HKU\.DEFAULT\...\Winlogon: [Shell] C:\ProgramData\lcaun\xcokxkc.exe,explorer.exe
HKU\S-1-5-21-293356991-225826379-2249491693-1000\...\Winlogon: [Shell] C:\ProgramData\lcaun\xcokxkc.exe,explorer.exe
C:\Users\ADA\AppData\Local\Temp\Quarantine.exe
C:\ProgramData\ypgywxh
C:\ProgramData\pkcx
C:\ProgramData\xptnsdg
C:\ProgramData\fruxhv
C:\ProgramData\cotbpks
C:\ProgramData\almagsi
C:\ProgramData\udijbu
C:\ProgramData\ofk
C:\ProgramData\lcaun
C:\Users\ADA\AppData\Roaming\Wipclhqbvc
C:\ProgramData\bmwpr
C:\Users\ADA\AppData\Local\Tmfrjxvbu