Library
My library

+ Add to library

Profile

Trojan.DownLoader33.62485

Added to the Dr.Web virus database: 2020-07-12

Virus description added:

Technical Information

Modifies file system
Creates the following files
  • <Current directory>\comct232.ocx
  • <Current directory>\assets\images\default_icon.ico
  • <Current directory>\assets\images\splash.bmp
  • <Current directory>\assets\images\techwaru3.bmp
  • <Current directory>\assets\images\techwaruicon.jpg
  • <Current directory>\assets\images\techwaruside.bmp
  • <Current directory>\assets\images\techwarutitle.jpg
  • <Current directory>\assets\ishelllink.tlb
  • <Current directory>\assets\logs\template\fonts\glyphicons-halflings-regular.ttf
  • <Current directory>\assets\logs\template\fonts\fontawesome-webfont.eot
  • <Current directory>\assets\logs\template\fonts\fontawesome-webfont.svg
  • <Current directory>\assets\logs\template\fonts\fontawesome-webfont.ttf
  • <Current directory>\assets\logs\template\fonts\fontawesome-webfont.woff
  • <Current directory>\assets\logs\template\fonts\fontawesome.otf
  • <Current directory>\assets\logs\template\fonts\glyphicons-halflings-regular.eot
  • <Current directory>\assets\images\techwarutop.bmp
  • <Current directory>\assets\logs\template\fonts\glyphicons-halflings-regular.svg
  • <Current directory>\assets\config\techwaru.ini
  • <Current directory>\assets\config\rt_preset.ini
  • <Current directory>\assets\config\d7ii.ini
  • <Current directory>\assets\config\customtools\vmt.cfg
  • <Current directory>\assets\config\customtools\ultravnc.cfg
  • <Current directory>\assets\config\customtools\sortorder.cfg
  • <Current directory>\assets\config\customtools\patchmypc.cfg
  • <Current directory>\assets\config\customtools\ocxregistertool.cfg
  • <Current directory>\assets\config\customtools\linx.cfg
  • <Current directory>\assets\config\customtools\gpuz.cfg
  • <Current directory>\assets\config\customtools\avastbrowsercleanup.cfg
  • <Current directory>\assets\config\customtools\3dp.cfg
  • <Current directory>\assets\config\customscripts\sortorder.cfg
  • <Current directory>\assets\config\customscripts\foo.cfg
  • <Current directory>\assets\dot_net_req.ini
  • <Current directory>\assets\logs\template\img\icon-color-close.png
  • <Current directory>\assets\logs\template\fonts\glyphicons-halflings-regular.woff
  • <Current directory>\assets\logs\template\img\datatable-row-openclose.png
  • <Current directory>\assets\logs\template\img\avatar.png
  • <Current directory>\assets\logs\template\img\avatar1.jpg
  • <Current directory>\assets\logs\template\img\avatar10.jpg
  • <Current directory>\assets\logs\template\img\avatar11.jpg
  • <Current directory>\assets\logs\template\img\avatar1_small.jpg
  • <Current directory>\assets\logs\template\img\avatar2.jpg
  • <Current directory>\assets\logs\template\img\avatar3_small.jpg
  • <Current directory>\assets\logs\template\fonts\simple-line-icons.dev.svg
  • <Current directory>\assets\logs\template\img\avatar4.jpg
  • <Current directory>\assets\logs\template\img\avatar5.jpg
  • <Current directory>\assets\logs\template\img\avatar6.jpg
  • <Current directory>\assets\logs\template\img\avatar7.jpg
  • <Current directory>\assets\logs\template\img\avatar8.jpg
  • <Current directory>\assets\logs\template\img\avatar9.jpg
  • <Current directory>\assets\logs\template\img\arrow-down.png
  • <Current directory>\assets\logs\template\img\ajax-modal-loading.gif
  • <Current directory>\assets\logs\template\fonts\simple-line-icons.eot
  • <Current directory>\assets\logs\template\html\stats.html
  • <Current directory>\assets\logs\template\img\ajax-loading.gif
  • <Current directory>\assets\logs\template\img\accordion-plusminus.png
  • <Current directory>\assets\logs\template\images\techwaru3.jpg
  • <Current directory>\assets\logs\template\html\wrapper.html
  • <Current directory>\assets\logs\template\html\tool.html
  • <Current directory>\assets\config\techwaru_defaultapps.ini
  • <Current directory>\assets\logs\template\html\sysinfo.html
  • <Current directory>\assets\config\custommalware\sortorder.pre
  • <Current directory>\assets\logs\template\html\categories.html
  • <Current directory>\assets\logs\template\html\alerts.html
  • <Current directory>\assets\logs\template\fonts\simple-line-icons.woff
  • <Current directory>\assets\logs\template\fonts\simple-line-icons.ttf
  • <Current directory>\assets\logs\template\fonts\simple-line-icons.svg
  • <Current directory>\assets\logs\template\html\sample.html
  • <Current directory>\assets\logs\template\img\avatar3.jpg
  • <Current directory>\assets\logs\template\img\hor-menu-red-arrow.png
  • <Current directory>\assets\config\custommalware\rkill.cfg
  • <Current directory>\assets\3rd party tools\ketarin\system information\webbrowserpassview.xml
  • <Current directory>\assets\config\3rd party configs\ccleaner.ini
  • <Current directory>\assets\cgziplibrary.dll
  • <Current directory>\assets\3rd party tools\subinacl.exe
  • <Current directory>\assets\3rd party tools\psexec.exe
  • <Current directory>\assets\3rd party tools\ketarin\tamir.sharpssh.dll
  • <Current directory>\assets\3rd party tools\ketarin\system.data.sqlite.dll
  • <Current directory>\assets\3rd party tools\ketarin\system tuneup\piriform defraggler.xml
  • <Current directory>\assets\3rd party tools\ketarin\system tuneup\piriform defraggler x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\winupdateslist.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\wincrashreport.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\wincrashreport x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\whatinstartup.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\whatinstartup x64.xml
  • <Current directory>\assets\config\custominstall\autoruns.cfg
  • <Current directory>\assets\config\brandos\brandos.ini
  • <Current directory>\assets\config\brandos\oeminfo.ini
  • <Current directory>\assets\3rd party tools\ketarin\system information\installeddriverslist x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installedcodec.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installedcodec x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\get product keys.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\devmanview.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\devmanview x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\currports.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\currports x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\browsing history view.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\browsing history view x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system cleanup\piriform ccleaner.xml
  • <Current directory>\assets\3rd party tools\ketarin\system cleanup\piriform ccleaner x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\scilexer.dll
  • <Current directory>\assets\3rd party tools\ketarin\system information\installeddriverslist.xml
  • <Current directory>\assets\config\custominstall\patchmypc (auto).cfg
  • <Current directory>\assets\config\custommalware\oldtimer listit.cfg
  • <Current directory>\assets\config\custommaint\eset av remover.cfg
  • <Current directory>\assets\config\custommalware\herdprotect.cfg
  • <Current directory>\assets\config\custommalware\autoruns.cfg
  • <Current directory>\assets\config\custommalware\combofix (uninstall).cfg
  • <Current directory>\assets\config\custommalware\combofix.cfg
  • <Current directory>\assets\config\custommalware\eset poweliks cleaner.cfg
  • <Current directory>\assets\config\custommalware\farbar service scanner.cfg
  • <Current directory>\assets\config\custommalware\gmer.cfg
  • <Current directory>\assets\config\custommalware\hijack this.cfg
  • <Current directory>\assets\config\brandos\brandos.exe
  • <Current directory>\assets\config\custommalware\hitmanpro.cfg
  • <Current directory>\assets\config\custommalware\kaspersky tdsskiller.cfg
  • <Current directory>\assets\config\custommalware\malwarebytes.cfg
  • <Current directory>\assets\config\custommalware\mcafee rootkitremover.cfg
  • <Current directory>\assets\config\custommalware\mcafee stinger.cfg
  • <Current directory>\assets\config\custommalware\microsoft safety scanner.cfg
  • <Current directory>\assets\config\custommalware\adw cleaner.cfg
  • <Current directory>\assets\config\custommaintii\sortorder.cfg
  • <Current directory>\assets\config\custommaintii\seatools.cfg
  • <Current directory>\assets\config\custommaint\tcpoptimizer.cfg
  • <Current directory>\assets\config\custommaint\startuplite.cfg
  • <Current directory>\assets\config\custommaint\spacesniffer.cfg
  • <Current directory>\assets\config\custommaint\sortorder.cfg
  • <Current directory>\assets\config\custommaint\revo uninstaller.cfg
  • <Current directory>\assets\config\custommalware\sortorder.post
  • <Current directory>\assets\config\custommaint\comintrepair.cfg
  • <Current directory>\assets\config\custommaint\codecinstaller.cfg
  • <Current directory>\assets\config\custommaint\auslogics registrycleaner.cfg
  • <Current directory>\assets\config\custommaint\auslogics diskdefrag.cfg
  • <Current directory>\assets\config\custommaint\auslogics browsercare.cfg
  • <Current directory>\assets\config\custominstall\sortorder.cfg
  • <Current directory>\assets\config\custominstall\patchmypc.cfg
  • <Current directory>\assets\config\custommalware\sortorder.cfg
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\nn\lc_messages\bleachbit.mo
  • <Current directory>\assets\logs\template\img\icon-color.png
  • <Current directory>\assets\modules\ifeo_dummy.exe
  • <Current directory>\assets\modules\ifeo_modifier.exe
  • <Current directory>\assets\modules\deltmps.cmd
  • <Current directory>\assets\modules\delzbf.cmd
  • <Current directory>\assets\modules\dependencies\comct232.ocx
  • <Current directory>\assets\modules\dependencies\comct332.ocx
  • <Current directory>\assets\modules\dependencies\comctl32.ocx
  • <Current directory>\assets\modules\dependencies\mscomct2.ocx
  • <Current directory>\assets\modules\killemall.scr
  • <Current directory>\assets\modules\dependencies\mscomctl.ocx
  • <Current directory>\assets\modules\dependencies\mscomm32.ocx
  • <Current directory>\assets\modules\dependencies\msinet.ocx
  • <Current directory>\assets\modules\dependencies\mswinsck.ocx
  • <Current directory>\assets\modules\entessa public license.txt
  • <Current directory>\assets\modules\goog.exe
  • <Current directory>\assets\modules\dependencies\comdlg32.ocx
  • <Current directory>\assets\modules\defs\reghunt_svcs_whitelist.txt
  • <Current directory>\assets\modules\d7_cfsvc.exe
  • <Current directory>\assets\modules\d7_browser.exe
  • <Current directory>\assets\modules\d714.ico
  • <Current directory>\assets\modules\curl\x64\curl.exe
  • <Current directory>\assets\modules\curl\x64\curl-ca-bundle.crt
  • <Current directory>\assets\modules\curl\x64\copyright.txt
  • <Current directory>\assets\modules\curl\x32\curl.exe
  • <Current directory>\assets\modules\curl\x32\curl-ca-bundle.crt
  • <Current directory>\assets\modules\curl\x32\copyright.txt
  • <Current directory>\assets\modules\cdosys.dll
  • <Current directory>\assets\modules\brandos.exe
  • <Current directory>\assets\modules\branding\oemlogo.bmp
  • <Current directory>\assets\modules\bootsafe.exe
  • <Current directory>\assets\modules\defs\reghunt_run_whitelist.txt
  • <Current directory>\assets\modules\d7_sr.exe
  • <Current directory>\assets\logs\template\img\icon-img-down.png
  • <Current directory>\assets\modules\killemallplus.scr
  • <Current directory>\assets\3rd party tools\ketarin.zip
  • <Current directory>\assets\scripts\hitman_auto.exe
  • <Current directory>\assets\scripts\hp_auto.exe
  • <Current directory>\assets\scripts\jrt_auto.exe
  • <Current directory>\assets\scripts\otl_auto.exe
  • <Current directory>\assets\scripts\rr_auto.exe
  • <Current directory>\assets\scripts\screencap.exe
  • <Current directory>\assets\unzip32.dll
  • <Current directory>\assets\scripts.zip
  • <Current directory>\assets\updatenotes.txt
  • <Current directory>\assets\vbwebdownload.dll
  • <Current directory>\assets\version.txt
  • <Current directory>\assets\zip32.dll
  • <Current directory>\assets\debugoutput-techwaru.txt
  • <Current directory>\assets\errorlog.txt
  • <Current directory>\assets\scripts\fss_auto.exe
  • <Current directory>\assets\modules\language.txt
  • <Current directory>\assets\modules\rebootmaster.exe
  • <Current directory>\assets\logs\template\stylesheets\themes\default.css
  • <Current directory>\assets\modules\vd_config.ini
  • <Current directory>\assets\scripts\eset_auto.exe
  • <Current directory>\assets\scripts\disablesleep.bat
  • <Current directory>\assets\scripts\cir_auto.exe
  • <Current directory>\assets\scripts\bcdedit64.exe
  • <Current directory>\assets\modules\ifeo_silent_dummy.exe
  • <Current directory>\assets\scripts\bcdedit32.exe
  • <Current directory>\assets\modules\vbwebdownload.dll
  • <Current directory>\assets\logs\template\stylesheets\uniform.default.min.css
  • <Current directory>\assets\modules\testpack\test.xlsx
  • <Current directory>\assets\modules\testpack\test.pdf
  • <Current directory>\assets\modules\testpack\test.mp3
  • <Current directory>\assets\modules\testpack\test.docx
  • <Current directory>\assets\olelib.tlb
  • <Current directory>\assets\logs\template\stylesheets\simple-line-icons.min.css
  • <Current directory>\assets\logs\template\stylesheets\plugins.css
  • <Current directory>\assets\logs\template\img\sidebar_arrow_icon_light_rtl.png
  • <Current directory>\assets\logs\template\img\portlet-collapse-icon-white.png
  • <Current directory>\assets\logs\template\img\sidebar-menu-arrow.png
  • <Current directory>\assets\logs\template\img\sidebar-menu-arrow-right.png
  • <Current directory>\assets\logs\template\img\sidebar-menu-arrow-reverse.png
  • <Current directory>\assets\logs\template\img\search_icon_light.png
  • <Current directory>\assets\logs\template\img\remove-icon-small.png
  • <Current directory>\assets\logs\template\img\portlet-remove-icon.png
  • <Current directory>\assets\logs\template\img\portlet-remove-icon-white.png
  • <Current directory>\assets\logs\template\img\portlet-reload-icon.png
  • <Current directory>\assets\logs\template\img\portlet-reload-icon-white.png
  • <Current directory>\assets\logs\template\img\portlet-expand-icon.png
  • <Current directory>\assets\logs\template\img\portlet-expand-icon-white.png
  • <Current directory>\assets\logs\template\img\portlet-config-icon.png
  • <Current directory>\assets\logs\template\img\portlet-config-icon-white.png
  • <Current directory>\assets\logs\template\img\portlet-collapse-icon.png
  • <Current directory>\assets\logs\template\img\icon-img-up.png
  • <Current directory>\assets\3rd party tools\ketarin\rt_apps.xml
  • <Current directory>\assets\logs\template\img\logo-big.png
  • <Current directory>\assets\logs\template\img\photo2.jpg
  • <Current directory>\assets\logs\template\img\photo1.jpg
  • <Current directory>\assets\logs\template\img\overlay-icon.png
  • <Current directory>\assets\logs\template\img\menu-toggler.png
  • <Current directory>\assets\logs\template\img\logo.png
  • <Current directory>\assets\logs\template\img\sidebar_inline_toggler_icon_darkblue.jpg
  • <Current directory>\assets\logs\template\img\logo-invert.png
  • <Current directory>\assets\logs\template\img\sidebar_inline_toggler_icon_blue.jpg
  • <Current directory>\assets\logs\template\img\loading-spinner-grey.gif
  • <Current directory>\assets\logs\template\img\loading-spinner-default.gif
  • <Current directory>\assets\logs\template\img\loading-spinner-blue.gif
  • <Current directory>\assets\logs\template\img\input-spinner.gif
  • <Current directory>\assets\logs\template\img\inbox-nav-arrow-blue.png
  • <Current directory>\assets\logs\template\img\loading.gif
  • <Current directory>\assets\3rd party tools\ketarin\system information\mail passview.xml
  • <Current directory>\assets\logs\template\img\sidebar_inline_toggler_icon_grey.jpg
  • <Current directory>\assets\logs\template\img\sidebar_toggler_icon_light2.png
  • <Current directory>\assets\logs\template\javascripts\metronic.js
  • <Current directory>\assets\logs\template\javascripts\jquery-ui-1.10.3.custom.min.js
  • <Current directory>\assets\logs\template\javascripts\jquery.blockui.min.js
  • <Current directory>\assets\logs\template\javascripts\jquery.cokie.min.js
  • <Current directory>\assets\logs\template\javascripts\jquery.slimscroll.min.js
  • <Current directory>\assets\logs\template\javascripts\jquery.uniform.min.js
  • <Current directory>\assets\logs\template\javascripts\layout.js
  • <Current directory>\assets\logs\template\javascripts\report.js
  • <Current directory>\assets\logs\template\img\sidebar_arrow_icon_light.png
  • <Current directory>\assets\logs\template\javascripts\respond.min.js
  • <Current directory>\assets\logs\template\stylesheets\bootstrap-switch.min.css
  • <Current directory>\assets\logs\template\stylesheets\bootstrap.min.css
  • <Current directory>\assets\logs\template\stylesheets\components.css
  • <Current directory>\assets\logs\template\stylesheets\custom.css
  • <Current directory>\assets\logs\template\stylesheets\font-awesome.min.css
  • <Current directory>\assets\logs\template\javascripts\jquery-migrate-1.2.1.min.js
  • <Current directory>\assets\logs\template\javascripts\jquery-1.11.0.min.js
  • <Current directory>\assets\logs\template\javascripts\excanvas.min.js
  • <Current directory>\assets\logs\template\javascripts\bootstrap.min.js
  • <Current directory>\assets\logs\template\javascripts\bootstrap-switch.min.js
  • <Current directory>\assets\logs\template\javascripts\bootstrap-hover-dropdown.min.js
  • <Current directory>\assets\logs\template\img\syncfusion-icons.png
  • <Current directory>\assets\logs\template\img\syncfusion-icons-white.png
  • <Current directory>\assets\logs\template\stylesheets\layout.css
  • <Current directory>\assets\logs\template\img\sidebar_toggler_icon_light.png
  • <Current directory>\assets\logs\template\img\sidebar_toggler_icon_grey.png
  • <Current directory>\assets\logs\template\img\sidebar_toggler_icon_default.png
  • <Current directory>\assets\logs\template\img\sidebar_toggler_icon_darkblue.png
  • <Current directory>\assets\logs\template\img\sidebar_toggler_icon_blue.png
  • <Current directory>\assets\logs\template\img\sidebar_inline_toggler_icon_light2.jpg
  • <Current directory>\assets\logs\template\img\sidebar_inline_toggler_icon_light.jpg
  • <Current directory>\assets\logs\template\img\sidebar_inline_toggler_icon_default.jpg
  • <Current directory>\assets\3rd party tools\ketarin\rt_apps.db
  • <Current directory>\assets\3rd party tools\ketarin\org.mentalis.security.dll
  • <Current directory>\assets\3rd party tools\ketarin\networking utilities\networkinterfacesview.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\secondlife_viewer.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\windows_media_player.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\windows_explorer.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\windows_defender.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\winamp.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\warzone2100.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\vuze.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\vlc.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\vim.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\tortoisesvn.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\thunderbird.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\teamviewer.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\skype.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\silverlight.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\xchat.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\winzip.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\wordpad.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\safari.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\realplayer.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\pidgin.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\paint.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\opera.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\octave.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\miro.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\microsoft_office.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\liferea.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\libreoffice.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\java.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\internet_explorer.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\hippo_opensim_viewer.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\screenlets.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\yahoo_messenger.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\et\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\bg\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\en_au\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\da\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\da\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\de\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\de\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\el\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\el\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\en_gb\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\google_chrome.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\en_gb\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\eo\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\eo\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\es\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\es\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\et\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\cs\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\cs\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ca\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ca\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\bs\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\bs\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\bn\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\bn\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\seamonkey.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\bg\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\be\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\be\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ast\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ast\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ar\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ar\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\google_toolbar.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\google_earth.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\gimp.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libgtk-win32-2.0-0.dll
  • <Current directory>\msinet.ocx
  • <Current directory>\assets\3rd party tools\bleachbit-portable\gtk._gtk.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\gobject._gobject.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\etc\gtk-2.0\im-multipress.conf
  • <Current directory>\assets\3rd party tools\bleachbit-portable\etc\gtk-2.0\gtkrc
  • <Current directory>\assets\3rd party tools\bleachbit-portable\etc\gtk-2.0\gdk-pixbuf.loaders
  • <Current directory>\assets\3rd party tools\bleachbit-portable\cairo._cairo.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\bz2.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\bleachbit_console.exe
  • <Current directory>\assets\3rd party tools\bleachbit-portable\bleachbit.ini
  • <Current directory>\assets\3rd party tools\bleachbit-portable\bleachbit.exe
  • <Current directory>\assets\3rd party tools\bleachbit-portable\atk.pyd
  • <Current directory>\assets.zip
  • <Current directory>\7z.exe
  • %WINDIR%\syswow64\msinet.ocx
  • %WINDIR%\syswow64\mswinsck.ocx
  • <Current directory>\mscomct2.ocx
  • <Current directory>\mswinsck.ocx
  • %WINDIR%\syswow64\mscomm32.ocx
  • <Current directory>\mscomm32.ocx
  • %WINDIR%\syswow64\mscomctl.ocx
  • <Current directory>\mscomctl.ocx
  • %WINDIR%\syswow64\mscomct2.ocx
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\eu\lc_messages\bleachbit.mo
  • %WINDIR%\syswow64\comdlg32.ocx
  • <Current directory>\comdlg32.ocx
  • %WINDIR%\syswow64\comctl32.ocx
  • <Current directory>\comctl32.ocx
  • %WINDIR%\syswow64\comct332.ocx
  • <Current directory>\comct332.ocx
  • %WINDIR%\syswow64\comct232.ocx
  • <Current directory>\assets\3rd party tools\bleachbit-portable\lib\gtk-2.0\2.10.0\engines\libwimp.dll
  • <Current directory>\assets\logs\template.zip
  • <Current directory>\assets\3rd party tools\bleachbit-portable\lib\gtk-2.0\modules\libgail.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\library.zip
  • <Current directory>\assets\3rd party tools\bleachbit-portable\servicemanager.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\perfmon.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\pyexpat.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\python25.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\pythoncom25.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\pywintypes25.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\select.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\bleachbit.png
  • <Current directory>\assets\3rd party tools\bleachbit-portable\intl.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\adobe_reader.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\amule.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\chromium.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\deepscan.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\filezilla.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\flash.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\pangocairo.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\pango.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libpng14-14.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libpng12-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libpangowin32-1.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libpangocairo-1.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libpango-1.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libgthread-2.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libcairo-2.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libatk-1.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libgmodule-2.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libglib-2.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libgio-2.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libgdk_pixbuf-2.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libgdk-win32-2.0-0.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\msvcr71.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\libgobject-2.0-0.dll
  • <Current directory>\assets\techwaru_updater.exe
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\eu\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\hu\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32gui.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\unicodedata.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\w9xpopen.exe
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32api.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32com.shell.shell.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32evtlog.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32file.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32pipe.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\_socket.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32process.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32service.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32ui.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\win32wnet.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\zlib1.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\cleaners\winrar.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\_ctypes.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\sqlite3.dll
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\zh_tw\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\zh_tw\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\zh_cn\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\zh_cn\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\vi\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\vi\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\uz\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\uz\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\uk\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\uk\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ug\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\tr\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\tr\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\_hashlib.pyd
  • <Current directory>\assets\3rd party tools\bleachbit-portable\_sqlite3.pyd
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\rkill.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\crystal disk info.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\junkware removal tool.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\adw cleaner.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\combofix.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\gmer.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hijack this.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hitmanpro x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hitmanpro.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\kaspersky tdsskiller.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\_win32sysloader.pyd
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\malwarebytes.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mbrcheck.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mcafee stinger x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mcafee stinger.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\ntfs junctions.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\oldtimer listit.xml
  • <Current directory>\assets\3rd party tools\ketarin\ketarin.exe.config
  • <Current directory>\assets\3rd party tools\ketarin\ketarin.exe
  • <Current directory>\assets\3rd party tools\ketarin\installation\patchmypc.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\whatishang.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\video memory stress test.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\linx.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\hdd scan.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\disksmartview.xml
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\th\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\bluescreenview.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\battery info view.xml
  • <Current directory>\assets\3rd party tools\ketarin\diffiehellman.dll
  • <Current directory>\assets\3rd party tools\ketarin\backup\piriform recuva.xml
  • <Current directory>\assets\3rd party tools\ketarin\backup\piriform recuva x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\application cleanup\avast browser cleanup tool.xml
  • <Current directory>\assets\3rd party tools\ketarin\7z.exe
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\th\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\themes\ms-windows\gtk-2.0\gtkrc
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\te\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\te\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\fa\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\hy\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ky\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ku\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ku\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ko\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ko\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ja\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ja\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\it\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\it\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\id\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\id\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ia\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ia\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\hy\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\hu\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\hr\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\hr\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\hi\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\hi\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\he\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\gl\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\lv\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\lt\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\fr\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\fr\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\fo\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\fi\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\fi\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\he\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\gl\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\fa\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ms\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\pt\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ta\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\sk\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ru\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ru\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\se\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\si\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\si\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\sk\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\sl\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\lt\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\sl\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\sr\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\sr\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\sv\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\sv\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ta\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ro\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\pt\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\pl\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\pl\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\nn\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\nl\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\lv\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\pt_br\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\nl\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\nb\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\nb\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\my\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ms\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\pt_br\lc_messages\gtk20.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\ro\lc_messages\bleachbit.mo
  • <Current directory>\assets\3rd party tools\bleachbit-portable\share\locale\nds\lc_messages\bleachbit.mo
  • <Current directory>\8675309.tmp
Deletes the following files
  • <Current directory>\7z.exe
  • <Current directory>\assets\3rd party tools\ketarin\system information\currports.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\devmanview x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\devmanview.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\get product keys.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installedcodec x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installedcodec.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installeddriverslist x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installeddriverslist.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\mail passview.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\webbrowserpassview.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\whatinstartup x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\whatinstartup.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\browsing history view.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\currports x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\wincrashreport x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system tuneup\piriform defraggler x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system tuneup\piriform defraggler.xml
  • <Current directory>\assets\3rd party tools\ketarin\7z.exe
  • <Current directory>\assets\3rd party tools\ketarin\diffiehellman.dll
  • <Current directory>\assets\3rd party tools\ketarin\ketarin.exe
  • <Current directory>\assets\3rd party tools\ketarin\ketarin.exe.config
  • <Current directory>\assets\3rd party tools\ketarin\org.mentalis.security.dll
  • <Current directory>\assets\3rd party tools\ketarin\rt_apps.db
  • <Current directory>\assets\3rd party tools\ketarin\rt_apps.xml
  • <Current directory>\assets\3rd party tools\ketarin\scilexer.dll
  • <Current directory>\assets\3rd party tools\ketarin\system.data.sqlite.dll
  • <Current directory>\assets\3rd party tools\ketarin\tamir.sharpssh.dll
  • <Current directory>\assets\3rd party tools\ketarin\system information\wincrashreport.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\winupdateslist.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\browsing history view x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system cleanup\piriform ccleaner.xml
  • <Current directory>\assets\3rd party tools\ketarin\system cleanup\piriform ccleaner x64.xml
  • <Current directory>\assets\3rd party tools\ketarin.zip
  • <Current directory>\assets\3rd party tools\ketarin\backup\piriform recuva x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\backup\piriform recuva.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\battery info view.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\bluescreenview.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\crystal disk info.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\disksmartview.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\hdd scan.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\linx.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\video memory stress test.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\whatishang.xml
  • <Current directory>\assets\3rd party tools\ketarin\installation\patchmypc.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\adw cleaner.xml
  • <Current directory>\assets.zip
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\combofix.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hijack this.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hitmanpro x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hitmanpro.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\junkware removal tool.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\kaspersky tdsskiller.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\malwarebytes.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mbrcheck.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mcafee stinger x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mcafee stinger.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\ntfs junctions.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\oldtimer listit.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\rkill.xml
  • <Current directory>\assets\3rd party tools\ketarin\networking utilities\networkinterfacesview.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\gmer.xml
  • <Current directory>\assets\3rd party tools\ketarin\application cleanup\avast browser cleanup tool.xml
  • <Current directory>\8675309.tmp
Substitutes the following files
  • <Current directory>\assets\3rd party tools\ketarin.zip
  • <Current directory>\assets\3rd party tools\ketarin\system information\currports.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\devmanview x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\devmanview.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\get product keys.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installedcodec x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installedcodec.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installeddriverslist x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\installeddriverslist.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\mail passview.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\webbrowserpassview.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\whatinstartup x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\browsing history view.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\currports x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\whatinstartup.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\winupdateslist.xml
  • <Current directory>\assets\3rd party tools\ketarin\system tuneup\piriform defraggler x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system tuneup\piriform defraggler.xml
  • <Current directory>\assets\3rd party tools\ketarin\diffiehellman.dll
  • <Current directory>\assets\3rd party tools\ketarin\ketarin.exe
  • <Current directory>\assets\3rd party tools\ketarin\ketarin.exe.config
  • <Current directory>\assets\3rd party tools\ketarin\org.mentalis.security.dll
  • <Current directory>\assets\3rd party tools\ketarin\rt_apps.db
  • <Current directory>\assets\3rd party tools\ketarin\rt_apps.xml
  • <Current directory>\assets\3rd party tools\ketarin\scilexer.dll
  • <Current directory>\assets\3rd party tools\ketarin\system.data.sqlite.dll
  • <Current directory>\assets\3rd party tools\ketarin\system information\wincrashreport x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\wincrashreport.xml
  • <Current directory>\assets\3rd party tools\ketarin\system information\browsing history view x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\system cleanup\piriform ccleaner.xml
  • <Current directory>\assets\3rd party tools\ketarin\system cleanup\piriform ccleaner x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\backup\piriform recuva.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\battery info view.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\bluescreenview.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\crystal disk info.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\disksmartview.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\hdd scan.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\linx.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\video memory stress test.xml
  • <Current directory>\assets\3rd party tools\ketarin\hardware diagnostics\whatishang.xml
  • <Current directory>\assets\3rd party tools\ketarin\installation\patchmypc.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\adw cleaner.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\combofix.xml
  • <Current directory>\assets\3rd party tools\ketarin\backup\piriform recuva x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\gmer.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hitmanpro x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hitmanpro.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\junkware removal tool.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\kaspersky tdsskiller.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\malwarebytes.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mbrcheck.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mcafee stinger x64.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\mcafee stinger.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\ntfs junctions.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\oldtimer listit.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\rkill.xml
  • <Current directory>\assets\3rd party tools\ketarin\networking utilities\networkinterfacesview.xml
  • <Current directory>\assets\3rd party tools\ketarin\malware removal\hijack this.xml
  • <Current directory>\assets\3rd party tools\ketarin\tamir.sharpssh.dll
  • <Current directory>\assets\3rd party tools\ketarin\application cleanup\avast browser cleanup tool.xml
Network activity
Connects to
  • 'google.com':80
TCP
HTTP GET requests
  • http://c0##################-a2065d3226b6f083a3fe1d53a8aa037e.r38.cf1.rackcdn.com/Assets.zip
  • http://c0##################-a2065d3226b6f083a3fe1d53a8aa037e.r38.cf1.rackcdn.com/Ketarin_Folder.zip
  • http://c0##################-a2065d3226b6f083a3fe1d53a8aa037e.r38.cf1.rackcdn.com/TechWARU_Updater.exe
  • http://c0##################-a2065d3226b6f083a3fe1d53a8aa037e.r38.cf1.rackcdn.com/Scripts.zip
  • http://c0##################-a2065d3226b6f083a3fe1d53a8aa037e.r38.cf1.rackcdn.com/Template.zip
  • http://c0##################-a2065d3226b6f083a3fe1d53a8aa037e.r38.cf1.rackcdn.com/RT_presets_1_5_2.ini
  • http://c0##################-a2065d3226b6f083a3fe1d53a8aa037e.r38.cf1.rackcdn.com/dot_net_req.ini
UDP
  • DNS ASK google.com
  • DNS ASK c0##################-a2065d3226b6f083a3fe1d53a8aa037e.r38.cf1.rackcdn.com
Miscellaneous
Creates and executes the following
  • '<Current directory>\assets\3rd party tools\ketarin\7z.exe' x "<Current directory>\Assets\3rd Party Tools\Ketarin.zip" -o"<Current directory>\Assets\3rd Party Tools\Ketarin" -y
  • '<Current directory>\assets\3rd party tools\ketarin\7z.exe' t "<Current directory>\Assets\3rd Party Tools\Ketarin.zip"
  • '<Current directory>\7z.exe' x "<Current directory>\Assets.zip" -o"<Current directory>" -y
  • '<Current directory>\assets\scripts\bcdedit32.exe' /deletevalue {current} safeboot
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\COMCT232.OCX" /s' (with hidden window)
  • '<Current directory>\assets\3rd party tools\ketarin\7z.exe' x "<Current directory>\Assets\3rd Party Tools\Ketarin.zip" -o"<Current directory>\Assets\3rd Party Tools\Ketarin" -y' (with hidden window)
  • '<Current directory>\assets\3rd party tools\ketarin\7z.exe' t "<Current directory>\Assets\3rd Party Tools\Ketarin.zip"' (with hidden window)
  • '<Current directory>\7z.exe' x "<Current directory>\Assets.zip" -o"<Current directory>" -y' (with hidden window)
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSWINSCK.OCX" /s' (with hidden window)
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSCOMCTL.OCX" /s' (with hidden window)
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSCOMM32.OCX" /s' (with hidden window)
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSCOMCT2.OCX" /s' (with hidden window)
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\COMDLG32.OCX" /s' (with hidden window)
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\COMCTL32.OCX" /s' (with hidden window)
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\COMCT332.OCX" /s' (with hidden window)
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSINET.OCX" /s' (with hidden window)
  • '<Current directory>\assets\scripts\bcdedit32.exe' /deletevalue {current} safeboot' (with hidden window)
Executes the following
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\COMCT232.OCX" /s
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\COMCT332.OCX" /s
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\COMCTL32.OCX" /s
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\COMDLG32.OCX" /s
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSCOMCT2.OCX" /s
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSCOMCTL.OCX" /s
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSCOMM32.OCX" /s
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSWINSCK.OCX" /s
  • '%WINDIR%\syswow64\regsvr32.exe' "%WINDIR%\SYSWOW64\MSINET.OCX" /s

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android