Technical Information
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'MarvelHost' = '┢偁䑐呁╁浜瑨灯㈳楢硥≥'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'MarvelHost' = '┢偁䑐呁╁浜瑨灯㈳楢硥≥'
- %APPDATA%\mozilla\firefox\profiles.ini
- %APPDATA%\thunderbird\profiles.ini
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\coffee.bmp
- %HOMEPATH%\desktop\contoso.cer
- %HOMEPATH%\desktop\contosoroot.cer
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\dashborder_144.bmp
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\nwfieldnotes1966.docx
- %HOMEPATH%\desktop\toolbar.bmp
- %APPDATA%\mhtop32bit.exe
- %ALLUSERSPROFILE%\mozilla\updates\308046b0af4a39cb\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft help\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows defender\support\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x86_6bf2947c61eb2a806ee6756bfbdda581aa113e_cab_014d8101\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x86_3d7e2448614bf82912853ac5f0bc80ae562b9024_cab_07be08dd\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_x86_289f42c8c0a9db05e4274a776fcf89f6ceaaf2_cab_014d811f\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_cab_0f381c73\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_06f0d010\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_cab_0a342f7e\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\wer\reportqueue\noncritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_0984e33a\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\steam\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\ringtones\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\windows\caches\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\user account pictures\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\secstore\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\propmap\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\gatherlogs\systemindex\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\rac\statedata\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\rac\publisheddata\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\564f02e6419b9858949b0cd5a65e2c8c0944dd88\packages\patch\x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\d4036846864773e3d647f421dfe7f6ca536e307b\packages\patch\x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\readme_decryptor.txt
- %HOMEPATH%\favorites\microsoft websites\readme_decryptor.txt
- %HOMEPATH%\favorites\links for united states\readme_decryptor.txt
- %HOMEPATH%\favorites\links\readme_decryptor.txt
- %HOMEPATH%\contacts\readme_decryptor.txt
- C:\users\public\videos\sample videos\readme_decryptor.txt
- C:\users\public\recorded tv\sample media\readme_decryptor.txt
- C:\users\public\pictures\sample pictures\readme_decryptor.txt
- C:\users\public\music\sample music\readme_decryptor.txt
- C:\users\public\libraries\readme_decryptor.txt
- C:\users\default\readme_decryptor.txt
- %ALLUSERSPROFILE%\sun\java\java update\readme_decryptor.txt
- C:\users\default\appdata\roaming\microsoft\windows\sendto\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\packages\vcruntimeadditional_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{ec9807de-b577-47b1-a024-0251805acf24}v14.29.30133\packages\vcruntimeminimum_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{bd95a8cd-1d9f-35ad-981a-3e7925026ebb}v11.0.61030\packages\vcruntimeminimum_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{7258184a-ec44-4b1a-a7d3-68d85a35bfd0}v14.16.27024\packages\vcruntimeadditional_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{5eefcefb-e5f7-4c82-99a5-813f04aa4fbd}v14.16.27024\packages\vcruntimeminimum_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{42667d2e-b054-46c1-9d46-2ee1332c14c1}v14.29.30133\packages\vcruntimeadditional_x86\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{39e28474-b67b-4209-af1b-e9ad0a83d8ca}\readme_decryptor.txt
- %ALLUSERSPROFILE%\package cache\{38b2c744-ad08-4d5b-91a2-3fb6f739ff3e}\readme_decryptor.txt
- %HOMEPATH%\favorites\msn websites\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\cache\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\office\uicaptions\3082\readme_decryptor.txt
- %APPDATA%\thunderbird\profiles\5sfumjqc.default\readme_decryptor.txt
- %APPDATA%\thunderbird\crash reports\readme_decryptor.txt
- %APPDATA%\telegram desktop\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\crashes\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\bookmarkbackups\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\readme_decryptor.txt
- %APPDATA%\mozilla\firefox\crash reports\readme_decryptor.txt
- %APPDATA%\microsoft\windows\themes\readme_decryptor.txt
- %APPDATA%\microsoft\windows\sendto\readme_decryptor.txt
- %APPDATA%\microsoft\windows\recent\customdestinations\readme_decryptor.txt
- %APPDATA%\microsoft\windows\recent\automaticdestinations\readme_decryptor.txt
- %APPDATA%\microsoft\windows\libraries\readme_decryptor.txt
- %APPDATA%\thunderbird\profiles\5sfumjqc.default\crashes\readme_decryptor.txt
- %APPDATA%\thunderbird\readme_decryptor.txt
- D:\readme_decryptor.txt
- %HOMEPATH%\desktop\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\office\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\mf\readme_decryptor.txt
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ab0000000001}\readme_decryptor.txt
- %ALLUSERSPROFILE%\adobe\acrobat\11.0\replicate\security\readme_decryptor.txt
- C:\msocache\all users\{90140000-0117-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0117-0409-0000-0000000ff1ce}-c\access.en-us\readme_decryptor.txt
- C:\msocache\all users\{90140000-0115-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-00ba-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-00a1-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0044-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.fr\readme_decryptor.txt
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.es\readme_decryptor.txt
- C:\msocache\all users\{90140000-002c-0409-0000-0000000ff1ce}-c\proof.en\readme_decryptor.txt
- C:\msocache\all users\{90140000-001b-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-001a-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0019-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0018-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0016-0409-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\msocache\all users\{90140000-0011-0000-0000-0000000ff1ce}-c\readme_decryptor.txt
- C:\kms\readme_decryptor.txt
- C:\readme_decryptor.txt
- %ALLUSERSPROFILE%\microsoft\office\uicaptions\1036\readme_decryptor.txt
- %HOMEPATH%\favorites\windows live\readme_decryptor.txt
- from %APPDATA%\microsoft\windows\libraries\documents.library-ms to %APPDATA%\microsoft\windows\libraries\documents.library-ms.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\crash reports\installtime20150507114201 to %APPDATA%\thunderbird\crash reports\installtime20150507114201.[ashtray@outlookpro.net].termit
- from %APPDATA%\telegram desktop\unins000.dat to %APPDATA%\telegram desktop\unins000.dat.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles.ini to %APPDATA%\mozilla\firefox\profiles.ini.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\xulstore.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\xulstore.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\user.js to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\user.js.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\times.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\times.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\addons.json to %APPDATA%\thunderbird\profiles\5sfumjqc.default\addons.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\abook.mab to %APPDATA%\thunderbird\profiles\5sfumjqc.default\abook.mab.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\1657114595amcateirvtisty.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\.metadata-v2 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\.metadata-v2.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sitesecurityservicestate.txt to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sitesecurityservicestate.txt.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\upgrade.jsonlz4-20190813150448 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\upgrade.jsonlz4-20190813150448.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\recovery.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\recovery.jsonlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\recovery.baklz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\recovery.baklz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\previous.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessionstore-backups\previous.jsonlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013537.136d2301-e9c9-4685-88a8-34350d6f8b5f.health.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013537.136d2301-e9c9-4685-88a8-34350d6f8b5f.health.jsonlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\blist.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\blist.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\times.json to %APPDATA%\thunderbird\profiles\5sfumjqc.default\times.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\sessioncheckpoints.json to %APPDATA%\thunderbird\profiles\5sfumjqc.default\sessioncheckpoints.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\secmod.db to %APPDATA%\thunderbird\profiles\5sfumjqc.default\secmod.db.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\prefs.js to %APPDATA%\thunderbird\profiles\5sfumjqc.default\prefs.js.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\pluginreg.dat to %APPDATA%\thunderbird\profiles\5sfumjqc.default\pluginreg.dat.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\places.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\places.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\permissions.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\permissions.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\mailviews.dat to %APPDATA%\thunderbird\profiles\5sfumjqc.default\mailviews.dat.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\localstore.rdf to %APPDATA%\thunderbird\profiles\5sfumjqc.default\localstore.rdf.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\key3.db to %APPDATA%\thunderbird\profiles\5sfumjqc.default\key3.db.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\history.mab to %APPDATA%\thunderbird\profiles\5sfumjqc.default\history.mab.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\global-messages-db.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\global-messages-db.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\formhistory.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\formhistory.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\extensions.json to %APPDATA%\thunderbird\profiles\5sfumjqc.default\extensions.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\extensions.ini to %APPDATA%\thunderbird\profiles\5sfumjqc.default\extensions.ini.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\crashes\store.json.mozlz4 to %APPDATA%\thunderbird\profiles\5sfumjqc.default\crashes\store.json.mozlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\cookies.sqlite to %APPDATA%\thunderbird\profiles\5sfumjqc.default\cookies.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\compatibility.ini to %APPDATA%\thunderbird\profiles\5sfumjqc.default\compatibility.ini.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\cert8.db to %APPDATA%\thunderbird\profiles\5sfumjqc.default\cert8.db.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessioncheckpoints.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\sessioncheckpoints.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\search.json.mozlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\search.json.mozlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\97485753-1b2b-4e3b-953d-ac3ea5457f3d to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\97485753-1b2b-4e3b-953d-ac3ea5457f3d.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\installs.ini to %APPDATA%\mozilla\firefox\installs.ini.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\containers.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\containers.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\compatibility.ini to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\compatibility.ini.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\broadcast-listeners.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\broadcast-listeners.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\bookmarkbackups\bookmarks-2023-06-28_11_ukwbceqzcyihwn6n3vgyrg==.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\bookmarkbackups\bookmarks-2023-06-28_11_ukwbceqzcyihwn6n3vgyrg==.jsonlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addonstartup.json.lz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addonstartup.json.lz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addons.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addons.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\user.js to %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\user.js.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\times.json to %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\times.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\crash reports\installtime20190813150448 to %APPDATA%\mozilla\firefox\crash reports\installtime20190813150448.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\crashes\store.json.mozlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\crashes\store.json.mozlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\microsoft\windows\themes\transcodedwallpaper.jpg to %APPDATA%\microsoft\windows\themes\transcodedwallpaper.jpg.[ashtray@outlookpro.net].termit
- from %APPDATA%\microsoft\windows\sendto\mail recipient.mapimail to %APPDATA%\microsoft\windows\sendto\mail recipient.mapimail.[ashtray@outlookpro.net].termit
- from %APPDATA%\microsoft\windows\sendto\desktop (create shortcut).desklink to %APPDATA%\microsoft\windows\sendto\desktop (create shortcut).desklink.[ashtray@outlookpro.net].termit
- from %APPDATA%\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget to %APPDATA%\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget.[ashtray@outlookpro.net].termit
- from %APPDATA%\microsoft\windows\recent\automaticdestinations\1b4dd67f29cb1962.automaticdestinations-ms to %APPDATA%\microsoft\windows\recent\automaticdestinations\1b4dd67f29cb1962.automaticdestinations-ms.[ashtray@outlookpro.net].termit
- from %APPDATA%\microsoft\windows\libraries\videos.library-ms to %APPDATA%\microsoft\windows\libraries\videos.library-ms.[ashtray@outlookpro.net].termit
- from %APPDATA%\microsoft\windows\libraries\pictures.library-ms to %APPDATA%\microsoft\windows\libraries\pictures.library-ms.[ashtray@outlookpro.net].termit
- from %APPDATA%\microsoft\windows\libraries\music.library-ms to %APPDATA%\microsoft\windows\libraries\music.library-ms.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\virtualfolders.dat to %APPDATA%\thunderbird\profiles\5sfumjqc.default\virtualfolders.dat.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles\5sfumjqc.default\blocklist.xml to %APPDATA%\thunderbird\profiles\5sfumjqc.default\blocklist.xml.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013430.39c8d187-e7b6-41f0-8919-3c3ad3614730.modules.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013430.39c8d187-e7b6-41f0-8919-3c3ad3614730.modules.jsonlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050073.b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25.event.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050073.b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25.event.jsonlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\content-prefs.sqlite to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\content-prefs.sqlite.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\58d05602-57c3-43da-8c92-63c175048e33 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\58d05602-57c3-43da-8c92-63c175048e33.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\39c8d187-e7b6-41f0-8919-3c3ad3614730 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\39c8d187-e7b6-41f0-8919-3c3ad3614730.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\38b30436-e66d-47e7-ad31-6c8f4f754428 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\38b30436-e66d-47e7-ad31-6c8f4f754428.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\136d2301-e9c9-4685-88a8-34350d6f8b5f to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\saved-telemetry-pings\136d2301-e9c9-4685-88a8-34350d6f8b5f.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\prefs.js to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\prefs.js.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\pluginreg.dat to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\pluginreg.dat.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\pkcs11.txt to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\pkcs11.txt.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\handlers.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\handlers.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.sig to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.sig.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.lib to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.lib.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\manifest.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\manifest.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\license.txt to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\gmp-widevinecdm\4.10.1440.18\license.txt.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extensions.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extensions.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extension-preferences.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extension-preferences.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\state.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\state.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\session-state.json to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\session-state.json.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050106.58d05602-57c3-43da-8c92-63c175048e33.first-shutdown.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050106.58d05602-57c3-43da-8c92-63c175048e33.first-shutdown.jsonlz4.[ashtray@outlookpro.net].ter...
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050105.38b30436-e66d-47e7-ad31-6c8f4f754428.main.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050105.38b30436-e66d-47e7-ad31-6c8f4f754428.main.jsonlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050005.97485753-1b2b-4e3b-953d-ac3ea5457f3d.new-profile.jsonlz4 to %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050005.97485753-1b2b-4e3b-953d-ac3ea5457f3d.new-profile.jsonlz4.[ashtray@outlookpro.net].termit
- from %APPDATA%\thunderbird\profiles.ini to %APPDATA%\thunderbird\profiles.ini.[ashtray@outlookpro.net].termit
- %APPDATA%\microsoft\windows\libraries\documents.library-ms
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\session-state.json
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050106.58d05602-57c3-43da-8c92-63c175048e33.first-shutdown.jsonlz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050105.38b30436-e66d-47e7-ad31-6c8f4f754428.main.jsonlz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050073.b7c5e8c3-95de-4c89-bfc9-c8e0264d6d25.event.jsonlz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406050005.97485753-1b2b-4e3b-953d-ac3ea5457f3d.new-profile.jsonlz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013537.136d2301-e9c9-4685-88a8-34350d6f8b5f.health.jsonlz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\archived\2022-09\1664406013430.39c8d187-e7b6-41f0-8919-3c3ad3614730.modules.jsonlz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\crashes\store.json.mozlz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\content-prefs.sqlite
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\containers.json
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\compatibility.ini
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\broadcast-listeners.json
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\bookmarkbackups\bookmarks-2023-06-28_11_ukwbceqzcyihwn6n3vgyrg==.jsonlz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addonstartup.json.lz4
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\addons.json
- %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\user.js
- %APPDATA%\mozilla\firefox\profiles\4biyo3ui.default\times.json
- %APPDATA%\mozilla\firefox\installs.ini
- %APPDATA%\mozilla\firefox\crash reports\installtime20190813150448
- %APPDATA%\microsoft\windows\themes\transcodedwallpaper.jpg
- %APPDATA%\microsoft\windows\sendto\mail recipient.mapimail
- %APPDATA%\microsoft\windows\sendto\desktop (create shortcut).desklink
- %APPDATA%\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget
- %APPDATA%\microsoft\windows\recent\automaticdestinations\1b4dd67f29cb1962.automaticdestinations-ms
- %APPDATA%\microsoft\windows\libraries\videos.library-ms
- %APPDATA%\microsoft\windows\libraries\pictures.library-ms
- %APPDATA%\microsoft\windows\libraries\music.library-ms
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\datareporting\state.json
- %APPDATA%\mozilla\firefox\profiles\e9nnxrwe.default-release\extension-preferences.json
- '%APPDATA%\mhtop32bit.exe'
- '<SYSTEM32>\cmd.exe' /c copy "<Full path to file>" "%APPDATA%\mhtop32bit.exe"' (with hidden window)
- '%APPDATA%\mhtop32bit.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c copy "<Full path to file>" "%APPDATA%\mhtop32bit.exe"