Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Encoder.39171

Added to the Dr.Web virus database: 2024-07-11

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKLM\Software\Classes\EncriptIDfile\Shell\Open\Command] '' = '%WINDIR%\SysWOW64\mshta.exe "%C:\Data recovery.hta"'
Creates the following files on removable media
  • <Drive name for removable media>:\data recovery.hta
  • <Drive name for removable media>:\split.avi
Malicious functions
Reads files which store third party applications passwords
  • %HOMEPATH%\desktop\508softwareandos.doc
  • %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
  • %APPDATA%\mozilla\firefox\profiles.ini
  • %HOMEPATH%\desktop\coffee.bmp
  • %HOMEPATH%\desktop\contosoroot.cer
  • %HOMEPATH%\desktop\cveuropeo.doc
  • %HOMEPATH%\desktop\dashborder_192.bmp
  • %HOMEPATH%\desktop\fi51.doc
  • %HOMEPATH%\desktop\glidescope_review_rev_010.docx
  • %HOMEPATH%\desktop\nwfieldnotes1966.docx
  • %APPDATA%\thunderbird\profiles.ini
  • %HOMEPATH%\desktop\ovp25012015.doc
  • %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
  • %HOMEPATH%\desktop\sdszfo.docx
  • %HOMEPATH%\desktop\thlps_keeper_mayer_1965.docx
Modifies file system
Creates the following files
  • %WINDIR%\delog.cmd
  • %ProgramFiles(x86)%\windows sidebar\gadgets\cpu.gadget\en-us\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\calendar.gadget\en-us\data recovery.hta
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\maintenance\data recovery.hta
  • C:\users\default\appdata\roaming\microsoft\windows\sendto\data recovery.hta
  • C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\multimedia\mpp\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hi\data recovery.hta
  • %ProgramFiles(x86)%\reference assemblies\microsoft\framework\v3.0\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\data recovery.hta
  • %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\data recovery.hta
  • %ProgramFiles(x86)%\reference assemblies\microsoft\framework\v3.5\subsetlist\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\win\data recovery.hta
  • %ProgramFiles(x86)%\reference assemblies\microsoft\framework\v3.0\redistlist\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\data recovery.hta
  • C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\data recovery.hta
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\1033\data recovery.hta
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %ProgramFiles(x86)%\reference assemblies\microsoft\framework\v3.5\redistlist\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_gb\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ar\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ms\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_us\data recovery.hta
  • %ProgramFiles(x86)%\reference assemblies\microsoft\framework\v3.0\subsetlist\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\da\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\currency.gadget\en-us\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\clock.gadget\data recovery.hta
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\rssfeeds.gadget\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\cpu.gadget\images\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\pipeline.v10.0\addinviews\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows mail\stationery\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\rssfeeds.gadget\images\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\rac\statedata\data recovery.hta
  • C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsto\10.0\1033\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extension rules\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{6cd9e9ed-906d-4196-8dc3-f987d2f6615f}v14.29.30133\packages\vcruntimeminimum_amd64\data recovery.hta
  • C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\1033\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\css\data recovery.hta
  • C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\data recovery.hta
  • C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\data recovery.hta
  • C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\data recovery.hta
  • C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform\pmp\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\currency.gadget\data recovery.hta
  • C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\mac\data recovery.hta
  • C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\languagenames2\data recovery.hta
  • %LOCALAPPDATA%\thunderbird\profiles\chdgbv82.default-release\startupcache\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\8.0\x86\data recovery.hta
  • C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %ProgramFiles(x86)%\reference assemblies\microsoft\framework\v3.5\data recovery.hta
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\databases\data recovery.hta
  • %ProgramFiles(x86)%\opera\29.0.1795.47\resources\data recovery.hta
  • %ProgramFiles(x86)%\steam\public\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\gatherlogs\systemindex\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\picturepuzzle.gadget\en-us\js\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\weather.gadget\en-us\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\desktop-connector-files\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-recent-files\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\zh-tw\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-computer\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-computer\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\add-account-select\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\home\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\fr-fr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\nl-nl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\tr-tr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\ca-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\eu-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\pt-br\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\en-ae\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\hr-hr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\el\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\pt-br\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\it-it\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\root\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\zh-cn\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\fi-fi\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\tr-tr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\editpdf\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\es-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-recent-files\js\nls\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\nb-no\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\cs-cz\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\sk-sk\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\en-gb\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\fr-ma\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\cpu.gadget\en-us\js\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\calendar.gadget\en-us\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\it-it\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\slideshow.gadget\images\in_sidebar\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\slideshow.gadget\images\on_desktop\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_cn\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\uk\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\currency.gadget\en-us\js\data recovery.hta
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_tw\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\root\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\slideshow.gadget\en-us\css\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\rssfeeds.gadget\en-us\css\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\cpu.gadget\en-us\css\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\slideshow.gadget\en-us\js\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\calendar.gadget\en-us\css\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\clock.gadget\en-us\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\eu-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\uk-ua\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\sv-se\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\cs-cz\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\pl-pl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\ro-ro\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\hr-hr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\da-dk\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\sl-si\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app-api\dev\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\bg\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\fi-fi\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\sk-sk\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\fr-ma\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\ru-ru\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\images\win-scrollbar\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ko\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_br\data recovery.hta
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0000b025\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1028\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{e699e009-1c3c-4e50-9b57-2b39f0954c7f}v14.29.30133\packages\vcruntimeadditional_amd64\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{ec9807de-b577-47b1-a024-0251805acf24}v14.29.30133\packages\vcruntimeminimum_x86\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\pi_brokers\data recovery.hta
  • %CommonProgramFiles(x86)%\java\java update\data recovery.hta
  • %ProgramFiles(x86)%\msbuild\microsoft\windows workflow foundation\v3.0\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\windows defender\support\data recovery.hta
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\privateassemblies\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\ink\1.7\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows media\12.0\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\portal\1033\data recovery.hta
  • %ProgramFiles(x86)%\windows nt\tabletextservice\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\windows nt\msscan\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\ink\1.0\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{a749d8e6-b613-3be3-8f5f-045c84eba29b}v12.0.21005\packages\vcruntimeminimum_amd64\data recovery.hta
  • %ProgramFiles%\msbuild\microsoft\windows workflow foundation\v3.0\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{bd95a8cd-1d9f-35ad-981a-3e7925026ebb}v11.0.61030\packages\vcruntimeminimum_x86\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\stationery\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\currency.gadget\en-us\js\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{929fbd26-9020-399b-9a7a-751d61f0b942}v12.0.21005\packages\vcruntimeadditional_amd64\data recovery.hta
  • %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\data recovery.hta
  • %ProgramFiles(x86)%\microsoft.net\redistlist\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\office14\1033\data recovery.hta
  • %CommonProgramFiles(x86)%\system\ole db\en-us\data recovery.hta
  • %APPDATA%\thunderbird\crash reports\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\default_apps\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\windows defender\definition updates\{d2b0b133-42ed-44d3-809a-46ebb62ba863}\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\locales\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\visualelements\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\extensions\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\installer\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows\wer\reportqueue\critical_microsoft .net f_5deabd23d637fc27acf7bfdd613025667396c824_cab_0fbabd8f\data recovery.hta
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\data recovery.hta
  • C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\picturepuzzle.gadget\en-us\css\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\picturepuzzle.gadget\en-us\js\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\clock.gadget\en-us\js\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\slideshow.gadget\en-us\css\data recovery.hta
  • %ProgramFiles%\microsoft analysis services\as oledb\10\resources\1033\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\slideshow.gadget\en-us\js\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\1033\onenote\14\notebook templates\data recovery.hta
  • %CommonProgramFiles%\system\msmapi\1033\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\legal\enu\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\cpu.gadget\en-us\js\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\calendar.gadget\en-us\css\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\cpu.gadget\en-us\css\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\weather.gadget\en-us\css\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\currency.gadget\en-us\css\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\calendar.gadget\en-us\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\locale\en_us\data recovery.hta
  • %ProgramFiles(x86)%\msbuild\microsoft\windows workflow foundation\v3.5\data recovery.hta
  • %ProgramFiles(x86)%\microsoft office\office14\1033\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\office14\cultures\data recovery.hta
  • %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\resources\1033\data recovery.hta
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\resources\1033\data recovery.hta
  • %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\74356068-1388-41cc-9c6d-3d77345b06f6
  • %CommonProgramFiles(x86)%\system\ado\en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\1033\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\idtemplates\enu\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\42d5bec7ddfbd49e76467529cbc2868987bf8460\packages\patch\x64\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\certificates\groove.net\components\data recovery.hta
  • %APPDATA%\thunderbird\profiles\hmz1jddi.default\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\prc\data recovery.hta
  • %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\certificates\groove.net\servers\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\certificates\groove.net\managedobjects\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\appinfodocument\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsto\10.0\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\saslprep\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1031\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{f1b0fb3a-e0ea-47a6-9383-3650655403b0}v14.16.27024\packages\vcruntimeminimum_amd64\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\3082\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1036\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1041\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\2052\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\8.0\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\icu\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\windows nt\msfax\virtualinbox\en-us\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\windows nt\msfax\common coverpages\en-us\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1033\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\annotations\stamps\enu\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\helpcfg\en_us\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1040\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1042\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticons\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\adobe\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\calendar.gadget\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\slideshow.gadget\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\picturepuzzle.gadget\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\cpu.gadget\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\pfm\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\data recovery.hta
  • %LOCALAPPDATA%\thunderbird\profiles\chdgbv82.default-release\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticonsold\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\secstore\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\arm\1.0\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\propmap\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\adobe\data recovery.hta
  • %LOCALAPPDATA%\thunderbird\profiles\chdgbv82.default-release\cache2\entries\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform\data recovery.hta
  • %ProgramFiles(x86)%\microsoft.net\primary interop assemblies\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\ink\en-us\data recovery.hta
  • %ProgramFiles(x86)%\windows nt\tabletextservice\en-us\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\datareporting\archived\2023-09\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vba\vba6\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\data recovery.hta
  • %ProgramFiles(x86)%\opera\29.0.1795.47\localization\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\smart tag\lists\1033\data recovery.hta
  • C:\users\public\recorded tv\sample media\data recovery.hta
  • %ALLUSERSPROFILE%\sun\java\java update\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1049\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acroapp\enu\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\data recovery.hta
  • %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\data recovery.hta
  • %CommonProgramFiles(x86)%\system\msadc\en-us\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\en-us\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\assistance\client\1.0\en-us\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\rac\publisheddata\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\annotations\stamps\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{42667d2e-b054-46c1-9d46-2ee1332c14c1}v14.29.30133\packages\vcruntimeadditional_x86\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\data recovery.hta
  • %LOCALAPPDATA%low\sun\java\jre1.8.0_45_x64\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\1046\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{37b8f9c7-03fb-3253-8781-2517c99d7c00}v11.0.61030\packages\vcruntimeadditional_amd64\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{cf2bea3c-26ea-32f8-aa9b-331f7e34ba97}v11.0.61030\packages\vcruntimeminimum_amd64\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{9d29fc96-9eee-4253-943f-96b3bbfdd0b6}v14.16.27024\packages\vcruntimeadditional_amd64\data recovery.hta
  • %ProgramFiles(x86)%\steam\bin\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\locales\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\pepperflash\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\weather.gadget\en-us\js\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\packages\vcruntimeadditional_x86\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\document parts\1033\14\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows mail\backup\new\data recovery.hta
  • %ProgramFiles(x86)%\steam\logs\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\textconv\wksconv\data recovery.hta
  • %APPDATA%\microsoft\windows\themes\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\desktop-connector-files-select\css\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\tr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_tw\data recovery.hta
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\permanent\chrome\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\de\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\bg\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\weather.gadget\images\120dpi\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\en-il\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\libs\jquery.ui.touch-punch\0.2.2\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\css\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\id\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_tw\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\th\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\tr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sk\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ro\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ja\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lt\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\es\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pl\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_br\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\nl\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ja\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\en\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\slideshow.gadget\images\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\images\win8-scrollbar\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hi\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\id\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_pt\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-files\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lt\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\uk\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\uk-ua\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\el\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-computer-select\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_pt\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\images\hi_contrast\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\add-account\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ar\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\cs\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\editpdf\js\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_ca\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ca\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ar\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\libs\require\2.1.15\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\cs\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\images\file_types\hi_contrast\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ca\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\it\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_br\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fil\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\es\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hi\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ko\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hu\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\da\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\cs-cz\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lv\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lv\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\images\file_types\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fi\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\vi\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_gb\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\no\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\da\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\nl\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\abbreviations\en_ca\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\bg\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\home\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\desktop-connector-files\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\uk-ua\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\en-il\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\it\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\fr-fr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ar\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_ca\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\da-dk\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\ru-ru\data recovery.hta
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\storage\permanent\chrome\idb\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\zh-tw\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\sv-se\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\es-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\combinepdf\css\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\th\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\nb-no\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_us\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\add-account\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\de-de\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sv\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\images\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\nb-no\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\ko-kr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\en-ae\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\en-il\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\en-gb\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\add-account-select\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\zh-cn\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\on-boarding\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\pl-pl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-computer\images\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sv\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\no\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\vi\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\tr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sl\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\tr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_pt\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ru\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\home\images\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\images\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ru\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\combinepdf\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\no\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\ro-ro\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\de\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\en-ae\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\da-dk\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\eu-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\fss\img\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\nl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\sl-si\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\de-de\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\ro-ro\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fi\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fr\data recovery.hta
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\weather.gadget\en-us\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\editpdf\images\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\en\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\root\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lt\data recovery.hta
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\data recovery.hta
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\pipeline.v10.0\hostsideadapters\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\cs\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\bg\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\weather.gadget\en-us\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\images\data recovery.hta
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\data recovery.hta
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\crashes\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\pipeline.v10.0\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\appinfodocument\microsoft.visualstudio.tools.office.appinfodocument\data recovery.hta
  • C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\clock.gadget\en-us\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\rssfeeds.gadget\en-us\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\data recovery.hta
  • %LOCALAPPDATA%low\sun\java\deployment\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ja\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\weather.gadget\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\eu\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es_419\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\el\data recovery.hta
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\picturepuzzle.gadget\images\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\calendar.gadget\images\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-us\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\currency.gadget\images\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\et\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\pipeline.v10.0\addinsideadapters\data recovery.hta
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\datareporting\data recovery.hta
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\saved-telemetry-pings\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\no\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lt\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-us\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\hu-hu\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fi\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-files\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\sl-si\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\images\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\cs\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\nl\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_us\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\pt-br\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_gb\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\it\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\add-account\images\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\zh-cn\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\picturepuzzle.gadget\en-us\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_cn\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\versions\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\weather.gadget\images\144dpi\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ro\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\uk\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fil\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hu\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\da\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\ja-jp\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\de\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\se\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\he\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\id\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ko\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pl\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fil\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\id\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\slideshow.gadget\en-us\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsta\pipeline.v10.0\contracts\data recovery.hta
  • C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\fr-fr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-files-select\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\fi-fi\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\es-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\de-de\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\nl-nl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\ko-kr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\ca-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\desktop-connector-files-select\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\nl-nl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\hu-hu\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\ja-jp\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\clock.gadget\en-us\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sl\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-recent-files-select\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ca\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sk\data recovery.hta
  • %APPDATA%\thunderbird\profiles\chdgbv82.default-release\datareporting\archived\2023-09\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\ja-jp\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hu\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\abbreviations\en_us\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ja\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\tr-tr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\ko-kr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\ru-ru\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\et\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\he\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_pt\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\js\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\pl-pl\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es_419\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\vi\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_us\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fil\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_gb\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\th\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\en-gb\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\he\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ko\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lv\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hu\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_br\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ro\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\misc\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ca\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\clock.gadget\images\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fi\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\picturepuzzle.gadget\en-us\css\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\rssfeeds.gadget\en-us\js\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sk\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\currency.gadget\en-us\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\ca-es\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\hr-hr\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ru\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\gadgets\weather.gadget\images\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fr\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\hu-hu\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\fr-ma\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\zh-tw\data recovery.hta
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\abbreviations\en_gb\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-computer-select\css\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\sv-se\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\it-it\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\sk-sk\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files\css\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\rssfeeds.gadget\en-us\css\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\clock.gadget\en-us\css\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\rssfeeds.gadget\en-us\js\data recovery.hta
  • %ALLUSERSPROFILE%\oracle\java\installcache_x64\data recovery.hta
  • %ProgramFiles(x86)%\windows nt\accessories\en-us\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\dataservices\data recovery.hta
  • %APPDATA%\microsoft\windows\start menu\programs\accessories\data recovery.hta
  • %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\data recovery.hta
  • %APPDATA%\microsoft\windows\start menu\programs\winrar\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\datareporting\data recovery.hta
  • %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\data recovery.hta
  • %LOCALAPPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\cache2\entries\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\pubspapr\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\sounds\things\data recovery.hta
  • %CommonProgramFiles(x86)%\services\data recovery.hta
  • %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\security\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\ea09503g\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\1033\access\part\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\1033\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\data recovery.hta
  • %LOCALAPPDATA%\microsoft\internet explorer\recovery\high\active\data recovery.hta
  • %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\data recovery.hta
  • %ProgramFiles(x86)%\windows defender\data recovery.hta
  • %ProgramFiles(x86)%\msbuild\data recovery.hta
  • %ProgramFiles%\mozilla firefox\distibution\data recovery.hta
  • %APPDATA%\microsoft\windows\start menu\programs\data recovery.hta
  • %ProgramFiles%\mozilla firefox\fonts\data recovery.hta
  • %CommonProgramFiles(x86)%\steam\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\1033\fax\data recovery.hta
  • %ProgramFiles%\windows nt\tabletextservice\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\application\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\1033\access\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\picturepuzzle.gadget\images\data recovery.hta
  • %ProgramFiles(x86)%\windows sidebar\data recovery.hta
  • %ProgramFiles%\internet explorer\en-us\data recovery.hta
  • %ProgramFiles%\microsoft office\media\office14\autoshap\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\1033\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\equation\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\officesoftwareprotectionplatform\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\smart tag\data recovery.hta
  • %ProgramFiles%\microsoft office\media\office14\bullets\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\cultures\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\data recovery.hta
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3150914307-1777937420-491476919-1000\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\vsto\data recovery.hta
  • %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\grphflt\data recovery.hta
  • %HOMEPATH%\favorites\links\data recovery.hta
  • %ProgramFiles%\microsoft office\media\office14\lines\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\mediacenter.gadget\images\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\vc\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\chrome\icons\default\data recovery.hta
  • %ProgramFiles%\reference assemblies\microsoft\framework\v3.0\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\fieldtypepreview\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\weather.gadget\images\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\weather.gadget\images\144dpi\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\weather.gadget\images\120dpi\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\main\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\translat\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\web folders\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\deploy\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\stationery\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\isp\data recovery.hta
  • %ProgramFiles(x86)%\windows photo viewer\data recovery.hta
  • C:\users\public\music\sample music\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\crashes\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\pubftscm\data recovery.hta
  • %ProgramFiles(x86)%\windows mail\data recovery.hta
  • %ProgramFiles(x86)%\steam\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\data recovery.hta
  • %ProgramFiles(x86)%\windows portable devices\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds cache\data recovery.hta
  • %ProgramFiles%\dvd maker\en-us\data recovery.hta
  • %LOCALAPPDATA%\microsoft\media player\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows\explorer\data recovery.hta
  • %LOCALAPPDATA%\microsoft\internet explorer\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows mail\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\security_state\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\bookmarkbackups\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\office\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\welcome tool\data recovery.hta
  • %ProgramFiles%\internet explorer\signup\data recovery.hta
  • %ProgramFiles%\windows mail\en-us\data recovery.hta
  • %ProgramFiles%\windows nt\accessories\data recovery.hta
  • %ProgramFiles%\windows sidebar\en-us\data recovery.hta
  • %ProgramFiles%\windows defender\en-us\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\presentation designs\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\source engine\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vsto\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\stationery\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\help\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\msinfo\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\vgx\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\ink\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\quickstyles\data recovery.hta
  • %ProgramFiles(x86)%\opera\assets\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\default\moz-extension+++5fc1ef9c-f7bf-452f-a7ef-92635f5362ce^usercontextid=4294967295\data recovery.hta
  • C:\users\public\libraries\data recovery.hta
  • %APPDATA%\thunderbird\data recovery.hta
  • %APPDATA%\microsoft\windows\recent\customdestinations\data recovery.hta
  • %APPDATA%\microsoft\windows\sendto\data recovery.hta
  • %APPDATA%\microsoft\windows\libraries\data recovery.hta
  • %ALLUSERSPROFILE%\mozilla\updates\308046b0af4a39cb\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds\data recovery.hta
  • %HOMEPATH%\favorites\windows live\data recovery.hta
  • %HOMEPATH%\favorites\microsoft websites\data recovery.hta
  • %ProgramFiles(x86)%\opera\29.0.1795.47\data recovery.hta
  • %HOMEPATH%\favorites\links for united states\data recovery.hta
  • C:\users\public\pictures\sample pictures\data recovery.hta
  • %HOMEPATH%\favorites\msn websites\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\calendar\data recovery.hta
  • %HOMEPATH%\contacts\data recovery.hta
  • %HOMEPATH%\searches\data recovery.hta
  • %LOCALAPPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\startupcache\data recovery.hta
  • %ProgramFiles(x86)%\windows media player\media renderer\data recovery.hta
  • %ProgramFiles(x86)%\windows media player\en-us\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\bibliography\style\data recovery.hta
  • %HOMEPATH%\links\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\office14\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\groovedocumentreview\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\commondata\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft help\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\sounds\people\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\travel\data recovery.hta
  • %ProgramFiles%\windows photo viewer\en-us\data recovery.hta
  • %CommonProgramFiles%\system\msadc\data recovery.hta
  • %ProgramFiles%\mozilla firefox\browser\features\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\accwiz\data recovery.hta
  • %CommonProgramFiles%\system\ado\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\user account pictures\data recovery.hta
  • %ProgramFiles%\windows journal\templates\data recovery.hta
  • %ProgramFiles%\microsoft office\document themes 14\data recovery.hta
  • %ProgramFiles%\windows media player\network sharing\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\outlookautodiscover\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\proof\data recovery.hta
  • %ProgramFiles%\windows media player\media renderer\data recovery.hta
  • %ProgramFiles%\windows media player\en-us\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\pubba\data recovery.hta
  • %ProgramFiles%\windows journal\en-us\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\pagesize\data recovery.hta
  • %ProgramFiles%\microsoft office\document themes 14\theme colors\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\network\downloader\data recovery.hta
  • %ProgramFiles%\microsoft office\document themes 14\theme effects\data recovery.hta
  • %ProgramFiles%\microsoft office\media\cagcat10\data recovery.hta
  • %ProgramFiles%\microsoft office\document themes 14\theme fonts\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\convert\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\convert\1033\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\cpu.gadget\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\currency.gadget\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\rssfeeds.gadget\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\media\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\onenote\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\infopathom\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\weather.gadget\data recovery.hta
  • %HOMEPATH%\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\calendar.gadget\data recovery.hta
  • %APPDATA%\microsoft\windows\ietldcache\data recovery.hta
  • %ProgramFiles%\windows media player\data recovery.hta
  • %ProgramFiles%\windows photo viewer\data recovery.hta
  • %CommonProgramFiles%\designer\data recovery.hta
  • %ProgramFiles%\windows portable devices\data recovery.hta
  • %ProgramFiles%\windows journal\data recovery.hta
  • %ProgramFiles%\windows mail\data recovery.hta
  • %ProgramFiles%\windows sidebar\data recovery.hta
  • %ProgramFiles%\windows defender\data recovery.hta
  • %ProgramFiles%\mozilla firefox\data recovery.hta
  • %ProgramFiles%\internet explorer\data recovery.hta
  • %ProgramFiles%\dvd maker\data recovery.hta
  • D:\data recovery.hta
  • C:\data recovery.hta
  • <Current directory>\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\data recovery.hta
  • %APPDATA%\microsoft\windows\cookies\data recovery.hta
  • %ProgramFiles%\microsoft office\stationery\1033\data recovery.hta
  • %ProgramFiles%\winrar\data recovery.hta
  • %APPDATA%\microsoft\internet explorer\quick launch\data recovery.hta
  • %LOCALAPPDATA%low\microsoft\internet explorer\services\data recovery.hta
  • %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\data recovery.hta
  • C:\users\default\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\pubwiz\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\queries\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\data recovery.hta
  • %CommonProgramFiles%\services\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\data recovery.hta
  • %ProgramFiles%\mozilla firefox\browser\data recovery.hta
  • %ProgramFiles(x86)%\internet explorer\en-us\data recovery.hta
  • %ProgramFiles(x86)%\opera\data recovery.hta
  • C:\kms\data recovery.hta
  • %ProgramFiles(x86)%\windows media player\data recovery.hta
  • %CommonProgramFiles%\system\data recovery.hta
  • %ProgramFiles(x86)%\internet explorer\data recovery.hta
  • %CommonProgramFiles%\system\msadc\en-us\data recovery.hta
  • C:\users\public\desktop\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\cpu.gadget\images\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\data recovery.hta
  • %ProgramFiles%\reference assemblies\microsoft\framework\v3.5\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\slideshow.gadget\images\data recovery.hta
  • %ProgramFiles%\microsoft office\clipart\pub60cor\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\rssfeeds.gadget\images\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\flippage\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\cache\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\calendar.gadget\images\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\solutions\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\layeredtitles\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\memories\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\performance\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\1033\access\datatype\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\huecycle\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\full\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\specialoccasion\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\push\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\pets\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\stacking\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\shatter\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\sports\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\rectangles\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\resizingpanels\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\vignette\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\fonts\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\ext\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\oldage\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\data recovery.hta
  • %APPDATA%\microsoft\protect\data recovery.hta
  • %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\webslices~\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\babygirl\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\mf\data recovery.hta
  • %APPDATA%\mozilla\firefox\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\addins\data recovery.hta
  • %ProgramFiles%\microsoft office\media\office14\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\clock.gadget\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\clock.gadget\images\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\slideshow.gadget\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\picturepuzzle.gadget\data recovery.hta
  • %HOMEPATH%\desktop\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\forms\1033\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\borders\data recovery.hta
  • %CommonProgramFiles%\system\ole db\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\bibliography\data recovery.hta
  • %ProgramFiles%\microsoft sql server compact edition\v3.5\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\bin\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\library\data recovery.hta
  • %ProgramFiles%\mozilla firefox\defaults\pref\data recovery.hta
  • %ProgramFiles%\microsoft analysis services\as oledb\10\data recovery.hta
  • %ProgramFiles%\microsoft synchronization services\ado.net\v1.0\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\vba\vba7\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office.en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\vba\vba7\1033\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\toolicons\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\infopathom\infopathomformservices\data recovery.hta
  • %LOCALAPPDATA%\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\sounds\places\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\access.en-us\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\certificates\verisign\components\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\management\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\currency.gadget\images\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\toolbmps\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\xml files\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\mediacenter.gadget\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\babyboy\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_cn\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hi\data recovery.hta
  • C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\data recovery.hta
  • %LOCALAPPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\offlinecache\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\springgreen\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\desert\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\slate\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~\data recovery.hta
  • %ProgramFiles%\mozilla firefox\browser\visualelements\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\infopath.en-us\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds\feeds for united states~\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\powerpoint.en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fr-fr\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\groove.en-us\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\bin\dtplugin\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office32.en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\outlook.en-us\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\lv-lv\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\web\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\sk-sk\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\aftrnoon\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\data recovery.hta
  • %CommonProgramFiles(x86)%\system\en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\auxpad\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\translat\arfr\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\msclientdatamgr\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\translat\enfr\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\samples\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\layers\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.es\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\translat\frar\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\oasis\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\springgreen\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\iris\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\textconv\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\cmm\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\picturepuzzle.gadget\en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\da-dk\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fi-fi\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\bg-bg\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\el-gr\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\onenote.en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\es-es\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\tr-tr\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\nl-nl\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\refined\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\profile\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\sv-se\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\pl-pl\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\et-ee\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\ro-ro\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{295d1583-fdb9-414b-a4c8-da539362a26b}\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\discussion\data recovery.hta
  • %APPDATA%\telegram desktop\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\visualelements\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\publisher.en-us\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\weather.gadget\en-us\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\uninstall\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\computers\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\accessweb\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\rssfeeds.gadget\en-us\data recovery.hta
  • %ProgramFiles%\mozilla firefox\uninstall\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\slideshow.gadget\en-us\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{fd9b6070-d13e-45dc-819b-41806bf45b6b}\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\clock.gadget\en-us\data recovery.hta
  • %CommonProgramFiles%\system\ole db\en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\sl-si\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins3d\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\americana\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\studio\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\infopathom\infopathomformservices\infopathomformservicesv12\data recovery.hta
  • C:\users\public\videos\sample videos\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\cascade\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\deepblue\data recovery.hta
  • %LOCALAPPDATA%low\oracle\java\au\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\sonora\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\bluecalm\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\concrete\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\slate\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\spring\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\strtedge\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\canyon\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\edge\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\sky\data recovery.hta
  • %ProgramFiles(x86)%\microsoft office\office14\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\msinfo\en-us\data recovery.hta
  • %APPDATA%\microsoft\windows\start menu\programs\maintenance\data recovery.hta
  • %ProgramFiles(x86)%\windows mail\en-us\data recovery.hta
  • %ALLUSERSPROFILE%\oracle\java\javapath\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\web server extensions\14\bin\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\web server extensions\14\bin\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\msinfo\en-us\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\default\moz-extension+++5fc1ef9c-f7bf-452f-a7ef-92635f5362ce^usercontextid=4294967295\idb\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\msenv\publicassemblies\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\data recovery.hta
  • %ProgramFiles%\microsoft sync framework\v1.0\documentation\1033\license agreements\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\defaults\pref\data recovery.hta
  • %ProgramFiles%\msbuild\microsoft\windows workflow foundation\v3.5\data recovery.hta
  • %ProgramFiles%\windows nt\accessories\en-us\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\defaults\messenger\data recovery.hta
  • %ProgramFiles(x86)%\windows photo viewer\en-us\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\swirl\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\rmnsque\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\slideshow.gadget\images\in_sidebar\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds cache\15ivkcr3\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\sts2\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\data recovery.hta
  • %APPDATA%\microsoft\windows\start menu\programs\telegram desktop\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\infopathom\infopathomv12\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds cache\6fwa5ftw\data recovery.hta
  • %CommonProgramFiles(x86)%\system\ado\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds cache\bbs9hw0e\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\brightorange\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\radial\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\swirl\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\brightorange\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\journal\data recovery.hta
  • %LOCALAPPDATA%\microsoft\feeds cache\xwtafhng\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\ko-kr\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\satin\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\slideshow.gadget\images\on_desktop\data recovery.hta
  • %ProgramFiles%\reference assemblies\microsoft\framework\v3.5\redistlist\data recovery.hta
  • %ALLUSERSPROFILE%\package cache\{38b2c744-ad08-4d5b-91a2-3fb6f739ff3e}\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\vsto\10.0\1033\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\data recovery.hta
  • %ProgramFiles%\dvd maker\shared\dvdstyles\videowall\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\data recovery.hta
  • %TEMP%\opera installer\data recovery.hta
  • %CommonProgramFiles(x86)%\system\msadc\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\mediacenter.gadget\js\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\mediacenter.gadget\css\data recovery.hta
  • %ALLUSERSPROFILE%\mozilla\updates\d78bf5dd33499ec2\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\mediacenter.gadget\en-us\data recovery.hta
  • %CommonProgramFiles(x86)%\system\ole db\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\zh-cn\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\ru-ru\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\sr-latn-cs\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\axis\data recovery.hta
  • %ProgramFiles(x86)%\windows defender\en-us\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\bin\server\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\web folders\1033\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\javascripts\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\dao\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\bibliography\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskmenu\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\biscay\data recovery.hta
  • %ProgramFiles%\reference assemblies\microsoft\framework\v3.0\redistlist\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\calendar.gadget\en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\filters\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\documentshare\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\babyblue\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\equation\1033\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\cpu.gadget\en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\zh-tw\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\boldstri\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\proof\1036\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\en\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\msinfo\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\babyblue\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightyellow\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1036\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\smart tag\1033\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\office32.ww\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\jfr\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\bin\plugin2\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\browser\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\uk-ua\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\help\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\air\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\keypad\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\euro\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\translat\fren\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vgx\data recovery.hta
  • %LOCALAPPDATA%\microsoft\windows sidebar\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\3082\data recovery.hta
  • %CommonProgramFiles%\system\en-us\data recovery.hta
  • %ProgramFiles(x86)%\windows nt\accessories\data recovery.hta
  • %APPDATA%\mozilla\firefox\profiles\m15ucxjx.default\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\basic\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\proof\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\features\data recovery.hta
  • %ProgramFiles%\windows sidebar\gadgets\currency.gadget\en-us\data recovery.hta
  • %ProgramFiles(x86)%\internet explorer\signup\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\portal\data recovery.hta
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\esl\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\bibliography\sort\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\library\solver\data recovery.hta
  • %ProgramFiles(x86)%\windows media player\skins\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\proof\1033\data recovery.hta
  • %ALLUSERSPROFILE%\microsoft\identitycrl\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\proof\3082\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\desert\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\translat\enes\data recovery.hta
  • %CommonProgramFiles%\system\ado\en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\sumipntg\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\smart tag\lists\data recovery.hta
  • %ProgramFiles%\microsoft office\templates\1033\access\wss\data recovery.hta
  • %ProgramFiles%\mozilla firefox\gmp-clearkey\0.1\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\translat\esen\data recovery.hta
  • %ProgramFiles%\windows nt\tabletextservice\en-us\data recovery.hta
  • %ProgramFiles%\java\jre1.8.0_45\lib\amd64\data recovery.hta
  • %CommonProgramFiles(x86)%\microsoft shared\vc\data recovery.hta
  • %ProgramFiles%\microsoft office\media\office14\1033\data recovery.hta
  • %ProgramFiles%\microsoft office\media\cagcat10\1033\data recovery.hta
  • %ProgramFiles%\windows media player\skins\data recovery.hta
  • %APPDATA%\microsoft\windows\start menu\programs\google chrome\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\oasis\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\blends\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\oasis\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\springgreen\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\brightyellow\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\ar-sa\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\biscay\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proofing.en-us\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\biscay\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\de-de\data recovery.hta
  • %APPDATA%\mozilla\firefox\crash reports\data recovery.hta
  • %TEMP%\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\quad\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\capsules\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\breeze\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\softblue\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\cs-cz\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\brightyellow\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\blueprnt\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\evrgreen\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\level\data recovery.hta
  • %ProgramFiles%\mozilla thunderbird\fonts\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\babyblue\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\network\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\ice\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\indust\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\papyrus\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\it-it\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\pixel\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.en\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\expeditn\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\dw\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\pt-pt\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\word.en-us\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\nb-no\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\pt-br\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\compass\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\echo\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\lime\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\ja-jp\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\eclipse\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\oskpred\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\symbols\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\lt-lt\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\lime\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\water\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\excel.en-us\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\graycheck\data recovery.hta
  • %CommonProgramFiles(x86)%\system\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\ripple\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\softblue\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\library\analysis\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\americana\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\numbers\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\lime\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\americana\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\hr-hr\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\th-th\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\graycheck\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proof.fr\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\slate\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\softblue\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\ricepapr\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\office14\office setup controller\proplus\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\hu-hu\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\slate\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\desert\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\fsdefinitions\osknumpad\data recovery.hta
  • %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\graycheck\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\watermar\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\themes14\arctic\data recovery.hta
  • %CommonProgramFiles%\microsoft shared\ink\he-il\data recovery.hta
  • %APPDATA%\microsoft\windows\recent\automaticdestinations\data recovery.hta
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\de\data recovery.hta
Sets the 'hidden' attribute to the following files
  • %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\74356068-1388-41cc-9c6d-3d77345b06f6
Moves the following files
  • from %ProgramFiles%\winrar\7zxa.dll to %ProgramFiles%\winrar\7zxa.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\contacts.accdt to %ProgramFiles%\microsoft office\templates\1033\access\contacts.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\ace.dll to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\ace.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\steam\bin\steamservice.exe to %ProgramFiles(x86)%\steam\bin\steamservice.exe.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\accddslm.dll to %ProgramFiles%\microsoft office\office14\accddslm.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\fax\orielfax.dotx to %ProgramFiles%\microsoft office\templates\1033\fax\orielfax.dotx.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\pi_brokers\64bitmapibroker.exe to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\pi_brokers\64bitmapibroker.exe.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\localization\af.pak to %ProgramFiles(x86)%\opera\29.0.1795.47\localization\af.pak.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\accvdtui.dll to %ProgramFiles%\microsoft office\office14\1033\accvdtui.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlceer35en.dll to %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlceer35en.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidabrightitalic.ttf to %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidabrightitalic.ttf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\header.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\header.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.addinmanager.dll to %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.addinmanager.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\datatype\name.accft to %ProgramFiles%\microsoft office\templates\1033\access\datatype\name.accft.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\bibliography\style\chicago.xsl to %ProgramFiles%\microsoft office\office14\bibliography\style\chicago.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\stationery\1033\judgesch.gif to %ProgramFiles%\microsoft office\stationery\1033\judgesch.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\adobepistd.otf to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\adobepistd.otf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.sqlserverce.dll to %ProgramFiles%\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.sqlserverce.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\people\mmhmm.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\people\mmhmm.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\lines\bd10307_.gif to %ProgramFiles%\microsoft office\media\office14\lines\bd10307_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\delete.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\delete.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\biscay.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\biscay.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\bg_adobe.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\bg_adobe.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\autoshap\bd18181_.wmf to %ProgramFiles%\microsoft office\media\office14\autoshap\bd18181_.wmf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\toolicons\computer.ico to %ProgramFiles%\microsoft office\office14\groove\toolicons\computer.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\theme effects\apothecary.eftx to %ProgramFiles%\microsoft office\document themes 14\theme effects\apothecary.eftx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\onenote\sendtoonenotenames.gpd to %ProgramFiles%\microsoft office\office14\onenote\sendtoonenotenames.gpd.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\bin\dcpr.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dcpr.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt to %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\pubspapr\pdir11f.gif to %ProgramFiles%\microsoft office\office14\1033\pubspapr\pdir11f.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\ffmpegsumo.dll to %ProgramFiles(x86)%\opera\29.0.1795.47\ffmpegsumo.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\winrar\descript.ion to %ProgramFiles%\winrar\descript.ion.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\dc35f7c9-5b80-4042-a301-e84d8619b27e to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\dc35f7c9-5b80-4042-a301-e84d8619b27e.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\bibliography\style\gb.xsl to %ProgramFiles%\microsoft office\office14\bibliography\style\gb.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\synchronization.dll to %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\synchronization.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\policies.fdt to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\policies.fdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\security\java.policy to %ProgramFiles%\java\jre1.8.0_45\lib\security\java.policy.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\vstaproject.dll to %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\vstaproject.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\addins\faxext.ecf to %ProgramFiles%\microsoft office\office14\addins\faxext.ecf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\delimwin.fae to %ProgramFiles%\microsoft office\office14\convert\delimwin.fae.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\media\breeze.wav to %ProgramFiles%\microsoft office\office14\media\breeze.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\people\sneeze.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\people\sneeze.wav.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\winrar\winrar.lnk to %APPDATA%\microsoft\windows\start menu\programs\winrar\winrar.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\chrome\icons\default\calendar-alarm-dialog.ico to %ProgramFiles%\mozilla thunderbird\chrome\icons\default\calendar-alarm-dialog.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\ext\jaccess.jar to %ProgramFiles%\java\jre1.8.0_45\lib\ext\jaccess.jar.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\actip10.hlp to %ProgramFiles%\microsoft office\office14\1033\actip10.hlp.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\deploy\messages_es.properties to %ProgramFiles%\java\jre1.8.0_45\lib\deploy\messages_es.properties.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\brightyellow.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\brightyellow.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\management\snmp.acl.template to %ProgramFiles%\java\jre1.8.0_45\lib\management\snmp.acl.template.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\msjet.xsl to %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\msjet.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\courierstd-bold.otf to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\courierstd-bold.otf.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\resources\013e742b-287b-4228-a0b9-bd617e4e02a4.ico to %ProgramFiles(x86)%\opera\29.0.1795.47\resources\013e742b-287b-4228-a0b9-bd617e4e02a4.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\toolicons\contactselector.ico to %ProgramFiles%\microsoft office\office14\groove\toolicons\contactselector.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\autoshap\bd18182_.wmf to %ProgramFiles%\microsoft office\media\office14\autoshap\bd18182_.wmf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\attention.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\attention.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubwiz\ad98.poc to %ProgramFiles%\microsoft office\office14\pubwiz\ad98.poc.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\onenote\sendtoonenoteui.dll to %ProgramFiles%\microsoft office\office14\onenote\sendtoonenoteui.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\bg_casual.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\bg_casual.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\borders\msart12.bdr to %ProgramFiles%\microsoft office\office14\borders\msart12.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143746.gif to %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143746.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\pfm\sy______.pfm to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\pfm\sy______.pfm.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10268_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10268_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_earthy.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_earthy.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\charitable contributions.accdt to %ProgramFiles%\microsoft office\templates\1033\access\charitable contributions.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\chrome\icons\default\addressbookwindow.ico to %ProgramFiles%\mozilla thunderbird\chrome\icons\default\addressbookwindow.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\api-ms-win-core-file-l1-2-0.dll to %ProgramFiles%\mozilla thunderbird\api-ms-win-core-file-l1-2-0.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\base_uris.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\base_uris.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\onenote\14\stationery\academic.one to %ProgramFiles%\microsoft office\templates\1033\onenote\14\stationery\academic.one.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\security\cacerts to %ProgramFiles%\java\jre1.8.0_45\lib\security\cacerts.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\solutions\generic.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\solutions\generic.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft office\office14\bcslaunch.dll to %ProgramFiles(x86)%\microsoft office\office14\bcslaunch.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\1033\localdv.dll to %ProgramFiles%\microsoft office\office14\convert\1033\localdv.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\xml files\spwaddin.xsd to %ProgramFiles%\microsoft office\office14\groove\xml files\spwaddin.xsd.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\management\management.properties to %ProgramFiles%\java\jre1.8.0_45\lib\management\management.properties.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\locale\en_us\stopwords.enu to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\locale\en_us\stopwords.enu.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\hierarchy.xsl to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\hierarchy.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10267_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10267_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10266_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10266_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform\adobepdf.xdc to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform\adobepdf.xdc.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\legal\enu\eula.ini to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\legal\enu\eula.ini.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\accwiz\acwzlib.accde to %ProgramFiles%\microsoft office\office14\accwiz\acwzlib.accde.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_country.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_country.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\pub60cor\ag00011_.gif to %ProgramFiles%\microsoft office\clipart\pub60cor\ag00011_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\onenote\sendtoonenotefilter.gpd to %ProgramFiles%\microsoft office\office14\onenote\sendtoonenotefilter.gpd.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10265_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10265_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\lines\bd10290_.gif to %ProgramFiles%\microsoft office\media\office14\lines\bd10290_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\theme effects\apex.eftx to %ProgramFiles%\microsoft office\document themes 14\theme effects\apex.eftx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\toolicons\chevron.ico to %ProgramFiles%\microsoft office\office14\groove\toolicons\chevron.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\cagcat10\cagcat10.mmw to %ProgramFiles%\microsoft office\media\cagcat10\cagcat10.mmw.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\calendar.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\calendar.gif.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\9cd37e15-817f-4044-81be-e43af1dfc595 to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\9cd37e15-817f-4044-81be-e43af1dfc595.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\babyblue.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\babyblue.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\bibliography\author2xml.xsl to %ProgramFiles%\microsoft office\office14\bibliography\author2xml.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\addins\bcsaddin.dll to %ProgramFiles%\microsoft office\office14\addins\bcsaddin.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\fax\medianfax.dotx to %ProgramFiles%\microsoft office\templates\1033\fax\medianfax.dotx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\adjacencymergeletter.dotx to %ProgramFiles%\microsoft office\templates\1033\adjacencymergeletter.dotx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\part\2 right.accdt to %ProgramFiles%\microsoft office\templates\1033\access\part\2 right.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143745.gif to %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143745.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\api-ms-win-crt-conio-l1-1-0.dll to %ProgramFiles%\mozilla firefox\api-ms-win-crt-conio-l1-1-0.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\msbuild\microsoft\windows workflow foundation\v3.0\workflow.targets to %ProgramFiles(x86)%\msbuild\microsoft\windows workflow foundation\v3.0\workflow.targets.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft.net\primary interop assemblies\adodb.dll to %ProgramFiles(x86)%\microsoft.net\primary interop assemblies\adodb.dll.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\on-screen keyboard.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\on-screen keyboard.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubba\mspub1b.bdr to %ProgramFiles%\microsoft office\office14\pubba\mspub1b.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\adobe\symbol.txt to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\adobe\symbol.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\microsoft.synchronization.dll to %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\microsoft.synchronization.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\delimdos.fae to %ProgramFiles%\microsoft office\office14\convert\delimdos.fae.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\borders\msart11.bdr to %ProgramFiles%\microsoft office\office14\borders\msart11.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\places\laser.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\places\laser.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\media\bomb.wav to %ProgramFiles%\microsoft office\office14\media\bomb.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\addins\colleagueimport.dll to %ProgramFiles%\microsoft office\office14\addins\colleagueimport.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\locales\en-us.pak to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrocef\locales\en-us.pak.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\babyblue.css to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\babyblue.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\things\coupler.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\things\coupler.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\informix.xsl to %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\informix.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\msbuild\microsoft\windows workflow foundation\v3.0\workflow.targets to %ProgramFiles%\msbuild\microsoft\windows workflow foundation\v3.0\workflow.targets.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\deploy\messages_de.properties to %ProgramFiles%\java\jre1.8.0_45\lib\deploy\messages_de.properties.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\vstaclientpkg.dll to %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\vstaclientpkg.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\hiring requisition.fdt to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\hiring requisition.fdt.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\winrar\winrar help.lnk to %APPDATA%\microsoft\windows\start menu\programs\winrar\winrar help.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\create_form.gif to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\create_form.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\cagcat10\elphrg01.wav to %ProgramFiles%\microsoft office\media\cagcat10\elphrg01.wav.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\as90.xsl to %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\as90.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\brightorange.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\brightorange.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\angles.thmx to %ProgramFiles%\microsoft office\document themes 14\angles.thmx.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\ext\dnsns.jar to %ProgramFiles%\java\jre1.8.0_45\lib\ext\dnsns.jar.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\forms\1033\activity.cfg to %ProgramFiles%\microsoft office\office14\forms\1033\activity.cfg.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\resources\1033\synchronization.rll to %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\resources\1033\synchronization.rll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\pub60cor\ag00021_.gif to %ProgramFiles%\microsoft office\clipart\pub60cor\ag00021_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\accddsf.dll to %ProgramFiles%\microsoft office\office14\accddsf.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\pub60cor\ag00037_.gif to %ProgramFiles%\microsoft office\clipart\pub60cor\ag00037_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\api-ms-win-crt-private-l1-1-0.dll to %ProgramFiles%\mozilla firefox\api-ms-win-crt-private-l1-1-0.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-computer-select\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-computer-select\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\pfm\zx______.pfm to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\pfm\zx______.pfm.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\css\main.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\aicuc\css\main.css.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\css\main-selector.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\css\main-selector.css.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\1033\vstaprojectui.dll to %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\1033\vstaprojectui.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\fax\urbanfax.dotx to %ProgramFiles%\microsoft office\templates\1033\fax\urbanfax.dotx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\adjacencyreport.dotx to %ProgramFiles%\microsoft office\templates\1033\adjacencyreport.dotx.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\charsets.jar to %ProgramFiles%\java\jre1.8.0_45\lib\charsets.jar.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\lines\bd10358_.gif to %ProgramFiles%\microsoft office\media\office14\lines\bd10358_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\bin\deploy.dll to %ProgramFiles%\java\jre1.8.0_45\bin\deploy.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-files\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-files\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\things\shot.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\things\shot.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\places\toot.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\places\toot.wav.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\ob-preview\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\zh-cn\ui-strings.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\dev\nls\zh-cn\ui-strings.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\form.js to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\form.js.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\editpdf\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\editpdf\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\people\throat.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\people\throat.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\apothecary.thmx to %ProgramFiles%\microsoft office\document themes 14\apothecary.thmx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143748.gif to %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143748.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\chrome\icons\default\calendar-event-dialog.ico to %ProgramFiles%\mozilla thunderbird\chrome\icons\default\calendar-event-dialog.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\casual.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\casual.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\process library.fdt to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\process library.fdt.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\msjet.xsl to %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\msjet.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\api-ms-win-core-localization-l1-2-0.dll to %ProgramFiles%\mozilla thunderbird\api-ms-win-core-localization-l1-2-0.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidasansdemibold.ttf to %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidasansdemibold.ttf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\borders\msart13.bdr to %ProgramFiles%\microsoft office\office14\borders\msart13.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\api-ms-win-crt-process-l1-1-0.dll to %ProgramFiles%\mozilla firefox\api-ms-win-crt-process-l1-1-0.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\autoshap\bd18184_.wmf to %ProgramFiles%\microsoft office\media\office14\autoshap\bd18184_.wmf.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\courierstd-boldoblique.otf to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\font\courierstd-boldoblique.otf.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft office\office14\inlaunch.dll to %ProgramFiles(x86)%\microsoft office\office14\inlaunch.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\faculty.accdt to %ProgramFiles%\microsoft office\templates\1033\access\faculty.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\localization\be.pak to %ProgramFiles(x86)%\opera\29.0.1795.47\localization\be.pak.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\mac\corpchar.txt to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\mac\corpchar.txt.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-recent-files\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-recent-files\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\pubspapr\pdir13f.gif to %ProgramFiles%\microsoft office\office14\1033\pubspapr\pdir13f.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\send-for-sign\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\1033\oladdr.fae to %ProgramFiles%\microsoft office\office14\convert\1033\oladdr.fae.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\plus.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\plus.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\images\a12_spinner.gif to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\images\a12_spinner.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\theme effects\austin.eftx to %ProgramFiles%\microsoft office\document themes 14\theme effects\austin.eftx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\cagcat10\j0090070.wmf to %ProgramFiles%\microsoft office\media\cagcat10\j0090070.wmf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\forms\1033\apptl.ico to %ProgramFiles%\microsoft office\office14\forms\1033\apptl.ico.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\combinepdf\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\combinepdf\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\bibliography\style\gostname.xsl to %ProgramFiles%\microsoft office\office14\bibliography\style\gostname.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\desksam.sam to %ProgramFiles%\microsoft office\office14\convert\desksam.sam.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlceoledb35.dll to %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlceoledb35.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\bg_country.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\bg_country.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\resources\07593226-c5c5-438b-86be-3f6361cd5b10.ico to %ProgramFiles(x86)%\opera\29.0.1795.47\resources\07593226-c5c5-438b-86be-3f6361cd5b10.ico.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\ja-jp\ui-strings.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\ja-jp\ui-strings.js.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\add-account\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\add-account\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\bg_adobe.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\bg_adobe.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\cs-cz\ui-strings.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\files\dev\nls\cs-cz\ui-strings.js.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform\pmp\datamatrix.pmp to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform\pmp\datamatrix.pmp.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\sl-si\ui-strings.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\sl-si\ui-strings.js.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrofx32.dll to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrofx32.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\init.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\init.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\biscay.css to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\biscay.css.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\fi-fi\ui-strings.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\fi-fi\ui-strings.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\deploy\messages_fr.properties to %ProgramFiles%\java\jre1.8.0_45\lib\deploy\messages_fr.properties.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\uk-ua\ui-strings.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\core\dev\nls\uk-ua\ui-strings.js.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\steam\public\steambootstrapper_brazilian.txt to %ProgramFiles(x86)%\steam\public\steambootstrapper_brazilian.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\apex.thmx to %ProgramFiles%\microsoft office\document themes 14\apex.thmx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\sql2000.xsl to %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\sql2000.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\informix.xsl to %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\informix.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\events.accdt to %ProgramFiles%\microsoft office\templates\1033\access\events.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_greentea.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_greentea.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\things\horn.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\things\horn.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\theme effects\aspect.eftx to %ProgramFiles%\microsoft office\document themes 14\theme effects\aspect.eftx.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrobroker.exe to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrobroker.exe.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\minus.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\minus.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\msbuild\microsoft\windows workflow foundation\v3.0\workflow.visualbasic.targets to %ProgramFiles(x86)%\msbuild\microsoft\windows workflow foundation\v3.0\workflow.visualbasic.targets.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubba\mspub2a.bdr to %ProgramFiles%\microsoft office\office14\pubba\mspub2a.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\fax\originfax.dotx to %ProgramFiles%\microsoft office\templates\1033\fax\originfax.dotx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\1033\odbcr.sam to %ProgramFiles%\microsoft office\office14\convert\1033\odbcr.sam.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\part\2 top.accdt to %ProgramFiles%\microsoft office\templates\1033\access\part\2 top.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\error.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\error.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\msbuild\microsoft\windows workflow foundation\v3.0\workflow.visualbasic.targets to %ProgramFiles%\msbuild\microsoft\windows workflow foundation\v3.0\workflow.visualbasic.targets.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\places\radar.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\places\radar.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\cagcat10\j0088542.wmf to %ProgramFiles%\microsoft office\media\cagcat10\j0088542.wmf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\beige.css to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\beige.css.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\adobe\zdingbat.txt to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\adobe\zdingbat.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\forms\1033\appt.cfg to %ProgramFiles%\microsoft office\office14\forms\1033\appt.cfg.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\brightorange.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\brightorange.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\onenote\14\stationery\blank.one to %ProgramFiles%\microsoft office\templates\1033\onenote\14\stationery\blank.one.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\1033\vstaclientpkgui.dll to %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\1033\vstaclientpkgui.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\pubspapr\pdir12f.gif to %ProgramFiles%\microsoft office\office14\1033\pubspapr\pdir12f.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform\pmp\adobepdf417.pmp to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\plug_ins\acroform\pmp\adobepdf417.pmp.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\datatype\payment type.accft to %ProgramFiles%\microsoft office\templates\1033\access\datatype\payment type.accft.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\localization\az.pak to %ProgramFiles(x86)%\opera\29.0.1795.47\localization\az.pak.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\tab_off.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\tab_off.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\distribute_form.gif to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\distribute_form.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\mac\centeuro.txt to %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\mac\centeuro.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\api-ms-win-core-file-l2-1-0.dll to %ProgramFiles%\mozilla thunderbird\api-ms-win-core-file-l2-1-0.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\media\camera.wav to %ProgramFiles%\microsoft office\office14\media\camera.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubwiz\adrespel.poc to %ProgramFiles%\microsoft office\office14\pubwiz\adrespel.poc.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidabrightregular.ttf to %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidabrightregular.ttf.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubba\mspub2b.bdr to %ProgramFiles%\microsoft office\office14\pubba\mspub2b.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\email_all.gif to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\email_all.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\part\comments.accdt to %ProgramFiles%\microsoft office\templates\1033\access\part\comments.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\solutions\main.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\solutions\main.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10297_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10297_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\onenote\14\stationery\business.one to %ProgramFiles%\microsoft office\templates\1033\onenote\14\stationery\business.one.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\css\main-selector.css to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\css\main-selector.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\pub60cor\ag00038_.gif to %ProgramFiles%\microsoft office\clipart\pub60cor\ag00038_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\home\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\home\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.designtime.dll to %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.designtime.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\brightyellow.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\brightyellow.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\addins\msosec.dll to %ProgramFiles%\microsoft office\office14\addins\msosec.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\acwizrc.dll to %ProgramFiles%\microsoft office\office14\1033\acwizrc.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\attention.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\attention.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\security\java.security to %ProgramFiles%\java\jre1.8.0_45\lib\security\java.security.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\datatype\phone.accft to %ProgramFiles%\microsoft office\templates\1033\access\datatype\phone.accft.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\stationery\1033\jungle.gif to %ProgramFiles%\microsoft office\stationery\1033\jungle.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\js\plugin.js to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\my-sharepoint-files-select\js\plugin.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_groove.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_groove.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\tab_on.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\tab_on.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme.txt to %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\bin\decora_sse.dll to %ProgramFiles%\java\jre1.8.0_45\bin\decora_sse.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\winrar\license.txt to %ProgramFiles%\winrar\license.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\accicons.exe to %ProgramFiles%\microsoft office\office14\accicons.exe.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\lines\bd10308_.gif to %ProgramFiles%\microsoft office\media\office14\lines\bd10308_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft office\office14\ieawsdc.dll to %ProgramFiles(x86)%\microsoft office\office14\ieawsdc.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.comrpcchannel.dll to %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.comrpcchannel.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlceme35.dll to %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlceme35.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\toolicons\gfserrorfromgroove.ico to %ProgramFiles%\microsoft office\office14\groove\toolicons\gfserrorfromgroove.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\biscay.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\biscay.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\accolki.dll to %ProgramFiles%\microsoft office\office14\1033\accolki.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\attention.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\attention.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\addins\accolk.dll to %ProgramFiles%\microsoft office\office14\addins\accolk.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\dataservices\folder.ico to %ProgramFiles%\microsoft office\office14\1033\dataservices\folder.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\theme effects\adjacency.eftx to %ProgramFiles%\microsoft office\document themes 14\theme effects\adjacency.eftx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\accddsui.dll to %ProgramFiles%\microsoft office\office14\1033\accddsui.dll.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\29.0.1795.47\d3dcompiler_47.dll to %ProgramFiles(x86)%\opera\29.0.1795.47\d3dcompiler_47.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\management\jmxremote.access to %ProgramFiles%\java\jre1.8.0_45\lib\management\jmxremote.access.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\datatype\address.accft to %ProgramFiles%\microsoft office\templates\1033\access\datatype\address.accft.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidabrightdemibold.ttf to %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidabrightdemibold.ttf.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\security\blacklist to %ProgramFiles%\java\jre1.8.0_45\lib\security\blacklist.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\assets.accdt to %ProgramFiles%\microsoft office\templates\1033\access\assets.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\adjacency.thmx to %ProgramFiles%\microsoft office\document themes 14\adjacency.thmx.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\recovery.baklz4 to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\recovery.baklz4.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\bibliography\style\apa.xsl to %ProgramFiles%\microsoft office\office14\bibliography\style\apa.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\winrar\default.sfx to %ProgramFiles%\winrar\default.sfx.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\internet explorer.lnk to %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\internet explorer.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\launcher.exe to %ProgramFiles(x86)%\opera\launcher.exe.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\people\cough.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\people\cough.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\xml files\builtincontrolsschema.xsd to %ProgramFiles%\microsoft office\office14\groove\xml files\builtincontrolsschema.xsd.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\basic\default.xsl to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\basic\default.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\media\applause.wav to %ProgramFiles%\microsoft office\office14\media\applause.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\infopathom\microsoft.office.infopath.dll to %ProgramFiles%\microsoft office\office14\infopathom\microsoft.office.infopath.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\toolicons\alert.ico to %ProgramFiles%\microsoft office\office14\groove\toolicons\alert.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\feedsync.dll to %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\feedsync.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\americana.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\americana.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\infopathom\infopathomformservices\microsoft.office.infopath.dll to %ProgramFiles%\microsoft office\office14\infopathom\infopathomformservices\microsoft.office.infopath.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\places\alarm.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\places\alarm.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\americana.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\americana.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\accwiz\acwzdat12.accdu to %ProgramFiles%\microsoft office\office14\accwiz\acwzdat12.accdu.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10253_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10253_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\proof\msgr3en.lex to %ProgramFiles%\microsoft office\office14\proof\msgr3en.lex.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\browser\features\webcompat@mozilla.org.xpi to %ProgramFiles%\mozilla firefox\browser\features\webcompat@mozilla.org.xpi.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\adobe.css to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\adobe.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\customer support.fdt to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\customer support.fdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\fax\equityfax.dotx to %ProgramFiles%\microsoft office\templates\1033\fax\equityfax.dotx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\adjacencyletter.dotx to %ProgramFiles%\microsoft office\templates\1033\adjacencyletter.dotx.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\add.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\add.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\pubspapr\papers.ini to %ProgramFiles%\microsoft office\office14\1033\pubspapr\papers.ini.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\cursors.properties to %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\cursors.properties.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_adobe.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_adobe.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\lines\bd10219_.gif to %ProgramFiles%\microsoft office\media\office14\lines\bd10219_.gif.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\internet explorer (no add-ons).lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\internet explorer (no add-ons).lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\sendto\desktop (create shortcut).desklink to %APPDATA%\microsoft\windows\sendto\desktop (create shortcut).desklink.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\bookmarkbackups\bookmarks-2024-03-21_11_w-7ab47btxtewdh4a2yehg==.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\bookmarkbackups\bookmarks-2024-03-21_11_w-7ab47btxtewdh4a2yehg==.jsonlz4.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\onenote\sendtoonenote.gpd to %ProgramFiles%\microsoft office\office14\onenote\sendtoonenote.gpd.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\2a211dea-1f81-457a-9f7c-a174126ff0dd to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\2a211dea-1f81-457a-9f7c-a174126ff0dd.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\add.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\add.gif.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\internet explorer (64-bit).lnk to %APPDATA%\microsoft\windows\start menu\programs\internet explorer (64-bit).lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\calendars.properties to %ProgramFiles%\java\jre1.8.0_45\lib\calendars.properties.ghb1iutxvony_rsa
  • from %ProgramFiles%\internet explorer\signup\install.ins to %ProgramFiles%\internet explorer\signup\install.ins.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\autoshap\autoshap.dll to %ProgramFiles%\microsoft office\media\office14\autoshap\autoshap.dll.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\ease of access.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\ease of access.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\command prompt.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\command prompt.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\isp\bogofilter.sfd to %ProgramFiles%\mozilla thunderbird\isp\bogofilter.sfd.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\cagcat10\cagcat10.dll to %ProgramFiles%\microsoft office\media\cagcat10\cagcat10.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\header.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\header.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\accdds.dll to %ProgramFiles%\microsoft office\office14\accdds.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\act3.sam to %ProgramFiles%\microsoft office\office14\convert\act3.sam.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\as80.xsl to %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\as80.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\bibliography\author2string.xsl to %ProgramFiles%\microsoft office\office14\bibliography\author2string.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\part\1 right.accdt to %ProgramFiles%\microsoft office\templates\1033\access\part\1 right.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\office10.dll to %ProgramFiles%\microsoft office\media\office14\office10.dll.ghb1iutxvony_rsa
  • from %APPDATA%\thunderbird\installs.ini to %APPDATA%\thunderbird\installs.ini.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.dll to %ProgramFiles%\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\borders\msart1.bdr to %ProgramFiles%\microsoft office\office14\borders\msart1.bdr.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\51da22b7-9513-4885-adb9-cd2e72f47f0a to %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\51da22b7-9513-4885-adb9-cd2e72f47f0a.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\protect\credhist to %APPDATA%\microsoft\protect\credhist.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\libraries\documents.library-ms to %APPDATA%\microsoft\windows\libraries\documents.library-ms.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget to %APPDATA%\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\datareporting\session-state.json to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\datareporting\session-state.json.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\previous.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\previous.jsonlz4.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3150914307-1777937420-491476919-1000\f58155b4b1d5a524ca0261c3ee99fb50_d99ef00b-ccd3-4f1d-9980-90ac453b0b47 to %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3150914307-1777937420-491476919-1000\f58155b4b1d5a524ca0261c3ee99fb50_d99ef00b-ccd3-4f1d-9980-90ac453b0b47.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\browser\features\webcompat-reporter@mozilla.org.xpi to %ProgramFiles%\mozilla firefox\browser\features\webcompat-reporter@mozilla.org.xpi.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\distibution\policies.json to %ProgramFiles%\mozilla firefox\distibution\policies.json.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\installs.ini to %APPDATA%\mozilla\firefox\installs.ini.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\add.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\add.gif.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\computer.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\computer.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\maintenance\help.lnk to %APPDATA%\microsoft\windows\start menu\programs\maintenance\help.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\installer_prefs.json to %ProgramFiles(x86)%\opera\installer_prefs.json.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\dataservices\+connect to new data source.odc to %ProgramFiles%\microsoft office\office14\1033\dataservices\+connect to new data source.odc.ghb1iutxvony_rsa
  • from %ProgramFiles%\winrar\ace32loader.exe to %ProgramFiles%\winrar\ace32loader.exe.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\defaults\pref\channel-prefs.js to %ProgramFiles%\mozilla firefox\defaults\pref\channel-prefs.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\queries\msn moneycentral investor currency rates.iqy to %ProgramFiles%\microsoft office\office14\queries\msn moneycentral investor currency rates.iqy.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\accessibility.properties to %ProgramFiles%\java\jre1.8.0_45\lib\accessibility.properties.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\onenote\sendtoonenote-pipelineconfig.xml to %ProgramFiles%\microsoft office\office14\onenote\sendtoonenote-pipelineconfig.xml.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\readme.htm to %ProgramFiles(x86)%\adobe\acrobat reader dc\readme.htm.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\installation_status.xml to %ProgramFiles(x86)%\opera\installation_status.xml.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\accessible.tlb to %ProgramFiles%\mozilla thunderbird\accessible.tlb.ghb1iutxvony_rsa
  • from %ProgramFiles%\windows sidebar\settings.ini to %ProgramFiles%\windows sidebar\settings.ini.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\browser\features\screenshots@mozilla.org.xpi to %ProgramFiles%\mozilla firefox\browser\features\screenshots@mozilla.org.xpi.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\browser\features\formautofill@mozilla.org.xpi to %ProgramFiles%\mozilla firefox\browser\features\formautofill@mozilla.org.xpi.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\browser\features\doh-rollout@mozilla.org.xpi to %ProgramFiles%\mozilla firefox\browser\features\doh-rollout@mozilla.org.xpi.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\.metadata-v2 to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\.metadata-v2.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\firefox.lnk to %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\firefox.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\default\moz-extension+++5fc1ef9c-f7bf-452f-a7ef-92635f5362ce^usercontextid=4294967295\.metadata-v2 to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\default\moz-extension+++5fc1ef9c-f7bf-452f-a7ef-92635f5362ce^usercontextid=4294967295\.metadata-v2.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\license.txt to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\license.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\background.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\background.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\browser\omni.ja to %ProgramFiles%\mozilla firefox\browser\omni.ja.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubwiz\acctbox.poc to %ProgramFiles%\microsoft office\office14\pubwiz\acctbox.poc.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk to %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\bin\awt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\awt.dll.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\manifest.json to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\manifest.json.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\accessiblehandler.dll to %ProgramFiles%\mozilla thunderbird\accessiblehandler.dll.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\libraries\music.library-ms to %APPDATA%\microsoft\windows\libraries\music.library-ms.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\queries\msn moneycentral investor stock quotes.iqy to %ProgramFiles%\microsoft office\office14\queries\msn moneycentral investor stock quotes.iqy.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\winrar\console rar manual.lnk to %APPDATA%\microsoft\windows\start menu\programs\winrar\console rar manual.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\datareporting\state.json to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\datareporting\state.json.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\copyright to %ProgramFiles%\java\jre1.8.0_45\copyright.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\fonts\twemojimozilla.ttf to %ProgramFiles%\mozilla firefox\fonts\twemojimozilla.ttf.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\msbuild\microsoft.office.infopath.targets to %ProgramFiles(x86)%\msbuild\microsoft.office.infopath.targets.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\library\eurotool.xlam to %ProgramFiles%\microsoft office\office14\library\eurotool.xlam.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\forms\1033\activitl.ico to %ProgramFiles%\microsoft office\office14\forms\1033\activitl.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\accessible.tlb to %ProgramFiles%\mozilla firefox\accessible.tlb.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\stationery\1033\currency.gif to %ProgramFiles%\microsoft office\stationery\1033\currency.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\ext\access-bridge-64.jar to %ProgramFiles%\java\jre1.8.0_45\lib\ext\access-bridge-64.jar.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubba\mspub10.bdr to %ProgramFiles%\microsoft office\office14\pubba\mspub10.bdr.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles.ini to %APPDATA%\mozilla\firefox\profiles.ini.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\control panel.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\control panel.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\dataservices\+newsqlserverconnection.odc to %ProgramFiles%\microsoft office\office14\1033\dataservices\+newsqlserverconnection.odc.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\google chrome.lnk to %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\google chrome.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\browser\crashreporter-override.ini to %ProgramFiles%\mozilla firefox\browser\crashreporter-override.ini.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubwiz\accsbar.poc to %ProgramFiles%\microsoft office\office14\pubwiz\accsbar.poc.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\adobe.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\adobe.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\adobe.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms4\formsstyles\adobe.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\queries\msn moneycentral investor major indicies.iqy to %ProgramFiles%\microsoft office\office14\queries\msn moneycentral investor major indicies.iqy.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\m15ucxjx.default\times.json to %APPDATA%\mozilla\firefox\profiles\m15ucxjx.default\times.json.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlceca35.dll to %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlceca35.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\background.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\background.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\1033\act3r.sam to %ProgramFiles%\microsoft office\office14\convert\1033\act3r.sam.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\license to %ProgramFiles%\java\jre1.8.0_45\license.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143744.gif to %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143744.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\convert\1033\delimr.fae to %ProgramFiles%\microsoft office\office14\convert\1033\delimr.fae.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\run.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\run.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\thunderbird\profiles.ini to %APPDATA%\thunderbird\profiles.ini.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\onenote\sendtoonenote.ini to %ProgramFiles%\microsoft office\office14\onenote\sendtoonenote.ini.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\tab_off.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\tab_off.gif.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\71d7d59d-5451-4f15-bb9e-420e88a3061f to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\saved-telemetry-pings\71d7d59d-5451-4f15-bb9e-420e88a3061f.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\people\giggle.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\people\giggle.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\forms\1033\activits.ico to %ProgramFiles%\microsoft office\office14\forms\1033\activits.ico.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\header.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\header.gif.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\libraries\videos.library-ms to %APPDATA%\microsoft\windows\libraries\videos.library-ms.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\americana.css to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\americana.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\accessiblemarshal.dll to %ProgramFiles%\mozilla thunderbird\accessiblemarshal.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\bin\bci.dll to %ProgramFiles%\java\jre1.8.0_45\bin\bci.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\release to %ProgramFiles%\java\jre1.8.0_45\release.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\bl.gif to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\bl.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_linknodrop32x32.gif to %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_linknodrop32x32.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\infopathom\infopathomformservices\infopathomformservicesv12\microsoft.office.infopath.dll to %ProgramFiles%\microsoft office\office14\infopathom\infopathomformservices\infopathomformservicesv12\microsoft.office.infopath.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\management\jmxremote.password.template to %ProgramFiles%\java\jre1.8.0_45\lib\management\jmxremote.password.template.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidabrightdemiitalic.ttf to %ProgramFiles%\java\jre1.8.0_45\lib\fonts\lucidabrightdemiitalic.ttf.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\security\blacklisted.certs to %ProgramFiles%\java\jre1.8.0_45\lib\security\blacklisted.certs.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\pubspapr\pdir10f.gif to %ProgramFiles%\microsoft office\office14\1033\pubspapr\pdir10f.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\babyblue.css to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\babyblue.css.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\attention.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms5\attention.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\lines\bd10256_.gif to %ProgramFiles%\microsoft office\media\office14\lines\bd10256_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\solutions\document.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\solutions\document.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\places\buzz.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\places\buzz.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\document themes 14\theme effects\angles.eftx to %ProgramFiles%\microsoft office\document themes 14\theme effects\angles.eftx.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\readme.txt to %ProgramFiles%\java\jre1.8.0_45\readme.txt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\background.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\swirl\background.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\isp\popfile.sfd to %ProgramFiles%\mozilla thunderbird\isp\popfile.sfd.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\autoshap\bd18180_.wmf to %ProgramFiles%\microsoft office\media\office14\autoshap\bd18180_.wmf.ghb1iutxvony_rsa
  • from %ProgramFiles%\winrar\default64.sfx to %ProgramFiles%\winrar\default64.sfx.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\isp\dspam.sfd to %ProgramFiles%\mozilla thunderbird\isp\dspam.sfd.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\as80.xsl to %ProgramFiles(x86)%\microsoft analysis services\as oledb\10\cartridges\as80.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.server.dll to %ProgramFiles%\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.server.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlcecompact35.dll to %ProgramFiles%\microsoft sql server compact edition\v3.5\sqlcecompact35.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\onenote\sendtoonenotefilter.dll to %ProgramFiles%\microsoft office\office14\onenote\sendtoonenotefilter.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubba\mspub1a.bdr to %ProgramFiles%\microsoft office\office14\pubba\mspub1a.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\a3dutils.dll to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\a3dutils.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\hiring requisition - customized.fdt to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\hiring requisition - customized.fdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\people\hiccup.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\people\hiccup.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\tab_on.gif to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms3\formsstyles\sts2\tab_on.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10264_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10264_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\lines\bd10289_.gif to %ProgramFiles%\microsoft office\media\office14\lines\bd10289_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\privateassemblies\microsoft.visualstudio.tools.applications.project.dll to %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\privateassemblies\microsoft.visualstudio.tools.applications.project.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\bibliography\style\apasixtheditionofficeonline.xsl to %ProgramFiles%\microsoft office\office14\bibliography\style\apasixtheditionofficeonline.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.adapter.dll to %ProgramFiles(x86)%\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.adapter.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\accessiblemarshal.dll to %ProgramFiles%\mozilla firefox\accessiblemarshal.dll.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\narrator.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\narrator.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\windows explorer.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\windows explorer.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft analysis services\as oledb\10\msmdlocal.dll to %ProgramFiles%\microsoft analysis services\as oledb\10\msmdlocal.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\xml files\grvschema.xsd to %ProgramFiles%\microsoft office\office14\groove\xml files\grvschema.xsd.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_movenodrop32x32.gif to %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_movenodrop32x32.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\isp\spampal.sfd to %ProgramFiles%\mozilla thunderbird\isp\spampal.sfd.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\tab_on.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\tab_on.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\isp\spamassassin.sfd to %ProgramFiles%\mozilla thunderbird\isp\spamassassin.sfd.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_movedrop32x32.gif to %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_movedrop32x32.gif.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\br.gif to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\br.gif.ghb1iutxvony_rsa
  • from %APPDATA%\thunderbird\crash reports\installtime20210406220621 to %APPDATA%\thunderbird\crash reports\installtime20210406220621.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\sendto\mail recipient.mapimail to %APPDATA%\microsoft\windows\sendto\mail recipient.mapimail.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\tab_off.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\sts2\tab_off.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubwiz\ad.dpv to %ProgramFiles%\microsoft office\office14\pubwiz\ad.dpv.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_linkdrop32x32.gif to %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_linkdrop32x32.gif.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\sendto\fax recipient.lnk to %APPDATA%\microsoft\windows\sendto\fax recipient.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\background.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\background.gif.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk to %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\preferred to %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\preferred.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_copynodrop32x32.gif to %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_copynodrop32x32.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10263_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10263_.gif.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\windows media player.lnk to %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\windows media player.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk to %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\tab_off.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\tab_off.gif.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\upgrade.jsonlz4-20200708170202 to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\upgrade.jsonlz4-20200708170202.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_copydrop32x32.gif to %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\win32_copydrop32x32.gif.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.lib to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.lib.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\a786b820-2a9e-4925-b3ac-88dea09c4a01 to %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\a786b820-2a9e-4925-b3ac-88dea09c4a01.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10255_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10255_.gif.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\windows explorer.lnk to %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\windows explorer.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\button.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\button.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\tab_on.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\formsstyles\brightorange\tab_on.gif.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\default\moz-extension+++5fc1ef9c-f7bf-452f-a7ef-92635f5362ce^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.sql... to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\default\moz-extension+++5fc1ef9c-f7bf-452f-a7ef-92635f5362ce^usercontextid=4294967295\idb\3647222921wleabceoxlt-eengsairo.sql...
  • from %ProgramFiles%\microsoft office\stationery\1033\dadshirt.gif to %ProgramFiles%\microsoft office\stationery\1033\dadshirt.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\invalid32x32.gif to %ProgramFiles%\java\jre1.8.0_45\lib\images\cursors\invalid32x32.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\defaults\pref\channel-prefs.js to %ProgramFiles%\mozilla thunderbird\defaults\pref\channel-prefs.js.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\recovery.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\sessionstore-backups\recovery.jsonlz4.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\bullets\bd10254_.gif to %ProgramFiles%\microsoft office\media\office14\bullets\bd10254_.gif.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\74356068-1388-41cc-9c6d-3d77345b06f6 to %APPDATA%\microsoft\protect\s-1-5-21-3150914307-1777937420-491476919-1000\74356068-1388-41cc-9c6d-3d77345b06f6.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\opera.lnk to %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\opera.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\libraries\pictures.library-ms to %APPDATA%\microsoft\windows\libraries\pictures.library-ms.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\browser\override.ini to %ProgramFiles%\mozilla firefox\browser\override.ini.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk to %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\thunderbird\profiles\chdgbv82.default-release\crashes\store.json.mozlz4 to %APPDATA%\thunderbird\profiles\chdgbv82.default-release\crashes\store.json.mozlz4.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\steam\public\steambootstrapper_bulgarian.txt to %ProgramFiles(x86)%\steam\public\steambootstrapper_bulgarian.txt.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.sig to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\gmp-widevinecdm\4.10.1582.2\widevinecdm.dll.sig.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\opera\resources.pri to %ProgramFiles(x86)%\opera\resources.pri.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\as90.xsl to %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\as90.xsl.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\media\arrow.wav to %ProgramFiles%\microsoft office\office14\media\arrow.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\deploy\messages.properties to %ProgramFiles%\java\jre1.8.0_45\lib\deploy\messages.properties.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\media\office14\office10.mmw to %ProgramFiles%\microsoft office\media\office14\office10.mmw.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\add_reviewer.gif to %ProgramFiles(x86)%\adobe\acrobat reader dc\reader\tracker\add_reviewer.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\java\jre1.8.0_45\lib\ext\cldrdata.jar to %ProgramFiles%\java\jre1.8.0_45\lib\ext\cldrdata.jar.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\hardware tracker.fdt to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveforms\formstemplates\hardware tracker.fdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143743.gif to %ProgramFiles%\microsoft office\clipart\publisher\backgrounds\j0143743.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\hierarchy.js to %ProgramFiles%\microsoft office\office14\groove\tooldata\groove.net\grooveprojecttoolset\projecttool\project report type\fancy\hierarchy.js.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\borders\msart10.bdr to %ProgramFiles%\microsoft office\office14\borders\msart10.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\clipart\pub60cor\ag00004_.gif to %ProgramFiles%\microsoft office\clipart\pub60cor\ag00004_.gif.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\pubba\mspub11.bdr to %ProgramFiles%\microsoft office\office14\pubba\mspub11.bdr.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla firefox\accessiblehandler.dll to %ProgramFiles%\mozilla firefox\accessiblehandler.dll.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\m15ucxjx.default\user.js to %APPDATA%\mozilla\firefox\profiles\m15ucxjx.default\user.js.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\private character editor.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\private character editor.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\notepad.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\notepad.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\internet explorer.lnk to %APPDATA%\microsoft\windows\start menu\programs\internet explorer.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\microsoft office\office14\authzax.dll to %ProgramFiles(x86)%\microsoft office\office14\authzax.dll.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\access12.acc to %ProgramFiles%\microsoft office\office14\1033\access12.acc.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\part\1 top.accdt to %ProgramFiles%\microsoft office\templates\1033\access\part\1 top.accdt.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\templates\1033\access\datatype\category.accft to %ProgramFiles%\microsoft office\templates\1033\access\datatype\category.accft.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\groove\sounds\things\can.wav to %ProgramFiles%\microsoft office\office14\groove\sounds\things\can.wav.ghb1iutxvony_rsa
  • from %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_casual.gif to %ProgramFiles%\microsoft office\office14\1033\grooveforms5\bg_casual.gif.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\magnify.lnk to %APPDATA%\microsoft\windows\start menu\programs\accessories\accessibility\magnify.lnk.ghb1iutxvony_rsa
  • from %APPDATA%\microsoft\windows\start menu\programs\winrar\what is new in the latest version.lnk to %APPDATA%\microsoft\windows\start menu\programs\winrar\what is new in the latest version.lnk.ghb1iutxvony_rsa
  • from %ProgramFiles%\mozilla thunderbird\chrome\icons\default\abcardwindow.ico to %ProgramFiles%\mozilla thunderbird\chrome\icons\default\abcardwindow.ico.ghb1iutxvony_rsa
  • from %ProgramFiles(x86)%\windows sidebar\settings.ini to %ProgramFiles(x86)%\windows sidebar\settings.ini.ghb1iutxvony_rsa
  • from %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite to %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.ghb1iutxvony_rsa
  • from %APPDATA%\thunderbird\profiles\chdgbv82.default-release\abook.sqlite to %APPDATA%\thunderbird\profiles\chdgbv82.default-release\abook.sqlite.ghb1iutxvony_rsa
Modifies the following files
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3150914307-1777937420-491476919-1000\f58155b4b1d5a524ca0261c3ee99fb50_d99ef00b-ccd3-4f1d-9980-90ac453b0b47
  • %ALLUSERSPROFILE%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
  • %ALLUSERSPROFILE%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\state.rsm
  • %ALLUSERSPROFILE%\package cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
  • %ALLUSERSPROFILE%\package cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\state.rsm
  • %ALLUSERSPROFILE%\mozilla\updates\308046b0af4a39cb\update-config.json
  • %APPDATA%\mozilla\firefox\installs.ini
  • %ProgramFiles%\mozilla firefox\defaults\pref\channel-prefs.js
  • %ProgramFiles%\microsoft office\office14\queries\msn moneycentral investor currency rates.iqy
  • %ProgramFiles%\java\jre1.8.0_45\lib\accessibility.properties
  • %ALLUSERSPROFILE%\microsoft help\hx.hxn
  • %ProgramFiles%\microsoft office\office14\onenote\sendtoonenote-pipelineconfig.xml
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\readme.htm
  • %ProgramFiles(x86)%\opera\installation_status.xml
  • %ProgramFiles%\mozilla thunderbird\accessible.tlb
  • %ProgramFiles%\windows sidebar\settings.ini
  • %ProgramFiles%\mozilla firefox\browser\features\screenshots@mozilla.org.xpi
  • C:\users\public\desktop\firefox.lnk
  • %ProgramFiles%\mozilla firefox\browser\features\formautofill@mozilla.org.xpi
  • C:\users\public\desktop\acrobat reader dc.lnk
  • %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\tokens.dat
  • %ProgramFiles%\mozilla firefox\browser\features\doh-rollout@mozilla.org.xpi
  • %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\storage\permanent\chrome\.metadata-v2
  • %LOCALAPPDATA%low\microsoft\internet explorer\services\search_{0633ee93-d776-472f-a0ff-e1416b8b2e3a}.ico
  • C:\kms\kms_vl_all_aio_debug.log
  • C:\kms\kms_vl_all_aio.cmd
  • <Drive name for removable media>:\split.avi
  • D:\install.log
  • %LOCALAPPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\cache2\entries\0eddf8c091e2fed62e44bedddc1723f5bf38fe4f
  • %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\firefox.lnk
Modifies multiple files.
Substitutes the following files
  • %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-3150914307-1777937420-491476919-1000\f58155b4b1d5a524ca0261c3ee99fb50_d99ef00b-ccd3-4f1d-9980-90ac453b0b47
Modifies user data files (Trojan.Encoder).
Changes user data files extensions (Trojan.Encoder).
Miscellaneous
Executes the following
  • '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\delog.cmd" "
  • '%WINDIR%\syswow64\cmd.exe' /c wevtutil.exe el
  • '%WINDIR%\syswow64\wevtutil.exe' el
  • '%WINDIR%\syswow64\wevtutil.exe' cl "Analytic"
  • '%WINDIR%\syswow64\wevtutil.exe' cl "Application"
  • '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\delog.cmd" "' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android