Technical Information
- <Drive name for removable media>:\delete.avi.tmp
- <Drive name for removable media>:\correct.avi.tmp
- <Drive name for removable media>:\split.avi.tmp
- <Drive name for removable media>:\archer.avi.tmp
- <Drive name for removable media>:\000814251_video_01.avi.tmp
- <Drive name for removable media>:\default.bmp.tmp
- <Drive name for removable media>:\dashborder_192.bmp.tmp
- <Drive name for removable media>:\dial.bmp.tmp
- <Drive name for removable media>:\tileimage.bmp.tmp
- <Drive name for removable media>:\contoso.cer.tmp
- <Drive name for removable media>:\contoso_1.cer.tmp
- <Drive name for removable media>:\sdksampleprivdeveloper.cer.tmp
- System Restore (SR)
- firefox.exe
- <SYSTEM32>\windowspowershell\v1.0\debug.log
- %TEMP%\config.bmp
- <Drive name for removable media>:\delete.avi.tmp
- <Drive name for removable media>:\correct.avi.tmp
- <Drive name for removable media>:\split.avi.tmp
- <Drive name for removable media>:\archer.avi.tmp
- <Drive name for removable media>:\000814251_video_01.avi.tmp
- <Drive name for removable media>:\default.bmp.tmp
- <Drive name for removable media>:\dashborder_192.bmp.tmp
- <Drive name for removable media>:\dial.bmp.tmp
- <Drive name for removable media>:\tileimage.bmp.tmp
- <Drive name for removable media>:\contoso.cer.tmp
- <Drive name for removable media>:\contoso_1.cer.tmp
- <Drive name for removable media>:\sdksampleprivdeveloper.cer.tmp
- <Drive name for removable media>:\applicantform_en.doc.tmp
- <Drive name for removable media>:\508softwareandos.doc.tmp
- <Drive name for removable media>:\hanni_umami_chapter.doc.tmp
- <Drive name for removable media>:\issi2013_template_for_posters.docx.tmp
- <Drive name for removable media>:\glidescope_review_rev_010.docx.tmp
- <Drive name for removable media>:\file_p_00000000_1371597592.docx.tmp
- <Drive name for removable media>:\nwfieldnotes1966.docx.tmp
- <Drive name for removable media>:\sdszfo.docx.tmp
- <Drive name for removable media>:\thlps_keeper_mayer_1965.docx.tmp
- <Drive name for removable media>:\adhd_and_obesity.docx.tmp
- <Drive name for removable media>:\holycrosschurchinstructions.docx.tmp
- <Drive name for removable media>:\ituneshelpunavailable.htm.tmp
- <Drive name for removable media>:\trivial-merge.htm.tmp
- <Drive name for removable media>:\iisstart.htm.tmp
- <Drive name for removable media>:\alert.htm.tmp
- <Drive name for removable media>:\advice_process.htm.tmp
- <Drive name for removable media>:\tree_view.htm.tmp
- <Drive name for removable media>:\browse.htm.tmp
- <Drive name for removable media>:\alert.html.tmp
- <Drive name for removable media>:\iisstart.html.tmp
- <Drive name for removable media>:\ituneshelpunavailable.html.tmp
- <Drive name for removable media>:\howto-index.html.tmp
- <Drive name for removable media>:\api-hashmap.html.tmp
- <Drive name for removable media>:\browse.html.tmp
- <Drive name for removable media>:\tree_view.html.tmp
- <Drive name for removable media>:\parnas_01.jpeg.tmp
- <Drive name for removable media>:\2.jpeg.tmp
- <Drive name for removable media>:\210252809.jpeg.tmp
- <Drive name for removable media>:\210252809.jpg.tmp
- <Drive name for removable media>:\pushkin.jpg.tmp
- <Drive name for removable media>:\168.jpg.tmp
- <Drive name for removable media>:\region-north-karelia.jpg.tmp
- <Drive name for removable media>:\4f0bf7ff71f28.jpg.tmp
- <Drive name for removable media>:\etc6_m_1.mov.tmp
- <Drive name for removable media>:\spanner.mov.tmp
- <Drive name for removable media>:\firefly1.mov.tmp
- <Drive name for removable media>:\scan.mov.tmp
- <Drive name for removable media>:\clip_480_5sec_6mbps_h264.mp4.tmp
- <Drive name for removable media>:\video_1.mp4.tmp
- <Drive name for removable media>:\clip_1080_5sec_10mbps_h264.mp4.tmp
- <Drive name for removable media>:\d0068197bb5a41fea16a220c45390606.mp4.tmp
- <Drive name for removable media>:\ff_ot_user_guide.pdf.tmp
- <Drive name for removable media>:\lom602.pdf.tmp
- <Drive name for removable media>:\10thingscondoms.pdf.tmp
- <Drive name for removable media>:\delongcacert.pem.tmp
- <Drive name for removable media>:\investmentbankca_ca8.pem.tmp
- <Drive name for removable media>:\irgeek.pem.tmp
- <Drive name for removable media>:\hhhlcert.pem.tmp
- <Drive name for removable media>:\server.pem.tmp
- <Drive name for removable media>:\ck_ugo.pem.tmp
- <Drive name for removable media>:\dissolveanother.png.tmp
- <Drive name for removable media>:\breakpoint.png.tmp
- <Drive name for removable media>:\block.png.tmp
- <Drive name for removable media>:\cbz.png.tmp
- <Drive name for removable media>:\background.png.tmp
- <Drive name for removable media>:\mappingconcepthubberlin.ppt.tmp
- <Drive name for removable media>:\sacs_presentation_sacs_qep_improving_rt_education_final.ppt.tmp
- <Drive name for removable media>:\sim_gametheory_to_finance.ppt.tmp
- <Drive name for removable media>:\proposaltemplates.ppt.tmp
- <Drive name for removable media>:\file1.ppt.tmp
- <Drive name for removable media>:\writingcompletesarnarrative_1103.ppt.tmp
- <Drive name for removable media>:\ppswamp.ppt.tmp
- <Drive name for removable media>:\accountsreceivable.ppt.tmp
- <Drive name for removable media>:\stoc13_ml_quoc_le.pptx.tmp
- <Drive name for removable media>:\asaprojectcompetition.pptx.tmp
- <Drive name for removable media>:\waterresourcesag.pptx.tmp
- <Drive name for removable media>:\indogerman2010.pptx.tmp
- <Drive name for removable media>:\samieee_obiee_presentation.pptx.tmp
- <Drive name for removable media>:\swc_2009-03-02.rdf.tmp
- <Drive name for removable media>:\digest.rdf.tmp
- <Drive name for removable media>:\contenttypes.rdf.tmp
- <Drive name for removable media>:\elvisimp.rdf.tmp
- <Drive name for removable media>:\foaf.rdf.tmp
- <Drive name for removable media>:\schema.rdf.tmp
- <Drive name for removable media>:\skos.rdf.tmp
- <Drive name for removable media>:\20140114.rdf.tmp
- <Drive name for removable media>:\router_manual.rtf.tmp
- <Drive name for removable media>:\phytoremediation.rtf.tmp
- <Drive name for removable media>:\myhrvoldhanssenbiharfamine.rtf.tmp
- <Drive name for removable media>:\krsweden.rtf.tmp
- <Drive name for removable media>:\waterlandhealthkano.rtf.tmp
- <Drive name for removable media>:\pandp.rtf.tmp
- <Drive name for removable media>:\military_callsigns_0311.rtf.tmp
- <Drive name for removable media>:\flower_trans_matte.wmv.tmp
- <Drive name for removable media>:\calculatorworksheet.xls.tmp
- <Drive name for removable media>:\guide_reorganization_mapping.xls.tmp
- <Drive name for removable media>:\productos.xls.tmp
- <Drive name for removable media>:\subjectclassification.xls.tmp
- <Drive name for removable media>:\removedtitles_records.xls.tmp
- <Drive name for removable media>:\2013_finalsummaryforweb.xlsx.tmp
- <Drive name for removable media>:\2013_smccc_competition_points_jul2013.xlsx.tmp
- <Drive name for removable media>:\applicant.xlsx.tmp
- <Drive name for removable media>:\national_autism_preparation_programs.xlsx.tmp
- <Drive name for removable media>:\disclosuredetails.xlsx.tmp
- <Drive name for removable media>:\removedtitles_records.zip.tmp
- <Drive name for removable media>:\fiche_inscription_2015.zip.tmp
- <Drive name for removable media>:\excel_example.zip.tmp
- <Drive name for removable media>:\calculatorworksheet.zip.tmp
- <Drive name for removable media>:\subjectclassification.zip.tmp
- <Drive name for removable media>:\price030215.zip.tmp
- <Drive name for removable media>:\price.zip.tmp
- <Drive name for removable media>:\1sm_price.zip.tmp
- <Drive name for removable media>:\system volume information\wpsettings.dat.tmp
- %APPDATA%\microsoft\windows\themes\transcodedwallpaper
- %APPDATA%\microsoft\windows\themes\cachedfiles\cachedimage_1152_864_pos2.jpg
- '<LOCALNET>..32.0':445
- '<LOCALNET>..32.1':445
- '<LOCALNET>..32.2':445
- '<LOCALNET>..32.3':445
- '<LOCALNET>..32.4':445
- '<LOCALNET>..32.5':445
- '<LOCALNET>..32.6':445
- '<LOCALNET>..32.7':445
- '<LOCALNET>..32.8':445
- '<LOCALNET>..32.9':445
- '<LOCALNET>..32.10':445
- '<LOCALNET>..32.11':445
- '<LOCALNET>..32.12':445
- '<LOCALNET>..32.13':445
- '<LOCALNET>..32.14':445
- '<LOCALNET>..32.15':445
- '<LOCALNET>..32.16':445
- '<LOCALNET>..32.17':445
- '<LOCALNET>..32.18':445
- '<LOCALNET>..32.19':445
- '<LOCALNET>..32.20':445
- '<LOCALNET>..32.21':445
- '<LOCALNET>..32.22':445
- '<LOCALNET>..32.23':445
- '<LOCALNET>..32.24':445
- '<LOCALNET>..32.25':445
- '<LOCALNET>..32.26':445
- '<LOCALNET>..32.27':445
- '<LOCALNET>..32.28':445
- '<LOCALNET>..32.29':445
- '<LOCALNET>..32.30':445
- '<LOCALNET>..32.31':445
- '<LOCALNET>..32.32':445
- '<LOCALNET>..32.33':445
- '<LOCALNET>..32.34':445
- '<LOCALNET>..32.35':445
- '<LOCALNET>..32.36':445
- '<LOCALNET>..32.37':445
- '<LOCALNET>..32.38':445
- '<LOCALNET>..32.39':445
- '<LOCALNET>..32.40':445
- '<LOCALNET>..32.41':445
- '<LOCALNET>..32.42':445
- '<LOCALNET>..32.43':445
- '<LOCALNET>..32.44':445
- '<LOCALNET>..32.45':445
- '<LOCALNET>..32.46':445
- '<LOCALNET>..32.47':445
- '<LOCALNET>..32.48':445
- '<LOCALNET>..32.49':445
- '<LOCALNET>..32.50':445
- '<LOCALNET>..32.51':445
- '<LOCALNET>..32.52':445
- '<LOCALNET>..32.53':445
- '<LOCALNET>..32.54':445
- '<LOCALNET>..32.55':445
- '<LOCALNET>..32.56':445
- '<LOCALNET>..32.57':445
- '<LOCALNET>..32.58':445
- '<LOCALNET>..32.59':445
- '<LOCALNET>..32.60':445
- '<LOCALNET>..32.61':445
- '<LOCALNET>..32.62':445
- '<LOCALNET>..32.63':445
- '<LOCALNET>..32.64':445
- '<LOCALNET>..32.65':445
- '<LOCALNET>..32.66':445
- '<LOCALNET>..32.67':445
- '<LOCALNET>..32.68':445
- '<LOCALNET>..32.69':445
- '<LOCALNET>..32.70':445
- '<LOCALNET>..32.71':445
- '<LOCALNET>..32.72':445
- '<LOCALNET>..32.73':445
- '<LOCALNET>..32.74':445
- '<LOCALNET>..32.75':445
- '<LOCALNET>..32.76':445
- '<LOCALNET>..32.77':445
- '<LOCALNET>..32.78':445
- '<LOCALNET>..32.79':445
- '<LOCALNET>..32.80':445
- '<LOCALNET>..32.81':445
- '<LOCALNET>..32.82':445
- '<LOCALNET>..32.83':445
- '<LOCALNET>..32.84':445
- '<LOCALNET>..32.85':445
- '<LOCALNET>..32.86':445
- '<LOCALNET>..32.87':445
- '<LOCALNET>..32.88':445
- '<LOCALNET>..32.89':445
- '<LOCALNET>..32.90':445
- '<LOCALNET>..32.91':445
- '<LOCALNET>..32.92':445
- '<LOCALNET>..32.93':445
- '<LOCALNET>..32.94':445
- '<LOCALNET>..32.95':445
- '<LOCALNET>..32.96':445
- '<LOCALNET>..32.97':445
- '<LOCALNET>..32.98':445
- '<LOCALNET>..32.99':445
- '<LOCALNET>..32.100':445
- '<LOCALNET>..32.101':445
- '<LOCALNET>..32.102':445
- '<LOCALNET>..32.103':445
- '<LOCALNET>..32.104':445
- '<LOCALNET>..32.105':445
- '<LOCALNET>..32.106':445
- '<LOCALNET>..32.107':445
- '<LOCALNET>..32.108':445
- '<LOCALNET>..32.109':445
- '<LOCALNET>..32.110':445
- '<LOCALNET>..32.111':445
- '<LOCALNET>..32.112':445
- '<LOCALNET>..32.113':445
- '<LOCALNET>..32.114':445
- '<LOCALNET>..32.115':445
- '<LOCALNET>..32.116':445
- '<LOCALNET>..32.117':445
- '<LOCALNET>..32.118':445
- '<LOCALNET>..32.119':445
- '<LOCALNET>..32.120':445
- '<LOCALNET>..32.121':445
- '<LOCALNET>..32.122':445
- '<LOCALNET>..32.123':445
- '<LOCALNET>..32.124':445
- '<LOCALNET>..32.125':445
- '<LOCALNET>..32.126':445
- '<LOCALNET>..32.127':445
- '<LOCALNET>..32.128':445
- '<LOCALNET>..32.129':445
- '<LOCALNET>..32.130':445
- '<LOCALNET>..32.131':445
- '<LOCALNET>..32.132':445
- '<LOCALNET>..32.133':445
- '<LOCALNET>..32.134':445
- '<LOCALNET>..32.135':445
- '<LOCALNET>..32.136':445
- '<LOCALNET>..32.137':445
- '<LOCALNET>..32.138':445
- '<LOCALNET>..32.139':445
- '<LOCALNET>..32.140':445
- '<LOCALNET>..32.141':445
- '<LOCALNET>..32.142':445
- '<LOCALNET>..32.143':445
- '<LOCALNET>..32.144':445
- '<LOCALNET>..32.145':445
- '<LOCALNET>..32.146':445
- '<LOCALNET>..32.147':445
- '<LOCALNET>..32.148':445
- '<LOCALNET>..32.149':445
- '<LOCALNET>..32.150':445
- '<LOCALNET>..32.151':445
- '<LOCALNET>..32.152':445
- '<LOCALNET>..32.153':445
- '<LOCALNET>..32.154':445
- '<LOCALNET>..32.155':445
- '<LOCALNET>..32.156':445
- '<LOCALNET>..32.157':445
- '<LOCALNET>..32.158':445
- '<LOCALNET>..32.159':445
- '<LOCALNET>..32.160':445
- '<LOCALNET>..32.161':445
- '<LOCALNET>..32.162':445
- '<LOCALNET>..32.163':445
- '<LOCALNET>..32.164':445
- '<LOCALNET>..32.165':445
- '<LOCALNET>..32.166':445
- '<LOCALNET>..32.167':445
- '<LOCALNET>..32.168':445
- '<LOCALNET>..32.169':445
- '<LOCALNET>..32.170':445
- '<LOCALNET>..32.171':445
- '<LOCALNET>..32.172':445
- '<LOCALNET>..32.173':445
- '<LOCALNET>..32.174':445
- '<LOCALNET>..32.175':445
- '<LOCALNET>..32.176':445
- '<LOCALNET>..32.177':445
- '<LOCALNET>..32.178':445
- '<LOCALNET>..32.179':445
- '<LOCALNET>..32.180':445
- '<LOCALNET>..32.181':445
- '<LOCALNET>..32.182':445
- '<LOCALNET>..32.183':445
- '<LOCALNET>..32.184':445
- '<LOCALNET>..32.185':445
- '<LOCALNET>..32.186':445
- '<LOCALNET>..32.187':445
- '<LOCALNET>..32.188':445
- '<LOCALNET>..32.189':445
- '<LOCALNET>..32.190':445
- '<LOCALNET>..32.191':445
- '<LOCALNET>..32.192':445
- '<LOCALNET>..32.193':445
- '<LOCALNET>..32.194':445
- '<LOCALNET>..32.195':445
- '<LOCALNET>..32.196':445
- '<LOCALNET>..32.197':445
- '<LOCALNET>..32.198':445
- '<LOCALNET>..32.199':445
- '<LOCALNET>..32.200':445
- '<LOCALNET>..32.201':445
- '<LOCALNET>..32.202':445
- '<LOCALNET>..32.203':445
- '<LOCALNET>..32.204':445
- '<LOCALNET>..32.205':445
- '<LOCALNET>..32.206':445
- '<LOCALNET>..32.207':445
- '<LOCALNET>..32.208':445
- '<LOCALNET>..32.209':445
- '<LOCALNET>..32.210':445
- '<LOCALNET>..32.211':445
- '<LOCALNET>..32.212':445
- '<LOCALNET>..32.213':445
- '<LOCALNET>..32.214':445
- '<LOCALNET>..32.215':445
- '<LOCALNET>..32.216':445
- '<LOCALNET>..32.217':445
- '<LOCALNET>..32.218':445
- '<LOCALNET>..32.219':445
- '<LOCALNET>..32.220':445
- '<LOCALNET>..32.221':445
- '<LOCALNET>..32.222':445
- '<LOCALNET>..32.223':445
- '<LOCALNET>..32.224':445
- '<LOCALNET>..32.225':445
- '<LOCALNET>..32.226':445
- '<LOCALNET>..32.227':445
- '<LOCALNET>..32.228':445
- '<LOCALNET>..32.229':445
- '<LOCALNET>..32.230':445
- '<LOCALNET>..32.231':445
- '<LOCALNET>..32.232':445
- '<LOCALNET>..32.233':445
- '<LOCALNET>..32.234':445
- '<LOCALNET>..32.235':445
- '<LOCALNET>..32.236':445
- '<LOCALNET>..32.237':445
- '<LOCALNET>..32.238':445
- '<LOCALNET>..32.239':445
- '<LOCALNET>..32.240':445
- '<LOCALNET>..32.241':445
- '<LOCALNET>..32.242':445
- '<LOCALNET>..32.243':445
- '<LOCALNET>..32.244':445
- '<LOCALNET>..32.245':445
- '<LOCALNET>..32.246':445
- '<LOCALNET>..32.247':445
- '<LOCALNET>..32.248':445
- '<LOCALNET>..32.249':445
- '<LOCALNET>..32.250':445
- '<LOCALNET>..32.251':445
- '<LOCALNET>..32.252':445
- '<LOCALNET>..32.253':445
- '<LOCALNET>..32.254':445
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Get-CimInstance Win32_ShadowCopy | Remove-CimInstance"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Get-VM | Stop-VM -Force"
- '<SYSTEM32>\cmd.exe' /c wevtutil cl security
- '<SYSTEM32>\wevtutil.exe' cl security
- '<SYSTEM32>\cmd.exe' /c wevtutil cl system
- '<SYSTEM32>\wevtutil.exe' cl system
- '<SYSTEM32>\cmd.exe' /c wevtutil cl application
- '<SYSTEM32>\wevtutil.exe' cl application
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {default} recoveryenabled No
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures
- '<SYSTEM32>\bcdedit.exe' /set {default} bootstatuspolicy ignoreallfailures
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Get-CimInstance Win32_ShadowCopy | Remove-CimInstance"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Get-VM | Stop-VM -Force"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil cl security' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil cl system' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wevtutil cl application' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {default} recoveryenabled No' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures' (with hidden window)