Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Encoder.34268

Добавлен в вирусную базу Dr.Web: 2021-08-23

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Модифицирует следующие ключи реестра
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsCheck' = 'C:\wincheck.exe'
Создает следующие файлы на съемном носителе
  • <Имя диска съемного носителя>:\wincheck.exe
  • <Имя диска съемного носителя>:\autorun.inf
Вредоносные функции
Для затруднения выявления своего присутствия в системе
блокирует отображение:
  • скрытых файлов
блокирует:
  • Средство контроля пользовательских учетных записей (UAC)
Изменения в файловой системе
Создает следующие файлы
  • C:\wincheck.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\ar\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\bg\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\ca\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\cs\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\da\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\de\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\el\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\en\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\en_gb\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\en_us\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\es\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\es_419\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_metadata\verified_contents.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\manifest.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\et\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\fr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\he\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\hi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\hr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\hu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_metadata\verified_contents.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\main.js.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\manifest.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ar\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\bg\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ca\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\cs\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\fi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\_locales\fil\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\zh_tw\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\vi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\de\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\fi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\fil\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\fr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\he\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\hi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\hr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\hu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\id\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\it\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\ja\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\ko\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\lt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\lv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\nl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\no\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\pl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\pt_br\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\pt_pt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\ro\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\ru\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\sk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\sl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\sr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\sv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\th\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\tr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\uk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\da\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\en\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\zh_cn\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\lv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\el\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\zh_tw\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_metadata\computed_hashes.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_metadata\verified_contents.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\craw_background.js.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\craw_window.js.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\css\craw_window.css.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\images\flapper.gif.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\manifest.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\bg\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ca\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\cs\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\da\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\de\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\el\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\en\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\en_gb\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\es\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\es_419\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\et\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\fi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\fil\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\fr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\hi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\hr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\hu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\id\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\it\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ja\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ko\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\zh_cn\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\el\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\es\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\tr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\en_us\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\es\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\es_419\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\et\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\fi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\fil\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\fr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\he\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\hi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\hu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\id\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\it\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ja\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ko\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\lt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\lv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ms\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\nl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\no\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\pl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\pt_br\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\pt_pt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ro\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\ru\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\sv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\th\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\uk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\en_gb\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\_locales\vi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\lt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\cs\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\da\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\de\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\el\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_gb\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_us\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es_419\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\et\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fil\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ar\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\cs\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\it\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ja\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ko\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ms\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\nl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\no\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\he\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\manifest.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_pt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\id\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ca\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.js.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_metadata\verified_contents.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\hu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\id\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\it\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ja\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ko\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ms\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\nl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\no\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pt_br\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ro\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ru\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\sv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\th\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\tr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\uk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\vi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\zh_cn\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\zh_tw\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_metadata\computed_hashes.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_br\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\pt_pt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fil\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ro\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ru\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\id\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ja\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ko\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ms\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\nl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\no\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_br\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_pt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ro\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ru\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\th\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\tr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\uk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\vi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_cn\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_tw\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_metadata\verified_contents.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\manifest.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\ar\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\bg\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\ca\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\it\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\de\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\_locales\da\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\bg\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\th\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\tr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\uk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\vi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_cn\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_tw\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata\computed_hashes.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata\verified_contents.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\manifest.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ar\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\bg\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ca\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\cs\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\da\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\de\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\el\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_gb\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_us\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es_419\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\et\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\eu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fil\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\he\messages.json.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.mspub.14.1033.hxn.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\nb\messages.json.exe
  • %LOCALAPPDATA%\microsoft\media player\localmls_0.wmdb.exe
  • %LOCALAPPDATA%\microsoft\media player\localmls_2.wmdb.exe
  • %LOCALAPPDATA%\microsoft\media player\localmls_3.wmdb.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\01_music_auto_rated_at_5_stars.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\02_music_added_in_the_last_month.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\03_music_rated_at_4_or_5_stars.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\04_music_played_in_the_last_month.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\05_pictures_taken_in_the_last_month.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\06_pictures_rated_4_or_5_stars.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\07_tv_recorded_in_the_last_week.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\08_video_rated_at_4_or_5_stars.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\09_music_played_the_most.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\lastplayed.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\10_all_music.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\localmls_1.wmdb.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\12_all_video.wpl.exe
  • %LOCALAPPDATA%\microsoft\msdn\7.0\toolbox.tbd.exe
  • %LOCALAPPDATA%\microsoft\office\onetconfig\998bcf2d84167c3ecb6ea5f94ac47905.sig.exe
  • %LOCALAPPDATA%\microsoft\office\onetconfig\cf415d5a8175006e051b612a96c83204.sig.exe
  • %LOCALAPPDATA%\microsoft\office\onetconfig\e9cf72c651e3959561340e69d4f45ead.sig.exe
  • %LOCALAPPDATA%\microsoft\windows\1033\structuredqueryschema.bin.exe
  • %LOCALAPPDATA%\microsoft\windows\burn\burn\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog.etl.exe
  • %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl.exe
  • %LOCALAPPDATA%\microsoft\windows\history\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\windows\history\history.ie5\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\ast[1].js.exe
  • %LOCALAPPDATA%\microsoft\media player\sync playlists\en-us\0005fdc0\11_all_pictures.wpl.exe
  • %LOCALAPPDATA%\microsoft\media player\currentdatabase_372.wmdb.exe
  • %LOCALAPPDATA%\microsoft\media player\wmpfolders.wmdb.exe
  • %LOCALAPPDATA%\microsoft\internet explorer\brndlog.txt.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing download.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\containertag[1].js.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing inclusion whitelist.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing ip blacklist.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing uws list.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing uws list prefix set.exe
  • %LOCALAPPDATA%\microsoft\dbgclr\7.1\toolbox.tbd.exe
  • %LOCALAPPDATA%\microsoft\device metadata\dmrc.idx.exe
  • %LOCALAPPDATA%\microsoft\feeds\feeds for united states~\popular government questions from usa~dgov~.feed-ms.exe
  • %LOCALAPPDATA%\microsoft\feeds\feeds for united states~\usa~dgov updates~c news and features~.feed-ms.exe
  • %LOCALAPPDATA%\microsoft\feeds\feedsstore.feedsdb-ms.exe
  • %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~\microsoft at home~.feed-ms.exe
  • %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~\microsoft at work~.feed-ms.exe
  • %LOCALAPPDATA%\microsoft\feeds\microsoft feeds~\msnbc news~.feed-ms.exe
  • %LOCALAPPDATA%\microsoft\feeds\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\webslices~\suggested sites~.feed-ms.exe
  • %LOCALAPPDATA%\microsoft\feeds\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\webslices~\web slice gallery~.feed-ms.exe
  • %LOCALAPPDATA%\microsoft\feeds cache\3v2zgiw9\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\feeds cache\3v2zgiw9\fwlink[1].exe
  • %LOCALAPPDATA%\microsoft\feeds cache\3v2zgiw9\fwlink[2].exe
  • %LOCALAPPDATA%\microsoft\feeds cache\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\feeds cache\dp0qcmsh\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\feeds cache\dp0qcmsh\fwlink[1].exe
  • %LOCALAPPDATA%\microsoft\feeds cache\e6k79x6b\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\feeds cache\e6k79x6b\fwlink[1].exe
  • %LOCALAPPDATA%\microsoft\feeds cache\e6k79x6b\ieonline.microsoft[1].exe
  • %LOCALAPPDATA%\microsoft\feeds cache\evw7z7yu\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\feeds cache\evw7z7yu\fwlink[1].exe
  • %LOCALAPPDATA%\microsoft\feeds cache\evw7z7yu\fwlink[2].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\big_loader_white[1].gif.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\connect[1].txt.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing download whitelist.exe
  • %LOCALAPPDATA%\microsoft\internet explorer\brndlog.bak.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\nl\messages.json.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\context_static_r1170[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\context[2].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\context_static_r1170[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\favicon[1].ico.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\fdc5uco11re5u283tqazmjrjqbqgkvd96cpwqln3_rbffffpgsmzemi6mk6f5mt[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\globalnav[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\helppage.min[1].css.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\httperrorpagesscripts[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\https.embed[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\icon-compare[1].svg.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\imslib.min[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\iosec[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\jquery-1.11.1.min[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\lang_def[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\mbox-contents-f3808f72f280c66c15bd81363d6f55f0659a684d[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\menu-icon-7[1].svg.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\o71pjc8m6hh[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\pfdintextpro-bolditalic-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\pfdintextpro-italic-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\pfdintextpro-light-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\pfdintextpro-mediumitalic-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\rd[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\respond[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\satellite-5359ac4ecd812179a60007a7[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\token[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\views[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\views[2].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\watch[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\connect[1].txt.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing csd whitelist.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\compiled[1].js.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing extension blacklist.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\desktop.ini.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\dil-contents-fe044508f2e9fdd5937011e33188cb0afb585dac[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\errorpagetemplate[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\favcenter[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\favicon[1].ico.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\favicon[2].ico.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\f[1].txt.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\f[2].txt.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\gnav[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\ielogo[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\ims[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\pfdintextpro-italic-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\pfdintextpro-lightitalic-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\pfdintextpro-medium-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\pfdintextpro-mediumitalic-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\pfdintextpro-regular-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\p[1].gif.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\reimagined[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\respond[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\rouble-webfont[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\satellite-54133e4209c7a707dc0001c5[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\st[1].css.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\tracking[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\vt12abarw5hnohlt-y66pkclfe7azdp7zks2rl0dit3ffwrpgsmzemi6mk6f5mb[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\warning[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\wxgyhhpdzg-ed4sr0bqelbfmapgw1pvw90lmrcrtly6ffwhpgsmzemi6mk6f5mw[1].eot.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\yoe7ink[1].js.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\62-343d51-57ea57a[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\about[1].exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\background_gradient[1].exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing cookies-journal.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\context[1].js.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing cookies.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing bloom prefix set.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\it\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\lt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\lv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\nl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\no\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\pl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\pt_br\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\pt_pt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\ro\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\ru\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\se\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\sk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\sl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\sr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\th\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\tr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\uk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\vi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\zh_cn\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\zh_tw\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_metadata\verified_contents.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\favicons.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\favicons-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\gcm store\000003.log.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\gcm store\000004.log.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\gcm store\000005.log.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\gcm store\current.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\id\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\gcm store\lock.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\fi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\ko\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\gcm store\log.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\hu\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\pl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\pt_pt\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ro\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\ru\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\sk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\sl\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\sr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\sv\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\th\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\tr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\uk\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\vi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\zh_cn\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\zh_tw\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_locales\pt_br\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\_metadata\verified_contents.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\ar\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\bg\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\ca\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\cs\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\da\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\de\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\el\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\en\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\es\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\fi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\fil\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\fr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\hr\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\manifest.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\hi\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\he\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\gcm store\manifest-000001.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\history.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\000003.ldb.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\000006.ldb.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\000009.ldb.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\000010.log.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\current.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\lock.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\log.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\log.old.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\session storage\manifest-000001.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\shortcuts.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\shortcuts-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\storage\ext\chrome-signin\def\gpucache\data_0.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\storage\ext\chrome-signin\def\gpucache\data_1.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\storage\ext\chrome-signin\def\gpucache\data_2.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\storage\ext\chrome-signin\def\gpucache\data_3.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\storage\ext\chrome-signin\def\gpucache\index.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\top sites.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\top sites-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\transportsecurity.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\visited links.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\web applications\_crx_coobgpohoikkiipiblmjeljniedjpjpf\google search.ico.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\web applications\_crx_coobgpohoikkiipiblmjeljniedjpjpf\google search.ico.md5.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\web data.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\web data-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\first run.exe
  • %LOCALAPPDATA%\google\chrome\user data\local state.exe
  • %LOCALAPPDATA%\google\chrome\user data\safe browsing bloom.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\quotamanager-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\quotamanager.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\secure preferences.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\readme.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\gcm store\log.old.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\_locales\ja\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\history provider cache.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\history-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticons\b8e2.tmp.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticons\b8e3.tmp.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticons\b8e4.tmp.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticons\b8e5.tmp.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticonsold\8a6c.tmp.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticonsold\8a6d.tmp.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\jumplisticonsold\8a6e.tmp.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\last session.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\last tabs.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\local storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\local storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\login data.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\login data-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\data_0.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\data_1.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\data_2.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\data_3.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\f_000001.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\f_000002.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\f_000003.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\f_000004.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\media cache\index.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\network action predictor.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\network action predictor-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\origin bound certs.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\preferences.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\google profile.ico.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\origin bound certs-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\et\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\es_419\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\es\messages.json.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\secstore\cist0000.000.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\secstore\cist0000.001.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\secstore\cist0000.002.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\windows.edb.exe
  • %ALLUSERSPROFILE%\microsoft\windows\devicemetadatastore\en-us\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms.exe
  • %ALLUSERSPROFILE%\microsoft\windows\devicemetadatastore\en-us\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms.exe
  • %ALLUSERSPROFILE%\microsoft\windows\drm\blackbox.bin.exe
  • %ALLUSERSPROFILE%\microsoft\windows\drm\drmstore.hds.exe
  • %ALLUSERSPROFILE%\microsoft\windows\drm\v3ks.bla.exe
  • %ALLUSERSPROFILE%\microsoft\windows\drm\v3ks.sec.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\settings.dia.exe
  • %ALLUSERSPROFILE%\microsoft\windows\ringtones\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\propmap\cipt0000.002.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\accessibility\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\calculator.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\displayswitch.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\math input panel.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\mobility center.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\networkprojection.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\paint.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\remote desktop connection.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\snipping tool.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\sound recorder.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\default programs.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\index.002.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\sync center.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\accessibility\speech recognition.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\propmap\cipt0000.001.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\index.001.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\index.000.exe
  • %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\tokens.dat.exe
  • %ALLUSERSPROFILE%\microsoft\rac\publisheddata\racwmidatabase.sdf.exe
  • %ALLUSERSPROFILE%\microsoft\rac\statedata\racdatabase.sdf.exe
  • %ALLUSERSPROFILE%\microsoft\rac\statedata\racmetadata.dat.exe
  • %ALLUSERSPROFILE%\microsoft\rac\statedata\racwmidatabookmarks.dat.exe
  • %ALLUSERSPROFILE%\microsoft\rac\statedata\racwmieventdata.dat.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\gatherlogs\systemindex\systemindex.1.crwl.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\gatherlogs\systemindex\systemindex.1.gthr.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\mss.chk.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\mss.log.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\mss00002.log.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\mssres00001.jrs.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\xlslicer.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\mssres00002.jrs.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\00010003.dir.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\00010003.wid.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\00010003.wsb.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0001.000.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0001.001.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0001.002.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0002.000.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0002.001.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0002.002.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciad0002.000.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciad0002.001.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciad0002.002.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\sticky notes.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\00010003.ci.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\xlintl32.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\character map.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\system configuration.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\disk cleanup.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\windows firewall with advanced security.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\windows powershell modules.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\games\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\games\gameexplorer.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\google chrome\google chrome.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\about java.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\check for updates.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\configure java.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\get help.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\visit java.com.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\codec tweak tool.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\directvobsub (x64).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\directvobsub.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\ffdshow vfw interface (x64).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\ffdshow vfw interface.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\lav audio (x64).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\lav audio.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\lav splitter (x64).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\lav splitter.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\lav video (x64).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\lav video.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\reset to recommended settings.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\x264 vfw (x64).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\x264 vfw (x86).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\configuration\xvid vfw.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\help\frequently asked questions.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\services.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\security configuration management.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\task scheduler.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\cache\cache.dat.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\xlintl32.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\wwintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\resource monitor.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\system information.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\system restore.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\task scheduler.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\windows easy transfer reports.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\windows easy transfer.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\tablet pc\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\tablet pc\shapecollector.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\tablet pc\tabtip.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\tablet pc\windows journal.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\welcome center.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell (x86).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell ise (x86).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell ise.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\wordpad.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\acrobat reader dc.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\component services.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\computer management.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\data sources (odbc).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\event viewer.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\iscsi initiator.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\memory diagnostics tool.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\microsoft .net framework 1.1 configuration.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\microsoft .net framework 1.1 wizards.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\print management.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\dfrgui.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\performance monitor.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\wwintl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\visintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\pub6intl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-us\resource.xml.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pictures.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\settings.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\wmp.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-us\resource.xml.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_pref.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_property.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_queue.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_property.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_settings.ico.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml.exe
  • %ALLUSERSPROFILE%\microsoft\identitycrl\ppcrlconfig.dll.exe
  • %ALLUSERSPROFILE%\microsoft\identitycrl\ppcrlui.dll.exe
  • %ALLUSERSPROFILE%\microsoft\ilscache\ilrcache.xml.exe
  • %ALLUSERSPROFILE%\microsoft\ilscache\imcrcache.xml.exe
  • %ALLUSERSPROFILE%\microsoft\mf\active.grl.exe
  • %ALLUSERSPROFILE%\microsoft\mf\pending.grl.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1028\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1031\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\media player classic.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1033\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.exe
  • D:\wincheck.exe
  • D:\autorun.inf
  • %ALLUSERSPROFILE%\adobe\arm\reader_15.007.20033\acrordrdcupd1500920077.msp.exe
  • %ALLUSERSPROFILE%\adobe\arm\reader_15.007.20033\readerdcmanifest.msi.exe
  • %ALLUSERSPROFILE%\adobe\arm\s\armmanifest.msi.exe
  • %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\abcpy.ini.exe
  • %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\acrordrdcupd1500820082.msp.exe
  • %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\acroread.msi.exe
  • %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\data1.cab.exe
  • %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\setup.ini.exe
  • %ALLUSERSPROFILE%\microsoft\assistance\client\1.0\en-us\help_cvalidator.h1d.exe
  • %ALLUSERSPROFILE%\microsoft\assistance\client\1.0\en-us\help_mkwd_assetid.h1w.exe
  • %ALLUSERSPROFILE%\microsoft\assistance\client\1.0\en-us\help_mkwd_bestbet.h1w.exe
  • C:\autorun.inf
  • %ALLUSERSPROFILE%\microsoft\assistance\client\1.0\en-us\help_mtoc_help.h1h.exe
  • %ALLUSERSPROFILE%\microsoft\assistance\client\1.0\en-us\help_mvalidator.lck.exe
  • %ALLUSERSPROFILE%\microsoft\assistance\client\1.0\en-us\help{9daa54e8-cd95-4107-8e7f-ba3f24732d95}.h1q.exe
  • %ALLUSERSPROFILE%\microsoft\crypto\keys\68383f0e45dd9b02f69c4041b082ee57_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee.exe
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\machinekeys\41fa41e1860a443a6e8a83304e30c052_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee.exe
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\machinekeys\445eadb8eaa5b6404dd631b679c28aca_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee.exe
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\machinekeys\8c5902e8ffbdb4ceeaff4edaff2de4c5_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee.exe
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\machinekeys\fa6744f88a9be461717b25be1060cd87_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee.exe
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee.exe
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\6d14e4b1d8ca773bab785d1be032546e_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee.exe
  • %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee.exe
  • %ALLUSERSPROFILE%\microsoft\dbgclr\7.1\1033\dbgclr.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml.exe
  • %ALLUSERSPROFILE%\microsoft\assistance\client\1.0\en-us\help_mvalidator.h1d.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\7a4e9b[1].eot.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1036\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1042\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\visbrres.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\visintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\wwintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\wwintl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\xlintl32.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\xlintl32.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\xlslicer.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\envelopr.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\grintl32.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\grintl32.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\mapir.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\mor6int.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\msointl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\msointl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\omsintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\onintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\onintl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\outllibr.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\outllibr.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\outlwvw.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\ppintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\ppintl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\pub6intl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\pub6intl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\pubwzint.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\sgres.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\stintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\visbrres.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1040\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\stintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1041\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\sgres.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1046\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1049\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\1050\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\2052\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\msdn\7.0\3082\dexplore.ctm.exe
  • %ALLUSERSPROFILE%\microsoft\network\downloader\qmgr0.dat.exe
  • %ALLUSERSPROFILE%\microsoft\network\downloader\qmgr1.dat.exe
  • %ALLUSERSPROFILE%\microsoft\office\assetlibrary.ico.exe
  • %ALLUSERSPROFILE%\microsoft\office\documentrepository.ico.exe
  • %ALLUSERSPROFILE%\microsoft\office\mysharepoints.ico.exe
  • %ALLUSERSPROFILE%\microsoft\office\mysite.ico.exe
  • %ALLUSERSPROFILE%\microsoft\office\sharepointportalsite.ico.exe
  • %ALLUSERSPROFILE%\microsoft\office\sharepointteamsite.ico.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\envelopr.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\grintl32.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\grintl32.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\mapir.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\mor6int.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\msointl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\msointl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\omsintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\onintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\onintl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\outllibr.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\outllibr.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\outlwvw.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\ppintl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\ppintl.rest.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\pub6intl.dll.trx_dll.exe
  • %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\pubwzint.rest.trx_dll.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\analytics[1].js.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\tools\graphstudionext (x64).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\tools\win7dsfiltertweaker.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\private character editor.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\windows explorer.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\maintenance\desktop.ini.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\maintenance\help.lnk.exe
  • C:\users\default\ntuser.dat.log.exe
  • C:\users\default\ntuser.dat.log1.exe
  • C:\users\default\ntuser.dat.log2.exe
  • C:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tm.blf.exe
  • C:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tmcontainer00000000000000000001.regtrans-ms.exe
  • C:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tmcontainer00000000000000000002.regtrans-ms.exe
  • C:\users\desktop.ini.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\computer.lnk.exe
  • C:\users\public\desktop\acrobat reader dc.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\desktop.ini.exe
  • C:\users\public\desktop\google chrome.lnk.exe
  • C:\users\public\desktop\mozilla firefox.lnk.exe
  • C:\users\public\desktop\mozilla thunderbird.lnk.exe
  • C:\users\public\desktop\opera.lnk.exe
  • C:\users\public\desktop\steam.lnk.exe
  • C:\users\public\desktop\winamp.lnk.exe
  • C:\users\public\desktop.ini.exe
  • C:\users\public\documents\desktop.ini.exe
  • C:\users\public\downloads\desktop.ini.exe
  • C:\users\public\libraries\desktop.ini.exe
  • C:\users\public\libraries\recordedtv.library-ms.exe
  • C:\users\public\music\desktop.ini.exe
  • C:\users\public\desktop\desktop.ini.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk.exe
  • C:\users\public\desktop\mirc.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\control panel.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\run.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.ini.exe
  • %ALLUSERSPROFILE%\package cache\{a2563e55-3bec-3828-8d67-e5e8b9e8b675}v14.0.23026\packages\vcruntimeminimum_x86\cab1.cab.exe
  • %ALLUSERSPROFILE%\package cache\{a2563e55-3bec-3828-8d67-e5e8b9e8b675}v14.0.23026\packages\vcruntimeminimum_x86\vc_runtimeminimum_x86.msi.exe
  • %ALLUSERSPROFILE%\package cache\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{bc958bd2-5dac-3862-bb1a-c1be0790438d}v14.0.23026\packages\vcruntimeadditional_amd64\cab1.cab.exe
  • %ALLUSERSPROFILE%\package cache\{bc958bd2-5dac-3862-bb1a-c1be0790438d}v14.0.23026\packages\vcruntimeadditional_amd64\vc_runtimeadditional_x64.msi.exe
  • %ALLUSERSPROFILE%\package cache\{be960c1c-7bad-3de6-8b1a-2616fe532845}v14.0.23026\packages\vcruntimeadditional_x86\cab1.cab.exe
  • %ALLUSERSPROFILE%\package cache\{be960c1c-7bad-3de6-8b1a-2616fe532845}v14.0.23026\packages\vcruntimeadditional_x86\vc_runtimeadditional_x86.msi.exe
  • %ALLUSERSPROFILE%\package cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{dde2682b-961a-41ea-8d44-6005991b7947}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{e46eca4f-393b-40df-9f49-076faf788d83}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\state.rsm.exe
  • C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\desktop.ini.exe
  • C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\shows desktop.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\window switcher.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget.exe
  • C:\users\default\appdata\roaming\microsoft\windows\sendto\desktop (create shortcut).desklink.exe
  • C:\users\default\appdata\roaming\microsoft\windows\sendto\desktop.ini.exe
  • C:\users\default\appdata\roaming\microsoft\windows\sendto\fax recipient.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\sendto\mail recipient.mapimail.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\desktop.ini.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\ease of access.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\magnify.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\narrator.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\on-screen keyboard.lnk.exe
  • C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\command prompt.lnk.exe
  • C:\users\public\music\sample music\desktop.ini.exe
  • %ALLUSERSPROFILE%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\state.rsm.exe
  • C:\users\public\music\sample music\kalimba.mp3.exe
  • %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\propmap\cipt0000.000.exe
  • C:\users\public\music\sample music\maid with the flaxen hair.mp3.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\f_000006.exe
  • C:\users\public\pictures\sample pictures\desktop.ini.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\f_000008.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\index.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\chromedwritefontcache.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cookies.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cookies-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\current session.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\current tabs.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\databases\databases.db-journal.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\000003.ldb.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\000006.ldb.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\000007.log.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\current.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\lock.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\log.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\log.old.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extension state\manifest-000001.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.js.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\manifest.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ar\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\bg\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ca\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\cs\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\da\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\de\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\el\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\en_gb\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\en_us\messages.json.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\f_000005.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\f_000004.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\f_000007.exe
  • %ALLUSERSPROFILE%\package cache\{a2199617-3609-410f-a8e8-e8806c73545b}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\state.rsm.exe
  • C:\users\public\music\sample music\sleep away.mp3.exe
  • C:\users\public\recorded tv\desktop.ini.exe
  • C:\users\public\recorded tv\sample media\desktop.ini.exe
  • C:\users\public\recorded tv\sample media\win7_scenic-demoshort_raw.wtv.exe
  • C:\users\public\videos\desktop.ini.exe
  • C:\users\public\videos\sample videos\desktop.ini.exe
  • %LOCALAPPDATA%\adobe\acrobat\dc\adobecmapfnt15.lst.exe
  • %LOCALAPPDATA%\adobe\acrobat\dc\adobesysfnt15.lst.exe
  • %LOCALAPPDATA%\adobe\acrobat\dc\cache\acrofnt15.lst.exe
  • %LOCALAPPDATA%\adobe\acrobat\dc\shareddataevents.exe
  • %LOCALAPPDATA%\adobe\acrobat\dc\usercache.bin.exe
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\chromedwritefontcache.exe
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_0.exe
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_1.exe
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_2.exe
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\data_3.exe
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cache\index.exe
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies.exe
  • %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies-journal.exe
  • %LOCALAPPDATA%\adobe\color\acecache11.lst.exe
  • %LOCALAPPDATA%\adobe\color\profiles\wscrgb.icc.exe
  • %LOCALAPPDATA%\adobe\color\profiles\wsrgb.icc.exe
  • %LOCALAPPDATA%\google\chrome\user data\chrome_shutdown_ms.txt.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\data_0.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\data_1.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\data_2.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\data_3.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\f_000001.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\f_000003.exe
  • C:\users\public\pictures\desktop.ini.exe
  • %LOCALAPPDATA%\google\chrome\user data\default\cache\f_000002.exe
  • %ALLUSERSPROFILE%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{51adbf11-493f-431c-a862-967a0fae2944}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{35459b22-19a6-44ec-8d34-27eb3131acac}\state.rsm.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\qip 2012\qip 2012.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\qip 2012\uninstall qip 2012.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\microsoft sharepoint workspace 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sidebar.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\steam\steam support center.url.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\steam\steam.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winamp\uninstall winamp.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winamp\what's new.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winamp\winamp (safe mode).lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winamp\winamp.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows dvd maker.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows fax and scan.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows media player.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\console rar manual.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\what is new in the latest version.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\winrar help.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\winrar.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\xps viewer.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\windows update.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\appcrash_autokms.exe_efd62e343880604c4145a2e4462f8c532327bc70_088cc9f7\report.wer.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\appcrash_autokms.exe_efd62e343880604c4145a2e4462f8c532327bc70_099489dd\report.wer.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\appcrash_autokms.exe_efd62e343880604c4145a2e4462f8c532327bc70_cab_0841821b\report.wer.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\appcrash_autokms.exe_efd62e343880604c4145a2e4462f8c532327bc70_cab_0841821b\wer5c82.tmp.appcompat.txt.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\appcrash_autokms.exe_efd62e343880604c4145a2e4462f8c532327bc70_cab_0841821b\wer5cd2.tmp.hdmp.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\appcrash_autokms.exe_efd62e343880604c4145a2e4462f8c532327bc70_cab_0841821b\wer7f7e.tmp.mdmp.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mozilla thunderbird.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mirc\versions.txt.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\tools\graphstudionext.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\qip 2012\qip 2012 on the web.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x64_5d5d8b7c1982ab7c66cf747e7b18b39e2441a_cab_073d8027\report.wer.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\pidgin.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mozilla firefox.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\uninstall\uninstall k-lite codec pack.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\backup and restore center.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\create recovery disc.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\desktop.ini.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\remote assistance.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\media center.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft .net framework sdk v1.1\documentation.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft .net framework sdk v1.1\overview.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft .net framework sdk v1.1\tools.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft access 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft excel 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft infopath designer 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\tools\mediainfo.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft infopath filler 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\microsoft clip organizer.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\microsoft office 2010 language preferences.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\microsoft office 2010 upload center.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\microsoft office picture manager.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft onenote 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft outlook 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft powerpoint 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft publisher 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft sharepoint workspace 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft word 2010.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mirc\ircintro help.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mirc\mirc help.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mirc\mirc.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\digital certificate for vba projects.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mirc\readme.txt.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x64_4a8ed64bf1962bf234c1a7153259451034e674_cab_0731c4f1\report.wer.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\k-lite codec pack\tools\haali muxer.lnk.exe
  • %ALLUSERSPROFILE%\microsoft\windows defender\definition updates\{d2b0b133-42ed-44d3-809a-46ebb62ba863}\mpasbase.vdm.exe
  • %ALLUSERSPROFILE%\microsoft\windows defender\definition updates\{d2b0b133-42ed-44d3-809a-46ebb62ba863}\mpengine.dll.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1_1033_mkwd_a.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1_1033_mkwd_f.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1_1033_mkwd_k.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1_1033_mkwd_netsdknamedurls.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1_1033_mtoc_netsdk.hxh.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1_1033_mvalidator.hxd.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1_1033_mvalidator.lck.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.ois.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.onenote.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.outlook.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.outlook.dev.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.powerpnt.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.powerpnt.dev.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.setlang.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.winword.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.winword.dev.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\nslist.hxl.exe
  • %ALLUSERSPROFILE%\mozilla\logs\maintenanceservice-install.log.exe
  • %ALLUSERSPROFILE%\mozilla\logs\maintenanceservice-uninstall.log.exe
  • %ALLUSERSPROFILE%\ntuser.pol.exe
  • %ALLUSERSPROFILE%\oracle\java\installcache_x64\baseimagefam8.exe
  • %ALLUSERSPROFILE%\package cache\42d5bec7ddfbd49e76467529cbc2868987bf8460\packages\patch\x64\windows6.1-kb2999226-x64.msu.exe
  • %ALLUSERSPROFILE%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{0d3e9e15-de7a-300b-96f1-b4af12b96488}v14.0.23026\packages\vcruntimeminimum_amd64\cab1.cab.exe
  • %ALLUSERSPROFILE%\package cache\{0d3e9e15-de7a-300b-96f1-b4af12b96488}v14.0.23026\packages\vcruntimeminimum_amd64\vc_runtimeminimum_x64.msi.exe
  • %ALLUSERSPROFILE%\package cache\{0f12c81f-93ef-46ec-bc94-d952c1a775d4}\state.rsm.exe
  • %ALLUSERSPROFILE%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\state.rsm.exe
  • %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x64_d473a376adfb18a7b165c5e3c26de43cd8bccb_cab_079d8596\report.wer.exe
  • %ALLUSERSPROFILE%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1_1033_cvalidator.hxd.exe
  • %ALLUSERSPROFILE%\microsoft\windows defender\definition updates\{d2b0b133-42ed-44d3-809a-46ebb62ba863}\mpasdlta.vdm.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.netframeworksdkv1.1.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.mspub.dev.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft\windows defender\support\mplog-07132009-221054.log.exe
  • %ALLUSERSPROFILE%\microsoft\windows nt\msfax\common coverpages\en-us\confident.cov.exe
  • %ALLUSERSPROFILE%\microsoft\windows nt\msfax\common coverpages\en-us\fyi.cov.exe
  • %ALLUSERSPROFILE%\microsoft\windows nt\msfax\common coverpages\en-us\generic.cov.exe
  • %ALLUSERSPROFILE%\microsoft\windows nt\msfax\common coverpages\en-us\urgent.cov.exe
  • %ALLUSERSPROFILE%\microsoft\windows nt\msfax\virtualinbox\en-us\welcomefax.tif.exe
  • %ALLUSERSPROFILE%\microsoft help\hx.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\hx_1033_mkwd_k.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\hx_1033_mkwd_namedurl.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\hx_1033_mtoc_hx.hxh.exe
  • %ALLUSERSPROFILE%\microsoft help\hx_1033_mvalidator.hxd.exe
  • %ALLUSERSPROFILE%\microsoft help\hx_1033_mvalidator.lck.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.dexplore.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.dexplore_1033_mkwd_a.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.dexplore_1033_mkwd_f.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.dexplore_1033_mkwd_k.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.dexplore_1033_mkwd_vs70namedurl.hxw.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.dexplore_1033_mvalidator.hxd.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.dexplore_1033_mvalidator.lck.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.excel.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.excel.dev.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.graph.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.groove.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.infopath.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.infopatheditor.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.msaccess.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.msaccess.dev.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.msouc.14.1033.hxn.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\opera.lnk.exe
  • %ALLUSERSPROFILE%\microsoft help\ms.mstore.14.1033.hxn.exe
  • %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\caasbycl\advert[1].gif.exe
Изменяет следующие файлы
  • %LOCALAPPDATA%\applicationhistory\ngen.exe.2c05686e.ini
Изменяет расширения файлов пользовательских данных (Trojan.Encoder).
Другое
Создает и запускает на исполнение
  • '<Полный путь к файлу>' ' (со скрытым окном)

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке