マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話

03-6550-8770

Profile

Trojan.KillFiles.65292

Added to the Dr.Web virus database: 2020-11-16

Virus description added:

Technical Information

Malicious functions
Executes the following
  • '<SYSTEM32>\taskkill.exe' /f /im EpicGamesLauncher.exe
  • '<SYSTEM32>\taskkill.exe' /f /im steam.exe
  • '<SYSTEM32>\taskkill.exe' /f /im FortniteClient-Win64-Shipping.exe
Modifies file system
Creates the following files
  • nul
  • volume{c84d25cd-f368-11e4-889d-806e6f6e6963}\system volume information\tracking.log.tmp
  • volume{600ba660-c712-11e6-a54f-080027cffa47}\system volume information\tracking.log.tmp
Deletes the following files
  • <SYSTEM32>\catroot2\dberr.txt
  • %WINDIR%\inf\prnlx006.inf
  • %WINDIR%\inf\prnlx005.pnf
  • %WINDIR%\inf\prnlx005.inf
  • %WINDIR%\inf\prnlx004.pnf
  • %WINDIR%\inf\prnlx004.inf
  • %WINDIR%\inf\prnlx003.pnf
  • %WINDIR%\inf\prnlx003.inf
  • %WINDIR%\inf\prnlx002.pnf
  • %WINDIR%\inf\prnlx002.inf
  • %WINDIR%\inf\prnle004.pnf
  • %WINDIR%\inf\prnle004.inf
  • %WINDIR%\inf\prnle003.pnf
  • %WINDIR%\inf\prnle003.inf
  • %WINDIR%\inf\prnle002.pnf
  • %WINDIR%\inf\prnle002.inf
  • %WINDIR%\inf\prnky009.pnf
  • %WINDIR%\inf\prnky009.inf
  • %WINDIR%\inf\prnky008.pnf
  • %WINDIR%\inf\prnky008.inf
  • %WINDIR%\inf\prnky007.inf
  • %WINDIR%\inf\prnky007.pnf
  • %WINDIR%\inf\prnlx006.pnf
  • %WINDIR%\inf\prnlx007.inf
  • %WINDIR%\inf\prnlx00x.inf
  • %WINDIR%\inf\prnlx00w.pnf
  • %WINDIR%\inf\prnlx00w.inf
  • %WINDIR%\inf\prnlx00v.pnf
  • %WINDIR%\inf\prnlx00v.inf
  • %WINDIR%\inf\prnlx00e.pnf
  • %WINDIR%\inf\prnlx00e.inf
  • %WINDIR%\inf\prnlx00d.pnf
  • %WINDIR%\inf\prnlx00d.inf
  • %WINDIR%\inf\prnlx00c.inf
  • %WINDIR%\inf\prnkm004.inf
  • %WINDIR%\inf\prnlx00b.pnf
  • %WINDIR%\inf\prnlx00b.inf
  • %WINDIR%\inf\prnlx00a.pnf
  • %WINDIR%\inf\prnlx00a.inf
  • %WINDIR%\inf\prnlx009.pnf
  • %WINDIR%\inf\prnlx009.inf
  • %WINDIR%\inf\prnlx008.pnf
  • %WINDIR%\inf\prnlx008.inf
  • %WINDIR%\inf\prnlx007.pnf
  • %WINDIR%\inf\prnky006.pnf
  • %WINDIR%\inf\prnky006.inf
  • %WINDIR%\inf\prnky005.pnf
  • %WINDIR%\inf\prnhp003.pnf
  • %WINDIR%\inf\prnhp003.inf
  • %WINDIR%\inf\prnhp002.pnf
  • %WINDIR%\inf\prnhp002.inf
  • %WINDIR%\inf\prngt004.pnf
  • %WINDIR%\inf\prngt004.inf
  • %WINDIR%\inf\prngt003.pnf
  • %WINDIR%\inf\prngt003.inf
  • %WINDIR%\inf\prngt002.pnf
  • %WINDIR%\inf\prngt002.inf
  • %WINDIR%\inf\prnge001.pnf
  • %WINDIR%\inf\prnge001.inf
  • %WINDIR%\inf\prnfx002.pnf
  • %WINDIR%\inf\prnfx002.inf
  • %WINDIR%\inf\prnep00l.pnf
  • %WINDIR%\inf\prnep00l.inf
  • %WINDIR%\inf\prnep00g.pnf
  • %WINDIR%\inf\prnep00g.inf
  • %WINDIR%\inf\prnhp004.pnf
  • %WINDIR%\inf\prnhp005.inf
  • %WINDIR%\inf\prnhp004.inf
  • %WINDIR%\inf\prnhp005.pnf
  • %WINDIR%\inf\prnky005.inf
  • %WINDIR%\inf\prnin002.inf
  • %WINDIR%\inf\prnky004.pnf
  • %WINDIR%\inf\prnky004.inf
  • %WINDIR%\inf\prnky003.pnf
  • %WINDIR%\inf\prnky003.inf
  • %WINDIR%\inf\prnky002.pnf
  • %WINDIR%\inf\prnky002.inf
  • %WINDIR%\inf\prnkm005.pnf
  • %WINDIR%\inf\prnkm005.inf
  • %WINDIR%\inf\prnlx00c.pnf
  • %WINDIR%\inf\prnlx00x.pnf
  • %WINDIR%\inf\prnkm003.pnf
  • %WINDIR%\inf\prnkm003.inf
  • %WINDIR%\inf\prnkm002.pnf
  • %WINDIR%\inf\prnkm002.inf
  • %WINDIR%\inf\prnin004.pnf
  • %WINDIR%\inf\prnin004.inf
  • %WINDIR%\inf\prnin003.pnf
  • %WINDIR%\inf\prnin003.inf
  • %WINDIR%\inf\prnin002.pnf
  • %WINDIR%\inf\prnkm004.pnf
  • %WINDIR%\inf\prnlx00y.inf
  • %WINDIR%\inf\prnlx00y.pnf
  • %WINDIR%\inf\prnlx00z.inf
  • %WINDIR%\inf\ricoh.inf
  • %WINDIR%\inf\rdvgwddm.inf
  • %WINDIR%\inf\rdpbus.pnf
  • %WINDIR%\inf\rdpbus.inf
  • %WINDIR%\inf\rdlsbuscbs.inf
  • %WINDIR%\inf\rawsilo.pnf
  • %WINDIR%\inf\rawsilo.inf
  • %WINDIR%\inf\ramdisk.pnf
  • %WINDIR%\inf\ramdisk.inf
  • %WINDIR%\inf\ql40xx2.pnf
  • %WINDIR%\inf\ql40xx2.inf
  • %WINDIR%\inf\ql40xx.pnf
  • %WINDIR%\inf\ql40xx.inf
  • %WINDIR%\inf\ql2300.pnf
  • %WINDIR%\inf\ql2300.inf
  • %WINDIR%\inf\qd3x64.pnf
  • %WINDIR%\inf\qd3x64.inf
  • %WINDIR%\inf\prnxx002.pnf
  • %WINDIR%\inf\prnxx002.inf
  • %WINDIR%\inf\ricoh.pnf
  • %WINDIR%\inf\rndiscmp.inf
  • %WINDIR%\inf\rndiscmp.pnf
  • %WINDIR%\inf\rspndr.pnf
  • %WINDIR%\inf\setupapi.offline.log
  • %WINDIR%\inf\setupapi.ev3
  • %WINDIR%\inf\setupapi.ev2
  • %WINDIR%\inf\setupapi.ev1
  • %WINDIR%\inf\setupapi.dev.log
  • %WINDIR%\inf\setupapi.app.log
  • %WINDIR%\inf\ServiceModelService 3.0.0.0\_ServiceModelServicePerfCounters.ini
  • %WINDIR%\inf\ServiceModelOperation 3.0.0.0\_ServiceModelOperationPerfCounters.ini
  • %WINDIR%\inf\ServiceModelOperation 3.0.0.0\_ServiceModelOperationPerfCounters.h
  • %WINDIR%\inf\ServiceModelService 3.0.0.0\_ServiceModelServicePerfCounters.h
  • %WINDIR%\inf\ServiceModelEndpoint 3.0.0.0\_ServiceModelEndpointPerfCounters.ini
  • %WINDIR%\inf\sensorsalsdriver.inf
  • %WINDIR%\inf\sdbus.pnf
  • %WINDIR%\inf\sdbus.inf
  • %WINDIR%\inf\scsidev.pnf
  • %WINDIR%\inf\scsidev.inf
  • %WINDIR%\inf\scrawpdo.pnf
  • %WINDIR%\inf\scrawpdo.inf
  • %WINDIR%\inf\sbp2.pnf
  • %WINDIR%\inf\sbp2.inf
  • %WINDIR%\inf\prnep00f.pnf
  • %WINDIR%\inf\prnsa002.pnf
  • %WINDIR%\inf\prnts003.inf
  • %WINDIR%\inf\prnts002.pnf
  • %WINDIR%\inf\prnrc004.pnf
  • %WINDIR%\inf\prnrc004.inf
  • %WINDIR%\inf\prnrc003.pnf
  • %WINDIR%\inf\prnrc003.inf
  • %WINDIR%\inf\prnrc002.pnf
  • %WINDIR%\inf\prnrc002.inf
  • %WINDIR%\inf\prnok002.pnf
  • %WINDIR%\inf\prnok002.inf
  • %WINDIR%\inf\prnod002.pnf
  • %WINDIR%\inf\prnod002.inf
  • %WINDIR%\inf\prnnr004.pnf
  • %WINDIR%\inf\prnnr004.inf
  • %WINDIR%\inf\prnnr003.pnf
  • %WINDIR%\inf\prnnr003.inf
  • %WINDIR%\inf\prnnr002.pnf
  • %WINDIR%\inf\prnnr002.inf
  • %WINDIR%\inf\prnms002.pnf
  • %WINDIR%\inf\prnms002.inf
  • %WINDIR%\inf\prnlx00z.pnf
  • %WINDIR%\inf\prnrc005.inf
  • %WINDIR%\inf\prnrc005.pnf
  • %WINDIR%\inf\prnrc006.inf
  • %WINDIR%\inf\prnrc006.pnf
  • %WINDIR%\inf\prnsv004.pnf
  • %WINDIR%\inf\prnsv004.inf
  • %WINDIR%\inf\prnsv003.pnf
  • %WINDIR%\inf\prnsv003.inf
  • %WINDIR%\inf\prnsv002.pnf
  • %WINDIR%\inf\prnsv002.inf
  • %WINDIR%\inf\prnso002.pnf
  • %WINDIR%\inf\prnso002.inf
  • %WINDIR%\inf\prnsh002.pnf
  • %WINDIR%\inf\sffdisk.inf
  • %WINDIR%\inf\prnsh002.inf
  • %WINDIR%\inf\prnsa002.inf
  • %WINDIR%\inf\prnrc00c.pnf
  • %WINDIR%\inf\prnrc00c.inf
  • %WINDIR%\inf\prnrc00b.pnf
  • %WINDIR%\inf\prnrc00b.inf
  • %WINDIR%\inf\prnrc00a.pnf
  • %WINDIR%\inf\prnrc00a.inf
  • %WINDIR%\inf\prnrc007.pnf
  • %WINDIR%\inf\prnrc007.inf
  • %WINDIR%\inf\prnts002.inf
  • %WINDIR%\inf\prnts003.pnf
  • %WINDIR%\inf\prnep00f.inf
  • %WINDIR%\inf\prnbr00a.inf
  • %WINDIR%\inf\netw5v64.pnf
  • %WINDIR%\inf\netw5v64.inf
  • %WINDIR%\inf\netvwifibus.PNF
  • %WINDIR%\inf\netvwifibus.inf
  • %WINDIR%\inf\netvg62a.pnf
  • %WINDIR%\inf\netvg62a.inf
  • %WINDIR%\inf\netvfx64.pnf
  • %WINDIR%\inf\netvfx64.inf
  • %WINDIR%\inf\nettun.pnf
  • %WINDIR%\inf\nettun.inf
  • %WINDIR%\inf\nettcpip.pnf
  • %WINDIR%\inf\netsstpt.pnf
  • %WINDIR%\inf\netsstpa.pnf
  • %WINDIR%\inf\netserv.pnf
  • %WINDIR%\inf\netrtx64.pnf
  • %WINDIR%\inf\netrtx64.inf
  • %WINDIR%\inf\netrtl64.pnf
  • %WINDIR%\inf\netrtl64.inf
  • %WINDIR%\inf\netrndis.pnf
  • %WINDIR%\inf\netrast.pnf
  • %WINDIR%\inf\netrndis.inf
  • %WINDIR%\inf\netxex64.inf
  • %WINDIR%\inf\netxex64.pnf
  • %WINDIR%\inf\perflib\0000\perfi.dat
  • %WINDIR%\inf\perflib\0000\perfh.dat
  • %WINDIR%\inf\perflib\0000\perfd.dat
  • %WINDIR%\inf\perflib\0000\perfc.dat
  • %WINDIR%\inf\pcmcia.pnf
  • %WINDIR%\inf\pcmcia.inf
  • %WINDIR%\inf\oem1.inf
  • %WINDIR%\inf\oem0.inf
  • %WINDIR%\inf\nv_lh.pnf
  • %WINDIR%\inf\nvraid.pnf
  • %WINDIR%\inf\netnvm64.inf
  • %WINDIR%\inf\nvraid.inf
  • %WINDIR%\inf\nulhpopr.pnf
  • %WINDIR%\inf\nulhpopr.inf
  • %WINDIR%\inf\ntprint.pnf
  • %WINDIR%\inf\ntprint.inf
  • %WINDIR%\inf\nfrd960.pnf
  • %WINDIR%\inf\nfrd960.inf
  • %WINDIR%\inf\netxfx64.pnf
  • %WINDIR%\inf\netxfx64.inf
  • %WINDIR%\inf\netrass.pnf
  • %WINDIR%\inf\netrasa.pnf
  • %WINDIR%\inf\netr7364.pnf
  • %WINDIR%\inf\netk57a.pnf
  • %WINDIR%\inf\netk57a.inf
  • %WINDIR%\inf\netirda.pnf
  • %WINDIR%\inf\netirda.inf
  • %WINDIR%\inf\netip6.pnf
  • %WINDIR%\inf\netimm.pnf
  • %WINDIR%\inf\netimm.inf
  • %WINDIR%\inf\netg664.pnf
  • %WINDIR%\inf\netg664.inf
  • %WINDIR%\inf\netevbda.pnf
  • %WINDIR%\inf\netevbda.inf
  • %WINDIR%\inf\netefe3e.pnf
  • %WINDIR%\inf\netefe3e.inf
  • %WINDIR%\inf\nete1g3e.pnf
  • %WINDIR%\inf\nete1g3e.inf
  • %WINDIR%\inf\nete1e3e.pnf
  • %WINDIR%\inf\nete1e3e.inf
  • %WINDIR%\inf\netbxnda.pnf
  • %WINDIR%\inf\netl160a.pnf
  • %WINDIR%\inf\netl1c64.inf
  • %WINDIR%\inf\netl160a.inf
  • %WINDIR%\inf\netl1c64.pnf
  • %WINDIR%\inf\netr7364.inf
  • %WINDIR%\inf\netl1e64.inf
  • %WINDIR%\inf\netr28x.pnf
  • %WINDIR%\inf\netr28x.inf
  • %WINDIR%\inf\netr28ux.pnf
  • %WINDIR%\inf\netr28ux.inf
  • %WINDIR%\inf\netpacer.pnf
  • %WINDIR%\inf\netnwifi.pnf
  • %WINDIR%\inf\netnvma.pnf
  • %WINDIR%\inf\netnvma.inf
  • %WINDIR%\inf\nv_lh.inf
  • %WINDIR%\inf\perflib\0409\perfc.dat
  • %WINDIR%\inf\netnb.pnf
  • %WINDIR%\inf\netmyk00.pnf
  • %WINDIR%\inf\netmyk00.inf
  • %WINDIR%\inf\netmscli.pnf
  • %WINDIR%\inf\netloop.pnf
  • %WINDIR%\inf\netloop.inf
  • %WINDIR%\inf\netl260a.pnf
  • %WINDIR%\inf\netl260a.inf
  • %WINDIR%\inf\netl1e64.pnf
  • %WINDIR%\inf\netnvm64.pnf
  • %WINDIR%\inf\perflib\0409\perfd.dat
  • %WINDIR%\inf\perflib\0409\perfh.dat
  • %WINDIR%\inf\perflib\0409\perfi.dat
  • %WINDIR%\inf\prnca00h.pnf
  • %WINDIR%\inf\prnca00h.inf
  • %WINDIR%\inf\prnca00g.pnf
  • %WINDIR%\inf\prnca00g.inf
  • %WINDIR%\inf\prnca00f.pnf
  • %WINDIR%\inf\prnca00f.inf
  • %WINDIR%\inf\prnca00e.pnf
  • %WINDIR%\inf\prnca00e.inf
  • %WINDIR%\inf\prnca00d.pnf
  • %WINDIR%\inf\prnca00d.inf
  • %WINDIR%\inf\prnca00c.pnf
  • %WINDIR%\inf\prnca00c.inf
  • %WINDIR%\inf\prnca00b.pnf
  • %WINDIR%\inf\prnca00b.inf
  • %WINDIR%\inf\prnca00a.pnf
  • %WINDIR%\inf\prnca00a.inf
  • %WINDIR%\inf\prnca003.pnf
  • %WINDIR%\inf\prnca003.inf
  • %WINDIR%\inf\prnbr00a.pnf
  • %WINDIR%\inf\prnca00i.inf
  • %WINDIR%\inf\prnca00i.pnf
  • %WINDIR%\inf\prnca00x.inf
  • %WINDIR%\inf\prnca00x.pnf
  • %WINDIR%\inf\prnep00d.pnf
  • %WINDIR%\inf\prnep00d.inf
  • %WINDIR%\inf\prnep00c.pnf
  • %WINDIR%\inf\prnep00c.inf
  • %WINDIR%\inf\prnep00b.pnf
  • %WINDIR%\inf\prnep00b.inf
  • %WINDIR%\inf\prnep00a.pnf
  • %WINDIR%\inf\prnep00a.inf
  • %WINDIR%\inf\prnep005.pnf
  • %WINDIR%\inf\prnep004.pnf
  • %WINDIR%\inf\prnep005.inf
  • %WINDIR%\inf\prnep004.inf
  • %WINDIR%\inf\prnep003.pnf
  • %WINDIR%\inf\prnep003.inf
  • %WINDIR%\inf\prnep002.pnf
  • %WINDIR%\inf\prnep002.inf
  • %WINDIR%\inf\prnca00z.pnf
  • %WINDIR%\inf\prnca00z.inf
  • %WINDIR%\inf\prnca00y.pnf
  • %WINDIR%\inf\prnca00y.inf
  • %WINDIR%\inf\prnep00e.pnf
  • %WINDIR%\inf\prnbr003.inf
  • %WINDIR%\inf\prnbr009.pnf
  • %WINDIR%\inf\prnbr009.inf
  • %WINDIR%\inf\ph3xibc6.inf
  • %WINDIR%\inf\ph3xibc5.pnf
  • %WINDIR%\inf\ph3xibc5.inf
  • %WINDIR%\inf\ph3xibc4.pnf
  • %WINDIR%\inf\ph3xibc4.inf
  • %WINDIR%\inf\ph3xibc3.pnf
  • %WINDIR%\inf\ph3xibc3.inf
  • %WINDIR%\inf\ph3xibc2.pnf
  • %WINDIR%\inf\ph3xibc2.inf
  • %WINDIR%\inf\ph3xibc12.PNF
  • %WINDIR%\inf\ph3xibc12.inf
  • %WINDIR%\inf\ph3xibc11.PNF
  • %WINDIR%\inf\ph3xibc11.inf
  • %WINDIR%\inf\ph3xibc10.PNF
  • %WINDIR%\inf\ph3xibc10.inf
  • %WINDIR%\inf\ph3xibc1.pnf
  • %WINDIR%\inf\ph3xibc1.inf
  • %WINDIR%\inf\ph3xibc0.pnf
  • %WINDIR%\inf\ph3xibc0.inf
  • %WINDIR%\inf\ph3xibc6.pnf
  • %WINDIR%\inf\ph3xibc7.inf
  • %WINDIR%\inf\ph3xibc7.pnf
  • %WINDIR%\inf\ph3xibc8.inf
  • %WINDIR%\inf\prnbr008.inf
  • %WINDIR%\inf\prnbr007.pnf
  • %WINDIR%\inf\prnbr007.inf
  • %WINDIR%\inf\prnbr006.pnf
  • %WINDIR%\inf\prnbr006.inf
  • %WINDIR%\inf\prnbr005.pnf
  • %WINDIR%\inf\prnbr005.inf
  • %WINDIR%\inf\prnbr004.pnf
  • %WINDIR%\inf\prnbr004.inf
  • %WINDIR%\inf\prnep00e.inf
  • %WINDIR%\inf\prnbr003.pnf
  • %WINDIR%\inf\prnbr002.pnf
  • %WINDIR%\inf\prnbr002.inf
  • %WINDIR%\inf\ph6xib64c1.PNF
  • %WINDIR%\inf\ph6xib64c1.inf
  • %WINDIR%\inf\ph6xib64c0.PNF
  • %WINDIR%\inf\ph6xib64c0.inf
  • %WINDIR%\inf\ph3xibc9.pnf
  • %WINDIR%\inf\ph3xibc9.inf
  • %WINDIR%\inf\ph3xibc8.pnf
  • %WINDIR%\inf\prnbr008.pnf
  • %WINDIR%\inf\wiacn001.inf
  • %WINDIR%\softwaredistribution\datastore\logs\edb00002.log
  • %WINDIR%\inf\sisraid2.pnf
  • %WINDIR%\Prefetch\DRVINST.EXE-4CB4314A.pf
  • %WINDIR%\Prefetch\DOTNETFX.EXE-FE16BE11.pf
  • %WINDIR%\Prefetch\DLLHOST.EXE-ECB71776.pf
  • %WINDIR%\Prefetch\DLLHOST.EXE-D58DA3A6.pf
  • %WINDIR%\Prefetch\DLLHOST.EXE-B2EB1806.pf
  • %WINDIR%\Prefetch\DLLHOST.EXE-861F96F8.pf
  • %WINDIR%\Prefetch\DLLHOST.EXE-7FAA2E4C.pf
  • %WINDIR%\Prefetch\DLLHOST.EXE-766398D2.pf
  • %WINDIR%\Prefetch\DLLHOST.EXE-5E46FA0D.pf
  • %WINDIR%\Prefetch\DEXPLORE.EXE-1749D792.pf
  • %WINDIR%\Prefetch\DEFRAG.EXE-588F90AD.pf
  • %WINDIR%\Prefetch\DBGCLR.EXE-AD18E06E.pf
  • %WINDIR%\Prefetch\CONTROL.EXE-817F8F1D.pf
  • %WINDIR%\Prefetch\CONHOST.EXE-1F3E9D7E.pf
  • %WINDIR%\Prefetch\CMD.EXE-4A81B364.pf
  • %WINDIR%\Prefetch\BCSSYNC.EXE-3F6C64A2.pf
  • %WINDIR%\Prefetch\AUDIODG.EXE-BDFD3029.pf
  • %WINDIR%\Prefetch\ASPNET_REGIIS.EXE-B76F1AD7.pf
  • %WINDIR%\Prefetch\ARH.EXE-F07E6C2C.pf
  • %WINDIR%\Prefetch\AgGlUAD_S-1-5-21-1960123792-2022915161-3775307078-1001.db
  • %WINDIR%\prefetch\agrobust.db
  • %WINDIR%\Prefetch\EXCEL.EXE-53A22446.pf
  • %WINDIR%\Prefetch\EXPLORER.EXE-A80E4F97.pf
  • %WINDIR%\Prefetch\MOFCOMP.EXE-FDE76EFC.pf
  • %WINDIR%\Prefetch\MOFCOMP.EXE-8FE3D558.pf
  • %WINDIR%\Prefetch\MMC.EXE-F5DC4F82.pf
  • %WINDIR%\Prefetch\MMC.EXE-F39CDED6.pf
  • %WINDIR%\Prefetch\MMC.EXE-53159585.pf
  • %WINDIR%\Prefetch\MIGPOLWIN.EXE-79E606FC.pf
  • %WINDIR%\Prefetch\MICROSOFT TOOLKIT.EXE-9DAE6A40.pf
  • %WINDIR%\Prefetch\MDM.EXE-EA9906DF.pf
  • %WINDIR%\Prefetch\MANAGEDDBGCA.EXE-6EA1439B.pf
  • %WINDIR%\prefetch\layout.ini
  • %WINDIR%\temp\ts_39ba.tmp
  • %WINDIR%\Prefetch\LAUNCHER.EXE-E41E51EE.pf
  • %WINDIR%\Prefetch\KMSNANO_SETUP.TMP-11A1562C.pf
  • %WINDIR%\Prefetch\KMSNANO_SETUP.EXE-631A87C6.pf
  • %WINDIR%\Prefetch\JAVAW.EXE-DCCF0AB8.pf
  • %WINDIR%\Prefetch\IPCONFIG.EXE-912F3D5B.pf
  • %WINDIR%\Prefetch\INSTALL.EXE-455F2D9B.pf
  • %WINDIR%\Prefetch\IEXPLORE.EXE-4B6C9213.pf
  • %WINDIR%\Prefetch\FLASHPLAYERUPDATESERVICE.EXE-216D9C35.pf
  • %WINDIR%\Prefetch\FIREFOX.EXE-18ACFCFF.pf
  • %WINDIR%\Prefetch\AgGlUAD_P_S-1-5-21-1960123792-2022915161-3775307078-1001.db
  • %WINDIR%\Prefetch\AgGlGlobalHistory.db
  • %WINDIR%\Prefetch\AgGlFgAppHistory.db
  • %WINDIR%\inf\xcbdav.pnf
  • %WINDIR%\inf\xcbdav.inf
  • %WINDIR%\inf\wvmic.inf
  • %WINDIR%\inf\wvmbusvideo.inf
  • %WINDIR%\inf\wvmbushid.inf
  • %WINDIR%\inf\wvmbus.inf
  • %WINDIR%\inf\wudfusbcciddriver.PNF
  • %WINDIR%\inf\wudfusbcciddriver.inf
  • %WINDIR%\inf\wstorvsc.inf
  • %WINDIR%\inf\wstorflt.inf
  • %WINDIR%\inf\wsdscdrv.pnf
  • %WINDIR%\inf\wsdscdrv.inf
  • %WINDIR%\inf\wsdprint.pnf
  • %WINDIR%\inf\wsdprint.inf
  • %WINDIR%\inf\ws3cap.inf
  • %WINDIR%\inf\wpdmtphw.pnf
  • %WINDIR%\inf\wpdmtphw.inf
  • %WINDIR%\inf\wpdmtp.pnf
  • %WINDIR%\inf\xnacc.pnf
  • %WINDIR%\Temp\8147932992814195939363050711163993686\AdobeARM.exe
  • %WINDIR%\inf\xnacc.inf
  • %WINDIR%\temp\adobearm.log
  • %WINDIR%\Prefetch\AgGlFaultHistory.db
  • %WINDIR%\temp\dmi8538.tmp
  • %WINDIR%\prefetch\agcx_sc4.db
  • %WINDIR%\Prefetch\AgAppLaunch.db
  • %WINDIR%\Prefetch\ADDINUTIL.EXE-FEF23417.pf
  • %WINDIR%\Prefetch\ACRORD32.EXE-ACF2947D.pf
  • %WINDIR%\Prefetch\1.EXE-BF9D2CEF.pf
  • %WINDIR%\temp\ts_8e67.tmp
  • %WINDIR%\temp\ts_77d1.tmp
  • %WINDIR%\temp\ts_5080.tmp
  • %WINDIR%\Prefetch\LOGONUI.EXE-09140401.pf
  • %WINDIR%\Prefetch\MSCONFIG.EXE-3A52734E.pf
  • %WINDIR%\temp\ts_3852.tmp
  • %WINDIR%\temp\ts_361e.tmp
  • %WINDIR%\temp\ts_316a.tmp
  • %WINDIR%\temp\ts_2bfb.tmp
  • %WINDIR%\temp\ts_2b0f.tmp
  • %WINDIR%\temp\ts_267a.tmp
  • %WINDIR%\Temp\FXSTIFFDebugLogFile.txt
  • %WINDIR%\Temp\FXSAPIDebugLogFile.txt
  • %WINDIR%\Temp\fwtsqmfile00.sqm
  • %WINDIR%\temp\ts_4f66.tmp
  • %WINDIR%\Prefetch\MSCORSVW.EXE-57D17DAF.pf
  • %WINDIR%\Prefetch\MSCORSVW.EXE-C3C515BD.pf
  • %WINDIR%\Prefetch\MSDTC.EXE-CC1DEC77.pf
  • %WINDIR%\Prefetch\TEST_MSVCP140D.EXE-606AF971.pf
  • %WINDIR%\Prefetch\TEST_MSVCP140.EXE-6A49BAE5.pf
  • %WINDIR%\Prefetch\TEST_MSVCP120XP.EXE-D7D05439.pf
  • %WINDIR%\Prefetch\TEST_MSVCP120D_X64.EXE-B16C3BB4.pf
  • %WINDIR%\Prefetch\TEST_MSVCP120D.EXE-ED7DFBED.pf
  • %WINDIR%\Prefetch\TEST_MSVCP120D.EXE-5E6BDB07.pf
  • %WINDIR%\Prefetch\TEST_MSVCP120.EXE-9F64D86B.pf
  • %WINDIR%\Prefetch\TEST_MSVCP120.EXE-5E9C35C1.pf
  • %WINDIR%\Prefetch\TEST_MSVCP110_X64.EXE-600927FB.pf
  • %WINDIR%\Prefetch\TEST_MSVCP110D_X64.EXE-6AFAA41F.pf
  • %WINDIR%\Prefetch\TEST_MSVCP110D.EXE-DD6C4BD2.pf
  • %WINDIR%\Prefetch\TEST_MSVCP110D.EXE-6C7E6CB8.pf
  • %WINDIR%\Prefetch\TEST_MSVCP110.EXE-F929C484.pf
  • %WINDIR%\Prefetch\TEST_MSVCP110.EXE-39F2672E.pf
  • %WINDIR%\Prefetch\TEST_MSVCP100_X64.EXE-6E02575E.pf
  • %WINDIR%\Prefetch\TEST_MSVCP100D_X64.EXE-24890C8A.pf
  • %WINDIR%\Prefetch\TEST_MSVCP100.EXE-D47FF5F1.pf
  • %WINDIR%\Prefetch\TEST_MSVCP100.EXE-93B75347.pf
  • %WINDIR%\Prefetch\TASKHOST.EXE-7238F31D.pf
  • %WINDIR%\Prefetch\TEST_MSVCP140D_X64.EXE-3E4F6ADE.pf
  • %WINDIR%\Prefetch\TEST_MSVCP140D_XP.EXE-B04BC36C.pf
  • %WINDIR%\Prefetch\TEST_MSVCP140XP.EXE-6D280B1D.pf
  • %WINDIR%\Prefetch\TEST_MSVCP140_X64.EXE-361D99D2.pf
  • %WINDIR%\softwaredistribution\datastore\logs\edb.log
  • %WINDIR%\softwaredistribution\datastore\logs\edb.chk
  • %WINDIR%\Prefetch\_IU14D2N.TMP-74616CED.pf
  • %WINDIR%\Prefetch\WMPNSCFG.EXE-FC0D39BF.pf
  • %WINDIR%\Prefetch\WMPLAYER.EXE-26C72A86.pf
  • %WINDIR%\Prefetch\WMIPRVSE.EXE-6768A320.pf
  • %WINDIR%\Prefetch\WMIPRVSE.EXE-1628051C.pf
  • %WINDIR%\Prefetch\WMIADAP.EXE-F8DFDFA2.pf
  • %WINDIR%\Prefetch\WINWORD.EXE-778F7C2B.pf
  • %WINDIR%\Prefetch\WEVTUTIL.EXE-400D93E8.pf
  • %WINDIR%\Prefetch\WEVTUTIL.EXE-EF5861C4.pf
  • %WINDIR%\Prefetch\WERMGR.EXE-0F2AC88C.pf
  • %WINDIR%\Prefetch\WERFAULT.EXE-E69F695A.pf
  • %WINDIR%\Prefetch\VSSVC.EXE-B8AFC319.pf
  • %WINDIR%\Prefetch\VS7JIT.EXE-AEF49C84.pf
  • %WINDIR%\Prefetch\UNINS000.EXE-53663602.pf
  • %WINDIR%\Prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf
  • %WINDIR%\prefetch\TRIGGERKMS.EXE-7E8EDFDC.pf
  • %WINDIR%\Prefetch\TEST_MSVCP90_X64.EXE-CF1ECFBE.pf
  • %WINDIR%\Prefetch\TEST_MSVCP90.EXE-29C5DA51.pf
  • %WINDIR%\inf\wpdmtp.inf
  • %WINDIR%\Prefetch\REGEDIT.EXE-90FEEA06.pf
  • %WINDIR%\Prefetch\SYSTEMPROPERTIESADVANCED.EXE-68C7C4F0.pf
  • %WINDIR%\Prefetch\SVCHOST.EXE-80F4A784.pf
  • %WINDIR%\Prefetch\OPERA_CRASHREPORTER.EXE-E30EBED0.pf
  • %WINDIR%\Prefetch\OPERA.EXE-9DD4E019.pf
  • %WINDIR%\Prefetch\NTOSBOOT-B00DFAAD.pf
  • %WINDIR%\Prefetch\NGEN.EXE-EC3F9239.pf
  • %WINDIR%\Prefetch\NGEN.EXE-AE594A6B.pf
  • %WINDIR%\Prefetch\NGEN.EXE-7900743E.pf
  • %WINDIR%\Prefetch\NETSH.EXE-F1B6DA12.pf
  • %WINDIR%\Prefetch\MSTSC.EXE-76A46E8A.pf
  • %WINDIR%\Prefetch\MSTSC.EXE-5283258E.pf
  • %WINDIR%\Prefetch\MSOXMLED.EXE-E473A01D.pf
  • %WINDIR%\Prefetch\MSOHTMED.EXE-68E5AB1E.pf
  • %WINDIR%\Prefetch\MSOHTMED.EXE-35A8CA79.pf
  • %WINDIR%\Prefetch\MSIF1A9.TMP-FA1CA0E9.pf
  • %WINDIR%\Prefetch\MSIEXEC.EXE-E09A077A.pf
  • %WINDIR%\Prefetch\MSIEXEC.EXE-A2D55CB6.pf
  • %WINDIR%\Prefetch\MSIEB32.TMP-A0D60608.pf
  • %WINDIR%\Prefetch\MSIDF38.TMP-4231CF8D.pf
  • %WINDIR%\Prefetch\MSI6837.TMP-63DEBE2C.pf
  • %WINDIR%\Prefetch\MSI419F.TMP-B24CC418.pf
  • %WINDIR%\Prefetch\OSE.EXE-51C16F0E.pf
  • %WINDIR%\Prefetch\OSE.EXE-533D8AC9.pf
  • %WINDIR%\Prefetch\OSE00001.EXE-3DA4B844.pf
  • %WINDIR%\Prefetch\OSPPSVC.EXE-E53D3CC0.pf
  • %WINDIR%\Prefetch\STEAMWEBHELPER.EXE-93613764.pf
  • %WINDIR%\Prefetch\SPPSVC.EXE-B0F8131B.pf
  • %WINDIR%\Prefetch\SETUP_WM.EXE-D33FD27D.pf
  • %WINDIR%\Prefetch\SETUP.EXE-F034C93C.pf
  • %WINDIR%\Prefetch\SETUP.EXE-D0F6149E.pf
  • %WINDIR%\Prefetch\SETUP.EXE-7C026C7F.pf
  • %WINDIR%\Prefetch\SCHTASKS.EXE-5CA45734.pf
  • %WINDIR%\Prefetch\SC.EXE-945D79AE.pf
  • %WINDIR%\Prefetch\REGTLIB.EXE-E21980A2.pf
  • %WINDIR%\inf\sisraid2.inf
  • %WINDIR%\Prefetch\REGSVCS.EXE-A54AD617.pf
  • %WINDIR%\Prefetch\ReadyBoot\Trace9.fx
  • %WINDIR%\Prefetch\ReadyBoot\Trace8.fx
  • %WINDIR%\Prefetch\ReadyBoot\Trace7.fx
  • %WINDIR%\Prefetch\ReadyBoot\Trace6.fx
  • %WINDIR%\Prefetch\ReadyBoot\Trace10.fx
  • %WINDIR%\Prefetch\RDRCEF.EXE-5852A8DE.pf
  • %WINDIR%\Prefetch\POWERPNT.EXE-158B76A4.pf
  • %WINDIR%\Prefetch\PfSvPerfStats.bin
  • %WINDIR%\Prefetch\PCAUI.EXE-3E82C312.pf
  • %WINDIR%\Prefetch\SVCHOST.EXE-7AC6742A.pf
  • %WINDIR%\inf\netbxnda.inf
  • %WINDIR%\inf\wpdfs.pnf
  • %WINDIR%\inf\wialx004.inf
  • %WINDIR%\inf\usbport.pnf
  • %WINDIR%\inf\usbport.inf
  • %WINDIR%\inf\usbcir.pnf
  • %WINDIR%\inf\usbcir.inf
  • %WINDIR%\inf\usb.pnf
  • %WINDIR%\inf\usb.inf
  • %WINDIR%\inf\unknown.pnf
  • %WINDIR%\inf\unknown.inf
  • %WINDIR%\inf\umpass.pnf
  • %WINDIR%\inf\umpass.inf
  • %WINDIR%\inf\umbus.pnf
  • %WINDIR%\inf\umbus.inf
  • %WINDIR%\inf\ts_wpdmtp.PNF
  • %WINDIR%\inf\ts_wpdmtp.inf
  • %WINDIR%\inf\ts_generic.PNF
  • %WINDIR%\inf\ts_generic.inf
  • %WINDIR%\inf\TsUsbHubFilter.PNF
  • %WINDIR%\inf\tsusbhubfilter.inf
  • %WINDIR%\inf\tsusbhub.inf
  • %WINDIR%\inf\tsprint.inf
  • %WINDIR%\inf\tsprint.pnf
  • %WINDIR%\inf\usbprint.inf
  • %WINDIR%\inf\usbprint.pnf
  • %WINDIR%\inf\wd.pnf
  • %WINDIR%\inf\wd.inf
  • %WINDIR%\inf\wceisvista.PNF
  • %WINDIR%\inf\wceisvista.inf
  • %WINDIR%\inf\wave.pnf
  • %WINDIR%\inf\wave.inf
  • %WINDIR%\inf\v_mscdsc.pnf
  • %WINDIR%\inf\v_mscdsc.inf
  • %WINDIR%\inf\vsmraid.pnf
  • %WINDIR%\inf\volume.pnf
  • %WINDIR%\inf\sti.inf
  • %WINDIR%\inf\volume.inf
  • %WINDIR%\inf\volsnap.pnf
  • %WINDIR%\inf\volsnap.inf
  • %WINDIR%\inf\vhdmp.pnf
  • %WINDIR%\inf\vhdmp.inf
  • %WINDIR%\inf\usbvideo.pnf
  • %WINDIR%\inf\usbvideo.inf
  • %WINDIR%\inf\usbstor.pnf
  • %WINDIR%\inf\usbstor.inf
  • %WINDIR%\inf\tsgenericusbdriver.inf
  • %WINDIR%\inf\transfercable.PNF
  • %WINDIR%\inf\transfercable.inf
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0011\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0010\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\000E\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\000D\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\000B\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\000A\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0009\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0008\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0007\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0006\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0005\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0001\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 3.0.0.0\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 3.0.0.0\_SMSvcHostPerfCounters.h
  • %WINDIR%\inf\smartcrd.pnf
  • %WINDIR%\inf\smartcrd.inf
  • %WINDIR%\inf\sisraid4.pnf
  • %WINDIR%\inf\sisraid4.inf
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0013\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0014\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0012\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0015\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\tpm.pnf
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0019\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\tpm.inf
  • %WINDIR%\inf\termmou.inf
  • %WINDIR%\inf\termkbd.inf
  • %WINDIR%\inf\tdibth.pnf
  • %WINDIR%\inf\tdibth.inf
  • %WINDIR%\inf\tape.pnf
  • %WINDIR%\inf\tape.inf
  • %WINDIR%\inf\synth3dvsc.inf
  • %WINDIR%\inf\vsmraid.inf
  • %WINDIR%\inf\wdmaudio.inf
  • %WINDIR%\inf\stexstor.pnf
  • %WINDIR%\inf\stexstor.inf
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\_SMSvcHostPerfCounters.h
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0816\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0804\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0416\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\0404\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\001F\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\SMSvcHost 4.0.0.0\001D\_SMSvcHostPerfCounters.ini
  • %WINDIR%\inf\sti.pnf
  • %WINDIR%\inf\wdmaudio.pnf
  • %WINDIR%\inf\wdma_usb.inf
  • %WINDIR%\inf\wdma_usb.pnf
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\000B\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\000A\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0009\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0008\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0007\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0006\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0005\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0001\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 3.0.0.0\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 3.0.0.0\PerfCounters.h
  • %WINDIR%\inf\wiaxx002.pnf
  • %WINDIR%\inf\wiaxx002.inf
  • %WINDIR%\inf\wiasa002.pnf
  • %WINDIR%\inf\wiasa002.inf
  • %WINDIR%\inf\wialx006.pnf
  • %WINDIR%\inf\wialx006.inf
  • %WINDIR%\inf\wialx005.pnf
  • %WINDIR%\inf\wialx005.inf
  • %WINDIR%\inf\wialx004.pnf
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\000C\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\000D\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\000E\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0010\PerfCounters.ini
  • %WINDIR%\inf\wpdcomp.inf
  • %WINDIR%\inf\wnetvsc.inf
  • %WINDIR%\inf\wmiaprpl\wmiaprpl.h
  • %WINDIR%\inf\wmiaprpl\0009\wmiaprpl.ini
  • %WINDIR%\inf\winusb.pnf
  • %WINDIR%\inf\winusb.inf
  • %WINDIR%\inf\windowssideshowenhanceddriver.PNF
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\PerfCounters.h
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0816\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0416\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0804\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0404\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\001F\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\001D\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0019\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0015\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0014\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0013\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0012\PerfCounters.ini
  • %WINDIR%\inf\Windows Workflow Foundation 4.0.0.0\0011\PerfCounters.ini
  • %WINDIR%\inf\wpdfs.inf
  • %WINDIR%\inf\sffdisk.pnf
  • %WINDIR%\inf\wialx003.pnf
  • %WINDIR%\inf\wialx003.inf
  • %WINDIR%\inf\wiaca00a.inf
  • %WINDIR%\inf\wiabr00a.pnf
  • %WINDIR%\inf\wiabr00a.inf
  • %WINDIR%\inf\wiabr009.pnf
  • %WINDIR%\inf\wiabr009.inf
  • %WINDIR%\inf\wiabr008.pnf
  • %WINDIR%\inf\wiabr008.inf
  • %WINDIR%\inf\wiabr007.pnf
  • %WINDIR%\inf\wiabr007.inf
  • %WINDIR%\inf\wiabr006.pnf
  • %WINDIR%\inf\wiabr006.inf
  • %WINDIR%\inf\wiabr005.pnf
  • %WINDIR%\inf\wiabr005.inf
  • %WINDIR%\inf\wiabr004.pnf
  • %WINDIR%\inf\wiabr004.inf
  • %WINDIR%\inf\wiabr002.pnf
  • %WINDIR%\inf\wiabr002.inf
  • %WINDIR%\inf\wfplwf.pnf
  • %WINDIR%\inf\wdmvsc.inf
  • %WINDIR%\inf\wiaca00a.pnf
  • %WINDIR%\inf\wiaca00b.inf
  • %WINDIR%\inf\wiaca00b.pnf
  • %WINDIR%\inf\wiaca00c.inf
  • %WINDIR%\inf\wialx002.inf
  • %WINDIR%\inf\wiaky002.pnf
  • %WINDIR%\inf\wiaky002.inf
  • %WINDIR%\inf\wiahp001.pnf
  • %WINDIR%\inf\wiahp001.inf
  • %WINDIR%\inf\wiaep003.pnf
  • %WINDIR%\inf\wiaep003.inf
  • %WINDIR%\inf\wiaep002.pnf
  • %WINDIR%\inf\wiaep002.inf
  • %WINDIR%\inf\wpdcomp.pnf
  • %WINDIR%\inf\wiacn001.pnf
  • %WINDIR%\inf\wiaca00i.pnf
  • %WINDIR%\inf\wiaca00i.inf
  • %WINDIR%\inf\wiaca00f.pnf
  • %WINDIR%\inf\wiaca00f.inf
  • %WINDIR%\inf\wiaca00e.pnf
  • %WINDIR%\inf\wiaca00e.inf
  • %WINDIR%\inf\wiaca00d.pnf
  • %WINDIR%\inf\wiaca00d.inf
  • %WINDIR%\inf\wiaca00c.pnf
  • %WINDIR%\inf\wialx002.pnf
  • %WINDIR%\Prefetch\TASKENG.EXE-48D4E289.pf
  • %WINDIR%\inf\netbvbda.pnf
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0019\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\ehstorpwddrv.PNF
  • %WINDIR%\inf\ehstorpwddrv.inf
  • %WINDIR%\inf\ehstorcertdrv.PNF
  • %WINDIR%\inf\ehstorcertdrv.inf
  • %WINDIR%\inf\eaphost.pnf
  • %WINDIR%\inf\eaphost.inf
  • %WINDIR%\inf\dot4prt.pnf
  • %WINDIR%\inf\dot4prt.inf
  • %WINDIR%\inf\dot4.pnf
  • %WINDIR%\inf\dot4.inf
  • %WINDIR%\inf\divacx64.pnf
  • %WINDIR%\inf\divacx64.inf
  • %WINDIR%\inf\display.pnf
  • %WINDIR%\inf\display.inf
  • %WINDIR%\inf\disk.pnf
  • %WINDIR%\inf\disk.inf
  • %WINDIR%\inf\digitalmediadevice.PNF
  • %WINDIR%\inf\digitalmediadevice.inf
  • %WINDIR%\inf\dc21x4vm.pnf
  • %WINDIR%\inf\cxraptor_philipstuv1236d_ibv64.PNF
  • %WINDIR%\inf\dc21x4vm.inf
  • %WINDIR%\inf\elxstor.inf
  • %WINDIR%\inf\elxstor.pnf
  • %WINDIR%\inf\hcw85c64.pnf
  • %WINDIR%\inf\hcw85c64.inf
  • %WINDIR%\inf\hcw85b64.pnf
  • %WINDIR%\inf\hcw85b64.inf
  • %WINDIR%\inf\hcw72b64.pnf
  • %WINDIR%\inf\hcw72b64.inf
  • %WINDIR%\inf\hal.pnf
  • %WINDIR%\inf\hal.inf
  • %WINDIR%\inf\gameport.pnf
  • %WINDIR%\inf\flpydisk.pnf
  • %WINDIR%\inf\compositebus.PNF
  • %WINDIR%\inf\flpydisk.inf
  • %WINDIR%\inf\fdc.pnf
  • %WINDIR%\inf\fdc.inf
  • %WINDIR%\inf\faxcn002.pnf
  • %WINDIR%\inf\faxcn002.inf
  • %WINDIR%\inf\faxcn001.pnf
  • %WINDIR%\inf\faxcn001.inf
  • %WINDIR%\inf\faxca003.pnf
  • %WINDIR%\inf\faxca003.inf
  • %WINDIR%\inf\cxraptor_philipstuv1236d_ibv64.inf
  • %WINDIR%\inf\cxraptor_fm1236mk5_ibv64.PNF
  • %WINDIR%\inf\cxraptor_fm1236mk5_ibv64.inf
  • %WINDIR%\inf\bth.inf
  • %WINDIR%\inf\brmfport.pnf
  • %WINDIR%\inf\brmfport.inf
  • %WINDIR%\inf\brmfcwia.pnf
  • %WINDIR%\inf\brmfcwia.inf
  • %WINDIR%\inf\brmfcumd.pnf
  • %WINDIR%\inf\brmfcumd.inf
  • %WINDIR%\inf\brmfcsto.pnf
  • %WINDIR%\inf\brmfcsto.inf
  • %WINDIR%\inf\brmfcmf.pnf
  • %WINDIR%\inf\brmfcmf.inf
  • %WINDIR%\inf\brmfcmdm.pnf
  • %WINDIR%\inf\brmfcmdm.inf
  • %WINDIR%\inf\blbdrive.pnf
  • %WINDIR%\inf\blbdrive.inf
  • %WINDIR%\inf\bda.pnf
  • %WINDIR%\inf\bda.inf
  • %WINDIR%\inf\battery.pnf
  • %WINDIR%\inf\bthmtpenum.inf
  • %WINDIR%\inf\bthmtpenum.PNF
  • %WINDIR%\inf\bth.pnf
  • %WINDIR%\inf\bthpan.inf
  • %WINDIR%\inf\cxraptor_fm1216mk5_ibv64.PNF
  • %WINDIR%\inf\bthpan.pnf
  • %WINDIR%\inf\cxraptor_fm1216mk5_ibv64.inf
  • %WINDIR%\inf\cxfalpal_ibv64.PNF
  • %WINDIR%\inf\cxfalpal_ibv64.inf
  • %WINDIR%\inf\cxfalcon_ibv64.PNF
  • %WINDIR%\inf\cxfalcon_ibv64.inf
  • %WINDIR%\inf\crcdisk.pnf
  • %WINDIR%\inf\crcdisk.inf
  • %WINDIR%\inf\cpu.pnf
  • %WINDIR%\inf\gameport.inf
  • %WINDIR%\inf\hdaudbus.inf
  • %WINDIR%\inf\compositebus.inf
  • %WINDIR%\inf\circlass.pnf
  • %WINDIR%\inf\circlass.inf
  • %WINDIR%\inf\cdrom.pnf
  • %WINDIR%\inf\cdrom.inf
  • %WINDIR%\inf\bthspp.pnf
  • %WINDIR%\inf\bthspp.inf
  • %WINDIR%\inf\bthprint.pnf
  • %WINDIR%\inf\bthprint.inf
  • %WINDIR%\inf\cpu.inf
  • %WINDIR%\inf\hdaudbus.pnf
  • %WINDIR%\inf\hdaudio.inf
  • %WINDIR%\inf\hdaudio.pnf
  • %WINDIR%\inf\mdm5674a.inf
  • %WINDIR%\inf\mdm3com.pnf
  • %WINDIR%\inf\mdm3com.inf
  • %WINDIR%\inf\mcx2.pnf
  • %WINDIR%\inf\mcx2.inf
  • %WINDIR%\inf\mchgr.pnf
  • %WINDIR%\inf\mchgr.inf
  • %WINDIR%\inf\machine.pnf
  • %WINDIR%\inf\machine.inf
  • %WINDIR%\inf\lsi_scsi.pnf
  • %WINDIR%\inf\lsi_scsi.inf
  • %WINDIR%\inf\lsi_sas2.pnf
  • %WINDIR%\inf\lsi_sas2.inf
  • %WINDIR%\inf\lsi_sas.pnf
  • %WINDIR%\inf\lsi_sas.inf
  • %WINDIR%\inf\lsi_fc.pnf
  • %WINDIR%\inf\lsi_fc.inf
  • %WINDIR%\inf\lltdio.pnf
  • %WINDIR%\inf\ksfilter.pnf
  • %WINDIR%\inf\mdm5674a.pnf
  • %WINDIR%\inf\mdmadc.inf
  • %WINDIR%\inf\mdmadc.pnf
  • %WINDIR%\inf\mdmagm64.inf
  • %WINDIR%\inf\mdmarn.inf
  • %WINDIR%\inf\mdmarch.pnf
  • %WINDIR%\inf\mdmarch.inf
  • %WINDIR%\inf\mdmar1.pnf
  • %WINDIR%\inf\mdmar1.inf
  • %WINDIR%\inf\mdmaiwat.pnf
  • %WINDIR%\inf\mdmaiwat.inf
  • %WINDIR%\inf\mdmaiwa5.pnf
  • %WINDIR%\inf\mdmaiwa5.inf
  • %WINDIR%\inf\mdmaiwa4.inf
  • %WINDIR%\inf\mdmaiwa4.pnf
  • %WINDIR%\inf\mdmaiwa3.pnf
  • %WINDIR%\inf\mdmaiwa3.inf
  • %WINDIR%\inf\mdmaiwa.pnf
  • %WINDIR%\inf\mdmaiwa.inf
  • %WINDIR%\inf\mdmairte.pnf
  • %WINDIR%\inf\mdmairte.inf
  • %WINDIR%\inf\mdmags64.pnf
  • %WINDIR%\inf\mdmags64.inf
  • %WINDIR%\inf\mdmagm64.pnf
  • %WINDIR%\inf\battery.inf
  • %WINDIR%\inf\image.inf
  • %WINDIR%\inf\kscaptur.pnf
  • %WINDIR%\inf\kscaptur.inf
  • %WINDIR%\inf\hpoa1ss.inf
  • %WINDIR%\inf\hpoa1so.pnf
  • %WINDIR%\inf\hpoa1so.inf
  • %WINDIR%\inf\hpoa1sd.pnf
  • %WINDIR%\inf\hpoa1sd.inf
  • %WINDIR%\inf\hpoa1nd.pnf
  • %WINDIR%\inf\hpoa1nd.inf
  • %WINDIR%\inf\hidserv.pnf
  • %WINDIR%\inf\hidserv.inf
  • %WINDIR%\inf\hidirkbd.pnf
  • %WINDIR%\inf\hidirkbd.inf
  • %WINDIR%\inf\hidir.pnf
  • %WINDIR%\inf\hidir.inf
  • %WINDIR%\inf\hiddigi.pnf
  • %WINDIR%\inf\hiddigi.inf
  • %WINDIR%\inf\hidbth.pnf
  • %WINDIR%\inf\hidbth.inf
  • %WINDIR%\inf\hdaudss.pnf
  • %WINDIR%\inf\hdaudss.inf
  • %WINDIR%\inf\hpoa1ss.pnf
  • %WINDIR%\inf\hpsamd.inf
  • %WINDIR%\inf\hpsamd.pnf
  • %WINDIR%\inf\iastorv.inf
  • %WINDIR%\inf\ks.inf
  • %WINDIR%\inf\keyboard.pnf
  • %WINDIR%\inf\keyboard.inf
  • %WINDIR%\inf\iscsi.pnf
  • %WINDIR%\inf\iscsi.inf
  • %WINDIR%\inf\ipmidrv.pnf
  • %WINDIR%\inf\ipmidrv.inf
  • %WINDIR%\inf\input.pnf
  • %WINDIR%\inf\input.inf
  • %WINDIR%\inf\mdmarn.pnf
  • %WINDIR%\inf\image.pnf
  • %WINDIR%\inf\iirsp2.pnf
  • %WINDIR%\inf\iirsp2.inf
  • %WINDIR%\inf\iirsp.pnf
  • %WINDIR%\inf\iirsp.inf
  • %WINDIR%\inf\igdlh.pnf
  • %WINDIR%\inf\igdlh.inf
  • %WINDIR%\inf\iem\0409\inetset.iem
  • %WINDIR%\inf\iem\0409\inetcorp.iem
  • %WINDIR%\inf\iastorv.pnf
  • %WINDIR%\inf\ks.pnf
  • %WINDIR%\inf\ksfilter.inf
  • %WINDIR%\inf\avmx64c.pnf
  • %WINDIR%\inf\ASP.NET_4.0.30319\0804\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET\0005\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0001\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0000\aspnet_perf2.ini
  • %WINDIR%\inf\arcsas.pnf
  • %WINDIR%\inf\arcsas.inf
  • %WINDIR%\inf\arc.pnf
  • %WINDIR%\inf\arc.inf
  • %WINDIR%\inf\angelu64.pnf
  • %WINDIR%\inf\angelu64.inf
  • %WINDIR%\inf\angel64.pnf
  • %WINDIR%\inf\angel64.inf
  • %WINDIR%\inf\angel264.pnf
  • %WINDIR%\inf\angel264.inf
  • %WINDIR%\inf\amdsbs.pnf
  • %WINDIR%\inf\amdsbs.inf
  • %WINDIR%\inf\amdsata.pnf
  • %WINDIR%\inf\amdsata.inf
  • %WINDIR%\inf\agp.pnf
  • %WINDIR%\inf\agp.inf
  • %WINDIR%\inf\af9035bda.inf
  • %WINDIR%\inf\af9035bda.PNF
  • %WINDIR%\inf\ASP.NET\0006\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0007\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0816\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0804\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0416\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0404\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\001F\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\001D\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0019\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0015\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0014\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0012\aspnet_perf2.ini
  • %WINDIR%\inf\1394.inf
  • %WINDIR%\inf\ASP.NET\0011\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0010\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\000E\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\000D\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\000C\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\000B\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\000A\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0009\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\0008\aspnet_perf2.ini
  • %WINDIR%\inf\adpu320.pnf
  • %WINDIR%\inf\adpu320.inf
  • %WINDIR%\inf\adpahci.pnf
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0011\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0010\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\000E\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\000D\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\000C\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\000B\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\000A\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0009\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0008\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0007\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0006\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0005\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0001\_Networkingperfcounters.ini
  • %WINDIR%\Logs\HomeGroup\homegrouplog.etl
  • %WINDIR%\logs\dpx\setuperr.log
  • %WINDIR%\logs\dpx\setupact.log
  • %WINDIR%\logs\directx.log
  • %WINDIR%\logs\cbs\cbs.log
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0013\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0014\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0012\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0015\_Networkingperfcounters.ini
  • %WINDIR%\inf\adpahci.inf
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0019\_Networkingperfcounters.ini
  • %WINDIR%\inf\adp94xx.pnf
  • %WINDIR%\inf\adp94xx.inf
  • %WINDIR%\inf\acpipmi.pnf
  • %WINDIR%\inf\acpipmi.inf
  • %WINDIR%\inf\acpi.pnf
  • %WINDIR%\inf\acpi.inf
  • %WINDIR%\inf\61883.pnf
  • %WINDIR%\inf\61883.inf
  • %WINDIR%\inf\ASP.NET\0013\aspnet_perf2.ini
  • %WINDIR%\inf\ASP.NET\aspnet_perf.h
  • %WINDIR%\inf\.NET Memory Cache 4.0\netmemorycache.h
  • %WINDIR%\inf\.NET Memory Cache 4.0\0009\netmemorycache.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\_NetworkingPerfCounters.h
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0816\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0804\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0416\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\0404\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\001F\_Networkingperfcounters.ini
  • %WINDIR%\inf\.NET CLR Networking 4.0.0.0\001D\_Networkingperfcounters.ini
  • %WINDIR%\inf\1394.pnf
  • %WINDIR%\inf\ASP.NET_1.1.4322\0000\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0001\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0005\aspnet_perf.ini
  • %WINDIR%\inf\aspnet_state\0014\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0013\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0012\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0011\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0010\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\000E\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\000D\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\000C\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\000B\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\000A\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0009\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0008\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0007\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0006\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0005\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0001\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0000\aspnet_state_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\aspnet_perf.h
  • %WINDIR%\inf\ASP.NET_4.0.30319\0816\aspnet_perf.ini
  • %WINDIR%\inf\aspnet_state\0015\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0019\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\001D\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\001F\aspnet_state_perf.ini
  • %WINDIR%\inf\averhbh826_noaverir_x64.inf
  • %WINDIR%\inf\averfx2swtv_x64.PNF
  • %WINDIR%\inf\averfx2swtv_x64.inf
  • %WINDIR%\inf\averfx2swtv_noavin_x64.PNF
  • %WINDIR%\inf\averfx2swtv_noavin_x64.inf
  • %WINDIR%\inf\averfx2hbtv_x64.PNF
  • %WINDIR%\inf\averfx2hbtv_x64.inf
  • %WINDIR%\inf\averfx2hbh826d_noaverir_x64.PNF
  • %WINDIR%\inf\averfx2hbh826d_noaverir_x64.inf
  • %WINDIR%\inf\avc.inf
  • %WINDIR%\inf\avc.pnf
  • %WINDIR%\inf\atiriol6.pnf
  • %WINDIR%\inf\atiriol6.inf
  • %WINDIR%\inf\atiilhag.pnf
  • %WINDIR%\inf\atiilhag.inf
  • %WINDIR%\inf\aspnet_state\aspnet_state_perf.h
  • %WINDIR%\inf\aspnet_state\0816\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0804\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0416\aspnet_state_perf.ini
  • %WINDIR%\inf\aspnet_state\0404\aspnet_state_perf.ini
  • %WINDIR%\inf\avmx64c.inf
  • %WINDIR%\inf\ASP.NET_4.0.30319\000C\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0416\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0404\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0404\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\001F\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\001D\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0019\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0015\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0014\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0013\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0012\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0011\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0010\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\000E\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\000D\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\000C\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\000B\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\000A\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0009\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0008\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0007\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0006\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0416\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0804\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\0816\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_1.1.4322\aspnet_perf.h
  • %WINDIR%\inf\ASP.NET_4.0.30319\001D\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0019\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0015\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0014\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0013\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0012\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0011\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0010\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\000E\aspnet_perf.ini
  • %WINDIR%\inf\averhbh826_noaverir_x64.PNF
  • %WINDIR%\inf\ASP.NET_4.0.30319\000D\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\000B\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\000A\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0009\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0008\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0007\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0006\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0005\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0001\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\0000\aspnet_perf.ini
  • %WINDIR%\inf\ASP.NET_4.0.30319\001F\aspnet_perf.ini
  • %WINDIR%\inf\mdmke.inf
  • %WINDIR%\inf\netbc664.pnf
  • %WINDIR%\inf\mdmatm2k.inf
  • %WINDIR%\inf\mdmtexas.inf
  • %WINDIR%\inf\mdmtdkj7.pnf
  • %WINDIR%\inf\mdmtdkj7.inf
  • %WINDIR%\inf\mdmtdkj6.pnf
  • %WINDIR%\inf\mdmtdkj6.inf
  • %WINDIR%\inf\mdmtdkj5.pnf
  • %WINDIR%\inf\mdmtdkj5.inf
  • %WINDIR%\inf\mdmtdkj4.pnf
  • %WINDIR%\inf\mdmtdkj4.inf
  • %WINDIR%\inf\mdmtdkj3.pnf
  • %WINDIR%\inf\mdmtdkj3.inf
  • %WINDIR%\inf\mdmtdkj2.pnf
  • %WINDIR%\inf\mdmtdkj2.inf
  • %WINDIR%\inf\mdmtdk.pnf
  • %WINDIR%\inf\mdmtdk.inf
  • %WINDIR%\inf\mdmsuprv.pnf
  • %WINDIR%\inf\mdmsuprv.inf
  • %WINDIR%\inf\mdmsupra.pnf
  • %WINDIR%\inf\mdmsupra.inf
  • %WINDIR%\inf\mdmsupr3.inf
  • %WINDIR%\inf\mdmsupr3.pnf
  • %WINDIR%\inf\mdmtexas.pnf
  • %WINDIR%\inf\mdmti.inf
  • %WINDIR%\inf\mdmwhql0.inf
  • %WINDIR%\inf\mdmvv.pnf
  • %WINDIR%\inf\mdmvv.inf
  • %WINDIR%\inf\mdmvdot.pnf
  • %WINDIR%\inf\mdmvdot.inf
  • %WINDIR%\inf\mdmusrsp.pnf
  • %WINDIR%\inf\mdmusrsp.inf
  • %WINDIR%\inf\mdmusrk1.pnf
  • %WINDIR%\inf\mdmusrk1.inf
  • %WINDIR%\inf\mdmusrgl.inf
  • %WINDIR%\inf\mdmrock5.inf
  • %WINDIR%\inf\mdmusrg.pnf
  • %WINDIR%\inf\mdmusrg.inf
  • %WINDIR%\inf\mdmusrf.pnf
  • %WINDIR%\inf\mdmusrf.inf
  • %WINDIR%\inf\mdmtron.pnf
  • %WINDIR%\inf\mdmtron.inf
  • %WINDIR%\inf\mdmtkr.pnf
  • %WINDIR%\inf\mdmtkr.inf
  • %WINDIR%\inf\mdmti.pnf
  • %WINDIR%\inf\mdmsun2.pnf
  • %WINDIR%\inf\mdmsun2.inf
  • %WINDIR%\inf\mdmsun1.pnf
  • %WINDIR%\inf\mdmpin.pnf
  • %WINDIR%\inf\mdmpin.inf
  • %WINDIR%\inf\mdmpenr.pnf
  • %WINDIR%\inf\mdmpenr.inf
  • %WINDIR%\inf\mdmpace.pnf
  • %WINDIR%\inf\mdmpace.inf
  • %WINDIR%\inf\mdmosi.pnf
  • %WINDIR%\inf\mdmosi.inf
  • %WINDIR%\inf\mdmoptn.pnf
  • %WINDIR%\inf\mdmoptn.inf
  • %WINDIR%\inf\mdmomrn3.pnf
  • %WINDIR%\inf\mdmomrn3.inf
  • %WINDIR%\inf\mdmolic.pnf
  • %WINDIR%\inf\mdmolic.inf
  • %WINDIR%\inf\mdmnttte.pnf
  • %WINDIR%\inf\mdmnttte.inf
  • %WINDIR%\inf\mdmnttp2.pnf
  • %WINDIR%\inf\mdmnttp2.inf
  • %WINDIR%\inf\mdmpn1.pnf
  • %WINDIR%\inf\mdmpp.inf
  • %WINDIR%\inf\mdmpn1.inf
  • %WINDIR%\inf\mdmpp.pnf
  • %WINDIR%\inf\mdmsun1.inf
  • %WINDIR%\inf\mdmpsion.inf
  • %WINDIR%\inf\mdmsonyu.pnf
  • %WINDIR%\inf\mdmsonyu.inf
  • %WINDIR%\inf\mdmsmart.pnf
  • %WINDIR%\inf\mdmsmart.inf
  • %WINDIR%\inf\mdmsii64.pnf
  • %WINDIR%\inf\mdmsii64.inf
  • %WINDIR%\inf\mdmsier.pnf
  • %WINDIR%\inf\mdmsier.inf
  • %WINDIR%\inf\mdmusrgl.pnf
  • %WINDIR%\inf\mdmwhql0.pnf
  • %WINDIR%\inf\mdmrock4.pnf
  • %WINDIR%\inf\mdmrock4.inf
  • %WINDIR%\inf\mdmrock3.pnf
  • %WINDIR%\inf\mdmrock3.inf
  • %WINDIR%\inf\mdmrock.pnf
  • %WINDIR%\inf\mdmrock.inf
  • %WINDIR%\inf\mdmracal.pnf
  • %WINDIR%\inf\mdmracal.inf
  • %WINDIR%\inf\mdmpsion.pnf
  • %WINDIR%\inf\mdmrock5.pnf
  • %WINDIR%\inf\mdmx5560.inf
  • %WINDIR%\inf\mdmx5560.pnf
  • %WINDIR%\inf\mdmzoom.inf
  • %WINDIR%\inf\mtconfig.pnf
  • %WINDIR%\inf\mtconfig.inf
  • %WINDIR%\inf\mstape.pnf
  • %WINDIR%\inf\mstape.inf
  • %WINDIR%\inf\msports.pnf
  • %WINDIR%\inf\msports.inf
  • %WINDIR%\inf\msmouse.pnf
  • %WINDIR%\inf\msmouse.inf
  • %WINDIR%\inf\mshdc.pnf
  • %WINDIR%\inf\mshdc.inf
  • %WINDIR%\inf\msdv.pnf
  • %WINDIR%\inf\msdv.inf
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\_TransactionBridgePerfCounters.h
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0816\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0804\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0416\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0404\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\001F\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\001D\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\multiprt.inf
  • %WINDIR%\inf\multiprt.pnf
  • %WINDIR%\inf\ndiscap.pnf
  • %WINDIR%\inf\ndisuio.pnf
  • %WINDIR%\inf\netbc664.inf
  • %WINDIR%\inf\netb57va.pnf
  • %WINDIR%\inf\netb57va.inf
  • %WINDIR%\inf\netavpnt.pnf
  • %WINDIR%\inf\netavpna.pnf
  • %WINDIR%\inf\netathrx.pnf
  • %WINDIR%\inf\netathrx.inf
  • %WINDIR%\inf\net8187se64.PNF
  • %WINDIR%\inf\net8187se64.inf
  • %WINDIR%\inf\net8185.pnf
  • %WINDIR%\inf\net8187bv64.inf
  • %WINDIR%\inf\net8185.inf
  • %WINDIR%\inf\net44amd.pnf
  • %WINDIR%\inf\net44amd.inf
  • %WINDIR%\inf\net1yx64.pnf
  • %WINDIR%\inf\net1yx64.inf
  • %WINDIR%\inf\net1qx64.pnf
  • %WINDIR%\inf\net1qx64.inf
  • %WINDIR%\inf\net1kx64.pnf
  • %WINDIR%\inf\net1kx64.inf
  • %WINDIR%\inf\mdmnttp.pnf
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0006\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0015\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0014\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\modemcsa.pnf
  • %WINDIR%\inf\modemcsa.inf
  • %WINDIR%\inf\mf.pnf
  • %WINDIR%\inf\mf.inf
  • %WINDIR%\inf\memory.pnf
  • %WINDIR%\inf\memory.inf
  • %WINDIR%\inf\megasr.pnf
  • %WINDIR%\inf\megasr.inf
  • %WINDIR%\inf\megasas2.pnf
  • %WINDIR%\inf\megasas2.inf
  • %WINDIR%\inf\megasas.pnf
  • %WINDIR%\inf\megasas.inf
  • %WINDIR%\inf\mdmzyxlg.pnf
  • %WINDIR%\inf\mdmzyxlg.inf
  • %WINDIR%\inf\mdmzyxel.pnf
  • %WINDIR%\inf\mdmzyxel.inf
  • %WINDIR%\inf\mdmzyp.pnf
  • %WINDIR%\inf\mdmzyp.inf
  • %WINDIR%\inf\mdmzoom.pnf
  • %WINDIR%\inf\monitor.inf
  • %WINDIR%\inf\monitor.pnf
  • %WINDIR%\inf\mpio.inf
  • %WINDIR%\inf\mpio.pnf
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0012\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0011\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0010\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\000E\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\000D\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\000C\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\000B\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0009\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0008\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\mdmati.pnf
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0007\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0005\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0001\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 3.0.0.0\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\MSDTC Bridge 3.0.0.0\_TransactionBridgePerfCounters.h
  • %WINDIR%\inf\msdsm.pnf
  • %WINDIR%\inf\msdsm.inf
  • %WINDIR%\inf\msdri.inf
  • %WINDIR%\inf\msclmd.pnf
  • %WINDIR%\inf\msclmd.inf
  • %WINDIR%\inf\MSDTC Bridge 4.0.0.0\0013\_TransactionBridgePerfCounters.ini
  • %WINDIR%\inf\netbvbda.inf
  • %WINDIR%\inf\mdmnttp.inf
  • %WINDIR%\inf\mdmmcom.inf
  • %WINDIR%\inf\mdmdyna.pnf
  • %WINDIR%\inf\mdmdyna.inf
  • %WINDIR%\inf\mdmdsi.pnf
  • %WINDIR%\inf\mdmdsi.inf
  • %WINDIR%\inf\mdmdp2.pnf
  • %WINDIR%\inf\mdmdp2.inf
  • %WINDIR%\inf\mdmdgitn.pnf
  • %WINDIR%\inf\mdmdgitn.inf
  • %WINDIR%\inf\mdmdf56f.pnf
  • %WINDIR%\inf\mdmdf56f.inf
  • %WINDIR%\inf\mdmdcm6.pnf
  • %WINDIR%\inf\mdmdcm6.inf
  • %WINDIR%\inf\mdmdcm5.pnf
  • %WINDIR%\inf\mdmdcm5.inf
  • %WINDIR%\inf\mdmcxpv6.pnf
  • %WINDIR%\inf\mdmcxpv6.inf
  • %WINDIR%\inf\mdmcxhv6.pnf
  • %WINDIR%\inf\mdmcxhv6.inf
  • %WINDIR%\inf\mdmcrtix.pnf
  • %WINDIR%\inf\mdmcpv.pnf
  • %WINDIR%\inf\mdmcrtix.inf
  • %WINDIR%\inf\mdmeiger.inf
  • %WINDIR%\inf\mdmeiger.pnf
  • %WINDIR%\inf\mdmgl002.pnf
  • %WINDIR%\inf\mdmgl002.inf
  • %WINDIR%\inf\mdmgl001.pnf
  • %WINDIR%\inf\mdmgl001.inf
  • %WINDIR%\inf\mdmgen.pnf
  • %WINDIR%\inf\mdmgen.inf
  • %WINDIR%\inf\mdmgcs.pnf
  • %WINDIR%\inf\mdmgcs.inf
  • %WINDIR%\inf\mdmgatew.pnf
  • %WINDIR%\inf\mdmfj2.pnf
  • %WINDIR%\inf\mdmcm28.pnf
  • %WINDIR%\inf\mdmfj2.inf
  • %WINDIR%\inf\mdmetech.pnf
  • %WINDIR%\inf\mdmetech.inf
  • %WINDIR%\inf\mdmeric2.pnf
  • %WINDIR%\inf\mdmeric2.inf
  • %WINDIR%\inf\mdmeric.pnf
  • %WINDIR%\inf\mdmeric.inf
  • %WINDIR%\inf\mdmelsa.pnf
  • %WINDIR%\inf\mdmelsa.inf
  • %WINDIR%\inf\mdmcpv.inf
  • %WINDIR%\inf\mdmcpq2.pnf
  • %WINDIR%\inf\mdmcpq2.inf
  • %WINDIR%\inf\mdmbr00a.inf
  • %WINDIR%\inf\mdmbr008.pnf
  • %WINDIR%\inf\mdmbr008.inf
  • %WINDIR%\inf\mdmbr007.pnf
  • %WINDIR%\inf\mdmbr007.inf
  • %WINDIR%\inf\mdmbr006.pnf
  • %WINDIR%\inf\mdmbr006.inf
  • %WINDIR%\inf\mdmbr005.pnf
  • %WINDIR%\inf\mdmbr005.inf
  • %WINDIR%\inf\mdmbr004.pnf
  • %WINDIR%\inf\mdmbr004.inf
  • %WINDIR%\inf\mdmbr002.pnf
  • %WINDIR%\inf\mdmbr002.inf
  • %WINDIR%\inf\mdmboca.pnf
  • %WINDIR%\inf\mdmboca.inf
  • %WINDIR%\inf\mdmaus.pnf
  • %WINDIR%\inf\mdmaus.inf
  • %WINDIR%\inf\mdmatm2k.pnf
  • %WINDIR%\inf\mdmbsb.inf
  • %WINDIR%\inf\mdmbsb.pnf
  • %WINDIR%\inf\mdmbr00a.pnf
  • %WINDIR%\inf\mdmbtmdm.inf
  • %WINDIR%\inf\mdmcpq.pnf
  • %WINDIR%\inf\mdmbtmdm.pnf
  • %WINDIR%\inf\mdmcpq.inf
  • %WINDIR%\inf\mdmcomp.pnf
  • %WINDIR%\inf\mdmcomp.inf
  • %WINDIR%\inf\mdmcommu.pnf
  • %WINDIR%\inf\mdmcommu.inf
  • %WINDIR%\inf\mdmcom1.pnf
  • %WINDIR%\inf\mdmcom1.inf
  • %WINDIR%\inf\mdmcodex.pnf
  • %WINDIR%\inf\mdmgatew.inf
  • %WINDIR%\inf\mdmgl003.inf
  • %WINDIR%\inf\mdmcm28.inf
  • %WINDIR%\inf\mdmcdp.pnf
  • %WINDIR%\inf\mdmcdp.inf
  • %WINDIR%\inf\mdmc26a.pnf
  • %WINDIR%\inf\mdmc26a.inf
  • %WINDIR%\inf\mdmbw561.pnf
  • %WINDIR%\inf\mdmbw561.inf
  • %WINDIR%\inf\mdmbug3.pnf
  • %WINDIR%\inf\mdmbug3.inf
  • %WINDIR%\inf\mdmcodex.inf
  • %WINDIR%\inf\mdmgl003.pnf
  • %WINDIR%\inf\mdmgl004.inf
  • %WINDIR%\inf\mdmgl004.pnf
  • %WINDIR%\inf\mdmmoto1.pnf
  • %WINDIR%\inf\mdmmoto1.inf
  • %WINDIR%\inf\mdmmot64.pnf
  • %WINDIR%\inf\mdmmot64.inf
  • %WINDIR%\inf\mdmmod.pnf
  • %WINDIR%\inf\mdmmod.inf
  • %WINDIR%\inf\mdmminij.pnf
  • %WINDIR%\inf\mdmminij.inf
  • %WINDIR%\inf\mdmmhzel.pnf
  • %WINDIR%\inf\mdmmhzel.inf
  • %WINDIR%\inf\mdmmhrtz.pnf
  • %WINDIR%\inf\mdmmhrtz.inf
  • %WINDIR%\inf\mdmmetri.pnf
  • %WINDIR%\inf\mdmmetri.inf
  • %WINDIR%\inf\mdmmega.pnf
  • %WINDIR%\inf\mdmmega.inf
  • %WINDIR%\inf\mdmmct.pnf
  • %WINDIR%\inf\mdmmct.inf
  • %WINDIR%\inf\mdmmcom.pnf
  • %WINDIR%\inf\mdmmotou.inf
  • %WINDIR%\inf\mdmmotou.pnf
  • %WINDIR%\inf\mdmmts.inf
  • %WINDIR%\inf\mdmmts.pnf
  • %WINDIR%\inf\mdmnttd6.pnf
  • %WINDIR%\inf\mdmnttd6.inf
  • %WINDIR%\inf\mdmnttd2.pnf
  • %WINDIR%\inf\mdmnttd2.inf
  • %WINDIR%\inf\mdmntt1.pnf
  • %WINDIR%\inf\mdmntt1.inf
  • %WINDIR%\inf\mdmnova.pnf
  • %WINDIR%\inf\mdmnova.inf
  • %WINDIR%\inf\mdmnokia.pnf
  • %WINDIR%\inf\mdmnis5t.pnf
  • %WINDIR%\inf\mdmnokia.inf
  • %WINDIR%\inf\mdmnis5t.inf
  • %WINDIR%\inf\mdmnis3t.pnf
  • %WINDIR%\inf\mdmnis3t.inf
  • %WINDIR%\inf\mdmnis2u.pnf
  • %WINDIR%\inf\mdmnis2u.inf
  • %WINDIR%\inf\mdmnis1u.pnf
  • %WINDIR%\inf\mdmnis1u.inf
  • %WINDIR%\inf\mdmneuhs.pnf
  • %WINDIR%\inf\mdmneuhs.inf
  • %WINDIR%\inf\mdmnttme.pnf
  • %WINDIR%\inf\mdmati.inf
  • %WINDIR%\inf\mdmmcd.pnf
  • %WINDIR%\inf\mdmmcd.inf
  • %WINDIR%\inf\mdmhay2.inf
  • %WINDIR%\inf\mdmhandy.pnf
  • %WINDIR%\inf\mdmhandy.inf
  • %WINDIR%\inf\mdmhaeu.pnf
  • %WINDIR%\inf\mdmhaeu.inf
  • %WINDIR%\inf\mdmgsm.pnf
  • %WINDIR%\inf\mdmgsm.inf
  • %WINDIR%\inf\mdmgl010.pnf
  • %WINDIR%\inf\mdmgl010.inf
  • %WINDIR%\inf\mdmgl009.pnf
  • %WINDIR%\inf\mdmgl009.inf
  • %WINDIR%\inf\mdmgl008.pnf
  • %WINDIR%\inf\mdmgl008.inf
  • %WINDIR%\inf\mdmgl007.pnf
  • %WINDIR%\inf\mdmgl007.inf
  • %WINDIR%\inf\mdmgl006.pnf
  • %WINDIR%\inf\mdmgl006.inf
  • %WINDIR%\inf\mdmgl005.pnf
  • %WINDIR%\inf\mdmgl005.inf
  • %WINDIR%\inf\mdmhay2.pnf
  • %WINDIR%\inf\mdmhayes.inf
  • %WINDIR%\inf\mdmhayes.pnf
  • %WINDIR%\inf\mdminfot.inf
  • %WINDIR%\inf\mdmmc288.inf
  • %WINDIR%\inf\mdmlucnt.pnf
  • %WINDIR%\inf\mdmlucnt.inf
  • %WINDIR%\inf\mdmlasno.pnf
  • %WINDIR%\inf\mdmlasno.inf
  • %WINDIR%\inf\mdmlasat.pnf
  • %WINDIR%\inf\mdmlasat.inf
  • %WINDIR%\inf\mdmkortx.pnf
  • %WINDIR%\inf\mdmkortx.inf
  • %WINDIR%\inf\mdmnttme.inf
  • %WINDIR%\inf\mdmke.pnf
  • %WINDIR%\inf\mdmjf56e.pnf
  • %WINDIR%\inf\mdmjf56e.inf
  • %WINDIR%\inf\mdmisdn.pnf
  • %WINDIR%\inf\mdmisdn.inf
  • %WINDIR%\inf\mdmirmdm.pnf
  • %WINDIR%\inf\mdmirmdm.inf
  • %WINDIR%\inf\mdmiodat.pnf
  • %WINDIR%\inf\mdmiodat.inf
  • %WINDIR%\inf\mdminfot.pnf
  • %WINDIR%\inf\mdmmc288.pnf
  • <SYSTEM32>\restore\machineguid.txt
Moves the following files
  • from volume{c84d25cd-f368-11e4-889d-806e6f6e6963}\system volume information\tracking.log.tmp to volume{c84d25cd-f368-11e4-889d-806e6f6e6963}\system volume information\tracking.log
  • from volume{600ba660-c712-11e6-a54f-080027cffa47}\system volume information\tracking.log.tmp to volume{600ba660-c712-11e6-a54f-080027cffa47}\system volume information\tracking.log
Miscellaneous
Searches for the following windows
  • ClassName: '' WindowName: ''
Executes the following
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat /f"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%ProgramFiles%\Epic Games\Fortnite\FortniteGame\Config"
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "1\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d 25077-31728-24105-1220830840 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "0\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d 25074-20980-6241-2091320525 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildLab /t REG_SZ /d 25074-20980-6241-2091320525 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d 25074-20980-6241-2091320525 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildBranch /t REG_SZ /d 25074-20980-6241-2091320525 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v UserModeDriverGUID /t REG_SZ /d {25074-20980-6241-2091320525} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\mouhid\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {25070-10231-21144-2961710211} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\kbdclass\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {25070-10231-21144-2961710211} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DESCRIPTION\System\BIOS /v BaseBoardProduct /t REG_SZ /d 25070-102312114429617 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\Software\Microsoft /v BuildLabEx /t REG_SZ /d 25070-10231 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\Software\Microsoft /v BuildLab /t REG_SZ /d 25070-10231 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\HardwareConfig\Current /v BaseBoardProduct /t REG_SZ /d 25070-102312114429617 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {25067-32251-%random} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /t REG_SZ /d 2506732251-3280-5554-32664 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d DESKTOP-25067 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d DESKTOP-25067 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%LOCALAPPDATA%\Microsoft\Feeds Cache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <SYSTEM32>\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %HOMEPATH%\Intel"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\Microsoft\Windows\History"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\Microsoft\Windows\INetCookies"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\Microsoft\Windows\INetCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %WINDIR%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q %ALLUSERSPROFILE%\Microsoft\DataMart\PaidWiFi\Rules"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q %ALLUSERSPROFILE%\Microsoft\DataMart\PaidWiFi\NetworksCache"
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0 /v Identifier /t REG_SZ /d 25077-31728-24105-1220830840 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %APPDATA%\EasyAntiCheat"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\BasicDisplay\Video /v VideoID /t REG_SZ /d {25077-31728-24105-1220830840} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\SQMClient /v MachineId /t REG_SZ /d {25077-31728-24105-1220830840} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d 2508420457 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareIds /t REG_SZ /d 25100-8663-18082-168114738 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d 25100-8663-18082-168114738 /f
  • '<SYSTEM32>\reg.exe' ADD HKCU\Software\Classes\Interface /v ClsidStore /t REG_BINARY /d 25100866318082168114738808626946108713106819858258387887 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global\CoProcManager /v ChipsetMatchID /t REG_SZ /d 25097-30683-218-2551627191 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v PersistenceIdentifier /t REG_SZ /d 25093-19934-15122-145316877 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v ClientUUID /t REG_SZ /d 25093-19934-15122-145316877 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /t REG_SZ /d 25093-19934-15122-145316877 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v PingID /t REG_SZ /d 25093-19934-15122-145316877 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v AccountDomainSid /t REG_SZ /d 25093-19934-15122-145316877 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Tracing\Microsoft\Profile\Profile /v Guid /t REG_SZ /d 25087-31206-12161-1886229016 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {2508731206-12161-18862-29016} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildLabEx /t REG_SZ /d 25087 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallTime /t REG_SZ /d 25084 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d 2508420457-27065-27567-18701 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %ALLUSERSPROFILE%\%username%\Microsoft\XboxLive\NSALCache"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d 2508420457-27065-27567-18701 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d 25084-20457-27065-27567 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v REGisteredOrganization /t REG_SZ /d 25084 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v REGisteredOwner /t REG_SZ /d 25080 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d 25080 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {250809709-9201-3503-838717293} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {250809709-9201-3503-838717293} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v NV" "Hostname /t REG_SZ /d DESKTOP-25080 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Control\DevQuery\6 /v UUID /t REG_SZ /d 25080 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v Domain /t REG_SZ /d 25077 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v Hostname /t REG_SZ /d DESKTOP-25077 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1 /v Identifier /t REG_SZ /d 25077-31728-24105-1220830840 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%LOCALAPPDATA%\NVIDIA Corporation"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%ProgramFiles%\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%ProgramFiles%\Epic Games\Fortnite\FortniteGame\Plugins"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWAREMicrosoft\Windows" "NT\CurrentVersion\Notifications\Data /v 418A073AA3BC3475 /t REG_BINARY /d 25051112771226316310138591472113027220121277013775280577227 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\SevilleEventlogManager /v LastEventlogWrittenTime /t REG_QWORD /d %random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_QWORD /d 250511127712263 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_QWORD /d %random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallTime /t REG_QWORD /d 2504852927167 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallTime /t REG_QWORD /d %random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\SQMClient /v WinSqmFirstSessionStartTime /t REG_QWORD /d 2504852927167 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\SQMClient /v WinSqmFirstSessionStartTime /t REG_QWORD /d %random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId4 /t REG_BINARY /d 25048529271672501435451079499152493929027 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId4 /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId /t REG_BINARY /d 25048529271672501435451079499152493929027 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Internet" "Explorer\Migration /v IE" "Installed" "Date /t REG_BINARY /d 25048529271672501435451079499152493929027 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Internet" "Explorer\Migration /v IE" "Installed" "Date /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKCU\SYSTEM\CurrentControlSet\Services\TPM\ODUID /v RandomSeed /t REG_BINARY /d 2504852927167250143545107949915249392902719923282057183 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKCU\SYSTEM\CurrentControlSet\Services\TPM\ODUID /v RandomSeed /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientIdValidation /t REG_BINARY /d 250442254893039512599868676802278661251526071283537139 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientIdValidation /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random%%rando...
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI /v WindowsAIKHash /t REG_BINARY /d 250442254893039512599868676802278661251526071 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI /v WindowsAIKHash /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKCU\Software\Classes\Installer\Dependencies /v MSICache /t REG_BINARY /d 25044225489303951259986867680227866125152607128353 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKCU\Software\Classes\Installer\Dependencies /v MSICache /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Notifications\Data\418A073AA3BC3475 /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Notifications\Data\418A073AA3BC3475 /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\System\CurrentControlSet\ControlvNotifications\418A073AA3BC8075 /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\System\CurrentControlSet\ControlvNotifications\418A073AA3BC8075 /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\SevilleEventlogManager /v LastEventlogWrittenTime /t REG_QWORD /d 250511127712263 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\System\CurrentControlSet\Control\Notifications /v 418A073AA3BC8075 /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%ran...
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings"
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-EventTracing/Admin /v OwningPublisher /t REG_SZ /d {%random%-%random%-%random%%random%} /f"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%ProgramFiles%\Epic Games\Fortnite\Engine\Plugins"
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Control\Notifications /v 418A073AA3BC8075 /t REG_BINARY /d 25051112771226316310138591472113027220121277013775280577227 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q %LOCALAPPDATA%\Microsoft\Windows\WebCache\*.*"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q %HOMEPATH%name%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %WINDIR%\Prefetch"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\AMD\DxCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %ALLUSERSPROFILE%\Microsoft\Windows\WER\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %WINDIR%\SoftwareDistribution\DataStore\Logs"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\Microsoft\Windows\SettingSync\metastore"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %WINDIR%\temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\CrashReportClient"
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 /f"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\D3DSCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q C:\Users\Public\Documents"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %WINDIR%\INF"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %LOCALAPPDATA%\FortniteGame\Saved"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %APPDATA%\Microsoft\Windows\CloudStore"
  • '<SYSTEM32>\reg.exe' delete HKCU\Software\Microsoft\Direct3D /v WHQLClass /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\Software\Microsoft\Direct3D /v WHQLClass /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Control\ProductOptions /v OSProductContentId /t REG_SZ /d {25054-22025-30128-7605} /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\System\CurrentControlSet\Control\ProductOptions /v OSProductContentId /t REG_SZ /d {%random%-%random%-%random%-%random%} /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Control\ProductOptions /v OSProductPfn /t REG_SZ /d Microsoft.Windows.25054.22025-30128_760524174 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\System\CurrentControlSet\Control\ProductOptions /v OSProductPfn /t REG_SZ /d Microsoft.Windows.%random%.%random%-%random%_%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Direct3D /v WHQLClass /t REG_BINARY /d 25051112771226316310138591472113027220121277013775280577227 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKCU\Software\Microsoft\Direct3D /v WHQLClass /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-EventTracing/Admin /v OwningPublisher /t REG_SZ /d {25051-11277-1226316310} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\SQMClient /v MachineId /t REG_SZ /d 25100-8663-18082-168114738 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWAREMicrosoft\Windows" "NT\CurrentVersion\Notifications\Data /v 418A073AA3BC3475 /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random%%r...
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v _DriverProviderInfo /t REG_SZ /d 25103-19412-3178-810715053 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\D3DSCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\FortniteGame\Saved"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "E:\Users\%username%\AppData\Local\Microsoft\Feeds Cache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\Intel"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\Microsoft\Windows\History"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q E:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q E:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Roaming\EasyAntiCheat"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "E:\Program Files\Epic Games\Fortnite\FortniteGame\Config"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "E:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "E:\Program Files\Epic Games\Fortnite\FortniteGame\Plugins"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "E:\Program Files\Epic Games\Fortnite\Engine\Plugins"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q E:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q E:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "E:\Users\%username%\AppData\Local\NVIDIA Corporation"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\AMD\DxCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\ProgramData\Microsoft\Windows\WER\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Windows\SoftwareDistribution\DataStore\Logs"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\CrashReportClient"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Windows\temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Windows\INF"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\ProgramData\%username%\Microsoft\XboxLive\NSALCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\Intel"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\Microsoft\Windows\History"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q <Drive name for removable media>:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q <Drive name for removable media>:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Roaming\EasyAntiCheat"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "<Drive name for removable media>:\Program Files\Epic Games\Fortnite\FortniteGame\Config"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "<Drive name for removable media>:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "<Drive name for removable media>:\Program Files\Epic Games\Fortnite\FortniteGame\Plugins"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "<Drive name for removable media>:\Program Files\Epic Games\Fortnite\Engine\Plugins"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Windows\Prefetch"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q <Drive name for removable media>:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q <Drive name for removable media>:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "<Drive name for removable media>:\Users\%username%\AppData\Local\NVIDIA Corporation"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\AMD\DxCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\ProgramData\Microsoft\Windows\WER\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Windows\SoftwareDistribution\DataStore\Logs"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Windows\temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\CrashReportClient"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\D3DSCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Windows\Prefetch"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\Public\Documents"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\D3DSCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\Public\Documents"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallTime /t REG_SZ /d 25021 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\CrashReportClient"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\Public\Documents"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\ProgramData\%username%\Microsoft\XboxLive\NSALCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Windows\INF"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\FortniteGame\Saved"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore"
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Control\ProductOptions /v OSProductContentId /t REG_SZ /d {25116-29637-9099-6056} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Control\ProductOptions /v OSProductPfn /t REG_SZ /d Microsoft.Windows.25116.29637-9099_605623543 /f
  • '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Direct3D /v WHQLClass /t REG_BINARY /d 25116296379099605623543277199740290021532221886250998108 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\SevilleEventlogManager /v LastEventlogWrittenTime /t REG_QWORD /d 25116296379099 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_QWORD /d 25116296379099 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallTime /t REG_QWORD /d 25116296379099 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\SQMClient /v WinSqmFirstSessionStartTime /t REG_QWORD /d 251131888924003 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId4 /t REG_BINARY /d 25113188892400314760132282379366283193031578 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId /t REG_BINARY /d 25113188892400314760132282379366283193031578 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Internet" "Explorer\Migration /v IE" "Installed" "Date /t REG_BINARY /d 25113188892400314760132282379366283193031578 /f
  • '<SYSTEM32>\reg.exe' ADD HKCU\SYSTEM\CurrentControlSet\Services\TPM\ODUID /v RandomSeed /t REG_BINARY /d 2511318889240031476013228237936628319303157828034252478064 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientIdValidation /t REG_BINARY /d 2511318889240031476013228237936628319303157828034252478064 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI /v WindowsAIKHash /t REG_BINARY /d 25110814061382346529141986635152089150671414 /f
  • '<SYSTEM32>\reg.exe' ADD HKCU\Software\Classes\Installer\Dependencies /v MSICache /t REG_BINARY /d 2511081406138234652914198663515208915067141425394 /f
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Compatibility32\FortniteLauncher /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Compatibility32\FortniteLauncher /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\System\CurrentControlSet\Control\WMI\Security\e5cdf199-abfd-11ea-8f7e-a8be27d3e473 /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\System\CurrentControlSet\Control\WMI\Security\e5cdf199-abfd-11ea-8f7e-a8be27d3e473 /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\System\CurrentControlSet\Control\WMI\Security\8c416c79-d49b-4f01-a467-e56d3aa8234c /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\System\CurrentControlSet\Control\WMI\Security\8c416c79-d49b-4f01-a467-e56d3aa8234c /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\3 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Windows\temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\ProgramData\%username%\Microsoft\XboxLive\NSALCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Roaming\EasyAntiCheat"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q D:\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Windows\INF"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Local\FortniteGame\Saved"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q E:\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "D:\Users\%username%\AppData\Local\Microsoft\Feeds Cache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\Intel"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\History"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q D:\ProgramData\Microsoft\DataMart\PaidWiFi\Rules"
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\3 /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v UserModeDriverGUID /t REG_SZ /d 25103-19412-3178-810715053 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Windows\Prefetch"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "D:\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "D:\Program Files\Epic Games\Fortnite\FortniteGame\Plugins"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "D:\Program Files\Epic Games\Fortnite\Engine\Plugins"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q D:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q D:\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "D:\Users\%username%\AppData\Local\NVIDIA Corporation"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Users\%username%\AppData\Local\AMD\DxCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\ProgramData\Microsoft\Windows\WER\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q D:\Windows\SoftwareDistribution\DataStore\Logs"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "D:\Program Files\Epic Games\Fortnite\FortniteGame\Config"
  • '<SYSTEM32>\reg.exe' delete HKLM\System\CurrentControlSet\Control\TimeZoneInformation /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\System\CurrentControlSet\Control\TimeZoneInformation /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\SoftwareProtectionPlatform /v ServiceSessionId /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\UnrealEngine"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD\VkCache"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\UsrClass.dat.log2"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\cache\qtshadercache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\ServiceProfiles\LocalService\AppData\Local\ConnectedDevicesPlatform\CDPGlobalSettings.cdp"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /q %systemdrive%\Users\%username%\AppData\Local\D3DSCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\ProgramData\USOShared\Logs\User"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\SoftwareDistribution\DataStore\Logs"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\ConnectedDevicesPlatform\L.%username%\ActivitiesCache.db-wal"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Roaming\Microsoft\Windows\CloudStore"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /q %systemdrive%\MSOCache"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /q %systemdrive%\Users\Public\Libraries"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /q %systemdrive%\ProgramData\Microsoft\Windows\WER"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /q %systemdrive%\Windows\System32\restore\MachineGuid.txt"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Internet Explorer\Recovery"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\CLR_v3.0"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\CLR_v4.0"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%systemdrive%\System Volume Information\IndexerVolumeGuid"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\LocalLow\Microsoft\CryptnetUrlCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\ntuser.ini"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\INTEL"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\UnrealEngineLauncher"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\CLR_v4.0\UsageLogs"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCache\IE\RHKRUA8J"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\EpicGamesLauncher"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\kbdclass\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {25008-2620-9405-3116610842} /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\ControlSet001\Services\kbdclass\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {%random%-%random%-%random%-%random%%random%} /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DESCRIPTION\System\BIOS /v BaseBoardProduct /t REG_SZ /d 25008-2620940531166 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\HARDWARE\DESCRIPTION\System\BIOS /v BaseBoardProduct /t REG_SZ /d %random%-%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\Software\Microsoft /v BuildLabEx /t REG_SZ /d 25008-2620 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\Software\Microsoft /v BuildLabEx /t REG_SZ /d %random%-%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\Software\Microsoft /v BuildLab /t REG_SZ /d 25005-24639 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\Software\Microsoft /v BuildLab /t REG_SZ /d %random%-%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\HardwareConfig\Current /v BaseBoardProduct /t REG_SZ /d 25005-24639243097103 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\HardwareConfig\Current /v BaseBoardProduct /t REG_SZ /d %random%-%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {25005-24639-%random} /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d {%random%-%random%-%random} /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /t REG_SZ /d 2500524639-24309-7103-527 /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d DESKTOP-25005 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v UserModeDriverGUID /t REG_SZ /d {%random%-%random%-%random%-%random%%random%} /f"
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d DESKTOP-%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d DESKTOP-25005 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d DESKTOP-%random% /f"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%localappdata%\XboxLive\Windows\AuthStateCache.dat""
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%localappdata%\Microsoft\Windows\WebCache""
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%localappdata%\Microsoft\Windows\INetCookies""
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%localappdata%\Microsoft\Windows\INetCache""
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%localappdata%\Microsoft\Feeds Cache""
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%localappdata%\Microsoft\Feeds""
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%localappdata%\NVIDIA Corporation\GfeSDK""
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%localappdata%\D3DSCache""
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\SERVIC~1\NETWOR~1\AppData\Local\Temp"
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\ControlSet001\Services\mouhid\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {%random%-%random%-%random%-%random%%random%} /f"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds Cache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%systemdrive%\Users\%username%\AppData\Local\Microsoft\Feeds Cache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\ProgramData\Microsoft\Windows\WER\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\CrashReportClient"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\D3DSCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\Public\Documents"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\ProgramData\%username%\Microsoft\XboxLive"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\INF"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\FortniteGame\Saved"
  • '<SYSTEM32>\cmd.exe' /C "rmdir / s / q %systemdrive%\Users\%username%\AppData\Local\Temp"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\ProgramData\USOShared\Logs"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\Logs"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\ProgramData\%username%\Microsoft\XboxLive\NSALCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\Explorer\IconCacheToDelete"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\servicing\InboxFodMetadataCache"
  • '<SYSTEM32>\cmd.exe' /C "rd /q /s <Drive name for removable media>:\$Recycle.Bin"
  • '<SYSTEM32>\cmd.exe' /C "rd /q /s e:\$Recycle.Bin"
  • '<SYSTEM32>\cmd.exe' /C "rd /q /s d:\$Recycle.Bin"
  • '<SYSTEM32>\cmd.exe' /C "rd /q /s %systemdrive%\$Recycle.Bin"
  • '<SYSTEM32>\cmd.exe' /C "taskkill /f /im FortniteClient-Win64-Shipping.exe"
  • '<SYSTEM32>\cmd.exe' /C "taskkill /f /im steam.exe"
  • '<SYSTEM32>\cmd.exe' /C "taskkill /f /im EpicGamesLauncher.exe"
  • '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\ControlSet001\Services\BEService /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SYSTEM\ControlSet001\Services\BEService /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD\DxCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\NVIDIA Corporation"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Windows\Prefetch"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\SettingSync\metastore"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q %systemdrive%\Users\username%\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\*.*"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\TargetedContentCache\v3"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\Intel"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\EcsCache0"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.OneConnect_8wekyb3d8bbwe\LocalState"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History\Low"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\History"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies\DNTException"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\IECompatCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\IECompatUaCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\IEDownloadHistory"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\mouhid\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {25008-2620-9405-3116610842} /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /t REG_SZ /d %random%%random%-%random%-%random%-%random% /f"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\INetCache"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\NetworksCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Roaming\EasyAntiCheat"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%systemdrive%\Users\%username%\AppData\Local\NVIDIA Corporation"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Config"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\PersistentDownloadDir"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\FortniteGame\Plugins"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "%systemdrive%\Program Files\Epic Games\Fortnite\Engine\Plugins"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\AC"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q %systemdrive%\Users\%username%\AppData\Local\Microsoft\XboxLive\*.*"
  • '<SYSTEM32>\cmd.exe' /C "@del /s /f /a:h / a : a / q %systemdrive%\Users\%username%\AppData\Local\Microsoft\Windows\WebCache\*.*"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\Temp"
  • '<SYSTEM32>\cmd.exe' /C "del /f /s /q %systemdrive%\ProgramData\Microsoft\DataMart\PaidWiFi\Rules"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q %systemdrive%\Users\%username%\AppData\Local\AMD\CN\NewsFeed"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v UserModeDriverGUID /t REG_SZ /d {25008-2620-9405-3116610842} /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume /f"
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 /f"
  • '<SYSTEM32>\reg.exe' delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Dfrg\Statistics /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Dfrg\Statistics /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\MountedDevices /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SYSTEM\MountedDevices /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global\CoProcManager /v ChipsetMatchID /t REG_SZ /d 25031-12323-3382-300217508 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global\CoProcManager /v ChipsetMatchID /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v PersistenceIdentifier /t REG_SZ /d 25031-12323-3382-300217508 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v PersistenceIdentifier /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v ClientUUID /t REG_SZ /d 25031-12323-3382-300217508 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v ClientUUID /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v SMBiosData /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v SMBiosData /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /t REG_SZ /d 25031-12323-3382-300217508 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v PingID /t REG_SZ /d 25028-1574-18286-117067193 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v PingID /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v AccountDomainSid /t REG_SZ /d 25028-1574-18286-117067193 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v AccountDomainSid /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\LastEnum /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\LastEnum /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume /f"
  • '<SYSTEM32>\reg.exe' delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket /v LastEnum /f"
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\SoftwareProtectionPlatform /v ServiceSessionId /f"
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v UserModeDriverGUID /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v UserModeDriverGUID /t REG_SZ /d 25038-1051-6343-183605369 /f
  • '<SYSTEM32>\reg.exe' delete HKCU\Software\Hex-Rays\IDA\History64 /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\Software\Hex-Rays\IDA\History64 /f"
  • '<SYSTEM32>\reg.exe' delete HKCU\Software\Hex-Rays\IDA\History /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\Software\Hex-Rays\IDA\History /f"
  • '<SYSTEM32>\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\SoftwareProtectionPlatform /v actionlist /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\SoftwareProtectionPlatform /v actionlist /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\SoftwareProtectionPlatform /v BackupProductKeyDefault /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\SoftwareProtectionPlatform /v BackupProductKeyDefault /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\SettingsRequests /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\SettingsRequests /f"
  • '<SYSTEM32>\reg.exe' delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume /f
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildBranch /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v _DriverProviderInfo /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' delete HKCU\Software\Classes\Interface /v ClsidStore /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCU\Software\Classes\Interface /v ClsidStore /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\SQMClient /v MachineId /t REG_SZ /d 25038-1051-6343-183605369 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\SQMClient /v MachineId /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareIds /t REG_SZ /d 25035-23071-21247-2706527823 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareIds /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d 25035-23071-21247-2706527823 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKCU\Software\Classes\Interface /v ClsidStore /t REG_BINARY /d 2503523071212472706527823278553023338802851611747287967006 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKCU\Software\Classes\Interface /v ClsidStore /t REG_BINARY /d %random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%random%%random% /f"
  • '<SYSTEM32>\reg.exe' delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket /v LastEnum /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 /v _DriverProviderInfo /t REG_SZ /d 25038-1051-6343-183605369 /f
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Users\%username%\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q <Drive name for removable media>:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData"
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKCR\com.epicgames.launcher /f"
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {%random%%random%-%random%-%random%-%random%%random%} /f >nul 2>&1"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v NV" "Hostname /t REG_SZ /d DESKTOP-25015 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v NV" "Hostname /t REG_SZ /d DESKTOP-%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Control\DevQuery\6 /v UUID /t REG_SZ /d 25015 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\System\CurrentControlSet\Control\DevQuery\6 /v UUID /t REG_SZ /d %random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v Domain /t REG_SZ /d 25015 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v Domain /t REG_SZ /d %random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v Hostname /t REG_SZ /d DESKTOP-25015 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v Hostname /t REG_SZ /d DESKTOP-%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\SQMClient /v MachineId /t REG_SZ /d {25015-24117-12366-1375731471} /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\SQMClient /v MachineId /t REG_SZ /d {%random%-%random%-%random%-%random%%random%} /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\BasicDisplay\Video /v VideoID /t REG_SZ /d {25015-24117-12366-1375731471} /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\ControlSet001\Services\BasicDisplay\Video /v VideoID /t REG_SZ /d {%random%-%random%-%random%-%random%%random%} /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1 /v Identifier /t REG_SZ /d 25015-24117-12366-1375731471 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1 /v Identifier /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0 /v Identifier /t REG_SZ /d 25012-13368-27269-2246221157 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0 /v Identifier /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "1\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d 25012-13368-27269-2246221157 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "1\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "0\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d 25012-13368-27269-2246221157 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "0\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildLab /t REG_SZ /d 25012-13368-27269-2246221157 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildLab /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d 25012-13368-27269-2246221157 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildBranch /t REG_SZ /d 25012-13368-27269-2246221157 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {%random%%random%-%random%-%random%-%random%%random%} /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v GUID /t REG_SZ /d {250182097-30230-5052-90188222} /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {250182097-30230-5052-90188222} /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d %random% /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\WOW6432Node\Epic" "Games /f
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d 25018 /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\WOW6432Node\Epic" "Games /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\WOW6432Node\EpicGames /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\WOW6432Node\EpicGames /f"
  • '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Classes\com.epicgames.launcher /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Classes\com.epicgames.launcher /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Tracing\Microsoft\Profile\Profile /v Guid /t REG_SZ /d 25025-23594-422-2041129647 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Tracing\Microsoft\Profile\Profile /v Guid /t REG_SZ /d %random%-%random%-%random%-%random%%random% /f"
  • '<SYSTEM32>\reg.exe' delete HKCU\Software\Epic" "Games /f
  • '<SYSTEM32>\cmd.exe' /C "REG delete HKCU\Software\Epic" "Games /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {2502112845-15326-29116-19332} /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%random%%random%-%random%-%random%-%random%} /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildLabEx /t REG_SZ /d 25021 /f
  • '<SYSTEM32>\cmd.exe' /C "reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume /f"
  • '<SYSTEM32>\reg.exe' delete HKCR\com.epicgames.launcher /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallTime /t REG_SZ /d %random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d 2502112845 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_SZ /d %random%%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d 2502112845-15326-29116-19332 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d %random%%random%-%random%-%random%-%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d 2502112845-15326-29116-19332 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d %random%%random%-%random%-%random%-%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d 25018-2097-30230-5052 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d %random%-%random%-%random%-%random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v REGisteredOrganization /t REG_SZ /d 25018 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v REGisteredOrganization /t REG_SZ /d %random% /f"
  • '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v REGisteredOwner /t REG_SZ /d 25018 /f
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v REGisteredOwner /t REG_SZ /d %random% /f"
  • '<SYSTEM32>\cmd.exe' /C "REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildLabEx /t REG_SZ /d %random% /f"
  • '<SYSTEM32>\cmd.exe' /C "rmdir /s /q "<Drive name for removable media>:\Users\%username%\AppData\Local\Microsoft\Feeds Cache"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android