%TMP%\restoro-service-uninstall.log
new file created
%ALLUSERSPROFILE%\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NGC_22.20.5.39\BASH\BHLinks.db-journal
new file created
%SystemDrive%\Users\ADMINI~1\AppData\Local\Temp\nsh5E27.tmp
new file created
%SystemDrive%\Users\ADMINI~1\AppData\Local\Temp\nsm5EE2.tmp
new file created
%TMP%\nsm5EE3.tmp
new file created
%TMP%\nsm5EE3.tmp
new catalogue created
%TMP%\nsm5EE3.tmp\System.dll
new file created
%TMP%\nsm5EE3.tmp\rCrypt.dll
new file created
%TMP%\nsqE806.tmp
new file created
%TMP%\nsm5EE3.tmp\LogEx.dll
new file created
%TMP%\nsbE97D.tmp
new file created
%TMP%\nsm5EE3.tmp\nsExec.dll
new file created
%TMP%\nsbE97E.tmp
new file created
%TMP%\nsbE97E.tmp
new catalogue created
%TMP%\nsbE97E.tmp\System.dll
new file created
%TMP%\nsbE97E.tmp\rCrypt.dll
new file created
%TMP%\nsbE97E.tmp\LogEx.dll
new file created
%TMP%\nsdBFB.tmp
new file created
%TMP%\nsbE97E.tmp\nsExec.dll
new file created
%TMP%\nsyDB0.tmp
new file created
%TMP%\nsoDC1.tmp
new file created
%TMP%\nsoDC1.tmp
new catalogue created
%TMP%\nsoDC1.tmp\System.dll
new file created
%SystemDrive%\Users\ASUSI3~1\AppData\Local\Temp\nsnF43A.tmp\System.dll
new file created
%TMP%\nsoDC1.tmp\rCrypt.dll
new file created
%SystemDrive%\Users\ASUSI3~1\AppData\Local\Temp\nsnF43A.tmp\LogEx.dll
new file created
%TMP%\nsoDC1.tmp\LogEx.dll
new file created
%USERPROFILE%\AppData\Local\Temp\nso73F0.tmp
new file created
%SystemDrive%\Users\ASUSI3~1\AppData\Local\Temp\nsnF43A.tmp\nsExec.dll
new file created
%TMP%\nsoDC1.tmp\nsExec.dll
new file created
%USERPROFILE%\AppData\Local\Temp\~nsu.tmp\Bu_.exe
new file created
%USERPROFILE%\AppData\Local\Temp\nsu7548.tmp
new file created
%USERPROFILE%\AppData\Local\Temp\nsj7558.tmp
new file created
%USERPROFILE%\AppData\Local\Temp\nsj7558.tmp
new catalogue created
%USERPROFILE%\AppData\Local\Temp\nsj7558.tmp\System.dll
new file created
%USERPROFILE%\AppData\Local\Temp\nsj7558.tmp\rCrypt.dll
new file created
%USERPROFILE%\AppData\Local\Temp\nsj7558.tmp\LogEx.dll
new file created
%USERPROFILE%\AppData\Local\Temp\restoro-service-uninstall.log
new file created
%USERPROFILE%\AppData\Local\Temp\nsj7558.tmp\nsExec.dll
new file created
%SystemDrive%\Users\WIN10~1\AppData\Local\Temp\nsn4301.tmp
new file created
%SystemDrive%\Users\WIN10~1\AppData\Local\Temp\nst43BD.tmp
new file created
%TMP%\nst43BE.tmp
new file created
%TMP%\nst43BE.tmp
new catalogue created
%TMP%\nst43BE.tmp\System.dll
new file created
%TMP%\nst43BE.tmp\rCrypt.dll
new file created
%TMP%\nst43BE.tmp\LogEx.dll
new file created
%TMP%\nst43BE.tmp\nsExec.dll
new file created
%ALLUSERSPROFILE%\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NGC_22.20.5.39\BASH\sdmys_388C682BFB561461E87D968B
file renamed
%TMP%\nsx513F.tmp
new file created
%TMP%\~nsu.tmp\Cu_.exe
new file created
%TMP%\nsp571B.tmp
new file created
%TMP%\nsu573B.tmp
new file created
%TMP%\nsu573B.tmp
new catalogue created
%TMP%\nsu573B.tmp\System.dll
new file created
%TMP%\nsu573B.tmp\rCrypt.dll
new file created
%TMP%\nsu573B.tmp\LogEx.dll
new file created
%TMP%\nsu573B.tmp\nsExec.dll
new file created
%TMP%\nsp79BD.tmp
new file created
%TMP%\nsq7A0C.tmp
new file created
%TMP%\nsf7A1C.tmp
new file created
%TMP%\nsf7A1C.tmp
new catalogue created
%ALLUSERSPROFILE%\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NGC_22.20.4.57\BASH\BHLinks.db-journal
new file created
%TMP%\nsf7A1C.tmp\System.dll
new file created
%ALLUSERSPROFILE%\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NGC_22.20.4.57\BASH\sdmys_E60EB0126E7D12F0FAA3D4A5
file renamed
%TMP%\nsf7A1C.tmp\rCrypt.dll
new file created
%TMP%\nsf7A1C.tmp\LogEx.dll
new file created
%TMP%\nsf7A1C.tmp\nsExec.dll
new file created
%TMP%\nsr7B8B.tmp
new file created
%TMP%\nsm7CA4.tmp
new file created
%TMP%\nsc7CB5.tmp
new file created
%TMP%\nsc7CB5.tmp
new catalogue created
%TMP%\nsc7CB5.tmp\System.dll
new file created
%TMP%\nsc7CB5.tmp\rCrypt.dll
new file created
%TMP%\nsc7CB5.tmp\LogEx.dll
new file created
%SystemDrive%\Users\DERVAT~1\AppData\Local\Temp\nsl5EC.tmp\System.dll
new file created
%SystemDrive%\Users\DERVAT~1\AppData\Local\Temp\nsl5EC.tmp\LogEx.dll
new file created
%SystemDrive%\Users\DERVAT~1\AppData\Local\Temp\nsl5EC.tmp\nsExec.dll
new file created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\B42FAA46FB65E9927C3694A79E772877\155CF1F57ADDA90121BF0AE4EFDD05C0
new registry key created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\B42FAA46FB65E9927C3694A79E772877\155CF1F57ADDA90121BF0AE4EFDD05C0\\Information
new registry key parameter created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18
new registry key created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18\2E84AD9724DC3A3CC01B9A3769B6E0B3
new registry key created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18\2E84AD9724DC3A3CC01B9A3769B6E0B3\\Information
new registry key parameter created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18\922B50FF67F16BB2A01F316CC72FB61B
new registry key created
%TMP%\nsf6739.tmp
new file created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18\922B50FF67F16BB2A01F316CC72FB61B\\Information
new registry key parameter created
%TMP%\nsl697B.tmp
new file created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18\C56C290285D1AD53F2ADACA6BE16E871
new registry key created
%TMP%\nsl697C.tmp
new file created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18\C56C290285D1AD53F2ADACA6BE16E871\\Information
new registry key parameter created
%TMP%\nsl697C.tmp
new catalogue created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18\D05AC4CC2159ECA4540B7BD0BCD33B79
new registry key created
%TMP%\nsl697C.tmp\System.dll
new file created
HKEY_USERS\FILECACHE\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\1AD88A163C9F88DC1FF8DBBE9C1EC637\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\A07189F8BDB340CB710086B025AAFA18\D05AC4CC2159ECA4540B7BD0BCD33B79\\Information
new registry key parameter created
%TMP%\nsl697C.tmp\rCrypt.dll
new file created
%TMP%\nsl697C.tmp\LogEx.dll
new file created
%TMP%\nsl697C.tmp\nsExec.dll
new file created
%ALLUSERSPROFILE%\Trusteer\Rapport\logs\gh_Bu_.852.log
new file created
HKEY_USERS\FileCache\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\7D4C53BF95619E882086738DC7CF81B7\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\B42FAA46FB65E9927C3694A79E772877\155CF1F57ADDA90121BF0AE4EFDD05C0
new registry key created
HKEY_USERS\FileCache\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\7D4C53BF95619E882086738DC7CF81B7\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\B42FAA46FB65E9927C3694A79E772877\155CF1F57ADDA90121BF0AE4EFDD05C0\\Information
new registry key parameter created
HKEY_USERS\FileCache\D9D2D9B03E45617278544E4BC0844BDF\7219027A0FD5ABCA10558F8F96F096C9\35C0D6FB7CF68169D23ECBE2D56BE79A\7D4C53BF95619E882086738DC7CF81B7\994C209F918A35DB828B0AE0DC473A37\ABBD3106BDD9DBE8C073D91B47AFE39E\CC332E39C7CC76BB8BC9AC1EB61ECB4E\FC46FF9020BAB6A19493B3927CBDA535
new registry key created