Technical Information
- <Drive name for removable media>:\readme.txt
- firefox.exe
- %APPDATA%\mozilla\firefox\profiles.ini
- %HOMEPATH%\Desktop\sdszfo.docx
- %HOMEPATH%\desktop\pmd.cer
- %HOMEPATH%\Desktop\lisp_success.doc
- %HOMEPATH%\desktop\garden.htm
- %HOMEPATH%\Desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\delete.avi
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\toolbar.bmp
- %HOMEPATH%\Desktop\dashBorder_96.bmp
- %HOMEPATH%\desktop\contoso.cer
- %HOMEPATH%\Desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\Desktop\advice_process.htm
- %HOMEPATH%\Desktop\adhd_and_obesity.docx
- %HOMEPATH%\Desktop\508softwareandos.doc
- %HOMEPATH%\Desktop\000814251_video_01.avi
- %APPDATA%\Thunderbird\profiles.ini
- %APPDATA%\Opera Software\Opera Stable\Login Data
- %HOMEPATH%\Desktop\dashBorder_144.bmp
- %HOMEPATH%\Desktop\tree_view.htm
- %TEMP%\vvs.bat
- %APPDATA%\icqm\icq\smiles\smiles\valentine\readme.txt
- %APPDATA%\icqm\icq\smiles\statuses\aim\readme.txt
- %APPDATA%\icqm\icq\smiles\statuses\gtalk\readme.txt
- %APPDATA%\icqm\icq\smiles\statuses\icq\readme.txt
- %APPDATA%\icqm\icq\smiles\statuses\jabber\readme.txt
- %APPDATA%\icqm\icq\smiles\statuses\set01\readme.txt
- %APPDATA%\mirc\readme.txt
- %APPDATA%\icqm\icq\smiles\statuses\vk\readme.txt
- %APPDATA%\icqm\icq\translation\readme.txt
- %APPDATA%\icqm\icq\video\readme.txt
- %APPDATA%\icqm\readme.txt
- %APPDATA%\macromedia\flash player\#sharedobjects\y6xx3t6b\kiks.yandex.ru\readme.txt
- %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#kiks.yandex.ru\readme.txt
- %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\#yastatic.net\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\smiles\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\static_png\readme.txt
- %APPDATA%\icqm\icq\sounds\readme.txt
- %APPDATA%\macromedia\flash player\macromedia.com\support\flashplayer\sys\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\set04\readme.txt
- %APPDATA%\icqm\icq\html\uz\jabber\readme.txt
- %APPDATA%\icqm\icq\html\uz\loading\readme.txt
- %APPDATA%\icqm\icq\smiles\flash\readme.txt
- %APPDATA%\icqm\icq\smiles\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\8march\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\animated\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\cat\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\emoji\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\icq6.0-emoticons\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\koloboks\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\odnoklassniki\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\set03\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\set05\readme.txt
- %APPDATA%\icqm\icq\html\ua\loading\readme.txt
- %APPDATA%\icqm\icq\smiles\smiles\set06\readme.txt
- %APPDATA%\icq-profile\readme.txt
- %APPDATA%\mirc\scripts\readme.txt
- %APPDATA%\telegram desktop\readme.txt
- %APPDATA%\telegram desktop\tdata\d877f783d5d3ef8c\readme.txt
- %APPDATA%\thunderbird\crash reports\readme.txt
- %APPDATA%\thunderbird\profiles\10e4mhmg.default\readme.txt
- %APPDATA%\thunderbird\readme.txt
- %APPDATA%\winrar\readme.txt
- %APPDATA%\yandex\readme.txt
- %APPDATA%\mozilla\firefox\crash reports\readme.txt
- %HOMEPATH%\contacts\readme.txt
- %HOMEPATH%\favorites\links\readme.txt
- %HOMEPATH%\favorites\links for united states\readme.txt
- %HOMEPATH%\favorites\msn websites\readme.txt
- %HOMEPATH%\Favorites\MSN Websites\msnbcn~1.url
- %HOMEPATH%\favorites\windows live\readme.txt
- %APPDATA%\qipguard\readme.txt
- %APPDATA%\opera software\opera stable\sync extension settings\knohfebhibeknbfioecpdmdkjkjdnjnl\readme.txt
- %APPDATA%\telegram desktop\tdata\readme.txt
- %APPDATA%\opera software\opera stable\local storage\readme.txt
- %APPDATA%\opera software\opera stable\jump list iconsold\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\crashes\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\datareporting\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\gmp-gmpopenh264\1.5.3\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\healthreport\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\sessionstore-backups\readme.txt
- %APPDATA%\icqm\icq\html\ua\jabber\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\storage\permanent\moz-safe-about+home\readme.txt
- %APPDATA%\icqm\icq\html\uz\error\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\webapps\readme.txt
- %APPDATA%\opera software\opera stable\readme.txt
- %APPDATA%\opera software\opera stable\databases\readme.txt
- %APPDATA%\opera software\opera stable\dictionaries\readme.txt
- %APPDATA%\opera software\opera stable\extension state\readme.txt
- %APPDATA%\opera software\opera stable\jump list icons\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\storage\permanent\moz-safe-about+home\idb\readme.txt
- %APPDATA%\mozilla\firefox\profiles\k0im4xo3.default\bookmarkbackups\readme.txt
- %APPDATA%\mozilla\firefox\readme.txt
- %APPDATA%\icqm\icq\html\ua\error\readme.txt
- %APPDATA%\icqm\icq\html\tr\loading\readme.txt
- %APPDATA%\icqm\icq\html\tr\jabber\readme.txt
- %LOCALAPPDATA%\apps\2.0\paxy2tl4.dk6\0l5hj4h1.d17\google.app_86fd5b6b43e66935_0001.0003_2d95797bbecd3cfc\readme.txt
- %LOCALAPPDATA%\apps\2.0\paxy2tl4.dk6\0l5hj4h1.d17\manifests\readme.txt
- %LOCALAPPDATA%\chromium\user data\readme.txt
- %LOCALAPPDATA%\readme.txt
- %LOCALAPPDATA%\google\chrome\user data\readme.txt
- %LOCALAPPDATA%\mozilla\firefox\profiles\k0im4xo3.default\readme.txt
- %LOCALAPPDATA%\mozilla\firefox\profiles\k0im4xo3.default\offlinecache\readme.txt
- %LOCALAPPDATA%\mozilla\firefox\profiles\k0im4xo3.default\safebrowsing\readme.txt
- %LOCALAPPDATA%\mozilla\firefox\profiles\k0im4xo3.default\startupcache\readme.txt
- %LOCALAPPDATA%\mozilla\updates\308046b0af4a39cb\readme.txt
- %LOCALAPPDATA%\thunderbird\profiles\10e4mhmg.default\startupcache\readme.txt
- %LOCALAPPDATA%\thunderbird\profiles\10e4mhmg.default\readme.txt
- %LOCALAPPDATA%low\adobe\acrobat\10.0\readme.txt
- %LOCALAPPDATA%\adobe\color\profiles\readme.txt
- %LOCALAPPDATA%\adobe\acrobat\11.0\readme.txt
- %LOCALAPPDATA%\apps\2.0\paxy2tl4.dk6\0l5hj4h1.d17\google~1.000\clickonce_bootstrap.exe.manifest
- %LOCALAPPDATA%\adobe\color\readme.txt
- %LOCALAPPDATA%\adobe\acrobat\10.0\readme.txt
- %ALLUSERSPROFILE%\readme.txt
- C:\readme.txt
- %ALLUSERSPROFILE%\adobe\acrobat\11.0\replicate\security\readme.txt
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ab0000000001}\readme.txt
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ab0000000001}\rdc\readme.txt
- %ALLUSERSPROFILE%\microsoft help\readme.txt
- %ALLUSERSPROFILE%\microsoft toolkit\readme.txt
- %LOCALAPPDATA%low\adobe\acrobat\11.0\assets\readme.txt
- %HOMEPATH%\readme.txt
- %ALLUSERSPROFILE%\mozilla\logs\readme.txt
- %ALLUSERSPROFILE%\package cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\readme.txt
- %ALLUSERSPROFILE%\package cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\readme.txt
- %ALLUSERSPROFILE%\package cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\readme.txt
- %ALLUSERSPROFILE%\package cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\readme.txt
- %ALLUSERSPROFILE%\package cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\readme.txt
- %ALLUSERSPROFILE%\sun\java\java update\readme.txt
- D:\readme.txt
- %ALLUSERSPROFILE%\package cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\readme.txt
- %HOMEPATH%\desktop\readme.txt
- %LOCALAPPDATA%low\adobe\acrobat\11.0\readme.txt
- %APPDATA%\adobe\acrobat\10.0\security\readme.txt
- %APPDATA%\icqm\icq\html\en\error\readme.txt
- %APPDATA%\icqm\icq\html\en\jabber\readme.txt
- %APPDATA%\icqm\icq\html\en\loading\readme.txt
- %APPDATA%\icqm\icq\html\kz\error\readme.txt
- %APPDATA%\icqm\icq\html\kz\jabber\readme.txt
- %LOCALAPPDATA%\applicationhistory\readme.txt
- %APPDATA%\icqm\icq\html\kz\loading\readme.txt
- %APPDATA%\icqm\icq\html\pt\jabber\readme.txt
- %APPDATA%\icqm\icq\html\pt\loading\readme.txt
- %APPDATA%\icqm\icq\html\ru\error\readme.txt
- %APPDATA%\icqm\icq\html\ru\jabber\readme.txt
- %APPDATA%\icqm\icq\html\ru\loading\readme.txt
- %APPDATA%\icqm\icq\html\tr\error\readme.txt
- %APPDATA%\icqm\icq\html\de\error\readme.txt
- %APPDATA%\icqm\icq\html\pt\error\readme.txt
- %APPDATA%\icqm\icq\html\de\loading\readme.txt
- %APPDATA%\icqm\icq\html\de\jabber\readme.txt
- %APPDATA%\icqm\icq\html\cz\loading\readme.txt
- %APPDATA%\icqm\icq\html\cz\jabber\readme.txt
- %APPDATA%\adobe\acrobat\10.0\security\crlcache\readme.txt
- %APPDATA%\adobe\acrobat\11.0\jscache\readme.txt
- %APPDATA%\adobe\acrobat\11.0\security\readme.txt
- %APPDATA%\adobe\acrobat\11.0\security\crlcache\readme.txt
- %APPDATA%\adobe\acrobat\11.0\readme.txt
- %LOCALAPPDATA%low\sun\java\deployment\readme.txt
- %APPDATA%\icq-profile\base\readme.txt
- %APPDATA%\.purple\readme.txt
- %APPDATA%\icq-profile\update\readme.txt
- %APPDATA%\icqm\icq\fonts\readme.txt
- %APPDATA%\icqm\icq\graphics\phone\readme.txt
- %APPDATA%\icqm\icq\html\bg\error\readme.txt
- %APPDATA%\icqm\icq\html\bg\jabber\readme.txt
- %APPDATA%\icqm\icq\html\bg\loading\readme.txt
- %APPDATA%\adobe\acrobat\10.0\javascripts\readme.txt
- %APPDATA%\icqm\icq\html\cz\error\readme.txt
- %APPDATA%\icqm\icq\database\readme.txt
- %HOMEPATH%\searches\readme.txt
- <Drive name for removable media>:\join.avi
- %ALLUSERSPROFILE%\Microsoft Help\MS.MSACCESS.14.1033.hxn
- %ALLUSERSPROFILE%\Microsoft Help\MS.INFOPATHEDITOR.14.1033.hxn
- %ALLUSERSPROFILE%\Microsoft Help\MS.INFOPATH.14.1033.hxn
- %ALLUSERSPROFILE%\Microsoft Help\MS.GROOVE.14.1033.hxn
- %ALLUSERSPROFILE%\Microsoft Help\MS.GRAPH.14.1033.hxn
- %ALLUSERSPROFILE%\Microsoft Help\MS.EXCEL.DEV.14.1033.hxn
- %ALLUSERSPROFILE%\Microsoft Help\MS.EXCEL.14.1033.hxn
- %ALLUSERSPROFILE%\Microsoft Help\MS.Dexplore_1033_MValidator.Lck
- %ALLUSERSPROFILE%\Microsoft Help\MS.Dexplore_1033_MValidator.HxD
- %ALLUSERSPROFILE%\Microsoft Help\MS.Dexplore_1033_MKWD_VS70NamedUrl.HxW
- %ALLUSERSPROFILE%\Microsoft Help\MS.Dexplore_1033_MKWD_K.HxW
- %ALLUSERSPROFILE%\Microsoft Help\MS.Dexplore_1033_MKWD_F.HxW
- %ALLUSERSPROFILE%\Microsoft Help\MS.Dexplore_1033_MKWD_A.HxW
- %ALLUSERSPROFILE%\Microsoft Help\MS.Dexplore.hxn
- %ALLUSERSPROFILE%\Microsoft Help\Hx_1033_MValidator.Lck
- %ALLUSERSPROFILE%\Microsoft Help\Hx_1033_MValidator.HxD
- %ALLUSERSPROFILE%\Microsoft Help\Hx_1033_MTOC_Hx.HxH
- %ALLUSERSPROFILE%\Microsoft Help\Hx_1033_MKWD_NamedURL.HxW
- %ALLUSERSPROFILE%\Microsoft Help\Hx_1033_MKWD_K.HxW
- %ALLUSERSPROFILE%\Microsoft Help\Hx.hxn
- %ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\Setup.ini
- %ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\RDC\Setup.ini
- %ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\RDC\ABCPY.INI
- %ALLUSERSPROFILE%\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\ABCPY.INI
- %ALLUSERSPROFILE%\Adobe\Acrobat\11.0\Replicate\Security\directories.acrodata
- C:\autoexec.bat
- D:\install.log
- %ALLUSERSPROFILE%\Microsoft Help\MS.MSACCESS.DEV.14.1033.hxn
- %ALLUSERSPROFILE%\Microsoft Help\MS.MSOUC.14.1033.hxn
- '<SYSTEM32>\cmd.exe' /c %TEMP%\VVS.bat' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\VVS.bat