General Info

File name

svchost.exe

Full analysis
https://app.any.run/tasks/14f5af7e-0a82-408c-8744-86a461e2ef5d
Verdict
Malicious activity
Analysis date
4/15/2019, 10:12:39
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

gandcrab

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5

a14ce13e02dcde656fa78d35324e1cfa

SHA1

1e538aeaad1ed2cefa70b464e29159786b7f699b

SHA256

2a383d56df3b0c729e988395bdae22085767c9d441c6b61404784c9b18d0870b

SSDEEP

6144:D4ulbugtBzlbN2ULhxf9TXOwC+BxroELlabxUPv:D4uQgbpbNV1xfV+wNBeEgyH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
240 seconds
Additional time used
180 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Deletes shadow copies
  • cmd.exe (PID: 2796)
Dropped file may contain instructions of ransomware
  • svchost.exe (PID: 2632)
Renames files like Ransomware
  • svchost.exe (PID: 2632)
Writes file to Word startup folder
  • svchost.exe (PID: 2632)
Actions looks like stealing of personal data
  • svchost.exe (PID: 2632)
GANDCRAB detected
  • svchost.exe (PID: 2632)
Starts CMD.EXE for commands execution
  • svchost.exe (PID: 2632)
Reads the cookies of Mozilla Firefox
  • svchost.exe (PID: 2632)
Creates files in the program directory
  • svchost.exe (PID: 2632)
Creates files in the user directory
  • svchost.exe (PID: 2632)
Dropped object may contain Bitcoin addresses
  • svchost.exe (PID: 2632)
Dropped object may contain TOR URL's
  • svchost.exe (PID: 2632)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   UPX compressed Win32 Executable (76%)
.exe
|   Win32 Executable (generic) (12.6%)
.exe
|   Generic Win/DOS Executable (5.6%)
.exe
|   DOS Executable Generic (5.6%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:02:11 08:57:37+01:00
PEType:
PE32
LinkerVersion:
9
CodeSize:
229376
InitializedDataSize:
20480
UninitializedDataSize:
94810112
EntryPoint:
0x5aa3470
OSVersion:
5
ImageVersion:
null
SubsystemVersion:
5
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
11-Feb-2018 07:57:37
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000F0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
3
Time date stamp:
11-Feb-2018 07:57:37
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
UPX0 0x00001000 0x05A6B000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
UPX1 0x05A6C000 0x00038000 0x00037800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 7.66173
.rsrc 0x05AA4000 0x00005000 0x00004A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.74915
Resources

No resources.

Imports
    ADVAPI32.dll

    GDI32.dll

    KERNEL32.DLL

    MSIMG32.dll

    ole32.dll

    SHELL32.dll

    USER32.dll

    WINSPOOL.DRV

Exports

    No exports.

Screenshots

Processes

Total processes
37
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

+
start #GANDCRAB svchost.exe cmd.exe vssadmin.exe no specs vssvc.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2632
CMD
"C:\Users\admin\AppData\Local\Temp\svchost.exe"
Path
C:\Users\admin\AppData\Local\Temp\svchost.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\svchost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll

PID
2796
CMD
"C:\Windows\system32\cmd.exe" /c vssadmin delete shadows /all /quiet
Path
C:\Windows\system32\cmd.exe
Indicators
Parent process
svchost.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\vssadmin.exe

PID
3472
CMD
vssadmin delete shadows /all /quiet
Path
C:\Windows\system32\vssadmin.exe
Indicators
No indicators
Parent process
cmd.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Command Line Interface for Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssadmin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\vss_ps.dll

PID
2332
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll

Registry activity

Total events
60
Read events
56
Write events
4
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2632
svchost.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2632
svchost.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1

Files activity

Executable files
0
Suspicious files
424
Text files
317
Unknown types
7

Dropped files

PID
Process
Filename
Type
2632
svchost.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Videos\Sample Videos\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.ptnlie
binary
MD5: 50c9313038b6759ba636f3bebbe82125
SHA256: bf0c8110eed719c7b9870f696c0827fea65151128849fabfcb87d28b027912d6
2632
svchost.exe
C:\Users\Public\Recorded TV\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Recorded TV\Sample Media\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.ptnlie
binary
MD5: a6fc4dbd15f31b8ab741f3584bfd236d
SHA256: c7d519b9505df2fad8fb7d86003017658a66db298ce3d3f8a98c1bd03541c340
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.ptnlie
binary
MD5: a45c4635c83bb7fb0237956245ab2904
SHA256: 1b04f49399b40102df4f575f31c5bc432078ea398679839502a4fc652301b2cf
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.ptnlie
binary
MD5: b5d00df8b99b41c797cbf429e4004e6c
SHA256: afe128418c749014964994a68dc9f92f01835d172fd166b06d2964ec148a86a4
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.ptnlie
binary
MD5: 53ba7627fcf244d7bf57b33aed48b435
SHA256: 4c6532638d5716ede24b0df27c752e6295500dc1928ce6915ede6654beb42936
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.ptnlie
binary
MD5: bf3e52faf8743158738d2a023f15fe6f
SHA256: 24157450cdd4845b6d641dc6f700572746d041bb6e83bcfe8607dc97df3933f3
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.ptnlie
binary
MD5: 8b7540882c2d4dff50a6e797ff155c2a
SHA256: 8bab2ff197f1c72925ac9a1c0d2d22700a7c3b137c1cc98ad9c3590a3fa1b3b6
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.ptnlie
binary
MD5: 93ca3b105cc98820ed13b0b8d3150102
SHA256: 9799d8888505eed43bf2caf44df61bb10163b5d9774b350d56fadd57c8251c75
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Pictures\Sample Pictures\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.ptnlie
binary
MD5: fcce213dc16896ac70a8760b6b381b99
SHA256: c8ad45b68f9b41fd1ae3d467583af7e5faf5dc5f6d66edb9d4e27657ca1ac982
2632
svchost.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.ptnlie
binary
MD5: 3d94c674ac9c1d33f6b6242dab1b9dd0
SHA256: 5a50542c9b59a3cf1304c0fd449c92133c83d490a203afc96f29a459f1da66cf
2632
svchost.exe
C:\Users\Public\Music\Sample Music\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Libraries\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Public\Favorites\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Videos\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Pictures\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Music\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Downloads\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Documents\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\Desktop\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\Saved Games\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Public\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.ptnlie
binary
MD5: ec027f5dfe2ae66a2655b3cc67ab1187
SHA256: a91524a085d146cb7d491b7eefcc677abe12486e1150f54e4b00c293c4aca9c0
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.ptnlie
binary
MD5: a2cfd400c9d610e96fcd4a0719ffddd8
SHA256: c709144e4313f7c911f3e75ea8ed07af68ab5d714891bc9ce18d35ca90eeccff
2632
svchost.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.ptnlie
binary
MD5: 0cb6efdb9ba98bc25236c288e857c731
SHA256: 5d7a1ec816c75cec8d094399cac924b3c175d1b767db62666a6d92578c44ae4d
2632
svchost.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Default\NTUSER.DAT.LOG1.ptnlie
binary
MD5: f67c23bf01bff98ed11defbc3c7e4f5c
SHA256: 6c46edb424a62642e95f95ccf8b44c531cae1fd3d3090f1cb2d4f7f625ecb520
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\NTUSER.DAT.LOG1
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Default\Pictures\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\Favorites\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\Downloads\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\Documents\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\Links\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\Music\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\Videos\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\Desktop\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Local\Microsoft\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Media Center Programs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Local\Temp\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Roaming\Microsoft\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Local\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Searches\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\History\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Saved Games\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\ntuser.ini.ptnlie
binary
MD5: ca70be71ddb3ac9998cfc46f0c956a58
SHA256: df7f7859c75408d2efda879e945125c25fa9407c8ea6a56780989f576d50c50d
2632
svchost.exe
C:\Users\Administrator\ntuser.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.ptnlie
binary
MD5: 8fe227b8fa2d8206280fc26a227f730d
SHA256: fe265940c526816dc85e4bab2e16a79fe8f5908513428c2f625d652908e9bbc3
2632
svchost.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.ptnlie
binary
MD5: a4c771b874817301689a70ebde213cb7
SHA256: caa9ed2cb24dffcefe6f76ae59c210b738fdf3f3de415335fea32e3069cb84a1
2632
svchost.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.ptnlie
binary
MD5: 3d08b5a5b9ccb445a6ed7585f9395729
SHA256: 84ea5b76b95087531439c65e3946fef127688fa9115916a321b6cee29b723e5f
2632
svchost.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\ntuser.dat.LOG1.ptnlie
binary
MD5: 6fa1cf0894b8df68c415bc80ba261261
SHA256: e1bd369e9501ceb39a0f4b9193507adf3e51668f31795027051074ced934fbc2
2632
svchost.exe
C:\Users\Administrator\ntuser.dat.LOG1
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url.ptnlie
binary
MD5: 6b0ef0bc9b8e75346c97b765de1ec345
SHA256: b95ced0da8f947e75fb28cc49b7e6f902807c0f7a2a6c0046967a55b627da04b
2632
svchost.exe
C:\Users\Administrator\Links\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url.ptnlie
binary
MD5: 728f85e6dd38aa1a313562f5d8b9afd1
SHA256: 8fe30911b70fb5f74fef71f2cf8ee41e72bbe2055309ee5ebdffa8502bb141f3
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url.ptnlie
binary
MD5: dcced5daf855dc042542cde63b3cdb23
SHA256: 283091148ad659d5f10aea25ee9c382e795513b221e1ba9e36162285a02b0173
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url.ptnlie
binary
MD5: 6dc7f585ff0b95beec3fd49b6978ffa6
SHA256: 6f78dbc70d301252c3eff5aee702661bc10a53cff17e62dcfb807a834b48da55
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url.ptnlie
binary
MD5: e37a9fa80de92b5a4476ea8773144879
SHA256: e100cfac211efc85de5811cc7a5db0cce5e406f2599c4c82957be7af41cb35a2
2632
svchost.exe
C:\Users\Administrator\Favorites\Windows Live\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url.ptnlie
binary
MD5: 6f173c2de955266e2628dfd79d182dbf
SHA256: a0e3d724d7e25b832acd2182b6ab76748d7d06c42e6163dc81e31ebfcd7f2df8
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url.ptnlie
binary
MD5: 28b2a7ec02e89a23e8764c926466aba7
SHA256: 29092ad654dd723635bd55585823c663d27247f4f8766ea186c8bbf0679d007a
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url.ptnlie
binary
MD5: 15ce7e5f47ae0d65c41966dc55e2db05
SHA256: b608f7ed4b7194981ee4a3716e43ac3b204c7dcb2f12e008a69ac28c7f1833f8
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url.ptnlie
binary
MD5: 758a096e40272c5f9bd6f8a8cbd0ff67
SHA256: 26c06752487794cae0a62395261f54057b52be54b1d61a5a8dbd518bfaf6b89d
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url.ptnlie
binary
MD5: af1bdbd1ec9914ccbff1ae590b1c65f1
SHA256: b6998bf2791213cca7a5126ce79216c7071fbecfc26930b48bce2b4715a6bda9
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\MSN Websites\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url.ptnlie
binary
MD5: 06bac4eb37d5fadb799086e5d1590375
SHA256: 028c2efb976279291a023251fe9b76a4d28058c9af20958e5c6ae030a329025d
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url.ptnlie
binary
MD5: a457c2e5cc26432736908c850fd132e0
SHA256: 37b4d48fd40085283cee79d113786fb5abdbadec516c43cb6c524a8ed2645ee4
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url.ptnlie
binary
MD5: 3f1f624d5c138ed83f88faa14c4ff6a3
SHA256: 01c15b279da896858eecbf7848dc8c2ea955079491c52160318d8e63963439b0
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url.ptnlie
binary
MD5: b529e62db7f66ab924ab64c6f13f0128
SHA256: 4bcf4291595a0c33e5299a88511ef38a20592a096646da5fdf3f1b013593a169
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url.ptnlie
binary
MD5: 5672cf658e801c250fac56bfd69db2db
SHA256: df98a666c573520a8b84f49fc060d8ce5a74b6caf18c5c426837d7600cf6be4f
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url.ptnlie
binary
MD5: b9062adc4d88cc6a1ee052cab15cdb45
SHA256: ddc824daa2f7a1fab4f1f8efa24072b698a9365388fbd9995669f14c4b1be537
2632
svchost.exe
C:\Users\Administrator\Favorites\Microsoft Websites\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url.ptnlie
binary
MD5: 2061fe7c31aed2a13095bf6bc067a383
SHA256: 7feadeb7a562bf648b0f16a92c4e117a5f06d18d6accee2688bd3af3d7bac1d8
2632
svchost.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Favorites\Links for United States\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url.ptnlie
binary
MD5: c771cf527c351bd643187bf11186f977
SHA256: 2a8b1e03f2f4f91e767e2fa0e09a75d178912f69f4c8c2b17dffa0e0313cd065
2632
svchost.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Videos\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Downloads\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Music\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Favorites\Links\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Pictures\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Favorites\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Documents\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Contacts\Administrator.contact.ptnlie
binary
MD5: 453031e8fa6703e904031f092e8fac8d
SHA256: 636c7e0ccd1934fe29c5cfbf88c862228f862c6f4de5eb39835b9bfdb0dd6f05
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Desktop\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\Contacts\Administrator.contact
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\Contacts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred.ptnlie
binary
MD5: 19774982c413b884919de5b4b74f0ab3
SHA256: 211fbfaff6fec53c9b31b2a40ea4b4a75f872e18d09eae142b64c389bc9f5fbe
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156.ptnlie
binary
MD5: 484e99a0bacc4c6236b3c9f051e06c14
SHA256: 0fd946bf3ca3b192b650b955f0d861b75d3b7e38c80dfc32dade36624be64e96
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST.ptnlie
gpg
MD5: b0a67e44df1b26a83d04d49185a9468e
SHA256: 27665b2134347c510a86d0c2ae443c0ea331988da8dd62efc8dc2c04c1d9565b
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Identities\{BA2162A3-2F32-4850-8D8C-B3C9A2AA9D43}\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Media Center Programs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\Identities\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log.ptnlie
binary
MD5: a809a287589c7ffdb54023814f4ba786
SHA256: ab72252ca563599edc2b38e669f194f20d3c6731719b6c69ab3c6050c8ff5669
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Temp\WPDNSE\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\LocalLow\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Roaming\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Temp\Low\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp.ptnlie
binary
MD5: 2cac83e82a56cb47ec30d831ac692bf4
SHA256: 35d9f4367fe60305f7d5b38b0e899a8cb01b7fa63ac0d90ff9b5fe0b389d00d3
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Temp\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini.ptnlie
binary
MD5: 536a51f62babe50428cdb2e27036a638
SHA256: 001f433cbb78b079796a0cd3fab87ab90830ebb963ff713093244b83b88c2c4e
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML.ptnlie
binary
MD5: 7252d07a8cd146432164c10c79f9b6df
SHA256: b0402a8b67f8506ccddf08bda39d9fa25cc68e6a850bebe000b59a5b4de09718
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Gadgets\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD.ptnlie
binary
MD5: 2ddc5bd5f1ec6d89a0bbe41d69ad5a96
SHA256: ffa8a881f244a1583cb8ad5bc23e455fb7c523dce798e9373f7f3fcbb9a7de2d
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat.ptnlie
binary
MD5: f51214f97e1574c49dacba41e0f17c42
SHA256: be5207ac62e300aa52a8e3950bbfe0de0fa6678ed8ade0e0945a0dae7c5bd33e
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore.ptnlie
binary
MD5: f2d2f7bcd2f66f556aedbb92b22fcc50
SHA256: e71da923e69c822845e462f8d711fd4f4f0981f91e45f2b94e90c78c6375e37d
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif.ptnlie
binary
MD5: 7431e385840723ee9d99042d790753de
SHA256: 3be68c65689fa691788a2caa094163fe09f88faec9d00c19ca6063591d98bfc5
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg.ptnlie
bs
MD5: 0aa469891177d5532f4c50fa23b9af40
SHA256: d10545f8160e4f34c87bc4884d227509ce974f766e120309cf29fcf292e3cb92
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf.ptnlie
binary
MD5: d817c7c41d92625c1e4f29551c2abbb4
SHA256: 5e39accd040620340ed34330a3d40c23c6a9be47a841255eb946824ab0acdc93
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif.ptnlie
binary
MD5: 1cfb4c8282b0da6a42c22c56b5021676
SHA256: d91c706b2edf88e7d1aa3de334c7866aa5f88ca346c577d5524ecd91aa5f29a2
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg.ptnlie
binary
MD5: 07817a1e5a2d247cba4b60b7f9f6017c
SHA256: 0298b5c3bb42b8008b3114922d93b718d7ad1e81e7641b6b23268331e709a553
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif.ptnlie
binary
MD5: 1b2df9d110970ae7eb55b7dd890a60aa
SHA256: ff8c001b61c22585fd9cf317871f438101ea1ca36ed5f2e0379fbe5bbfb4df48
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.ptnlie
binary
MD5: a1384709a6b987d1d125244b5ed7b0db
SHA256: b261692c9838386cbe4454cd0f02409f6ecf042bf00610fd117d2029833a8433
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm.ptnlie
binary
MD5: c6e59367c469cddcfa20a027e9b228ee
SHA256: dcf5bc73d633f99f6703712e2433dc8e05774efd66e0fb9e149b8c4ec11509aa
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.ptnlie
binary
MD5: e38d4dab828da547f30e1e033d99f113
SHA256: 3cd3267f651445221bf91638dfcbb7f26667935bce286e740cb79a00f9efb5ec
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm.ptnlie
binary
MD5: dcd2c5f342e884ae80d8af15bf41458b
SHA256: e45c5b9e88b259f7e5f429fa2589540ecf0472660f476209c9b479d13d541af2
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg.ptnlie
binary
MD5: 72f95b96a49a0f2c09dc5ae72b4c38f0
SHA256: dbe4eb2fb040b3c7ee6c6e67ff5f1de75f1e489b9bc1bd3ea27a68a127775a46
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf.ptnlie
binary
MD5: ee39a56ad7c9586e3d0d366c54b0970a
SHA256: 46f6de9344f7c25b22b04afcdb17c1517af7f2a9d089bf27c8c9063dc0ddb5bf
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.ptnlie
binary
MD5: 59873fa23ba7697f7a450e3e65dc34e4
SHA256: 9fc6cd6f7c2efdf25f0728e994625ff9ac5406c78076b67b130940e403e47c60
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm.ptnlie
binary
MD5: 4e457f6c4075a1bcec5117cb9c8b1327
SHA256: f20e2269c52f1c770507241bd52f769f042cfdae8d351f94a11d73a6ae07279b
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf.ptnlie
binary
MD5: 6c6fdcb2f0578b612e1a40f030ca6bdc
SHA256: 7fa46837dff17abfb6185d5e1952d6cfdd0669659bd2b7bc6de93bd4a69c0f6d
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg.ptnlie
binary
MD5: 81d539bd640a89fe0216f2ada9e19f59
SHA256: 1aa9b67c63095868cbc49ad325dc8d7de32ec46df3d7a3c46a3d59494b23a17a
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.ptnlie
prg
MD5: 1d25aff341c3795cffc3734404a6098d
SHA256: 37863c27b2ef5a2dad61574f03ee1c987004c0096e10ac4afd2b1e4aaef56859
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm.ptnlie
binary
MD5: 8fb390ecf61f5f94fdeb70af52bd81b1
SHA256: 3b50388be3d1eb5b15b7317f3f6d13440003dc06e780e45f0e906730beacdb91
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg.ptnlie
binary
MD5: c3d72882f611b63879324d10de150f94
SHA256: 7c77b65e788acc55c57d2604c686ed7d002d4159f851f775842ebf16b316fa42
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg.ptnlie
binary
MD5: c7e787204587522e8c3524ad8d0bd8ba
SHA256: 258f6749b854b9b37c64cd8bdf270ced0781431c87013b5bbfce94dfa800e257
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg.ptnlie
binary
MD5: 779af77592e3016e250e08f5473ca373
SHA256: b782671bd6202f29db70e3e4a0c7e7fbe04ec0134a55249551d0e8e80fb7db55
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.ptnlie
binary
MD5: 349666a3613f389518658282dc806406
SHA256: 11a7e88a2d567db65479e475aafce0b55828d940f580c6502b5d01adb719e234
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm.ptnlie
flc
MD5: 55bd0850532c2a74e6ffcfc970dafe05
SHA256: 1fcc6a6d54f901e6041a5d7e839b8739a38dcfb78b304c9d67163f93c6329132
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.ptnlie
binary
MD5: e9a774d54fb5486adab08a77b36fd21a
SHA256: 0dab169e26da732eb6e40c1feb51d8efddae0657d781eb06868be184de9683ec
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm.ptnlie
binary
MD5: 7b9467872522f215c83d9c9cdd6d479a
SHA256: 67c512fb6c84425182807f8178d02961f3cce76913ff36da865749cc515f5acc
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg.ptnlie
binary
MD5: 68a7b957a2b061900974fd0d4beb0b7e
SHA256: 34aae5c3acbb0996d04f353e22e690ab01f1900f3c4b52a1e7fbae1d80e14db6
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf.ptnlie
binary
MD5: 99500508fa8dd35ff04bca791575f83f
SHA256: 806eaf0ec44fbaf76a1eee1e9e1f6133249f4c4c922107a4cb203d35828d6fd8
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf.ptnlie
binary
MD5: f84ec8fc27206d12c492f8004721d20c
SHA256: b4301a9350cce11cd741b36068298977bdc39576cbb230fe60d35474539275bf
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg.ptnlie
binary
MD5: ed8cd9e2d3225e68f3a015e5f92ee3d5
SHA256: 0dfa8a77b22c7c01ce0727fea696ee06431ec3f44392ad6b92f960de7e1c1802
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf.ptnlie
binary
MD5: 1d1f02f8bd9af269952c70f244d28bab
SHA256: c6aa2b65b6558a582f30fd9d29081c4555bf1c8f664108cc7c6a2536e6615bad
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.ptnlie
binary
MD5: 1418f741ff856a68f00b2c82ef9672ef
SHA256: f7a1207842db4dcaf2ab9781adb6609ce16936713e01082c72671dfb12f18422
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm.ptnlie
binary
MD5: 1cf3b24500769e9a4601d4c0a633c47f
SHA256: 693802773aff4f52de458d89e1f8d9eefa64d10b0aa0752322614b0f72b05f92
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf.ptnlie
binary
MD5: bb2c6a6b6e7d36ea0ab8f18206250e3f
SHA256: 5a2e4de10718fead9ca1e101fdfb36c3d97923385f79d4a074fd17d8af7d7b4f
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf.ptnlie
binary
MD5: 0ba70f6d02c8c9aced8ed0b0a3e5861d
SHA256: 17856112318719ac8aae8b2ecfc5f33eeaffdd0c4ab373ee80f7ca62189d16fb
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.ptnlie
binary
MD5: b3447cf9f8785dd374b3d04746868a45
SHA256: f7f63e28c90213f65a893bd0663ff2c016da1e93ba3fa7df8baae54225c22336
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm.ptnlie
binary
MD5: 348844fbbda4c5682e5d5aa135abced7
SHA256: 0ed5142fcce5ff6e969db2a5d491089d1287398f58e9fbb36e58ab02d1619f2a
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf.ptnlie
binary
MD5: 8dddcef5fbc94e99e59d4bbc3256003a
SHA256: 697e4284bb775b03c2460cef357c76a64d91f660216c0c33860bc0dd914dcea1
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf.ptnlie
binary
MD5: 4fece8a419fc532064510a039d18959f
SHA256: f579710e17b1d7792771402c52becf8a0c5011c019f07b7aa7fbb792e2fc8486
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf.ptnlie
binary
MD5: 4540956f29a19c342416bb88373e7706
SHA256: a18e6b2f23d4612586b09b92fb79ea7cb4a73c5c3c199d6692e2d7571150d548
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.ptnlie
binary
MD5: 2301ed3cf11c5333ed183b780a893800
SHA256: 9a6c63049a48fa027420739e8956092cfaae60561824295edb170939e3739f7e
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf.ptnlie
binary
MD5: caae7c2f9a5c29a3cfa1f300c0d46976
SHA256: edba411fad1be6fd7b9b0dd3f40821ad7651b2fd24e8e12174933bd78402ab77
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm.ptnlie
binary
MD5: 05c368088757cffaa00808bc5ec2e721
SHA256: 56217a519212cf1e6070c95e699f62237eed37c74ab2ab9b7f5db606b2b9e3ac
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif.ptnlie
binary
MD5: dc18320bca5b046f9c79ba7ac27e6a26
SHA256: 2eaa1f4c44bc8d0e44d3206bb9bf1367f822451294c297e1582aae7557eeaf93
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg.ptnlie
binary
MD5: 9b9ceb4cb1247475a61bbdb2ba24f990
SHA256: 2eda3a9bcbd1a2e1f83bdbd39fe941c9b19eced8c3e9ec5d03354ddaed5837da
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif.ptnlie
binary
MD5: 48ac0a3b9a1335f7173410453f16bbe3
SHA256: 44ecdc8cfc1f46ed5b9bd393cfffcc53eaca91129bd19878744d3d0024172a30
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.ptnlie
binary
MD5: ce0e5d0430ae8efbd67fdf87368f2fad
SHA256: 20484d5ed7936f5e3629d15f8633efe7e8af6ed4e9c701eb7ac901c04e3690c5
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm.ptnlie
binary
MD5: ecd7d6dca537dae2d14a26bb79636255
SHA256: 06b299f78cae5a3150fb91d3feacb5cb0687f890439c14d3f9b79d271600240e
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml.ptnlie
binary
MD5: 4e5149b4877e51a89ac18d42bb1993fa
SHA256: d238eb80309415b1f6721bee5c53f6cd15f0b8164657c3745671ffabc54130fb
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs.ptnlie
binary
MD5: e3173970d13b670352616cf758ec04e0
SHA256: dadebf07e0c3ea03a3e037abf2ca7ec385a5d3a1187728d3a6fd35f7b71b5793
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs.ptnlie
binary
MD5: 2ec811d1de852faa8baff1547b7e63fa
SHA256: 2499c961c2304612c858072a701b0e099e8666ef2b614a0b9a78dbbfee262fa9
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log.ptnlie
binary
MD5: ac494e33c3037b41d27cb2af518d07ac
SHA256: fbbe5fc43fe32af7e50b54ffe3391dde8da5843fd93818fd623b32aa3d1012cf
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log.ptnlie
binary
MD5: f4ed521b769208bd82707db695de34a4
SHA256: 1ae2fd45b76de1ad747e6ecf987417436b69e5419a7985669657416a23e26cb1
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk.ptnlie
binary
MD5: ae61d76a126c40bdff3f59fcfb87f4e7
SHA256: a27c32e562c5304239654aa6518ae4b09f6a3d57454b0b7b05f2a0b48b135cb4
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat.ptnlie
binary
MD5: 4e55f810956e6b230124ac115bf76412
SHA256: e19de3eb0f40e1b98673e6c71158163710c043893c168fb441303fa6c0beaf25
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore.ptnlie
binary
MD5: 0653344d039ef4ba75347c268c178100
SHA256: 81eeb1f532f5083cd75d8266c6e4dfcc514dc0996409986d79c5bfd209fabc60
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log.ptnlie
binary
MD5: 40d40a303199bb9bb8b9ddf9928709ba
SHA256: 14e1d07bff26241250daec32ad3055c8d259d4d43181b3d00974e184bb09e25f
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount.ptnlie
binary
MD5: adc87f33b70cd4cbb4d553971297848e
SHA256: 3150ceb4e5df2474b840d63b9532ddae30ddc72f99a195ffcbd02caf7f3f02d4
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount.ptnlie
binary
MD5: 7b98c864dc01449bcd1e72d17ad46f58
SHA256: dc742fadb10e022d3ba5f948c084bb7d486d156001e7077cb02f39d45067c7aa
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount.ptnlie
binary
MD5: f2d24700e51d8a869aee7ba4f1b1a84b
SHA256: 318fa92853d2d38857f8faca5270020ab795aa1c15b7e8e30ddd6055e443e2af
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl.ptnlie
binary
MD5: eca29b3931b0588fe71d057042c6239c
SHA256: f34cb9ae4b13c9cc341f72ef253c56d8d2585baa65ec9117fe7405d31cad7102
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl.ptnlie
binary
MD5: 5573da22711591c5f8d589e53480fc74
SHA256: b082d75a36a89bbbeef829532cc5468e60dc87dba1c5449b4b7122b650c17ecb
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl.ptnlie
binary
MD5: d81c00856d7fc4c1d0da1d96aa3bfc08
SHA256: c103419aa183430527ae6114e69f3328ce98f93712795b398e4d502f761cbdaa
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl.ptnlie
binary
MD5: 95ad9ed092516203aa261764f9da4143
SHA256: cc539be8d63991f2bc56a875ebc0ddc333268df7067a0bc4ee8f3cab755666d8
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl.ptnlie
binary
MD5: 1ffe445eda06c7c424d12d6ec8c51db1
SHA256: 5e4e4e1819e764b0e064665a8afe8bab0775053c6cd6bffc1d0d78cfd9e60ac7
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl.ptnlie
binary
MD5: 2b3aca348095205d356cb61f98b44815
SHA256: 6cbefa2d10a88bddbe936b55186878b45ec8a133ca3acad2b09ff7f826874032
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl.ptnlie
binary
MD5: 6251753d00ab8da91e32985214ab158d
SHA256: a6ba093bdaa76a05efa77be0ba19275d3790e3d725cd8ff54981f65888c735fe
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl.ptnlie
binary
MD5: b83d6daa1da0f2a18de9260650ef6295
SHA256: 9edfce2b6c08ea0c0c4b025793e5d22f460a5d63192e24b9b92172bfc9242c19
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl.ptnlie
bs
MD5: a08ca8bddd9f66de735fe91b969b076d
SHA256: fa5e92f989e213065d1db7ce16e76faf0e191cabe41a7824b9b5391ac808598f
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl.ptnlie
binary
MD5: ecdcdcc012cdb9f59aa9264dd63806c4
SHA256: c5360b7720a1254d4e9d8da35dd512f54aa93e6103df1c24935ecaa929194e97
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl.ptnlie
binary
MD5: e7f33d5ce6bb2e5201dbe583e0c778eb
SHA256: bc9ce34d7be3689855a78730b05cfbd7ae3ac57b37908dc9b7bc419afb5ff5f1
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl.ptnlie
binary
MD5: 090b0650b353f9133c96e0c164777339
SHA256: 03e96c5da2d23f8b9f17de35dfd34c0918ee99e614512c1238f5e824c408478c
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb.ptnlie
binary
MD5: 50ba8d3f8ab349a1fc804c640e175b5c
SHA256: 22706371d9c0f64df79a77b087522efe81331729dd612217a90492af4623b3cc
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb.ptnlie
binary
MD5: 94a4ee4d5b40223c8a8423565ae28cc6
SHA256: c27504ed7a2f361c867794202c66bd23b07d39037d41756ad8a1a6c98cdcb4ed
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.ptnlie
binary
MD5: c715f051e102bb8873f5234a0f46484f
SHA256: efbd0e462f4d45e3fc3f98d4d87da53bf58644d316f18e7237282f65624d8606
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat.ptnlie
binary
MD5: 73064c459e2fce30ba03464f8730694a
SHA256: e231b36ac278bf18f0e6c3535fa4c3abe073f892fd98f786d508f66e3e7ec322
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\VM3JD5NM\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\G4PHTCUR\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\HPSK10OB\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\9RI45C46\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms.ptnlie
binary
MD5: 97614034f2f0e428a3ab803bb680be4f
SHA256: 77cf7eaeb5a140851e4901401046bc418c86b4746c4864de49743fd25b80dffb
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms.ptnlie
binary
MD5: 15716e4efaba5d3d35d989cab01f1f23
SHA256: 305a8c11e3e1a58ad027e048908ab7e13733636f5bc2db23b4b01efc2eb80fe2
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms.ptnlie
binary
MD5: 536f3428049626e261837a541116487d
SHA256: 3333b85308099b89e871a8afc14bc0ffb0e4cbce2a8ced535847ae254abe1ca7
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms.ptnlie
binary
MD5: 6827ab1dfda8f549d731777d83b55d15
SHA256: aa0c49bb7e8058dd2245e3bcb1a1f52596a3194884addb971fe14587662db0a7
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms.ptnlie
binary
MD5: 7c136e082e4ecd12228e11ceb39f46ef
SHA256: 3f9c26ec885ea6f2103c06deef12830ade7c4acb177d4bf978a9c9395d69dd52
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms.ptnlie
binary
MD5: 7f121d12efeef67865d03dfcdf2c65f1
SHA256: a16a24f114a982c8c6e445d26b579b642bdae4553e15e64dee8fc66f3439c053
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms.ptnlie
binary
MD5: f367392ac1c0e19f13d4bc4f4e84ffcb
SHA256: 99aa9634ca12ebde5a6d44d401beb9cbb8a92898a44d6f9b6fe183004ee57113
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\History\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\Microsoft\Credentials\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\Local\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\Administrator\AppData\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.ptnlie
binary
MD5: b09647fd105828707af2613373edd435
SHA256: 960314fe319eeab394ef43364db52f786414cabaa810d18d783a92037dbf98ec
2632
svchost.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.ptnlie
binary
MD5: fb5f137695667edc6d01d5035a8c2413
SHA256: af812a5b959a7a9d74af5c6c5db855a0b65e94e6c4970c2415780f101cabc07d
2632
svchost.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Searches\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Pictures\washingtonhowever.png.ptnlie
binary
MD5: 5beaf72d2092797957dddf346ff3c0dd
SHA256: da133fbaa97934454b912e512c51bde53ebf690c8b3a685693bb9e33c57a354f
2632
svchost.exe
C:\Users\admin\Saved Games\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Pictures\washingtonhowever.png
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Pictures\heartapplied.png.ptnlie
binary
MD5: 2f7cb4757736f227606afbd4933f2083
SHA256: bbbf3a222ebb59eeef8c6ff1f7a1f9168e399b9dc9986492e70e61edb583d576
2632
svchost.exe
C:\Users\admin\Pictures\grantmedium.jpg.ptnlie
binary
MD5: 7b61a31ee5e2136efdb08d4bd37a61f4
SHA256: 7220ccc8efa8936ed904eda6536db1f6c10851d18e38d7f877b8e0ea8be7c719
2632
svchost.exe
C:\Users\admin\Pictures\mrusing.png.ptnlie
binary
MD5: 123204274d84720a05cfb9758948717f
SHA256: c8eedec3fc492018f960150d45294f77ff6c9c17ce3e62c88c84c32e0bc6c1d3
2632
svchost.exe
C:\Users\admin\Pictures\mrusing.png
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Pictures\heartapplied.png
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Pictures\grantmedium.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Pictures\amdiscuss.jpg.ptnlie
binary
MD5: a17a20bfacc04943c2b1a3fd97b3a716
SHA256: 1f3fc189bacf2c08ae5e7d69f444e2d762f8095d5a1d5d5f62cda4c7da539f65
2632
svchost.exe
C:\Users\admin\ntuser.ini.ptnlie
binary
MD5: 514384751bd113f78429a2692fbf645e
SHA256: 9958f6248dd1863fe13b4f5fbb04928ca3f62e07cd6f198b72c0fef024bd5f19
2632
svchost.exe
C:\Users\admin\Pictures\amdiscuss.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.ptnlie
binary
MD5: fe09bfcb5dd36e34bf6c9e8b646cb8c8
SHA256: 491b0098e75a30952b4b25b4d5acf433dac4ddaad1130477a73368b2b8e66e3f
2632
svchost.exe
C:\Users\admin\Links\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.ptnlie
binary
MD5: 24404d3ce00281ef68e50fc5af9a1f5c
SHA256: abba5a8a38bafef72a60a3d63a25fbcf46f227a85119993b7b7b6be3f509824c
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.ptnlie
binary
MD5: f21ed7e75dbc2185129245645336bd75
SHA256: b1e6f8e5b4e51e1d9d3ecb5ac6b1472a11a5006e6dbf7af7dbda7ff25e1759cd
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.ptnlie
binary
MD5: 6352cc402ca630f986cfe1e1f39c58ae
SHA256: 00da00c6e1d480b9da810e626ddb684a63d5998be71111d50e75f93941fd1c30
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Windows Live\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.ptnlie
binary
MD5: d5c430028dc6017fc260d7303c5f19fe
SHA256: 0082d6746e327cac68c3e9355b6d3ec6e84321982f3fd882d9c1266444373b30
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.ptnlie
binary
MD5: dc3f0cc4ac4758c3034c5408bfbb215d
SHA256: 519228471db35cb250d51e895a2d5dfcd5a50f4f41b7a97867b2fdacd5abcc66
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.ptnlie
binary
MD5: 3f1cef249fd89a821031e7d919972f92
SHA256: 6609f425878117446bf4d237887b004a313986933b8a385124ea2bb1b3c9c1a2
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.ptnlie
binary
MD5: 1465c22c63b602de77322ae54b10d811
SHA256: 4139ab0aaea95efc3418345017a18045609f27f1a308e8fece158b0762da745b
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.ptnlie
binary
MD5: 030dd5a9755cbb6adffca50dd6a10ea4
SHA256: 264ea357954e0b712e456c0cb9a2abbec47e83ffc208f0c05be1e02a929de926
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.ptnlie
binary
MD5: 72c308ac3ac2bbbaae53bea4ab32c6a7
SHA256: 5e146acfbca77643aa7a9d6249fec693f95bf3752503d87735070b901e62336e
2632
svchost.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.ptnlie
binary
MD5: b158791b59d552ceef9667c94022483c
SHA256: 5021f78c60312a80bd42c4babcf2ddb4129bb692bb59032586327dd9de0c65c7
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.ptnlie
binary
MD5: fdb29470467edc4fb9c69df5f45ac6e0
SHA256: f35049da2471fb80d6e3bda41713bf6bb1236c8ce226f3d9272c6cab083727b3
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.ptnlie
binary
MD5: 9ee1e7dbc9db0c88ae81e2c5058acc46
SHA256: c7abf5f6d08789dc8b377dd8adf488bb8f0af0fe374c5a9386d129fefa0b4d30
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.ptnlie
binary
MD5: 082655f8b5fe5df86fc54196788fe249
SHA256: 86e5cf507dcf26133a96efdf42ea0c66e44620752a67fc860ed53d85b976c000
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.ptnlie
binary
MD5: 6e2ee0066d3bc706b3be9709a12d28b7
SHA256: a6b79ea11b5e71bb60875cb042ad7d242128b07321542df922b6b43f9fab77fa
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.ptnlie
binary
MD5: 1f0f297809b8cc4ac9b4e21c2cd63600
SHA256: 3cd5c7b2325405dc9f3a2f8bfd3f93c142149547ebd0cdd35b6bef9919bb05c6
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.ptnlie
binary
MD5: 78eb7a055085ee9a257846a3c9e8f328
SHA256: c3a4f8d23d52cee1bdfd05e49efd2fdd70c17010196d1da2ee9428b9fa31c239
2632
svchost.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.ptnlie
binary
MD5: 34bc5bee3c69453557dd68769aff164d
SHA256: 81cba7a6927d3b3fb69fd9681c0c34fcf9e926fe419b02754496a6e543a7a141
2632
svchost.exe
C:\Users\admin\Favorites\Links for United States\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.ptnlie
binary
MD5: 4591cc99982af15f880be7f69ab5e96d
SHA256: a532b351483b4a304329f32bd301748c0cdde0d405ed014fb94c355aedc70e69
2632
svchost.exe
C:\Users\admin\Downloads\meetassociates.jpg.ptnlie
binary
MD5: 07b48b8259762922c78a52ff3e66a5fb
SHA256: fd0537fa0b958b258960209d565d77ed06ab0034f47839302911c49cc9b2676b
2632
svchost.exe
C:\Users\admin\Downloads\phenterminedirectly.png.ptnlie
binary
MD5: d1182d3a609c33ba31d9494fe3d99d38
SHA256: efbca73ce4197380b8a9ceca4d0bd2a60b05c8d02ffdf4c700dd38fbe1712979
2632
svchost.exe
C:\Users\admin\Favorites\Links\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Favorites\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Downloads\phenterminedirectly.png
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\sportaccept.rtf.ptnlie
binary
MD5: f8b000d2db56b47af3d1c05dbd4618af
SHA256: 226bfa4d31cb1532d4f137ec485156255725284609d7d43b724fe5e61823f08b
2632
svchost.exe
C:\Users\admin\Documents\sellingbody.rtf.ptnlie
binary
MD5: 16e352428c16cb2191491032d928cd97
SHA256: 802ba6167e2a7d6af1f6977c5472d84e2ecabba46d8e4d4f5c862fbf6ff453c1
2632
svchost.exe
C:\Users\admin\Downloads\amountitem.jpg.ptnlie
binary
MD5: ab32bec47d2442e0dfc8c19fe899aaf3
SHA256: 3fbb4aab016ab7a4e5f440e96bceaa64bfc201cb62a193b083aeb13c15ba348b
2632
svchost.exe
C:\Users\admin\Downloads\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Documents\sportaccept.rtf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\sellingbody.rtf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Downloads\meetassociates.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Downloads\amountitem.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.ptnlie
binary
MD5: 32224c375a822df82c66a6027bf280f6
SHA256: 28a3577de66763c721835678a0251b7e00fdaf599d2f1e5526d7a6a2872ae395
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.ptnlie
binary
MD5: 796168a6319bad554355abf435a24e95
SHA256: 5db1ab197d3ffa98b9f769189d639cf22903393c80dfdd3529ee92fefb28bcb5
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: 59511cc0be6b5ad6dee81d349cff882d
SHA256: 91970f90516db1b75911a4ab0629b4e4b2ea9f02e22ef85af28f43f8b462c2da
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.ptnlie
binary
MD5: f2586ede942db44cad82b2fb084f3c0c
SHA256: 66258749a2923e534b0f74902e64e4f3c31cbf844ffd54fc4941ea92f11900a0
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.ptnlie
binary
MD5: 0c4076022cd46aae3836c701facc594e
SHA256: 6d466de7aa5dd73ea4769fe5e934df5e6accda9588f13a651943caf4befd971a
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.ptnlie
binary
MD5: a08eb94a3f789036a2e8179db071e19e
SHA256: 3522ee4155d60fa5d72a88e490814fb74c5a4607c3fb0d1107bf5dd3ad621ce9
2632
svchost.exe
C:\Users\admin\Documents\Outlook Files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.ptnlie
binary
MD5: f8d1187d660166ed1be059770f1fef65
SHA256: 85f78a1a83f7ad4f9ea9090590e16fe0b4e4e14880ca7907301b0c564cc8b3d2
2632
svchost.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.ptnlie
binary
MD5: efbf32111c43869689a8417745c0aa15
SHA256: 29c1cd57c0fa3e16f25138ff9d0afb6458b536843cb4a9e0a771595e5e7befa5
2632
svchost.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\OneNote Notebooks\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Music\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Videos\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Pictures\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Documents\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Desktop\tueart.png.ptnlie
binary
MD5: 6f37ba607807473ecbe6889b53bb54db
SHA256: 6faf3e4cab4fad2b36bbf945f4572bc1954d9eb5b958f45e265a9bd6da4dceb4
2632
svchost.exe
C:\Users\admin\Desktop\technologydvds.rtf.ptnlie
binary
MD5: 2ed927977b7d5ab96b0152317d6377ae
SHA256: 20422c375dbdd5b577e1aaa9c29316de53e9d3dc08211d6f380780f2b897d70b
2632
svchost.exe
C:\Users\admin\Documents\beingyellow.rtf.ptnlie
binary
MD5: 394b1f275ca28d4cd044ddca083e2782
SHA256: 47d03bc85c73c055dfca09445b558981ecccb678d1a6fda6fe6e0091c06a6ba3
2632
svchost.exe
C:\Users\admin\Desktop\technologydvds.rtf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Documents\beingyellow.rtf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\tueart.png
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\indiait.jpg.ptnlie
binary
MD5: 6ae736c76a9c6e844f43e7a0a3f4d085
SHA256: cb0e67163316dd97eb47e3c846191de8da8d72f332750f0ce46290091d109af7
2632
svchost.exe
C:\Users\admin\Desktop\stopcolumbia.jpg.ptnlie
binary
MD5: 36f3e5041c1dc9c24ee7ae67531834d0
SHA256: 35f91662d01076927f85e6b94e96ec6b36d716dfc3ad43d39efdb0388c370c31
2632
svchost.exe
C:\Users\admin\Desktop\japanesetools.rtf.ptnlie
binary
MD5: af99f7d5fd4290f469095efacc26a8cd
SHA256: d6c82c29367ae878da9b4db04d2c38aca32ef50e21c294d64f67daef5fc5e893
2632
svchost.exe
C:\Users\admin\Desktop\stopcolumbia.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\japanesetools.rtf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\indiait.jpg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\fewstreet.rtf.ptnlie
binary
MD5: 5049a20b4879a092c23bc8c516a41513
SHA256: beefc3a747aa316cff6f60869096ccdd044ad910cb702cc7ccc23a76a1ea9267
2632
svchost.exe
C:\Users\admin\Desktop\halfshows.rtf.ptnlie
binary
MD5: 7cc5894966f2baebc27ee1e73c05c962
SHA256: e0f169a40198a1c844e5fc0b8996acf7588693cfdee2aa103a49cc0d21f2b9a0
2632
svchost.exe
C:\Users\admin\Desktop\fewstreet.rtf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\halfshows.rtf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\danceour.png.ptnlie
binary
MD5: 2c8347a26c0f737c744d90ccca4f0efc
SHA256: 5c59d70678d3f45d3068b3e9ab038331e54867de1e95db6f81bdbe26c1c19134
2632
svchost.exe
C:\Users\admin\Desktop\choosepowered.rtf.ptnlie
binary
MD5: ab76af9183e7a1a0876ac7dc27f4ac03
SHA256: 10aefb2ab5a748435363fdfea33001f1803999da36c2442045047a836eda24d4
2632
svchost.exe
C:\Users\admin\Desktop\danceour.png
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\choosepowered.rtf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Desktop\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\Contacts\admin.contact.ptnlie
binary
MD5: 4bd0f987ddb7e1d5a9e0c0bd4623292a
SHA256: 37782e4c4dff8b69dd0fdf05c656f37f10b15d05708674ca96667da8f6eef735
2632
svchost.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\Contacts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\WinRAR\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.ptnlie
binary
MD5: 02bae3fc2c60272befdc67cc76a9b5f1
SHA256: b77392e26b2d9c693a01168a1b2a27e579ec6b4b5f27b0c83ad3825fe1a0ab89
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Sun\Java\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Sun\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.ptnlie
binary
MD5: cfb954bfaa7d890efefdf5944fd7a845
SHA256: 8c08206ee1475b627f4ed69c95cd665f9040a272bde9d764c26858117f90f722
2632
svchost.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.ptnlie
binary
MD5: eb34005945940667f461fe304a486958
SHA256: 57adb228d54f7a4349a6adbd804fb00c3ac19cdebc367e053a8539ef4f4c6fbe
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.ptnlie
binary
MD5: 93ee3d77c5aaa47349de5625a0a00266
SHA256: 1d88e19c54ef69c48bbdba5a40a82247644d350f87466805c7de59a1600b7444
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.ptnlie
binary
MD5: 3ab376794077c1a2cf4a12a6193c17cc
SHA256: 823d2f91d6732d67220d7aff4d71ce7c5023898dadcd6ea4fcf715228e1b6431
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.ptnlie
binary
MD5: 310ee8204272aa6a7cd69ba5b10b91bc
SHA256: d91f574bfd9f87d03eb14982a2d75bf968d842d8cebeb44f6efe1466fc4dfe3a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.ptnlie
binary
MD5: 24098e4f08de912b0bea6c2d858be0d1
SHA256: 6645996a2ff94574360fccc64f8940edfc93e17f5c0cfca132f75560df8d7823
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\logs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.ptnlie
binary
MD5: 27324919279e9699bb2602444ba3a00c
SHA256: 00b01a1f83121134b1e614bbfaf37df3fced2a554382f34a3b339947eb7d8511
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.ptnlie
binary
MD5: b030a474020827f63e8734d43991af6b
SHA256: 6bda8fee513136a909f9a58c5b7efab8ae38a36becc787ded39a1c2a91bcf88e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.ptnlie
binary
MD5: e6b241c897c5000de029ff4beff1e747
SHA256: 945a398749b153473f4623fa8a7c670fdf316966a5ea4b80887d188588eae381
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.ptnlie
binary
MD5: b81da9d344ea494c941c24d5dbe9df9f
SHA256: 265df02ea8a7d236addbf525f3739bbc5c19e14633f3ceff7902e98a448ca6ee
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.ptnlie
binary
MD5: e02921b3658d6109cd0451e29d3dd6e3
SHA256: af3b7ab2e51c92f2dc873bf47f33a51621edea439c14415112a70110033d17b0
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.ptnlie
binary
MD5: 09c46175a614d135fa377d88febe917d
SHA256: 649a8f580e9a54c8a48d360257f250ff8983b64c87059aed1bbbab19096cc7e7
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.ptnlie
binary
MD5: 4d2e8b5f862df38bc03dedeb576844fe
SHA256: fc54ecc84111c0cd6441b27396157ec080ada86172ff77ad373fa881878e47d8
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.ptnlie
binary
MD5: 1cfc332a1804aa5b6996447524d60477
SHA256: 96c168bd65f8ce73e9b6f73ff4037abc7c68233cb765eaf41feb651a7a931f7f
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.ptnlie
binary
MD5: 22ce6d10345813fbed9f7b333ce21902
SHA256: 67c45f684969509b12a56382642d151e85b415e343574822cac1042baacee5d0
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.ptnlie
binary
MD5: f673695e9405143e08c5583954239b6c
SHA256: 2e68a8c514fae776f727c92005bcb3c17715aafc6e0f9e215e2cb84a074fed2b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.ptnlie
binary
MD5: 0309f5461af799e7aee02ddefe257efc
SHA256: d74274824b733c9f79fb731abe1efe37623baebc353b542b27c20651fdf5c09f
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.ptnlie
binary
MD5: b2bceb0cdd3b786b591223526ee7f24c
SHA256: 6b02770f09425ce200fb55ea6bb34830982cbf291c0a3e4b1a0c750e8ab64b7e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.ptnlie
binary
MD5: aec4c1947df26c5cb3aa0274d4985223
SHA256: 94e4f05cc28308feb612dccc4d81a811f5c3485dd2f95da2ba2431e746c7aa25
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.ptnlie
binary
MD5: f6b6b3f19c02bf6f42eefd0ff137beb4
SHA256: 82a9f58655c021827fa496d1aff70764aa279f8995f388444e96bd6742ca162e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.ptnlie
binary
MD5: 5d4797aad90b52f4ec004b4a1cb52abb
SHA256: 39393f6aae0669e9e919cb2a059dc311871222d9456e72bb3c7622082f792b2a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.ptnlie
binary
MD5: 67691315c640aef4f5484052c73eab9c
SHA256: b2dc8eab51af6687ab11c2ef0ed087246106d22b0f2b12d5cd2b6295d87519ae
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.ptnlie
binary
MD5: d6f2d500f71d3e4c9495187daf6d2a72
SHA256: 06faf4f6e76c7b446250dd3fb25deb55359dabc23987bfa043470fa907d98c60
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.ptnlie
binary
MD5: 185cc50382125c5dc2cb6fadea21c463
SHA256: 51cc9306269103fabbad21c56df225a1249d600faf8f218943f3e5a52b88427f
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.ptnlie
binary
MD5: fff95e239a3dc5db795adcd9db8ea625
SHA256: 604e053af842a148a2c80ca42c2db5715c25c0d4c6304c5f5d935bedb3d69574
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.ptnlie
binary
MD5: 0c99dd0af0bd3f953e85ea550d4c55a1
SHA256: dc005081703a95f3226b6441515f40f5753f3cd1b13cd7836dac7677b505c4ba
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.ptnlie
binary
MD5: d7278921ce433a1d34e2bef7f81fcfba
SHA256: 782a19ce26409591b3cd62ad4cd3f793c0f21d71f520156e3b38146f494295a3
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.ptnlie
binary
MD5: 005c7cf666744ba2945f5ab794fe6927
SHA256: 8fb6e1537f24db86be3f7ba3bf3a0b6a5bf8697fc2746e3313893ae18795375a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.ptnlie
binary
MD5: 9397e101cf1b7864131d59df69cb2f2a
SHA256: e4330238d768909d3508e007cf49df481932ed5e5dd73741c488e48276742a0c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.ptnlie
binary
MD5: c4338aaa8fd0f418d94dab77792dcb11
SHA256: 5432357880efb3e6984f107b0be5b96e76d3ab46fe088dec348be0eb3c81c64d
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.ptnlie
binary
MD5: 23767ac49abeba28b01bd9fb1a699815
SHA256: c9240b9280f4358716722245a89e34b50df4baf8ba2d91c207d94c4ded06bb90
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.ptnlie
binary
MD5: 82a5234d9eb2aebbb996aae3be6da499
SHA256: 8e845bb1b69e3c6607734af4cb13806cac03ca4d7f030bb3362e22aa79554450
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.ptnlie
binary
MD5: 7dc4aa3378eb670fb485142b7255d29c
SHA256: df3b3a2e169bcd26a466a0bade97769724b530a92feb7f048c5f09a4237245ad
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.ptnlie
binary
MD5: 9551c62b11687ee38d823369083bfcea
SHA256: bb36609015c6b48a3b481866f3ac7c138fd5ad0db8d4748eb76e14c34e91b899
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.ptnlie
binary
MD5: a1b6460db96d30f18c147296470f9f29
SHA256: 8f7b142cb8dbf503cfabedf60f61b6a56e93470bcc898d3a0e4d58b3083554c3
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.ptnlie
binary
MD5: 083822ea3e07130a636711cbbd00c50e
SHA256: c7a883df81cfdc43e0b437d1bff6e70677e2536da241951df57e7df1eaa882c5
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.ptnlie
binary
MD5: 7c15015ee25a9ec4c5c8590c370012db
SHA256: 5f91ecb4d330b3b5de9b6045a57b6a6d14eeac8a9fbe43b0a66b0e182dbb48bb
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.ptnlie
binary
MD5: c1da162600c41f083dffedaf16fb5543
SHA256: 607f48023f86d4cf8f8d1178296a921cbf6d58a168de357e4f595fd4ae34665f
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.ptnlie
binary
MD5: 04ad2e3d3d22f28d59c589fc5da7ec0d
SHA256: 50d7405d58966ad89b150730549bb564677537af345bbe91fb2f60b8741f4427
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.ptnlie
binary
MD5: afed05dbb17230b21dcfb7f9eed69a35
SHA256: 23fa0be92c8c8bc27b2a52b48e557b708e0bf02ceed8abad155581884d331c99
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.ptnlie
binary
MD5: 6ae2b4aebc9776ee63a53aff671cc641
SHA256: 14320eecdbfad9f7fe61935c15a10ff91bcde926eeca4325ca9e7388544ad91b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.ptnlie
binary
MD5: 3cc0662df46406da84806a23b4a37b19
SHA256: 7ff14c0f735bdf61fb7d5da7b58cdaf22e0c56783bfb3314e9f9e9c826ed2cc4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.ptnlie
binary
MD5: 67ae9c364fce6f0bc85148a46d9c3117
SHA256: 0db11ab27ede7c0b238108025cc2d3d1c83b13f983bb4f86dd8caf821306bce8
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.ptnlie
binary
MD5: c550e9043a2f728c06fdab3c048b8bcd
SHA256: 9dfeb919e114bb3bdb46272596869d0b99d53ef96ed33ee63fd9d0c7fde0ca8f
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.ptnlie
binary
MD5: 6bf58c0b2e2d29efd49a9aa1085d6388
SHA256: af7e77d9bd168e14bd36901ac1bfbc240505d530140831415cca20087bce1d69
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.ptnlie
binary
MD5: eeffc9a36b0f3360262cfe10facde74d
SHA256: 6bdfb218bbf08bfe03751d1a16cf2155d845fa488d0b7e452b46eaedc7622c38
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.ptnlie
binary
MD5: e2d5f9dd6385810ef5a55abb9f5a9f85
SHA256: a585f46558f6477676c3ca6728cb2e6727c652ae8751891b835ce21e65ca6736
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.ptnlie
binary
MD5: 13954a912470b2fc41570b6281ce6ed1
SHA256: 9745fa835114887536b28323e513ee9af3cbb13254bc668af19230736822491e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.ptnlie
binary
MD5: e86357c2c2be1315ada3749ca92cee93
SHA256: 29aa58ec018c106494c279f22cabbaa31fc4c2a39dab3f45a7ea53b0c153a012
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.ptnlie
binary
MD5: a911f61e08e753fd1685dd1b422465b3
SHA256: 5247e2fe7400552570bc31b02ca1ceb864b03368fa5e721f60d9373498789a3a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.ptnlie
binary
MD5: 7286efa09d104e53f8a1198f048f857a
SHA256: 8608f8ec5bc43b5ab0fa4a5b31ff7a948711665bc9b9e6d5b9dba15bedb32513
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.ptnlie
binary
MD5: fd3eb8f08269ab61cf8c705c5564290a
SHA256: efba3b322f3ffbabeba41ef0dfd1d8967506257bb54a032502f83274b06ae8f9
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.ptnlie
binary
MD5: 39fd7544525e72a17a62e8742cb459fa
SHA256: cc322bd45a2c449a8b663dc55f10ca67a16ce0dcb73a1027131ab08e3b439504
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.ptnlie
binary
MD5: 623e23cd21c12bc2ab47695062e52dd7
SHA256: 70f06950cdafac1b9b3ef5ec2e5804870900370935a382cc7a69ff83e22e3fc1
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.ptnlie
binary
MD5: d35ab51e7cfd9f6adab163e9dbcb6537
SHA256: a2fab298ae426b8b1d2f717d6c4e622f2cd1854b5dc93552de0359dba910e012
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.ptnlie
binary
MD5: f253bd92806e336ad3c7482004e49a6d
SHA256: 6c5cd898a285968685320d4acad4f9b887e8b9d650a0f5baea19b8f7ab8fdca8
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.ptnlie
binary
MD5: 21a0dd91d22d7ccc065901efa6fa64ae
SHA256: 7319d91ef023edfd297c316ddaaca2155cce618ab0ea87e748b6ab08758ca3e7
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.ptnlie
binary
MD5: e55b556bf4b11a4fd3e1d920d211b46e
SHA256: 29cf5c4dfa2cf514df8d673b230e1d1fd607418e8cbf41975c724430935c4dcb
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.ptnlie
binary
MD5: 81b62e5aa7286e99d1b7c356c2d46f93
SHA256: 35bf0be2d0ef68d8500c4932fe581734b231557f15098ddbf7fefa904c9e81be
2632
svchost.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.ptnlie
binary
MD5: 100a7f3bb13300c5bcc67982d10555bf
SHA256: 7c63fc13f398042227303bfcf850c06dfcf9cd1a9133000a851c495b1628f444
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.ptnlie
binary
MD5: ff334098ad9a10798a9b5a8d2845cd8c
SHA256: 1fb4aad5e318827a10dae160d6b8a3efed4f863782bbadff02ad793020f1fd22
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.ptnlie
binary
MD5: d0fe293297e4b575149610e2c55d4d07
SHA256: c7f881164e7148685fcd61b88ef8023cdd34215d991b4b12f1592e14f525880a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.ptnlie
binary
MD5: 109570085b36a0e2803f9428a5403412
SHA256: 8d70319031b74be9b9bd9d62f012952647dfac78c29baf7d7ed63970d27b22f7
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Notepad++\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.ptnlie
binary
MD5: 0349a37a2da099b7c5ccf5b24dde91d0
SHA256: 55dfc3513889e642d0c3e6c64ef2591ddb6ab5bf3d90750779fb72c83324f64a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.ptnlie
binary
MD5: 37380140ff1c7c93c3fb5608600bf469
SHA256: 070f4d6bb9090abee6009711c36b1d6330934416b69fd758e218316c2bab988e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.ptnlie
binary
MD5: 62268f1d292248395c7d732c07f596e2
SHA256: dc32d4ccfdae9a6d1fc527f6ab8750bc449f71e1b14cd4c5994b8175e6b56488
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.ptnlie
binary
MD5: 940bc6bd6849bf13e00df19731dd9ce6
SHA256: 7b5cb6860616d9b5e88d6c3b7ea14b967d64c4f06fd70da6e2ebe659919f6156
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.ptnlie
binary
MD5: d68d9fafedaf79b600649c85ab05cc2e
SHA256: 3e3449eaccc0b8cbfe143cca0585d32d21afedaae61ca0525d0da25f342655ca
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.ptnlie
binary
MD5: 03b8d315b787e0554ce44bb54287b700
SHA256: 21e9e4ea74e9c33168d187377efcdee6c5081b3baaba83e36c51ed65651665e2
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.ptnlie
binary
MD5: 8fca6e15c85699c7dfff89ee11216045
SHA256: 5257f3c91af03b47d7c443e9e3e92a3612d9444d8efde84c0db3cac48eb9730c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.ptnlie
binary
MD5: a9008098c4f3f8bab8c5b3070b5e720e
SHA256: e9c14ada92094ecd0fc95058246b582d214279b35a07066c52af163d9a8515d7
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.ptnlie
binary
MD5: 355374f45e9db540d5a2fcb8b8a453dd
SHA256: 899e3eed25e56034643d84fa3dc56786fd04e3fa9433c96a0f53f151663781f6
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.ptnlie
binary
MD5: 8d5af86d9bf17f8dbac20fa3cac5645f
SHA256: f67b574436dfb2e03444a9a94111b33ab8cd55bc3e67a02ec10f00986629a7c2
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.ptnlie
binary
MD5: 414dd6cb237d2ad1c2d1e800edaee713
SHA256: 4d7c8bb9172a2ad3100e7685e1b3e852ca29d842d8a864627533644f07fc03e9
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.ptnlie
binary
MD5: 8d3bb0eefd38ad857907501d507fbbb7
SHA256: 289aa92cef80fa93673c97c25836fc769557f6343ae2c8f5c801e89bd189694d
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.ptnlie
binary
MD5: 97b2e8c6a64fab6a15bdf16c208f2b10
SHA256: 9a1499b20e70af7b859e4f3ad352908defa358f663150008e2db716f61e578b4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.ptnlie
binary
MD5: 79d0a1049788a4e1f1a6e0fca1e5d7e0
SHA256: df78f240dbd0d90a44b051b1b1276c24ccd1c68827dca459e354bd5dac28032a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\journals\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\1.ptnlie
binary
MD5: bc99c157a9700a0f1672d51bd19302c8
SHA256: 3b8275237e12b3c5604961e7b856a68372d7723cf471cf05ab1a7ac067dbbfc4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\1
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.ptnlie
binary
MD5: 5c6e895db9126ad2c4fbf494c543a2e8
SHA256: e8a3b89b9cb5ddb5ac805599be2a21a0c0961a109519ac09ee2d8f327b115971
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.ptnlie
binary
MD5: f694058472bba167a89b303324a70781
SHA256: f53150410908ea84e9b90d9632b3ad084a2ace8f8b7a3e7452d5d48b10336d86
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.ptnlie
binary
MD5: 495b2b37badf791c2baf402acf53d3d0
SHA256: 5668921b6e12bfd74a0ea38be6ce273b1cda6bacf91bd7526f0767fa8c76a658
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.ptnlie
binary
MD5: eafbc648fe62eeb776d7ba8fe9a14b06
SHA256: d098272185d6472162a8b422ac24cedf8f2b6a6f9ec8f528ce92633848b781b0
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.ptnlie
binary
MD5: 845e320d0c46d67559aab1b394628b46
SHA256: 3345e2f91298556dff9cc6e4ea32d1e6d2d9437b56c1f1ec1ce3c45565c3393e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.ptnlie
binary
MD5: e967211a66e2d8228caa11cdb64ea663
SHA256: 7ac2ea8fbe278da754f434fe90787d73ef13ab1d1f4f223b3fa374af301641ca
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.ptnlie
binary
MD5: b6ed425015c09603d593b84165c5b677
SHA256: 88e53b1772af609166858e3e35091729a5aa003edf66b17508c9a7b341008296
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.ptnlie
binary
MD5: c3a2eee8f24f7f1c6629f6fb5cd61b55
SHA256: 8b29ec63742e9fc8ad2985bf34ee87a26db3a91839cf407f2c64861be38fe7ef
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\2.ptnlie
binary
MD5: 6562c0810a1c75ba818350c3f2d96cc0
SHA256: ca0934755230cbe09089f82174c3c84be0b8a9cd6765568ca0f54bbb6f8d877b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\2
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.ptnlie
binary
MD5: c1cd42927d1af65eb16e4cdd1a753d78
SHA256: 08a4c0877f5cc2d2f9133cfb86b8f827aa34de588b74f9368a1c6b0a8335c86a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.ptnlie
binary
MD5: bee3a6dc25e9c91ed1debd041c6ce884
SHA256: 42c8b850cb5949a676a186607a55f25ae2b622f561547db0250f58dda2f67f1b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.ptnlie
binary
MD5: 9a19dfacf9b023a8361eb66340959c1f
SHA256: cbb817a4a46a1c5edf6c0f11b198a76873be1d268f2d70f81fceba9ab338d421
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.ptnlie
binary
MD5: 39b839aee6557e817139750dcf5cd34f
SHA256: 03b15025623c81cf58afc77d85fac25cfbb89b7a2734e9b84ce5fbb6b53f4858
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.ptnlie
binary
MD5: 21a1daa4148135659efefb13ed509181
SHA256: 7fb61af2b682b296c1d9ff2a0f5901292d0b7d0e180bd8cd2f8c1fe6d739412c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.ptnlie
binary
MD5: 3784264db599adfb740fe1cf1f5ffd1b
SHA256: 4176567c686e9bd8d84451dd565d77b52f884ddb2ba42ba2d3673be21fcaff1c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.ptnlie
binary
MD5: 5eead3d2be3b0452b56f6d675e489942
SHA256: 1098e96407207d9736701693961f0c8823f8db3c6f0689f15cb059d91a94a7e4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\6c8d38fa-8188-40ce-822e-2249c9316ad9.ptnlie
binary
MD5: c0f2344b0cda1f229c8dc70e94b3afce
SHA256: 83917737c1ba52fdd87f337e00635db3b539ca7212f7677401359637e3e0db12
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\6c8d38fa-8188-40ce-822e-2249c9316ad9
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\5b3e494c-cfc0-48fc-8a46-d7b0f7ac9ab8.ptnlie
binary
MD5: 1fc3f2871b63d07f3d55c8734e03ccf9
SHA256: 708b982281321ba5121c44fcd751ff6a3c0dc60e2fd650cc585f741e45c25696
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\5b3e494c-cfc0-48fc-8a46-d7b0f7ac9ab8
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\4802db1c-08fa-4dd6-86ed-b549a554341f.ptnlie
binary
MD5: 1db465fb927b21caea9142f69c681acb
SHA256: b7ec9db81a8f605fcab921f9a0bb35b302b42e653f70da147140eff1ff653f92
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\4802db1c-08fa-4dd6-86ed-b549a554341f
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.ptnlie
binary
MD5: 2ca4f7e615e6564ad518546318670cf7
SHA256: 7ce67c15736846be7f787bb187c2d618baa5490125a3b094e2f6734a734063ab
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.ptnlie
binary
MD5: c7c0a8055773fb81132cc48e2c5345c6
SHA256: 93b601b4e40e8a0bd0cd30a85b351af52b6376f267775629223d3df76631aaa4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.ptnlie
binary
MD5: e3c510c8a081129d1d89373e83d708db
SHA256: 55a0e68835808d3f76e5b660ab22a43125af9325461cb939007a0c960a9e2c00
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.ptnlie
binary
MD5: 6760a2d41abebbb6912a4e7ed9d6ba7a
SHA256: 4b05028d178daaa9bf1b784798bd7aad4de1f78f2e8cb46f8b5c24d9eee80d91
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.ptnlie
binary
MD5: b6bba31072f203ba414678085dad7a1d
SHA256: 41d360750ceb47af78fc8b9c71b809ef397bb846f810d735f3446d91a3c9f4b2
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.ptnlie
binary
MD5: ea389544764aa6aa10bb4f57144e0b39
SHA256: 905a6b033e4724ed19c538c45dabd0afa9c6a992261748d20b5a5f61611fc69b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.ptnlie
binary
MD5: ff35866b034f248904f39b29e6ad997e
SHA256: d92de866eb61eb7c9ac11058a6d0c0467b5eaa7d4d74afa9b013790d1f3439f4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.ptnlie
binary
MD5: da012738ca9186d0afebacf2e98f888b
SHA256: b3679685c88f3457868cdd62608782d48d0a5eedf74999b06450fb0eebd33bea
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.ptnlie
binary
MD5: febe2f00d2b6da56bf0c2526d7e22938
SHA256: dea84f3a61e7c9938ff6ff9adb473c85c29dd8a4fc95c4808a3cfad8dfd17441
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.ptnlie
binary
MD5: 44650b529a57817f748dbea1ca26723d
SHA256: 0f67a578bbd48bf9dfb932cc73148a3bcf28dbac9d9d62bb5df8c232a6d05cea
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.ptnlie
binary
MD5: b761b751f710efc71df89e2dfc96badd
SHA256: 6b37eedc162b448c93db7d56314524a72e7e6c24be0bfc9049f58e35012fc7fe
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.ptnlie
binary
MD5: 95dd3c5e1f24803802c65f881e521114
SHA256: 44fb906fbfcce582e08d82d31e3b208679450ce80b6324179e25bfcb1a0fceba
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.ptnlie
binary
MD5: f365ac1cbb8afafa42fee871f838d839
SHA256: e7578aabeafb5854c87b052e9eddac2ef5e69926227a645640982990d0b7ccac
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.ptnlie
binary
MD5: 33473bc5721c7bf4dd9b2c9c6fce667d
SHA256: 38ca5dc556e0eb0f5cf3b5ee88918c1e83a2a3c74e454b0fb9754a1b1884718d
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.ptnlie
binary
MD5: 9e8ddc359c90d07b860bf38148a18808
SHA256: 53e2370cc12d831c6beccef45ffb4db5bbe0ad5d12577fc4de5f6b4209700c9e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.ptnlie
binary
MD5: 75dea5a2986c07f876bf8c10501c83ea
SHA256: d19f936cfa00a7ba6fc6052ebb2afb6e18a02ab7426c3befbd7624abdceff35f
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.ptnlie
binary
MD5: a37886651ba3f3e9c0ddbbd249ba906c
SHA256: 1a347576b9f3bd95d3ac16afb2d3a37f89302f4abd723967bc1a2bc96ecc40cb
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553060497627.6268dd77-e77c-4ffa-a941-4f4f321ce007.main.jsonlz4.ptnlie
binary
MD5: 9f002faba044a799ffafa7a0612deac9
SHA256: 93069658476294e9c6fe50b53eac72bd8a78fb50033cafba9d5093259ee83452
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553060497627.6268dd77-e77c-4ffa-a941-4f4f321ce007.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553060497613.ac4871d9-bd78-4681-8633-61427101b006.health.jsonlz4.ptnlie
binary
MD5: 1ae9a2d3d2763307c1d074ae08937efd
SHA256: d2a6a60a8817d63af3f58cc3594d64ad31e2eae205a7fe33df0da12b8c69d4cd
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553060497613.ac4871d9-bd78-4681-8633-61427101b006.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553060497593.5b3e494c-cfc0-48fc-8a46-d7b0f7ac9ab8.health.jsonlz4.ptnlie
binary
MD5: 050f64905d153aa1573fcd4c2bffa7eb
SHA256: fbd0dda26ed451599c6caaead3598fd8ee5cf6539fada10106702b276af82d71
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553060497593.5b3e494c-cfc0-48fc-8a46-d7b0f7ac9ab8.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646937.9c1d5aa7-8417-4152-b187-6829a20b449c.main.jsonlz4.ptnlie
binary
MD5: 67b84f28e552024c3bf7e51b9aeae328
SHA256: bfafd47b15d8b402b1c785ac50d74f7a8da8de090a6f8b2c8c34eae1a3667f6c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646916.428022fd-1128-47e0-9128-82697384584b.health.jsonlz4.ptnlie
binary
MD5: 06822ec8abd6ad1b6f3a8e5a03b8c536
SHA256: 20d54708a347f4cd6609c5186281071ac69cbbcb0ff0175ab90b7ae062da91c9
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646937.9c1d5aa7-8417-4152-b187-6829a20b449c.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646916.428022fd-1128-47e0-9128-82697384584b.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000637968.4802db1c-08fa-4dd6-86ed-b549a554341f.update.jsonlz4.ptnlie
binary
MD5: 17db60377eafeaa7166fa5d0624f19ab
SHA256: 9e292a5c901a5004c1b71067a199047431c3b20c56d5bbcee6e657267df40d08
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646892.6c8d38fa-8188-40ce-822e-2249c9316ad9.health.jsonlz4.ptnlie
binary
MD5: 28d6496e8d5454337e4380e6f666bf7b
SHA256: 6a8b502307891e44b008bad9515189213b99d8b39a17890b37b95c5d25ce871d
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000637968.4802db1c-08fa-4dd6-86ed-b549a554341f.update.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646892.6c8d38fa-8188-40ce-822e-2249c9316ad9.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000620729.94b06a80-a39c-46bf-90b5-264680171d04.main.jsonlz4.ptnlie
binary
MD5: 5334f64be2ee012f7619279cc0481909
SHA256: 6e899f59c81f28535ea3fe97523a7d32f4837a8b875d2de529657633724819c7
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.ptnlie
binary
MD5: c2442dfe28e7388db9aba6e908f605fd
SHA256: 893edde24a5ba1103c238ccbe0d07ff2ea309bcf1e4ed50e6424c3acbe7a4b0b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000620729.94b06a80-a39c-46bf-90b5-264680171d04.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.ptnlie
binary
MD5: f064f3cbeecc62bdc37605197296f5d1
SHA256: 85195bf589149135ac13906e3d892f5f5233946aefebb822334673b6ea5b643e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.ptnlie
binary
MD5: 9a8793c4ab0359ffdb2709bf2bf5e8bc
SHA256: 9f9e7e3f55294f2fe2a355b6cd2d8a7dd936365551369868ba60ba48b3e1a245
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.ptnlie
binary
MD5: a512e106b7105035d31ff2ecf1cf26f3
SHA256: 88372c8a5cff89cf1650d2b3e2e55abfa96b42b552e51d8d8bd2d4a537c1668e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.ptnlie
binary
MD5: 083be85d0aee9dd69c3008fa1350e20f
SHA256: 6de8855aca7d05d924cc41b71549f7d2569691f4eac19256a4ecce4b82f3355b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.ptnlie
binary
MD5: 63be302f78ddae44f1b3305903310d9f
SHA256: 66633527c5a1060bc3716889b4d708135caef7fd8681f539f6a725c750f2c2b7
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.ptnlie
binary
MD5: 59cbdd38dd371c80ef754c5c3ff48f43
SHA256: cd4dfe6a582e116f13ca9da0c86441423e7cdd74501b4e6bb6e42c14be63f25a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.ptnlie
binary
MD5: c5d80368b502763f6305ac0249853d33
SHA256: 7d2284d8e85387988de0aba8ddb32cbd53dda5eb3946eb5de2fabc8186d9fe32
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.ptnlie
binary
MD5: 6dc4a7160e74fba79eda8a0b56c545d2
SHA256: 8a8a7c02b776b5fa32822fb24dbc00fe97b60e74721abdd48a4ee4ddc4e1aefc
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.ptnlie
binary
MD5: 0a9adf75a59f614cced6c5fa7ef7f113
SHA256: 64885c649f300bbcf39f0aab58993a16c6dee17760f4eb9841ebe04cf13e3651
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190225143501.ptnlie
binary
MD5: 30c59dbe6b85b89a2e6bdc53ad5010ae
SHA256: c0ff048a7c0eb73487f6fe5c184074db55b67e9a2875ff644ecf1c8c14380593
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.ptnlie
binary
MD5: 72aa5849b917c251f9328db56a19a6a9
SHA256: 0f5d97a51a3fadecc670e960285a30e4361dca9338ecd0ea46198fca44c3bfad
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190225143501
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.ptnlie
binary
MD5: 18dc44aa306151507c212dacd2df2a47
SHA256: 6afc29b889d68698d551be11f93e6161ed64e6cf09c277ae3986b2fa769a0c72
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.ptnlie
binary
MD5: 1ae7f15061ba88b3e253edb39b4ad0f4
SHA256: 02079c1191d15337a08d0db9266b4f66d094f5cf276fd8f04ce13cb671563b0a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.ptnlie
binary
MD5: 33fae82b29e3f119eb39579893a78ac9
SHA256: d2f3f9b18a245611b66a54fec421b22de11ce6d5fba3216ee1ec58dc14363266
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.ptnlie
binary
MD5: 51256d0b289d14437dca5bde99a01dd7
SHA256: 520dfee349f025106d8542673d2875316c5a8fdcdd46eb9528b94689ac81e982
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.ptnlie
binary
MD5: c76ce375a4d89af459942c9d93c3fa88
SHA256: c4aaccd3beb105c8e87caeed49f5a147bfb783c95dc3868b0e9c7c2690649a65
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.ptnlie
binary
MD5: 4d17e21e85aa132dd32aed821b456d90
SHA256: 8b1af307ada467d5333da532ac4320870937009d655a84b10103dea858af741c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.ptnlie
binary
MD5: 0c811a1d2ca0bd7827d2ef8bb2bd93a2
SHA256: eedd1fca4916f55cf2284dda98fdfe78044a5c2b39dee0fbb4575bdd61c16c01
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.ptnlie
binary
MD5: 09adf610e65b2001a91b06fb153a98f6
SHA256: 5558bc5fb014eceee5af7854c5692eb13e59e17eed7e5e4e639835ffcd7f4d57
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.ptnlie
binary
MD5: d1c116ba803df5452026620452d70346
SHA256: 856f6f9176ed2a55c7a254d9462e035de79858198ba5affe70dbd78506e57248
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.ptnlie
binary
MD5: a11a8aa84babfb129925952f49879b7b
SHA256: 50132f7dfcf64233f8e902e83dedca57ff95f4825a976c42096262f42c3dd1ad
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.ptnlie
binary
MD5: c22820a6fc1edde188f0dc0e3b7861dc
SHA256: 4d9121423a16d73f344880992ffbd85483db95138502c8ba9f9db2262e30a3c4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.ptnlie
binary
MD5: 2e908e95010cdd089711551242b87a33
SHA256: ea3afc7a9f2f53fe11af1fd800716414f84b1bddd1f073aab46f684ecda4468c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.ptnlie
binary
MD5: 6125ae19b27db16e51db757bae9c3d84
SHA256: 495573d1e085cd87df238541f2c7dff7ebc0e653cb5f611525d960fc33930440
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.ptnlie
binary
MD5: 1fdf07d73f3b86780c52505b9bfd93df
SHA256: 96b2722b6d2f6aad19e9a1ea4de391e700014f95a6fe3acd25c89469510f3fe6
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.ptnlie
binary
MD5: ab1cddf466b109a49c78acc693ba774e
SHA256: 6490681e9d4d283ef5203a88fcc847c041f2a3534d0a0fdb92ee125a0682458c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.ptnlie
binary
MD5: d53ed179b7a8a960e99818a8a5e424e4
SHA256: c55d111599ba00f63420bbe421439d0f7c7d29655fabd63bafd755e6c0e172f2
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.ptnlie
binary
MD5: f11ad4ac23be467e643bbe18da2fdd9d
SHA256: e9f3bb52a9ea666a75cb60de34ae23876660d3f7eba81f7c7e6375f8a3f5d483
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.ptnlie
binary
MD5: 4144bc440ec87accd825f04e92ec4904
SHA256: ebd16afc1bccf5fc43d5232347df6d58a70f10de98d3a6112028feca6c277f15
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.ptnlie
binary
MD5: f60059f4e3d75aba4e2a520f772f41d5
SHA256: 9ca4f25d85415deb7ce19b8449d05936c984cdd2633b7d196a1282fea4312361
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.ptnlie
binary
MD5: 2877248212b67e77edcea84cd02b5ea4
SHA256: c030730c111b7416089338ecb9141cdf35f5d1a3970126ff2149522a55388c15
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.ptnlie
binary
MD5: 446859133e06d55516e876e1986c44bc
SHA256: 578d92d52447e285dfe258423c13267c7cca0391a083c8593a4518d7da474e6f
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.ptnlie
binary
MD5: 1f6d77bf2f55ec4a1591c5113df9d248
SHA256: 9038a7aff8c50fcae5ff99567541e077ff7c9189f8bb74023f1c9585bd338f92
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.ptnlie
binary
MD5: feb3bf5a160736e0948f386e99a2d190
SHA256: 8fe46a2aae811ab63e6065eff5bd679ec62aad8a6efd86e869a3c3166eac7cc3
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.ptnlie
flc
MD5: 1f698dcb8cead40447479c8d45e4813c
SHA256: 7e0d047b1a085b43775b9550f2f930b63192d7f5c51c5c6bae0f0aed7623e7c5
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.ptnlie
binary
MD5: 8d4c4bb93b4b81a4e4d047126a17677e
SHA256: 0fb57f1cf727973fd76fa2352c59ee484a354054a86b46de4b5eed4a33d18c97
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.ptnlie
binary
MD5: d8c26fb4cc90262480b5974610517569
SHA256: 8bde6a7aa49526fd2d2d1bff0472cca2fbaeee5ffbfd9cce7653209691328c1b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.ptnlie
binary
MD5: 3a271431f5ff4bd44f763904ecd05422
SHA256: 48d7b6be34501328ab0dfde6187173473d3860f01e3711eaf1a2d2124d93fccd
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.ptnlie
binary
MD5: b54e2e994903763abc9ad7d6d5275c89
SHA256: 5fa5aa2918b77b4712667d12105d993d2f48d658100c5e95120cd69b89baa565
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.ptnlie
binary
MD5: 772a493e969b03782800388b9409f401
SHA256: 9d21f3d48e4d48de6d714f81ad8e3aaaf9018c719bb85dfb6a04959e62985824
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.ptnlie
binary
MD5: 86ec68518d9f93bdfa418e6a2d27859b
SHA256: ed302fe50cca8f3aceb6eb5544575d118464827eb17a87ecbe1b9dc790561dbb
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.ptnlie
binary
MD5: e2d25eba2ca474970947244ab68062a9
SHA256: f1559240db0ee4cef3b5b5c9bd3df25b80c6eded1ad7c9436439dd2e95875fe9
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.ptnlie
binary
MD5: 2ef3467c7adc54297e98e7029553be7f
SHA256: 821a630ea6a86b6d2d931cfa27a2a08c761899152393d141f54f6c097ad33cfd
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.ptnlie
binary
MD5: 61e7263cc2bdb4b0e1faf94acbe2399a
SHA256: ac4b4d1153783e8513db8a1885a933f17b8790d14accc86f929dfdbb2115b296
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.ptnlie
binary
MD5: 7cad69edcc420e514d92d220aecc2a04
SHA256: 5e9eb00f1325e41b5b9a87890e758b447cb1f6fa358e53d46496f7acfa7dbd56
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.ptnlie
binary
MD5: b0e878a91036752686328b9140debfb9
SHA256: ee36ca2cfee5866312b29de8ef63995a3ca159d2e884056625820c4ff4c8b660
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.ptnlie
binary
MD5: ea40ad05d666147b69258d7a8e5fe3b0
SHA256: 641e51f433eaf52507cfbe887b3e43ccdd14903678422324bd43f9f276bc1d4e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.ptnlie
binary
MD5: a31bb55baaae9de02135c1bf9d5c7df0
SHA256: 8383eeb414804d68032cb3ec12980450724a86bdffc2f7908575179f4f46f1d7
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.ptnlie
binary
MD5: 930f0a77f9ba7e5b2d0063e925f46640
SHA256: 06ff5871d2176c80b8b62c5138ac81979ef272df5cc167f7e8b4d2160ee8a4fb
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.ptnlie
binary
MD5: d14a17dd3e769c878958cb0d38091da1
SHA256: fa937f8bf212ed4ac942ea55003bfb37680fdfddfa48f4f22aaee6b66e3676a4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.ptnlie
binary
MD5: 0b687eb0e5965d7af1290ee119c845e5
SHA256: 1a5da1fa124f24bc14fce4e8e3ac23425a860fd3b67430bcfe9975c92d7699d8
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.ptnlie
binary
MD5: 1fa7cf24a001373a5cfd3d4c88aaa737
SHA256: d5890e6d793edde8b5242acf217676f59dd65575a87538b7344e575ac6a0daa4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.ptnlie
binary
MD5: 607d91be4919dc12125b35caf1e1ab73
SHA256: fc9b0e4f0a1f0df1695935cfa27b646bcbce7b39c67b20cc812cac00dd0ecb5a
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.ptnlie
binary
MD5: 71f71c23bce1354e218f8b1f5c249e75
SHA256: 5a0e8fa6ea101eaf2573d47c5f7e8ca80773e20bc75e604b7571c807b885fbba
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.ptnlie
binary
MD5: 66c0b8a630dcc53bad819ee557bdc70a
SHA256: 0a91a6665fcec140926bb7882294634e619cbb23ab7bfa049c7e6bb550e4a9ae
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.ptnlie
ini
MD5: f80990bb50c8d7257e7a35085aa21af1
SHA256: 77853caed128756a684ba7380a132ec186eef583398026d070b0e3054338c170
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.ptnlie
binary
MD5: b5f56a8df6a002e64d0f4829dd9969e4
SHA256: 5e7aaf0ed8c91a8e0dd44d2455c9cc6472e74d24606870cb524d10dbcf4c1faf
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.ptnlie
binary
MD5: 08d7d6a2d4fb21764b820af45768df6a
SHA256: cdbfffafb4a3564396cada6a62cfa12908fd0226a920d1d6f697f3859f7ee4b1
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.ptnlie
binary
MD5: ea254006134a4b70b2682d7a68c43bd9
SHA256: ecbf3647c4aade770bc9edfbb0b9f02bde553169f327bb4ef28f7a11f86c0e11
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.ptnlie
binary
MD5: a635d13568329827b6f6202deb26d284
SHA256: f8a2cc529066093b58883c3040d9476f3a23f09d763235410d1fbc776ff533a8
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\fc958741-2c2f-465a-852a-5ea30b2a11d1.ptnlie
binary
MD5: c23f1d03ee013f1b855c754fa9d4a744
SHA256: a94ff56dacd1f13a8880fa787f8a88f1141331836d5f280dd100e0b9a503cf8c
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\fc958741-2c2f-465a-852a-5ea30b2a11d1
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.ptnlie
binary
MD5: e244c8a90e61e3a7e83ea24a56f75d28
SHA256: 2420263a4b2ad47fad2a9292880fbe84c646e5ac3a129c5a7f17ce9c372c9a45
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.ptnlie
binary
MD5: 099b94f1f0472217cfacaea766b1af0e
SHA256: 2a1173f0151f9e3938799c8bc5f00e4f146314a238663f84e14497a7fd705d1e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.ptnlie
binary
MD5: b800012ea8b0f27ad676de5836ce2b78
SHA256: eabcda3e80744f9fa9bfa848ce1dc11fa9dcbba1eb325bbea692be3ef4812a8e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.ptnlie
binary
MD5: 7a05374659041a324e769ae75913fd11
SHA256: 7a705a6de887c6a8a098278fb439b336cca3e64caf299cda85786a148f275274
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.ptnlie
binary
MD5: e70069476071af39faf90c859df4a299
SHA256: af5d7df13045c002aeeb2b4dcd99bab2aefc0d7294be9925ea5d0db1421c2059
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.ptnlie
binary
MD5: 35212ecd8d454ecdc2b69a3a3b738c40
SHA256: 13bbe4b4e77116efa9757e5fd031b4f90286e02240440043d3904b10e4459197
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.ptnlie
binary
MD5: 1ea5aa9cefc4a349bdd97b683a56dc38
SHA256: df46c149635914eb2e5f4409b976415ac14d7a49908316f99876366236d48286
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.ptnlie
bs
MD5: 47067d0453dbde635b02ef11f629cac4
SHA256: bb5872199948e7f2a0b95094673f7b6365de291052b1ed07b8dd96d0591fed8e
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.ptnlie
binary
MD5: 33ef3f864082299060fccc12fa3f15a7
SHA256: 16abd6085f0de9659bc1e374fc0e996c387878d637ef0ff5c71799800bbd68e5
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.ptnlie
binary
MD5: cc6a821a5a6a39d9f9609f211cc09db4
SHA256: 6aa7f7513f4f182188471e44f6954e944066d3bc0942b0e9957fcb5ee929d417
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.ptnlie
binary
MD5: 64aab3ed5e5e2f9edbcdca9ec806979c
SHA256: 9d82bc66d654583710053dbce2e1f6679a61f25b504191671979ef632d673dcb
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.ptnlie
binary
MD5: 2952ead26de318c01ffc0f3f07446387
SHA256: 6afbc32868db2ac3def7619d92ac76887c89cbc2d5d010cc30283e0d5a56a8aa
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.ptnlie
binary
MD5: 29e0271b5d6a094af464383f26261c5e
SHA256: afbc666fec9b60bead57aec173b7cc4e2e1ca9be726dcc80c48fde07e81273a1
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.ptnlie
binary
MD5: ead6bb35c39971dfbaa523c810917956
SHA256: 6392bc6bb2a6874caa50df83add15f3d0c46edb9e3087794cc58e3da51354c85
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.ptnlie
binary
MD5: 0f5350373d6f310888e6bd11e8557e20
SHA256: acf965d28cc255fdaba085b66cabab6de7cb91b748fe9e0dc86d1ed5fcf508a0
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.ptnlie
binary
MD5: 7edc2149d51d126bd2c71874e0d8223a
SHA256: d66990816d40e940f08be55deef92380810d281c2014c77bbb67f436c790a005
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.ptnlie
binary
MD5: 78d35e9d89862e92033b8a1fb506c5e6
SHA256: f3e8f4fca42b8af861df6642eb29d2efddffd912033f070143870632e090acbf
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Identities\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.ptnlie
binary
MD5: a715e254a3ee344119613f8d7aa7ba8c
SHA256: 767893a5657245371e4b2e8fdf714009a5a9fb051b8dae27274d2ab28c41ab46
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.ptnlie
binary
MD5: 82af73259d3494bf5b8604ef224a76fa
SHA256: 17138a3318c8dc4602b8ee13101c4704a15b9e88c582fa3d3cde4e13690f50b4
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.ptnlie
binary
MD5: 4e4b016f352e2d682530135607f398c7
SHA256: 4878634c2ed60e757e9261f6112394187f5dff0fa3e50c9f5252b53723d3a82d
2632
svchost.exe
C:\Users\admin\AppData\Roaming\FileZilla\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.ptnlie
binary
MD5: 1ab663929f70595f316a55bad2664a9b
SHA256: 630acf441c78c2c159414ec705342f23594ee64bde2455f5815fa639403622cc
2632
svchost.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.ptnlie
binary
MD5: 6b334e8a8320b4a513662ce47867bf35
SHA256: 6388d5d0a9bb92a9705beb3b2a0f70fc778f0cbc488c001910ea6034a20d2c1b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.ptnlie
binary
MD5: b35bbf16776d752141e6284d1da0fe40
SHA256: 00d3260df09a78447b8068b646e11ab2d39e41f6d49c7ef38fe91e07bbbda649
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.ptnlie
binary
MD5: a7854c4485abe56e3114bca57dff1c23
SHA256: 5b947141964e9465b89ea9383eb942f325a29a978dcf6542dcabe0b3d01f7d2b
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.ptnlie
binary
MD5: 8765ebab55c474f21cb8c2ff4fa26388
SHA256: cee5a246c73b0be5c1e9d8806c8dbef7c8b413839b37e1737632f7225c61fa36
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.ptnlie
binary
MD5: 96c9f6401abc4585229ce79b40ffe6e6
SHA256: fcf5dbbd072bcdb8b4eefbec6e82cc29c7fa05075db932120003cfd109c49682
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.ptnlie
binary
MD5: 331129e23732b7e86b7dea7bde027d28
SHA256: c7e497e01832d2416c60257a1505a5c7b04eef16a5f95e8fb3387fa3e5c87f6d
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.ptnlie
binary
MD5: b571f95956fd82a91349ec332f7fc31f
SHA256: 499a72f8061241cb3d976040c437323e8120c1b7b19001b0d109219851d07031
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.ptnlie
binary
MD5: 41a9cd1cdd5bdbd5906cf064c691426c
SHA256: b9937f1325cda14b4a337efddd7e079c8449c0f92eaeec3f4086c102756a4025
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Forms\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.ptnlie
binary
MD5: ba3b7f311f4310cf4dc5e1758dcc1cfb
SHA256: c51df4c45d103625fc3a526155fee6bf6a3215d4e5fcf126110547bfced9c982
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Collab\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\AppData\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp.ptnlie
binary
MD5: 34b36e1d121a2108d96a9a849f429a71
SHA256: 7f8cb0f991b4d5da96826c8b79b744f5bc3ab3916b0716c35340cb5cf8cf4811
2632
svchost.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Users\admin\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\admin\.oracle_jre_usage\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_WindowsUpdateInfo.ptnlie
binary
MD5: 2f0e67f3243579a1d68a8517ea7a8ab1
SHA256: 1f23bd8b9cef2019399e265cf1ef68982d7eff2103a715a45fdc354339fdda2a
2632
svchost.exe
C:\System Volume Information\tracking.log.ptnlie
binary
MD5: d3c4600403b21517e438afea7fb0dd66
SHA256: c924707bd541bd3020df2d8b96a9dcc0b25a6f465e4d2385e93bbc7887f8a029
2632
svchost.exe
C:\System Volume Information\tracking.log
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_DriverPackageInfo.ptnlie
binary
MD5: 3f812ea6977483e23c3a6ef87f98ffb4
SHA256: 4f2f62fcf6335b4dd6f53402be8d26a8828937c1314f42b868ed23e5c54e80e6
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_WindowsUpdateInfo.ptnlie
binary
MD5: a6a55faa30d3bdb7101205fe9bcc3916
SHA256: 5d8202252acced6a0809658aebe28ec58011e93929041ce17da9c37142498d3f
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_DriverPackageInfo.ptnlie
binary
MD5: da1066fb653ed51d63f3c9df933691fc
SHA256: f88cc2055211a31a981d797c44c7e013d775106ca15ccbae922baf216c3e7439
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_DriverPackageInfo.ptnlie
binary
MD5: f9a968f51bf3cc497529177a50479b40
SHA256: b4502d49ba5be1dcc32e2fb2409c33466170cd89ac17ba59b451b76be3e879c1
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_WindowsUpdateInfo.ptnlie
binary
MD5: 6651e217dc5dff759b993d0bfeb9698e
SHA256: 670d64c4913e398e4552746fbc607a3182aaa7c25dc5c08ea6e069bd9bc532ac
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_DriverPackageInfo.ptnlie
binary
MD5: b6902cdfa4c0cf5716139123ffb227fd
SHA256: f6ce0aa6aa52e85d4e7c304319bfab1e2d81e956c042006eaeb899649ead35ab
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_WindowsUpdateInfo.ptnlie
binary
MD5: 86c4f294f0af294d611fb5ffc585ed57
SHA256: 84fc9479a3eb6de03a7663566b42a8e1bf75b0917dd94138c76392da70fadef5
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_WindowsUpdateInfo.ptnlie
binary
MD5: 8396337773679f2da29c6f82879d539a
SHA256: 66b094b66ba3ed5eab788e421816eb6bc366463671841086316d8f1fa4407609
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_DriverPackageInfo.ptnlie
binary
MD5: 380927e84dedbe10525d75f5b340924d
SHA256: 50aa524f4b0e177ac9eb22835862a9d368db7d64b60fec9b3e90f82cb226ea2d
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_DriverPackageInfo.ptnlie
binary
MD5: 02c36f5e072b040e6a1a7c5b956ea850
SHA256: 3bf896bcc0f08b3cdde46dcc794417931bbafda9b877300e14938a784cc4f00d
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_WindowsUpdateInfo.ptnlie
binary
MD5: 14e196a4b40f57635f197450f0fa4cb1
SHA256: ddf302e33a30e4a938d20f3e7aff5d402e759c67df0657ac08c33d2e86f9123d
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{8B4C0ECB-7F10-47DC-AE3F-C1F2BD0A0DD1}_WindowsUpdateInfo.ptnlie
binary
MD5: 1c1e09d254d42b9d6d621af1c83781cf
SHA256: 656239fe2210567c5c31c12989a82d3a69cb482253123d19e57f3810ee60110b
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{8B4C0ECB-7F10-47DC-AE3F-C1F2BD0A0DD1}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{8B4C0ECB-7F10-47DC-AE3F-C1F2BD0A0DD1}_DriverPackageInfo.ptnlie
binary
MD5: b6f383c4dd27e4e0dacdec1e5518d073
SHA256: c128594e39e6e015339b437b71a54c50e91fce50b2612f06f20887776454a4c4
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{8B4C0ECB-7F10-47DC-AE3F-C1F2BD0A0DD1}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{6AF49B38-A69B-4427-8E0D-1D7F53ED58E8}_DriverPackageInfo.ptnlie
binary
MD5: ad02612a27f6668a4464c3ee66093152
SHA256: 1712dbf76ba0bfe997a3b81fff01bd462cc2bb49df61c4eba2002ae0a50356b3
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{6AF49B38-A69B-4427-8E0D-1D7F53ED58E8}_WindowsUpdateInfo.ptnlie
binary
MD5: c41482f3bc4c37cd0a089d962c56bccb
SHA256: 7bbcb5103871b76162760b4adca041630da598aeff47251a19c41def5cf0b1b3
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{6AF49B38-A69B-4427-8E0D-1D7F53ED58E8}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\{6AF49B38-A69B-4427-8E0D-1D7F53ED58E8}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{fc5f241b-73f6-4813-9d64-4e4f00d39c97}_OnDiskSnapshotProp.ptnlie
binary
MD5: ca1531ce82ca0e4ab1529f9a032ada9e
SHA256: c6d452939f1b28f89d56a8aeec785317050e643b7ac9069b6ccb761fd6eedd0f
2632
svchost.exe
C:\System Volume Information\SPP\SppGroupCache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\System Volume Information\SPP\SppCbsHiveStore\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{fc5f241b-73f6-4813-9d64-4e4f00d39c97}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{fbc1d708-be70-4ddf-91ea-c05528f7becb}_OnDiskSnapshotProp.ptnlie
binary
MD5: e795cbc67a085c21758ad29d7fc3049e
SHA256: c4c237a77876e212680261f1159b8d0eea4e14a445242075de5e61da0d2e9b58
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{fbc1d708-be70-4ddf-91ea-c05528f7becb}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{ebafcf70-55f1-48bb-822a-5412291c8b75}_OnDiskSnapshotProp.ptnlie
binary
MD5: 0efcde3d6eef606de1d521cd0b80fa5a
SHA256: 44b62ff532bc0b3026da5fad9fba24ef220b75b1c42f249dc3fb1f24d7605a2c
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{ee321e85-0e9d-4572-b152-5e2dc9f9bcbe}_OnDiskSnapshotProp.ptnlie
binary
MD5: e9b86d275ea1242e72b550ac1215b45f
SHA256: 1dd11c8bdb9eefd90e84f9ea349ab895e8281f00dbd700b8f9d23085dadb59cc
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{ebafcf70-55f1-48bb-822a-5412291c8b75}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{ee321e85-0e9d-4572-b152-5e2dc9f9bcbe}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{de4fb673-c96d-43aa-a06e-db0853b54bfa}_OnDiskSnapshotProp.ptnlie
binary
MD5: 657f615ace6cbd91f2241376dfa7f45b
SHA256: fe5992eef9ac08997c0f754574cb500f6f34e768440bb0e6c060b3af12aaadbc
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{cec64297-f2cb-423b-9a4d-7695294fdbcd}_OnDiskSnapshotProp.ptnlie
binary
MD5: df836408d15e022fb62932bde0c22d5a
SHA256: 5df33a687d4b2e01b5bb5c48c644dbc9dbb3eb9c006dfcaccdcaaea581c7e4f2
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{c9cf9f24-5351-4202-a015-c273ae785f0c}_OnDiskSnapshotProp.ptnlie
binary
MD5: d5507f7f513488b10188b8ccd065d395
SHA256: d1771d3ef4ac31950c4be0c2d4bb3062afe52310dbbaf8b9535d1288e310e945
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{de4fb673-c96d-43aa-a06e-db0853b54bfa}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{cec64297-f2cb-423b-9a4d-7695294fdbcd}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{c9cf9f24-5351-4202-a015-c273ae785f0c}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{94e6c3a2-599e-462d-9c45-78274daded0c}_OnDiskSnapshotProp.ptnlie
binary
MD5: d0f01648c68c156c072e122ec060fff6
SHA256: 4d58332d3e06f566ea3eba7d39ba3d32ee74a0538e28f995c24ab27e748cae74
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{8b4c0ecb-7f10-47dc-ae3f-c1f2bd0a0dd1}_OnDiskSnapshotProp.ptnlie
binary
MD5: 03fa24b6e3b9280f1c5fbf59af5de47e
SHA256: 78d900069846faf5447daa63edcf17b3ade43fdf55606f04b5bf5874c8935769
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{b45425b2-5957-425c-82c9-bf873c06e2b9}_OnDiskSnapshotProp.ptnlie
binary
MD5: a4494f4e029006c96cfaeef3354fb476
SHA256: a8c802a7c5eb1966c831b297ef3e6833bac9851053fb1676afa2f38e59a33113
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{94e6c3a2-599e-462d-9c45-78274daded0c}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{b45425b2-5957-425c-82c9-bf873c06e2b9}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{8b4c0ecb-7f10-47dc-ae3f-c1f2bd0a0dd1}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6af49b38-a69b-4427-8e0d-1d7f53ed58e8}_OnDiskSnapshotProp.ptnlie
binary
MD5: adea7c3f60aba554ddd64bc1b090a59a
SHA256: 0aaa73a9e91e17906a5bdc194192aa798e08c14769322e625e4ccfa502ce4bd8
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{5c4beaff-a038-4df7-9b35-072a18f8e3d6}_OnDiskSnapshotProp.ptnlie
binary
MD5: ff795d73a50b8fa3eaafe6d832beb20d
SHA256: 7cc1e942413f9273a96d54a443ab9771548a0500fa64fb44492fc38c645c332b
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6dec60c5-cac5-4c55-9061-62edac696401}_OnDiskSnapshotProp.ptnlie
binary
MD5: 3dc0bffefc14947766af68256c6ea8cd
SHA256: cfb3a45798859d361edb647c6ed99edb296ce89b2b65807e66512f1316522c2b
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6dec60c5-cac5-4c55-9061-62edac696401}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{5c4beaff-a038-4df7-9b35-072a18f8e3d6}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6af49b38-a69b-4427-8e0d-1d7f53ed58e8}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{38e8535f-27d0-4352-aa3a-ce4178930102}_OnDiskSnapshotProp.ptnlie
binary
MD5: 073e6f4e906cae5da1145e0d4c546e86
SHA256: 86975b462d6fc01b106c1fc8eadddc4ca559057aeade7a468e8ca174857da3f7
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{3cc0f82b-873a-4e59-b89f-689fbdf88af9}_OnDiskSnapshotProp.ptnlie
binary
MD5: 4985bd21657cdff377130b3ba20bef3c
SHA256: 38358ca8dba04ea87ce690420483effe6e14557d871c4141a1f3d0d985d9335d
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{16d74681-6bc3-4c44-97f0-8b8dfefe2355}_OnDiskSnapshotProp.ptnlie
binary
MD5: e5c771d06711af32396c9772297cfdba
SHA256: a5cd82ddda4429b145ee0ca608897cff11401cb6d2cb894ffa716d53ddc8998a
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{3cc0f82b-873a-4e59-b89f-689fbdf88af9}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{38e8535f-27d0-4352-aa3a-ce4178930102}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{16d74681-6bc3-4c44-97f0-8b8dfefe2355}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{05ed3515-06b3-48f6-8cf2-bf24b1bf0727}_OnDiskSnapshotProp.ptnlie
binary
MD5: 767e39fa2a5e644d34a8f25bbad16a5d
SHA256: 661796987321b8a9a31aff0b6485039389c74d693ea56e763589833ac713e9cc
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\System Volume Information\SPP\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\Winre.wim
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{05ed3515-06b3-48f6-8cf2-bf24b1bf0727}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\Winre.wim.ptnlie
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\boot.sdi.ptnlie
binary
MD5: 13e014194812acb2959f344fe9269f6b
SHA256: 491554a1799863b7de54de026d41da1b46a8f1ba8a8796b00cfe36ef81007156
2632
svchost.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\boot.sdi
––
MD5:  ––
SHA256:  ––
2632
svchost.exe
C:\Recovery\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Program Files\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\MSOCache\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\Users\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\PerfLogs\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\PerfLogs\Admin\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\$Recycle.Bin\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-500\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229
2632
svchost.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\PTNLIE-MANUAL.txt
text
MD5: 556173954c667af2cabed470e52d314f
SHA256: ab8cff9c92c37d18180820f2b2732180b163d1b2a16f5fa2b6ee85e398eff229

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

No debug info.