Technical Information
- %ALLUSERSPROFILE%
- %APPDATA%\microsoft\uproof
- %APPDATA%\microsoft\windows\cookies\low
- %APPDATA%\microsoft\windows\iecompatcache
- %APPDATA%\microsoft\windows\ietldcache
- %APPDATA%\microsoft\windows\libraries
- %APPDATA%\microsoft\windows\network shortcuts
- %APPDATA%\microsoft\windows\printer shortcuts
- %APPDATA%\microsoft\windows\privacie
- %APPDATA%\microsoft\windows\recent
- %APPDATA%\microsoft\windows\sendto
- %APPDATA%\microsoft\windows\start menu
- %APPDATA%\microsoft\windows\templates
- %APPDATA%\microsoft\windows\themes
- %APPDATA%\microsoft\word
- %APPDATA%\mozilla\extensions
- %APPDATA%\microsoft\templates
- %APPDATA%\macromedia
- %APPDATA%\microsoft\systemcertificates
- %APPDATA%\microsoft\publisher building blocks
- %APPDATA%\media center programs
- %APPDATA%\microsoft\addins
- %APPDATA%\microsoft\crypto
- %APPDATA%\microsoft\dbgclr
- %APPDATA%\microsoft\document building blocks
- %APPDATA%\microsoft\excel
- %APPDATA%\microsoft\internet explorer
- %APPDATA%\microsoft\mmc
- %APPDATA%\microsoft\msdn
- %APPDATA%\microsoft\network
- %APPDATA%\microsoft\office
- %APPDATA%\microsoft\powerpoint
- %APPDATA%\microsoft\proof
- %APPDATA%\microsoft\protect
- %APPDATA%\microsoft\publisher
- %APPDATA%\microsoft\speech
- %APPDATA%\mail.ru
- %APPDATA%\mozilla\firefox\crash reports
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\gmp
- %HOMEPATH%\downloads
- %HOMEPATH%\links
- %HOMEPATH%\local settings
- %HOMEPATH%\music
- %HOMEPATH%\my documents
- %HOMEPATH%\nethood
- %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\offlinecache
- %HOMEPATH%\pictures
- %HOMEPATH%\recent
- %HOMEPATH%\saved games
- %HOMEPATH%\searches
- %HOMEPATH%\sendto
- %HOMEPATH%\start menu
- %HOMEPATH%\templates
- %HOMEPATH%\cookies
- %HOMEPATH%\documents
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\crashes
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\bookmarkbackups
- %APPDATA%\mirc
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\gmp-gmpopenh264
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\healthreport
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\minidumps
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\sessionstore-backups
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\storage
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\webapps
- %APPDATA%\mra
- %APPDATA%\opera software
- %APPDATA%\qip
- %APPDATA%\qipguard
- %APPDATA%\telegram desktop
- %APPDATA%\thunderbird
- %APPDATA%\winamp
- %HOMEPATH%\application data
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\datareporting
- %HOMEPATH%\contacts
- %APPDATA%\identities
- %APPDATA%\icqm
- %APPDATA%\icq-profile
- %LOCALAPPDATA%\microsoft\msdn
- %LOCALAPPDATA%\microsoft\media player
- %LOCALAPPDATA%\microsoft\office
- %LOCALAPPDATA%\microsoft\publisher
- %LOCALAPPDATA%\microsoft\taskschedulerconfig
- %LOCALAPPDATA%\microsoft\windows\1024
- %LOCALAPPDATA%\microsoft\windows\1033
- %LOCALAPPDATA%\microsoft\windows\burn
- %LOCALAPPDATA%\microsoft\windows\gameexplorer
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012015112320151124
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012016081820160819
- %LOCALAPPDATA%\microsoft\windows\history\low
- %LOCALAPPDATA%\microsoft\windows\ringtones
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9
- %LOCALAPPDATA%\microsoft\internet explorer\domstore
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke
- %LOCALAPPDATA%\microsoft\feeds cache\evw7z7yu
- %LOCALAPPDATA%\microsoft\feeds cache\dp0qcmsh
- C:\users\default
- C:\users\default user
- C:\users\public
- %LOCALAPPDATA%\adobe
- %LOCALAPPDATA%\application data
- %LOCALAPPDATA%\applicationhistory
- %LOCALAPPDATA%\cef
- %LOCALAPPDATA%\google
- %LOCALAPPDATA%\history
- %LOCALAPPDATA%\microsoft\dbgclr
- %LOCALAPPDATA%\microsoft\device metadata
- %LOCALAPPDATA%\microsoft\event viewer
- %LOCALAPPDATA%\microsoft\feeds\feeds for united states~
- %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~
- %LOCALAPPDATA%\microsoft\feeds cache\3v2zgiw9
- %LOCALAPPDATA%\microsoft\feeds cache\e6k79x6b
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl
- %LOCALAPPDATA%\microsoft\internet explorer\recovery\high\last active
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr
- %TEMP%\temp1_fp_13.0.0.182_archive.zip
- %TEMP%\webinstaller
- %TEMP%\acrord32_sbx
- %TEMP%\hsperfdata_user
- %TEMP%\lilo.1516
- %LOCALAPPDATA%\<INETFILES>
- %LOCALAPPDATA%\thunderbird
- %LOCALAPPDATA%\virtualstore
- %LOCALAPPDATA%low\adobe
- %LOCALAPPDATA%low\microsoft\internet explorer
- %LOCALAPPDATA%low\oracle
- %LOCALAPPDATA%low\sun
- %APPDATA%\adobe
- %APPDATA%\ghisler
- %TEMP%\opera installer
- %TEMP%\low
- %TEMP%\wpdnse
- %TEMP%\microsoft visual c++ 2010 x86 redistributable setup_10.0.30319
- %TEMP%\adobe_admlogs
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.mra.images
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\virtualized
- %LOCALAPPDATA%\microsoft\windows mail
- %LOCALAPPDATA%\microsoft\windows media
- %LOCALAPPDATA%\microsoft\windows sidebar
- %HOMEPATH%\videos
- %HOMEPATH%\printhood
- %LOCALAPPDATA%\microsoft help
- %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\safebrowsing
- %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\thumbnails
- %LOCALAPPDATA%\mozilla\updates
- %LOCALAPPDATA%\opera software
- %LOCALAPPDATA%\programs
- %LOCALAPPDATA%\steam
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.mso
- %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2
- %HOMEPATH%\voip
- %ALLUSERSPROFILE%
- %APPDATA%\microsoft\uproof
- %APPDATA%\microsoft\windows\cookies\low
- %APPDATA%\microsoft\windows\iecompatcache
- %APPDATA%\microsoft\windows\ietldcache
- %APPDATA%\microsoft\windows\libraries
- %APPDATA%\microsoft\windows\network shortcuts
- %APPDATA%\microsoft\windows\printer shortcuts
- %APPDATA%\microsoft\windows\privacie
- %APPDATA%\microsoft\windows\recent
- %APPDATA%\microsoft\windows\sendto
- %APPDATA%\microsoft\windows\start menu
- %APPDATA%\microsoft\windows\templates
- %APPDATA%\microsoft\windows\themes
- %APPDATA%\microsoft\word
- %APPDATA%\mozilla\extensions
- %APPDATA%\microsoft\templates
- %APPDATA%\macromedia
- %APPDATA%\microsoft\systemcertificates
- %APPDATA%\microsoft\publisher building blocks
- %APPDATA%\media center programs
- %APPDATA%\microsoft\addins
- %APPDATA%\microsoft\crypto
- %APPDATA%\microsoft\dbgclr
- %APPDATA%\microsoft\document building blocks
- %APPDATA%\microsoft\excel
- %APPDATA%\microsoft\internet explorer
- %APPDATA%\microsoft\mmc
- %APPDATA%\microsoft\msdn
- %APPDATA%\microsoft\network
- %APPDATA%\microsoft\office
- %APPDATA%\microsoft\powerpoint
- %APPDATA%\microsoft\proof
- %APPDATA%\microsoft\protect
- %APPDATA%\microsoft\publisher
- %APPDATA%\microsoft\speech
- %APPDATA%\mail.ru
- %APPDATA%\mozilla\firefox\crash reports
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\gmp
- %HOMEPATH%\downloads
- %HOMEPATH%\links
- %HOMEPATH%\local settings
- %HOMEPATH%\music
- %HOMEPATH%\my documents
- %HOMEPATH%\nethood
- %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\offlinecache
- %HOMEPATH%\pictures
- %HOMEPATH%\recent
- %HOMEPATH%\saved games
- %HOMEPATH%\searches
- %HOMEPATH%\sendto
- %HOMEPATH%\start menu
- %HOMEPATH%\templates
- %HOMEPATH%\cookies
- %HOMEPATH%\documents
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\crashes
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\bookmarkbackups
- %APPDATA%\mirc
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\gmp-gmpopenh264
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\healthreport
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\minidumps
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\sessionstore-backups
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\storage
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\webapps
- %APPDATA%\mra
- %APPDATA%\opera software
- %APPDATA%\qip
- %APPDATA%\qipguard
- %APPDATA%\telegram desktop
- %APPDATA%\thunderbird
- %APPDATA%\winamp
- %HOMEPATH%\application data
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\datareporting
- %HOMEPATH%\contacts
- %APPDATA%\identities
- %APPDATA%\icqm
- %APPDATA%\icq-profile
- %LOCALAPPDATA%\microsoft\msdn
- %LOCALAPPDATA%\microsoft\media player
- %LOCALAPPDATA%\microsoft\office
- %LOCALAPPDATA%\microsoft\publisher
- %LOCALAPPDATA%\microsoft\taskschedulerconfig
- %LOCALAPPDATA%\microsoft\windows\1024
- %LOCALAPPDATA%\microsoft\windows\1033
- %LOCALAPPDATA%\microsoft\windows\burn
- %LOCALAPPDATA%\microsoft\windows\gameexplorer
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012015112320151124
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012016081820160819
- %LOCALAPPDATA%\microsoft\windows\history\low
- %LOCALAPPDATA%\microsoft\windows\ringtones
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9
- %LOCALAPPDATA%\microsoft\internet explorer\domstore
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke
- %LOCALAPPDATA%\microsoft\feeds cache\evw7z7yu
- %LOCALAPPDATA%\microsoft\feeds cache\dp0qcmsh
- C:\users\default
- C:\users\default user
- C:\users\public
- %LOCALAPPDATA%\adobe
- %LOCALAPPDATA%\application data
- %LOCALAPPDATA%\applicationhistory
- %LOCALAPPDATA%\cef
- %LOCALAPPDATA%\google
- %LOCALAPPDATA%\history
- %LOCALAPPDATA%\microsoft\dbgclr
- %LOCALAPPDATA%\microsoft\device metadata
- %LOCALAPPDATA%\microsoft\event viewer
- %LOCALAPPDATA%\microsoft\feeds\feeds for united states~
- %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~
- %LOCALAPPDATA%\microsoft\feeds cache\3v2zgiw9
- %LOCALAPPDATA%\microsoft\feeds cache\e6k79x6b
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl
- %LOCALAPPDATA%\microsoft\internet explorer\recovery\high\last active
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr
- %TEMP%\temp1_fp_13.0.0.182_archive.zip
- %TEMP%\webinstaller
- %TEMP%\acrord32_sbx
- %TEMP%\hsperfdata_user
- %TEMP%\lilo.1516
- %LOCALAPPDATA%\<INETFILES>
- %LOCALAPPDATA%\thunderbird
- %LOCALAPPDATA%\virtualstore
- %LOCALAPPDATA%low\adobe
- %LOCALAPPDATA%low\microsoft\internet explorer
- %LOCALAPPDATA%low\oracle
- %LOCALAPPDATA%low\sun
- %APPDATA%\adobe
- %APPDATA%\ghisler
- %TEMP%\opera installer
- %TEMP%\low
- %TEMP%\wpdnse
- %TEMP%\microsoft visual c++ 2010 x86 redistributable setup_10.0.30319
- %TEMP%\adobe_admlogs
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.mra.images
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\virtualized
- %LOCALAPPDATA%\microsoft\windows mail
- %LOCALAPPDATA%\microsoft\windows media
- %LOCALAPPDATA%\microsoft\windows sidebar
- %HOMEPATH%\videos
- %HOMEPATH%\printhood
- %LOCALAPPDATA%\microsoft help
- %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\safebrowsing
- %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\thumbnails
- %LOCALAPPDATA%\mozilla\updates
- %LOCALAPPDATA%\opera software
- %LOCALAPPDATA%\programs
- %LOCALAPPDATA%\steam
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.mso
- %LOCALAPPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cache2
- %HOMEPATH%\voip
- %LOCALAPPDATA%\microsoft\feeds\feedsstore.feedsdb-ms
- %LOCALAPPDATA%\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Suggested Sites~.feed-ms
- %LOCALAPPDATA%\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms
- %TEMP%\fxsapidebuglogfile.txt
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\content-prefs.sqlite
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cookies.sqlite
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cookies.sqlite-wal
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\formhistory.sqlite
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\permissions.sqlite
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\places.sqlite
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\places.sqlite-wal
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\webappsstore.sqlite
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\webappsstore.sqlite-wal
- %TEMP%\mirc741.exe
- %TEMP%\ose00000.exe
- %TEMP%\ose00001.exe
- %HOMEPATH%\Desktop\calc.exe
- %HOMEPATH%\Desktop\notepad.exe
- %HOMEPATH%\Desktop\utorrent.exe
- C:\Users\desktop.ini
- %APPDATA%\Microsoft\Windows\Cookies\user@mozilla[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@demdex[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@c.msn[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@c.msn[1].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@c.bing[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@c.bing[1].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@bing[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@bing[1].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@adobe[3].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@adobe[1].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@adnxs[1].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@246059135.log.optimizely[1].txt
- %TEMP%\wmsetup.log
- %TEMP%\wallpaper.bmp
- %TEMP%\user.bmp
- %TEMP%\opera_crashreporter.log
- %TEMP%\jusched.log
- %TEMP%\jawshtml.html
- %TEMP%\dotNetFxSDK.log
- %TEMP%\dotNetFx.log
- %TEMP%\dd_wcf_CA_smci_20200611_031101_060.txt
- %TEMP%\dd_wcf_CA_smci_20200611_031056_919.txt
- %TEMP%\dd_wcf_CA_smci_20151217_052908_497.txt
- %TEMP%\dd_wcf_CA_smci_20151217_052858_840.txt
- %TEMP%\dd_vcredist_x86_20151216210157_001_vcRuntimeAdditional_x86.log
- %TEMP%\dd_vcredist_x86_20151216210157_000_vcRuntimeMinimum_x86.log
- %TEMP%\dd_vcredist_x86_20151216210157.log
- %TEMP%\dd_vcredist_amd64_20151216210341_000_vcRuntimeMinimum_x64.log
- %TEMP%\dd_vcredist_amd64_20151216210341_001_vcRuntimeAdditional_x64.log
- %APPDATA%\Microsoft\Windows\Cookies\user@msn[1].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@msn[2].txt
- %HOMEPATH%\Desktop\Total Commander 64 bit.lnk
- %HOMEPATH%\Desktop\Telegram.lnk
- %HOMEPATH%\Desktop\QIP 2012.lnk
- %HOMEPATH%\Desktop\Mail.Ru Agent.lnk
- %HOMEPATH%\Desktop\ICQ.lnk
- %APPDATA%\Mozilla\Firefox\profiles.ini
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\xulstore.json
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\user.js
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\times.json
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\sessionCheckpoints.json
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\search.json
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\revocations.txt
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\prefs.js
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\extensions.json
- %TEMP%\Microsoft .NET Framework 4.5 Setup_20150506_155317844.html
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\extensions.ini
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\compatibility.ini
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\addons.json
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\SiteSecurityServiceState.txt
- %APPDATA%\Microsoft\Windows\Cookies\user@yandex[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@yandex[1].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@www.msn[3].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@www.msn[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@www.bing[1].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@sportiv[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@scorecardresearch[3].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@scorecardresearch[2].txt
- %APPDATA%\Microsoft\Windows\Cookies\user@onlinestores.metaservices.microsoft[1].txt
- %TEMP%\dd_vcredist_amd64_20151216210341.log
- %TEMP%\dd_SetupUtility.txt
- %TEMP%\dd_NDP471-KB4033342-x86-x64-AllOS-ENU_decompression_log.txt
- %TEMP%\ASPNETSetup_00003.log
- %TEMP%\ASPNETSetup_00002.log
- %TEMP%\ASPNETSetup_00001.log
- %TEMP%\ASPNETSetup_00000.log
- %TEMP%\ASPNETSetup.log
- %LOCALAPPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\directoryLinks.json
- %LOCALAPPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\_CACHE_CLEAN_
- %LOCALAPPDATA%\Microsoft\Windows\<INETFILES>\desktop.ini
- %LOCALAPPDATA%\Microsoft\Windows\<INETFILES>\Content.IE5\desktop.ini
- %LOCALAPPDATA%\Microsoft\Windows\History\desktop.ini
- %LOCALAPPDATA%\Microsoft\Windows\History\History.IE5\desktop.ini
- %LOCALAPPDATA%\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl
- %LOCALAPPDATA%\Microsoft\Windows\Explorer\ExplorerStartupLog.etl
- %LOCALAPPDATA%\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000004c.db
- %LOCALAPPDATA%\Microsoft\Windows\Caches\cversions.1.db
- %LOCALAPPDATA%\Microsoft\Internet Explorer\tabiconcache.dat
- %LOCALAPPDATA%\Microsoft\Internet Explorer\frameiconcache.dat
- %LOCALAPPDATA%\Microsoft\Internet Explorer\brndlog.txt
- %LOCALAPPDATA%\Microsoft\Internet Explorer\brndlog.bak
- %LOCALAPPDATA%\Microsoft\Internet Explorer\Recovery\High\Active\{8E55D4ED-921A-11E5-B42A-080027FCB322}.dat
- %LOCALAPPDATA%\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{8E55D4EC-921A-11E5-B42A-080027FCB322}.dat
- %LOCALAPPDATA%\Microsoft\Internet Explorer\MSIMGSIZ.DAT
- %LOCALAPPDATA%\Microsoft\Feeds Cache\desktop.ini
- %HOMEPATH%\Favorites\Links\desktop.ini
- %HOMEPATH%\Favorites\desktop.ini
- %LOCALAPPDATA%\GDIPFONTCACHEV1.DAT
- %TEMP%\AdobeARM_NotLocked.log
- %TEMP%\AdobeSFX.log
- %TEMP%\AdobeARM.log
- %TEMP%\CProgram Files (x86)Opera29.0.1795.47opera_autoupdate.download.lock
- %TEMP%\dd_NDP452-KB2901907-x86-x64-AllOS-ENU_decompression_log.txt
- %TEMP%\CProgram Files (x86)Opera29.0.1795.47opera_autoupdate.metrics.lock
- %TEMP%\SetupExe(20160310140634718).log
- %TEMP%\SetupExe(201603101200226DC).log
- %TEMP%\SetupExe(20151124155624744).log
- %TEMP%\RGIE195.tmp-tmp
- %TEMP%\RGIE195.tmp
- %TEMP%\RGI8564.tmp-tmp
- %TEMP%\RGI8564.tmp
- %TEMP%\Microsoft Visual C++ 2010 x86 Redistributable Setup_20150506_155226438.html
- %TEMP%\Microsoft .NET Framework 4.7.1 Setup_20200610_200621826.html
- %TEMP%\Microsoft .NET Framework 4.7.1 Setup_20200610_200621826-MSI_netfx_Full_x64.msi.txt
- %TEMP%\Microsoft .NET Framework 4.7.1 Setup_20200610_195959602.html
- %TEMP%\Microsoft .NET Framework 4.5.2 Setup_20151216_212237215.html
- %APPDATA%\Mozilla\Firefox\Profiles\gn7ryp3k.default\healthreport.sqlite
- %HOMEPATH%\Desktop\desktop.ini
- %TEMP%\MSIeb217.LOG
- %TEMP%\MSIe45bf.LOG
- %TEMP%\MSId38c.LOG
- %TEMP%\MSIc204f.LOG
- %TEMP%\MSI1cfbe.LOG
- %TEMP%\JavaDeployReg.log
- %TEMP%\CVRF2A3.tmp.cvr
- %TEMP%\CVREAF2.tmp.cvr
- %TEMP%\CVRDE7F.tmp.cvr
- %TEMP%\CVRC867.tmp.cvr
- %TEMP%\CVRBADA.tmp.cvr
- %TEMP%\CVR6D44.tmp.cvr
- %TEMP%\CVR6B9C.tmp.cvr
- %TEMP%\Microsoft .NET Framework 4.5.2 Setup_20151216_212237215-MSI_netfx_Full_GDR_x64.msi.txt
- %HOMEPATH%\ntuser.pol