- C:\Users\user\AppData\Local\Temp\74339b2f522ed9b1b47ba4249b9a6234694c1ce4.ENU
- C:\Users\user\AppData\Local\Temp\74339b2f522ed9b1b47ba4249b9a6234694c1ce4.ENU.DLL
- C:\Users\user\AppData\Local\Temp\74339b2f522ed9b1b47ba4249b9a6234694c1ce4.EN
- C:\Users\user\AppData\Local\Temp\74339b2f522ed9b1b47ba4249b9a6234694c1ce4.EN.DLL
- C:\Windows\Fonts\staticcache.dat
-
- C:\Program Files (x86)\Mozilla Firefox\nss3.dll
- C:\Users\user\AppData\Local\Temp\WINMM.dll
- C:\Windows\System32\winmm.dll
- C:\Users\user\AppData\Local\Temp\WSOCK32.dll
- C:\Windows\System32\wsock32.dll
- C:\Users\user\AppData\Local\Temp\MSVCR120.dll
- C:\Windows\System32\MSVCR120.dll
- C:\Windows\system\MSVCR120.dll
- C:\Windows\MSVCR120.dll
- C:\ProgramData\Oracle\Java\javapath\MSVCR120.dll
- C:\Windows\System32\wbem\MSVCR120.dll
- C:\Windows\System32\WindowsPowerShell\v1.0\MSVCR120.dll
- C:\Program Files\Microsoft Network Monitor 3\MSVCR120.dll
- C:\Program Files (x86)\Universal Extractor\MSVCR120.dll
- C:\Program Files (x86)\Universal Extractor\bin\MSVCR120.dll
- C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\MSVCR120.dll
- C:\Python27\MSVCR120.dll
- C:\Python27\Scripts\MSVCR120.dll
- C:\tools\sysinternals\MSVCR120.dll
- C:\tools\MSVCR120.dll
- C:\tools\IDA_Pro_v6\python\MSVCR120.dll
- C:\Program Files (x86)\Mozilla Firefox\msvcr120.dll
- C:\Users\user\AppData\Local\Temp\mozglue.dll
- C:\Windows\System32\mozglue.dll
- C:\Windows\system\mozglue.dll
- C:\Windows\mozglue.dll
- C:\ProgramData\Oracle\Java\javapath\mozglue.dll
- C:\Windows\System32\wbem\mozglue.dll
- C:\Windows\System32\WindowsPowerShell\v1.0\mozglue.dll
- C:\Program Files\Microsoft Network Monitor 3\mozglue.dll
- C:\Program Files (x86)\Universal Extractor\mozglue.dll
- C:\Program Files (x86)\Universal Extractor\bin\mozglue.dll
- C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\mozglue.dll
- C:\Python27\mozglue.dll
- C:\Python27\Scripts\mozglue.dll
- C:\tools\sysinternals\mozglue.dll
- C:\tools\mozglue.dll
- C:\tools\IDA_Pro_v6\python\mozglue.dll
- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
- C:\Users\user\AppData\Local\Temp\VERSION.dll
- C:\Windows\System32\version.dll
- C:\Users\user\AppData\Local\Temp\MSVCP120.dll
- C:\Windows\System32\MSVCP120.dll
- C:\Windows\system\MSVCP120.dll
- C:\Windows\MSVCP120.dll
- C:\ProgramData\Oracle\Java\javapath\MSVCP120.dll
- C:\Windows\System32\wbem\MSVCP120.dll
- C:\Windows\System32\WindowsPowerShell\v1.0\MSVCP120.dll
- C:\Program Files\Microsoft Network Monitor 3\MSVCP120.dll
- C:\Program Files (x86)\Universal Extractor\MSVCP120.dll
- C:\Program Files (x86)\Universal Extractor\bin\MSVCP120.dll
- C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\MSVCP120.dll
- C:\Python27\MSVCP120.dll
- C:\Python27\Scripts\MSVCP120.dll
- C:\tools\sysinternals\MSVCP120.dll
- C:\tools\MSVCP120.dll
- C:\tools\IDA_Pro_v6\python\MSVCP120.dll
- C:\Program Files (x86)\Mozilla Firefox\msvcp120.dll
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
- C:\Program Files (x86)\Mozilla Firefox\softokn3.dll
- C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\secmod.db
- C:\Windows\System32\tzres.dll
- C:\Program Files (x86)\Mozilla Firefox\freebl3.dll
- C:\
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\cert8.db
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\key3.db
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\nssckbi.dll
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\signons.sqlite
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\logins.json
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\signons.txt
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\signons2.txt
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\signons3.txt
- C:\Program Files\NETGATE\Black Hawk
- C:\Program Files (x86)\Lunascape\Lunascape6\plugins\{9BDD5314-20A6-4d98-AB30-8325A95771EE}
- C:\Users\user\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Comodo\Dragon\User Data\Default\Web Data
- C:\Users\user\AppData\LocalComodo\Dragon\Login Data
- C:\Users\user\AppData\LocalComodo\Dragon\Default\Login Data
- C:\Users\user\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data
- C:\Users\user\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data
- C:\Users\user\AppData\LocalMapleStudio\ChromePlus\Login Data
- C:\Users\user\AppData\LocalMapleStudio\ChromePlus\Default\Login Data
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Nichrome\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Nichrome\User Data\Default\Web Data
- C:\Users\user\AppData\LocalNichrome\Login Data
- C:\Users\user\AppData\LocalNichrome\Default\Login Data
- C:\Users\user\AppData\Local\RockMelt\User Data\Default\Login Data
- C:\Users\user\AppData\Local\RockMelt\User Data\Default\Web Data
- C:\Users\user\AppData\LocalRockMelt\Login Data
- C:\Users\user\AppData\LocalRockMelt\Default\Login Data
- C:\Users\user\AppData\Local\Spark\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Spark\User Data\Default\Web Data
- C:\Users\user\AppData\LocalSpark\Login Data
- C:\Users\user\AppData\LocalSpark\Default\Login Data
- C:\Users\user\AppData\Local\Chromium\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Chromium\User Data\Default\Web Data
- C:\Users\user\AppData\LocalChromium\Login Data
- C:\Users\user\AppData\LocalChromium\Default\Login Data
- C:\Users\user\AppData\Local\Titan Browser\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Titan Browser\User Data\Default\Web Data
- C:\Users\user\AppData\LocalTitan Browser\Login Data
- C:\Users\user\AppData\LocalTitan Browser\Default\Login Data
- C:\Users\user\AppData\Local\Torch\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Torch\User Data\Default\Web Data
- C:\Users\user\AppData\LocalTorch\Login Data
- C:\Users\user\AppData\LocalTorch\Default\Login Data
- C:\Users\user\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data
- C:\Users\user\AppData\LocalYandex\YandexBrowser\Login Data
- C:\Users\user\AppData\LocalYandex\YandexBrowser\Default\Login Data
- C:\Users\user\AppData\Local\Epic Privacy Browser\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Epic Privacy Browser\User Data\Default\Web Data
- C:\Users\user\AppData\LocalEpic Privacy Browser\Login Data
- C:\Users\user\AppData\LocalEpic Privacy Browser\Default\Login Data
- C:\Users\user\AppData\Local\CocCoc\Browser\User Data\Default\Login Data
- C:\Users\user\AppData\Local\CocCoc\Browser\User Data\Default\Web Data
- C:\Users\user\AppData\LocalCocCoc\Browser\Login Data
- C:\Users\user\AppData\LocalCocCoc\Browser\Default\Login Data
- C:\Users\user\AppData\Local\Vivaldi\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Vivaldi\User Data\Default\Web Data
- C:\Users\user\AppData\LocalVivaldi\Login Data
- C:\Users\user\AppData\LocalVivaldi\Default\Login Data
- C:\Users\user\AppData\Local\Comodo\Chromodo\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Comodo\Chromodo\User Data\Default\Web Data
- C:\Users\user\AppData\LocalComodo\Chromodo\Login Data
- C:\Users\user\AppData\LocalComodo\Chromodo\Default\Login Data
- C:\Users\user\AppData\Local\Superbird\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Superbird\User Data\Default\Web Data
- C:\Users\user\AppData\LocalSuperbird\Login Data
- C:\Users\user\AppData\LocalSuperbird\Default\Login Data
- C:\Users\user\AppData\Local\Coowon\Coowon\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Coowon\Coowon\User Data\Default\Web Data
- C:\Users\user\AppData\LocalCoowon\Coowon\Login Data
- C:\Users\user\AppData\LocalCoowon\Coowon\Default\Login Data
- C:\Users\user\AppData\Local\Mustang Browser\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Mustang Browser\User Data\Default\Web Data
- C:\Users\user\AppData\LocalMustang Browser\Login Data
- C:\Users\user\AppData\LocalMustang Browser\Default\Login Data
- C:\Users\user\AppData\Local\360Browser\Browser\User Data\Default\Login Data
- C:\Users\user\AppData\Local\360Browser\Browser\User Data\Default\Web Data
- C:\Users\user\AppData\Local360Browser\Browser\Login Data
- C:\Users\user\AppData\Local360Browser\Browser\Default\Login Data
- C:\Users\user\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Login Data
- C:\Users\user\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Web Data
- C:\Users\user\AppData\LocalCatalinaGroup\Citrio\Login Data
- C:\Users\user\AppData\LocalCatalinaGroup\Citrio\Default\Login Data
- C:\Users\user\AppData\Local\Google\Chrome SxS\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Google\Chrome SxS\User Data\Default\Web Data
- C:\Users\user\AppData\LocalGoogle\Chrome SxS\Login Data
- C:\Users\user\AppData\LocalGoogle\Chrome SxS\Default\Login Data
- C:\Users\user\AppData\Local\Orbitum\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Orbitum\User Data\Default\Web Data
- C:\Users\user\AppData\LocalOrbitum\Login Data
- C:\Users\user\AppData\LocalOrbitum\Default\Login Data
- C:\Users\user\AppData\Local\Iridium\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Iridium\User Data\Default\Web Data
- C:\Users\user\AppData\LocalIridium\Login Data
- C:\Users\user\AppData\LocalIridium\Default\Login Data
- C:\Users\user\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data
- C:\Users\user\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data
- C:\Users\user\AppData\Roaming\Opera\Opera Next\data\Login Data
- C:\Users\user\AppData\Roaming\Opera\Opera Next\data\Default\Login Data
- C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Login Data
- C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Web Data
- C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Login Data
- C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Default\Login Data
- C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Login Data
- C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Web Data
- C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Login Data
- C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Default\Login Data
- C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Login Data
- C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Web Data
- C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Login Data
- C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data
- C:\Users\user\AppData\Local\QupZilla\profiles\default\browsedata.db
- C:\Users\user\AppData\Roaming\Opera
- C:\Users\user\AppData\Roaming\.purple\accounts.xml
- C:\Users\user\Documents\SuperPutty
- C:\Program Files (x86)\FTPShell\ftpshell.fsi
- C:\Users\user\AppData\Roaming\Notepad++\plugins\config\NppFTP\NppFTP.xml
- C:\Program Files (x86)\oZone3D\MyFTP\myftp.ini
- C:\Users\user\AppData\Roaming\FTPBox\profiles.conf
- C:\Program Files (x86)\Sherrod Computers\sherrod FTP\favorites
- C:\Program Files (x86)\FTP Now\sites.xml
- C:\Program Files (x86)\NexusFile\userdata\ftpsite.ini
- C:\Users\user\AppData\Roaming\NexusFile\ftpsite.ini
- C:\Users\user\Documents\NetSarang\Xftp\Sessions
- C:\Users\user\AppData\Roaming\NetSarang\Xftp\Sessions
- C:\Program Files (x86)\EasyFTP\data
- C:\Users\user\AppData\Roaming\SftpNetDrive
- C:\Program Files (x86)\AbleFTP7\encPwd.jsd
- C:\Program Files (x86)\AbleFTP7\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP7\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP8\encPwd.jsd
- C:\Program Files (x86)\AbleFTP8\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP8\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP9\encPwd.jsd
- C:\Program Files (x86)\AbleFTP9\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP9\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP10\encPwd.jsd
- C:\Program Files (x86)\AbleFTP10\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP10\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP11\encPwd.jsd
- C:\Program Files (x86)\AbleFTP11\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP11\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP12\encPwd.jsd
- C:\Program Files (x86)\AbleFTP12\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP12\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP13\encPwd.jsd
- C:\Program Files (x86)\AbleFTP13\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP13\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP14\encPwd.jsd
- C:\Program Files (x86)\AbleFTP14\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\AbleFTP14\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp7\encPwd.jsd
- C:\Program Files (x86)\JaSFtp7\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp7\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp8\encPwd.jsd
- C:\Program Files (x86)\JaSFtp8\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp8\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp9\encPwd.jsd
- C:\Program Files (x86)\JaSFtp9\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp9\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp10\encPwd.jsd
- C:\Program Files (x86)\JaSFtp10\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp10\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp11\encPwd.jsd
- C:\Program Files (x86)\JaSFtp11\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp11\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp12\encPwd.jsd
- C:\Program Files (x86)\JaSFtp12\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp12\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp13\encPwd.jsd
- C:\Program Files (x86)\JaSFtp13\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp13\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp14\encPwd.jsd
- C:\Program Files (x86)\JaSFtp14\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\JaSFtp14\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\Automize7\encPwd.jsd
- C:\Program Files (x86)\Automize7\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\Automize7\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\Automize8\encPwd.jsd
- C:\Program Files (x86)\Automize8\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\Automize8\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\Automize9\encPwd.jsd
- C:\Program Files (x86)\Automize9\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\Automize9\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\Automize10\encPwd.jsd
- C:\Program Files (x86)\Automize10\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\Automize10\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\Automize11\encPwd.jsd
- C:\Program Files (x86)\Automize11\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\Automize11\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\Automize12\encPwd.jsd
- C:\Program Files (x86)\Automize12\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\Automize12\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\Automize13\encPwd.jsd
- C:\Program Files (x86)\Automize13\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\Automize13\data\settings\ftpProfiles-j.jsd
- C:\Program Files (x86)\Automize14\encPwd.jsd
- C:\Program Files (x86)\Automize14\data\settings\sshProfiles-j.jsd
- C:\Program Files (x86)\Automize14\data\settings\ftpProfiles-j.jsd
- C:\Users\user\AppData\Roaming\Cyberduck
- C:\Users\user\AppData\Roaming\iterate_GmbH
- C:\Users\user\.config\fullsync\profiles.xml
- C:\Users\user\AppData\Roaming\FTPInfo\ServerList.xml
- C:\Users\user\AppData\Roaming\FTPInfo\ServerList.cfg
- C:\Program Files (x86)\FileZilla\Filezilla.xml
- C:\Users\user\AppData\Roaming\FileZilla\filezilla.xml
- C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml
- C:\Users\user\AppData\Roaming\FileZilla\sitemanager.xml
- C:\Program Files (x86)\Staff-FTP\sites.ini
- C:\Users\user\AppData\Roaming\BlazeFtp\site.dat
- C:\Program Files (x86)\Fastream NETFile\My FTP Links
- C:\Program Files (x86)\GoFTP\settings\Connections.txt
- C:\Users\user\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat
- C:\Program Files (x86)\DeluxeFTP\sites.xml
- C:\Windows\wcx_ftp.ini
- C:\Users\user\AppData\Roaming\wcx_ftp.ini
- C:\Users\user\wcx_ftp.ini
- C:\Users\user\AppData\Roaming\GHISLER\wcx_ftp.ini
- C:\Program Files (x86)\FTPGetter\Profile\servers.xml
- C:\Users\user\AppData\Roaming\FTPGetter\servers.xml
- C:\Program Files (x86)\WS_FTP\WS_FTP.INI
- C:\Windows\WS_FTP.INI
- C:\Users\user\AppData\Roaming\Ipswitch
- C:\Users\user\site.xml
- C:\Users\user\AppData\Local\PokerStars*
- C:\Users\user\AppData\Local\ExpanDrive
- C:\Users\user\AppData\Roaming\Steed\bookmarks.txt
- C:\Users\user\AppData\Roaming\FlashFXP
- C:\ProgramData\FlashFXP
- C:\Users\user\AppData\Local\INSoftware\NovaFTP\NovaFTP.db
- C:\Users\user\AppData\Roaming\NetDrive\NDSites.ini
- C:\Users\user\AppData\Roaming\NetDrive2\drives.dat
- C:\ProgramData\NetDrive2\drives.dat
- C:\Users\user\AppData\Roaming\SmartFTP
- C:\Users\user\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db
- C:\Users\user\Documents\*.tlp
- C:\Users\user\Documents\*.bscp
- C:\Users\user\Documents\*.vnc
- C:\Users\user\Desktop\*.vnc
- C:\Users\user\Documents\mSecure
- C:\ProgramData\Syncovery
- C:\Program Files (x86)\FreshWebmaster\FreshFTP\FtpSites.SMF
- C:\Users\user\AppData\Roaming\BitKinex\bitkinex.ds
- C:\Users\user\AppData\Roaming\UltraFXP\sites.xml
- C:\Users\user\AppData\Roaming\FTP Now\sites.xml
- C:\Program Files (x86)\Odin Secure FTP Expert\QFDefault.QFQ
- C:\Program Files (x86)\Odin Secure FTP Expert\SiteInfo.QFP
- C:\Program Files (x86)\Foxmail\mail
- C:\Foxmail*
- C:\Users\user\AppData\Roaming\Pocomail\accounts.ini
- C:\Users\user\Documents\Pocomail\accounts.ini
- C:\Users\user\AppData\Roaming\GmailNotifierPro\ConfigData.xml
- C:\Users\user\AppData\Roaming\DeskSoft\CheckMail
- C:\Program Files (x86)\WinFtp Client\Favorites.dat
- C:\Windows\32BitFtp.TMP
- C:\Windows\32BitFtp.ini
- C:\FTP Navigator\Ftplist.txt
- C:\Softwarenetz\Mailing\Daten\mailing.vdt
- C:\Users\user\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
- C:\Users\user\Documents\*Mailbox.ini
- \Device\KsecDD
- C:\Users\user\Documents\yMail2\POP3.xml
- C:\Users\user\Documents\yMail2\SMTP.xml
- C:\Users\user\Documents\yMail2\Accounts.xml
- C:\Users\user\Documents\yMail\ymail.ini
- C:\Users\user\AppData\Roaming\TrulyMail\Data\Settings\user.config
- C:\Users\user\Documents\*.spn
- C:\Users\user\Desktop\*.spn
- C:\Users\user\AppData\Roaming\To-Do DeskList\tasks.db
- C:\Users\user\AppData\Roaming\stickies\images
- C:\Users\user\AppData\Roaming\stickies\rtf
- C:\Users\user\AppData\Roaming\NoteFly\notes
- C:\Users\user\AppData\Roaming\Conceptworld\Notezilla\Notes8.db
- C:\Users\user\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt
- C:\Users\user\Documents
- C:\Users\user\Documents\*.kdbx
- C:\Users\user\Desktop
- C:\Users\user\Desktop\*.kdbx
- C:\Users\user\Documents\*.kdb
- C:\Users\user\Desktop\*.kdb
- C:\Users\user\Documents\Enpass
- C:\Users\user\Documents\My RoboForm Data
- C:\Users\user\Documents\1Password
- C:\Users\user\AppData\Local\Temp\Mikrotik\Winbox
- C:\Users\user\AppData\Roaming\D5E2DE
- C:\Users\user\AppData\Roaming\D5E2DE\E36C7A.hdb
- C:\Users\user\AppData\Local\Temp\NETAPI32.DLL
- C:\Windows\System32\netapi32.dll
- C:\Users\user\AppData\Local\Temp\netutils.dll
- C:\Windows\System32\netutils.dll
- C:\Users\user\AppData\Local\Temp\srvcli.dll
- C:\Windows\System32\srvcli.dll
- C:\Users\user\AppData\Roaming\D5E2DE\E36C7A.lck
- C:\Users\user\AppData\Roaming\Microsoft\Credentials
- C:\Users\user\AppData\Roaming\Microsoft\Credentials\*
- C:\Users\user\AppData\Local\Microsoft\Credentials
- C:\Users\user\AppData\Local\Microsoft\Credentials\*
- C:\Users\user\AppData\Local\Temp\74339b2f522ed9b1b47ba4249b9a6234694c1ce4.exe
- C:\Users\user\AppData\Roaming\D5E2DE\E36C7A.exe
- C:\Windows\Temp
- Show More 365
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
-
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\CurrentVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\46.0.1 (x86 en-US)\Main\Install Directory
- HKEY_CURRENT_USER\Software\Ghisler\Total Commander\FtpIniName
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\27c571c20b901b4bae192bbd30c1921b\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\34b9531bce896442a8a090c8845e0b0c\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\41bcc567153c3748a9b366420dae5a66\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Email Address
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Email Address
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Server URL
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Port
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Port
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Port
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\c02ebc5353d9cd11975200aa004ae40e\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f4102a07475a2f4bb2d7ccaf6665ac90\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Reminders\Email
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
- Show More 93
- C:\Users\user\AppData\Roaming\D5E2DE\E36C7A.lck
- C:\Users\user\AppData\Roaming\D5E2DE\E36C7A.exe
- kernel32.dll.GetDiskFreeSpaceExA
- oleaut32.dll.VariantChangeTypeEx
- oleaut32.dll.VarNeg
- oleaut32.dll.VarNot
- oleaut32.dll.VarAdd
-
- oleaut32.dll.VarSub
- oleaut32.dll.VarMul
- oleaut32.dll.VarDiv
- oleaut32.dll.VarIdiv
- oleaut32.dll.VarMod
- oleaut32.dll.VarAnd
- oleaut32.dll.VarOr
- oleaut32.dll.VarXor
- oleaut32.dll.VarCmp
- oleaut32.dll.VarI4FromStr
- oleaut32.dll.VarR4FromStr
- oleaut32.dll.VarR8FromStr
- oleaut32.dll.VarDateFromStr
- oleaut32.dll.VarCyFromStr
- oleaut32.dll.VarBoolFromStr
- oleaut32.dll.VarBstrFromCy
- oleaut32.dll.VarBstrFromDate
- oleaut32.dll.VarBstrFromBool
- user32.dll.GetMonitorInfoA
- user32.dll.GetSystemMetrics
- user32.dll.EnumDisplayMonitors
- dwmapi.dll.DwmIsCompositionEnabled
- gdi32.dll.GetLayout
- gdi32.dll.GdiRealizationInfo
- gdi32.dll.FontIsLinked
- advapi32.dll.RegOpenKeyExW
- advapi32.dll.RegQueryInfoKeyW
- gdi32.dll.GetTextFaceAliasW
- advapi32.dll.RegEnumValueW
- advapi32.dll.RegCloseKey
- advapi32.dll.RegQueryValueExW
- gdi32.dll.GetFontAssocStatus
- advapi32.dll.RegQueryValueExA
- advapi32.dll.RegEnumKeyExW
- gdi32.dll.GdiIsMetaPrintDC
- user32.dll.AnimateWindow
- comctl32.dll.InitializeFlatSB
- comctl32.dll.UninitializeFlatSB
- comctl32.dll.FlatSB_GetScrollProp
- comctl32.dll.FlatSB_SetScrollProp
- comctl32.dll.FlatSB_EnableScrollBar
- comctl32.dll.FlatSB_ShowScrollBar
- comctl32.dll.FlatSB_GetScrollRange
- comctl32.dll.FlatSB_GetScrollInfo
- comctl32.dll.FlatSB_GetScrollPos
- comctl32.dll.FlatSB_SetScrollPos
- comctl32.dll.FlatSB_SetScrollInfo
- comctl32.dll.FlatSB_SetScrollRange
- user32.dll.SetLayeredWindowAttributes
- user32.dll.GetLastInputInfo
- kernel32.dll.VirtualProtect
- cryptsp.dll.CryptAcquireContextW
- cryptsp.dll.CryptCreateHash
- cryptsp.dll.CryptHashData
- cryptsp.dll.CryptGetHashParam
- cryptsp.dll.CryptDestroyHash
- cryptsp.dll.CryptReleaseContext
- kernel32.dll.GetTickCount64
- nss3.dll.NSS_Init
- nss3.dll.NSS_Shutdown
- nss3.dll.PK11_GetInternalKeySlot
- nss3.dll.PK11_FreeSlot
- nss3.dll.PK11_Authenticate
- nss3.dll.PK11SDR_Decrypt
- nss3.dll.PK11_CheckUserPassword
- nss3.dll.SECITEM_FreeItem
- kernel32.dll.InitializeCriticalSectionEx
- softokn3.dll.NSC_GetFunctionList
- softokn3.dll.NSC_ModuleDBFunc
- nssdbm3.dll.legacy_Open
- nssdbm3.dll.legacy_ReadSecmodDB
- nssdbm3.dll.legacy_ReleaseSecmodDBData
- nssdbm3.dll.legacy_DeleteSecmodDB
- nssdbm3.dll.legacy_AddSecmodDB
- nssdbm3.dll.legacy_Shutdown
- nssdbm3.dll.legacy_SetCryptFunctions
- freebl3.dll.FREEBL_GetVector
- cryptbase.dll.SystemFunction001
- cryptbase.dll.SystemFunction002
- cryptbase.dll.SystemFunction003
- cryptbase.dll.SystemFunction004
- cryptbase.dll.SystemFunction005
- cryptbase.dll.SystemFunction028
- cryptbase.dll.SystemFunction029
- cryptbase.dll.SystemFunction034
- cryptbase.dll.SystemFunction036
- cryptbase.dll.SystemFunction040
- cryptbase.dll.SystemFunction041
- vaultcli.dll.VaultEnumerateItems
- vaultcli.dll.VaultEnumerateVaults
- vaultcli.dll.VaultFree
- vaultcli.dll.VaultGetItem
- vaultcli.dll.VaultOpenVault
- vaultcli.dll.VaultCloseVault
- rpcrt4.dll.RpcStringBindingComposeW
- rpcrt4.dll.RpcBindingFromStringBindingW
- rpcrt4.dll.NdrClientCall2
- rpcrt4.dll.RpcStringFreeW
- rpcrt4.dll.RpcBindingFree
- sechost.dll.LookupAccountSidLocalW
- netapi32.dll.NetUserGetInfo
- cryptsp.dll.CryptImportKey
- cryptsp.dll.CryptSetKeyParam
- cryptsp.dll.CryptDecrypt
- cryptsp.dll.CryptDestroyKey
- Show More 105
- C:\Users\user\AppData\Roaming\D5E2DE\E36C7A.lck
- C:\Users\user\AppData\Local\Temp\74339b2f522ed9b1b47ba4249b9a6234694c1ce4.exe
- HKEY_CURRENT_USER\Software\Borland\Locales
- HKEY_LOCAL_MACHINE\Software\Borland\Locales
- HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
-
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
- HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\CurrentVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\46.0.1 (x86 en-US)\Main
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\46.0.1 (x86 en-US)\Main\Install Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\IceDragon\Setup
- HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\Safari
- HKEY_LOCAL_MACHINE\SOFTWARE\K-Meleon
- HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\SeaMonkey
- HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey
- HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Flock
- HKEY_CURRENT_USER\Software\QtWeb.NET\QtWeb Internet Browser\AutoComplete
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
- HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox86
- HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox
- HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon
- HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Waterfox
- HKEY_CURRENT_USER\Software\LinasFTP\Site Manager
- HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings
- HKEY_CURRENT_USER\Software\Ghisler\Total Commander
- HKEY_CURRENT_USER\Software\Ghisler\Total Commander\FtpIniName
- HKEY_CURRENT_USER\Software
- HKEY_CURRENT_USER\Software\7-Zip
- HKEY_CURRENT_USER\Software\Adlice Software
- HKEY_CURRENT_USER\Software\Adobe
- HKEY_CURRENT_USER\Software\AppDataLow
- HKEY_CURRENT_USER\Software\Clients
- HKEY_CURRENT_USER\Software\Ghisler
- HKEY_CURRENT_USER\Software\Google
- HKEY_CURRENT_USER\Software\Hex-Rays
- HKEY_CURRENT_USER\Software\JavaSoft
- HKEY_CURRENT_USER\Software\JetBrains
- HKEY_CURRENT_USER\Software\Macromedia
- HKEY_CURRENT_USER\Software\Microsoft
- HKEY_CURRENT_USER\Software\Mozilla
- HKEY_CURRENT_USER\Software\MozillaPlugins
- HKEY_CURRENT_USER\Software\MPC-HC
- HKEY_CURRENT_USER\Software\Netscape
- HKEY_CURRENT_USER\Software\NTCore
- HKEY_CURRENT_USER\Software\ODBC
- HKEY_CURRENT_USER\Software\PEiD
- HKEY_CURRENT_USER\Software\Policies
- HKEY_CURRENT_USER\Software\Sysinternals
- HKEY_CURRENT_USER\Software\Telerik
- HKEY_CURRENT_USER\Software\VB and VBA Program Settings
- HKEY_CURRENT_USER\Software\Wow6432Node
- HKEY_CURRENT_USER\Software\Classes
- HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts
- HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts
- HKEY_CURRENT_USER\Software\Bitvise\BvSshClient
- HKEY_CURRENT_USER\Software\VanDyke\SecureFX
- HKEY_LOCAL_MACHINE\Software\NCH Software\Fling\Accounts
- HKEY_CURRENT_USER\Software\NCH Software\Fling\Accounts
- HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts
- HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts
- HKEY_CURRENT_USER\Software\9bis.com\KiTTY\Sessions
- HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions
- HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions
- HKEY_LOCAL_MACHINE\Software\9bis.com\KiTTY\Sessions
- HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird
- HKEY_CURRENT_USER\Software\IncrediMail\Identities
- HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities
- HKEY_CURRENT_USER\Software\Martin Prikryl
- HKEY_LOCAL_MACHINE\Software\Martin Prikryl
- HKEY_LOCAL_MACHINE\SOFTWARE\Postbox\Postbox
- HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\FossaMail
- HKEY_CURRENT_USER\Software\WinChips\UserAccounts
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\27c571c20b901b4bae192bbd30c1921b
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\27c571c20b901b4bae192bbd30c1921b\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\34b9531bce896442a8a090c8845e0b0c
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\34b9531bce896442a8a090c8845e0b0c\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\41bcc567153c3748a9b366420dae5a66
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\41bcc567153c3748a9b366420dae5a66\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Email Address
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Email Address
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Server URL
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail User Name
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Port
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Port
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Port
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password2
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\c02ebc5353d9cd11975200aa004ae40e
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\c02ebc5353d9cd11975200aa004ae40e\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f4102a07475a2f4bb2d7ccaf6665ac90
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f4102a07475a2f4bb2d7ccaf6665ac90\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Reminders
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Reminders\Email
- HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
- HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook
- HKEY_CURRENT_USER\SOFTWARE\flaska.net\trojita
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
- HKEY_USERS\S-1-5-18
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
- HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
- HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
- HKEY_USERS\.DEFAULT\Environment
- HKEY_USERS\.DEFAULT\Volatile Environment
- HKEY_USERS\.DEFAULT\Volatile Environment\0
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe
- Show More 209
- "C:\Users\user\AppData\Local\Temp\74339b2f522ed9b1b47ba4249b9a6234694c1ce4.exe"
- C:\Windows\system32\lsass.exe
- C:\Windows\Fonts\staticcache.dat
- C:\Program Files (x86)\Mozilla Firefox\nss3.dll
- C:\Windows\System32\winmm.dll
- C:\Windows\System32\wsock32.dll
- C:\Program Files (x86)\Mozilla Firefox\msvcr120.dll
-
- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
- C:\Windows\System32\version.dll
- C:\Program Files (x86)\Mozilla Firefox\msvcp120.dll
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
- C:\Program Files (x86)\Mozilla Firefox\softokn3.dll
- C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll
- C:\Windows\System32\tzres.dll
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\secmod.db
- C:\Program Files (x86)\Mozilla Firefox\freebl3.dll
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\cert8.db
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\key3.db
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
- \Device\KsecDD
- C:\Users\user\AppData\Roaming\D5E2DE\E36C7A.hdb
- C:\Windows\System32\netapi32.dll
- C:\Windows\System32\netutils.dll
- C:\Windows\System32\srvcli.dll
- C:\Users\user\AppData\Roaming\D5E2DE\E36C7A.lck
- Show More 18