%AppData%\Local\Temp\vprdh.exe
\Windows\CurrentVersion\Run
C:\Windows\system32\VSSADMIN.EXE Delete Shadows /All /QuietC:\Windows\system32\wbadmin.exe delete systemstatebackup -keepVersions:0 -quietC:\Windows\system32\wbadmin.exe delete backup -keepVersions:0 -quiet
coronaVi2022@protonmail.ch__
cmd.exe /c ping 127.0.0.1 && del C:\temp\kpot.exe