| %ProgramFiles%\accessories\backup\system\vsf\explorer2.exe |
| %ProgramFiles%\kari\win32ip.exe |
| %System%\aicrun.exe |
| %System%\ddj\hide.exe |
| %System%\dk\lam3.exe |
| %System%\dll\hex.exe |
| %System%\dllcache\r2c\hid.exe |
| %System%\drive\lam3.exe |
| %System%\drivers\etc\cache03\smnt.exe |
| %System%\drivers\etc\tmp7\smnt.exe |
| %System%\drivers\etc\wtf22\smnt.exe |
| %System%\drivers\etc\x.exe |
| %System%\drivers\nvidia\dll\hex.exe |
| %System%\drivers\petanix.exe |
| %System%\drivers\system\hex.exe |
| %System%\instalation-software\rundll32.exe |
| %System%\mirc.exe |
| %System%\mirc32.exe |
| %System%\mnut\lam3.exe |
| %System%\mouse\rundll32.exe |
| %System%\newsfr.exe |
| %System%\oobe\x.exe |
| %System%\programs\hex.exe |
| %System%\restore\font\systems\download\winhide.exe |
| %System%\restore\font\systems\winhide.exe |
| %System%\securaq.exe |
| %System%\stafsrun.exe |
| %System%\temp2.exe |
| %System%\ttt\lam3.exe |
| %Temp%\gsf2\lindisecret.exe |
| %Windir%\font\font\sytem\winhide.exe |
| %Windir%\system\programas\hex.exe |
| %Windir%\system\rgdet.exe |
| %Windir%\system\rundll32.exe |
| %Windir%\system\x.exe |
| %Windir%\win32.exe |
| %Windir%\win-secure\run32.exe |
| c:\hide.exe |
| c:\recycled\msn\hex.exe |
| c:\recycler\s-1-5-21-3252328098-71414409-2463015037-501\hex.exe |
| c:\winnt\system32\certsrv\0w3x24\mscmd.exe |
| c:\winnt\system32\devcheck.exe |
| c:\winnt\system32\lavan\devcheck.exe |
| c:\winnt\system32\os\devcheck.exe |