General Info

File name

10_.exe

Full analysis
https://app.any.run/tasks/07a75391-8b06-4e84-a6c2-8e3df8638b56
Verdict
Malicious activity
Analysis date
2/10/2019, 22:33:25
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

gandcrab

trojan

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5

b7559c47eb4d598566763bf71061ea16

SHA1

fbe895bdb4bed333823496922ec87b50909bf0ab

SHA256

485cc13a1ea59aa461542cae6974c35c1f3ea59be6a5e82b9ae907415d898c74

SSDEEP

3072:TlvgpQdmzEqrb8UhkApsxF56EKTb51ROoladHHcsawKmt5abRw66DzgCBlMb7X:TlIpQdCEqkhAps4E0V1R46wrAb2cKM3X

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes settings of System certificates
  • 10_.exe (PID: 3052)
Deletes shadow copies
  • 10_.exe (PID: 3052)
GandCrab keys found
  • 10_.exe (PID: 3052)
Actions looks like stealing of personal data
  • 10_.exe (PID: 3052)
Connects to CnC server
  • 10_.exe (PID: 3052)
Renames files like Ransomware
  • 10_.exe (PID: 3052)
Writes file to Word startup folder
  • 10_.exe (PID: 3052)
Dropped file may contain instructions of ransomware
  • 10_.exe (PID: 3052)
Creates files in the program directory
  • 10_.exe (PID: 3052)
Adds / modifies Windows certificates
  • 10_.exe (PID: 3052)
Creates files like Ransomware instruction
  • 10_.exe (PID: 3052)
Reads the cookies of Mozilla Firefox
  • 10_.exe (PID: 3052)
Creates files in the user directory
  • 10_.exe (PID: 3052)
Dropped object may contain TOR URL's
  • 10_.exe (PID: 3052)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   UPX compressed Win32 Executable (64.2%)
.dll
|   Win32 Dynamic Link Library (generic) (15.6%)
.exe
|   Win32 Executable (generic) (10.6%)
.exe
|   Generic Win/DOS Executable (4.7%)
.exe
|   DOS Executable Generic (4.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:05:16 13:12:41+02:00
PEType:
PE32
LinkerVersion:
10
CodeSize:
147456
InitializedDataSize:
28672
UninitializedDataSize:
188416
EntryPoint:
0x52350
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
FileVersionNumber:
1.0.0.0
ProductVersionNumber:
1.0.0.0
FileFlagsMask:
0x004f
FileFlags:
(none)
FileOS:
Unknown (0x40534)
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Unknown (557D)
CharacterSet:
Unknown (F56C)
FileVersion:
3.2.0.10
InternalName:
toxaku.exe
LegalCopyright:
Copyright (C) 2018, cahazebanekudu
ProductVersion:
3.2.0.10
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
16-May-2018 11:12:41
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000E0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
3
Time date stamp:
16-May-2018 11:12:41
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
UPX0 0x00001000 0x0002E000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
UPX1 0x0002F000 0x00024000 0x00023600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 7.73537
.rsrc 0x00053000 0x00007000 0x00006200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 3.88963
Resources

No resources.

Imports
    GDI32.dll

    KERNEL32.DLL

    USER32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
36
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start #GANDCRAB 10_.exe wmic.exe vssvc.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3052
CMD
"C:\Users\admin\AppData\Local\Temp\10_.exe"
Path
C:\Users\admin\AppData\Local\Temp\10_.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\10_.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\kbdus.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

PID
2448
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
Parent process
10_.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
1860
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll

Registry activity

Total events
130
Read events
96
Write events
34
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\ex_data\data
ext
2E0075007000790067006E000000
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\keys_data\data
public
0602000000A400005253413100080000010001000D670D55E486C2A103E606B8D8EAEDBA8FB5913E3C870DE4F937EFCF59C2CFAE191A6FFB4818C948E2DD4751931202BF573F8A1DC18A6BEA6953952DEC9365C57E1665CB7DCCE1AF38E50C180019645A7BC38FB23A63A275EA42A47B2441450C2B717774695279E1FC4EEE2D5A2BF885EE36C20F09E2ABD677C366CC498DBDD19FE7B93C71AFDC04F6C99A980455D3B44A994212A9C09BA4A0C8BB27C70CB91AFDE285879F1BDED2AF5BC7310C4463EB24B2B502954093E427956D6B1BA8168FA5A9CBB8EFDB2D6F243E50021930AEDC3597FB37FAD84D7E0B5F19870147D53FEE154E3F8D1190BD15D307347C2C5FFF2F11DD3FCE3E9C77D07CC80A2BF58DA5
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\keys_data\data
private
9404000033B43A2D01F829ED79F917D3D4529EEC84BE06BFDB4CB6BAD85855A4CFEEE0A50038F35F250E84303ED4FC7A0B4F8A9A1609F218B7FA0750EC99B8C1D42CFC1F1E1E8F39460252BF432F44FBFF5864AE9CAD098CCF998D0A86683CE19FD0DB72FD0386667E12AFD96AFF1AF0E320FA9EE31DF75D7FD8B500C5B072A4C4A7C30229FC95BC2F3003CFEB17CA8412B80C31923127F4C8CF6126534A95F964F6140413058F5868E6516716E21D70CD5F172F54286B944FF1F1A9F588395826C60967834B89E5468D401D88A7E032B829AF6A08860DFF4ED12F25A80A4DC3D081435C36724C4632C0B75E7ABBFE972CC89F19D68744D6722066306CD1DF2B6953522B43D0D3DC227439D2961B15CF7C3297FD88B969F3E46179AD47AFCA7A0FD2818796252CA6BA20A183D95BD7EFD011ACFCCD41E79E0516487470B3D868C69C68651388DF4AEE1C9EE16DE769F1C2AE667B1124069AF9EA0ABD3D5E6628ACCA888E9D4A81856C137CD3465E7C3680BF8878ADAE5C283D60A910846DB3A03F057AEE1B7371D6C4FF6690650AEC943CBCB93FCC6D64FFF92781E8E4251B928835553B7CEFB5A67989AF6B930510D297115B671AE14E7983AFA72AE88B7C87065EB230CFFF93A1C67BA41138267C37DC29D6649CA1975134877E98AE7353364F96715D72791067852FE35D40109D6A09538A1F39147C1CAD3CA9748300E41D348F29587CE86A62390F65F69B0646C4DC41AC84507DE6561C8AF8044FBB9D1B3D25E6E7887CEB8C064EA8519ABC05743F33F20EFE6DCA4B337D91B8FEA71C6ED2408EE3A8FBEB790BD665794BE55EBCDF476DCADD0C995477B479CE9B035B7E2696AD2E47DE95E0C9929783596BE59E3DB9CEBD4AD6C055BE920A646B5FF72572C4F24A5A7FA05F5280B29EFFA887C9502CFA7041EEB49ECC964620C1179AD533B0039C767173B1651C46F99383ED9A05B82D9F42592DEAEE48962F8CD0708E0B0935A4FB3E2C96894B8A646BFC5DFA07E9B9FC4A0B13FF104E371FD350FC90C0BD4A1348EC2C866EB403341CB30B60DD3A608A4A464910DCA781305576E30A9F9D27199D600659EC9D50D3224CFB4A174301D01D968A4ECDB9EA8C8EF545DF1164252C5A8C3516F7A06D80DF38CC09736068EDB8ACEC59C857E5A6889282B93F82718109E6D3B8F26CE85B08F396B7A0FE2A74AB00E11E1E8747E553B29641EF58A42142938A77C9CDFA73D4BE923993DA6B2193195A8CC85777CE366D4804C58BA9D967D21FA48E108A8288332F1DFB406812A2B0EDD636976BA4D277D999B203E930C08C8BE8AC7A4572DB14C6ACCD00276ADD553F3ECFBED70BC83EFB1021CF0251BECA73BB7BC95681CB1C43203D3DD863780FFDB4540FDCE78566D2D89A0C802AFFC23D0753E30517AEDC4337B7475CDF907D8E37B5CEB859CA2B6371F03627BCC87F13778B1DDB16DC0E4C6CBF8542514AED90537DE601A74DFD42C1C218CBFE1E997D783C77EEEB0EFBBF22F08330678993283472389C5EB07D4852860F1127F4AB3F832F8FFCA649280887686415D391E62BFBDE41AED53D54203A1E27C0FB7588AA0FAFE7D847C0950BB7532BDE366CF326BCBECFF1EB2CAFEBF4293987122E135F68552390EE994E335D5898A7D1D2BFAB7D861BD29A65B97F85F7294E01BACA9956C836C269A82BF149CA9774463F663A785B5108DEEF6E37615430B80E0CE3331FA4391682E5B7C093883CCE078B7AD9547414E5F1052EC1C5A0882AAA12CCD23EF91B6C21559E99FA88723916ECC8A5C1659DF748E3E06F178B5844147B194E40873B0C2F132F654E44FAFC48BCB9F9AF1EC9AE57C332645EFC31E68E259638C9DBF935F99A16FAD7E8DE537AF6ADB25B2EA52C7D5433DED0E70CD074197774E1BC575ACFBEB91CC479BE61F562C3D17FCC060F370DA3C51A8659D5A7580947B96B82C89C781FF63CD27F1E0A9B17F221C4426A35F96E33B1123D0457AAB390D35189D10725223370A1E5AF77C6B4A0BEEFC1F529E2A18C360CC8816E3286762C4E591CCEE99B0583417697A2148D8AF0D1E9D733F70943E4CD9BF7DE371532935F9AC33F4B6A1FDD5554DFC59D8A88A5140C55BC24AA96A72A35B900E066D470971A5F255171F4E3D7AC79A261C8C831467BC08BC38F823ED0D02DA07A5F00BEBC08F66DEFD1837809518A71BA4D63DB5D65F1FA8C1292536896E40B7785A5818EA17E1467B06A572507AA69696288D9F7FF096514F0180A346769978D09CCDDFFEC5F142AB710BF076FD44DD5D02C36E1694BB480270E55D663DE2828667B833F032E247378362002BCA7C670902C37ACF68980D662B5320DF1CAF98EBFA9D4E624AAA317F3365BBE1DB2EB43BEFB38
3052
10_.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3052
10_.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASAPI32
EnableFileTracing
0
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASAPI32
EnableConsoleTracing
0
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASAPI32
FileTracingMask
4294901760
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASAPI32
ConsoleTracingMask
4294901760
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASAPI32
MaxFileSize
1048576
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASAPI32
FileDirectory
%windir%\tracing
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASMANCS
EnableFileTracing
0
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASMANCS
EnableConsoleTracing
0
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASMANCS
FileTracingMask
4294901760
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASMANCS
ConsoleTracingMask
4294901760
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASMANCS
MaxFileSize
1048576
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\10__RASMANCS
FileDirectory
%windir%\tracing
3052
10_.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3052
10_.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000003000000090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
3052
10_.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
DefaultConnectionSettings
4600000002000000090000000000000000000000000000000400000000000000F094666288C1D401000000000000000000000000020000001700000000000000FE80000000000000A179B3FF019923140B000000000000001700000000000000FE80000000000000A179B3FF019923140B000000000000001C00000000000000000000000000000000000000000000000000000000000000170000000000000000000000000000000000FFFFC0A86483000000000000000002000000C0A864830000000000000000000000000000000000000000000000000C00000C1C90000090372800084226000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
3052
10_.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
WpadLastNetwork
3052
10_.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3052
10_.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
Blob
040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510

Files activity

Executable files
0
Suspicious files
429
Text files
318
Unknown types
9

Dropped files

PID
Process
Filename
Type
3052
10_.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.upygn
bs
MD5: ac6573d73e6e46b60da5b19dea70bacf
SHA256: 7b4b2d6f1e829f4bba8b1f90b16966da7763c869647914c71bd35ead113d87f8
3052
10_.exe
C:\Users\Public\Videos\Sample Videos\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Recorded TV\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Recorded TV\Sample Media\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.upygn
binary
MD5: b4b8106eb056ecfeb16d22656981992d
SHA256: f3efce093a9f4ef143b8d98e9cff5aed8733628920e458eb364e6f452134818a
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.upygn
binary
MD5: acb604bcbecb08426707b6c79ba0b956
SHA256: 8d42322d3f1ee5ba9f0d819f2012c81251b3b2ac86799000f43bbf67986ad33c
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.upygn
binary
MD5: 65e02b873737a444ce97c0707648cfe9
SHA256: 86fc839e19e143d69036b99c6eb8a1ce7fff78ea60b2bcc51b49c0b5bbf23c2f
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.upygn
binary
MD5: 1d25750dd0dae353c28804039ea1e05e
SHA256: 5f33fce6561dd78c98fc2c9b47c9c09bfc7d090a99695fa1287bd59c1efb9bff
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.upygn
binary
MD5: 96ab6042722ddb5520f7322936030de8
SHA256: 9fd45448450cb24282bd1089695db38580b64c15dae497a5798e5cfca0803b61
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.upygn
binary
MD5: 594f4c44a934af72407da2731d1e82bd
SHA256: fa7fa6e3e730b729638a02ec3ea46203bc4e4d90ee6cffcd0d01910dde23f981
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.upygn
binary
MD5: e5acf4dc4ad966cb95ef9c2aab398031
SHA256: 2b81bda7a3bc3a8528b7a30d234d0d56c8ae9b57284c1881770a3562442c7e28
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.upygn
binary
MD5: 801eeb5e26832c104154ebb62b4efb89
SHA256: 9b0a36446ea0d40a7dfd59ee34ec509f3a32ac79720f6b571d8a3b6c9cd638da
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Pictures\Sample Pictures\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.upygn
binary
MD5: 4bf95be23c43cb9f65189bcd438bbad1
SHA256: 0f121f194b40e917df5831f5d0bbf7452d2267a0fdb7e08720731b2126580094
3052
10_.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.upygn
binary
MD5: caa1dd57375f26666e4029f2689a5e25
SHA256: 611acee5d62609a338c4465e00201b37e2a79298a6cc52ae1971ae6398c3ec10
3052
10_.exe
C:\Users\Public\Music\Sample Music\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Downloads\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Videos\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Favorites\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Libraries\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Documents\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Music\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Pictures\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Public\Desktop\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\Saved Games\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.upygn
binary
MD5: bb40e37d5398416c709cbe32cd18b5ad
SHA256: dcaf39ca5662c5eb936b69c444d6f4372d1890fd0589c273e689c97e7d3e9644
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.upygn
binary
MD5: 4ecdae7d2e1c53d47c15c81e00929679
SHA256: 4d173217d24fb4dc50cca9232c26ea1d0b4285b1663848146249c35bbca41393
3052
10_.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.upygn
binary
MD5: ee510bccb4051b869d970e23b4cc653d
SHA256: 336edf0598fbf4bd3020d52cd5202bfda69254014acf42f130662dc8cb14d157
3052
10_.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Default\NTUSER.DAT.LOG1.upygn
binary
MD5: 1f529ba2cdda0288d1813742292082ea
SHA256: 61608b2451e368ae3fe691869ad462e8f2198609a6cc872fbc9227b7d28df5f9
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\NTUSER.DAT.LOG1
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Default\Music\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\Videos\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\Links\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\Pictures\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\Favorites\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\Documents\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\Downloads\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\Desktop\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Microsoft\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\Media Center Programs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Local\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Local\Temp\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Local\Microsoft\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\History\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\AppData\Roaming\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Default\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Searches\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Saved Games\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\ntuser.ini.upygn
binary
MD5: 26ab3c030c7168856a6e10165cd7df8a
SHA256: 7c7be46566f29bcbf9f38a16252f7a6188b71dfb756a3800217c21e8b751d77a
3052
10_.exe
C:\Users\Administrator\ntuser.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.upygn
binary
MD5: 9a1149cfc4944af1113b22f40a61af72
SHA256: 641fa088d583240df0af74ad2db14640e0eeb6843132492372b92cc2ad7c788d
3052
10_.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.upygn
binary
MD5: 215619b5b9301d09b17d0a5ad47ac348
SHA256: b0a0840c6872531cdd446fea4081adb7116fd3383c6c9ae3508685f8541b60f7
3052
10_.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.upygn
binary
MD5: 33150db7797373d2ada04a04b2020852
SHA256: 5dd3138fe814ceb12755c8f604b5c707d44fd3a0eb552f6bd2894e52869158f5
3052
10_.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\ntuser.dat.LOG1.upygn
binary
MD5: 44ca2a977600c6e8f67b903bb1a00b67
SHA256: 7dc37418d7bb8bff584fa1cd119b281e3328fac0511c5229dcff3fe1507768c0
3052
10_.exe
C:\Users\Administrator\ntuser.dat.LOG1
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url.upygn
binary
MD5: f675d751d1f531464f3cda94072d0962
SHA256: cf97cdf620d35971f1e55754dfbd3bb758385eeba5530647e6f998f78ffb538d
3052
10_.exe
C:\Users\Administrator\Links\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url.upygn
binary
MD5: a2b69057c843364456f0b3e311444b7c
SHA256: b84c411cacd5f59be8e5851de8696306764e56e391d6759a0879e3dffdc4cc99
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url.upygn
binary
MD5: d3d8be56216f8e19f023df3b253abb62
SHA256: 94e785df3bb65d29d33f687abe164cab3e9058b5a78877f6efb4f87a15ab4a85
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url.upygn
binary
MD5: eda59fd253534f8e47273d3378d01fe1
SHA256: ca47715dad80aa9a3958e595df9671c43c071db44457003157ad98898eeeebdc
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url.upygn
binary
MD5: 17adc6867f7c74533ebd21c07378cdf0
SHA256: d4058c2ab046688a3f044cec0a751ba8ceb30cc3bb3bbb52208aa06e4be16bcb
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url.upygn
binary
MD5: f8c9dafd5514b6be9ec5e7c5312cb492
SHA256: ca891c9de6e860834b3900b8fcfdb84b7a53574d983dfdd792d710ac06e6749c
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url.upygn
binary
MD5: 08d01c58837305131de27f9f9b5398e1
SHA256: 9e0b40a575cae65c6c4bedfaccb52195388df7ac1614e1ea490e070119ea6172
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url.upygn
binary
MD5: 8db6a039b377fe2f59690f577ca56c6b
SHA256: 1fd7775692745f853a436095e64e5fdf0012f0bb4e630dec7938c909f76fa78f
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url.upygn
binary
MD5: 1f078bd750ddb1a048b99ba6c7fba763
SHA256: a6663f50f5f18e6ba83467214d56581c869c328245267c42aeaa9704cc727d34
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url.upygn
binary
MD5: aaa6c1c49b1fbb88a5d63e478e4fea1a
SHA256: b539b88ccbfa342c095208a34495934c782c4c225620a0d2a9fe8c38fc1b9b46
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\MSN Websites\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url.upygn
binary
MD5: 648191762f1edadfb83baa34ddb2e31c
SHA256: d0cab76df20ff972f19d654dbdeca95017bfe5b9b41ca2e373ccade9250dba54
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url.upygn
binary
MD5: ce5d62135aa3bfc9885501cac28c723a
SHA256: 1e7ac1fc04cf0326f1761dd8b7a0820dc9df42da3fe495c9e5364fc6f108c726
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url.upygn
binary
MD5: eba628f05212801697881d6c7b648548
SHA256: 2c2f190f1b9443bd000ae7106d5f5ddaa0f7bd9ead04cac7f21a6dc21d86d83e
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url.upygn
binary
MD5: 5ad2142d299a5e81629c1e58fb48180c
SHA256: 372f9881dc9b5c685e804fd1717e7a6fc647b52b2b95fa72828519f35a568e99
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url.upygn
binary
MD5: 42888abeb6fbcafa2c7e2b69e1c1d544
SHA256: 7bf7bb7941a3a3572ba5016b56231145f48d03f0aa88cebac701de7838b91789
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url.upygn
binary
MD5: ac5a38b244f0661cad91d95820babdb2
SHA256: bde57c9af81dd920e60b992861570e16399718032b839a1840cc81b8e67bb4c9
3052
10_.exe
C:\Users\Administrator\Favorites\Microsoft Websites\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url.upygn
binary
MD5: 7728df330c6c6d2e681cbe3807f5882a
SHA256: 900766bf8f656d166737154a877833abdf964e0a2efdca79629568b99a86bf83
3052
10_.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Favorites\Links for United States\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url.upygn
binary
MD5: 28d347f2e48560e24a2a99e178b24167
SHA256: f858ebcbe7127b43110b28c5fff16d46220fb49f02deb8f17750a26c25217c5e
3052
10_.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\Pictures\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Documents\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Desktop\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Favorites\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Music\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Favorites\Links\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Downloads\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Videos\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\Contacts\Administrator.contact.upygn
binary
MD5: 0f0528e653a3591303c4c62dabe000b1
SHA256: 9f41e40828728258e17e8301e12f91f6b9927093b9cdb8dae146730d266b4a1d
3052
10_.exe
C:\Users\Administrator\Contacts\Administrator.contact
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred.upygn
binary
MD5: 926e975cb0c374dd1800795af3a94974
SHA256: 27ead5aaac9cb3897b21e9ce94aedc1e17563716574415ab87f491218e434fd8
3052
10_.exe
C:\Users\Administrator\Contacts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156.upygn
binary
MD5: 3e6ba77636fa66e367cfe1254f19faf7
SHA256: fe1b330328a2257ce56ab57596886e8154cf9c2b36ed4046717162f6638fd5e2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST.upygn
binary
MD5: 6ff91d9f803839b2e904f2aacd4e9920
SHA256: f7b7f8d952a2f4bfc6332359e03034279c731b2696907b9cec69c7545525a2d4
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Temp\WPDNSE\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\LocalLow\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Identities\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log.upygn
binary
MD5: 4efa990e1f76d7d17256af7b37a1ace2
SHA256: 3815677ede485e6aa4850e5b45810b2b679ef599916f8c004a815054f2a0170d
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Identities\{BA2162A3-2F32-4850-8D8C-B3C9A2AA9D43}\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Roaming\Media Center Programs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Temp\Low\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp.upygn
binary
MD5: 525e42d7984fced8c5a1910a2d3b6100
SHA256: 7a28a4f95e77429e40b1026509a0441b871dd35481e6020922a8df0650c6d3eb
3052
10_.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Temp\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Gadgets\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini.upygn
binary
MD5: 3ee1c81d62d57d419e9feedad6de735d
SHA256: 391ac1d55d3e8640b124b4327fba136729a9764de93375771124b314fe0a849a
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML.upygn
binary
MD5: 8fd93185b65e0c3db1177f3337c2b242
SHA256: bd943213a1b55f293d8789242786d7a4bdf9f8da6d0521a4beae2f93aec662a2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD.upygn
binary
MD5: afe4952c2052f965f30e134ecebe9132
SHA256: 8db096e7e5b8ae1cea16a9105a7ed13a4238a193209f6c747c1e6be7511ae981
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat.upygn
binary
MD5: b31a0e4296c98928009b6c9ccbd341cd
SHA256: eb8a32e36dc52b9fb1abc3bb667efba0de21da5956f9192f9ca9356e46cce7ff
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore.upygn
binary
MD5: 969264706483efb11259b2758d89bc9f
SHA256: 1eb699fd2fbca688b11029f7156262594d93f0e7d935b71286de6634bfca1a05
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif.upygn
binary
MD5: 844badc3730f67e74714aaef0e91181c
SHA256: c8df3b58c5595287659013481bb1c2c919f9115ecffb152f67bac53ed292ab6f
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg.upygn
binary
MD5: d653cf224d7d267a3f7b928da36fed95
SHA256: fe6536b6b70e8e0fbe8ffe9d05371e43a5d3827bec919f06e9dabfad23c9f790
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf.upygn
binary
MD5: fe6f8b1da4651df864cd8136818194a8
SHA256: fdf1a9582e1083e52b8a73f460bb5a6d1db88d6f6d504d333c0003ff0558a686
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif.upygn
binary
MD5: 9d7dba2cb807ad7bfa3ee5d82b5315a9
SHA256: c57201875aa874789162cc5c347b68a6686ef8d291d87a7fcec596386b222bfe
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg.upygn
binary
MD5: 405c73adc34d72f4e90c2eefea868eaf
SHA256: 0ace1747b1dfef96aa0d3d5f51e96122a69a701d42115dbfd51ea43a15be38cf
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif.upygn
binary
MD5: 7853a73b71a799a7b3590d9b1334c5e1
SHA256: d61ce0b95f7cfaabb57e692381ad18e7d132be0b2c33df4dc6828b4237ff11ba
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.upygn
binary
MD5: d538f6c08541a9489f495dd876b5f4dd
SHA256: 958503b6166a1d81807bc074734281aeb35fcc33edeb454d5da519a7d2e82c6a
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.upygn
binary
MD5: c9d72bcaa78b2290668a41f2f6c02966
SHA256: 8fa09cfe7e0792f4b8f2ece2e976ecca5c4e3dc82bd54d1f31e4eb2224da7873
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm.upygn
binary
MD5: ff16c3b70ad71ed2f2cd5c01d5add953
SHA256: 0bab34fe031c911e3ea3a4f698c3f1a1554dd2e497c459f95334e4ee594aadc3
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm.upygn
binary
MD5: 1a94be0fe1d20e71e14d379c171089f2
SHA256: 7efd615615fa5deeaebc94d2bc8800238d4255d7371cbb2c7f89e8f7e63e2a69
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg.upygn
binary
MD5: bbf49c51ab666085880c603adf5eb578
SHA256: 5f06ec08f731b88ef44760f6bf7919ec376f55369150ee1d5c93f41a8a59152e
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf.upygn
binary
MD5: 0b1c4c276e7df2ff571e9fab958fdb5e
SHA256: ec2b14805fe81d2f1be9e6e8226a6008254685695f784d335ee39710e6efe7e3
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.upygn
binary
MD5: ca0361d6ac65df228c72219408901720
SHA256: e397c89fd8e847031b4a9f969742b4d4c901430d8e32f6b95cb608aa9c862b54
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm.upygn
binary
MD5: 09cf06a9f9b0c44dfef16ec03e51f3e4
SHA256: 5fb418d0ef3052dea7931ff97be8be2ff9ae9ed58795d007e5e06f79786a70e5
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf.upygn
binary
MD5: 6d736d10c540ae81c18b8921c9ad74ef
SHA256: b27a9774124c673a3b295a69a0d34fdcaa13c76a2731d9ddddf368d588a4a22d
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg.upygn
binary
MD5: 361ba1008c29efd41472c0676eab92c3
SHA256: 6d8494168d08036e3566928f6bf390e72a61458e6aab463a07f11fd55df78197
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.upygn
binary
MD5: f809add43d786537ab15c850ad77487f
SHA256: d5082a780c3fd51ba4822096219aacc68a4d98b1cb0504018185cf158cb9b36f
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm.upygn
binary
MD5: 4757d8ecff0d6e4973f9cae8acfe113d
SHA256: 2c43d07aea6f43ee5367c5c86e273831708a2a76798c4f04d07578e4411c1f59
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg.upygn
binary
MD5: 8194fb8180001c912c09d69df6cb8f63
SHA256: ce5a49033b15ab2cfacdd6224856c3184774c1fc901fd192769d1c3ca8b3c43c
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg.upygn
binary
MD5: 39ac6b727bbc7247055b42639efe79b8
SHA256: 42bbbc65cf1db998eda3a8fce2bc149bf2e33f8af0540a32fcb7acbd55cfce81
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg.upygn
binary
MD5: 12b58dbc78b0f3bf653344060c2786d2
SHA256: eaa6a32d6bc42afb3a51cc3824c9bc495e98aabda581d782fa3d7efc440789ef
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.upygn
binary
MD5: f9775e897188f67d960f121712f88d94
SHA256: 70364896a1ff3fe3e8a48d892feb1d4c5f9089c0a0ae29c2e3af93795f0377c5
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm.upygn
binary
MD5: e0d08dd0b4251c9024068a9f9df4f0b6
SHA256: dd216f2babdb10d4ef366821ec572365392c643e7588d451fb8e1db74f0c9765
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.upygn
binary
MD5: 51aaf8ba6a0ba944a05233436a2ca725
SHA256: fd106b7beb6b02e45566f6a2b6295aadfae92cc606e75bfd63b9c5346da25279
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm.upygn
binary
MD5: 3715a462314cded1fcb37df14aacebbb
SHA256: 09e72fbfc9e4b34479a2dda0795b53de1fa1094903f1c4a053137b57b67a09b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg.upygn
binary
MD5: 9113287dbbaa43d0bc8929bb2d0f160b
SHA256: 25810189f62be26b1483ebbd435ee9400bf1285a3a70d3a985de6c0af453e3b4
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf.upygn
binary
MD5: 87eb109e664edbe5f3b1670c845bf61b
SHA256: 4a26e9a0e261667f70044d34d44fba9f215f8411d9cd5438630976652a30486e
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf.upygn
binary
MD5: 9a72efbe728bdd40ea1e6f6404683674
SHA256: 8fd03a3f41e9b16d586a6c1371d5946a6f99f7d69a31b980923128f9ef2bc40a
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg.upygn
pgc
MD5: ce6bdcfb87188d93a0ead0fc371ea708
SHA256: ef559b80a6fefbc884764514867356b4ac5dabe3b31c6422560406d58c58ddea
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf.upygn
binary
MD5: fbdb7c5002f4d70c40984a66116e26a4
SHA256: 8c0cb89f4b74166e84f441f7035317daef55457c32e2edc4e9fa0960faaed068
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf.upygn
binary
MD5: 656487fb9cef2396fe42017dc6096497
SHA256: 90c253c7fcf37e2d30277e9b668d394ab84a00dc99addb412c86ef60b6e38912
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm.upygn
binary
MD5: 458be50695048a05f6cd495d62fe60c7
SHA256: 8ba2ca1a5b19c3dc7577c0aaa55a9ae93876142ecf88d56de470ac4d5c71ed33
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.upygn
binary
MD5: 896f84e81d2d982875d631ddd1f0059c
SHA256: db09ebc9e0b44d1425c9a4439a43d141d7cf62a189a944cd261a7a066980414a
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.upygn
binary
MD5: b98071ac7c552c60c9b2b394c499562e
SHA256: 6e38ac02f9d25eca1e04a4d1e4318ae6fc85afe763d66633e0b0244a1a173bc8
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf.upygn
binary
MD5: d4f5e55b4dbeee26dc41ff30322af602
SHA256: 4fd5a53440ead0941380838bae92600b567eedde3320d87321cd26b283c29df0
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf.upygn
binary
MD5: c89e690ee737db52ebd8d12b3f50287e
SHA256: ea36acc4ac22c0f8bbdf09f2a3bb58ff79a3b3dcef6a03c75186de404a4f62cf
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm.upygn
binary
MD5: 5c855629cd9aad0ce48af46d666ec3a9
SHA256: 4ede25e0d36413cb4f575593ef74dbb03ac2cfbf85352011da930b2244425b6c
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf.upygn
binary
MD5: 24322eb9e6d34eaf7ccce2519965c0dc
SHA256: b197e324badb6acae2e685bbdfa1fe6d77ec8171f69778df7061c98390deef4d
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.upygn
binary
MD5: e97ed6f12aa50e8db3ee934029670e1a
SHA256: 6f1225f76ea4f6c735ee087e19dada092a2a72855664346dfa00ade35714f2a7
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm.upygn
binary
MD5: 82d41d31e8ddfe2e52f111052b0fc9ef
SHA256: ec7d7a818b2f3f43debf458e571288f0681d998105ff89674e8499496e30e941
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf.upygn
binary
MD5: 5cdd5ca12036ded331f915401aaf8414
SHA256: 9ff1b3c0e3df65b82a6fe1d82defe4124669eddd29307c15f3e65ee1a81c48ca
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif.upygn
binary
MD5: b3e7f9c8bb074c13fe19a74e6975d430
SHA256: d46e2363a06e746c36dc599dd6e4436f9784e608b30caad938734b3013c2d5fb
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf.upygn
binary
MD5: b2f56c9ce440d0cb164d8b1ffeb71d50
SHA256: 06c4bbea4309b28e56feffd1bffe94b939f5236b6a6eeb9904d947ee0e12296f
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif.upygn
binary
MD5: beceb64040de402c770c284b5274729a
SHA256: b4dea31c698c827abe5db3c5904aec02e9cca337fb381deedda96594e0c22bad
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm.upygn
binary
MD5: ce7a3682741e76c17fcabdedbd3f914d
SHA256: 9d2f7d0ec88406ddb24a6dbc7234ea91e4f54f5c8d9aabcf67388a8e43b0f3b7
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.upygn
binary
MD5: 447a26d3f2d49022590a8be3e704e49e
SHA256: 5247b64615ba9d2cb3a68f08abfd62f54a3573b618517ec84b4df2dd53a8e569
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg.upygn
binary
MD5: f3c76f238c1acf910f564a2d1ed54489
SHA256: 131158dca8944790bba8c424ce06f5029bda94b06814cee751eb790054ee1030
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml.upygn
binary
MD5: 8e00361712c751c48b07dd5e67522b11
SHA256: 02c970eb6daa10ae8f6d3eba7052a96e1d2ae7a3e6f4e3e66362cba5159b8ffd
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs.upygn
binary
MD5: d613bc493cde13bd822efd0332fad797
SHA256: af1c2ac53f1ae82218c893c96b9cc14c219222d66712854ad3c1eeb91f928b5a
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs.upygn
binary
MD5: de9361caae5e18043c8dccbc44807bbe
SHA256: 50782c2ae987beadbfe8bf044307111f267ba0757d3afc21ae0a0917086df461
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log.upygn
binary
MD5: ae24363af138f068016f6d2fac57670b
SHA256: 2fb0cd7530f049432b540b2957f1684a61b816f012eb048fc39310e3c4f8aad7
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log.upygn
binary
MD5: a255c48ea86fd7aa5b2bd8cfcf56e65b
SHA256: ef39e812bceabc0e749486c18b5ce63d027f85f625c8ac9e8105c4bf020b2ace
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk.upygn
binary
MD5: 2f12b910ccc7587164b1ebe07dfff950
SHA256: 78a231600b7b822fd57d9f053b52573f4f511d6ed6ca3fa99785caf7fe4c0713
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore.upygn
binary
MD5: b4cd2f28a511b38fae155ef60bce29e4
SHA256: 67f7c57d1a2489c49498c0bdd116b84898d93f4959a538b8f5dbfb6e9e8875af
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat.upygn
binary
MD5: 9c354f28dccf673de2d3adcf05d9084b
SHA256: cd22b7a16c736f9b372985de1379060f0f50539ccf89b68c7455abd6e9a18d86
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log.upygn
binary
MD5: 33e4c805587db6b0015cb615736ffeae
SHA256: 6687fca403de356235639e6930600a228399d4412f41c7322f2077e0f6596a24
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount.upygn
binary
MD5: 2bf2ea6eb18c89f5ed32dc8d6359c3b1
SHA256: 87ed06167614458e6b9dc93af23599eba263c6aa2522a8e86c0ca8bb156992fb
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount.upygn
binary
MD5: 2cac2df1f700e3f5f3aa806044a45020
SHA256: 8ecc323ffd4f348769a33855d63d11e321718d41e9bfff5193fed1d161b7c669
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount.upygn
binary
MD5: 613760b687b671804f2b894cd579d9de
SHA256: b03afc3d3e04ddf5b5b207a29819a3aaf732b2621fd2208fca22bcb9e4ee8fea
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl.upygn
binary
MD5: b526015f920429728d9b5a23d2827f0a
SHA256: 46c0a387cbf45c199500cc926b26ede432ec2172f7817d334dac0e5f850816db
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl.upygn
binary
MD5: 6b44f650fcef8eabb16293aa12548e7f
SHA256: 559e5cf58d70e83ae8721d36858e14cae9b26678da76d7115553b134cb1f4aef
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl.upygn
binary
MD5: bded34e8a5b737b8c28089ac3dbff246
SHA256: ed3b73d2dd44f306eb6c091fff11366d4a0f4c7f306600d1866928bbdc67c229
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl.upygn
binary
MD5: 3cbbbafc80045160636e2ebe1c2f378b
SHA256: d94c0b909f56c616bf17d116a39a04233a12266d0db0193acbda6d509b26802f
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl.upygn
binary
MD5: b4ac80d821e9afd5d4f3664ed952513f
SHA256: 2141c8fc2bb76d44e4816e97fd9d735ac1f3f82b158323626fa18f76f2c700a1
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl.upygn
binary
MD5: 5a52663f8b7082c3b4dc02249c6f07cf
SHA256: 39a078c8eaca7e937dc9d21ca96565668bb0d94e9a074b46d35be7dabceda02a
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl.upygn
binary
MD5: a21e4ab0e7b098da0a0d2fc20daa0146
SHA256: 738445eaf6b4a15488b122ce5bfc7c646579f320db64bf958e936cbd3f15c029
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl.upygn
binary
MD5: 8915df93d913f58311b46b76b98602c7
SHA256: 3ca05bf3d1c42dfa3a015c8a85aab3d770bdc63e5ffbdbefcaf4c3433c824880
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl.upygn
binary
MD5: 7a608ed0b466daeb54808ee09b209c18
SHA256: cb6abea6e635ff25a48c4d7ce44bd6728cd40593d314d2666ad877e98b77da6c
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl.upygn
binary
MD5: e40d5469d9d8f64817c99a3a207453f7
SHA256: b872c10bf8bd2bb32a30a133991ebf07055e5d50b749678e1968a65d8ebe9c63
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl.upygn
mp3
MD5: 2b9e7dc31ca74cc213da9b5c1112c7b0
SHA256: 497cad1a974236bd6051028ade05852f2eb222fc65bbc11f0178ccb04ac8cbf5
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl.upygn
binary
MD5: c2ca9095c866d71b738dbf9a378e7c6f
SHA256: fa4bac067a4fd261c4626f94198c8b2cecfcf50a9f801ac20abb8902a348c774
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb.upygn
binary
MD5: 1a73745c8dcaea39d35b8b6ab9cde0fa
SHA256: 4e5453ab1bbdc5d31f5d61d9b07ffe63e44b4650a7e03b8658c858ef7e95362d
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb.upygn
binary
MD5: 2e8d923ca74e5d15bd9e86d5b0099fd5
SHA256: 15f9215dc15ff3fb43feeb2c63cba7a41b8a34d5d6906a46550c7ffccb9bc198
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.upygn
binary
MD5: 82ba1822b7c257aa32a04dfc17629e6c
SHA256: 21bc0d433a811f5654fbe76c6d0a600c1e0202e7ba3e84cf6a0986c11cab28c5
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\HPSK10OB\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\VM3JD5NM\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat.upygn
binary
MD5: eee6de1ebb7bcb92dd2b07432b63fd1e
SHA256: 6acd037da87617612ebf0695090ff5c37ba37d4346c7f412322a97ca2e754ff3
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\G4PHTCUR\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\9RI45C46\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms.upygn
binary
MD5: 0762be5813189505ca181f7ee68c15d0
SHA256: d4e8780c6cc1e0cbf493133cb0171be246bfae2c3a42e039d236f8439a8ef2d5
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms.upygn
binary
MD5: b9a5e1cec72eba53841d7cf1a4e627a1
SHA256: ae33279042f91907220fbb5ddb60c4f9c20062dc32a8ac7a440ce41478cd77aa
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms.upygn
binary
MD5: 16e09228eca784d41cd5f8fa5470ecb8
SHA256: e75b569dcdd2a0b92eeb05798ee4385240d9954a059c1259a04e92e14e8decc6
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms.upygn
binary
MD5: 5660a58e069bae169371e5d74f7a8df3
SHA256: 8ff26e0d0ad2870bbfcba0b839f8f4162b4b4ccb05e197f3d5ca52f2ace2b414
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms.upygn
binary
MD5: 6499c0543e21e5b2ad81ceaf2d78428d
SHA256: deb61cc78c026cd2842fd09556b41724c279ef0e0c0d7d1d91c999949916712a
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms.upygn
binary
MD5: e039a311f02aae4c20edc2823000c3bf
SHA256: 51c04ab8500dee2203a7bb6f6e56e7ba02b047bf8ed085f1f92c0dac7fd7efe9
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms.upygn
binary
MD5: 01205b81d595133e75c0b82b76aa1703
SHA256: a2f88f9c0129ed64bab097a29d4b68f060b80c1e852a11ad2cc121785ecd6252
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Administrator\AppData\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Credentials\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\History\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\AppData\Local\Microsoft\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\Administrator\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.upygn
binary
MD5: c43bbcf4c85f439d4542fc73f619eafd
SHA256: 6e288702312ac53e4dbd3cbb12a5ca832763c11b2632521d7d20e921a1fe3de2
3052
10_.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.upygn
binary
MD5: 0b4de4bf571018ecd291d1830fdd19bf
SHA256: 4a73f76fb8b206c0f29c8014fe3fb1ba8574c3f1da49b5d22981e8cfea1538fc
3052
10_.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Saved Games\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Searches\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Pictures\testshe.jpg.upygn
binary
MD5: 61bb2b020f97b57a7644b41a6dab8f3b
SHA256: 0497341bd7f3671487a521cb23946074395267ce4eb5056fa771b5f3a947b743
3052
10_.exe
C:\Users\admin\Pictures\womanothers.jpg.upygn
binary
MD5: 0998baee6c5804e62129c083925477d3
SHA256: 83d79b0e664243d59b0e4b356242d877e1d188bf37959910e0ebbedfa2239454
3052
10_.exe
C:\Users\admin\Pictures\womanothers.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Pictures\testshe.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Pictures\likepolitics.png.upygn
binary
MD5: 5b1aa0ee9dd865e66acf4282e3594f9b
SHA256: 2b62f78b376c1eac2558e4b7481d68c3875966e31dc86aa19655bdc7a2e29d0b
3052
10_.exe
C:\Users\admin\Pictures\enterprisemeans.jpg.upygn
binary
MD5: 7475c2fb46fe7b1285c45db22c1832dd
SHA256: 2b6e5913b90b1f9f7d58748295635fbc1c46772f78250a5aab1d51a7bf787e53
3052
10_.exe
C:\Users\admin\Pictures\relatedwashington.png.upygn
binary
MD5: 263199c6a32063d832a969288c7633b7
SHA256: c57da0d9d883f692f51a32ce2e7763ab908574bbadac64f7718fff6a5cb33b7b
3052
10_.exe
C:\Users\admin\Pictures\likepolitics.png
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Pictures\relatedwashington.png
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Pictures\enterprisemeans.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.upygn
binary
MD5: ca3b7b61b7128784f045e2f5d5c7985f
SHA256: 9ee2bef8462240268f50508be31d97837d3d77b459529b08e072d536bfd18f25
3052
10_.exe
C:\Users\admin\ntuser.ini.upygn
binary
MD5: 69f14e3a861bb527089253bb5deede13
SHA256: 3c13d9565380808e3228d3a8b8e69b3e7e94770be02eb195a89e39be28649a57
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Links\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.upygn
binary
MD5: 408c5c6327fd338c1ffd5963b818176d
SHA256: a49bae66021f4586395f88c251d8081256ed16fcd215a18b713434cd8c32c85d
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.upygn
binary
MD5: 899f363c76dbbd4b4b14bf09bba2eefb
SHA256: 063dbd4d0be1578663df9794196b1cbe4a7163835b46f2027c6b30ad96d7ab40
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.upygn
binary
MD5: c0f4262276e155a8daf6d64081c553de
SHA256: 0d0cae1795db5266861922717574f6567c279bc9836ef61ed7bed96de20f123d
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.upygn
binary
MD5: 7291bd76934bc1be16f8d8423b6205b8
SHA256: dbf32ac2f96b59c9aca77a5a7e3b67467194fdd15cbaf6423f4ff0ba077ac2df
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.upygn
binary
MD5: 0396b4aa68641df4b68a7f0515229b44
SHA256: 994f70efa77119bd7998839f9dface7b1fbdc3321a617617bb1d176067350b89
3052
10_.exe
C:\Users\admin\Favorites\Windows Live\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.upygn
binary
MD5: 4b3c97dfc2a7ea0dc25c9182712d9fe7
SHA256: 6c5b3ff07a30ec69543008b6be30c675fd0995b7dcfd8cd05340ded82e85b421
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.upygn
binary
MD5: d0d9075d96bb64e275e3055a641dfa05
SHA256: 0969bab81e8af8bcfb48095bc874bf978fe4734066e7c109cb6bf077de4ae9dd
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.upygn
binary
MD5: efc5ed7ceeba196976e72db54ad899eb
SHA256: e379cf1c24f0e5ad78dc6726b84f1f361a736e156907bbe65696b2f30bdda2ad
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.upygn
binary
MD5: f09ab4da5bdcab8cbe56a1a6e2a2224a
SHA256: 443deab9de3afc0db1b4c57bad31177fc91adf93a6249d9d9bfbc12a53cc42e1
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.upygn
binary
MD5: e0556f103c72f1322a93fa5f05ee26a6
SHA256: 43e29e4155fc8651bb901b10bd352cf7c7b08795ea9a81032b37da30600ee0f2
3052
10_.exe
C:\Users\admin\Favorites\MSN Websites\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.upygn
binary
MD5: 75f45f59ff8db3811c5c190922c76e00
SHA256: 34369a5349e630b4add5196b00dd25164fcff3fb31efc405793d288c33b5b1f3
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.upygn
binary
MD5: 2f281d4f7e77365f0a6dc3afb5558b62
SHA256: 7f1cfa7bd521e535fb4dc9de0efadc8eb8b1ce07a6b6aa637fb0d0ada580634f
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.upygn
binary
MD5: 150a69a18f6623b9193dfa10309172d5
SHA256: d700156e2cf113c56e3a44a5469330fb05393fed09ba94eb9b77bd275ac0e18c
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.upygn
binary
MD5: f1a1ebf49a62a045067928370bb2cc23
SHA256: 6fe75f07c18b118053313b011d0a8612a7759980b47aab39fc5e8ec1e6be28bb
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.upygn
binary
MD5: ed9fb239ac979e1241ec5552d45ee8b4
SHA256: e1c17b118c4edd9ab4dc54125e1f09655e00518654d47fdd49cbd671edb2fc0c
3052
10_.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Links for United States\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.upygn
binary
MD5: 1fefd1ef52dca599cd679707cce5a5ed
SHA256: ada4047d08322886be87c860238bb89cc08c0ed403d9b90ce3c52421693945fb
3052
10_.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.upygn
binary
MD5: fc868a7af321ae2d79cffac43a0671be
SHA256: 4bf4b8c09ce5412279bc8c9c4f1ceecf42b4080a904f0ab6b5b5de664be28ebb
3052
10_.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.upygn
binary
MD5: bd2432ae63c08155360e3d42030366a9
SHA256: 5a2afe56fac14aee1f5821376547f9225bc402d74ba6053ae7e5048cb80decc0
3052
10_.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Favorites\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Downloads\methodsbasket.png.upygn
binary
MD5: fa7f246067567a92802cc35edc7a4e86
SHA256: d8b2b1c69b00cddb1de6ad06675de97556fd8cb1d02b6d27823800510789008f
3052
10_.exe
C:\Users\admin\Downloads\coursemarket.jpg.upygn
binary
MD5: 8dbde5b6ce84bf50ad62e1f2d5e3b8f9
SHA256: 0508e611bcdcf22d6b78431920682e63303ddcb9f4c88f45f8c5d125ab1daab7
3052
10_.exe
C:\Users\admin\Favorites\Links\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Downloads\coursemarket.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Downloads\methodsbasket.png
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Downloads\bigsold.png.upygn
binary
MD5: 78b0feb616d16819608d5236aede7f55
SHA256: d1599a96f93139de41d8ace8fc3814f3f664385de8f78d57dc0ca35b1d47f30c
3052
10_.exe
C:\Users\admin\Downloads\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Downloads\assistancenetworks.png.upygn
binary
MD5: f79c0d06ca41e70875a20268c3b69522
SHA256: a8ec1232b137011fffdd6fe5808b53d3dfe2238a4ea74033450c9308b4cda8b5
3052
10_.exe
C:\Users\admin\Documents\workan.rtf.upygn
binary
MD5: c701204f72b21b12946cb1296cc613e0
SHA256: 43bf0ac1a07fa34a2626258ea47b5b1684a13cd891492ff3fb5eac4bc1767919
3052
10_.exe
C:\Users\admin\Documents\videogalleries.rtf.upygn
binary
MD5: 852373a69d5703ccf17be472d9cfdbdb
SHA256: 9c8ff3166183923a69ce424c07f999ff15bfedc4a789aaa11156ddf821f2ce2f
3052
10_.exe
C:\Users\admin\Downloads\bigsold.png
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\videogalleries.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\workan.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Downloads\assistancenetworks.png
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.upygn
binary
MD5: 0fbd8e914584fae4d87c087ad977be66
SHA256: 41137322ddb02d410c40793d9c2c6d0b2bcbc10eacdbb89bc95969aa7f9cea23
3052
10_.exe
C:\Users\admin\Documents\reviewsdc.rtf.upygn
binary
MD5: 7497f0c0d2f66c02904089640a5a0ddd
SHA256: 0ae9e20784bab40f979f5b40cda0718bff6d1787d4da004fe830be0d3625aae1
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.upygn
binary
MD5: dd41a96b4b319ffa26061b32bc2301e8
SHA256: 2fc64d811b13a94911ce2af826148cc942e7c47cc259cbc47760421cead5dd36
3052
10_.exe
C:\Users\admin\Documents\reviewsdc.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.upygn
binary
MD5: 566abbc7353740d08127c7a60414df46
SHA256: 02763800b7e37c2be7fbc9ce21ebf97b8cb4eb7f1e1bd22ee860c6236b5865de
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.upygn
binary
MD5: 88c2f007cb3e8e44c1911a641e9fc437
SHA256: 182b3d78e69c87a400c5e11e9a40a9ad6da5f3540e6122b66b80f8976bb9191a
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.upygn
binary
MD5: 6fd22a9d727aa80a69b0075db36131a3
SHA256: efca23fe8b4b87b2edd99e98f8e88c0d84540fd76603780c11aae0ea338b4328
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.upygn
binary
MD5: 78317a0825d85e2f644befddcd92b093
SHA256: a1cf852c2570adc847a9d6d3517efecde22b4fa416acd6d13048ccae380cc80f
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: 68cc1f413566b831f68272a2ee16f1b1
SHA256: e782d4c19186a89e60341d8746447e990b5b49a678d1a180b4b2523c32e2ea8d
3052
10_.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.upygn
binary
MD5: ef6bb962774308aa376b463ec962e649
SHA256: 6b5340047ff4b71b9209628315d3c32ed58ad0b8f01cea98687fa280bfdb5156
3052
10_.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Pictures\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Documents\followinglast.rtf.upygn
binary
MD5: eb4435e61887667ffd576098d7108506
SHA256: 109acc3f47cad133876590cf1123ed6c1b00ab7427f3dc241a4e93d806e4a2fe
3052
10_.exe
C:\Users\admin\Desktop\xmlfishing.rtf.upygn
binary
MD5: d38ec10bf32c17912597f403d1daa0df
SHA256: 1d7ffedd748d5d25b5e928345f0b69c88d2231f84092ca2d35d45eb8062869fb
3052
10_.exe
C:\Users\admin\Videos\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Documents\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Documents\OneNote Notebooks\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Music\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Desktop\xmlfishing.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Documents\followinglast.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\weddingwestern.png.upygn
binary
MD5: 10eb671337baf4244a027cef61469c3e
SHA256: ad63e838227a456e59e79f706ee337b3fb89b08d729c5bf1d793f3ccc6ca8a2c
3052
10_.exe
C:\Users\admin\Desktop\travelcopy.jpg.upygn
binary
MD5: f852dea35b5580a4518018bb769c46a7
SHA256: 45244a34a0ba2450d4fc7fa28a4e239f56cdb016ee6be9eb81180957547f89f2
3052
10_.exe
C:\Users\admin\Desktop\takesbegin.rtf.upygn
binary
MD5: 63a44eb2d3c7a2579bd712655a21f987
SHA256: bb758e535b7ff64abb8d2ccf734a4fd21825d63b86e14601690e8d3ab4b0e61e
3052
10_.exe
C:\Users\admin\Desktop\thursdayknow.rtf.upygn
binary
MD5: 2bba8f540b5be7a54f74245dcdeacc28
SHA256: e89f620dd69b8bbdfc876d19ee71bf34b1d89dcb88fdd09d9241b0e908ae94cc
3052
10_.exe
C:\Users\admin\Desktop\thursdayknow.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\takesbegin.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\travelcopy.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\weddingwestern.png
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\restmilitary.jpg.upygn
binary
MD5: 4e906db223bd91b49102c528bf93d2fd
SHA256: 5e421e7fa137cce52708818a9743c199d84084c10fbcd472be0706a831b27c13
3052
10_.exe
C:\Users\admin\Desktop\enjoycould.png.upygn
binary
MD5: 5de5600a399bee04183f16b01fc46785
SHA256: 31f12e868e9b1506a198226debfde196cc863533a0a799992d40ef0d1c66ef03
3052
10_.exe
C:\Users\admin\Desktop\reportsold.rtf.upygn
binary
MD5: a5829720912529987badcafa389006cb
SHA256: 2800ca525a7076b4cc0b19ecaddc48b7ad17f9c0b0b18a6cce5a861238b23532
3052
10_.exe
C:\Users\admin\Desktop\needhit.rtf.upygn
binary
MD5: bf66b3e8e8078f56ff85968f0d944c59
SHA256: 103662c29e5a8844d6baccdedea2bdb30f8559442cc998692aa4cec8959d6e1e
3052
10_.exe
C:\Users\admin\Desktop\offeredwashington.rtf.upygn
binary
MD5: c0936c54cb2784a2d6a9071135e2a529
SHA256: fd1716df34fe6af9a4d539ad9277c14491a5c286132bd8775ceea65480fbd8e7
3052
10_.exe
C:\Users\admin\Desktop\enjoycould.png
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\offeredwashington.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\restmilitary.jpg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\reportsold.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Desktop\needhit.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Desktop\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Desktop\describedgay.rtf.upygn
binary
MD5: 2ac79ff18e341e7c6350841ace8b4b09
SHA256: 7b18fe8bceb98db53f406cc38ffa67291c2a52ad10ad2bbe1b87389bf16cb67f
3052
10_.exe
C:\Users\admin\Desktop\describedgay.rtf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\Contacts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\Contacts\admin.contact.upygn
binary
MD5: 6af52c9748cfe660eba903a523a6bb0d
SHA256: 539676920227b211736499e5303e0a9199baa51647304912e50e04fce2dccc42
3052
10_.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\WinRAR\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.upygn
binary
MD5: 0aac9c0b5b04c756d401fb0a1212386e
SHA256: e47ed79e29b7d60ae47436d21620e56bc0a7ca0d73c1a8b5f2640c2b9566f146
3052
10_.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Sun\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Sun\Java\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.upygn
binary
MD5: d3a6bde6c4e7807696a0b87fd848e137
SHA256: 4e6a3b2ca866fa1063485d393d7252b464175dffe4c708ced0b46d8f7b880529
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.upygn
binary
MD5: d4862086a096237282b78e8838bb0f9f
SHA256: 1c6d185eba12414a8b80ee84b32a2bd959feb794bcb55c2caa5ac16cea657234
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.upygn
binary
MD5: f8286116c1045d1e98adf7538598455e
SHA256: ecca85d314af0a17406f528a2d1358f8cb3ff4a7f765c6cd06238d55d037dd43
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.upygn
binary
MD5: a57700e091475fa5fbf09c31a986ff60
SHA256: b8a42ed22c4695cd7ab08500f019520771aae03f5ec8e8c125109310c85a816e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.upygn
binary
MD5: 0cce4c98a5ad093862cc79d56b1915b8
SHA256: a38bf831fd5107c54d1b021c68b3784ca0be2367a48aec07bb30127b7efe03d7
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.upygn
binary
MD5: 2b34e4f238988bb3f54d035adcf446d6
SHA256: 1ea0e4784916360d4caa643fd8bee006802fd808e2582bc35cae40fb923f7453
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.upygn
binary
MD5: 868799b0af717f383bd58ae0e266c396
SHA256: 86ab643ef814041387de6e02b135f9ee482ceda7fd2f788342ea9870b9777761
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\logs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.upygn
binary
MD5: c41248823016dd32a9ed0a57433eef72
SHA256: 7aac9e0f8e96043d56aac2454558743062b09a65e5e3550f3f204bf4241b54f1
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Skype\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.upygn
binary
MD5: 97698ac62ebe0bdc097430d3e8ecaa8e
SHA256: 865acffa451da286126b5013b4423eff374a8ccdfdf61a21d2236673a1feaca0
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.upygn
binary
MD5: c4c71a81042fe760f3d3aa56b2d0dbb2
SHA256: 7b91d2f3c332029dd93810dbd83e3fba753832d4d85c5945dcb8a0e3bc9365d7
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.upygn
binary
MD5: b9730eeffd9aea40b55cffee3e0c2ee0
SHA256: 3480e073772659ec86b1fd2f8cff0c5b66bb76212a2cdf433b6405a6deec2203
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.upygn
binary
MD5: 5d206fe8382a7535888bd17f75a240fb
SHA256: 18e6054ed6f19b2ac1ec8c3813eec420c1bb7a24138b399952f1edc67c479a48
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.upygn
binary
MD5: 8ab71384c665e2fbe18f9037a9c475c2
SHA256: 2bfb8749084a506b65ad031a9ca51061a7c5855a1cd251ceed519936ef8c5187
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.upygn
binary
MD5: bb0255b8b03060ce1d1a2340ee853024
SHA256: a28beb6fac1a6a1ad41967b2ebcc9b5d46a4a9a94c9b41358c93fd12c12eb9f7
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.upygn
binary
MD5: 56e902bb774dd3076a9163a2494e5ef2
SHA256: a5e178ec200a94b94b8099333b6e5f8a8e57d90d115d479f3a461aeb5ee5f824
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.upygn
binary
MD5: 9b726fcadc775ec5093fec1d0efae213
SHA256: fad9d6070c565c43cbadf8cd52a8c590deff080389aab8c0fd22635a4716459f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.upygn
binary
MD5: be9ca31a297e700886233f4ee01a0ed0
SHA256: 2244feffb38b9a87b6ad237ee589ab94d6c647e4332a910e0b32ce75fc4ade07
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.upygn
binary
MD5: a53b970f9f7cdfddc10e2edcf5acc413
SHA256: 6467ceeb4fa95b6e08f7608d49218f511f242d98b204902b095ec1797f0ea9ed
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.upygn
binary
MD5: e400be68f10b61a7942568b99991aa89
SHA256: 2f3c5758f3e8da3f9177b1a92ca8ffcc85ef30fc4d5e01775477a66d9cf602e8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.upygn
binary
MD5: 4a1d8fc01c29e26bbd58668823c0ecc3
SHA256: 50276c4a88fd298d2d90ab123a582de71b26aca17657433f3de1942cf064f011
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.upygn
binary
MD5: c63e8e63f901413020479f126cf09586
SHA256: 21a6e12d410be4a04f633e1b4687d63ffb65375806f1dc56364fa81138fa5451
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.upygn
binary
MD5: a3058b1b29b1b2a7df1949cd09ee4e9c
SHA256: f7e1ebd1a911b4e46014bf8fda745b4b340c0786d332c6a401944c1033ded146
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.upygn
binary
MD5: 98cf499071d7de67d20e8474a25f5b23
SHA256: 908e09fe8d79e3245c933ecd6fb8f38c566762d040d0a8dbb72bb9cd72b758ad
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.upygn
binary
MD5: bb21c9a5e3c7eb37c57c6b9ccfd574a1
SHA256: fc3d8e18df71a0e15c786296b399712a975f803b68829d091dcdef50280bd62e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.upygn
binary
MD5: 827c0eb87fd04a37470f2d12d66b6b24
SHA256: 4a031ae28d8ac3f3f843873a814f8d04c9e727c14bd91aef708e126f08a67f89
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.upygn
binary
MD5: 702daa6f8b0b9127bf953d9880f1fb9e
SHA256: a3fbdc27ed6213f07281027c1d27cbd0adca1f2352b9eeccafb424cc64108732
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.upygn
binary
MD5: 3194b4194bbb6b1d962c516b152e3400
SHA256: 780ed04b9ab03a4ead9182d191a6c127a36d645fe5cb52ffa580b855554917fa
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.upygn
binary
MD5: 74dbafe872aaea3bf24c5655c3438abb
SHA256: c9e538549d358bf22d842ace5013a114e7cdecfad9693729f7b7ac8aacae2046
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.upygn
binary
MD5: 17c30084df2f781b6390e4a9dfc61803
SHA256: e6064683ae9b2841b5d362dadf908b5136c3eadc3311e486dc669bf6f9549d7b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.upygn
binary
MD5: 41abce5be24089723f3de079e5c4bd65
SHA256: dfea93a9d4eae4059a4f0dd8848cadfe8d123d506b7b150c9438ddf87a0653a6
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.upygn
binary
MD5: 58ff5fff1a0c7a90feafad0910c976ef
SHA256: 28918b057b7adb77ea04079ae4e7d8ad5ce5bf5d2710d44060e20c5fb362417d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.upygn
binary
MD5: 77f3180d75c2b0b08504c2cc4f08aff8
SHA256: 3a0b95ea4fec1a8e9af7c563e60dbfa0d6d0e24d692834bab956272e4a084afd
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.upygn
binary
MD5: eb597688b7fa5a4378347faa756c2878
SHA256: 596674dc2934e75ee6a60668628a92f23dc08659031a27a501b972cced629de4
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.upygn
vc
MD5: b44d6ef31b564c4b9307904dab3afb36
SHA256: e302c4d8db83af8cf9696a0d8c9b3ad5c7b18edeb384d54a8def3b301421e5e6
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.upygn
binary
MD5: 565cfa5c4c200487a3edeb44ebd67d31
SHA256: a69c8243a5c5ae3ede172318a9dbc445350f24bcbc437f6ceafdbcf768ba4ed1
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.upygn
binary
MD5: 355bfec90b68a767a7c11877b634aa1d
SHA256: 741e96b62b093f4b19a752b40b49b78671129f8757a85770180843686ffef6e1
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.upygn
binary
MD5: efd2b20b0cb7f0bb7b6195fde89dbb04
SHA256: 117611578fb12097c6efd2cbee8bdf527e735e3ea738e0f20557c87fbed4a00b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.upygn
binary
MD5: e6fa627c67aeba14785a2d27d7441bcc
SHA256: 085d99d18a839fa7779331d018981cc6c5e7a0a7aa9c43ba43991b69896e19ef
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.upygn
binary
MD5: 3b39ddf2de5991a44b1276b553f21986
SHA256: 7c6e8a0a35894fda49849d1cc9265095fce43da00a2ef7e46b1b2421136e5903
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.upygn
binary
MD5: 9e518655d7df8f90b4fb85897e5f6ba2
SHA256: 79b1a4c7ad2e6e44d6898bd0db88e0ab5304df2bdc9ec13cb5aafe43abfd2256
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.upygn
binary
MD5: c36dc7dcd599758af4444f042a4ff9e4
SHA256: 30a809e9521b0855d50577a8c4baed88f660f22226210df5f32d6c83c8c1f9ea
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.upygn
binary
MD5: 3810a3bce77e3c71f53a2e0475cb5152
SHA256: eb515c3152006b57dcb7a5e241d78ba7ada8fb66fd795d9c40f4d8ee11bd994d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.upygn
binary
MD5: 83ff9f59e9f7ad7a366ad981b6ff2af1
SHA256: e5e082c0158f56db27542e46f86e2aaad5c48d8c85d12782de035e82d1687f16
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.upygn
binary
MD5: 1662e5a08be6a0d9c7e4163ad8eaddbf
SHA256: d85ea046756ef098704ae6c33a3d793092854fc74f9c1bff1f5581e3fbacc8ee
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.upygn
binary
MD5: 479f30206f0ffce18ecea82abf7607ad
SHA256: ab318a51f6853cd11eca2d654312a4ce16fe77c588e1a8e0cf1d0abf30e1a35b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.upygn
binary
MD5: baa8dd270592756d751964da30cd9fd3
SHA256: 50f5ad385362de5bf9fc45a8d8df53bd6a2da6bc248e1947384f247e2daa5edb
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.upygn
binary
MD5: 8a236b8ef4f4fbf9cd5dab5043f6206c
SHA256: ad56b96a67c917c11d550858a1f0f8a361cef1e6139c176169d14ba08af3f125
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Opera\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.upygn
binary
MD5: 57e6cd13a9a5236f873c689e7673e5b3
SHA256: e6c7b8320952f5c4387317e85d14a1880d39b0db1ccbf3b6656e4e2338569d7b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.upygn
binary
MD5: 482987dd0d1f2b96dbc925600711015d
SHA256: cf2a3f68bd94fa78100ac284591a72712e95a6f648c28fb485f3391cb4ee1480
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.upygn
binary
MD5: f2e6dd7b5b47d27f315f34b24172b917
SHA256: 16b76eefb7934b1bfb73b653eba4c8ed448a9665f9ef4558663f8898b44a6b83
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.upygn
binary
MD5: 0c3536e9652c7cf3df353dcfae3db817
SHA256: 3c10e5aa9fe875a354d197fb6c99098e49404c171a78150a0d2eeb236d8d10ca
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.upygn
binary
MD5: fa24ba7c439115ae1e1af7536b22584e
SHA256: c270ba0e51b977e0d953c466e3c536210de976fc47cba0436e7212a5f4023ae5
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.upygn
binary
MD5: f9ac3d52dd90c20a9b5126bad29b8e98
SHA256: 2c50b679dce9172b848a7cdcf0460624992da05846ae357236848b67e6ff20fa
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.upygn
binary
MD5: 2acd6c8541d4bc8eb5b2469b7b6bc2f4
SHA256: b5cdcad646cf87a3412564371c6d0c47ddfc525475dc049b6578f9061b42d1ba
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.upygn
binary
MD5: b7f445f9063d76124108ac4973c9f466
SHA256: 3a0a5eb123e72e7e9d002cb7d1c7f0a0edfec1e92abb34859dd5e14f02350c40
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.upygn
binary
MD5: a7842d89ab618a4905ff6b70f827e0ac
SHA256: 3da9384285d6175c5262055ac8cb4e3688b5f00f6a68ce3e20ae3200c332ea73
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.upygn
binary
MD5: 5d6ed5a6836e6081e799066e701dd5a2
SHA256: 874adbe64fc9170ea9218fef37d4f7b1b9b24110832baaa466777fb2852e60d3
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.upygn
binary
MD5: 10e3e92e10795940a83e1d2b8601a313
SHA256: d2d3a0e81df3c24e0de2a7c00e073335992e1adedd4cd60f0eb4d8e0de476d99
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.upygn
binary
MD5: f73eb5e6bfb10254340f276eb96f5b83
SHA256: 7ddca69409dfcd96c39e88f944ca0522ebf1f787e90607c5c2e1926e1dbce9bc
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.upygn
binary
MD5: 1d2568e58c555d354fdae2817234bc53
SHA256: a948047f5dd2d46dbe1ab58ffa105f2fd2d4566e3d20092161073ec0d746333b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.upygn
binary
MD5: 7ac7d2a128e95c46c2b898e607709dec
SHA256: 11d877a362098fb28204730674be304fed71ad4f9ff07e98de3afd1fda2970cc
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.upygn
binary
MD5: 47e3293fd05e75f86f11dce4d19cf43b
SHA256: 9b37aea251ad8a7e9bd8ff0bf9c4a898373336854228e30570d5f4724f2ca582
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.upygn
binary
MD5: 37d5e7437adb644eb135a2eabb8117fb
SHA256: f13a6cce4fc1f51c3bcfa2b7a88040f6cace0ede9a057d4049a61ec83ddd9577
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.upygn
binary
MD5: e845db71cd767d8d228c0becfd121587
SHA256: 240ade941cd1572b295863012cceeefaa82eea57c202ca00202df2c5c19f9243
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.upygn
binary
MD5: 1721438a9e9529944f8b55d8a825fad3
SHA256: a5fd6920741e9c95369bdc733be0299dfd641d7c896d9c39b98ddb914114018d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.upygn
binary
MD5: 14f90126ad89e71240419577d22e7451
SHA256: 2e966a6855583781bc0510ff89a3c12df80e02a47625838590d5889be7e21d0d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.upygn
binary
MD5: ca5da72552260e08e1fae5fe32539766
SHA256: d4099afc113a7fc20cc6e434c1aa37031fef77132b0916ca58d06ea9d2affa79
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.upygn
binary
MD5: d03368262ee12dd8762bf9eebca99758
SHA256: 4d370d78f9b89c921f7e017df127f8036ade1c83a4bd6e7fed87441b115caaf7
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.upygn
binary
MD5: a7401bf9847ed2c03de042f3ad0c97e2
SHA256: 56af24c7aa2789e1f3757fc4c903844199253809f112eb63cea1a86c18f215dd
3052
10_.exe
C:\Users\admin\AppData\Roaming\Notepad++\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.upygn
binary
MD5: a7d6ed31e9c58f55c77f354ae81f57c1
SHA256: 38d0998461aa6fd651d673be70feacdf14a3ca50edb4277be02568de2a5efb27
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.upygn
binary
MD5: d33b048435ffb41c0df4d06ee5ec67b9
SHA256: 62cfdd78361e5f75009a93244f8d9783815bf06bc02747a33415fc70e5df6c7f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.upygn
binary
MD5: 8305748c50defbb6b448287dc3d96a7d
SHA256: 87198fc1cc57902d5b93210ad02750e7ce2a55ba3c4ca71933f9d2d6824f9a27
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.upygn
binary
MD5: a075b941e3bd133e976e60a94a11427b
SHA256: 03cfc169f7ef240f05a85b27a3b1a7ed9e2938cdea88852851d1e35eddaa2948
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.upygn
binary
MD5: 47b65316256a0ef7fcacbc5c2a896806
SHA256: b6e6d1e247043013c7014f65dc5ca61c57c4a09a76ac916b625e4923da02ca3a
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.upygn
binary
MD5: db4bb7d7d2574c392cc10c21a4fcf315
SHA256: 3e171cc34c215252910279fdc59ffc7804b516764e6af8f4ad49d0e3be9fc49c
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.upygn
binary
MD5: c32bc50ba6061c6827e5d49a39cbeb10
SHA256: 9272683767d1be87ec10005f24b9c8a8532d84a9f7c07d1b5c7564bc6528df0c
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.upygn
binary
MD5: 6be758df0920c2e08692be9bd9d5b57f
SHA256: 2d109610a6c195b55269bbd331c6f40b4186dbf8b02eda5b8fab51778727fb40
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.upygn
binary
MD5: 008193357d900820e628f9a832fcb0b0
SHA256: 3354db1a7e7500116c0c6050737ffde3415595727cec7ca2a95c5827dfff86e6
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.upygn
binary
MD5: 988cf6c9c1d51a330023a8de151af0b2
SHA256: 60a03dc1ca1a160ef5e6ef12c148caf4600cfa19751f336b5e8e4fe102285c7e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.upygn
binary
MD5: 71a6982c7270ccded4cac4adebde78b3
SHA256: b005c1f9e56f9a801033df5dc474ce2094bef7b9849452208e4995a16e30e70b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.upygn
binary
MD5: f09f8d544bac94161b558c3abfe5957f
SHA256: 14feb34ae8b12d77f6abcf266f08b04a5855b7701d8774cb055de5e7dd5787c8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.upygn
binary
MD5: f1cd54e3ae0373f7a799f3a44feefb8f
SHA256: 2d8f483def1dd7caf41c8a8a2695eab5fffae4ace5a531ea2364bcb3a966e97b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.upygn
binary
MD5: 9429d76dc007ac37462aeb39bf79eb33
SHA256: abfa8a3e2862c83a1b0ab924d4ab166e31c5abca21a517ecc56df1fb36842939
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.upygn
binary
MD5: dd6effb7a24f4cf2bfe0081c728fa73c
SHA256: 983de7f9552d4c3840f63ea0aa1deeae142b34476964f6b2dd25e4a52327642e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.upygn
binary
MD5: 5dd9d48bc803e9ad2190bc86cc43df46
SHA256: 7acf42ebf406bfb1666dd7fe4c8643c140580cbd74d32c63b66584551b3a07b6
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.upygn
binary
MD5: 8401ba19a91e0ad22f077363af7898ff
SHA256: 3e8dc0b9522f9e630dd2dd826271cc4fb74ca34eae12ebb9059199051deff75f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.upygn
binary
MD5: d740e269737db5e06917e22cf08f5845
SHA256: 56cd9474afe463a24cdea9dc1cc59752a22302e6d70a1658f0ebd2c7d125c4b8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.upygn
binary
MD5: c472dc89dfc6c8d65e3c0ae539a67f8f
SHA256: 91e29619932c4e2e2d8af8ac390107b92f885d2957fd796aa60c87c5dd3bbc81
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.upygn
binary
MD5: 35bf07235e473cf7e6b55259b4ad7e17
SHA256: 0502dc40a42543ef684139b881d624e2ca9f6878ce797cd7ee60635b921c37ca
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.upygn
binary
MD5: d1dd8a06a2ba1303236890c1ed55cf67
SHA256: c5a0259f48083e05954c2ae39f86885b0b358d1eb3b5fde4d9b16dbee1962d4c
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.upygn
binary
MD5: be7ecb07dede4989fcaeb3b73a48f73d
SHA256: 388a3c73d9d32cee47d647bbf71786ca95e16c97e2f9bc98e4cafdd83dc68a24
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.upygn
binary
MD5: 24148f73de831b311bdac0bf92c32845
SHA256: 61e55572d1ce951675332b70c52ec2094412ec1b014f1a928a80ab7cfbd1d389
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.upygn
binary
MD5: c638c7a25ef3cf99e1c2011df35a5373
SHA256: db628bb64858a35dc68c3db05c237e38b9667758ba6335c7871f3430516ad4c8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.upygn
binary
MD5: dd0594c2f8bfd521e708b5c40b98e40f
SHA256: 271cde35bcc95bdec3b76383d5216d8f004205043ab0be8f078a7287d44b422e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.upygn
binary
MD5: 3302edf897933deb1304b1347d54da11
SHA256: 0819ecc6375334e86a155b3c7e053a5215aa5cd1a17d4330d88f76153c02f9b9
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.upygn
binary
MD5: 69f4060354032a6f96ef3538918da192
SHA256: 78b3b2bdd8fabc8166d5a11653dca74d1d63c6748e133cd14df47eb4744930a4
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.upygn
binary
MD5: fd68a977d3b6a7e2ef4d02f17dd390f0
SHA256: 9ecb35a7022b68e2ea7694281b5b974128ba28c1c83960a6656431a115e24fcf
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.upygn
binary
MD5: 350e99606b4fda046c7e1cb18a5546ca
SHA256: 77317bf3d83592d469890e56f04b2fd476a3812bb423c3103196ba9f6b8095cc
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.upygn
binary
MD5: 34f30240fadf433a07fedc35040bb318
SHA256: 3aca893685a13dd9187bdc013816d6c4c08adfe780265a6a60a44f5eedc4486d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.upygn
binary
MD5: 497d980f069baa9ba657f677e2cb19aa
SHA256: 841c1b601f8bbfddea6040876bc2a9f85a617c8338e1600d6a371f16b4268353
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.upygn
binary
MD5: 2e54eace858210114463dcc34ffc1b87
SHA256: f273a2cf6e1ec4197a2b70874ddf69b4f1fc472a98dbb0603be7d4b83d2a08d2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.upygn
binary
MD5: 5e519fcd1fd77b5966f233a14fdc6bdb
SHA256: d82340edf1d7ec8651cd1c02ede0d3540412975faf3ead530439cb2851b03a1c
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.upygn
binary
MD5: aabcbdc9cec4bc1649700a8620e624f3
SHA256: 1d9a06587155106faeb2f34a74be728f3d72420e3f9b32494138b0b78e721d0d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.upygn
binary
MD5: 51342e231aef6d1c5c9c6adb32426123
SHA256: b8a0bb88fb7e4c39fced67402629d732151b723da966d1216138b59b0c12889e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.upygn
binary
MD5: bdbdd11768255bd4c18902e803fd8f79
SHA256: f3e842e21a721b31a05930b0fee40141918be2279eae5dcd8c6457817c5c2f30
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.upygn
binary
MD5: 7e11bb57be50ab0246cd0ae5d8c0c201
SHA256: f7f6dd9e987094101a1b85fc64c5e302305d94010e76bf028552fdc126082433
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.upygn
binary
MD5: e3b95a5b7469cc7129996c1acd5275ed
SHA256: 5501c5fe67e476fb40c333390d474d9ca67802c6daaa6fcc013f53fda1e80ba9
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.upygn
vc
MD5: 1304c900fed7fc53a905fa720d0f0e99
SHA256: 6d38f9421d0709a25c7829457763e8e2d9437f1af2ba9be8a31a6d3df906e5c5
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.upygn
flc
MD5: b24b84b1bbd9c535c02a2d01ab0c7c16
SHA256: bfc235cfe31cc012814c7ca95e3e87dfc57397596705afaaee97330b165ad414
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.upygn
binary
MD5: 08dfe3e04d4623befacf065d6a4a2a78
SHA256: f8aa718d5990a510fcc0ed9c41219c52826673d002149f9f377a954c257b507b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.upygn
binary
MD5: 64fc0361022a117ce9b314c709fd100e
SHA256: 7e65565a87201025d629f5dd4dbf3381abeb71cef4b7ceba8de0e631ac4d9b99
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.upygn
binary
MD5: 6c340f3fe5189cafc8c44def318efbbf
SHA256: 935573d80a16ac0ff86057b5e435ba29f7867bdd8fd061278c6e4f9bd252ee7e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.upygn
binary
MD5: a8df51d55e1252efdb8826b2a10ac4a8
SHA256: 7c51e5da32fd866381d00cb1e3cdcb96976ea4a7058cb143a36be47baf133f97
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.upygn
binary
MD5: 990a43a19ad90b730476c0704608ac0e
SHA256: ba0c4da2a6391b94183ea1212bb41ec29bed236b653af9108c14b7f38456a9fc
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.upygn
binary
MD5: 6e13158cd464db3f9e826b75ae56f110
SHA256: 3079efcd2ff6705683ff106786f587216f1228a128a540af0f41d2468a5ac5a8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.upygn
binary
MD5: 20faad902e34cde418bcdbc2cf57fd72
SHA256: e637aa0ddff31c099b07b09904a3fd7965878338df3350029ba42cf1233c6ed5
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.upygn
binary
MD5: 07198454f24018e9d2841383059873de
SHA256: 877240253d9915fbda7ba666eb99f0531ace3ba7633c7999b32fa087ec584e9d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.upygn
binary
MD5: 2615bd2a629d38237d22f48fe885cd9e
SHA256: 93f9161ef80a9cb9f314fd3432865a6186ee40dbad98d173d471b1f095c25a38
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.upygn
binary
MD5: 830de0318e74f4a80af6e19b25a8cd39
SHA256: c0df90bc36916e0d55ca08e7f9ed12b27da2efcdeebf7ec922a4139a8a5f000d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.upygn
binary
MD5: ff09192db35954bd0b38db65cf8c0f8b
SHA256: 4f3ba11752905830bada8aa49509504ef52ca0823aeed80bde2f3ddf5971bf34
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.upygn
binary
MD5: 2a101d77641309072b1bcabd3c2521ed
SHA256: 163906dc074a892266b7bcb0befbead327cc87a44de0247cec144eacb0e1ce3f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4
binary
MD5: 830de0318e74f4a80af6e19b25a8cd39
SHA256: c0df90bc36916e0d55ca08e7f9ed12b27da2efcdeebf7ec922a4139a8a5f000d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.upygn
binary
MD5: 85ad8fbab8895e34d26df622355f661b
SHA256: de02602573146efb170f6ff6d0c6568aa99b8e016060780c224792d93c0b5abb
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.upygn
binary
MD5: 8f3a1c1c24cc9719499fc6021c51e438
SHA256: d6f9e3405029a0200f87c6e84d7c9e1043fce38407c944835f3d747cbc933985
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.upygn
binary
MD5: 9e4ed0753bc135213f7dd59d6f8e4db8
SHA256: da21db1779a454ed0d106dc20432b95e71c75df7cbe614f930f6fce02595a5ee
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.upygn
binary
MD5: 088259b994db19ce51abd77031b1d0d1
SHA256: 5af8b6def19d9bbe7255e9616d7ba479c7e7bbc004a3d964b3035430f5c6ae69
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.upygn
binary
MD5: 8bef96ab35a998b808822932e0ed46a6
SHA256: 5619d6a5178783610b8bc94914c955a75ecfbd48d62db8e0baaa57370e32423d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.upygn
binary
MD5: a0e3b62a22af7a7dd18e4f22b8e88bb3
SHA256: 5f81e51409b2fa8c4fdb26bec5de62730b1c8e5637f3176b6000e54a8db0d6d5
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.upygn
binary
MD5: 4a3cec48951791f378550276dd7f0d15
SHA256: 570882b24e27233e70679481c2ba5e895898b20604499733e1dac9286c6192b8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.upygn
binary
MD5: d6ea03673ed64c4e41bd0792bb85c4b3
SHA256: 1b2bd0232da952efbf1d2598e756c919784f48f636a5afbcbdffc9e7a68266ac
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.upygn
binary
MD5: 7f5fbde7892374cbd8c576a1b82f37e0
SHA256: 35de6273a829cab53ec71f0b32faaa1add575e224ff1bc8aa60383c645233ab0
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.upygn
binary
MD5: 9d2f9db7262b40bae4c28c01a8332ee0
SHA256: a7c4497bf7e3bf1fb6422bd0afc147addfe323a759c973c503bee17dfda400e4
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.upygn
binary
MD5: a949ad30d0b40cb7a9cbe2c2443c55a2
SHA256: 22e33a5be99e4dfea8d9a66a2dc85b61e77f28687d44afa22aab0c87f4786052
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.upygn
binary
MD5: 0f78f212d3dc08da16dbd114684f2f09
SHA256: 754d940313f27f4e5a0bc90286868c80f7ab884f9e1b5a6bbb40f6a389b14f07
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.upygn
binary
MD5: 1bdc4bfd2bdc9f5439721e789086107d
SHA256: 61191553f9133e2daff62ca8acc8c1d13bb31db488f19b337adbc851cf889879
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.upygn
binary
MD5: 7b3cedc35037d2cf8d5d9a85031a10a8
SHA256: aac7c89c0cff9b8eedbc78cc09e479b5fceae5be741a9aa4b688f9e85fe2f719
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.upygn
binary
MD5: b8de4e15665fb35640bef1d2a5ddf9e7
SHA256: a9fddfc01786f2027ea5b2f537bc91e78e491ec9b2ae2d79f0864a3c2f8dd62d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Mozilla\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.upygn
binary
MD5: 19648d71a3a51279975a8ceee8037140
SHA256: 7683e1562f66e3af40001b7c1c6b84fa304fe74b45c0bb4367e647a8fa2437dc
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.upygn
binary
MD5: 593976cbc2a14bbbc3bba08d2bc4d6c2
SHA256: 4cf4d74b62d68063c01c0cd822419cae40c146dfd2651e71f4d1c2147f0096d2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.upygn
binary
MD5: f7ba90d93a5e3db1e311d83e73817c64
SHA256: c1ccbcfca28f7f425635dadede964b4d6898d1b07d07badbf51dd7bd79b6a8e9
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.upygn
binary
MD5: 2222bac3744c479b126e0691be7a5b87
SHA256: 7fc9e62387a18a29a8c8b1566afc20e20cea4ecd90fdc0642f6f1deb75f14da0
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.upygn
binary
MD5: d10898fb59215cfc8862412b7c753e70
SHA256: aa0fd00dabbe32abe9adbeb23401325e5c13db5db99100aac4e756c5322ce3bb
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.upygn
binary
MD5: ca953e3aca303ea657e74bb09cb60e7c
SHA256: f2f45022b9196c0b669f8da491e423a275cbe014f15c389b4475951867551cad
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.upygn
binary
MD5: fdcb43b4eea439f95d6e4f40ef562792
SHA256: 91f51bc776e9f6d5780dedc4f89703f4b1bedc5791b0c18d84793e363dcfeef0
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.upygn
binary
MD5: 2d9ed1b8990ee0a70dff934eb55c81a8
SHA256: 90da1faab68f7e62dfe50895f20676584367ff93066794209da8eaea44e56903
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.upygn
binary
MD5: 9d06bfb77788a5a0b209847b72bda635
SHA256: 6b3fb7c7b9c0cc2e356e03b7956e51674f40009b8b3a9b03491d11d2c8bc4e99
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.upygn
binary
MD5: 06903c1f7f38f764c9d9a1616fbb179e
SHA256: 9772bf244a1f7cf5ac3a4331639e7f2bab527376f7cebaef73fc52a26a100ca8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.upygn
binary
MD5: 1b145c6897d7c83e6e703fbe51177ac1
SHA256: 2867632f65468e102f048d7b6e4aa2df62b0ec41be63a6b21b79e6c1441ed45f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.upygn
binary
MD5: 0957c200f2d2a5b745f623ebf20aa356
SHA256: 6a1f4e91c84282f3788066e1f31d5b21c20ffeefc18f5cbe90336c5017bc273f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.upygn
binary
MD5: ee41d3523cd38ffb2523cf4c3c8eaca0
SHA256: ffef0e5248e93bc803115b6dba0f276fc57d76f1ef24bcbd196cc71033b957db
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.upygn
binary
MD5: 4147937d6753f397f8ab24f1b79242b1
SHA256: 4e0ba7cf939d088a7e3b71af918661fb5eb084d23e8b00b40c9cb173c81dd1c3
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.upygn
binary
MD5: 5c05c933abde34a181313bf5892400e3
SHA256: 1391de1f6fc0b0625b9c24fa4f635f7f52562d928d73653873613b89f95658c1
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.upygn
ini
MD5: ea3547154f34307a48acee7ed9bcb6f5
SHA256: bbaddb3b5786117cc25b64d2728a6fc50464c9982d9ab987b0866fabfc965c8d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.upygn
binary
MD5: 60c6764f8e0bb72eea6cae119f533965
SHA256: 7e4273179e8611b38bf50e7861f55981de3ccc117a82ffe458119cb1fd237f7a
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.upygn
binary
MD5: d8a6fff691c9ba47282ea549efa89eab
SHA256: fa0b0795cea5308d61a94e159dd5591dee502b215df1318742d799c985ed06e9
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.upygn
binary
MD5: 2072548257cefaecd5b5722eeed63279
SHA256: e747a886424bf3a799c26d72056aa8702b513f32cabebbcb8af2d9aaa795235e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.upygn
binary
MD5: 550095a0696f7a3039743c5a34501b05
SHA256: b39a61bfbd234ccf0baf0b56bb1e18f82fd468b174b2bbb229146cd388220613
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.upygn
binary
MD5: bb0a17c911c7552b765fdadb953ef46c
SHA256: 2b3e7adad9c41597377b9c93bfc48a576c7e50d7d04797624df7b0eeb4e13439
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.upygn
binary
MD5: 409968085d35a255b31465a355c08724
SHA256: 170baa747ef38d50455e69c5c38091fc2c6502d78111991c60acc1f1379495a2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.upygn
binary
MD5: 9b8bfb8184454054626dde55f83db409
SHA256: dd6d8b66e5b36d6c7757725bf719b5cc3096073b9af4f0672945d13fd4bc6e8e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.upygn
binary
MD5: 6250b93dbe9ff0cdcebd2369d23d43dd
SHA256: 34f6b99c1da425fc624b0ccf678fc440e0a22ee34b2818ee938f752705293f24
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.upygn
binary
MD5: 4200790330f89463877072df6699788a
SHA256: 1396a42f84edf6d51e8462482f3a3c039c53865697bf6f07d27ec7d915a9f952
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.upygn
binary
MD5: 12ae56b87997288e733fd0f13b244ace
SHA256: b9a328d2cbf0abab76f7a7f118ca817c548f759df9e097972837b3ee572eb591
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.upygn
binary
MD5: b6edb5ba79c516ef8929029b75cdade7
SHA256: de86c948f8e759c3cbc6cf603cf954b8ce6cf41163a88008cad2f8f8c802eeeb
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.upygn
binary
MD5: 544ebbe4943f7957b75b6b753b953439
SHA256: bff7ff16e17d24a071e1bd02ba4fc1d22d48c49c4c9fac964fb4515f111a0007
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.upygn
binary
MD5: edf38c9ddffece306332d6a1b6ebdc67
SHA256: 7f3e8c2339025fb15990cee9072935489d2ed0388122e3b8eea1b21b7a6f0a9f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.upygn
q
MD5: fc88fb2d29bdcd0b62c485e5570e0e2a
SHA256: b9d9c0f7c9c4528afef2316ac1c2019707b59648ed3ea0b0e733092619e4b680
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.upygn
binary
MD5: 94cc91c1cb1c64bec5919611855b00cb
SHA256: 39d191f80a0c90ed149357e66937e7db2a86214b874e9e070894161acb1df418
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.upygn
gpg
MD5: 3567e1c46bc1ce5065e5c081bc879f48
SHA256: 33e5cccb63c5509b2ef4126f3ee619c3a3f130d18c5bfc8027538440f1cec9f7
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.upygn
binary
MD5: afc0a927ed682d37ee1aba307fb6f4e7
SHA256: 75b5db07fd830ac922169e402d62684bb4cd7c6f669fd912e991a692510f4842
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.upygn
binary
MD5: c1a995fdb5492d8ae7590a316a0d3b13
SHA256: a205226d6add14b113ae76e0265927c36ad34d24e3cec36ca4b8ef60a6d779e1
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.upygn
binary
MD5: 952e09dac75906cdf82e069547cd1638
SHA256: fc69079ee736fa7a237c2a0b746683d87bf9711e883ef8f86eba0e054e9d89ad
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.upygn
binary
MD5: 754ae1c6bbf925b3c7e7bfb5d1a60b78
SHA256: 26b29fba8602ef3ee759fcd7845c7bb550670b834b2f21f79477bb8108f61b6f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.upygn
binary
MD5: 5b25abd3e66be7094f1923117c126ce4
SHA256: 34ff418612d8b294ca41baf2603a33c150eb3eeda82646005997a1c1bc8088ea
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.upygn
binary
MD5: 39f171e834a5bbcc7798a97201597a3d
SHA256: aab313a654faad48b803e1bf40bed26a3265a673e3f82f4009e4a70e66d8e5fc
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.upygn
binary
MD5: 0d45967c5d74c8721c1485843ef8d665
SHA256: 19cd502e0a58d9c813e83cff348c54204e1676698d2c0c9a0add57ab50000cb8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.upygn
binary
MD5: bc07f3cc2602f5b30dbb6c74c9e8d6b5
SHA256: a892658211856ce27f96d38695f5165aa98f71918d873083b5693ccdc8e6f141
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.upygn
binary
MD5: dc8da96f5b541f001d209a5ea278eb51
SHA256: 1080a7055efe26ba05f414ea8aee87bfd155b1644d3f7894c61dc92343377a52
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.upygn
binary
MD5: 8a948b5f81a5af0618018b55c49d9908
SHA256: 06ec2111cffb3aa652072fab17eafc86d94c404dab2eefe2adc47066787b8593
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.upygn
binary
MD5: b393fb70bf21a5f933bd8ea4967c583d
SHA256: b39ed3f5fe9ad61bf198536e234a75d07a3bd296fe8c3b54cf6ee3d268ed21e8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.upygn
binary
MD5: 0b399b4e8c13af38faf7c21e8b5f2f3d
SHA256: fd909d0ea7453f7df4632dc7e0b76cd61833f0328a0e69a7f6db3422bf158b13
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.upygn
binary
MD5: b629a1dabe0eeab16e5f7b26e8e3d9ae
SHA256: 3735ad3fd77b6b9ba9e7a1d01044366ea1d7baf1c38e66023375656facc056ba
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.upygn
binary
MD5: 90ae8130f7a1d8094ccca81f54c1bed8
SHA256: 459edd689c4ee235c5c82a3772d1bf5683bea41316dfc05e5e8cde406fb81da2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.upygn
binary
MD5: 92365c11ab74c2bd3e347ae86f9558e5
SHA256: 6fed456fbc026dc0f30b70d675d5438a9e1a7503cbc401fd207396a492a49e6c
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\6e559dee-c391-4be5-bad4-09932270e614.upygn
binary
MD5: 01ede65b03cb444fb3c3b41c751f8d3c
SHA256: efce74ab251f05e90b48c2b70e41c1807f6ff541d4f10c65004b0358c361ccfc
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\6e559dee-c391-4be5-bad4-09932270e614
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.upygn
binary
MD5: 4d08e8dedd175c460cbd732e4ecf033c
SHA256: 77502b1868b1f5c67d9b9e83be3f147a2aa02e9f8351001ee809f2e2f151a9f3
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.upygn
binary
MD5: 94bafb00441caaa5c9f9b23a714181ee
SHA256: c03238dbce3520bf2ed8b7acc97a8b8e9a56a9a33111df3c48162a59cb27d84b
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.upygn
binary
MD5: 71dd2fcc1a18353c7da74267fb2d2686
SHA256: 560b82599f010dec404aa7d0e04960ea4df6961a280feecbaeb003cd8bd7f97a
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.upygn
binary
MD5: 51fcd6133343c9b475e8854f1e2a8fe5
SHA256: 9cddde1f56909b6a4bb4fea304854f7f61fdb57a30ee1d8b159a669edfb9720d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.upygn
binary
MD5: 1f2fa5af28b2b1c3375b23970942f1e5
SHA256: 6d3bd9bea03e9f312ad8a3a52749ebe8ecb389def17b08f79832f21ecfdc9531
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.upygn
binary
MD5: e236cd89573637234856750b1d7004d9
SHA256: 3e28253c4fcd4fa2e228bdc5c4950337b30f523a034b24d34b6cc6ed1d4286dc
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.upygn
binary
MD5: ffc56d9b57a6317d70888910d7eb7be6
SHA256: b07c48685a5ca5b111e8d6cf45ddc089e3c0f00f64af972c16a0970a0b631074
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.upygn
binary
MD5: 602d95ce9c59c39344da681b8fdc4987
SHA256: 166a5f0a8f8b512b1f16b775252133e2c6681b8bbfe15bd5aca4932124a65244
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.upygn
binary
MD5: bd3fd4f82501d570a746289666f61455
SHA256: 92ff8b909482e0313e36ba384f311083b03567a1e01a7db48c395d5db6576e61
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.upygn
binary
MD5: 41a38738c7b150a1990791412891e979
SHA256: 9c90d9b33edbe93486401ff4c0308cdc5583f10872e1a4d4c2ed6e6944c0af1e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.upygn
binary
MD5: 9663a6c7ab59bd3f493e6760758f7605
SHA256: fc89622e059046ebf80668a90d21d9b017fd3e49b37a9f9042ae56c21f814c56
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.upygn
binary
MD5: a92835ae9e04d4fdbc773012ffffb1b2
SHA256: 75cce7fdf35d1baa23d0d250caa6f81ea48372828028010b8eddeb633c4ff73d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.upygn
binary
MD5: 61564b93ff1aa6a077f196865fb81fe4
SHA256: ea1a78dda2ae9cd631c1d2e7c9a61706a2dabb6b8ad595cf6cfb293229ed1279
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.upygn
binary
MD5: d2f6528aeef09784895f2c1dc04d35da
SHA256: 3a3fb67804fff4d704567791cf3abd45f7c70ed3b9ba251dfad91c0edfd17d18
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.upygn
binary
MD5: d7fda92c1c090305d8d193104ab48dd8
SHA256: 19bf5b58d6d3e070dff0d6c095d9337ab360007d187548a468dcf45b9b1ccc10
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.upygn
binary
MD5: d71a9852dbbb804fffaf1e9c071e1dfd
SHA256: 2a6cac0bec84a56fe199093759c848f5c2d3327c1afce4019db233d05da6ebb4
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.upygn
binary
MD5: eecfea23ac0723ee4163e591d6ffefbd
SHA256: 86e17da55e50c3d0166d18cf0e5164409838f19eaf777620c61a9c572f24d153
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.upygn
binary
MD5: 286f232acc0803383afa0183628120c5
SHA256: 478895757925c8d28db5bbaea4be6396a04c87df4664391f7c2ef83c78d75022
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Identities\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.upygn
binary
MD5: f1162e5ccb86e491cf15d2c5b0f9f976
SHA256: e9ce9e0bf5ea331b1957ba9dfaefa742cef26ef9bc52388ed84338521af0c230
3052
10_.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.upygn
flc
MD5: 9c0fc57e908a3b4438b4b7398c3847fb
SHA256: 1dc82cbd16aa02948308b2b55a13e55e4e87ab7118dcfc312dcef489b50010d9
3052
10_.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.upygn
binary
MD5: 3e9ec6d4e77ef0c7af543ae394a32472
SHA256: e0d743c041214d753288fba1d5876d059805854ef546288c1a0c605b00f83cb1
3052
10_.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.upygn
binary
MD5: 818b64f539b5abbac2d9c0bfbd2b7313
SHA256: a2da4a251a6748723a5bf4a499927fe616d5318ab01857ca295879f18094554f
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\FileZilla\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.upygn
binary
MD5: 2a24c142bc8a649ec7a2f5fd4806a4f6
SHA256: 88c2491bafaa9cebdbee1c1a122760f1428136fa9b74522f33442f54c2659530
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.upygn
binary
MD5: 0020baebc7540065dbe80edaa004ee35
SHA256: ebaadf6f28f000c454ad05b05655212a8c9c7e02cd0264791aed74f3718f109d
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.upygn
binary
MD5: 2853626a31501d446930df0994e35dd2
SHA256: 1afd495e12e9f7899d8ef131ac4a447a277ca353a2049812470f4f972d76a566
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.upygn
binary
MD5: b8208552dffc811efce0d23d21cd94e6
SHA256: 4d9362b41f5222a27a060b3f52af7f3cbf1162b2a4122f0d34a62096976d8e73
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.upygn
binary
MD5: 4f59d9792e4b608a8fc8e1b933014155
SHA256: c0f0c641f5b7e1d788593c4e0c8367fe3bcd13d32b63369e7db5f0ebdb31f120
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.upygn
binary
MD5: d9ad282ea29f15af2c0e155e0b514ffa
SHA256: 8ed7e8f3af2833e9c89a68ce0486901756755817271b7cc3faa5b3dbcdce3aa8
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.upygn
binary
MD5: e6100f67532df5844f5691fa878dece5
SHA256: 52fc455e7dd04a9a8d810f4d32bf7e229cafe3133dc9b73a0aed5cff4ae9ec30
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.upygn
binary
MD5: b6d969ff32e4871387a737ddf4d0556c
SHA256: 73d4b45b8ac42ead42671068dfb82bfa9cdaf165486183190c123a010bafe47e
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Collab\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Forms\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.upygn
binary
MD5: 6391c96d891d53c034004c1c983296ec
SHA256: 2941628e2dc1c53dd14eb0acdf631fdebfc6f1f17bae823bae8af8a0f8be4a85
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\tracking.log.upygn
binary
MD5: a90f19c9275ba378ea41846ef21990c3
SHA256: 88fd4bba9244c7988f8c6ad29ea2ed14b52ec1119aedba7811efcfac51b39d7b
3052
10_.exe
C:\Users\admin\AppData\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp.upygn
binary
MD5: c96bc971b2d38ffdec2ffc8d521ec7f1
SHA256: 66ac9214a8af930571352c87a15abc13ec5097cd6975a4a94ab09013611e8fe5
3052
10_.exe
C:\Users\admin\.oracle_jre_usage\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\admin\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\System Volume Information\tracking.log
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_DriverPackageInfo.upygn
binary
MD5: 53959efb12f1af83a2640866b0ac5d73
SHA256: 686bf8a32a27ea122469080e10333b815da64cd5c7c92b0121ed346696287845
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_WindowsUpdateInfo.upygn
binary
MD5: 4ef0e0bc439376549c9b34a6967ed9ab
SHA256: 1398626e463d5b361c56ec83282b50060ed1f9708964a8e2ddbc063ee71726ba
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_WindowsUpdateInfo.upygn
binary
MD5: 28497ff9879542f18bacdae314843a21
SHA256: d794309cfe3435aa9aab0daee51242315607190da4ed295404024b6a5927fc3e
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_DriverPackageInfo.upygn
compressed
MD5: 66b02de4c6fcf70a6a297d35702fa8b7
SHA256: 897e35c691ad6796a4a27cb469bd0552a7a31b9af57310ff556af2f1f69a23ea
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_DriverPackageInfo.upygn
binary
MD5: 041cba90f77c59c2c37465a747f5784a
SHA256: 711961ca709d253c10d7c009a3b677d5ea9eb3df97bebde176b63b3765ea25c5
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_WindowsUpdateInfo.upygn
binary
MD5: 9119ff055cd1531c49adfd00dc6619c8
SHA256: 71e9f5288d5218214f022864e9724939f5aed8c6ce6ba006f7140da621aea7a6
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_WindowsUpdateInfo.upygn
binary
MD5: 2d4117700ba6c6a9a03ca757645ac032
SHA256: d684a2a395a26f59dbb49f9cc6d2d37ddd8e6bf469a0f83e897f36e889c8f71f
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_DriverPackageInfo.upygn
binary
MD5: 5a7dd2954239a9253a1ba9e7bb43c96f
SHA256: 18e27205ffe447d3db9eb26fc3147b2b7ecbd27a7d29dd070064545ab3ed8200
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_WindowsUpdateInfo.upygn
binary
MD5: 7a7bdc43f2454b682ba5a97e6f584136
SHA256: 0bd60c4326fb0e4996f8489900fdacfa3f804515f54ec8a1fbe988846869e7e2
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_DriverPackageInfo.upygn
binary
MD5: e97eec708ae49c5249ac9673c7d0b143
SHA256: 0e144d5feaf9e136dbb0ee5a9fc07be8e76cd16277662a849e70f2321489dd46
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_WindowsUpdateInfo.upygn
binary
MD5: 3d6205e9e9cef56a318c40e90b9f0647
SHA256: 4034efd5e0491a4bda8887e1be2cda7ffb85d84f3fc77b03356a89bfc7803867
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{8B4C0ECB-7F10-47DC-AE3F-C1F2BD0A0DD1}_DriverPackageInfo.upygn
binary
MD5: 10cbb4afb2ffd443b59cfc0ae942b53a
SHA256: a90f2bb77bbcf16f90af96898068a5acabaf72595407796f1261a6245faad7f7
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_DriverPackageInfo.upygn
binary
MD5: e87ae2d3b04f382ee2e7f7a0f15a3e31
SHA256: d5509faedce63afebfa29ff17c62dcfcc1bd61e31b5585d55c0384f1bf0a8030
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{8B4C0ECB-7F10-47DC-AE3F-C1F2BD0A0DD1}_WindowsUpdateInfo.upygn
binary
MD5: 67eee7ae4afb015431310fd7dd6bd993
SHA256: 23f7d581bf4d5470258eb0480e48337146c8d1ada3bee52d511b39055c658ba4
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{8B4C0ECB-7F10-47DC-AE3F-C1F2BD0A0DD1}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{8B4C0ECB-7F10-47DC-AE3F-C1F2BD0A0DD1}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{6AF49B38-A69B-4427-8E0D-1D7F53ED58E8}_WindowsUpdateInfo.upygn
binary
MD5: 7b23d4ebe980f57e52a6bae1d41b732c
SHA256: 99002cc69683b2982c84bf30fa9ca0df83389a21656891ed78cfe43b7c9ab893
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{6AF49B38-A69B-4427-8E0D-1D7F53ED58E8}_DriverPackageInfo.upygn
binary
MD5: 164064a1738051d7cd4631f5c65df941
SHA256: 82efecf2c62a1912fc18fa533881bcd9cbe0c502aa6ee478dce789682dc6c1f8
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{6AF49B38-A69B-4427-8E0D-1D7F53ED58E8}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\{6AF49B38-A69B-4427-8E0D-1D7F53ED58E8}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{fbc1d708-be70-4ddf-91ea-c05528f7becb}_OnDiskSnapshotProp.upygn
binary
MD5: abd7d58ca4357842dee59d5592a2d496
SHA256: 4da9c66df48e97b37ce015a72e03ba2701fd78c639f6d1dd2baebcea774f913c
3052
10_.exe
C:\System Volume Information\SPP\SppCbsHiveStore\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\System Volume Information\SPP\SppGroupCache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{fc5f241b-73f6-4813-9d64-4e4f00d39c97}_OnDiskSnapshotProp.upygn
binary
MD5: 030ba8d60040953e92e34301d9538edb
SHA256: 171bee1f538904b12938c50ee68ffcdaa6f27ea0ffadbf89116b3ff17d9b6509
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{fc5f241b-73f6-4813-9d64-4e4f00d39c97}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{fbc1d708-be70-4ddf-91ea-c05528f7becb}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{ee321e85-0e9d-4572-b152-5e2dc9f9bcbe}_OnDiskSnapshotProp.upygn
binary
MD5: 1a129c601ac28a0b1235fd1b980af86d
SHA256: 9a3fbeb7f0c7ece0ed215eb72da8cfa2997d87717994cb0a3ea0eae4b392cb39
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{de4fb673-c96d-43aa-a06e-db0853b54bfa}_OnDiskSnapshotProp.upygn
binary
MD5: 5952e7ae94b6045b59dd98f0a13773ef
SHA256: 982a16bec992a4aa560e99614b9e929b1e0e608bf1a7928caf459319098684b2
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{ebafcf70-55f1-48bb-822a-5412291c8b75}_OnDiskSnapshotProp.upygn
binary
MD5: 9ea24ffdd4e99f3cdd7c0c77c6803d9c
SHA256: 5c131114d6a7f3eec509c29f7c78d6e907cf8948c5b2c3ca4c59a5a3955e9392
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{cec64297-f2cb-423b-9a4d-7695294fdbcd}_OnDiskSnapshotProp.upygn
binary
MD5: 3075dd2691a62f0bfcb414245bcac5df
SHA256: bf5f343fe0a00cff41819f5af0af1ef8af3793e8e9b9f863d82507dc914f7b51
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{de4fb673-c96d-43aa-a06e-db0853b54bfa}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{cec64297-f2cb-423b-9a4d-7695294fdbcd}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{ee321e85-0e9d-4572-b152-5e2dc9f9bcbe}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{ebafcf70-55f1-48bb-822a-5412291c8b75}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{b45425b2-5957-425c-82c9-bf873c06e2b9}_OnDiskSnapshotProp.upygn
binary
MD5: dfae59b6301d2e91312458cb575f4d6f
SHA256: e21b15cef040870063a44205a2c8d31892ca77c1890d608b5eeba2c9b926248b
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{8b4c0ecb-7f10-47dc-ae3f-c1f2bd0a0dd1}_OnDiskSnapshotProp.upygn
binary
MD5: 9c4008200748872954ac29478e9516fb
SHA256: 1f55c4dca610b0b4fb966d2fb0db29a447a3b52df74a3b8fb19a0369685d2f34
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{94e6c3a2-599e-462d-9c45-78274daded0c}_OnDiskSnapshotProp.upygn
binary
MD5: dcf242270729407273acc82cd7b0e9d5
SHA256: 7bebae465c0061efa0cee07e73b32fa8daf277758b1a651cf43426e408f46912
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{c9cf9f24-5351-4202-a015-c273ae785f0c}_OnDiskSnapshotProp.upygn
binary
MD5: 8325a3359184c07007b0bbc452182856
SHA256: 6eb568e9a126ce2dd23a667da937b2cf2a5f749806e40ad79ca3cb5ec1288a96
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{c9cf9f24-5351-4202-a015-c273ae785f0c}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{b45425b2-5957-425c-82c9-bf873c06e2b9}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{94e6c3a2-599e-462d-9c45-78274daded0c}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6af49b38-a69b-4427-8e0d-1d7f53ed58e8}_OnDiskSnapshotProp.upygn
binary
MD5: 047477df65e93fa10f7d934165603339
SHA256: 1521a93397d16925ccaa9b85d363493546677cabc5f9e97ccb73aa1272221cb0
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6dec60c5-cac5-4c55-9061-62edac696401}_OnDiskSnapshotProp.upygn
binary
MD5: 52c4d3b199af71d4d2180c45622f3a85
SHA256: 75832fbe2be8e5f6ff60f0667f0f7b9cb559d0078a3540c3b5510e1eff0cc146
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6dec60c5-cac5-4c55-9061-62edac696401}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6af49b38-a69b-4427-8e0d-1d7f53ed58e8}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{8b4c0ecb-7f10-47dc-ae3f-c1f2bd0a0dd1}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{5c4beaff-a038-4df7-9b35-072a18f8e3d6}_OnDiskSnapshotProp.upygn
binary
MD5: d8bed7826b99fbbddf1bfc943fe8688a
SHA256: 3216b4367ed82a74e8378515fb602d1a631e8ee713d59acea60732f1e29e9365
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{16d74681-6bc3-4c44-97f0-8b8dfefe2355}_OnDiskSnapshotProp.upygn
binary
MD5: d21b5de7e80c1526b7dc3a0f309f7c93
SHA256: 5a4876906dc8924e62fa8b0afd10ce7bf819977a221ead52a7ca6dd691cb1db7
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{38e8535f-27d0-4352-aa3a-ce4178930102}_OnDiskSnapshotProp.upygn
binary
MD5: a2de4b56f2ec9e4b84ee3a28ed8c3495
SHA256: 4e7cc7174550c3d804284edcb4f8bc337f38bfc0b48e8a63373c43e64174cbfe
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{3cc0f82b-873a-4e59-b89f-689fbdf88af9}_OnDiskSnapshotProp.upygn
binary
MD5: e4c3b9bbdc6b48df3e3b314f912223d6
SHA256: 856fee7ca416b3fa236bda315131580aaf1c2ba6418d0e0e7e83c405d163f0aa
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{3cc0f82b-873a-4e59-b89f-689fbdf88af9}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{5c4beaff-a038-4df7-9b35-072a18f8e3d6}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{38e8535f-27d0-4352-aa3a-ce4178930102}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{16d74681-6bc3-4c44-97f0-8b8dfefe2355}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\System Volume Information\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\System Volume Information\SPP\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{05ed3515-06b3-48f6-8cf2-bf24b1bf0727}_OnDiskSnapshotProp.upygn
binary
MD5: d68c42fc87dbd78263ac299cadaa7206
SHA256: df77760099d81b5f078a559ff3b0dd0dac7fe4889270caff1f33b22da7923ed6
3052
10_.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{05ed3515-06b3-48f6-8cf2-bf24b1bf0727}_OnDiskSnapshotProp
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\Winre.wim.upygn
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\Winre.wim
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\boot.sdi.upygn
binary
MD5: d43a83f5d0a124bfa4edb1850fdd669b
SHA256: 727fdaa89e6f52304fa2224fe6ff61ff59d210358c3561c2a5b1543fc997c7d0
3052
10_.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\boot.sdi
––
MD5:  ––
SHA256:  ––
3052
10_.exe
C:\Program Files\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Config.Msi\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-500\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\PerfLogs\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Users\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\MSOCache\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Recovery\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\PerfLogs\Admin\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\$Recycle.Bin\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2
3052
10_.exe
C:\UPYGN-DECRYPT.txt
text
MD5: 072e26d998e9200945022d38672a49eb
SHA256: 91674690aab30f21888d66f1bfa31b96c9d2b79a49e10305615955e9c7edb0b2

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
1
Threats
2

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3052 10_.exe GET 301 185.52.2.154:80 http://www.kakaocorp.link/ NL
html
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3052 10_.exe 185.52.2.154:80 RouteLabel V.O.F. NL suspicious
3052 10_.exe 185.52.2.154:443 RouteLabel V.O.F. NL suspicious

DNS requests

Domain IP Reputation
www.kakaocorp.link 185.52.2.154
malicious

Threats

No threats detected.

Debug output strings

No debug info.