Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'xncrypt v.1' = '<Full path to file>'
- Windows Task Manager (Taskmgr)
- firefox.exe
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\dashborder_144.bmp
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\glidescope_review_rev_010.docx
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\split.avi
- %HOMEPATH%\desktop\thlps_keeper_mayer_1965.docx
- %HOMEPATH%\desktop\tileimage.bmp
- C:\kms\kms_vl_all_aio.cmd.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\data sources (odbc).lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\event viewer.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\iscsi initiator.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\memory diagnostics tool.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\performance monitor.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\print management.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\security configuration management.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\services.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\system configuration.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\task scheduler.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\windows firewall with advanced security.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft onenote 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\windows powershell modules.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\about java.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\check for updates.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\configure java.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\get help.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\java\visit java.com.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\backup and restore center.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\create recovery disc.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\maintenance\remote assistance.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft access 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft excel 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft infopath designer 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\component services.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\administrative tools\computer management.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\games\gameexplorer.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft infopath filler 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\sync center.lnk.xncrypt
- %TEMP%\microsoft .net framework 4 setup_20230531_155457219-msi_netfx_extended_x64.msi.txt.xncrypt
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_20220928_164850616-msi_vc_red.msi.txt.xncrypt
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_20220928_165235616-msi_vc_red.msi.txt.xncrypt
- %TEMP%\microsoft visual c++ 2010 x86 redistributable setup_20220928_165304913-msi_vc_red.msi.txt.xncrypt
- %TEMP%\opera_crashreporter.log.xncrypt
- %TEMP%\ose00000.exe.xncrypt
- %TEMP%\setupexe(20220928171621f0c).log.xncrypt
- %TEMP%\wmsetup.log.xncrypt
- %APPDATA%\telegram desktop\telegram.exe.xncrypt
- %APPDATA%\telegram desktop\unins000.exe.xncrypt
- %APPDATA%\telegram desktop\updater.exe.xncrypt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\mss.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\mss00003.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\calculator.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\displayswitch.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\math input panel.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\mobility center.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\networkprojection.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\paint.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\remote desktop connection.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\snipping tool.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\sound recorder.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\sticky notes.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\welcome center.lnk.xncrypt
- %TEMP%\jusched.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\wordpad.lnk.xncrypt
- %TEMP%\adobesfx.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft outlook 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell ise.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\digital certificate for vba projects.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\microsoft clip organizer.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\microsoft office 2010 language preferences.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\microsoft office 2010 upload center.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft office 2010 tools\microsoft office picture manager.lnk.xncrypt
- C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\shows desktop.lnk.xncrypt
- C:\users\default\appdata\roaming\microsoft\internet explorer\quick launch\window switcher.lnk.xncrypt
- C:\users\default\appdata\roaming\microsoft\windows\sendto\fax recipient.lnk.xncrypt
- %LOCALAPPDATA%\google\chrome\application\chrome.exe.xncrypt
- %LOCALAPPDATA%\google\chrome\application\debug.log.xncrypt
- %LOCALAPPDATA%\microsoft\windows mail\stationery\cave_drawings.gif.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft powerpoint 2010.lnk.xncrypt
- %LOCALAPPDATA%\microsoft\windows mail\stationery\connectivity.gif.xncrypt
- %LOCALAPPDATA%\microsoft\windows mail\stationery\tiki.gif.xncrypt
- %LOCALAPPDATA%\microsoft\windows mail\stationery\wrinkled_paper.gif.xncrypt
- %LOCALAPPDATA%low\microsoft\internet explorer\services\search_{0633ee93-d776-472f-a0ff-e1416b8b2e3a}.ico.xncrypt
- %APPDATA%\microsoft\internet explorer\quick launch\google chrome.lnk.xncrypt
- %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk.xncrypt
- %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.lnk.xncrypt
- %APPDATA%\microsoft\internet explorer\quick launch\window switcher.lnk.xncrypt
- %APPDATA%\microsoft\windows\sendto\fax recipient.lnk.xncrypt
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\alternateservices.txt.xncrypt
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\pkcs11.txt.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell ise (x86).lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell (x86).lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\tablet pc\windows journal.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\tablet pc\tabtip.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft publisher 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft word 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sharepoint\microsoft sharepoint workspace 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\steam\steam.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\console rar manual.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\what is new in the latest version.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\winrar help.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\winrar\winrar.lnk.xncrypt
- %LOCALAPPDATA%\microsoft\internet explorer\brndlog.txt.xncrypt
- %LOCALAPPDATA%\microsoft\windows mail\edb.log.xncrypt
- %LOCALAPPDATA%\microsoft\windows mail\edb00001.log.xncrypt
- %TEMP%\javadeployreg.log.xncrypt
- %TEMP%\opera installer\opera_installer_20220928171325.log.xncrypt
- %TEMP%\microsoft .net framework 4 setup_20230531_155457219-msi_netfx_core_x64.msi.txt.xncrypt
- %TEMP%\opera installer\opera_installer_20220928171336.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\character map.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\dfrgui.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\disk cleanup.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\resource monitor.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\system information.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\system restore.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\task scheduler.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\windows easy transfer reports.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\system tools\windows easy transfer.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\tablet pc\shapecollector.lnk.xncrypt
- %TEMP%\opera installer\opera_installer_20220928171326.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\microsoft office\microsoft sharepoint workspace 2010.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\accessories\accessibility\speech recognition.lnk.xncrypt
- %TEMP%\dd_wcf_ca_smci_20230531_225945_094.txt.xncrypt
- %TEMP%\dd_wcf_ca_smci_20230531_225943_157.txt.xncrypt
- %TEMP%\dd_vcredist_x86_20220928170410.log.xncrypt
- %HOMEPATH%\desktop\telegram.lnk.xncrypt
- %HOMEPATH%\desktop\utorrent.exe.xncrypt
- %HOMEPATH%\links\desktop.lnk.xncrypt
- %HOMEPATH%\links\downloads.lnk.xncrypt
- %HOMEPATH%\links\recentplaces.lnk.xncrypt
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\setup.exe.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\default programs.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\windows update.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows defender\support\mplog-07132009-221054.log.xncrypt
- %ALLUSERSPROFILE%\oracle\java\javapath\java.exe.xncrypt
- %ALLUSERSPROFILE%\oracle\java\javapath\javaw.exe.xncrypt
- %ALLUSERSPROFILE%\oracle\java\javapath\javaws.exe.xncrypt
- C:\users\public\music\sample music\kalimba.mp3.xncrypt
- C:\users\public\music\sample music\maid with the flaxen hair.mp3.xncrypt
- C:\users\public\music\sample music\sleep away.mp3.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pictures.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\settings.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\wmp.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.xncrypt
- %HOMEPATH%\desktop\dotnetfx45_full_setup.exe.xncrypt
- %HOMEPATH%\desktop\correct.avi.xncrypt
- %HOMEPATH%\desktop\jre-7u75-windows-i586-iftw.exe.xncrypt
- %HOMEPATH%\desktop\dashborder_144.bmp.xncrypt
- %HOMEPATH%\desktop\calc.exe.xncrypt
- %ALLUSERSPROFILE%\package cache\{295d1583-fdb9-414b-a4c8-da539362a26b}\vc_redist.x64.exe.xncrypt
- <Full path to file>.xncrypt
- %ALLUSERSPROFILE%\microsoft\office\assetlibrary.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\office\documentrepository.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\office\mysharepoints.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\office\mysite.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\office\sharepointportalsite.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\office\sharepointteamsite.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\officesoftwareprotectionplatform\tokens.dat.xncrypt
- %ALLUSERSPROFILE%\microsoft\user account pictures\guest.bmp.xncrypt
- %ALLUSERSPROFILE%\microsoft\user account pictures\user.bmp.xncrypt
- %ALLUSERSPROFILE%\microsoft\user account pictures\user.dat.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_pref.ico.xncrypt
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\securitypreloadstate.txt.xncrypt
- %ALLUSERSPROFILE%\package cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe.xncrypt
- %ALLUSERSPROFILE%\package cache\{38b2c744-ad08-4d5b-91a2-3fb6f739ff3e}\vc_redist.x86.exe.xncrypt
- %ALLUSERSPROFILE%\package cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe.xncrypt
- %ALLUSERSPROFILE%\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe.xncrypt
- %ALLUSERSPROFILE%\package cache\{fd9b6070-d13e-45dc-819b-41806bf45b6b}\vc_redist.x64.exe.xncrypt
- C:\users\public\desktop\acrobat reader dc.lnk.xncrypt
- C:\users\public\desktop\firefox.lnk.xncrypt
- C:\users\public\desktop\mozilla thunderbird.lnk.xncrypt
- C:\users\public\desktop\opera.lnk.xncrypt
- C:\users\public\desktop\steam.lnk.xncrypt
- %HOMEPATH%\desktop\508softwareandos.doc.xncrypt
- %HOMEPATH%\desktop\archer.avi.xncrypt
- C:\kms\kms_vl_all_aio_debug.log.xncrypt
- %ALLUSERSPROFILE%\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe.xncrypt
- %LOCALAPPDATA%\microsoft\windows mail\stationery\stucco.gif.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_property.ico.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_settings.ico.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165956_001_vcruntimeminimum_x64.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165956_002_vcruntimeadditional_x64.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928170114.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928170250.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928170250_001_vcruntimeminimum_x64.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928170250_002_vcruntimeadditional_x64.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928170328.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165536.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165536_0_vcruntimeminimum_x86.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165536_1_vcruntimeadditional_x86.log.xncrypt
- %HOMEPATH%\desktop\google chrome.lnk.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165710.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165710_1_vcruntimeadditional_x86.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165916.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165916_000_vcruntimeminimum_x86.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165916_001_vcruntimeadditional_x86.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928170143.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928170143_001_vcruntimeminimum_x86.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928170143_002_vcruntimeadditional_x86.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928170221.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928170335.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928170335_001_vcruntimeminimum_x86.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928170335_002_vcruntimeadditional_x86.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165746_000_vcruntimeminimum_x64.log.xncrypt
- %TEMP%\dd_vcredist_x86_20220928165710_0_vcruntimeminimum_x86.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165956.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165746_001_vcruntimeadditional_x64.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165746.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165628_1_vcruntimeadditional_x64.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\acrobat reader dc.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\firefox.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\media center.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\mozilla thunderbird.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\opera.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\sidebar.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows dvd maker.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows fax and scan.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\windows media player.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\xps viewer.lnk.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_queue.ico.xncrypt
- %TEMP%\adobearm.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_.ico.xncrypt
- %TEMP%\aspnetsetup_00000.log.xncrypt
- %TEMP%\chrome_installer.log.xncrypt
- %TEMP%\dd_dotnetfx40_full_x86_x64_decompression_log.txt.xncrypt
- %TEMP%\dd_ndp48-x86-x64-allos-enu_decompression_log.txt.xncrypt
- %TEMP%\dd_setuputility.txt.xncrypt
- %TEMP%\dd_vcredistmsi7a3c.txt.xncrypt
- %TEMP%\dd_vcredistui7a3c.txt.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165349.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165349_0_vcruntimeminimum_x64.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165349_1_vcruntimeadditional_x64.log.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165628.log.xncrypt
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_property.ico.xncrypt
- %TEMP%\dd_vcredist_amd64_20220928165628_0_vcruntimeminimum_x64.log.xncrypt
- %TEMP%\aspnetsetup_00001.log.xncrypt
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\sitesecurityservicestate.txt.xncrypt