Analysis
-
max time kernel
89s -
max time network
36s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 12:46
Behavioral task
behavioral1
Sample
bitcheats_cleaner.exe
Resource
win7-20240221-en
General
-
Target
bitcheats_cleaner.exe
-
Size
2.5MB
-
MD5
24999353450c234c36cc2e0a74f75051
-
SHA1
3b716b36775bc53bd67c0786ed040628cbc926f9
-
SHA256
363f8d66fa5bd0c72eb46fd821a2eb09e723e2f42e6bb293212f07ab0c2b5ddb
-
SHA512
1c0dfac601da714ffc0a3dcd5f6b1fbe95c7238177cbf3ab9551b833f5a062c717ab69ff206a7c9dee677b52cec1cb81efd4e36dc6af5fc195ab07e4e453d143
-
SSDEEP
49152:rabHjq7IZiuzkKECE95eHmRSW97qWOEhSI7o1U26TYtkY+toY:rabOUiujECE95eGRB718zgY4
Malware Config
Signatures
-
Identifies VirtualBox via ACPI registry values (likely anti-VM) 2 TTPs 1 IoCs
Processes:
bitcheats_cleaner.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\ACPI\DSDT\VBOX__ bitcheats_cleaner.exe -
Modifies Windows Firewall 2 TTPs 1 IoCs
Processes:
netsh.exepid process 1548 netsh.exe -
Checks BIOS information in registry 2 TTPs 2 IoCs
BIOS information is often read in order to detect sandboxing environments.
Processes:
bitcheats_cleaner.exedescription ioc process Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion bitcheats_cleaner.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion bitcheats_cleaner.exe -
Reads user/profile data of web browsers 2 TTPs
Infostealers often target stored browser data, which can include saved credentials etc.
-
Processes:
resource yara_rule behavioral1/memory/2240-0-0x000000013F5B0000-0x000000013FCD4000-memory.dmp themida behavioral1/memory/2240-2-0x000000013F5B0000-0x000000013FCD4000-memory.dmp themida behavioral1/memory/2240-4-0x000000013F5B0000-0x000000013FCD4000-memory.dmp themida behavioral1/memory/2240-3-0x000000013F5B0000-0x000000013FCD4000-memory.dmp themida behavioral1/memory/2240-6-0x000000013F5B0000-0x000000013FCD4000-memory.dmp themida behavioral1/memory/2240-5-0x000000013F5B0000-0x000000013FCD4000-memory.dmp themida behavioral1/memory/2240-1059-0x000000013F5B0000-0x000000013FCD4000-memory.dmp themida behavioral1/memory/2240-1074-0x000000013F5B0000-0x000000013FCD4000-memory.dmp themida -
Processes:
bitcheats_cleaner.exedescription ioc process Key value queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA bitcheats_cleaner.exe -
Suspicious use of NtSetInformationThreadHideFromDebugger 1 IoCs
Processes:
bitcheats_cleaner.exepid process 2240 bitcheats_cleaner.exe -
Drops file in Windows directory 64 IoCs
Processes:
cmd.execmd.execmd.execmd.exedescription ioc process File opened for modification C:\Windows\INF\ESENT\0410\esentprf.ini cmd.exe File opened for modification C:\Windows\INF\netrass.inf cmd.exe File opened for modification C:\Windows\INF\UGTHRSVC\0C0A\gthrctr.ini cmd.exe File opened for modification C:\Windows\INF\NETDAT~2\_dataperfcounters_shared12_neutral.h File opened for modification C:\Windows\INF\WSEARC~1\0411\idxcntrs.ini File opened for modification C:\Windows\INF\BITS\0411\bitsctrs.ini cmd.exe File opened for modification C:\Windows\INF\SERVIC~3.0\0411\_ServiceModelOperationPerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\WINDOW~1.0\0411\PerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\MSDTC\0409\msdtcprf.ini cmd.exe File opened for modification C:\Windows\INF\NETDAT~2\_dataperfcounters_shared12_neutral.ini cmd.exe File opened for modification C:\Windows\INF\TERMSE~1\040C\tslabels.ini cmd.exe File opened for modification C:\Windows\INF\rdyboost\0411\ReadyBoostPerfCounters.ini cmd.exe File opened for modification C:\Windows\INF\en-US\netavpnt.inf_loc File opened for modification C:\Windows\INF\REMOTE~1\rasctrnm.h File opened for modification C:\Windows\INF\TAPISRV\0407\tapiperf.ini cmd.exe File opened for modification C:\Windows\INF\usbhub\0C0A\usbperf.ini cmd.exe File opened for modification C:\Windows\INF\NETCLR~1\0000\_DataPerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\SERVIC~1.0\0407\_ServiceModelEndpointPerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\NETCLR~1\0C0A\_DataPerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\es-ES\netavpna.inf_loc cmd.exe File opened for modification C:\Windows\INF\rdyboost\0410\ReadyBoostPerfCounters.ini cmd.exe File opened for modification C:\Windows\INF\usbhub\usbperfsym.h cmd.exe File opened for modification C:\Windows\INF\NETCLR~1\0000\_DataPerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\NETDAT~1\0000\_DataOracleClientPerfCounters_shared12_neutral_D.ini cmd.exe File opened for modification C:\Windows\INF\netnb.inf cmd.exe File opened for modification C:\Windows\INF\WSEARC~1\0C0A\idxcntrs.ini cmd.exe File opened for modification C:\Windows\INF\MSDTCB~1.0\040C\_TransactionBridgePerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\NETDAT~2\0410\_dataperfcounters_shared12_neutral_D.ini cmd.exe File opened for modification C:\Windows\INF\TAPISRV\0410\tapiperf.ini File opened for modification C:\Windows\INF\NETCLR~2\0C0A\_Networkingperfcounters_D.ini cmd.exe File opened for modification C:\Windows\INF\netavpna.inf cmd.exe File opened for modification C:\Windows\INF\rspndr.inf cmd.exe File opened for modification C:\Windows\INF\MSDTC\0409\msdtcprf.ini cmd.exe File opened for modification C:\Windows\INF\NETDAT~1\0407\_DataOracleClientPerfCounters_shared12_neutral_D.ini cmd.exe File opened for modification C:\Windows\INF\MSDTC\0C0A\msdtcprf.ini cmd.exe File opened for modification C:\Windows\INF\REMOTE~1\rasctrnm.h cmd.exe File opened for modification C:\Windows\INF\NETCLR~1\0407\_DataPerfCounters_D.ini File opened for modification C:\Windows\INF\SERVIC~1.0\040C\_ServiceModelEndpointPerfCounters_D.ini File opened for modification C:\Windows\INF\TAPISRV\0409\tapiperf.ini File opened for modification C:\Windows\INF\rdyboost\0407\ReadyBoostPerfCounters.ini cmd.exe File opened for modification C:\Windows\INF\NETCLR~1\0410\_DataPerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\NETDAT~2\0407\_dataperfcounters_shared12_neutral_D.ini cmd.exe File opened for modification C:\Windows\INF\MSDTC\0411\msdtcprf.ini cmd.exe File opened for modification C:\Windows\INF\UGTHRSVC\040C\gthrctr.ini cmd.exe File opened for modification C:\Windows\INF\MSDTCB~1.0\0C0A\_TransactionBridgePerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\rdyboost\0411\ReadyBoostPerfCounters.ini cmd.exe File opened for modification C:\Windows\INF\SERVIC~1.0\0407\_ServiceModelEndpointPerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\netmscli.inf cmd.exe File opened for modification C:\Windows\INF\rdyboost\0407\ReadyBoostPerfCounters.ini cmd.exe File opened for modification C:\Windows\INF\NETCLR~1\_DataPerfCounters.ini File opened for modification C:\Windows\INF\NETFRA~1\0000\corperfmonsymbols_D.ini File opened for modification C:\Windows\INF\UGTHRSVC\0411\gthrctr.ini cmd.exe File opened for modification C:\Windows\INF\SERVIC~2.0\0000\_ServiceModelServicePerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\SERVIC~2.0\0410\_ServiceModelServicePerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\usbhub\0411\usbperf.ini cmd.exe File opened for modification C:\Windows\INF\TERMSE~1\0409\tslabels.ini cmd.exe File opened for modification C:\Windows\INF\TAPISRV\0C0A\tapiperf.ini File opened for modification C:\Windows\INF\netpgm.inf cmd.exe File opened for modification C:\Windows\INF\netbrdgm.inf File opened for modification C:\Windows\INF\UGATHE~1\040C\gsrvctr.ini File opened for modification C:\Windows\INF\UGATHE~1\0000\gsrvctr.ini cmd.exe File opened for modification C:\Windows\INF\SERVIC~2.0\0409\_ServiceModelServicePerfCounters_D.ini cmd.exe File opened for modification C:\Windows\INF\MSDTC\0000\msdtcprf.ini cmd.exe File opened for modification C:\Windows\INF\netnwifi.inf cmd.exe -
Launches sc.exe 2 IoCs
Sc.exe is a Windows utlilty to control services on the system.
Processes:
pid process 384 2572 -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Event Triggered Execution: Netsh Helper DLL 1 TTPs 21 IoCs
Netsh.exe (also referred to as Netshell) is a command-line scripting utility used to interact with the network configuration of a system.
Processes:
netsh.exenetsh.exenetsh.exenetsh.exenetsh.exenetsh.exenetsh.exedescription ioc process Key opened \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key value enumerated \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key value enumerated \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key opened \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key value enumerated \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key value enumerated \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key opened \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key opened \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key opened \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key opened \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key value enumerated \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key opened \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key value enumerated \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe Key value enumerated \REGISTRY\MACHINE\SOFTWARE\Microsoft\NetSh netsh.exe -
Gathers network information 2 TTPs 4 IoCs
Uses commandline utility to view network configuration.
Processes:
ipconfig.exeipconfig.exeipconfig.exepid process 1696 ipconfig.exe 2032 ipconfig.exe 1036 ipconfig.exe 2444 -
Processes:
iexplore.exeIEXPLORE.EXEdescription ioc process Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\GPU iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Recovery\PendingRecovery iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\BrowserEmulation\LowMic iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\IntelliForms iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\SearchScopes iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage\LastProcessed = 10890eacebcada01 iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\IETld\LowMic iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\LowRegistry\DontShowMeThisDialogAgain iexplore.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\FullScreen = "no" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Recovery\PendingRecovery\AdminActive = "1" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\MINIE\TabBandWidth = "500" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NTPFirstRun = "1" iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Recovery\AdminActive iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\Window_Placement = 2c0000000200000003000000ffffffffffffffffffffffffffffffff2400000024000000aa04000089020000 iexplore.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch\Version = "WS not running" IEXPLORE.EXE Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Recovery\AdminActive\{D5A92371-36DE-11EF-AB41-FA5112F1BCBF} = "0" iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main IEXPLORE.EXE Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch IEXPLORE.EXE Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\MINIE iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage\DecayDateQueue = 01000000d08c9ddf0115d1118c7a00c04fc297eb010000000e412f987cacf24fa6ced2e15bdf3df8000000000200000000001066000000010000200000006deb3dcb6f5ac8c264cbea714fa9456f1f7f34fd099da5b7702854ce7ee1f759000000000e8000000002000020000000e65a208fdd5bba56294e6a069d9a53c1ab46ef6c473f76e847415ab6d7c622f820000000bc05812abfdaa7cba75f78c7948ca328a6d93a6e040d386e30baef3ba3e88653400000009afd3938b4964d45d7d2fbe3013695f2d5dedafd7238d5e9d178340d698fb2f098dd49782ac73becadc4359a520a8b84ff608a42a08e704f39d59851d49bc3cf iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\PageSetup iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Toolbar iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\CompatibilityFlags = "0" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\SearchScopes\DownloadRetries = "3" iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage\MFV = 01000000d08c9ddf0115d1118c7a00c04fc297eb010000000e412f987cacf24fa6ced2e15bdf3df8000000000200000000001066000000010000200000005957e21be5b097404ce9dca356ab4eb8a8ca76030f01869df418a477f3b4b311000000000e8000000002000020000000fd243bd3df75488d3a6f345842d82d5538f5527c3a79d86c5ae0c1b35c5371e4900000008c506a0db8eee8386d9a404f1db54bc89577c685490d1f4ffeb27147d0cf7bfa95ee8981a792e6b117675b4080760af21857759cf6bcfa1d18129f22e065326b5c68bacf2d66745ca3cad8a3291d77ee7971c2fe09623a80e48db284e3ac746b1e726377023b4f89462a38b396f2bd1c71ae82e90a60b4f1bb344c6affe456cac95de7938e13d8cffbe28f5a4af0409d400000006bb06f92684499974f0373c6d9fe1d7498c167d76f87a5d71578d4d0013fc8f469787286a97da0cc4e06f853f387adf3f53dd2a8a0f2b240a9e73e7bf908fd73 iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\InternetRegistry iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\LowRegistry iexplore.exe Key created \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Zoom iexplore.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch\Version = "WS not running" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Internet Explorer\Recovery\PendingRecovery\AdminActive = "0" iexplore.exe -
Modifies registry key 1 TTPs 6 IoCs
Processes:
reg.exereg.exereg.exereg.exereg.exereg.exepid process 936 reg.exe 2252 reg.exe 1580 reg.exe 1324 reg.exe 2236 reg.exe 2172 reg.exe -
Runs net.exe
-
Suspicious behavior: EnumeratesProcesses 46 IoCs
Processes:
bitcheats_cleaner.exepid process 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe 2240 bitcheats_cleaner.exe -
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
bitcheats_cleaner.exepid process 2240 bitcheats_cleaner.exe -
Suspicious use of FindShellTrayWindow 1 IoCs
Processes:
iexplore.exepid process 3024 iexplore.exe -
Suspicious use of SetWindowsHookEx 6 IoCs
Processes:
iexplore.exeIEXPLORE.EXEpid process 3024 iexplore.exe 3024 iexplore.exe 2548 IEXPLORE.EXE 2548 IEXPLORE.EXE 2548 IEXPLORE.EXE 2548 IEXPLORE.EXE -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
bitcheats_cleaner.exeiexplore.exedescription pid process target process PID 2240 wrote to memory of 3024 2240 bitcheats_cleaner.exe iexplore.exe PID 2240 wrote to memory of 3024 2240 bitcheats_cleaner.exe iexplore.exe PID 2240 wrote to memory of 3024 2240 bitcheats_cleaner.exe iexplore.exe PID 2240 wrote to memory of 2520 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2520 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2520 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2620 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2620 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2620 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2800 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2800 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2800 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2028 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2028 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2028 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2624 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2624 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2624 2240 bitcheats_cleaner.exe cmd.exe PID 3024 wrote to memory of 2548 3024 iexplore.exe IEXPLORE.EXE PID 3024 wrote to memory of 2548 3024 iexplore.exe IEXPLORE.EXE PID 3024 wrote to memory of 2548 3024 iexplore.exe IEXPLORE.EXE PID 3024 wrote to memory of 2548 3024 iexplore.exe IEXPLORE.EXE PID 2240 wrote to memory of 2372 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2372 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2372 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2432 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2432 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2432 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2444 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2444 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2444 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2080 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2080 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2080 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2688 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2688 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2688 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2728 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2728 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2728 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2768 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2768 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2768 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2672 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2672 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2672 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2156 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2156 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2156 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1616 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1616 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1616 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1864 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1864 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1864 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 820 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 820 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 820 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1464 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1464 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 1464 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2152 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2152 2240 bitcheats_cleaner.exe cmd.exe PID 2240 wrote to memory of 2152 2240 bitcheats_cleaner.exe cmd.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\bitcheats_cleaner.exe"C:\Users\Admin\AppData\Local\Temp\bitcheats_cleaner.exe"1⤵
- Identifies VirtualBox via ACPI registry values (likely anti-VM)
- Checks BIOS information in registry
- Checks whether UAC is enabled
- Suspicious use of NtSetInformationThreadHideFromDebugger
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of WriteProcessMemory
-
C:\Program Files\Internet Explorer\iexplore.exe"C:\Program Files\Internet Explorer\iexplore.exe" http://bitcheats.net/2⤵
- Modifies Internet Explorer settings
- Suspicious use of FindShellTrayWindow
- Suspicious use of SetWindowsHookEx
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:3024 CREDAT:275457 /prefetch:23⤵
- Modifies Internet Explorer settings
- Suspicious use of SetWindowsHookEx
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\History\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\Temp\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Temp\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Prefetch\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Temp\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Program Files (x86)\Common Files\BattlEye\BEService.exe2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Program Files (x86)\Common Files\BattlEye\BEService_fn.exe2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\AMD\CN\GameReport\FortniteClient-Win64-Shipping.exe\gpa.bin2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\AMD\DxCache\92b1da15789e5451b49097cdafa85ec0f45214d6b0df9e8d.bin2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\AMD\DxCache\92b1da15789e5451e900a9bc20b57cd2f45214d6b0df9e8d.bin2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\AMD\cl.cache\x64\Version 2.1 AMD-APP (3380.6).Ellesmere.cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\D3DSCache\e4548a4577c56a84\52264C4C-172F-41B9-91B8-7F0C3B1E9021_VEN_1002&DEV_67DF&SUBSYS_C580&REV_E7.idx2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\D3DSCache\e4548a4577c56a84\52264C4C-172F-41B9-91B8-7F0C3B1E9021_VEN_1002&DEV_67DF&SUBSYS_C580&REV_E7.lock2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\D3DSCache\e4548a4577c56a84\52264C4C-172F-41B9-91B8-7F0C3B1E9021_VEN_1002&DEV_67DF&SUBSYS_C580&REV_E7.val2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Cache\f_00010e2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\IndexedDB\https_launcher.store.epicgames.com_0.indexeddb.leveldb\000036.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\IndexedDB\https_launcher.store.epicgames.com_0.indexeddb.leveldb\000038.ldb2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Session Storage\LOG.old2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\NVIDIA Corporation\GfeSDK\FortniteClient-Win64-Shipping_12856.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\Temp\171cac9.tmp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\5.0\Saved\Config\WindowsClient\Manifest.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\5.0\Saved\Config\WindowsEditor\Manifest.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\Common\Analytics\8E1D46DBC38F4A789939D781E1B915202⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\CrashReportClient\Saved\Config\WindowsEditor\Engine.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\CrashReportClient\Saved\Logs\CrashReportClient.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\e4988bfc0f4c4c6596237473da200329\ClientSettings.Sav2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config\ClientSettings.Sav2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config\CrashReportClient\UECC-Windows-F4478CA54827E7195F8F7BBAB4BC51F8\CrashReportClient.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\GameUserSettings.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\LMS\Manifest.sav2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Logs\FortniteGame.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Logs\FortniteLauncher.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\BackgroundHttp\URLMap\TempFileURLMappings.urlmap2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\DownloadCache.json2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\08B44835D9E8B3BEDFB49C3650F634FF11B74454.jpeg2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\1773DBBF630BAD44B34734176DD5D03F2E6F4D78.png2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\86F7F05520A581636CEBF3AD1BD5C4383AE77494.png2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\88271B0993D67835C1C89BF7D1B9A1E5ED989F06.jpg2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\B666DE51F8E930A8A99CB03C4454727680759203.jpg2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\B6D962B44AD39D2129B4A96DB8C24DFF6A98D213.jpeg2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\D04ECBD1A835D9714A6F6D279077C15B2FCEDBEF.jpeg2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\EA7CDAA7AF5B1335517D581803C34BB2394218D1.png2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E2\ED43DE88DA78F8F4D6645415A7FC446EAE3BD5B8.jpeg2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\0bef34491af34fc584b687e433656e902⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\0ef043433c754e0588525283cacda0ab2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\1492c7f2588940848a4920cdff4e69d72⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\20334c6a270641c0835bed15d9cde4ea2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\3460cbe1c57d4a838ace32951a4d71712⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\6dea1559a81c4b18864782deeba57a832⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\7e2a66ce68554814b1bd0aa14351cd712⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\8b616e78d2674a3e92157d40df1d4cda2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\a22d837b6a2b46349421259c0a5411bf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\b4b8bebcb5e84d86b11ebb7bb989d88f2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\b6c60402a72e4081a6a47c641371c19f2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\b800b911053c4906a5bd399f46ae00552⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\be84cc30e34142d293ed27d15522b62c2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\c52c1f9246eb48ce9dade87be5a66f292⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\c7dee411e20a44ab930f841e8d206b1b2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS\f2f660d7855c45fdbb7922edda562a602⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\ManifestArchive.journal2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Startup\BuildIdentity.txt2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\ManifestCache\VkeX0y1esOdbd-ggEkmjBETCpYALDw\Full.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\ManifestCache\VkeX0y1esOdbd-ggEkmjBETCpYALDw.manifest2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Prefetch\BESERVICE.EXE-622E150D.pf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Prefetch\CRASHREPORTCLIENT.EXE-C297728D.pf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Prefetch\EASYANTICHEAT_SETUP.EXE-CF3441CE.pf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Prefetch\FORTNITECLIENT-WIN64-SHIPPING-42C11B98.pf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Prefetch\FORTNITECLIENT-WIN64-SHIPPING-5EAA410A.pf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Prefetch\FORTNITELAUNCHER.EXE-AF00A2B5.pf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\Prefetch\RUNDLL32.EXE-F264FACF.pf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Compat.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\EditorPerProjectUserSettings.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Game.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\GameUserSettings.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Hardware.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Input.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Lightmass.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Data\e4988bfc0f4c4c6596237473da200329.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\cef3.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\EpicGamesLauncher.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Cache\data_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Cache\data_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Cache\data_22⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Cache\data_32⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Code Cache\js\9f9fe5b8b6d30293_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Code Cache\js\e7a03ae0f25a578a_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Code Cache\js\index-dir\the-real-index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\IndexedDB\https_launcher.store.epicgames.com_0.indexeddb.leveldb\LOG2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\IndexedDB\https_launcher.store.epicgames.com_0.indexeddb.leveldb\LOG.old2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\IndexedDB\https_launcher.store.epicgames.com_0.indexeddb.leveldb\MANIFEST-0000012⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Local Storage\leveldb\000003.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Local Storage\leveldb\LOG2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\LOG2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Network Persistent State2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\QuotaManager2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\QuotaManager-journal2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Service Worker\Database\000003.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Service Worker\Database\LOG2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Session Storage\000003.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\Session Storage\LOG2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache_4430\TransportSecurity2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Program Files (x86)\Common Files\BattlEye2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\AMD\CN\GameReport2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\AMD\CN\GameReport\FortniteClient-Win64-Shipping.exe2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\AMD\cl.cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\AMD\cl.cache\x642⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\D3DSCache\e4548a4577c56a842⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\NVIDIA Corporation\GfeSDK2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\5.0\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\5.0\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\5.0\Saved\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\5.0\Saved\Config\WindowsClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\5.0\Saved\Config\WindowsEditor2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\Common2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\UnrealEngine\Common\Analytics2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\CrashReportClient\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\CrashReportClient\Saved\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\CrashReportClient\Saved\Config\WindowsEditor2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\CrashReportClient\Saved\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\e4988bfc0f4c4c6596237473da2003292⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config\CrashReportClient\UECC-Windows-F4478CA54827E7195F8F7BBAB4BC51F82⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config\WindowsClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Demos2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\LMS2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\BackgroundHttp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\BackgroundHttp\URLMap2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\Files\C28FF1DE0C661DAF01E118A30B3F21B897A7A6E22⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\EMS2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\CosmeticBundleSeparateCosmetics2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\FortniteBR2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\FortniteBROptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\FortniteCreative2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\FortniteCreativeOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\FrontEnd2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\FrontEndOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\KairosCapture2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\KairosCaptureOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.all2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.allOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.de2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.deOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.es-4192⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.es-419Optional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.es-ES2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.es-ESOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.fr2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.frOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.it2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.itOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.pl2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.plOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.ru2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.ruOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.zh-CN2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Lang.zh-CNOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\Startup2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\InstalledBundles\StartupOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\ManifestCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\ManifestCache\VkeX0y1esOdbd-ggEkmjBETCpYALDw2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\CosmeticBundleSeparateCosmetics2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\FortniteBR2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\FortniteBROptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\FortniteCreative2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\FortniteCreativeOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\FrontEnd2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\FrontEndOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\KairosCapture2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\KairosCaptureOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.all2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.allOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.de2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.deOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.es-4192⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.es-419Optional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.es-ES2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.es-ESOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.fr2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.frOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.it2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.itOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.pl2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.plOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.ru2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.ruOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.zh-CN2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\Lang.zh-CNOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\StagingBundles\StartupOptional2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c REG DELETE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BEService /f2⤵
-
C:\Windows\system32\reg.exeREG DELETE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BEService /f3⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c REG DELETE HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BEService /f2⤵
-
C:\Windows\system32\reg.exeREG DELETE HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BEService /f3⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c REG DELETE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EasyAntiCheat /f2⤵
-
C:\Windows\system32\reg.exeREG DELETE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EasyAntiCheat /f3⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c REG DELETE HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EasyAntiCheat /f2⤵
-
C:\Windows\system32\reg.exeREG DELETE HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EasyAntiCheat /f3⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.etl2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.dmp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.chk2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.bup2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.bac2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.bak2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\*.old2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Data\Staged\a1acda587b3e4c7b87df4eb11fece3c0.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Data\a1acda587b3e4c7b87df4eb11fece3c0.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000672⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\ProgramData\Intel\ShaderCache\EpicGamesLauncher_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\databases\Databases.db2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Local Storage\https_ssl.kaptcha.com_0.localstorage2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Local Storage\https_www.epicgames.com_0.localstorage2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\databases2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Local Storage2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\2cc80dabc69f58b6_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\4cb013792b196a35_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\f1cdccba37924bda_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\ba23d8ecda68de77_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\67a473248953641b_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\b6c28cea6ed9dfc1_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\013888a1cda32b90_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000012⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00004d2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00004e2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00004f2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000502⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000512⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000522⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000532⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\47343f26116f49d1a460ad740dc2bbbb\ClientSettings.Sav2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\Common Files\BattlEye2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\CommonFiles\BattlEye\BEDaisy.sys\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\Epic Games\Launcher\Engine\Programs\CrashReportClient\Config\DefaultEngine.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\Epic Games\Launcher\VaultCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\EpicGames\Launcher\Portal\Binaries\Win322⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\EpicGames\Launcher\Portal\Binaries\Win32\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)\Epic Games\Launcher\Engine\Config\Base.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)\Epic Games\Launcher\Engine\Config\BaseGame.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)\Epic Games\Launcher\Engine\Config\BaseInput.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)\Epic Games\Launcher\Engine\Config\Windows\BaseWindowsLightmass.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)\Epic Games\Launcher\Engine\Config\Windows\WindowsGame.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)\Epic Games\Launcher\Portal\Config\UserLightmass.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)Epic Games\Launcher\Engine\Config\BaseHardware.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)Epic Games\Launcher\Portal\Config\NotForLicensees\Windows\WindowsHardware.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files(x86)Epic Games\Launcher\Portal\Config\UserScalability.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite1\FortniteGame\PersistentDownloadDir\CMS2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite1\FortniteGame\PersistentDownloadDir\EMS2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\Engine\Config\NoRedist\Windows\ShippableWindowsGameUserSettings.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\Engine\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\Engine\Plugins\CurveEditorTools\AssetRegistry.bin2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\Engine\Plugins\Editor\CryptoKeys\AssetRegistry.bin2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\Engine\Plugins\Editor\CurveEditorTools\AssetRegistry.bin2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe.local2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\Shared Files2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\Shared Files:VersionCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\SharedFiles:VersionCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Binaries\Win64\XSettings.Sav2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir\CMS2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\ProgramData\Epic\EpicGamesLauncher\Data\EMS\stage2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\d945f059b8b54aa58202ed2989bebfc82⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Config\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Config\CrashReportClient\UE4CC-Windows-AED3596C4ADFAC4DB9E422A6546810D32⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Config\WindowsClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Demos2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\LMS2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher\2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved\LMS\Manifest.sav2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Users\%Username%\AppData\Local\BattlEye2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\Program Files (x86)\Epic Games\Launcher\Portal\Content\New UI\White.png2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:Program FilesEpic GamesFortniteFortniteGameBinariesWin64Shared Files2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Intermediate\Config\CoalescedSourceConfigs\PortalRegions.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\CrashReportClient\UE4CC-Windows-72CCB9004D132462217ECE948BC03CBE\CrashReportClient.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\CrashReportClient\UE4CC-Windows-E3661BE544621B07B291448442161091\CrashReportClient.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Compat.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\EditorPerProjectUserSettings.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Engine.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Game.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\GameUserSettings.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Hardware.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Input.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\Lightmass.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Config\Windows\PortalRegions.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Data\65f6b08d488442e694b1e23d152d971e.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Data\b371f0ee15b74eba84bd23830461130c.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Data\OC_65f6b08d488442e694b1e23d152d971e.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Data\OC_b371f0ee15b74eba84bd23830461130c.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\cef3.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\EpicGamesLauncher.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\Logs\EpicGamesLauncher_2.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\data_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\data_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\data_22⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\data_32⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000012⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000022⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000042⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000052⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000062⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000072⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000082⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000092⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00000a2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00000b2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00000c2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00000d2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00000e2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00000f2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000102⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000112⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000122⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000132⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000142⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000152⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000162⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000172⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000182⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000192⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00001a2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00001b2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00001c2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00001d2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00001e2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00001f2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000202⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000212⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000222⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000232⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000242⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000252⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000262⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000272⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000282⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00002b2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00002c2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00002d2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00002e2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00002f2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000302⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000312⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000322⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000332⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000342⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000352⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000362⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000372⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000382⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000392⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00003a2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00003b2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00003c2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00003d2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00003e2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_00003f2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000402⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000412⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000422⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000432⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000442⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000452⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\f_0000462⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cache\index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cookies2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Cookies-journal2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\databases\Databases.db2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\databases\Databases.db-journal2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\data_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\data_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\data_22⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\data_32⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\GPUCache\index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\IndexedDB\https_www.epicgames.com_0.indexeddb.leveldb\000003.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\IndexedDB\https_www.epicgames.com_0.indexeddb.leveldb\CURRENT2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\IndexedDB\https_www.epicgames.com_0.indexeddb.leveldb\LOCK2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\IndexedDB\https_www.epicgames.com_0.indexeddb.leveldb\LOG2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\IndexedDB\https_www.epicgames.com_0.indexeddb.leveldb\LOG.old2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\IndexedDB\https_www.epicgames.com_0.indexeddb.leveldb\MANIFEST-0000012⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Local Storage\https_payment-website-pci.ol.epicgames.com_0.localstorage2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Local Storage\https_payment-website-pci.ol.epicgames.com_0.localstorage-journal2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Local Storage\https_ssl.kaptcha.com_0.localstorage2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Local Storage\https_ssl.kaptcha.com_0.localstorage-journal2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\QuotaManager2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\QuotaManager-journal2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\5dff4910-44e7-4ef8-b06f-a66ce53e0e69\fe0c4ca0c0cbe875_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\5dff4910-44e7-4ef8-b06f-a66ce53e0e69\index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\5dff4910-44e7-4ef8-b06f-a66ce53e0e69\index-dir\the-real-index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\779a3f11-745c-419e-bb8b-5b6f2e7e0547\index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\779a3f11-745c-419e-bb8b-5b6f2e7e0547\index-dir\the-real-index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\e6f1282c-98d7-452b-bbde-050c09a94995\4bbf414005652440_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\e6f1282c-98d7-452b-bbde-050c09a94995\index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\e6f1282c-98d7-452b-bbde-050c09a94995\index-dir\the-real-index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\0f02f0723dc027b2_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\8b79e197c1500c11_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\a8a9373a71443d80_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\a8a9373a71443d80_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\be52f68b51029c9d_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\eda4eea3ffd63d3b_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\eda4eea3ffd63d3b_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\f5fe54ed-e03a-40a0-80f8-d0350a52b7e3\index-dir\the-real-index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\CacheStorage\e60030e2e5440743857a39cacd108634434c91f1\index.txt2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\Database\000003.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\Database\CURRENT2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\Database\LOCK2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\Database\LOG2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\Database\LOG.old2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\Database\MANIFEST-0000012⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\013888a1cda32b90_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\013888a1cda32b90_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\2cc80dabc69f58b6_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\2cc80dabc69f58b6_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\4cb013792b196a35_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\4cb013792b196a35_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\67a473248953641b_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\67a473248953641b_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\b6c28cea6ed9dfc1_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\b6c28cea6ed9dfc1_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\ba23d8ecda68de77_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\ba23d8ecda68de77_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\f1cdccba37924bda_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\f1cdccba37924bda_12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\fa813c9ad67834ac_02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Service Worker\ScriptCache\index-dir\the-real-index2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\EpicGamesLauncher\Saved\webcache\Visited Links2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Cloud\65f6b08d488442e694b1e23d152d971e\ClientSettings.Sav2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config\CrashReportClient\UE4CC-Windows-FA58D227408B75B949C1ECA1ABE0D4C7\CrashReportClient.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Config\WindowsClient\GameUserSettings.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Demos\UnsavedReplay-2020.06.08-22.56.55.replay2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\LMS\Manifest.sav2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\Logs\FortniteGame.log2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved\PersistentDownloadDir\CMS\CacheAccess.json2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\spp\store\2.0\data.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\spp\store\2.0\tokens.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\spp\store\2.0\cache\cache.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\Public\Libraries\desktop.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\ProgramData\ntuser.pol2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Users\Default\NTUSER.DAT2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive\AuthStateCache.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\INF\keyboard.pnf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\INF\netrasa.pnf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\INF\netavpna.pnf2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en-US\keyboard.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en-GB\keyboard.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en\keyboard.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en-GB\bthpan.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en\bthpan.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en-US\bthpan.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en-GB\netvwifimp.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en\netvwifimp.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en-US\netvwifimp.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en-GB\b57nd60a.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en\b57nd60a.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\Windows\System32\DriverStore\en-US\b57nd60a.inf_loc2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\Windows\System32\spp\store\2.0\data.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\Windows\System32\spp\store\2.0\tokens.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\Windows\System32\spp\store\2.0\cache\cache.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\Users\Public\Libraries\desktop.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\ProgramData\ntuser.pol2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\Users\Default\NTUSER.DAT2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive\AuthStateCache.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\Windows\System32\spp\store\2.0\data.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\Windows\System32\spp\store\2.0\tokens.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\Windows\System32\spp\store\2.0\cache\cache.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\Users\Public\Libraries\desktop.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\ProgramData\ntuser.pol2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\Users\Default\NTUSER.DAT2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive\AuthStateCache.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\Windows\System32\spp\store\2.0\data.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\Windows\System32\spp\store\2.0\tokens.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\Windows\System32\spp\store\2.0\cache\cache.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\Users\Public\Libraries\desktop.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\ProgramData\ntuser.pol2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\Users\Default\NTUSER.DAT2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\XboxLive\AuthStateCache.dat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c reg delete HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat /f2⤵
-
C:\Windows\system32\reg.exereg delete HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat /f3⤵
- Modifies registry key
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c reg delete HKLM\system\ControlSet001\Services\EasyAntiCheat /f2⤵
-
C:\Windows\system32\reg.exereg delete HKLM\system\ControlSet001\Services\EasyAntiCheat /f3⤵
- Modifies registry key
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c reg delete HKLM\system\ControlSet001\Services\BEService /f2⤵
-
C:\Windows\system32\reg.exereg delete HKLM\system\ControlSet001\Services\BEService /f3⤵
- Modifies registry key
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c netsh winsock reset2⤵
-
C:\Windows\system32\netsh.exenetsh winsock reset3⤵
- Event Triggered Execution: Netsh Helper DLL
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c netsh winsock reset catalog2⤵
-
C:\Windows\system32\netsh.exenetsh winsock reset catalog3⤵
- Event Triggered Execution: Netsh Helper DLL
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c netsh int ip reset2⤵
-
C:\Windows\system32\netsh.exenetsh int ip reset3⤵
- Event Triggered Execution: Netsh Helper DLL
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c netsh advfirewall reset2⤵
-
C:\Windows\system32\netsh.exenetsh advfirewall reset3⤵
- Modifies Windows Firewall
- Event Triggered Execution: Netsh Helper DLL
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c netsh int reset all2⤵
-
C:\Windows\system32\netsh.exenetsh int reset all3⤵
- Event Triggered Execution: Netsh Helper DLL
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c netsh int ipv4 reset2⤵
-
C:\Windows\system32\netsh.exenetsh int ipv4 reset3⤵
- Event Triggered Execution: Netsh Helper DLL
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c netsh int ipv6 reset2⤵
-
C:\Windows\system32\netsh.exenetsh int ipv6 reset3⤵
- Event Triggered Execution: Netsh Helper DLL
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c ipconfig /release2⤵
-
C:\Windows\system32\ipconfig.exeipconfig /release3⤵
- Gathers network information
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c ipconfig /renew2⤵
-
C:\Windows\system32\ipconfig.exeipconfig /renew3⤵
- Gathers network information
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c ipconfig /flushdns2⤵
-
C:\Windows\system32\ipconfig.exeipconfig /flushdns3⤵
- Gathers network information
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\INF2⤵
- Drops file in Windows directory
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\ProgramData\%username%\Microsoft\XboxLive\NSALCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\Public\Documents2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\ProgramData\Microsoft\Windows\WER\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\AMD\DxCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "C:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q C:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q C:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "C:\Program Files\Epic Games\Fortnite\Engine\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "C:\Program Files\Epic Games\Fortnite\FortniteGame\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "C:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Roaming\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\History2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\Intel2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "C:\Users\%username%\AppData\Local\Microsoft\Feeds Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\INF2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\ProgramData\%username%\Microsoft\XboxLive\NSALCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\Public\Documents2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\ProgramData\Microsoft\Windows\WER\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\AMD\DxCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "D:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q D:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q D:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "D:\Program Files\Epic Games\Fortnite\Engine\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "D:\Program Files\Epic Games\Fortnite\FortniteGame\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "D:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "D:\Program Files\Epic Games\Fortnite\FortniteGame\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "D:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Roaming\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q D:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\History2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\Intel2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "D:\Users\%username%\AppData\Local\Microsoft\Feeds Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Windows\INF2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\ProgramData\%username%\Microsoft\XboxLive\NSALCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\Public\Documents2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Windows\temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\ProgramData\Microsoft\Windows\WER\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\AMD\DxCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "E:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q E:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q E:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "E:\Program Files\Epic Games\Fortnite\Engine\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "E:\Program Files\Epic Games\Fortnite\FortniteGame\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "E:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "E:\Program Files\Epic Games\Fortnite\FortniteGame\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "E:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Roaming\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q E:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\AppData\Local\Microsoft\Windows\History2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Users\%username%\Intel2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q E:\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "E:\Users\%username%\AppData\Local\Microsoft\Feeds Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Windows\INF2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\ProgramData\%username%\Microsoft\XboxLive\NSALCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\Public\Documents2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Windows\temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\ProgramData\Microsoft\Windows\WER\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\AMD\DxCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "F:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q F:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q F:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "F:\Program Files\Epic Games\Fortnite\Engine\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "F:\Program Files\Epic Games\Fortnite\FortniteGame\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "F:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "F:\Program Files\Epic Games\Fortnite\FortniteGame\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "F:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Roaming\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q F:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\AppData\Local\Microsoft\Windows\History2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Users\%username%\Intel2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q F:\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "F:\Users\%username%\AppData\Local\Microsoft\Feeds Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Roaming\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rd /q /s %systemdrive%\$Recycle.Bin >nul 2>&12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rd /q /s d:\$Recycle.Bin >nul 2>&12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rd /q /s e:\$Recycle.Bin >nul 2>&12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rd /q /s f:\$Recycle.Bin >nul 2>&12⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\servicing\InboxFodMetadataCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\Explorer\IconCacheToDelete2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\INF2⤵
- Drops file in Windows directory
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\ProgramData\%username%\Microsoft\XboxLive\NSALCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\ProgramData\Microsoft\Windows\WER\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD\DxCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\ProgramData\USOShared\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q %systemdrive%\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\Engine\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Roaming\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir / s / q %systemdrive%\Users\%username%\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\INF2⤵
- Drops file in Windows directory
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\ProgramData\%username%\Microsoft\XboxLive2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\Public\Documents2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\ProgramData\Microsoft\Windows\WER\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD\DxCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q %systemdrive%\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q %systemdrive%\Users\%username%\AppData\Local\Microsoft\XboxLive\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\Engine\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Roaming\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\IEDownloadHistory2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\IECompatUaCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\IECompatCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies\DNTException2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History\Low2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.OneConnect_8wekyb3d8bbwe\LocalState2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\EcsCache02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\TargetedContentCache\v32⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\Intel2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\UnrealEngine2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\UnrealEngineLauncher2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\INTEL2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\ntuser.ini2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\LocalLow\Microsoft\CryptnetUrlCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\system Volume Information\IndexerVolumeGuid2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\CLR_v4.02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\CLR_v3.02⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Internet Explorer\Recovery2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /q %systemdrive%\Windows\system32\restore\MachineGuid.txt2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /q %systemdrive%\ProgramData\Microsoft\Windows\WER2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /q %systemdrive%\Users\Public\Libraries2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /q %systemdrive%\MSOCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\ConnectedDevicesPlatform\L.%username%\ActivitiesCache.db-wal2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\ProgramData\USOShared\Logs\User2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /q %systemdrive%\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\ServiceProfiles\LocalService\AppData\Local\ConnectedDevicesPlatform\CDPGlobalSettings.cdp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\cache\qtshadercache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\UsrClass.dat.log22⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD\VkCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD\CN\NewsFeed2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCache\IE\RHKRUA8J2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\CLR_v4.0\UsageLogs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\SERVIC~1\NETWOR~1\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q %systemdrive%\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c reg delete HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat /f2⤵
-
C:\Windows\system32\reg.exereg delete HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat /f3⤵
- Modifies registry key
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c reg delete HKLM\system\ControlSet001\Services\EasyAntiCheat /f2⤵
-
C:\Windows\system32\reg.exereg delete HKLM\system\ControlSet001\Services\EasyAntiCheat /f3⤵
- Modifies registry key
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c reg delete HKLM\system\ControlSet001\Services\BEService /f2⤵
-
C:\Windows\system32\reg.exereg delete HKLM\system\ControlSet001\Services\BEService /f3⤵
- Modifies registry key
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\INF2⤵
- Drops file in Windows directory
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\ProgramData\%username%\Microsoft\XboxLive\NSALCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\Public\Documents2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\ProgramData\Microsoft\Windows\WER\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\AMD\DxCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q C:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q C:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Program Files\Epic Games\Fortnite\Engine\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Program Files\Epic Games\Fortnite\FortniteGame\Plugins2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Program Files\Epic Games\Fortnite\FortniteGame\Config2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Roaming\EasyAntiCheat2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c del /f /s /q C:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\History2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\Intel2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q C:\Users\%username%\AppData\Local\Microsoft\Feeds Cache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\FortniteGame\Saved2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\INF2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\ProgramData\%username%\Microsoft\XboxLive\NSALCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\Public\Documents2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\Prefetch2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\D3DSCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\CrashReportClient2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Windows\SoftwareDistribution\DataStore\Logs2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\ProgramData\Microsoft\Windows\WER\Temp2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\AMD\DxCache2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\NVIDIA Corporation2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q D:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c @del /s /f /a:h / a : a / q D:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC2⤵
-
C:\Windows\System32\cmd.exe"C:\Windows\System32\cmd.exe" /c rmdir /s /q D:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache2⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-948125896-1532802483588045281-621968743-652831222-4568420121854825649459635381"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-245633796-12330014591730806876-1427182733-1660245122206593186320165117851357846485"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-400891099203347282379966058219701305371937634786-2131145379-1445940338-745557124"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-8387260498040069591895169631-806625538-396881554-12670746731461475928-1203371145"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "16250899871594901097-1488373262-21368312221451696513-1369680739-726582640295236246"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-231018054-6188751361106995022755491869-24147751168715731-1349823619-1013215229"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1021786781236106769-7394629211319992534171034728192821338899816093936037280"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-2028271366-1674842912-161609947-1945843117-1099513562057924921283802537706580362"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-443001900-1244802243-13241675001017819191-889190176-2020455171246262202-732817938"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1086832521-1296317660905037486-1644986095-1642003243-379476559750140051-998742509"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "187412590-17838641165798750479253780451137251160-1222853439-487119374-1370559416"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "20335966611436108726-12731964058313713116448230712559368341935478963-762618729"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "2007021281796530817597639442-20402162651477791871-806312880831909162-126728453"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1284782077-187091010116944833774727163997699191074512602947054688791645659013"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1436992054-97510668582384848-1814746196724652182-6671194862007999327-695586466"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "68076835-803004444-10818083801533132103-2252169561794171410-987954607-1302763310"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-610334491169568058934275573-1594130069-1049612124-1531743442-14582694901987165124"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1129135188-7220761411215421354-1560678192-1394145362-676655291782254447212021607"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-176752488-1419753595395423038-2011226661-18279836612741249241166737884-1864954068"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1351895935637610113-1683535612-1337195988-1800853199-68587232492422984285049391"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1402655327904429799184811827910474328101291280849-62614007-1712822173784678827"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-11029164507446782401802074904-1512238842-20972958172021222302-15198622081663873068"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1783163197-949130432-736736665-189066209411883182941574912249-763696563599774384"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "317312131-2562649681053241648-21242581791263124744-1327373010-1013258577-1915520033"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1052228954-982117256-1462725201836278041172078611019742254331993128659-1142545786"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1936492341691432237228092783-1535805407-1920505420-1615281362-6634748661689164214"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-2731609161549012674328050897-1947718561-993710118-11623034952073951475-1595923552"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-11226770531202139937-5471543864160649281829016704068613-12728327084619578"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-4104761318008008661771013899681909139-617446202-1114928869-87126707383062109"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1507421740241411568-1133332250-1711150586-125796986-1203812887-809471683-1683935858"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1644301395-8020865431476043265-3123237122019228197146456845-636921832093726851"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "12800826052123118452-46952498126139800-1764664630-18004895421280591150-510151013"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1615231485-87981466790384224-19967483211440191293-108392468-122917374760352935"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "41729521-430562213-19896537741120498124151372873-2133991185-11579081951102447080"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-17493037322110088661997794539-21295188447112964499128184981402724158-265320731"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-11564278138918693841077952775-1054483428112552482-863405319444612281578976232"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1139587508784043764-57490304948959968612586073541612492305474233492364062454"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "602814582-53387146810324970720911313642054335007-552984520-1939497690-1586243092"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1907581018485427451-188473222-16271709782123935207228440574487255762564859229"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "21278063511402505346-9391838951212418897-786556662-1812337109-420450137-195346095"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "2015456524921180733-134360840784519480-10036723882852816461956299809879492516"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1501060651-136968156447611874817018975581469093835180493576214281132341268143358"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "10090545491936192818-1846764050-664904521846408701-1984677849-304445433988731105"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "9735834611137917875638501572211661204731433007111199972461838462274-586539343"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-485586729-6430822981381313824-1535138376-400355505-216839000-485621484-1004868700"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-125581933-284854963349270088427300351-20424666291033977557-1458568755-1755285776"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1505628371392635822-1730540682533820986-1583012328125693241260990652-1159264797"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-882522434-766294803-927317511-52647788859692868-866643668-1422458884538061041"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-18739706671121574355122048288811175861319574768481863767269-11350865371306856853"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1650382323-1896557967-1341838711-1065660853-133382556379140116311256201181923024401"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1648060996-1026317287-11695176661826827850747822046-3915156271349791840-55174764"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1152486918-2274364167140684690166853-7433732507773817381336272805-4265391"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "514043614691689750844711968928333690153243701316903862861320691421-724049869"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1318850032115024217215935103751391116554-5886867932106128926329741232843057203"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "2046042369-10208053481437199005-30043282817708558499525505487822471321786542828"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "2381543576238553671792735493872645844-1628518733-1823408923127270909814245024"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-344069459-154608329712008425652308028961987835328785498851975823169-984164288"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "573307780-1087678532-261002820-715088465-17553423301456789212720154289-2076654333"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "171834788-2089075720566909552-17943092329657850761903573002-1882810892-1284857266"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "11968830674989811931237889980-7262554631219080289-445145598-491824241508271954"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "356729007-17179851181673245431-11834504401350583601165707780513586367041633904333"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-908737682-14923743941058891441-1279306876-118046401710203716932351153-699888118"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-242348066-1247017898-1089452227338818326-1016778933-1453831852-1996708844-1977387274"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-584003155-5990591652125105770833277493672934836-303587859866553385-464465578"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-53162266-607096233-13986466771128390310485547920-12001484981136720322072929234"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-92531178010685335781765367211765067186401115849-11266938771661454470-248483206"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-88707378-7020259311157798548-706194716-15778959408458705641871230665-645115194"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "7998166020603023391599935207129267666551526649329433783618636-1177787555"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1793932210-149022728-17816034351023248512-670743733866172475123244667-169591800"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "19121679398660239837192547222069239073-42650479-3968385091701775503-1425362528"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-44946360820763556620551067911525127001097796235903257148350660360-827621999"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-2024651423-1411784296-10641120741863112572-1413621377-537839117-78470713-1239362213"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "11656940752862979191124691410289895948-1290670268-20208957811390797866-780413400"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-19563945451959439387281607522-13014608540807761718390730659292508542044245483"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1371983763230530512-1460749477-183738072311617923711315551248-12043159291513586136"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-572734998150006011-2041120141305016377-949539161-12011587841832618691-2009325853"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "2076700992-1063847036-12981638435663183891999166242-1800592041952412426-844626350"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "642521421-50326531-83586591019268646752091198947-10713521716048602851418696834"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-2260855312141315311468691521-712432001-136075164396788885625136495419808222"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-12796199671089741185-1493891689-834911016-1198938985120028809-19897634221043595753"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1933905728-682292008-381847549170955540889331174799151949-739397004849432216"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-917384806-183677219320795534251175548844-1395568263-1995073014-750805831-404403241"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "10685341652029341864-8614237441614843217952738885390275107-613966035404272652"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-20680196561456457739724731601610390925-353181191-1937249001-6711574481120105655"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-248779485-1498295931-209744160211016888952019225090-2554236751211210093171683326"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "798222815-361416469-1571224838-1149496127-676846203-18469470622053893725165977263"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-12455427641640458263431550194861664976-1812971151735173298-449802577-1336287452"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1461925381-661136030-6495787829207154021718312252-18908248772085650166850998448"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "14236968278062710752064632643320794762-1837716311-1725093969236640372556758087"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "917211187-9765823311365271753-1366390612-715129314-13410154561156169122-1281472406"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "189523575-1707961007-258024027464630703455049072-1516673847-7196359041170422902"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-9304175201104203208106967742012673869620160551-1451272473-1200054697856539114"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-3418154-194614771014772628205001000872874515-129471889013805586804489478"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1323088012196019101219873370901913671825-1640662384715461601404805579727388253"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "8933132611994344129-164292961612388770711323683749-14646154871688548591-1378663741"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1649058115-5223937261953203519-1989061064-1357075085-722966077-1843884991-1138504134"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-16003132851096947862-819455454-13324076085721566211315001001540140646-2132981178"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1937738331-17152818031135140973-2078766743-259919736-1463551906-7331127071271334888"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1727803334-652923132-69093330-10950169321756254242211931148311516920922063803028"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "721474137-169136326318966975423161097-1011277043-794373349132231770-1422720617"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1913771669-1319217084296134200-85143028339576424212826600162036141437-1643922824"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "480007622-2085719576651517080-1481857230-1153538041-385985858-809899595333246851"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-43911333-158015336-574699001-1817310571404690558-1669093835-310415370-2136314474"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "677444691-6677256271883236651-15231392581933340097-637398790-18820106671979253232"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1902873899-1171742585536071113324390758120568978-1051180427-15488447461879113773"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-2012890678244334731-8490384799952575571962168416167859186-1995748965-1481326244"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1023736927-17297496211767705011-1932140251123881919790450188813700273591512475543"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1824902238-188063397419777203931939094816589477886-11067930181907161282-1135743221"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "18801783001348559956124998816-850157871-3879035791543022149-20806430321383104130"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1112572866-1298964028-169547306817370253322011895907-2873194091103356336-1755993161"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "175642610-550190593265477691449530648-17439979869285201391614341778-1939927418"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-21039146573743515281369554655-1442026025-1510361711690823243-603701132-1977712005"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-19823070981930818687-822792061-923619819-405523504168465707816996672481399231422"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-15048846206122504301979597944-1854538170-2004074692-1793697637-5379726281997655741"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "219894126876448239143801764-1505571031-19702560788861104748968484321097676927"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1118116476488464507401371609518042731-1726233433-1624078559-1897019436234348439"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-65939017-44526510-1384916006-1723084439788597601202956580529027518-2059622795"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "20893825221604838268-12994316821511907211-1245565625-1196335693-805157810-210375370"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "242781813-990479270-1370117860-777797855-1102953602502082743-1984056155-562958944"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "2550905151697495890-21344297471140535609966311122192217699412735953971461483060"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-14083904611278302021289591808-1604632545153416685-8347703656216238471736926022"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1760412534-1353490819-9096989292051410620-13957884873956431752058786650-1935886907"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "338630466-91075122-15691811421819439312-16967232681604326437-560678055416715377"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-17292713911085153019-179150428461034560-5182312901966261247-620328548-516847202"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "817700342031189442-936974560342104848-1289624640-10910016731410103131843090724"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1118284472-980903249-1632463039-11625853361684860299-1306069017946694660-1773142200"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "2047192988771100492-360372438-12301444911002111328-247998442441174223-1721057719"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-601156144154379983-468629681208765902620189353031958873622626256900-1886433360"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1538833374-2091601584-1002902343-209560136253879011585845353-2030951094253053759"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "717056364-130889597991977560-834455352-6659352541748543921-11753753911388571727"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1579609204-198621301972243872-12911683011230874564-1898662755-859118601-369399757"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "197773760-192629686197266919621130589279742056191404374873659451760-509205535"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "20738114311023199115975027445-59577819294803258632303186-1735598213-788184031"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-169924920991716259628694008818381933801339161292-11331107751321652689-370848984"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "16334699520719621561822354716-1065350891334108672158508690413665640561881227111"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1066568939-1138832567-616069267-2459523392004381218721929519669795748-2047508082"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-16067975891051658582-174923336310679859581426238460-1982725146-1589095443-513883932"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "464859673-1462208286-1604207476-1758020572-1448350830778060362-1148995703-240657367"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "17932245481206002456-809323088841086496-1691560647763945141-481715005-1294501856"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "161024558-1622728611-2164942671387258533-8416342601371324277-455898647-1706944314"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1821425533-1990585418766208909-1049560274112163442744777316011180713131020584560"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-439502503-18854765381701625003-1819144559-697909416-251684640-926490453-2104197663"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1129632485181516519-51321679521773437954070030972841947587312767-1632255281"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1588770027-1834644101902715733-1696663878-430664901-5970671247187644111247816293"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-765865778-12164777955178284441087919038844206593-2086600602-1163167332960164072"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "694292448-171815199186561841542827689-1991814016-1883315272-864368777-1950423550"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-19487056971522607879-14742583231561792587-348539885-5780001381480593397245899844"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-396771535-1420137708-763093288-444044434-767586796-1229672854837910853222077690"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1034708024-302776389904438206-611831537-131698515719041206271830132778-1194457129"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1052528581-17433447481861671016539419521340688059844642816289153233226423077"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-406856080-120452587555985728-2046836710-700616318-7475937471477177481471420037"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1495884818-1777442766-88456732914286664101605312219468464190-1426274075-1811270892"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-182964801509045143-47021459514937998031864673764213964318522955446958976669"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-2121106817-1846465310-7965481361601712299-642208725164894451924305084-1113435509"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-222651116-1070139965-1965610625-1754884952-1168934105428573828-65815619-1030069345"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "651482847-1795378315-9635022041707509324-13443401051081732628-14495563861632777682"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "894079121-141137957593494993315520407222130446722-796551814-1671734429-399228023"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1485664532790548710555268791-10145139992036250739895812635-1822624508-1194799887"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-16079051151364495717877882911310945661511639489-1220154473-490689163-2031615137"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "9876857904611207088751588872008377924-1113536981-1997561939-18830505171986833978"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "895399228612088843-759360549140448663145855606117451063941287333894-2063941473"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "461936083-181346141614677519841760182588571930332-2134068832-2053653635-334220323"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-81940081268707823664243353-366090403966128079-158994725710426932491593209479"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-42089315-18082593655991591072000311180-19429322161018797710-16519482751458834403"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "1536915859533949659-2114594960-11842039164804821568213967701676021007-1449914757"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "994026741-1062689738803639630108106142750808726048758981154852871-121662222"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "-1287184298-865683124-325880873-179973611110461828991486881544-704564837689706253"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "68313998345417641759172046544987233-1826400175-81121145-11833459161002237640"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "12590112281625635097-1371994810-1138982020-183776482-97660270711485432491411711549"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "2128720592-684723486-447011286-390308369-1590466057-12555335441127734646-1753163838"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "114217871-938050766-1563707744-10902209601826271056-183299062613439396551492321616"1⤵
-
C:\Windows\system32\conhost.exe\??\C:\Windows\system32\conhost.exe "9315974238800538121874841624-1206767757-173711731-1867046259-2012454402790725043"1⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Execution
System Services
1Service Execution
1Command and Scripting Interpreter
1Persistence
Create or Modify System Process
2Windows Service
2Event Triggered Execution
1Netsh Helper DLL
1Privilege Escalation
Create or Modify System Process
2Windows Service
2Event Triggered Execution
1Netsh Helper DLL
1Defense Evasion
Virtualization/Sandbox Evasion
1Impair Defenses
2Disable or Modify System Firewall
1Modify Registry
2Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6~1Filesize
854B
MD58d1040b12a663ca4ec7277cfc1ce44f0
SHA1b27fd6bbde79ebdaee158211a71493e21838756b
SHA2563086094d4198a5bbd12938b0d2d5f696c4dfc77e1eae820added346a59aa8727
SHA512610c72970856ef7a316152253f7025ac11635078f1aea7b84641715813792374d2447b1002f1967d62b24073ee291b3e4f3da777b71216a30488a5d7b6103ac1
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAFilesize
1KB
MD5611d09a9ad8d4de7dbaa159266b22eb2
SHA18a636d87f0f9c3b88bf2ab72b668288ece5ec916
SHA25674ebc9a2d9aed68879f32fdd6e5faae3240671ae5f2664e7604c7c335c189504
SHA512b61d42c43b8184dec5c94a080190dbfb89b9f3ea06f5865a06e8da2c3649814ad42f4fb7461b55e3faa50eef165cbb1f83b41636dd7837c2d54cee4b1c683d8d
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4FA45A~1Filesize
472B
MD5e6352fe4bdea282f2f0a1a5282bb5c32
SHA1b3682b4f01987e086fbe49c17c4f815cc005f855
SHA256d3b8198a69fccaea3806c21cdcf084d6a96152819ad06600ae0ba3175295a328
SHA5123e5f60fce6abff003346b7a72ae3acb939af741ff5c8111ee9e5cf9a98f9886a576034dfb8a1e9d233a33c820854e6ed7fd7964162950c9e4df3c5972a3a92ea
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6DA548~1Filesize
471B
MD5fd84c1a26b78850895b35b299c0fa27e
SHA13cc51bf386ba69bdf1616b72742aa52c1cf176ad
SHA2569bbb6dacb7ff60dd8d6cf95eb8312cca8871f46b62e344b4bd641884c2f5b7b5
SHA51204875ca239784b66f33b0c7f2dee33369a3f4e1eddb0cef7e0656710335a13a1348e933efeb0679a89367b39e87714aa880095dec107a2bc98bdeb979afc05dc
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015Filesize
70KB
MD549aebf8cbd62d92ac215b2923fb1b9f5
SHA11723be06719828dda65ad804298d0431f6aff976
SHA256b33efcb95235b98b48508e019afa4b7655e80cf071defabd8b2123fc8b29307f
SHA512bf86116b015fb56709516d686e168e7c9c68365136231cc51d0b6542ae95323a71d2c7acec84aad7dcecc2e410843f6d82a0a6d51b9acfc721a9c84fdd877b5b
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF470~1Filesize
724B
MD58202a1cd02e7d69597995cabbe881a12
SHA18858d9d934b7aa9330ee73de6c476acf19929ff6
SHA25658f381c3a0a0ace6321da22e40bd44a597bd98b9c9390ab9258426b5cf75a7a5
SHA51297ba9fceab995d4bef706f8deef99e06862999734ebe6a05832c710104479c6337cbf0a76e1c1e0f91566a61334dc100d837dfd049e20da765fe49def684f9c9
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DDE8B1~1Filesize
472B
MD5d989d166cb70cd587adc13dc38ca7715
SHA1ee72eb2899e1610d1903c97254e9bdaa07d9cd38
SHA2563916444dc425edc8348873eac1d26ef3342accef35b3c9940f39cf3c428ece5e
SHA51265523be974fd1450a6c1b22d924a2fc6de5f65be50503adc06e93e8b3eea8e382df1ae37f183e1cc961d9c19800cf1843aa07cc771b7fc6e95e9e7c5c6220df2
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199Filesize
170B
MD57dc065f4f7ffd637938b0292fc16f546
SHA11913d68e82e9e2bcf0e6467c1e7f96e75367ecb9
SHA25676be4774ac75741ed44c34b03b1d40e2c40234b70a7b077a458ed0fa1a9ac813
SHA512aa696be97044970f239911876553862a0e036d89fb5bc75edd5ec39ed016b4ea2b7496e3c2c2e52c0f84491a021978eb34ff9cf1579d3c4300fdc7c310b1f843
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6~1Filesize
170B
MD58443519e1caaa32ec860fb1812fa3660
SHA1429a6098849f9f00cd10788182f44c09c109ad13
SHA256a258e757019652a93cc97dfb34766976e0118c92687b4207ba6a9f395aae22bf
SHA512fd9df1158b99ea31628b0f4a0cc16a20562b0cc8ba3f20c25dbbd04d75f346234640f2626723058e54770553e327b99d32dd4e75661f3686a9e05e4d3fedda2a
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAFilesize
410B
MD5194a7254342d426f585b5b666f75bd98
SHA1e6de845d4dc9afe9cc0ea522ddd45aa28785bfb4
SHA2567053845e4aa6ff1c6f46631c9d949fde6dc707c636a85ba12b545cbdc4c13ad9
SHA51278f72feeb77f7ef1199b6f34eef818d85408bcf4ff3b9ce862d5c949ed6a12a9b52156f1abd523a98aceeba0758460ce7a835377724a848f1faf7f66bb3db7aa
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAFilesize
410B
MD5d77f074f8dee25dc97c66de1e92a4d50
SHA1df2487cee9d719bcbce420c0665c3952c171be33
SHA2566f7c2ebbef31842d57a394deabfc119306b36ab6bb0a7f149f76922eb784c862
SHA512883d53877f38b50f0ba7e2e54b83cb4f000a440d3e999ed8b3f2a461953e929f9507e316c95d62d7c465ccf26aba4c3f87ee4ea89303d29674dea7b9e72c3b41
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4FA45A~1Filesize
406B
MD5bfd6fd7f334be9fd021976d96e39ff56
SHA1306169e7f593fca3a5bf6e1f04b86b869007764f
SHA25649ccf1f428d81e8e6ab0012627b5a257e0cc0959882560a9d51399a0881a4ec3
SHA512dbcf0e42a7095e0a9ae73b6108fdd5e212323541c312a24fb6b74a312e37667091ff3f598c0a67c4f0cf213e5d50d8dd4bec421df515767c9132dc5b4ea23d4a
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6DA548~1Filesize
410B
MD53a11c0aa785d0325878996df237b9419
SHA178999cd75025d3bcef2e2605a78b03f251d23002
SHA256c1ed526c26e84813e8f8c152f54eacca4e2be0317e206f6339aaf949a5c23b15
SHA51235d8ac96de34b525e9497dcf544e09fe893bcc79b4bcce503cb69b44c61e438e9bb832670a264c1e5ecde6c7e90d67dc9c9ce09daedf77bece5542aa33c3bdea
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD54ee2c9cd3d6e9d87581700399a56875b
SHA1046f4e517abccccedb2654d433b20f9c6d617074
SHA2564e8c03b5e86608aa3bb22551fd68650d612a5dcdec1bee417409aa0703db4a9f
SHA512307395aec243afc16b328e7a4619f7d15a8ceaf092562619ac971206bfb812db6bf74863b15a798d8cd99f83e85dfc37a48917fc5dd0db58ac6e87dc2993a7d5
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD540af462dd8eb55d398cadb032efa8949
SHA180ed9bbbf356f74cdffb10e2c207163ffb651ecb
SHA256e8f40dacf24214a6484f464d9a998b87f1ded9199788fca8f7a3fdf078f93e12
SHA5123f72b05e2f7664692773932ebb0a9a3fce6b0b1b89651a5d2e52718a7ea653f4641243f482e25be5b27831bd4aa044ced2cc98d98d2a519bb702915fd47c17a0
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5117d06baa2996a0ecc001a5530a49f55
SHA16c546f7ed2440567ede89c1baa543f91cf8738cb
SHA25602b38d747e251c1129973cadd204c74a5b942720d9e873d17acb110749e79ece
SHA51229dffa2729d8d3428ef14f37d70917acf4895431ba981818242ecc00ccfd07e5f1684c47851d1a577cd35e99cc4c48e5bcc123d5c9ea3695726acdcd48939568
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD593cf84d6a8772abccc25ec44aa8fbe0e
SHA1943080ce6560356a4966ce47bca232e599991669
SHA2569c55345251701c7f6419a4b13637ed6c2099553da7a97a2c4ee7efbde5e8c4f7
SHA512d756ca4efe99f3e0fe02f88a9601572924c69cf3ef19946ad4eae2cf6ddd692bd7c5bcf923edea84dfb1d24ca455ded58966f3828907603fc346ed8a00e75235
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5222b639793479636675eb4b0a3053cd8
SHA12e07111b233fa613a3719a0a74d8107e8090057e
SHA256ded013695edda746245e6c47bf529c96e919f718be38b90e16df37ddd197a9f1
SHA5121aff66294ecca41cd9dc9865f10b9f0547911a7b5dcdb8f9eeb4c2a42d4f2de1ce1da8f0fffb9a668bba4a3565339b1f25f5b796f273336c70028ab3bbb36f55
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5e0df7c400293e4b11a9372ec859f68a0
SHA10f70d3751894ab832cc676eea361a4afce9287a4
SHA25634294742bfbbb1df9914b11a9502fcf0834371f8e5851213303051efcac9bffb
SHA5127694c7d9440b1bd5b906f0c972106d7ec43079940f53d39de6c002b15f55b39f7a3a54201d2242dbca6b433f1d782d73cb57e6a3c49fc4130686ad1ea761ac27
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD508e0530cccad8c51d1b683deec5cf947
SHA184916b6190f78076d40e9e038622ccc9f4159551
SHA2569fd46a418871c939d6f925941c8ef02028ce3660f3023540391293d7a9bb0ca9
SHA5124a0336b3cca5dd2a930055a8bb61fb3e35c798d74d5dc18a506bc307add15486b11f6f69c79c39182ce659789dc5ec904e79cf1ef27f6d90598ae2e27da32116
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5782b44817b616bf35d3757d90d472295
SHA15840edb29e53e4991a8a2f1e8a3fc312e2a11d96
SHA256617f8ebae45cedc0b52e23999b70ecc2504ee3cf1bf2e168ffcb2e838ef5f13b
SHA512dbc2a16d11d46c8349e969a66e0a71c8367bd09a23b878a85cac1af9ee2b1ba83ab2088f147681039e927ba074d49991dc0579e66a47088478f1eb92782f838d
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD59bf9cd140b89acaf757d610098043096
SHA19a124b2240cf0e10274a2de5f491609590714b88
SHA25634763f34da6680290b5f81d51621e10e916a0d263686f66387ab478af6dc191b
SHA5129409271b0db8335785ba35923a8bf893e3f4475d73ce156ffc50a9f5219b073a0462ca58c3b49ddb1d7ce41d92fccc32816d8dd80e797835d6cf8cfc54c5a511
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5f699dfebada53bbb18580bd76a05e397
SHA1e5011d61e8759280ee4b7dd3ddad4592e6be6d01
SHA256b41e74c356584ed00b61fba7fc2023a3b23ad536ef9cbd4784e6010f64d115b7
SHA512e1bd41df664aa299bb3a3bf7b9a239efb9750500e82c17759e82efca8d44cfa5ac5d0ba3edd7e44fb7f9cb8027f50a4793e451c9dd895d92f45cbdc803170aa0
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD50e3bf64f2cda22fccbe1f0f308eae0b4
SHA1b3590d9cb7aa2d8242c61bae45f58b96484a92b4
SHA256958e3063b0db63c0230b09754942a0035b70ababeccb86066785e08c1d9b0df1
SHA51293e5c4259c5235ff6ae616640e3415673b7adf5dfd53e4b0081aeaefc959f6b4e04676bf56f578391fc2a7e2b32783fbfcd9472fb2ec8b63484207ec450a13a5
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5fea7a2a996dd94b0fd191ef15ae166d2
SHA1d08baaf02bf704c9f2ff68c87e7a7fe04416b0c1
SHA256957ac2deee9be6bcbaa05c73eb8891e7434480430f4f0a40fd19eb05d16d56b4
SHA512fe05dbf8daac8d9112615ec2380a7144ee66395e8244ef01692e7f36fc78151616ba7aa7b0ec7235ac5c595cc24b39bee57b3b5b5836419dc45f7dab2fdfa41b
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5c634ae60f76932640c1ab114fb009b08
SHA1b5abe8b5184ff33cc52da8c63b73e278b9a1c8b5
SHA2565e1ff2118178477e6e067f0f527211316e4d283d9fa7939170fec8c8f4041cb7
SHA51275a9759e6fdebc3c2a650ece005b0c3b17b9ddc60854e1a411a412f77270a1a5b3c1adc9ae325108c4b5cc00f5de004ba5c5e8681532d9f4f01f88c046e14fc2
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5bf6fdb8cce611e3c4b135176e709753a
SHA115d9549407a6be650076b5481612c8cd5d9223c7
SHA256ba165ad5e9505dfed51b2033d78679687254382da99e00e99062b46f28c384cf
SHA51269644a8340b90ac93fbab06a5b686cef68ffd011fd91605d7ee3e7d6186239ce87f839844ff34a781556853a654fabfd78dee870df6dc98345802a5912a403c1
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5af7a57f9f359d16c6c9b106dbfc3d855
SHA1eff4edf8fdce7083203a0b82a26602df77a61a85
SHA2565ac85118c5688dc63a55db8967e26f4473a4438e323736c8920691ed14c9dbad
SHA512c3ff89135c2c30fe0687cca542a14465b0260d62165584dcdc90dd07ab6d690fde1a60848700710491e6a2cd5efef17e054fc79a13ce3e0502c1e62bd998abf6
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD58937545a565a6f869544e70eac5da05b
SHA18073d882d6d3c1e71cbc97c1cf0d5eeca7ebe8a0
SHA256adc544a9143e7347c836d84bd542979e186641f7fab6ac33f9e52afe9de3123e
SHA512e0c5f2558c3a1448b3a3b85e1294429ac80dbdd3d277fae209d51536e981635d2397fa40d212c6f97bf6bb5e131b615e77ca0d44d748e1d11158d9cf28bb8bd5
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD5de16f11169cfe6b4ba033f2cb9e52905
SHA183b81009ce14e9b4c39f7be630df354b2978c284
SHA256ae89a73567ab53fd5064d9ffc5cdd98adae847a51d038823d825ea5fe38d7ed8
SHA512fde8f5eb52af31fa7a0b081f0b8160bc9c4f93d25bde21f04b417aea0647dc7f4ba0b1b2346f2e46f31f78d73470056179e91285191e5d1cdca5a421a7554b9f
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD518981132ae55f5fd5c764abb4215782a
SHA11b05b0cf2a270c2fd6564172f6a737d595af856b
SHA25679d8e87a1e076d5f75b213672368971d7488021a5790810ee4b70c40e9ebc362
SHA5125e99717b31a0e2ebf3b500e15a5014c3e4cc2236aa931d374c1711eeba6f05ac074b39a5604140ad6ec5b000dd0e934e36ec49b8be7fa2d5c389248483ada3a5
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015Filesize
342B
MD511bb41282cbc63a8b3011ae6e4b7b38e
SHA14158773f33f21f84663f4c4416cea9153f7ef616
SHA2562ae0f245e98d30c9cd6f98c272c6036a1e613ddd1219e504c5f72ec562526004
SHA512337eca070ba222e052dfbc7bf72aeaa3e5886289a4f6263ad66cd9ec3af59d5bfaca7502b0456063746d83296901d67d92cc061669037d39c7c9fa5ec4be1f8a
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\943080~1Filesize
342B
MD53ec3a3a30beea7559f8aac0b208409ec
SHA1e13a00e19dd213730406a24e272c670db103a5ca
SHA25647786a952269647d6ea534abd02e6921077d03ecc6f19b443ccd9755595cbac0
SHA51254c16a4bbfcea66fef956d452c6b8d1e385a41f8da5f889f1d8c0f161d630dab5daf3e49073a9394464a36bcd098d09a4b5bd3af7ed799a8781741fce11f65fe
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF470~1Filesize
392B
MD519407b3d318d59ab20732532ade13e6b
SHA1e75c6e1ef750214a30616955b424a5f8d65fc1ec
SHA2564016b6e67a9ecba48e6d1abdb287455c0e84c33e1fbee0e612810c0589aca40e
SHA51259dcfff45b1d1afd6d6cd5d0ff5e0bc7cf196fbcb4697ef2ae6dd2af462590e77dba5bc552defa922ec279a67c36a6dc7016149103d271de2052f148dce03da3
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DDE8B1~1Filesize
402B
MD5471b404c3e4330a5d1cddaf1c652758c
SHA1913bdd994b20f7e7fa2047c85f1617e686371c55
SHA256bfb582d3ebb22e0ecea76ebef45806019a4be234354f7dc68b995382fea5e68a
SHA512eacc4f5fa348ab3d722c6eb29878f60b079b789257be82b3c124d2bd385e54f900ed68c36b5f2be97edb0a9304254f546e4e3813ce3f1a587c7653b4c3202097
-
C:\Users\Admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\LASTAC~1\RECOVE~1.DATFilesize
5KB
MD54071f211b644701d8b081f0b4091b5ce
SHA1bd58fc749549ecf08485a94af33ae876dae271d7
SHA2565339ae8c2116c02dc48f9b87bc89c253fb8210ce993c0dc1b28b1ba1b0707419
SHA5122afe0958578f2c1839ec696c39248e4eb8dc31d37f18166d549a74d22a5d39445d6cba81322702420e72062642215feee91b74677bcd8b07204945dd528a84ea
-
C:\Users\Admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\LASTAC~1\{DD6DE~1.DATFilesize
4KB
MD50919b1bdbdb33a191fcfa3e8b3ae1129
SHA173f04802990cc73a2eeb30066fe787e966aa412b
SHA2567319e1de55e5edad8d7744ef209a8c97e8a20f9da39216f21d70675f39ecd2b0
SHA51279dca6bd573bfa7891f0073c6e5a732c6e194c2f51a974b2248efda651f24975a2bb3eea7e03ae7fd2c5a989497fabd02eebc0bed72a98da0c245cdf1e2d0d81
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NPBB818\VisbyRoundCF-DemiBold-317879fb[1].woffFilesize
36KB
MD59c28846c2b76bfa720f5535d28edcff5
SHA1e777874cb15fe1827bcaaea74e2ee081dd65a423
SHA256317879fb3542917376006438c919ac8367cb07ab69357310cdbe2f3c24471a8a
SHA512dd2840182a4f4eb4dea16203f0011063145fb5e9268958248f019e64be095819bc99d3e39a9bf039b44f6c19aa64535df45ac35fb60cdd85ab84ade7afa4682a
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5OCCPTL4\BitCheats_logo[1].pngFilesize
74KB
MD5505b0c2ddb254c6318a0b00a0b728c36
SHA1fd75db8f370d236d1838bf1a4548423b3f46bc3e
SHA256ad3ac18390aa15a075ae2f9e8d5e6e1d46fb37f9595c8dd3388d174ba2fcda69
SHA512e8e1b8e1264304e11e60a33b74440eb5a903b3a097f611ea755723e79704c39d7152b0f0a62f4e611db8b14b4515f0c7a51aed5803792a3594d0bac585d70a72
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5OCCPTL4\MagmawaveCaps-Bold-db1b8956[1].woffFilesize
9KB
MD5fb90fe844af89afdb577940072e9b17c
SHA17e31b1bb382926407837e441f09828ca359f773e
SHA256db1b8956ded9db97192311360774e69f993ecedbae1c91e01b3035f00640caae
SHA512749db10d4da598f828fc6cbe182e27bdfedd354213c75ba4189d7cd476e06b31f6a513f0779d58674117232e5b29d5b064aafc9cb8af49abc5f41e788e41913e
-
C:\Users\Admin\AppData\Local\Temp\Cab169E.tmpFilesize
65KB
MD5ac05d27423a85adc1622c714f2cb6184
SHA1b0fe2b1abddb97837ea0195be70ab2ff14d43198
SHA256c6456e12e5e53287a547af4103e0397cb9697e466cf75844312dc296d43d144d
SHA5126d0ef9050e41fbae680e0e59dd0f90b6ac7fea5579ef5708b69d5da33a0ece7e8b16574b58b17b64a34cc34a4ffc22b4a62c1ece61f36c4a11a0665e0536b90d
-
C:\Users\Admin\AppData\Local\Temp\Tar179F.tmpFilesize
181KB
MD54ea6026cf93ec6338144661bf1202cd1
SHA1a1dec9044f750ad887935a01430bf49322fbdcb7
SHA2568efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8
SHA5126c7e0980e39aacf4c3689802353f464a08cd17753bd210ee997e5f2a455deb4f287a9ef74d84579dbde49bc96213cd2b8b247723919c412ea980aa6e6bfe218b
-
C:\Users\Admin\AppData\Local\Temp\~DF2E95D7ED2016F719.TMPFilesize
16KB
MD583b7eb6488118b651e677235e11cfe39
SHA17187222658b6a4c2ee2b18599a74a90d09cb774b
SHA25690d60b150ab20c05ad84cc48fbb18959f5aa127eb98f04f8fb1751c18c0c071a
SHA5120d537cca04853cfd07162ca248c1c3b0387bbc71ea9858275e5a920272686ce928c4e17e4b81bfc3e3134457ba2a29aa55b7632871518d82a1976e2b3dc2be09
-
memory/2240-5-0x000000013F5B0000-0x000000013FCD4000-memory.dmpFilesize
7.1MB
-
memory/2240-1074-0x000000013F5B0000-0x000000013FCD4000-memory.dmpFilesize
7.1MB
-
memory/2240-6-0x000000013F5B0000-0x000000013FCD4000-memory.dmpFilesize
7.1MB
-
memory/2240-3-0x000000013F5B0000-0x000000013FCD4000-memory.dmpFilesize
7.1MB
-
memory/2240-4-0x000000013F5B0000-0x000000013FCD4000-memory.dmpFilesize
7.1MB
-
memory/2240-2-0x000000013F5B0000-0x000000013FCD4000-memory.dmpFilesize
7.1MB
-
memory/2240-1-0x0000000076DA0000-0x0000000076DA2000-memory.dmpFilesize
8KB
-
memory/2240-1059-0x000000013F5B0000-0x000000013FCD4000-memory.dmpFilesize
7.1MB
-
memory/2240-0-0x000000013F5B0000-0x000000013FCD4000-memory.dmpFilesize
7.1MB