| %AllUsersProfile%\desktop.exe |
| %AllUsersProfile%\documents.exe |
| %AllUsersProfile%\drm.exe |
| %AllUsersProfile%\drm\drm.exe |
| %AllUsersProfile%\favorites.exe |
| %AllUsersProfile%\templates.exe |
| %AppData%\%username%.task\services.exe |
| %AppData%\explorer.exe |
| %AppData%\lsass.exe |
| %AppData%\microsoft\svchost.exe |
| %AppData%\svchost.exe |
| %AppData%\winupdate.exe |
| %CommonAppData%\adobe.exe |
| %CommonAppData%\adobe\adobe.exe |
| %CommonAppData%\microsoft.exe |
| %CommonAppData%\microsoft\crypto.exe |
| %CommonAppData%\microsoft\crypto\crypto.exe |
| %CommonAppData%\microsoft\crypto\dss.exe |
| %CommonAppData%\microsoft\crypto\dss\dss.exe |
| %CommonAppData%\microsoft\crypto\rsa.exe |
| %CommonAppData%\microsoft\crypto\rsa\rsa.exe |
| %CommonAppData%\microsoft\microsoft.exe |
| %CommonAppData%\microsoft\network.exe |
| %CommonAppData%\microsoft\network\connections.exe |
| %CommonAppData%\microsoft\network\connections\connections.exe |
| %CommonAppData%\microsoft\network\network.exe |
| %CommonAppData%\normal.exe |
| %CommonAppData%\vmware.exe |
| %CommonDesktopDir%\desktop.exe |
| %CommonDocuments%\documents.exe |
| %CommonFavorites%\favorites.exe |
| %CommonPrograms%\startup\msadvisor.exe |
| %CommonPrograms%\startup\sysinfo.exe |
| %CommonTemplates%\templates.exe |
| %DesktopDir%\desktop.exe |
| %DesktopDir%\winupdaterwinnt.exe |
| %Favorites%\favorites.exe |
| %FontsDir%\uucmss.exe |
| %MyDocuments%\dlhost.exe |
| %MyDocuments%\explorer.exe |
| %Profiles%\default user\cookies.exe |
| %Profiles%\default user\desktop.exe |
| %Profiles%\default user\desktop\desktop.exe |
| %Profiles%\default user\favorites.exe |
| %Profiles%\default user\favorites\favorites.exe |
| %Profiles%\default user\nethood.exe |
| %Profiles%\default user\nethood\nethood.exe |
| %Profiles%\default user\printhood.exe |
| %Profiles%\default user\printhood\printhood.exe |
| %Profiles%\default user\recent.exe |
| %Profiles%\default user\recent\recent.exe |
| %Profiles%\default user\sendto.exe |
| %Profiles%\default user\sendto\sendto.exe |
| %Profiles%\default user\templates.exe |
| %Profiles%\default user\templates\templates.exe |
| %Profiles%\default user\templates\winword.doc.exe |
| %Profiles%\default user\templates\winword.exe |
| %Profiles%\default user\templates\winword2.doc.exe |
| %Profiles%\default user\templates\winword2.exe |
| %Profiles%\localservice.exe |
| %Profiles%\localservice\cookies.exe |
| %Profiles%\localservice\localservice.exe |
| %Profiles%\networkservice.exe |
| %Profiles%\networkservice\cookies.exe |
| %Profiles%\networkservice\networkservice.exe |
| %ProgramFiles%\aore-unpacktools\armadumper.exe |
| %ProgramFiles%\bifrost\server.exe |
| %ProgramFiles%\bifrost\svchost32.exe |
| %ProgramFiles%\crux calculator v5\crux_calc.exe |
| %ProgramFiles%\explorer.exe |
| %ProgramFiles%\internet explorer\connection wizard\explorer.exe |
| %ProgramFiles%\internet explorer\mui\winmon.exe |
| %ProgramFiles%\internet explorer\smss.exe |
| %ProgramFiles%\kindar\kindar.exe |
| %ProgramFiles%\msn\msn9.exe |
| %ProgramFiles%\mui\microsoftms.exe |
| %ProgramFiles%\mui\sysmss.exe |
| %ProgramFiles%\snx.exe |
| %ProgramFiles%\tn_hacker\tn_hacker.exe |
| %ProgramFiles%\uninst.exe |
| %ProgramFiles%\windowsupdate\imjpmig.exe |
| %ProgramFiles%\winmon.exe |
| %Programs%\startup\1a353.exe.exe |
| %Programs%\startup\377f7.exe.exe |
| %Programs%\startup\3852b.exe.exe |
| %Programs%\startup\51059.exe.exe |
| %Programs%\startup\6420c.exe.exe |
| %Programs%\startup\95f04.exe.exe |
| %Programs%\startup\a2811.exe.exe |
| %Programs%\startup\b7920.exe.exe |
| %Programs%\startup\c79e5.exe.exe |
| %Programs%\startup\cd061.exe.exe |
| %Programs%\startup\ctfmon.exe |
| %Programs%\startup\dd374.exe.exe |
| %Programs%\startup\dde8d.exe.exe |
| %Programs%\startup\e5b1c.exe.exe |
| %Programs%\startup\e8d4b.exe.exe |
| %Programs%\startup\f52fb.exe.exe |
| %Programs%\startup\f8414.exe.exe |
| %Programs%\startup\fe2c4.exe.exe |