Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'UpdateTask' = '%APPDATA%\svchost.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\read_it.txt
- <Drive name for removable media>:\read_it.txt
- <Drive name for removable media>:\middaugh_keynote.pptx.6wum
- <Drive name for removable media>:\samieee_obiee_presentation.pptx.zufw
- <Drive name for removable media>:\iso27k_isms_implementation_and_certification_process_overview_v2.pptx.xdti
- <Drive name for removable media>:\system volume information\wpsettings.dat.fdf9
- <Drive name for removable media>:\system volume information\wpsettings.dat
- <Drive name for removable media>:\system volume information\read_it.txt
- <Drive name for removable media>:\surprise.exe
- %HOMEPATH%\desktop\1189.jpeg
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %HOMEPATH%\desktop\toolbar.bmp
- %HOMEPATH%\desktop\tileimage.bmp
- %HOMEPATH%\desktop\thlps_keeper_mayer_1965.docx
- %HOMEPATH%\desktop\testcertificate.cer
- %HOMEPATH%\desktop\sdksampleunprivdeveloper.cer
- %HOMEPATH%\desktop\sdkfailsafeemulator.cer
- %HOMEPATH%\desktop\region-north-karelia.jpg
- %HOMEPATH%\desktop\pmd.cer
- %HOMEPATH%\desktop\parnas_01.jpg
- %HOMEPATH%\desktop\ituneshelpunavailable.html
- %HOMEPATH%\desktop\ituneshelpunavailable.htm
- %HOMEPATH%\desktop\iisstart.html
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\glidescope_review_rev_010.docx
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\contoso_1.cer
- %HOMEPATH%\desktop\contosoroot.cer
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\desktop\alert.htm
- %HOMEPATH%\desktop\advice_process.htm
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\3.jpg
- %HOMEPATH%\desktop\2.jpeg
- %HOMEPATH%\desktop\13.jpg
- %HOMEPATH%\desktop\13.jpeg
- %HOMEPATH%\desktop\1189.jpg
- %APPDATA%\mozilla\firefox\profiles.ini
- %APPDATA%\thunderbird\profiles.ini
- %TEMP%\content\2512-1532-<File name>.exe-18-57-24-968.dump
- %LOCALAPPDATA%\packages\microsoft.microsoftsolitairecollection_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.microsoftstickynotes_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.mixedreality.portal_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.mspaint_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\bibliography\style\apasixtheditionofficeonline.xsl.0x93
- %LOCALAPPDATA%\packages\microsoft.office.onenote_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\bibliography\style\read_it.txt
- %APPDATA%\microsoft\bibliography\style\chicago.xsl.92b5
- %LOCALAPPDATA%\packages\microsoft.oneconnect_8wekyb3d8bbwe\localstate\diagoutputdir\read_it.txt
- %APPDATA%\microsoft\bibliography\style\gb.xsl.j4gc
- %LOCALAPPDATA%\packages\microsoft.oneconnect_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\bibliography\style\gostname.xsl.f9no
- %LOCALAPPDATA%\packages\microsoft.people_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\bibliography\style\gosttitle.xsl.r0a5
- %APPDATA%\microsoft\bibliography\style\harvardanglia2008officeonline.xsl.7hhm
- %LOCALAPPDATA%\packages\microsoft.microsoftofficehub_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\accessibility\on-screen keyboard.lnk.xpzd
- %LOCALAPPDATA%\packages\microsoft.microsoftedge_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.microsoftedge_8wekyb3d8bbwe\ac\microsoftedge\user\default\dntexception\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\upps\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\webcache\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.messaging_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\winx\group1\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.microsoft3dviewer_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\winx\group2\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\winx\group3\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.microsoftedgedevtoolsclient_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\windows sidebar\read_it.txt
- %LOCALAPPDATA%\microsoftedge\sharedcachecontainers\microsoftedge_dntexception\read_it.txt
- %LOCALAPPDATA%\microsoftedge\sharedcachecontainers\microsoftedge_iecompat\read_it.txt
- %LOCALAPPDATA%\microsoftedge\sharedcachecontainers\microsoftedge_iecompatua\read_it.txt
- %TEMP%\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.microsoftedge_8wekyb3d8bbwe\ac\microsoftedge\history\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.microsoftedge_8wekyb3d8bbwe\ac\microsoftedge\user\default\datastore\data\nouser1\120712-0049\dbstore\logfiles\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.microsoftedge_8wekyb3d8bbwe\ac\microsoftedge\user\default\recovery\active\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\shell\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.lockapp_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\microsoft\bibliography\style\iso690.xsl.r8lf
- %APPDATA%\microsoft\windows\accountpictures\read_it.txt
- %APPDATA%\microsoft\windows\libraries\read_it.txt
- %APPDATA%\microsoft\windows\recent\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.webmediaextensions_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\windows\sendto\bluetooth file transfer.lnk.sb90
- %APPDATA%\microsoft\windows\sendto\read_it.txt
- %APPDATA%\microsoft\windows\sendto\fax recipient.lnk.mr2v
- %APPDATA%\microsoft\windows\start menu\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\onedrive.lnk.3njt
- %APPDATA%\microsoft\windows\start menu\programs\accessibility\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\accessibility\magnify.lnk.lei4
- %LOCALAPPDATA%\packages\microsoft.webpimageextension_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\accessibility\narrator.lnk.eq7f
- %LOCALAPPDATA%\packages\microsoft.print3d_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.wallet_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\bibliography\style\ieee2006officeonline.xsl.g0jd
- %LOCALAPPDATA%\packages\microsoft.vp9videoextensions_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.ppiprojection_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.screensketch_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\bibliography\style\iso690nmerical.xsl.cox5
- %APPDATA%\microsoft\bibliography\style\mlaseventheditionofficeonline.xsl.v56w
- %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\ac\<INETFILES>\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\ac\inetcookies\ese\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\localstate\read_it.txt
- %APPDATA%\microsoft\bibliography\style\sist02.xsl.vo5c
- %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\localstate\diagoutputdir\read_it.txt
- %APPDATA%\microsoft\bibliography\style\turabian.xsl.elw3
- %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\settings\read_it.txt
- %APPDATA%\microsoft\internet explorer\quick launch\read_it.txt
- %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk.fll6
- %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk.p99t
- %LOCALAPPDATA%\packages\microsoft.storepurchaseapp_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk.qwxi
- %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\file explorer.lnk.s7nl
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_pt\read_it.txt
- %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.desktopappinstaller_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\internet explorer\recovery\active\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\images\darktheme\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\logoimages\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\read_it.txt
- %HOMEPATH%\links\downloads.lnk.wp47
- %LOCALAPPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\startupcache\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows defender.bak\scans\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows defender.bak\scans\history\cachemanager\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows defender.bak\scans\history\service\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows defender.bak\support\read_it.txt
- %LOCALAPPDATA%\packages\1527c705-839a-4832-9118-54d4bd6a0c89_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\darktheme\read_it.txt
- %LOCALAPPDATA%\microsoft\internet explorer\iecompatdata\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.getstarted_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\internet explorer\read_it.txt
- %LOCALAPPDATA%\microsoft\gamedvr\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\lfsvc\geofence\s-1-5-21-2377844457-1847597103-2569463324-1000_s-1-15-2-2551677095-2355568638-4209445997-2436930744-3692183382-387691378-1866284433\read_it.tx...
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ro\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ru\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\se\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sk\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\th\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\tr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\uk\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\vi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_cn\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_tw\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\session storage\read_it.txt
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\read_it.txt
- %HOMEPATH%\links\desktop.lnk.3s02
- %LOCALAPPDATA%\packages\microsoft.heifimageextension_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\notifications\read_it.txt
- %LOCALAPPDATA%\packages\e2a4f912-2574-4a75-9bb0-0d023378592b_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\caches\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\explorer\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.ecapp_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\history\low\history.ie5\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\iecompatcache\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\iecompatcache\low\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\iecompatuacache\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\iecompatuacache\low\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\ie\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.gethelp_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\inetcookies\dntexception\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\inetcookies\ese\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows nt\msscan\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\burn\burn\read_it.txt
- %ALLUSERSPROFILE%\microsoft onedrive\setup\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\application shortcuts\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows nt\msfax\virtualinbox\en-us\read_it.txt
- %LOCALAPPDATA%\packages\f46d4000-fd22-4db4-ac8e-4e1ddde828fe_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\images\lighttheme\read_it.txt
- %LOCALAPPDATA%\packages\inputapp_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.aad.brokerplugin_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.accountscontrol_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.asynctextservice_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.bingweather_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\settings\personal\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.bioenrollment_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\onedrive\setup\logs\read_it.txt
- %LOCALAPPDATA%\microsoft\penworkspace\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.creddialoghost_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\vault\userprofileroaming\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\1033\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\lfsvc\geofence\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\accessories\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\administrative tools\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.secureassessmentbrowser_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.shellexperiencehost_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.startmenuexperiencehost_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\telegram desktop\read_it.txt
- %APPDATA%\thunderbird\installs.ini.034m
- %APPDATA%\thunderbird\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.startmenuexperiencehost_cw5n1h2txyewy\tempstate\read_it.txt
- %APPDATA%\thunderbird\profiles.ini.ywb7
- %APPDATA%\thunderbird\profiles\mt2yxlwj.default\times.json.25i8
- %APPDATA%\thunderbird\profiles\mt2yxlwj.default\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.xgpuejectdialog_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\addons.json.6fm1
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\read_it.txt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\alternateservices.txt.xv66
- %LOCALAPPDATA%\packages\microsoft.windowsalarms_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.sechealthui_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\datareporting\glean\db\data.safe.bin.6tar
- %TEMP%\{00a55dfd-ecc5-4a28-80d7-7c391f06f241}.png
- %LOCALAPPDATA%\packages\microsoft.windows.photos_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\security_state\data.safe.bin.o02e
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\security_state\read_it.txt
- %APPDATA%\opera software\opera stable\default_partner_content.json.asrk
- %APPDATA%\opera software\opera stable\read_it.txt
- %APPDATA%\opera software\opera stable\opera_autoupdate.log.hf22
- %APPDATA%\opera software\opera stable\update_prefs.json.mxg2
- %APPDATA%\opera software\opera stable\dictionaries\read_it.txt
- %APPDATA%\opera software\opera stable\extension state\000003.log.ekcy
- %APPDATA%\opera software\opera stable\extension state\read_it.txt
- %APPDATA%\opera software\opera stable\themes_backup\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.narratorquickstart_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.oobenetworkcaptiveportal_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.oobenetworkconnectionflow_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.parentalcontrols_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.peopleexperiencehost_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.pinningconfirmationdialog_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\datareporting\glean\db\read_it.txt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\compatibility.ini.yehd
- %LOCALAPPDATA%\packages\microsoft.windowscalculator_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.xbox.tcui_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.xboxgamecallableui_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.xboxgamingoverlay_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.xboxidentityprovider_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.xboxgameoverlay_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.xboxspeechtotextoverlay_8wekyb3d8bbwe\settings\read_it.txt
- %HOMEPATH%\saved games\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.yourphone_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.zunevideo_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\microsoft\windows\explorer\notifyicon\microsoft.explorer.notification.{f3021280-8b71-ae51-7bf9-daa692344272}.png
- %LOCALAPPDATA%\packages\windows.cbspreview_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\windows.immersivecontrolpanel_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\windows.printdialog_cw5n1h2txyewy\settings\read_it.txt
- D:\$recycle.bin\s-1-5-21-2377844457-1847597103-2569463324-1000\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windowsstore_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.xboxapp_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\extension-preferences.json.c5bt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\directorytree.json.aqxp
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\datareporting\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windowscamera_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\ac\inethistory\backgroundtransferapi\read_it.txt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\pkcs11.txt.u1nb
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\prefs.js.4huu
- %LOCALAPPDATA%\packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\securitypreloadstate.txt.qzyt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\sessioncheckpoints.json.p77m
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\sitesecurityservicestate.txt.i26b
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\times.json.d383
- %LOCALAPPDATA%\packages\microsoft.windowsfeedbackhub_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\xulstore.json.r77b
- %LOCALAPPDATA%\packages\microsoft.windowsmaps_8wekyb3d8bbwe\settings\read_it.txt
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\datareporting\session-state.json.eecu
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\datareporting\state.json.mqti
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\extensions.json.34d9
- %LOCALAPPDATA%\packages\microsoft.windowssoundrecorder_8wekyb3d8bbwe\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.win32webviewhost_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\accessories\internet explorer.lnk.oep9
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\datareporting\session-state.json.ez7z
- %APPDATA%\microsoft\windows\start menu\programs\windows powershell\windows powershell (x86).lnk.ueri
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\ac\<INETFILES>\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\windows powershell\windows powershell ise (x86).lnk.8jw7
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\ac\inetcookies\ese\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\windows powershell\windows powershell ise.lnk.myo8
- %APPDATA%\microsoft\windows\start menu\programs\windows powershell\windows powershell.lnk.6duo
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\202914\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\280810\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\280811\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\winrar\console rar manual.lnk.tby3
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\280815\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\winrar\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\310091\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\telegram desktop\uninstall telegram.lnk.kvs1
- %LOCALAPPDATA%\packages\microsoft.windows.capturepicker_cw5n1h2txyewy\settings\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.cloudexperiencehost_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\windows powershell\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\winrar\what is new in the latest version.lnk.5r1q
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\datareporting\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\google chrome\google chrome.lnk.btud
- %LOCALAPPDATA%\packages\microsoft.windows.apprep.chxapp_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\google chrome\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\maintenance\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\system tools\administrative tools.lnk.m6ry
- %LOCALAPPDATA%\packages\microsoft.windows.assignedaccesslockapp_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\system tools\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\system tools\command prompt.lnk.tzcb
- %APPDATA%\microsoft\windows\start menu\programs\system tools\computer.lnk.zqhl
- %APPDATA%\microsoft\windows\start menu\programs\system tools\control panel.lnk.o3ec
- %LOCALAPPDATA%\packages\microsoft.windows.callingshellapp_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\system tools\file explorer.lnk.9hyc
- %APPDATA%\microsoft\windows\start menu\programs\system tools\run.lnk.l6lh
- %APPDATA%\microsoft\windows\start menu\programs\telegram desktop\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\accessories\notepad.lnk.ixdx
- %APPDATA%\microsoft\windows\start menu\programs\telegram desktop\telegram.lnk.c3nf
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\datareporting\state.json.o4nt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\310093\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\338388\read_it.txt
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\containers.json.mldw
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\extension-preferences.json.77ie
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\settings\read_it.txt
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\extensions.json.1e8g
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\handlers.json.8wqm
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\pkcs11.txt.tx6j
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\prefs.js.jnby
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\sessioncheckpoints.json.ejzh
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\shield-preference-experiments.json.o3v7
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\sitesecurityservicestate.txt.5al9
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\times.json.q1lj
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\user.js.dq1b
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\xulstore.json.qjfp
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\compatibility.ini.7k9r
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\88000161\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\88000165\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\88000163\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\314559\read_it.txt
- %APPDATA%\microsoft\windows\start menu\programs\winrar\winrar help.lnk.ujvz
- %APPDATA%\microsoft\windows\start menu\programs\winrar\winrar.lnk.l71d
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\338389\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\353694\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\353698\read_it.txt
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\88000045\read_it.txt
- %APPDATA%\microsoft\windows\themes\cachedfiles\read_it.txt
- %APPDATA%\mozilla\firefox\installs.ini.l6d0
- %APPDATA%\mozilla\firefox\read_it.txt
- %APPDATA%\mozilla\firefox\profiles.ini.v0zx
- %APPDATA%\mozilla\firefox\profiles\jkail15y.default\times.json.rnk8
- %APPDATA%\mozilla\firefox\profiles\jkail15y.default\read_it.txt
- %APPDATA%\mozilla\firefox\profiles\jkail15y.default\user.js.i8wi
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\addons.json.7y6c
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\broadcast-listeners.json.nbxz
- %LOCALAPPDATA%\packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\localstate\contentmanagementsdk\creatives\338387\read_it.txt
- %APPDATA%\mozilla\firefox\profiles\la5zhz1m.default-release\read_it.txt
- %HOMEPATH%\links\read_it.txt
- %HOMEPATH%\favorites\links\read_it.txt
- %HOMEPATH%\favorites\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lv\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ms\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\nl\read_it.txt
- %ALLUSERSPROFILE%\microsoft\storage health\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\no\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_br\read_it.txt
- %ALLUSERSPROFILE%\mozilla\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_pt\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ro\read_it.txt
- %ALLUSERSPROFILE%\mozilla\updates\308046b0af4a39cb\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ru\read_it.txt
- %ALLUSERSPROFILE%\mozilla\updates\d78bf5dd33499ec2\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sk\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ko\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ja\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\id\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fr\read_it.txt
- %ALLUSERSPROFILE%\microsoft\network\downloader\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\he\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hi\read_it.txt
- %ALLUSERSPROFILE%\microsoft\office\read_it.txt
- %ALLUSERSPROFILE%\package cache\{a749d8e6-b613-3be3-8f5f-045c84eba29b}v12.0.21005\packages\vcruntimeminimum_amd64\read_it.txt
- %ALLUSERSPROFILE%\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\read_it.txt
- %ALLUSERSPROFILE%\package cache\{bd95a8cd-1d9f-35ad-981a-3e7925026ebb}v11.0.61030\packages\vcruntimeminimum_x86\read_it.txt
- %ALLUSERSPROFILE%\package cache\{cf2bea3c-26ea-32f8-aa9b-331f7e34ba97}v11.0.61030\packages\vcruntimeminimum_amd64\read_it.txt
- %ALLUSERSPROFILE%\package cache\{e699e009-1c3c-4e50-9b57-2b39f0954c7f}v14.29.30133\packages\vcruntimeadditional_amd64\read_it.txt
- %ALLUSERSPROFILE%\package cache\{ec9807de-b577-47b1-a024-0251805acf24}v14.29.30133\packages\vcruntimeminimum_x86\read_it.txt
- %ALLUSERSPROFILE%\package cache\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\packages\vcruntimeadditional_x86\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hr\read_it.txt
- %ALLUSERSPROFILE%\microsoft\smsrouter\messagestore\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hu\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\it\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fil\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\he\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fi\read_it.txt
- C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\window switcher.lnk.p7jf
- C:\users\default\appdata\roaming\microsoft\windows\sendto\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\sendto\fax recipient.lnk.839d
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\onedrive.lnk.u60u
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessibility\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\cs\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\da\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\de\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\el\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\en\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\es\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fil\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ca\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sv\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\bg\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\tr\read_it.txt
- C:\users\default\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\uk\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\vi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_cn\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_tw\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ar\read_it.txt
- C:\users\default\appdata\local\microsoft\windows\shell\read_it.txt
- %ALLUSERSPROFILE%\microsoft\uev\inboxtemplates\read_it.txt
- C:\users\default\appdata\local\microsoft\windows\winx\group1\read_it.txt
- C:\users\default\appdata\local\microsoft\windows\winx\group2\read_it.txt
- %ALLUSERSPROFILE%\microsoft\uev\templates\read_it.txt
- %ALLUSERSPROFILE%\microsoft\user account pictures\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\read_it.txt
- C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\th\read_it.txt
- C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\shows desktop.lnk.p758
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\eu\read_it.txt
- %ALLUSERSPROFILE%\microsoft\diagnosis\scenariossqlstore\read_it.txt
- C:\users\public\documents\read_it.txt
- %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\read_it.txt
- C:\users\public\downloads\read_it.txt
- C:\users\public\libraries\read_it.txt
- C:\users\public\music\read_it.txt
- C:\users\public\pictures\read_it.txt
- %ALLUSERSPROFILE%\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\read_it.txt
- C:\users\public\videos\read_it.txt
- %HOMEPATH%\read_it.txt
- %HOMEPATH%\3d objects\read_it.txt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\read_it.txt
- %LOCALAPPDATA%\read_it.txt
- %ALLUSERSPROFILE%\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\read_it.txt
- %LOCALAPPDATA%\connecteddevicesplatform\l.user\read_it.txt
- C:\users\public\desktop\opera.lnk.56c1
- %LOCALAPPDATA%\google\chrome\application\read_it.txt
- C:\users\public\desktop\mozilla thunderbird.lnk.4x9o
- C:\users\public\desktop\acrobat reader dc.lnk.dnja
- %APPDATA%\svchost.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %TEMP%\content\2648-2964-svchost.exe-21-36-34-475.dump
- %WINDIR%\softwaredistribution\sls\9482f4b4-e343-43b6-b170-9a65bc822c77\sls.cab
- %WINDIR%\softwaredistribution\sls\9482f4b4-e343-43b6-b170-9a65bc822c77\tmp689e.tmp
- %WINDIR%\softwaredistribution\sls\855e8a7c-ecb4-4ca3-b045-1dfa50104289\sls.cab
- %WINDIR%\softwaredistribution\sls\855e8a7c-ecb4-4ca3-b045-1dfa50104289\tmp6d61.tmp
- %WINDIR%\softwaredistribution\sls\8b24b027-1dee-babb-9a95-3517dfb9c552\sls.cab
- %WINDIR%\softwaredistribution\sls\8b24b027-1dee-babb-9a95-3517dfb9c552\tmp734e.tmp
- C:\recovery\windowsre\reagent.xml.xbp8
- C:\recovery\windowsre\read_it.txt
- C:\users\read_it.txt
- C:\users\public\read_it.txt
- C:\users\public\accountpictures\read_it.txt
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\read_it.txt
- C:\users\public\desktop\firefox.lnk.6ae2
- %ALLUSERSPROFILE%\microsoft\identitycrl\production\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hi\read_it.txt
- C:\users\public\desktop\steam.lnk.a108
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ar\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\bg\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ca\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\cs\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\da\read_it.txt
- %ALLUSERSPROFILE%\package cache\{929fbd26-9020-399b-9a7a-751d61f0b942}v12.0.21005\packages\vcruntimeadditional_amd64\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\de\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\el\read_it.txt
- %ALLUSERSPROFILE%\microsoft\diagnosis\tenantstorage\p-aria\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_gb\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_us\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es_419\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\et\read_it.txt
- %ALLUSERSPROFILE%\microsoft\identitycrl\int\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\read_it.txt
- %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\read_it.txt
- %ALLUSERSPROFILE%\package cache\{37b8f9c7-03fb-3253-8781-2517c99d7c00}v11.0.61030\packages\vcruntimeadditional_amd64\read_it.txt
- %ALLUSERSPROFILE%\microsoft\diagnosis\downloadedsettings\read_it.txt
- %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\default_apps\read_it.txt
- %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\extensions\read_it.txt
- %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\installer\read_it.txt
- %ALLUSERSPROFILE%\package cache\{6cd9e9ed-906d-4196-8dc3-f987d2f6615f}v14.29.30133\packages\vcruntimeminimum_amd64\read_it.txt
- %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\pepperflash\read_it.txt
- %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\visualelements\read_it.txt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-us\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\read_it.txt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\databases\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\data_reduction_proxy_leveldb\read_it.txt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-us\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extension rules\read_it.txt
- %ALLUSERSPROFILE%\microsoft\diagnosis\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extension state\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\read_it.txt
- %ALLUSERSPROFILE%\package cache\{42667d2e-b054-46c1-9d46-2ee1332c14c1}v14.29.30133\packages\vcruntimeadditional_x86\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lt\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_pt\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ru\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sk\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sv\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\th\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\tr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\uk\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\vi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_cn\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_tw\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_br\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ro\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_gb\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fil\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\he\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hu\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\id\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\it\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ja\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ko\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lt\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lv\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\no\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es_419\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\nl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\et\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ar\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\da\read_it.txt
- %HOMEPATH%\desktop\microsoft edge.lnk.fc2y
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office 2016 tools\read_it.txt
- %HOMEPATH%\desktop\telegram.lnk.yusc
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\steam\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\system tools\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\caches\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\clipsvc\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\clipsvc\archive\apps\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_br\read_it.txt
- %HOMEPATH%\documents\read_it.txt
- %HOMEPATH%\downloads\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\nl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lv\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\no\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\bg\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ca\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\de\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\el\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\en\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\es\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fil\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hu\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\id\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\it\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ja\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lt\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\cs\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ko\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_us\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hu\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\computer.lnk.084a
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\control panel.lnk.x649
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\file explorer.lnk.gs6n
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\run.lnk.rmbx
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_br\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_pt\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ro\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ru\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sk\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sr\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sv\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\th\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell (x86).lnk.qhxk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\administrative tools.lnk.lrsg
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\maintenance\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\id\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\it\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ja\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ko\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lt\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lv\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\nl\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\no\read_it.txt
- C:\users\default\appdata\local\microsoft\windows\winx\group3\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessibility\magnify.lnk.5wko
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessibility\narrator.lnk.72rx
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessibility\on-screen keyboard.lnk.leae
- C:\users\default\appdata\local\microsoft\windows sidebar\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk.hkd5
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pl\read_it.txt
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell ise (x86).lnk.6e8x
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnk.rku8
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell ise.lnk.0d1c
- %HOMEPATH%\desktop\2.jpeg.q5zk
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\vi\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\zh_cn\read_it.txt
- %HOMEPATH%\desktop\3.jpg.wjcv
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\zh_tw\read_it.txt
- %HOMEPATH%\desktop\google chrome.lnk.qljc
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ar\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\bg\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ca\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\cs\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\da\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\de\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\el\read_it.txt
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\tr\read_it.txt
- %HOMEPATH%\desktop\13.jpeg.kb7z
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\uk\read_it.txt
- %HOMEPATH%\desktop\13.jpg.ozo9
- %HOMEPATH%\desktop\1189.jpg.7q9o
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell.lnk.nucu
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessibility\read_it.txt
- %HOMEPATH%\music\read_it.txt
- %HOMEPATH%\onedrive\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\read_it.txt
- %HOMEPATH%\pictures\read_it.txt
- D:\surprise.exe
- %LOCALAPPDATA%\packages\microsoft.zunemusic_8wekyb3d8bbwe\settings\read_it.txt
- %HOMEPATH%\pictures\camera roll\read_it.txt
- %HOMEPATH%\videos\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\read_it.txt
- %HOMEPATH%\contacts\read_it.txt
- %HOMEPATH%\desktop\1189.jpeg.cmx8
- %HOMEPATH%\desktop\read_it.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\read_it.txt
- %HOMEPATH%\searches\read_it.txt
- %APPDATA%\read_it.txt
- <Drive name for removable media>:\system volume information\wpsettings.dat
- C:\recovery\windowsre\reagent.xml
- %HOMEPATH%\desktop\13.jpeg
- %HOMEPATH%\desktop\1189.jpg
- %HOMEPATH%\desktop\1189.jpeg
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell ise.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell ise (x86).lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell (x86).lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\run.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\file explorer.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\control panel.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\computer.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnk
- %HOMEPATH%\desktop\13.jpg
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\administrative tools.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessibility\on-screen keyboard.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessibility\narrator.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessibility\magnify.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\onedrive.lnk
- C:\users\default\appdata\roaming\microsoft\windows\sendto\fax recipient.lnk
- C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\window switcher.lnk
- C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\shows desktop.lnk
- C:\users\public\desktop\steam.lnk
- C:\users\public\desktop\opera.lnk
- C:\users\public\desktop\mozilla thunderbird.lnk
- C:\users\public\desktop\firefox.lnk
- C:\users\public\desktop\acrobat reader dc.lnk
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk
- %HOMEPATH%\desktop\2.jpeg
- DNS ASK settings-win.data.microsoft.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%APPDATA%\svchost.exe'
- '<SYSTEM32>\notepad.exe' %APPDATA%\read_it.txt