Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'WindowsUpdateCheck' = '<Full path to file>'
- %HOMEPATH%\start menu\programs\startup\.d0169387eb562c92b2d5
- <Drive name for removable media>:\.d0169387eb562c92b2d5
- <Drive name for removable media>:\wrar520.exe
- <Drive name for removable media>:\fi51.doc
- <Drive name for removable media>:\lisp_success.doc
- <Drive name for removable media>:\ovp25012015.doc
- <Drive name for removable media>:\applicantform_en.doc
- <Drive name for removable media>:\february_catalogue__2015.doc
- <Drive name for removable media>:\contoso.cer
- <Drive name for removable media>:\tcm851ax32.exe
- <Drive name for removable media>:\contosoroot_1.cer
- <Drive name for removable media>:\testee.cer
- <Drive name for removable media>:\sdkfailsafeemulator.cer
- <Drive name for removable media>:\testcertificate.cer
- <Drive name for removable media>:\dashborder_144.bmp
- <Drive name for removable media>:\dialmap.bmp
- <Drive name for removable media>:\000814251_video_01.avi
- <Drive name for removable media>:\join.avi
- <Drive name for removable media>:\sdksampleprivdeveloper.cer
- <Drive name for removable media>:\skypesetup.exe
- Windows Defender
- %ALLUSERSPROFILE%\local\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\programs\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\opera software\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\mozilla\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\microsoft help\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\microsoft\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\gdipfontcachev1.dat.systems32x
- %HOMEPATH%\local settings\iconcache.db.systems32x
- %HOMEPATH%\local settings\history\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\google\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\cef\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\applicationhistory\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\adobe\.d0169387eb562c92b2d5
- %HOMEPATH%\recent\automaticdestinations\7e4dca80246863e3.automaticdestinations-ms.systems32x
- %HOMEPATH%\local settings\<INETFILES>\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\steam\.d0169387eb562c92b2d5
- %HOMEPATH%\recent\automaticdestinations\1b4dd67f29cb1962.automaticdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\c312e260e424ae76.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\how to back your files.txt
- %HOMEPATH%\recent\customdestinations\bf8efb871eda5262.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\969252ce11249fdd.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\9027fe24326910d2.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\7e4dca80246863e3.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\74d7f43c1561fc1e.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\5d696d521de238c3.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\5afe4de1b92fc382.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\590aee7bdd69b59b.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\1b4dd67f29cb1962.customdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\28c8b86deab549a1.customdestinations-ms.systems32x
- %HOMEPATH%\recent\automaticdestinations\how to back your files.txt
- %HOMEPATH%\favorites\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\e\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\d\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\c\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\b\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\a\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\9\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\8\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\7\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\6\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\5\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\4\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\3\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\2\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\1\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\0\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache2\entries\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache2\doomed\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\startupcache\startupcache.4.little.systems32x
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\startupcache\how to back your files.txt
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\_cache_clean_.systems32x
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\how to back your files.txt
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\startupcache\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache2\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\updates\8216c80c92c4e828\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\updates\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\how to back your files.txt
- %HOMEPATH%\recent\customdestinations\10a2479c877ca098.customdestinations-ms.systems32x
- %HOMEPATH%\recent\automaticdestinations\74d7f43c1561fc1e.automaticdestinations-ms.systems32x
- %HOMEPATH%\recent\customdestinations\.d0169387eb562c92b2d5
- %HOMEPATH%\recent\automaticdestinations\.d0169387eb562c92b2d5
- %HOMEPATH%\searches\how to back your files.txt
- C:\perflogs\.d0169387eb562c92b2d5
- %HOMEPATH%\cookies\.d0169387eb562c92b2d5
- %HOMEPATH%\contacts\.d0169387eb562c92b2d5
- %HOMEPATH%\application data\.d0169387eb562c92b2d5
- %HOMEPATH%\appdata\.d0169387eb562c92b2d5
- %HOMEPATH%\.d0169387eb562c92b2d5
- C:\users\public\.d0169387eb562c92b2d5
- C:\users\default\.d0169387eb562c92b2d5
- C:\totalcmd\.d0169387eb562c92b2d5
- C:\system volume information\.d0169387eb562c92b2d5
- C:\recovery\.d0169387eb562c92b2d5
- %ALLUSERSPROFILE%\.d0169387eb562c92b2d5
- %ProgramFiles(x86)%\.d0169387eb562c92b2d5
- %ProgramFiles%\.d0169387eb562c92b2d5
- C:\msocache\.d0169387eb562c92b2d5
- %HOMEPATH%\documents\.d0169387eb562c92b2d5
- C:\far2\.d0169387eb562c92b2d5
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\.d0169387eb562c92b2d5
- C:\documents and settings\.d0169387eb562c92b2d5
- <Current directory>\.d0169387eb562c92b2d5
- C:\$recycle.bin\.d0169387eb562c92b2d5
- D:\system volume information\.d0169387eb562c92b2d5
- D:\$recycle.bin\.d0169387eb562c92b2d5
- z:\system volume information\.d0169387eb562c92b2d5
- C:\.d0169387eb562c92b2d5
- D:\.d0169387eb562c92b2d5
- z:\.d0169387eb562c92b2d5
- <Current directory>\ids.txt
- %ALLUSERSPROFILE%\share\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\_cache_001_.systems32x
- %HOMEPATH%\local settings\virtualstore\.d0169387eb562c92b2d5
- %HOMEPATH%\downloads\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\.d0169387eb562c92b2d5
- %HOMEPATH%\desktop\.d0169387eb562c92b2d5
- %HOMEPATH%\sendto\mail recipient.mapimail.systems32x
- %HOMEPATH%\sendto\how to back your files.txt
- %HOMEPATH%\sendto\desktop (create shortcut).desklink.systems32x
- %HOMEPATH%\sendto\compressed (zipped) folder.zfsendtotarget.systems32x
- %HOMEPATH%\start menu\programs\accessories\system tools\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\accessories\accessibility\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\winrar\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\total commander\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\telegram desktop\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\maintenance\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\mail.ru\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\icq\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\administrative tools\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\accessories\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\.d0169387eb562c92b2d5
- %HOMEPATH%\how to back your files.txt
- %HOMEPATH%\voip\.d0169387eb562c92b2d5
- %HOMEPATH%\videos\.d0169387eb562c92b2d5
- %HOMEPATH%\templates\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\.d0169387eb562c92b2d5
- %HOMEPATH%\sendto\.d0169387eb562c92b2d5
- %HOMEPATH%\searches\.d0169387eb562c92b2d5
- %HOMEPATH%\saved games\.d0169387eb562c92b2d5
- %HOMEPATH%\recent\.d0169387eb562c92b2d5
- %HOMEPATH%\printhood\.d0169387eb562c92b2d5
- %HOMEPATH%\pictures\.d0169387eb562c92b2d5
- %HOMEPATH%\nethood\.d0169387eb562c92b2d5
- %HOMEPATH%\music\.d0169387eb562c92b2d5
- %HOMEPATH%\links\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\_cache_002_.systems32x
- %ALLUSERSPROFILE%\local\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\steam\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\programs\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\opera software\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\mozilla\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\microsoft help\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\microsoft\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\history\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\google\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\cef\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\applicationhistory\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\adobe\.d0169387eb562c92b2d5
- %HOMEPATH%\recent\customdestinations\.d0169387eb562c92b2d5
- %HOMEPATH%\recent\automaticdestinations\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\accessories\system tools\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\accessories\accessibility\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\winrar\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\total commander\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\telegram desktop\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\startup\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\maintenance\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\mail.ru\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\<INETFILES>\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\virtualstore\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\d\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\c\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\b\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\a\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\9\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\8\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\7\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\6\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\5\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\4\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\3\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\2\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\1\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\0\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache2\entries\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache2\doomed\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\startupcache\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache2\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\updates\8216c80c92c4e828\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\updates\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\icq\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\administrative tools\.d0169387eb562c92b2d5
- C:\users\public\.d0169387eb562c92b2d5
- C:\totalcmd\.d0169387eb562c92b2d5
- C:\system volume information\.d0169387eb562c92b2d5
- C:\recovery\.d0169387eb562c92b2d5
- %ALLUSERSPROFILE%\.d0169387eb562c92b2d5
- %ProgramFiles(x86)%\.d0169387eb562c92b2d5
- %ProgramFiles%\.d0169387eb562c92b2d5
- C:\perflogs\.d0169387eb562c92b2d5
- C:\msocache\.d0169387eb562c92b2d5
- C:\far2\.d0169387eb562c92b2d5
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\.d0169387eb562c92b2d5
- C:\documents and settings\.d0169387eb562c92b2d5
- <Current directory>\.d0169387eb562c92b2d5
- C:\$recycle.bin\.d0169387eb562c92b2d5
- D:\system volume information\.d0169387eb562c92b2d5
- D:\$recycle.bin\.d0169387eb562c92b2d5
- z:\system volume information\.d0169387eb562c92b2d5
- C:\.d0169387eb562c92b2d5
- D:\.d0169387eb562c92b2d5
- <Drive name for removable media>:\.d0169387eb562c92b2d5
- z:\.d0169387eb562c92b2d5
- %ALLUSERSPROFILE%\share\.d0169387eb562c92b2d5
- C:\users\default\.d0169387eb562c92b2d5
- %HOMEPATH%\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\.d0169387eb562c92b2d5
- %HOMEPATH%\appdata\.d0169387eb562c92b2d5
- %HOMEPATH%\voip\.d0169387eb562c92b2d5
- %HOMEPATH%\videos\.d0169387eb562c92b2d5
- %HOMEPATH%\templates\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\.d0169387eb562c92b2d5
- %HOMEPATH%\sendto\.d0169387eb562c92b2d5
- %HOMEPATH%\searches\.d0169387eb562c92b2d5
- %HOMEPATH%\saved games\.d0169387eb562c92b2d5
- %HOMEPATH%\recent\.d0169387eb562c92b2d5
- %HOMEPATH%\printhood\.d0169387eb562c92b2d5
- %HOMEPATH%\pictures\.d0169387eb562c92b2d5
- %HOMEPATH%\nethood\.d0169387eb562c92b2d5
- %HOMEPATH%\music\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\.d0169387eb562c92b2d5
- %HOMEPATH%\links\.d0169387eb562c92b2d5
- %HOMEPATH%\favorites\.d0169387eb562c92b2d5
- %HOMEPATH%\downloads\.d0169387eb562c92b2d5
- %HOMEPATH%\documents\.d0169387eb562c92b2d5
- %HOMEPATH%\desktop\.d0169387eb562c92b2d5
- %HOMEPATH%\cookies\.d0169387eb562c92b2d5
- %HOMEPATH%\contacts\.d0169387eb562c92b2d5
- %HOMEPATH%\application data\.d0169387eb562c92b2d5
- %HOMEPATH%\start menu\programs\accessories\.d0169387eb562c92b2d5
- %HOMEPATH%\local settings\thunderbird\profiles\wjj9aet2.default\cache\e\.d0169387eb562c92b2d5