, launch it and let it update his database. You might have to click on the Update Now button;
  • Once the database update is complete, click on the Scan tab, then select the Threat Scan button and click on Start Scan;
  • Let the scan run, the time required to complete the scan depends of your system and computer specs;
  • Once the scan is complete, make sure that the checkbox by Threat is checked (it means that every item detected is checked), then click on the Remove Selected button;
  • Click on Save Results after the deletion (in the bottom-right corner) and select Copy to clipboard. Paste the content in your next reply;

Your next reply(ies) should include:

  • Answer to my question about the keylogger and dynamic DNS programs;
  • Copy/pasted content of FRST fixlog.txt;
  • Copy/pasted content of the Malwarebytes clean log (if you were able to run it);

fixlist.txt

Link to post
Share on other sites

Hi, sorry for the day delay but i have been busy lately. Anyway, i wasn't aware about the keylogger that you have found, should i do something about it? Instead i know about NO-IP, the dynamic DNS program, and it's a perfectly fine software that shouldn't be malicious. I ran the farbar fix and you can find the log attached, it restarted the computer and i don't see the RAT anymore. Malwarebytes on the other hand doesn't want to start up... should i try a fresh install of it?

Fixlog.txt

Link to post
Share on other sites

You should be able to uninstall it, it's called Ardamax Keylogger 4.5. See if it's listed as an installed program, and uninstall it.

Can you upload the Upload.zip file that was created on your desktop to the link below?

http://www.bleepingcomputer.com/submit-malware.php?channel=194

Follow the instructions below to do a clean uninstall of Malwarebytes, then proceed to reinstall it. If it works, run a Threat Scan, delete everything it finds and provide me the log at the end.

https://forums.malwarebytes.org/topic/146017-mbam-clean-removal-process-2x/

 

Link to post
Share on other sites

All good :)

So Malwarebytes didn't detect anything. Let's see if Emsisoft Emergency Kit have anything to report, and let's grab a fresh set of FRST logs after.

G0tu5D9.pngEmsisoft Emergency Kit
Follow the instructions below to run a scan using the Emsisoft Emergency Kit.

  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Extract button to extract the program in the EEK folder;
  • Once the extraction is complete, Emsisoft Emergency Kit will open, and suggest you to run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let Emsisoft Emergency Kit detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on Quarantine selected;
    Egla2gt.png
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, click on the Start Emsisoft Emergency Kit icon again on your desktop to open it;
  • This time, click on Logs;
  • From there, go under the Quarantine Log tab, and click on the Export button;
    IgfWDr3.png
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply;

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.

  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds;
  • Click on the Scan button;
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files;
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply;

How's your computer running now? Do you still notice anything weird?

Your next reply(ies) should include:

  • Copy/pasted content of the EEK scan log;
  • Copy/pasted content of FRST.txt;
  • Copy/pasted content of Addition.txt;
  • Current status of your computer;

Link to post
Share on other sites

Take a look on your desktop and in your Documents folder. There should be tons of files with random name, and the extension .locked.

2016-09-27 20:36 - 2016-09-27 20:36 - 51565008 _____ C:\Users\Luca\Documents\A0B330C50DCEB00B7623BE289BD6D21067C9A7D0912C9C7A7DF9BA6E4124FB96289C819220940477BD7E2449B8EBB6F88FCF65F9.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 47376416 _____ C:\Users\Luca\Documents\A0C337C508BBCA047651BE589BD6D31C65B6A6A1EB279F0D0788BD194321FDE32F9886E221E30275C10A224BC59DB5888DC81EF42BDF6C4567422E20F5259D03F2735B884B1E0EF01DCBDEBEF9BA.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 34488720 _____ C:\Users\Luca\Desktop\DCBF37B40DBCCA76732EC558E7A0D16367B6A7D090209C0D7DFBBB1F3A23FEE12CED.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 33526624 _____ C:\Users\Luca\Documents\A5B237C20DCCB170732EBF29E6A1D01566BDA2D3EB529C0D7E88BB684027FF922C9D859624E60375C77E2039B89AB58E8DB81F8528AC6D3B67472F2CF42A9D03F17D27FB341D0EF01DCBDEBEF9BA.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 05129872 _____ C:\Users\Luca\Documents\A0C330B708C8B0047656B95EE7A2D11766BB.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 04024560 _____ C:\Users\Luca\Desktop\DCC337C80CCBCB067353B95EE6A7D16467BF.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 03447712 _____ C:\Users\Luca\Desktop\A5C331B00FCFB0007654BE289CA6D41662B8A3D2EA57997A7A8BB86D4654FB9329EE82E524907975C779.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 03160560 _____ C:\Users\Luca\Documents\A0B537C30DC9B00A7655C42C9BD6D36666B9A6D690279E0B07F3BA184024FE962CE886E024E27872C77F223FC59FB6F88FCB668351AD6E4964432E538B51E207F60E58FC4F140AF51DC9.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 02788288 _____ C:\Users\Luca\Desktop\A5C331B00FCFB0007654BE289CA6D41662B8A3D2EA57997A7A8BB86D4653FB9529EB82E524907975C779.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 02501232 _____ C:\Users\Luca\Documents\A5B237C30DCFCA0B7251BF53E7A2D06466B9A7D7902C9D007AFDBB1F4620FA97289A819120EA0300C07E2148C49C.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 02458096 _____ C:\Users\Luca\Documents\A5B237C30DCFCA0B7251BF53E7A2D06466B9A7D7902C9D007AFDBB1F4627FAE02DE9869127E1.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 02454048 _____ C:\Users\Luca\Desktop\A5C331B00FCFB0007654BE289CA6D41662B8A3D2EA57997A7A8BB86D4654FB9629EB82E524907975C779.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 02403264 _____ C:\Users\Luca\Desktop\A5C331B00FCFB0007654BE289CA6D41662B8A3D2EA57997A7AF3B8684624FB94299D82E524907975C779.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 01595136 _____ C:\Users\Luca\Desktop\DDB034C609B9CA057322C429.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 01501088 _____ C:\Users\Luca\Documents\DCB237C20DCAB0007654BE289CA4D11567BAA5DC90579D7E79FBBC6A3A25FF95.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 01415264 _____ C:\Users\Luca\Documents\A0B130B408C9B00A762EBC5FE6D7D11367BBA7D690259C7A07FABC6A3A21FE932F9F86EC27E17870C77F213CC6EAB78F8FCB66F951AA6E4A654029508C239F07F372.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 01269216 _____ C:\Users\Luca\Documents\A0B037C208BBB0027655BE529BD6D21666BBA6DC90239C7E7D89BC6C4026FC922EE780E426E20171BC05234EC6E1B5808CB3628051AF6B386130282588279F05F30F5F8F.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 01146032 _____ C:\Users\Luca\Documents\A0B230C408CACA06762FC4299CA6D41067BAA3A2EA20990B7AFDB8684622FB962CEA869123EB7870C704214AB99FB7FA8ABD618050D16B3F604728208B55E201F778268F4C1B0A861DCCDDBFF8BDFC3D1973F00ADCBEF009DF3A663F94F9.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 01077184 _____ C:\Users\Luca\Documents\A0B730C408CBB002732EC4529CA5D11462B9A3D4ED279C7C7DFCBF6E.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 01077184 _____ C:\Users\Luca\Documents\A0B234B50CC2CB007322C4539CA2D56167BEA6A19056.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00999472 _____ C:\Users\Luca\Documents\A0B130C208C9B0077656BE2C9BD7D11C66B9A6D4.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00939648 _____ C:\Users\Luca\Desktop\A0B730C708CBB0037652BE539CA1D56167CCA7D39055.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00918896 _____ C:\Users\Luca\Documents\A0B037C308C8CA067651BE599BD6D36364BCA4D2ED279D087DFCBC68.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00821616 _____ C:\Users\Luca\Desktop\A5C637C30CBBCB077251B92B9CA4D51663CDA2D3E8509D7E7E8EBC683A28FE9228EB879224977879C00C214EC3EAB78F8BCC62F32AAB6B4E603228258F21E206F67D5B894B1E0EF518B8DDBFF8CDFD38.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00794288 _____ C:\Users\Luca\Documents\A0B730C608CEB004762FBE299CD1D41162B8A5DCE82D9C0B7DF8BF6A3A52FEE62F9F859721970272C70C213CC3E1B78C8FBC66F750DC6D4967312D508F569802F20E5C884C6F0A841CB8DEB8F8BDFE4B1E70F476DFBEF17EDB3F614997F72B6DA2E0.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00747040 _____ C:\Users\Luca\Desktop\A5C331B00FCFB0007654BE289CA6D41662B8A3D2EA57997A7AF3B8684624FB94299D82E624917805C70B253CC3EFB6818FB2.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00652512 _____ C:\Users\Luca\Desktop\A0B230C408CBB0037652BE539CA1D41462BAA3D2EA52990179FBBF623B24FE90.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00642448 _____ C:\Users\Luca\Desktop\DDB337B70DBECB067324BE289CA4D41362BAA3D2EA52990A7A8BB86D4653FBE129EF81ED20917878C70C213CB8EBB78B8ECC6685.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00630464 _____ C:\Users\Luca\Desktop\DDB337B70DBECB067324BE289CA4D41362BAA3D2EA52990A7A8BB86E4625FB97299D819520917878C70C213CB8EBB78B8ECC6685.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00480512 _____ C:\Users\Luca\Desktop\DCB230C40DC9B7707326C459E6D7D56167CCA7D39055.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00478656 _____ C:\Users\Luca\Documents\A0B730C608CFB0007654BE539CA3D41362BBA5DCE8529C7E7E89BF1A3A20FE922C9C859624EA7874C709223FC69AB7808EC8658450AA6F4465302E53F4269D01F17327F5486871811FBFA5BDF8B1FD381804F500DDC4F40EDF3A.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00454112 _____ C:\Users\Luca\Documents\A0B430B408CCB0017652BE299BD6D21067BCA7D190209C7B7EFCBB684323FE962CE6869520E30173C70C2145C3E0B6FB8BCC62F32BAC6D3B67402E238820E376F27F5CFB4F1E.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00452656 _____ C:\Users\Luca\Desktop\DDB337B70DBECB067324BE289CA4D41362BAA3D2EA52990A7A8BB86E4624FB9729EB819020917878C70C213CB8EBB78B8ECC6685.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00417072 _____ C:\Users\Luca\Documents\A0B730C608CEB000762EBE2C9CA3D41262BBA5DCEB569C0B7E8EBC6B3B20FA9A2DEB869527E17976C70A213CC6EAB7FB8FCF66F650AA6F44654029508F239877F20C.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00182784 _____ C:\Users\Luca\Desktop\A0B130C608C9B0047726BE2B9CA7D56062BBA3D3ED50997A7A88BA184624FBE62F9F819023E40378C1082139C3EBB7FD8FC965F950D16E39644529258B51E376F67258FC4B1F0D8518B8DDBFF8CDFD38.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00163712 _____ C:\Users\Luca\Desktop\A0B130C608C9B0047726BE2B9CA7D56062BBA3D3ED50997A7A8BBA184624FBE62F9F819623E60378C1082139C3EBB7FD8FC965F950D16E39644529258B51E376F67258FC4B1F0D8518B8DDBFF8CDFD38.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00141072 _____ C:\Users\Luca\Desktop\DCC336C60DBBCA767325C42C9BD6D41363B7A6A091509C7C.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00125520 _____ C:\Users\Luca\Desktop\DCB737C90DCBCB077326C42CE6D7D01267C9A2A590249C0B7DFBBB1F3A55FF972CEC.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00109456 _____ C:\Users\Luca\Documents\A0B230C408CACA06762FC4299CA6D41067BAA3A2EA20990B7AFDB8684622FB962CEA869123EB7870C704214AB99FB7FA8ABD618050D16B3F604728208B55E201F77B5CF54C6C0A83.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00090384 _____ C:\Users\Luca\Desktop\DDB337C70CCCCA03722FC4289BD7D11167C9A6D5.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00050816 _____ C:\Users\Luca\Documents\A7BE33B208CBB00B7754BE539CA4D41663B9A3D5EA55997D798CB86E4625FB9229EB82E620E30477BD052448B998B2818ACE61802AAD6D49604128258B52E201F6095B8948690AF41DC9DEB8.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00039520 _____ C:\Users\Luca\Documents\A0B030C708B8B7757355C459E6A6.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00026816 _____ C:\Users\Luca\Documents\A0B730C408C8B0077654BE2B9CA1D41062CAA5DCEB269C0C7D8BBB1E4023FE962D9D87E421E07971C07E214CC3E0B6FA8CBA1F8351AB6F4465372C228F2AE376F27F5CFB4F1E.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00012512 _____ C:\Users\Luca\Desktop\A0B230C608CBB0017754BC2BE7A2D11367CDA6A1912C9C0F798CBD1E3A54FEE02CEE869727E17874C77A204DB89AB4FD8EC9668751AB6E4865402D518C559F04F77B5F8D4F6F0981.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00012256 _____ C:\Users\Luca\Desktop\DCB234C60CC8CA777322C453E6A1D01267C9A6DC9027980C7EFDBF1E3A28.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00010032 _____ C:\Users\Luca\Documents\A0B237C30DCACA047356C4299BD6D21C67C9A5D3E8509E0D078EBD694354FC932F9F879726EB7805C278233EC5E0B5808DC81E802BAA6C3B66422E53F450E206F60858FC4F1C0A841DCB.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00006992 _____ C:\Users\Luca\Documents\DCB237C20CC8CA0B7024C42CE6D7D26662B8A2DDEA51980C7DFFBC6B.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00006096 _____ C:\Users\Luca\Documents\A0B230C408CACA06762FC4299CA6D41067BAA3A2EA20990B7AFDB8684622FB962CEA869123EB7870C704214AB99FB7FA8ABD618050D16B3F604728208B55E201F60B58FC4C190AF51CCF.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00005856 _____ C:\Users\Luca\Desktop\A6B634C50DCDCB007251C45EE6A1D16067BCA7D0EA2D980C7E88BC193B20.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00004736 _____ C:\Users\Luca\Documents\A0B230C408CACA06762FC4299CA6D41067BAA3A2EA20990B7AFDB8684622FB962CEA869123EB7870C704214AB99FB7FA8ABD618050D16B3F604728208B55E201F60E58FC4C190AF51CCF.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00004736 _____ C:\Users\Luca\Documents\A0B230C408CACA06762FC4299CA6D41067BAA3A2EA20990B7AFDB8684622FB962CEA869123EB7870C704214AB99FB7FA8ABD618050D16B3F604728208B55E201F60858FC4C190AF51CCF.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00003984 _____ C:\Users\Luca\Desktop\A5C634C30DBECB047324B92BE6A4D16667BAA7D690249C7E7DFBBC6C3A52FA972CEF86E220E37971C77F204AC4E1B78E8BCC62F32AAB6A4F61302C218F219F03.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00003424 _____ C:\Users\Luca\Documents\A0B437C008BBCA017622BE2F9BD6D21564BCA4DDEB2D9E7A07FCBD6C4026FEE12FED809521E47805C278233EC6EFB7888CCC1E802BDF6D4467402F2CF5569F01F60F5B8D486909871CC8DDBD.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00002736 _____ C:\Users\Luca\Documents\A0C430B408C9B004762FBE2E9CA6D56062BCA3D4EA509C7A7AF2BF6C3A25FB9629E9819523E67876C77A2148B99FB2818FC9618750AB6E44654728278B2A9806F30B5BF54C1C0A8319CEDEBDFDBFFD3C1E05F177D9B7F17CDB3E653C94F9571BD895618197093D5D.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00002720 _____ C:\Users\Luca\Documents\A0B230C008CBB0057622BE2F9BD6D31367B7A6A290579C0C7D89BF6D3A20FDE32EEE85E327E37879C70A204AC3ECB78E8FBB65F828DF6B3C6130282588279F05F30F5F8F.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00000160 _____ C:\Users\Luca\Documents\A7B530C408CBB0037725C52FE7D1D012.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00000160 _____ C:\Users\Luca\Desktop\A6B331B40FCCB775722FC558E7A4.locked
2016-09-27 20:36 - 2016-09-27 20:36 - 00000080 _____ C:\Users\Luca\Desktop\A5C634C30DBECB047324B92BE6A4D16667BAA7D690249C7E7DFBBC6C3A52FA972CEF86E220E37971C77F204AC4E1B78E8BBB658451D86F3B.locked

 

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.