General Info

File name

____________.js.zip

Full analysis
https://app.any.run/tasks/595de56c-9e7e-4dd2-b9fa-be13489fc23d
Verdict
Malicious activity
Analysis date
12/6/2018, 03:42:12
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

gandcrab

trojan

Indicators:

MIME:
application/zip
File info:
Zip archive data, at least v2.0 to extract
MD5

ce9eb637a363bee64b40e855db7d4b54

SHA1

1512ff819033dabdcf576cc84b6cc74365f23ff9

SHA256

500aa7d4af5c2792d5c5b6ee4dba12b7fbacc48f8f6d19b8b725813f034cda34

SSDEEP

12288:8IylbUUsVKMnhdaRuWBkNDwWc3nLc0OtbAuKpUzDS8yklCy44sAe:VylbVTKXskyWcJ6bRKOfZ3lCg1e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Writes file to Word startup folder
  • powershell.exe (PID: 3632)
Renames files like Ransomware
  • powershell.exe (PID: 3632)
Dropped file may contain instructions of ransomware
  • powershell.exe (PID: 3632)
Deletes shadow copies
  • powershell.exe (PID: 3632)
GandCrab keys found
  • powershell.exe (PID: 3632)
Connects to CnC server
  • powershell.exe (PID: 3632)
Actions looks like stealing of personal data
  • powershell.exe (PID: 3632)
Executes PowerShell scripts
  • WScript.exe (PID: 3796)
Reads the cookies of Mozilla Firefox
  • powershell.exe (PID: 3632)
Starts CMD.EXE for commands execution
  • powershell.exe (PID: 3632)
Creates files like Ransomware instruction
  • powershell.exe (PID: 3632)
Reads Internet Cache Settings
  • powershell.exe (PID: 3632)
Creates files in the user directory
  • WScript.exe (PID: 3796)
  • powershell.exe (PID: 3632)
Reads Microsoft Office registry keys
  • WINWORD.EXE (PID: 2676)
Creates files in the user directory
  • WINWORD.EXE (PID: 2676)
Dropped object may contain TOR URL's
  • powershell.exe (PID: 3632)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.zip
|   ZIP compressed archive (100%)
EXIF
ZIP
ZipRequiredVersion:
788
ZipBitFlag:
0x0001
ZipCompression:
Deflated
ZipModifyDate:
2018:12:03 03:14:14
ZipCRC:
0x649b9707
ZipCompressedSize:
447720
ZipUncompressedSize:
1856102
ZipFileName:
____________.js

Screenshots

Processes

Total processes
50
Monitored processes
10
Malicious processes
2
Suspicious processes
0

Behavior graph

+
start winrar.exe no specs wscript.exe no specs #GANDCRAB powershell.exe winword.exe no specs wscript.exe no specs wmic.exe no specs explorer.exe no specs cmd.exe no specs timeout.exe no specs notepad.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3460
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\____________.js.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wshext.dll
c:\windows\system32\wscript.exe
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
3796
CMD
"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\____________.js"
Path
C:\Windows\System32\WScript.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft ® Windows Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\jscript.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\program files\common files\system\ado\msado15.dll
c:\windows\system32\msdart.dll
c:\windows\system32\mlang.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll

PID
3632
CMD
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -Command "IEX (([System.IO.File]::ReadAllText('C:\Users\admin\AppData\Roaming\qaqjnce.log')).Replace('?',''));"
Path
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Indicators
Parent process
WScript.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows PowerShell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\4bdde288f147e3b3f2c090ecdf704e6d\microsoft.powershell.consolehost.ni.dll
c:\windows\assembly\gac_msil\system.management.automation\1.0.0.0__31bf3856ad364e35\system.management.automation.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management.a#\a8e3a41ecbcc4bb1598ed5719f965110\system.management.automation.ni.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\e112e4460a0c9122de8c382126da4a2f\microsoft.powershell.commands.diagnostics.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuratio#\f02737c83305687a68c088927a6c5a98\system.configuration.install.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.wsman.man#\f1865caa683ceb3d12b383a94a35da14\microsoft.wsman.management.ni.dll
c:\windows\assembly\gac_msil\microsoft.wsman.runtime\1.0.0.0__31bf3856ad364e35\microsoft.wsman.runtime.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\82d7758f278f47dc4191abab1cb11ce3\microsoft.powershell.commands.utility.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\583c7b9f52114c026088bdb9f19f64e8\microsoft.powershell.commands.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\6c5bef3ab74c06a641444eff648c0dde\microsoft.powershell.security.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.directoryser#\45ec12795950a7d54691591c615a9e3c\system.directoryservices.ni.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll

PID
2676
CMD
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\dealdeep.rtf"
Path
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Word
Version
14.0.6024.1000
Modules
Image
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\microsoft office\office14\wwlib.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\program files\microsoft office\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\program files\microsoft office\office14\oart.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\program files\microsoft office\office14\1033\wwintl.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwmapi.dll
c:\program files\common files\microsoft shared\office14\msptls.dll
c:\windows\system32\uxtheme.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shell32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
c:\windows\system32\spool\drivers\w32x86\3\sendtoonenoteui.dll
c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
c:\windows\system32\fontsub.dll
c:\windows\system32\prntvpt.dll
c:\program files\common files\microsoft shared\office14\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\microsoft office\office14\msproof7.dll
c:\program files\microsoft office\office14\proof\1033\msgr3en.dll
c:\program files\microsoft office\office14\gkword.dll
c:\windows\system32\oleacc.dll
c:\program files\common files\system\ado\msadox.dll
c:\windows\system32\netutils.dll

PID
3188
CMD
"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\____________.js"
Path
C:\Windows\System32\WScript.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft ® Windows Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\jscript.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\program files\common files\system\ado\msado15.dll
c:\windows\system32\msdart.dll
c:\windows\system32\mlang.dll

PID
2732
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
No indicators
Parent process
powershell.exe
User
admin
Integrity Level
MEDIUM
Exit code
2147749908
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

PID
3024
CMD
"C:\Windows\explorer.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
3012
CMD
"C:\Windows\System32\cmd.exe" /c timeout -c 5 & del "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" /f /q
Path
C:\Windows\System32\cmd.exe
Indicators
No indicators
Parent process
powershell.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\timeout.exe

PID
4036
CMD
timeout -c 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2748
CMD
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\Public\Documents\YGLRN-DECRYPT.txt
Path
C:\Windows\system32\NOTEPAD.EXE
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Notepad
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll

Registry activity

Total events
1577
Read events
1435
Write events
138
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
3460
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\____________.js.zip
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
3460
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@C:\Windows\System32\wshext.dll,-4804
JScript Script File
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
0
C:\Users\admin\Desktop
3460
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface
ShowPassword
0
3796
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3796
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3632
powershell.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3632
powershell.exe
write
HKEY_CURRENT_USER\Software\ex_data\data
ext
2E00790067006C0072006E000000
3632
powershell.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
public
0602000000A40000525341310008000001000100DD7C8F9962AA6BA8D353A9531C73AB613C9E27F450A79D61BE7A88FE700D7BEB148F69F945DFBA83BD1344454F3B3BCCB6FD3938E68D262AE6CEF15B2D48E0E1923714A37394A75FEA10EECA7687A1AA53B7F3A4C06E5DF3E2628FE55403900C3C9B7411D79FB1610DB58BC99C1E389F2070270593D09EC3F6E1CB7D3FFF90E6A52B6376EDC4AC7B44FCF36DD1E5E2864F072465D741B8B00ADDB069E08FAFD96443AC57222BD2690B4660A8363ADA5F472579C309D6B62C475705F82BE96575EC66880F036D089209D7CCFCD2D723DE3C08C8AF19BF128035A7F92BA42FBCCB3F516EB4659565EB6138B7B2E4D4A1B621FF4C53C0F375275535B51E38074CC1
3632
powershell.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
private
94040000F505859906F56F4A06DFD0BDB9A9759D5D26CE937FBDB4C1F6E0D672518F2CC22BCC82A96E295D1FE2AEEFBBDDFA6BA8F3CCB946087272255729460A582ED52FA318C562B6DC6F7413E17214B984519438F01D0AC75DD8910D7D55E5ED6FECC882C5E8AD772CB26390DEC503F914F09E4F74862833DE4F5C67A0D2A012899BF5839E0930DDD761DA551CEFC524DAADD124B4C395233355A76270FE818ADEF7171B24933A9B08FDE2F4A2A477AB648E1F80D3A6C7D65DCF5F19E70C247DAE7F0E7325825A435D49DCF2D20E263409E67BCA789CAF5BA928B4508326C12B52871DFCE335F91E700390F0736B13570E03CDEC38F2A23CDB2DD690A5BBFC15A32380DC8D8724890BDBFE80B300BC030BD88AC24AA82C28AA1C7000E186E73DDFEB8F1D5475A4497D5D2A0CE6ECD2EC2307251FA3AA4526BDD1D538930C24B2EBC73FB8A541B996656E25FAD9C5809F4AAD8AB770E2922586679F6E96DF60085C2D59C30A996676D239BE6BF39988C706FA71128328DCE89E4017420DC532729EBFDB0494ACBD5BABC3E1A8EF8DA14AA13ADCF318EF0F93B8783A730BE3B97BB44A413F42797CFD348D91A93316EB30F2FFC9B87EAB6B84AF27066CA34D308474704405757F816A8C1565D02B041CCF7D23F8BF6668CF6B7C2CDDAC3A91CED540B9C02A65235515665C1D0E281155C0194D90F42A96FA259AE400B609321895A91D0A7378FC2395568EDBFF71FAEBCBC003E204F4BA8DFDB4E74B7502646D62B617E5A35C5422E82869A7A31B3E955A9CC08A3E848043490B68458E9FDB6670F7B6775A658186EB5668E21DA6B2A46AAA266224B12A84D24DCB34D057BB79E7B79A85C5AC069C9965BD1850E296D3265BA33E3DC74B8F3198FF8B25B93664CFFD4C74452AE443969A35AE5D245AF5F915C8236C0681C3248E92EEA28E8623C5A69558C41D16E19DFB47C6AE9B53378B120FDD4BBCF7C20D976E0E86AE18171927A36921B4F7F7B392B2FEB024A85113A8E8DEEDE7F04D575EE0AF4AE63C8646B8B3163B86D1FD174A36750F23AA91EB9899C90FB7B06D49E6341E09468C0FA9EC092291EFBA4A47DDC96942CA8986CCA6D8B32F1D84F5501F8F9950A45D5A154676767D1AF2DC518CEA33EB179D79F48899F47CFE59006B183D7555DB7EB00D12A25BFE6D09D8D692B5C0B3E02C2AADAD3F2141B673F7A400806F01E89D5BB31B1EFCA0935006EA264F901A9225C3FE5D7E08314B91664853D8174BB9BCE471C4E1F79F65182919CD48963872679F110F7311506907E3DBBA05C3A4D1B0E503EC8CC98DE411AA403C92FFE3D470AF73149D03727CD4CEC5EB5F251AACF9067D4A51ECE790C3470EACF586834DADC5262E5D8F0BCA292BAF6E5994F558A8C1943182B6B41C72E9C23AA6A1C43966518F0705145C7E9271B42F1AA21C719C469E9E7307C4CC58320F90CD5EF9388E6B8B07676C706D4E9BB76D07F6A090F95C401094075E57A17A5E7BAF55588E6FEF312342AA23421658BD703545E30AFDCFFDC6B852F359705D2262D175E9AEBB6BDAA42AE8C72130D79BE24A5278642B9AD02ED047F694FD0A52CE37FEF56DDA235D58C901202C05B19446A6877DDC14FDEC1A068AF50CD751CC9BDB921BE68EE677541B969C549BF52C7D3611FFB293908F94A1D5DB14044DB40B3F31F7DB8093BBD015CEA79139243861A45FC64105A23F861259D0604E7AC32F85473DD8FB676BFFE29C5603B28195B7D9F384FAC2D1A520E5D5B48F6D4FFCCAAA3931993EF0852750E6A26282A7E1D2535DDB64633F9C7BD664FE55347172E1F75076EFEAA0F6C9CBA8B1528932D9CD08A3CB5DEA9E4EB9C3E574391BAC5E2D259773ADD6BB202FD5891DCC79DD00D8EB229A27BB6918A22CE047B258F27EE5063A8313CD549BD6D0EE7A04E1583ED8719D5F28E84908296451B56BC9766D76A5E9FF9BC6482F1225CDB4377FFD5DF086F84A0B9A9A989470753E90FA6EB540152B2B2704FF8DBC4AFEB3993F5A908289716C83459F0B7FE760D1D683363204D1562CA54EB8CCB1513610B17578FF83CE1CFC8E5A44C70AA84C277D7826A6183A820CA02A469D62FDA6C1A45F7536C4B2CAF7D79F1ECEA24726E850F9977FC0EA398DD565EC8824469130EBE885A59D28A21CE3AFE8A48D9E4538FACF6859CAA54EA6EC890F02184FA2D459755DDFB067F3739910C7C210DD08646EF3447E00000006993B9060808341308280FC41D0165CEFCBE59C5EE589942CC56326586BE1F1DE63C2A47F3277D7E29969E98562B7DCEA76FE2F5D14A7AE61D4012635C8966BD6C0A7A66DAFE39813EC8B057465EF0B7371B27F7F6072D6DC47A677B6A858D107698482C373F45C53FD3A80
3632
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3632
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
EnableFileTracing
0
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
EnableConsoleTracing
0
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
FileTracingMask
4294901760
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
ConsoleTracingMask
4294901760
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
MaxFileSize
1048576
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
FileDirectory
%windir%\tracing
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
EnableFileTracing
0
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
EnableConsoleTracing
0
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
FileTracingMask
4294901760
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
ConsoleTracingMask
4294901760
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
MaxFileSize
1048576
3632
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
FileDirectory
%windir%\tracing
3632
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3632
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2676
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
2676
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\14C35F
2676
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery
2676
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
v??
763F3F00740A0000010000000000000000000000
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
WORDFiles
1300627480
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1300627600
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1300627601
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
740A00007061EE7E0D8DD40100000000
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
za?
7A613F00740A000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
db?
64623F00740A000006000000010000005800000002000000480000000400000063003A005C00750073006500720073005C00610064006D0069006E005C006400650073006B0074006F0070005C006400650061006C0064006500650070002E00720074006600000000000000
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
{48381696-4D46-4987-8807-7BE673717748}
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
25
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Item 1
[F00000000][T01D48D0D7FB69370][O00000000]*C:\Users\admin\Desktop\
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Max Display
25
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Item 1
[F00000000][T01D48D0D7FB69370][O00000000]*C:\Users\admin\Desktop\dealdeep.rtf
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\14C35F
14C35F
04000000740A00002300000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C006400650061006C0064006500650070002E007200740066000C0000006400650061006C0064006500650070002E0072007400660000000000010000000000000080F2F286EBA2D2015FC314005FC3140000000000DB040000000000000000000000000000000000000000000000000000FFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1300627497
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1300627498
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1300627497
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1300627498
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1300627514
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1300627515
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1300627499
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1300627500
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1300627499
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1300627500
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Licensing
019C826E445A4649A5B00BF08FCC4EEE
01000000270000007B39303134303030302D303033442D303030302D303030302D3030303030303046463143457D005A0000004F00660066006900630065002000310034002C0020004F0066006600690063006500500072006F00660065007300730069006F006E0061006C002D00520065007400610069006C002000650064006900740069006F006E000000
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1300627516
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1300627517
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1300627518
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1300627519
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1300627520
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1300627521
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Toolbars\Settings
Microsoft Word
0101000000000000000006000000
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
C00010033001000034010000040000001E0000001E0000001E0000001E0000001E0000001E000000220000001E0000001E0000001E000000060000000600000006000000060000000600000000000000060000000600000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000C00000002000000020000000200000002000000000000000000000000000000480000000600000006000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004000000DC000000E25024A1100A00633090060007000A002D001600000016000000C0030000F501000004060300000000000000000000000000040087010C000600C80009000180FFFF000006000000040000000C0100000502000000000000A004020000001200000000603090000064000000000000FF0000FF000000000000FF01000000010000005C08E0100000000000010000E40400001D000100000000000000020050000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D000000000000000000000000D4944600D49446010000002F91010000080A000600000003333296040000000A050C0C0302040600000300000101010606060000000000000000000000000000000000000063631900000001000000000000000000000000000000030000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002100190000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000B01300004B0000004B000000640000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000009002000002000001010101010101000101010101010001010100010001000101010101010101000100020003010301030103000301020003010301030103010000230101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101020101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010301010101010101010101010101FFFFCFFFFFFF00008602FFFF00008602FFFF00000C00FFFF00000100FFFF00000100FFFF0000010061000000610064006D0069006E000000000000000000000087FFFF0300003E00020200000600090034000000000090009000000000000F000000FFFFFF000000000000001400140000000000000002637800C80000000000140000000000900090008000FFFF00000800FFFF00000800FFFF0B00040001002000018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E00650077000180140001002000018014000B0043006F007500720069006500720020004E00650077000180140009004D005300200047006F0074006800690063000180150007004D0069006E0067004C0069005500018018000600530069006D00530075006E0001801500050044006F00740075006D00018014000100200001801C0000000000
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
BackgroundOpen
0
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1300627602
2676
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1300627603
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
84
2676
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
84

Files activity

Executable files
0
Suspicious files
276
Text files
208
Unknown types
15

Dropped files

PID
Process
Filename
Type
3632
powershell.exe
C:\Users\admin\AppData\Local\Temp\pidor.bmp
image
MD5: 9e1eba7438584321137c11d8f67800f7
SHA256: 5b88a49d827fcfed57d06e78cb880be2071f58e0388a07e11efada51cf74bb73
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Videos\Sample Videos\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.yglrn
binary
MD5: 31c71d2dc3c71e4909af49ca1ff1219f
SHA256: 6b6f8eb3fc3cb20c6a0cedb8881f5a070bb6fb3b33dac7fb79f93ae63a9c401f
3632
powershell.exe
C:\Users\Public\Recorded TV\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Recorded TV\Sample Media\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.yglrn
binary
MD5: 681ce27594acc336636e9f0874e4339e
SHA256: 8fa1f86739515508c3fdd94299f08be644760824bfd415a830cab6eae1a89025
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.yglrn
binary
MD5: 656177aabbeb1190485d627e5b0b70d4
SHA256: 597a5b1ffbef56e643fa5f0842443ebb2dde14e07213d415dab99ec82e1a7430
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.yglrn
binary
MD5: c188fc54ce83405cc4c225f17aa44ec9
SHA256: a827638803d411b861a0fa88fe4e4841f308f08cb61943b2c8cb23f1bf43a2a0
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.yglrn
binary
MD5: 5bda68f4134cf5288b925b6e5ae53ebd
SHA256: e8b3404fc03dccb6bad9ad1d65cfc31397024b0c51f0c9ffca0aa792c22642b7
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.yglrn
binary
MD5: 7812d5a59e4a3c2df2e132d6e5ed7580
SHA256: 5d30a77e851210f366594c7182dfdf45e42b35447fa05be2e03dd0cb8b41f76b
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.yglrn
binary
MD5: a07b89fc7e460060273741d9b6d4ef30
SHA256: 32724b9df9728d416644a2d08526559c9095a624cb42685b586b637ddef19526
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.yglrn
binary
MD5: 2bbe1dbae0e23dc54b71fc801f64c873
SHA256: 7217af5671c0e6de8c50cda15770a9a6dcc53e89add82bef3fd0bffcb15c6cb1
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.yglrn
binary
MD5: 01646b5ce4c6a3aeece15aa0a9f31a2f
SHA256: a80e6169c0c82557dfeb8864922d6d4a1d47bf11a5bd48eda493162ba5d66f4e
3632
powershell.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.yglrn
fli
MD5: 0f58ff4eabba9d60dd5b4347b8cd4a4f
SHA256: d6efc3e4f2801881664874384d5b59f8937ebcc1fb384536c7e39f5b6e7d84a6
3632
powershell.exe
C:\Users\Public\Videos\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Downloads\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Music\Sample Music\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Libraries\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Favorites\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\Public\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Music\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Pictures\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\Public\Documents\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Searches\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.yglrn
binary
MD5: f099fecb767063fe1714e4d99073e6a7
SHA256: f835f1e3463d54d0402658666d0fb19104f0fda9eee116b9c7b7fa8fcb6a96d2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.yglrn
binary
MD5: fe2d0aef66aca7e917006eabd56d73eb
SHA256: c5e6a1d87614f8603275b68bec6f88384dd95641cdc8063dc7dfdf7a35148104
3632
powershell.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Pictures\numbercareer.jpg.yglrn
binary
MD5: abf18a33c0923e6b7521fc6ace95f7fe
SHA256: 3c7e40b9f4c4a818acb8b9fe85fcca60f0e4e6a9995557379548149cef569857
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Pictures\typesviews.png.yglrn
binary
MD5: 7d23b37fededf73d6576f4f0d4dc44e2
SHA256: 62dd4c718e3926d195194c6f15a24823ba834a0bbc79e1aaa12932bafe8704e7
3632
powershell.exe
C:\Users\admin\Saved Games\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Pictures\leadingphotos.png.yglrn
binary
MD5: 64768b8ae62b1618998bc6b753510a8c
SHA256: 59d44367c4e66ffc8226393f51c93690ba43af40bb89a33b093b06db12e80856
3632
powershell.exe
C:\Users\admin\Pictures\allowsanything.jpg.yglrn
binary
MD5: 71842871526e058b1147d029387a9305
SHA256: ec8113320417aada8086aa88d03348da2d12a635192395a29bede77687566744
3632
powershell.exe
C:\Users\admin\Pictures\typesviews.png
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Pictures\numbercareer.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Pictures\leadingphotos.png
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Pictures\allowsanything.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Links\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\ntuser.ini.yglrn
binary
MD5: e7ed85b127e525541ba164a09c24ab56
SHA256: 58f4c53e8e0bcdfc85f101c0796930fdc6a2a13b368e03677c6eab8acf9383bf
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.yglrn
binary
MD5: d1941e6065055792226d29c09b68e777
SHA256: 6165603daab5e9d8098effef3f7a032d19142a13e60be853b97e96ea92ae80c4
3632
powershell.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.yglrn
binary
MD5: b67669d21bad14b9e57cfc5638f5b6fc
SHA256: 87ce4788648e5a6ecb8b59627c8c12936d2ee59c42fe356ffac2a2cfbb27fcc9
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.yglrn
binary
MD5: 34d326657c43a7c7f5e649d2ca722e50
SHA256: 84d9907ae4bbefd3070375cb3e4f3d2b738f1cf0465706ce64e87beeb74e9549
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.yglrn
binary
MD5: ffbcd53f667d1f20cd500955e9006f55
SHA256: 1f5fd2fc1b8bec9929d759a3ed0c95d840f89fcef176b2c6e0a828b35d21a3b6
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.yglrn
binary
MD5: b819223c631abffad9540afc4a122e91
SHA256: 93daa9cd360fe8b3f8ef2d55c5c92df1a2b64f0688124b78c696749ce988a4f3
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.yglrn
binary
MD5: 421d69e952d449a3ce19f15ae3b6b4b6
SHA256: 36175433b50652dae5957007e9beb8827c01349a8cf0bd5e88de4c49c03f46e3
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.yglrn
binary
MD5: b1f2ae109db21134f26e31479761669e
SHA256: 3bad109b9563ea8078b2caffac68f075ffc10bd17f95de50c2d9a987db633476
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.yglrn
binary
MD5: 9e4cab3b5b0821cdcc2d9e050e4e91c1
SHA256: 8d55e972ea19f2106b90a00c46e00b82e4bce695a6b6213a8d57c099e4707454
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.yglrn
binary
MD5: 66cd7b5e6d48d2cb4dddfe9a0f8417a1
SHA256: da5aa4d57a3081916a86ad3a464c4013295e3b4457b4fe9bc5a8041cb971a4ef
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.yglrn
binary
MD5: 2cdb7995014928232a51ce72646c8692
SHA256: 2337da4804a77e47d8d00fbc73fb0cb410fdfecfcc46a54236a4ddc7c4649f87
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.yglrn
binary
MD5: 0781c96977258c9d2fcd2e8ec614e8be
SHA256: 77bbf0bac7ff37ef2f5c7baed4995f414a463d179be29d47a8af61caa8b9762d
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.yglrn
binary
MD5: e5655b54a1cd5c0da0fa7498db7746f2
SHA256: 2e98aac0af07312804e1e244dd6d2d1067056821ba67d30b9f352abcfa298852
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.yglrn
binary
MD5: 102904957c5a9b875c1b67ca7147234d
SHA256: ac05d759695a0b0946cc9e0b097f6fcd5aad49bd09ee3979019e26d3ff7db757
3632
powershell.exe
C:\Users\admin\Favorites\MSN Websites\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.yglrn
binary
MD5: 97c8a68f59154407f6a769826663f9a8
SHA256: d6448f66c1a43c319a484059efeda225e662f8de8773cc5bb2130b4262248065
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.yglrn
binary
MD5: fc033137cbcda77d662767af2ef3ece4
SHA256: 6c2a20839e649e236d4f6b7202b9b1b624a135aa97cc49312f6d3027623377ff
3632
powershell.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.yglrn
binary
MD5: 820196dae0351d9b9742f2e5a412a363
SHA256: c44e64a2f80bf9b7aad9596dc02355674e2306b458cce959cce917322a60803c
3632
powershell.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Links for United States\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.yglrn
binary
MD5: 9d1217d4166b76e54dc5a22f8ba9f532
SHA256: 328684a616493f41893c0540afab392e96b16f52ff3d5d75759f7cba8b207c4f
3632
powershell.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.yglrn
binary
MD5: 08fd6b858859accef97be488d44f18ba
SHA256: 40141af3473fea7001cc447855f56f0ef6369648a94d20ef5bc29fbeb479424e
3632
powershell.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.yglrn
binary
MD5: bbb0d635a32a7a66cc3ca848f478d8d3
SHA256: 7b110215cee9560efecaf0028190dc12b33eb0022fa077a96a93bd1cc6216b5c
3632
powershell.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Downloads\peacelives.jpg.yglrn
binary
MD5: dfea4574d229dc86648eedfa111dfcd0
SHA256: 07b2380cb80655ec0a7234186a2b1fc4c3fbe8dace427c0ea591653185a64937
3632
powershell.exe
C:\Users\admin\Downloads\possiblehair.jpg.yglrn
binary
MD5: 2d68cfddbdbf5110492c524f06dbed8f
SHA256: 768dbaf5f97620372162326352d5f8969ceb9c58208678308d3fa3a5b0724408
3632
powershell.exe
C:\Users\admin\Favorites\Links\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Downloads\protectionangeles.jpg.yglrn
binary
MD5: a02111a11bc052bf5eb514d3428f20ee
SHA256: 6040c2e9cb68b0cb92062d9533a36a3c9fd1ab55072473adb0df8a15b3d27bfb
3632
powershell.exe
C:\Users\admin\Favorites\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Downloads\metaltown.jpg.yglrn
binary
MD5: 1c144e3117ab98c0b89ddb43e4cdc506
SHA256: ec641a45aa2f1ce9c7cc10fdbe71579f0f022aa0a38bc90e6ef1bb358b54d470
3632
powershell.exe
C:\Users\admin\Downloads\protectionangeles.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Downloads\possiblehair.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Downloads\metaltown.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Downloads\peacelives.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\unlessaround.rtf.yglrn
binary
MD5: 41011bf084b26a13629a9c7556b2ba58
SHA256: 1925f22e4dd90e7dfcea53056cce96800273391452cf13f654af5a5dce684e92
3632
powershell.exe
C:\Users\admin\Downloads\bornregion.png.yglrn
binary
MD5: 7f3290517b4d4e915d20949c6f6a1a45
SHA256: e109704fc0466fbb60e142b1f5d9ef08abc33199d51d2123c12f26d551cb8167
3632
powershell.exe
C:\Users\admin\Downloads\fargood.png.yglrn
binary
MD5: 83b58ffe835e909f67663a41db43d52f
SHA256: 81d81d8661d58ead47a24f16c85e75b4337e5095416bfc4768b3713f3c5a1be1
3632
powershell.exe
C:\Users\admin\Downloads\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Downloads\fargood.png
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Downloads\bornregion.png
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\unlessaround.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.yglrn
binary
MD5: ad05aab08875600dcaa575ceaca36383
SHA256: 5e0d7769e1dc96ff1685817fa210b749bb7ad99519c2a23ef2e337485cce370a
3632
powershell.exe
C:\Users\admin\Documents\situationsilver.rtf.yglrn
binary
MD5: 72dd911fe07955a72497f6fc5724d63b
SHA256: f06e6c48a676f8ad78ca131615d3fd8d4970217559318a7762c279368b9ee0f2
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.yglrn
binary
MD5: 5680518ee347e9b15fdf79af4d7ef53d
SHA256: 5b84767749e8f7d8163a847201d774898b4517a3a9486ae8b778a658f207498b
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.yglrn
binary
MD5: 71c07726b10c6a436c3adea4564d5bc0
SHA256: 60aa3b4d05c6f4b248cf34381850476f6f93b07684a9c077e256cfd60b90ae3f
3632
powershell.exe
C:\Users\admin\Documents\situationsilver.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.yglrn
binary
MD5: af8f26048e9e1a04185c6a0c2eef321e
SHA256: dbe696fe18ec2ed99bc1750bb2264d60d55cd6a06a523cc49da8e54d899f50b1
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: 01ef0ab9b60e15c2a001e06b54dc12e6
SHA256: c78b6132ce198719c0b4d3f7e21092eda5cc91ade7dcde45b5acf98173c13ac0
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\Outlook Files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.yglrn
bs
MD5: b180674c2817ddcfb1e111d3475401e4
SHA256: 543032abf71b23a24f7aaf0ef9911903cc5b72e3e8e9402ab4160772c9740f88
3632
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.yglrn
binary
MD5: edea3004f52b3815eaaf7aff49a17fec
SHA256: 6da098dede6fd65236afbcac19dac9ddf404d0d6ff5256d4180d2e474e8c8d32
3632
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.yglrn
binary
MD5: f85b9567c641576d84a0e06563331014
SHA256: 63e8160ce9f8894be76ce7c7552053ab85f2436d47824b0c191d48717d348f7b
3632
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\ohtests.rtf.yglrn
fli
MD5: 8f8c826fc49f04e57d3006a7df69be24
SHA256: b709d12d215e682e640691c87d1a3051e89a0e75543f429e7b4da96d5e3a7f3c
3632
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Pictures\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Videos\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Documents\ohtests.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\carsbackground.rtf.yglrn
binary
MD5: 7f1c68465c9af11c619279b26e4d158d
SHA256: 85a976ec9c840536c0a5335379e12241eb346dbbf0b1d2c285263489507360fd
3632
powershell.exe
C:\Users\admin\Music\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Documents\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Documents\literaturesource.rtf.yglrn
binary
MD5: 4cb2cdfef2004de132020918257b7dd0
SHA256: 8c416b64f63894c99159b04d9274eb786636eb410f24e697465ac24346e2d562
3632
powershell.exe
C:\Users\admin\Desktop\____________.js.yglrn
binary
MD5: 49425f9fc7dd6de643e03d8d3abc83c0
SHA256: 44b916e381c41bc32b38e9eba4685221cb86b7dcd0eba4b700cbe2350d1da893
3632
powershell.exe
C:\Users\admin\Documents\carsbackground.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Documents\literaturesource.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\____________.js
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\whoselicense.jpg.yglrn
binary
MD5: 55bcfe97cb699ae2856c520017e1dfa9
SHA256: 7b9b12897b8647dac080098e3328f20b1df0f2baba43e49a0fec6add30f52064
3632
powershell.exe
C:\Users\admin\Desktop\stepused.rtf.yglrn
binary
MD5: aebf7bfd79ca3bd3d1b157a1895b9be6
SHA256: db093c3cf1c7b552f16a36f07645092f45b513bd39010a418e20e33517cd91e6
3632
powershell.exe
C:\Users\admin\Desktop\whoselicense.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\stepused.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\roomfees.rtf.yglrn
binary
MD5: ae57e0ccabe7f09f4ca18fc3470dc0e8
SHA256: 2aedb2315ef68a29e24b51b8238645fece8d0c9dc0851eeb1e732225c2a3cb24
3632
powershell.exe
C:\Users\admin\Desktop\roomfees.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\moviesled.jpg.yglrn
binary
MD5: d370ded09a283fb8e914e7cf565c6ff2
SHA256: 3d6a79ad311d16a0fe3ed1049a75e92df5c22c714fb935555c20db53defb5ac9
3632
powershell.exe
C:\Users\admin\Desktop\femalestudy.jpg.yglrn
binary
MD5: 764d5bc670649a1f81abdf4c24555eb8
SHA256: 0b7d5b68c952dd6ff756241565813e90e8f2b17ec69267512bdf0709edeb7883
3632
powershell.exe
C:\Users\admin\Desktop\moviesled.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\dealdeep.rtf.yglrn
binary
MD5: fae24d76c2a0472cad1612f5ef3c1a46
SHA256: 0014cc2bce7a20880723abdaa7f44fd32440bd4c9f5b3f15d1ca0358edbe625d
3632
powershell.exe
C:\Users\admin\Desktop\dealdeep.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\femalestudy.jpg
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\boardcommercial.rtf.yglrn
binary
MD5: 2a9970d32f176db7562bec1d0fe7e6b0
SHA256: c36d4c084d864a1c8816cc5a19c074fc53d5a21977dbe05e7780c94cfeda1962
3632
powershell.exe
C:\Users\admin\Desktop\blogsratings.png.yglrn
binary
MD5: e639f31ab91b01070e6b4b0bd93843f7
SHA256: db67cd11c0f3854c64d2fad34bb278e5a82d2e21d7c57a32df979f52cd7fcd65
3632
powershell.exe
C:\Users\admin\Desktop\boardcommercial.rtf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Desktop\blogsratings.png
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Contacts\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Contacts\admin.contact.yglrn
binary
MD5: 16f01eda56a65a74ae1c8ce5406477b1
SHA256: 9dc2f796787987ff1b45ef0f8cda054b62b46b7799d2fa208c1705bb757a2b44
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\Desktop\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.yglrn
binary
MD5: e02ed063db7a4e75fbf99352970e5902
SHA256: 109c55f8bf97e5bb7992f667b37cdd4814c1f4f159e654201becd145f1406e72
3632
powershell.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\WinRAR\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.yglrn
binary
MD5: 93d26b56c6e8700770f986d077e7a1b0
SHA256: 1ebf42df2e286ade5d94cccff333f439b04b04e3a16912306bdd69cc17f824c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Sun\Java\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.yglrn
binary
MD5: f5b1de3775a28d6733106e035c2f2df2
SHA256: e0d02eaa9be020845c9310c980af9277c5b8bcab55984bbb5c709e437ca32102
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Sun\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.yglrn
binary
MD5: c8572427a0d773084ca7cf20de33e758
SHA256: 6b1034f3b85f7d344efdc34091b9c4b01b984e8a64ad509c36da04b9ae6c3fd3
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.yglrn
binary
MD5: 3540076e34b50178ee00dd993eab6de3
SHA256: b455a836a4fbcb7e07e0a0552a7b5601b5da7f2c955e35e15813b82ce317c425
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.yglrn
binary
MD5: 5cf30cae9456dac3390d5f6d87a6630c
SHA256: 53d1c17c885c3ef924c13ac08bbcebed34adee641ddfa6d7d8d401d6f16aeaac
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.yglrn
binary
MD5: 934afac3676e64256ecd789b02cbae2d
SHA256: 58771d33b2e353b5ca6878d36ba792ef60451211278799a51c3bfc1c474490ab
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.yglrn
binary
MD5: 5d940c7a6abcef13a2253c53be044b08
SHA256: 285787bb8bc271771ef262fd995c431bea06482db7578685f0fd2fe7c72c44c0
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.yglrn
gpg
MD5: 5871ef6d0774ac98860179e479f75939
SHA256: 618c1c934a7f59b3d2e3881dff41309f72d319e9e11053c14fc7c8c3e0592386
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\logs\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\qaqjnce.log.yglrn
binary
MD5: 5430faae49c68f995c4638737de0fb44
SHA256: 6ec5a3114248b7751b005e5eddfc14e5ce8f0366967591ed1bad49b9bfb0a743
3632
powershell.exe
C:\Users\admin\AppData\Roaming\qaqjnce.log
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.yglrn
binary
MD5: ae611d306b6394018692d1f36f20c241
SHA256: f4e083e2a93c88f1bba17625de92a3955780a80f49777247dd39606691408ce0
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.yglrn
binary
MD5: 240778ca0eedb59ad9071774a9abcd01
SHA256: 61b4735b49ba02ed3dd19876aa1c6266ae1ad4651a5d65f7dec33a13ce502be7
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.yglrn
binary
MD5: c02038550524f01455061d83e83786d7
SHA256: b17a1c2e47fd460486800877e77558a6c16a59eddef822b52eb4eac6c8744f59
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.yglrn
binary
MD5: e5baa7ddc64e1f0eb25b4275a97240c3
SHA256: 1bb003c185c12d8d4e75d01369bb936fe0e64367303892b4a800873a572285a1
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.yglrn
binary
MD5: 5836c75e5b0fe5701b42a48c15453f2c
SHA256: bf45d7b5d37d6691ea541aa6dbc8254abcb041c8b0c6be628a869421386714f9
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.yglrn
binary
MD5: 1daefb464619cb73b0505e92c7efa684
SHA256: 8ad6f7de8b280ea6c2b511891a542c019b28facd4df40ef589954ae34e88a62d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.yglrn
binary
MD5: 34d9dec94715f29721deee9c254cb824
SHA256: 7b957cab6bad44bfcafa83c3e6848bd262e661d86d3f53dc0c86e49a36badfa6
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.yglrn
binary
MD5: a855a27f48ff759cc95487b2437de5be
SHA256: 5329760563dba3efbe54600f351b0abc7b948c46ce8e5ada83ec26458cafa081
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.yglrn
binary
MD5: 875254b8adbc723d2ce5df740e77e44f
SHA256: d1783ffaea160b56ceec7e07c6207e1c251041189061ac751299b40d178421f8
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.yglrn
binary
MD5: c001d3a66fae13fe0e1d00ba0adf014b
SHA256: b693f0bbd55afabd5a35bdadfd7c3a2c10de64eac26eb773be31f3527d8b69f4
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.yglrn
binary
MD5: 6fd4f4529e5a3290cb617632bea300da
SHA256: b9def16f6dcbde768df2aee67447899b93531b1761869129c0b286902aa5537c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.yglrn
binary
MD5: 67801b6ae36d52004e91dd4b5e1513b3
SHA256: f84744fa62ecdc07f119547c871f9889e8d8f1a15c5360f064603a6a595b7262
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.yglrn
binary
MD5: 7a54a1c0035268e7214380170619b829
SHA256: 22a1d593dcf679a860ca8c98911d76af2b4f49b939eeea863fe8f0a89399f07e
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.yglrn
binary
MD5: 24aa15a065e5b7ff0f3ffbf6f36e18bf
SHA256: 18ee67525dbb87785a0bc6b16e6219d119e3288df64b078b14c762885d468d6e
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.yglrn
bs
MD5: 886b921023f6e20c763e942251532b93
SHA256: 85ec3e60b24dcbeb7b9ff2594436650180c76274b6efe02ac1d54a8438e1dbb4
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.yglrn
binary
MD5: 1c8954cbd6e5fd78dafe875ff8b6ab33
SHA256: 3cb047ef1453d93f62f8284dced8e932d3aead68e1cf4004ca109661c5417a63
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.yglrn
binary
MD5: 7774fb29e726571fec299de3c4a9861f
SHA256: f42652c21ab2ceb9ff1d4c8d8a71c4d9b98b2a190c6c19c19bdc45928fb1b6e6
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.yglrn
fli
MD5: 0f598f369ad748c97c0463ae3e20517b
SHA256: 13d741c61f6c98d1fa14b0841a85d15217eb87626f806bf6f6ba64cad63645f0
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.yglrn
binary
MD5: e8f37b289e1ae6aba919c34a43b8eedd
SHA256: 460137986fc53334704d2fc7b111f6af232b9516a0d1b529e5002278d2205987
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.yglrn
binary
MD5: 19792d7327594c606a216d228d4444d8
SHA256: 95d82785b94556f82b2e86344cf1f1e85ea23e5c8a0f0d772d90e8df43617ca3
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.yglrn
binary
MD5: 09f6be8f739f866d3310e8f99f996ecd
SHA256: 82086ac3b0846c33f64d1312f52e3a7bdbdc248e97beca505fb0dfa44f3398f3
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.yglrn
binary
MD5: 42595a3a984eb93533ab931873f6cc2d
SHA256: 13e87285622e8ed5afc71f1c20386ced8c28b245a58a1d5f3c7833b28656612c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.yglrn
binary
MD5: 417736d671829aff0eed6a6870bc9fdf
SHA256: 587fcc24f8913778f78690ae3f31fa620ea6adecf71f994c06abd6de17fe1066
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.yglrn
binary
MD5: 75971f0b1fae6dabffcba1f231070970
SHA256: 048ab6a89ef7c8037f280e371512206e2102feacbf26b0d1d77444b4c1c7018b
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.yglrn
binary
MD5: 0e817074f1006f4fa3f05c4527facc15
SHA256: 2644de337dad448df4433cdce3175ba3b2338a8bfeeaef6825b720080e7a8fe0
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.yglrn
binary
MD5: 575e21ed6f4f5e54d5da5b661d237c10
SHA256: 7a9e75e334ed4c2dbb4c0f5e89e4673fb2a214278550b30d9687769ba27cf5dd
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.yglrn
binary
MD5: 0db1f2994be789a1db184086056682aa
SHA256: 5d60e73a57a0528ede6ace02871c80f2d85d079fc6f21837c7850deb9e28ec62
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.yglrn
binary
MD5: 0f38debe6be5e8c7e26df8e7f2f4dad9
SHA256: 12670330dcdae7291dc4c57d0083b3edc841184da1df561a883c85660492c97c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.yglrn
binary
MD5: 867904629ea1dd5c11437af25afca1a3
SHA256: 6806f18070c563c5b995803c5d35f50f47ddfc2b4960d563b6d7b698ad9ff0b1
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.yglrn
binary
MD5: 46c0df0e38608a051ff19cc6a3c0b078
SHA256: 742f1f37db0e40981f491ad0c998738b5a23907672082b6d51239872ef0b815b
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.yglrn
binary
MD5: caafca13703cec619d2a031ee7fc1974
SHA256: 2433c3f781dc6409e514519f04bd51a1a05391fba4e0c75819bf1f26c8d06151
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.yglrn
binary
MD5: 4334f31f058a2f2b70ff6611aa7863aa
SHA256: 25e4d8a5c8f73bbc81affba1071304519ca31006ebe1e4f52e7694a5728a34c7
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.yglrn
binary
MD5: 524f2748fb679cd82b1dd6626c1a9133
SHA256: 475e236ba07148cfc45ac3a20e357fbc1a5c0034eb04730594977da2f77427ac
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.yglrn
binary
MD5: 8a0f6cb17e11e6ffb9fded6aba14fa26
SHA256: 5cdee9260e969a1f14bbe57dbbb8c4f77814591ffae110bf57f7287890baa2ed
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.yglrn
binary
MD5: b4667ac8f7b0df75b26652dbc1521f91
SHA256: 7a294f2f6f802228bb11f15062ce3b9ea1feab0776b05e99cd0ed2f5c28d2407
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.yglrn
binary
MD5: bd35f4603da1569d8bbf436b97234388
SHA256: 28e41dc0c8c772bf784be346d9db73c7644e1a0aa4fdba8da1be52fed1c17246
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.yglrn
binary
MD5: ad2bc4c223a579599594fec376df283b
SHA256: cc83a1cf752b61a5bbfece9dd4ab2b22299e16c5ce48ccc01bab2b4d585d84ed
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.yglrn
binary
MD5: e1081d16164075c3aca7bc934e4ce9f0
SHA256: 7bec0f19151498a50565bd4a1422eebd6fd57a8778bda2d237e1318a3637733d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.yglrn
binary
MD5: 12cab670b3c76ef1087cc8667fce5155
SHA256: 14fdd3428b78d4181d2dc1e6bc8c8c2281f2b9e1c4c7f02ac53cdcd2558d889f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.yglrn
binary
MD5: 6744c7ff65f4f65bb82150d9c60ec1f3
SHA256: ec167b5009ecdefb41947e18d03a8b21462a5813ff4bbfdc45a541cbc1052f21
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.yglrn
binary
MD5: 1e2a3c227e489c97c63dc6b8d441d068
SHA256: 310d62a9f048ae69b3cf8a9aa96170f69f56d2ece7a817092def6c8f4ad92045
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.yglrn
binary
MD5: 3439b4213fae4e35a91f50a4b17e8f33
SHA256: f69660260743526b48e236bd39c35b4e4bcb62b8c704c02b0b70162f7d7b64ff
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.yglrn
binary
MD5: 384441311097008e246913430b187e9d
SHA256: 4d7230ec48069f2791bfd8d1d1f2ba82fde23250bb10529cde611d5cf17e3432
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.yglrn
binary
MD5: c495a7302bb82931192812acd3bf0224
SHA256: b8512d7a116aa390dd02310b6f4f79999360d52f933774e49d9b78519d3d8225
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.yglrn
binary
MD5: 7f1b66e8e240d605ffd6598c07dbb58f
SHA256: 99eb4c6e968110b5a50bebda6857bcbdeec2081afb68769544888f3f3b625285
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.yglrn
binary
MD5: 3bd58a516b3aee1cf46520b336e7ff89
SHA256: cf2cf5a7967f0bc6e0d0358f78bcf9dde90cf4c7718d461176082993977077ae
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.yglrn
binary
MD5: 76529c0487c5bfa7529549a87dad1bb3
SHA256: 6812c689d9cde97d7de753c1e69f1b41f254c7ec44079cbbcbdcba75c1432c85
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.yglrn
binary
MD5: f03895345645091e50c2842fe6e3bd70
SHA256: 795fd6605a02e138984ebad58a9f1a621684b17b6c0e40435754bb4c9a14a3d0
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.yglrn
binary
MD5: 9528980d20ad552d13f208444f9fb4c9
SHA256: cd7053c2e1b17268c97f440f1a2de9b96a504b4c4dcb95406acacac1ccb7afa1
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.yglrn
binary
MD5: ea20b70735f125b5350133638edbd220
SHA256: da74b2af0c42ca0460a9423e4d4e0e494d0b8a1ce4e40951c13217815aba2ead
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.yglrn
binary
MD5: 596e550f2fd39c350f4479a0ca9d5b0d
SHA256: 3e891ba5e18cf3bd4de59e7ed83fadc3df9b77511237e6a620a5b9f4b39163e4
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.yglrn
binary
MD5: c5dadba2fc6368de9e3afacf3dcf47f8
SHA256: 268fe68b0da69d3e802d0ca365cf39eca4dceea12f59de3c9c17bf95439aeed5
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.yglrn
binary
MD5: 20cca115d5b648af462168bb065144de
SHA256: 86c5f9da368978ddc2e54baf768105f8d287221bd6bb901034442ebb40d147a8
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.yglrn
ini
MD5: fb593a475a5d6622314b58c854620652
SHA256: 6d53502609d253a6ded5ed564bb9c8a41fbe718a923abaf9f833d49fb74fef51
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.yglrn
binary
MD5: d73d1eeb1069251b7a4dc28e9c43ad77
SHA256: 63c587c64e85df91bd457db99281bff825337b3c09918f5763f9006244f1000c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.yglrn
binary
MD5: 5e56249a2f5a6109f59732ee7b7a3a6d
SHA256: 69cfe2d2be307437727ddd1091da5ae50d456275bf8cd75439e7c8fa79048bbb
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.yglrn
binary
MD5: f2a3168f8307dc023d49e1da5b85ea50
SHA256: 543cca2ce3fce9672895e526550ec87e9c87f314d031a3bad75a3f68b902ea84
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.yglrn
binary
MD5: c1b01c11f30951c9cbaac723dc7dcf93
SHA256: 4464ec19ae86b568c9287ce350fc004996fa0c91ef2c20406f7026adca0a2720
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.yglrn
binary
MD5: c87d5eac6d2b791e0af42ffe470c77e9
SHA256: fa4aba90ff0b045f4f8a25e7884311da0b27a8ad0fd07953128e1aecd7c93bca
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.yglrn
binary
MD5: 629ba5bf90d0d023f8c696d62c1e54d9
SHA256: 4675acbefe56abccb17313b63a4166d0b3e4854603db6538d2720a813fd36a64
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.yglrn
binary
MD5: bef25ea3526341d72ae38de22cbbd364
SHA256: 24312ac8f993f626784bdb273fb642d418cffb4dfe95eb1f095ecf12e5a8f2c5
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.yglrn
binary
MD5: 7d5f691eb0fd1aac7e0edf7b883bd181
SHA256: b817d55d107e35e26b20e41b5b7315d0677e30bdf4330cf177a579b93f9e3066
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.yglrn
binary
MD5: 96b1ba03e23bd61549fb828dc2de272a
SHA256: e9e98882273f3bf9b2ed9915725300edbf0b2b5b7cb71f879f7f4b9ec5232197
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.yglrn
binary
MD5: ed9fd35ccaf0351255ac97520aa592d0
SHA256: 637bd588461e460d7c59f82b312b052d5bf7569319f42244dcab88d95afec740
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.yglrn
flc
MD5: 07a2ae0a69676b3e829ed2007f99f374
SHA256: aaaa9c8aa8225b63d9acbb0ffaaddd81202327ace941e03e0b7f7e828e611611
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.yglrn
binary
MD5: 0f8e1371f2c42450d3baac0a1468de0e
SHA256: fba5ea30ec553eb016097052621132598213b3a90526a18fc0ffcf4110dbad4d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.yglrn
binary
MD5: 874d1afefb8f04619de5ee3b83b44063
SHA256: 4a2a86b476e31d90f1cbb70626337436819bdce392dd3f7aeb1eecab96123dc1
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.yglrn
binary
MD5: b12fece14fe1823472a8252a050ea899
SHA256: 80b6c4911dad83ec38ac471dbfe548294f8dfad339f6e7997b66680b9bf96766
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.yglrn
binary
MD5: 405e3a66d710002834a479df0e8086b6
SHA256: 76bae5300d939fb442401c4cd4363e1617c911ed0d05be6e26544c038eff8b35
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.yglrn
binary
MD5: fba3ba485ef44f9866281ba0095fb0b1
SHA256: f837905aaa1d2f797f2b7f312e4b84c523096a01b486a8fc4c6ea992ff7bf66f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.yglrn
binary
MD5: df66df5703195e05d7021868570494c8
SHA256: 62b4cb62feefcdb7a4f781ad353a6ef6f224084472e00c2436898a12858c8df8
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.yglrn
binary
MD5: e544c705ce5bed841b6073c75fceaec4
SHA256: f53eed898f6e46ac62e5a4033b7b50deec30935bba2f2f97ee1b43103b0f4569
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.yglrn
binary
MD5: 6934eed1aa87e6d3ae40a643f63aee9b
SHA256: 162bfee4176bcf823339ed15f01beb6977eeb4ba372af4d819c1bfcebdca8d42
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.yglrn
binary
MD5: 7d5ff78d8a57fba0e774ec282939efba
SHA256: bf2f7ede7a8e6255c9291493b0580a4432593e07eaf38521a7a62014deb1dcfd
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.yglrn
binary
MD5: a73a0b6954c0ef1d34ee0e1485edf8ee
SHA256: 96b986c3d3542b5b5ccacb6bd837de674e941791e55be6d413850894fad5272f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.yglrn
binary
MD5: db4cf9bd4b98523c299074598b6de9be
SHA256: 592364bed09e0190e392687aad89aa22182886af90dda5f41b3c55a0a258abd6
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.yglrn
binary
MD5: 74f41a155348eaa57cc0bb843c705d03
SHA256: 59a3a140dd7407b26f9f6a83db496099dfb2ef4cd610dffb3744e74249f5d27d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.yglrn
binary
MD5: e8e63c95eedf00c4cb24c851240f6833
SHA256: 974e2bf1b85517802edc58737b34fc9f2a6ebd7051543d691854a3a02f99dbe3
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.yglrn
binary
MD5: d912ea52e1c7a5adf8b0230f68792173
SHA256: e5e9cabd944b03ab67937f07232085cae1cefe72ad8f38af827e855923efa072
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.yglrn
binary
MD5: 1ba7f01c5661a1c562b6621c2935b770
SHA256: dbde173421e9bf582e4b084bc5e24bca63c03c34ab9ec62eb7dc2827c03fa482
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.yglrn
binary
MD5: 6a6d40b2731221d2d2ebfcd0ee8a1747
SHA256: f2b910cd50a0617a920508baedfd381b801743055db0519caaf72f4b8c4200dd
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.yglrn
binary
MD5: c913a96f214bafae46f701d9dae5ce29
SHA256: 9ba63e9b3ba6f9516b05f79e9f1d89051802feffa90e70ccacdd5a07d3e5adf6
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.yglrn
binary
MD5: 217400d10cb6ee6ee7730b5803c42332
SHA256: da2abb1caf9faa3f7ee4cdc4cf9b58a25b0d0bafa41bc5998e6611bce3353a69
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.yglrn
binary
MD5: 2cf847c2aca71b36ce13976c4a766247
SHA256: c8fb47f846ad9e5613cce212b10c42ad14553e06eede09d2d518946370f9d94d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.yglrn
binary
MD5: 877867f5e91777b931989a554e8363dc
SHA256: f4f340ee89ffa46f17f4c6dd66fef66b96b14939afb2664f680110cac4e1f7f0
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.yglrn
binary
MD5: 6cd13dba9a1c630fccb490a0ad9b8425
SHA256: 1abd67b9f1d7896053a9792b2a6d499ead1cca9382c0ec1ca210f2e074753359
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.yglrn
binary
MD5: 60ed1055bff07d660691d2d42229a8a6
SHA256: e39b45f4c6156737dc4822df612f5cc40f4bee3db63935c1aee349377c990300
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.yglrn
binary
MD5: 9cc89d413a5f640c54c9bc84335237bf
SHA256: fab0e4e1015850cfd2ffbe966fcff5c82b887d11cfc8ad823584a6c6567545f7
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.yglrn
binary
MD5: 945aeec9974606f19cad940c1177bc98
SHA256: bd9eb7a217848ccb32fe58496b0a4fe30b350e180f5b4533b7b5d3ba2e802b89
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.yglrn
binary
MD5: 1ab730ca78269a9b2573f2a73fd8332d
SHA256: 41ffbdc01f5c80ced866dd125f0a19fe617a287be35f6adfff8ea5a796525ed0
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.yglrn
binary
MD5: f6aa20f81263b65772b5b21473223d60
SHA256: 9d168f08f22edf2f68327e7460ed85c1df61870e461c595050010217141926b8
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.yglrn
binary
MD5: 6b9270286a4ce5119f6a4aa794cf728c
SHA256: 08ed4bbf04a26c9b99edc6244ad79910bb8512000ce7d34148decccd7fa860de
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.yglrn
binary
MD5: 89a920a7f15df01edce340a318864479
SHA256: d8fac7d196d9bebcdf3f5f819ab20328d827ac10a878322f36148dde45306e83
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.yglrn
binary
MD5: 2cd936bd6401fe1a7228114dcc708495
SHA256: ccea045344a0d7cebcf85544608b0c8e8447e2aec8a32afc6246f81e9ddbe7f5
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.yglrn
binary
MD5: a0bbd0b5bca2fd885f53eaf883807d7c
SHA256: dd3df8052914f4cd15cf8a2feaa7ae59f8d45396a958ff16ec692bf3dd4bed29
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.yglrn
binary
MD5: 9df862eca187ae29b04b5142fb5a68d4
SHA256: 2502ebb326ea10f578b17e84827ce79d1cb46d195943e74b5343ef9f496848d9
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.yglrn
binary
MD5: e85cee848582d169589d0e2543076e20
SHA256: 137facf9d62b0caba8fd101f28823ea1c633c953b8088ab60c3a2996c3eb4367
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.yglrn
binary
MD5: b9bd5932be1a8ade575b5d226b765a9d
SHA256: 0594b8ea5890d339f3890712e0ef78489882f4e8456266cb3ef63db05719224f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.yglrn
binary
MD5: c335abdbcd90c0d76f2d2c0299e037f8
SHA256: eef4cf682aed7c3409c4c356ccddc5e1add433ac9ea4cd6a98329c6d5f1498ae
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.yglrn
binary
MD5: 48b53d199f9f37950f534e9554005b14
SHA256: c32d02f787bfbbd2241c343574eb06c73797e3707ed5664a65a0e85e40cd9788
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.yglrn
binary
MD5: 6c15b6a935dacc2253ca6329ecfec164
SHA256: e06d617c1a5520bd3bba80d931a81ce827e5e8ee58a1300738ce102dc8054e00
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.yglrn
binary
MD5: 9ba8805696740c6040bb0551bd9f9290
SHA256: 09ed06b98c000a6d29625791080ac70c27750b8817e7d41059441fbacb7c86cd
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.yglrn
binary
MD5: 8c558672fbb892a24d752042452898f5
SHA256: ee134af875a015519afaee4879484f74eea07db1b1429de568d55f57f91e00ac
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.yglrn
binary
MD5: 8dd2d790759bdaccf051a76c1b1cc161
SHA256: 011992f5711acf2835fb4e55c607c8a8dc5a6e78eb07b49537468d81fa151c42
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.yglrn
binary
MD5: 2e90f1979f63e354066c7640dd2f230f
SHA256: a6d6bd43933ae323b417cc028e570482a5daaa952bf9ff0a0ef4be9846cf71e3
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.yglrn
binary
MD5: 9fe240cbf5c2e7f10c447e7ac3568033
SHA256: ec1e8d3c5ec32ba000c81803b74d12c44c11b020c35dcaf0834d43ac265186fd
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.yglrn
binary
MD5: 362f45b98693ad2b56ae7720935fe1a1
SHA256: be3cbb11fa822c6b3fbcd7f29536216dfabdb345fdd727c34d888a6c9cd713a8
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.yglrn
binary
MD5: 262b91c5cfba2d93dae40d9680aea615
SHA256: 6133a3395db7b40c0b771094ce941fbf0f613d8e236c0f009dc17653036338a1
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.yglrn
binary
MD5: ef72e6ab23c0a074654d446d8448fb4f
SHA256: 91d4bec8d2aaabf84bdf7c7fe3c6d09d1b4e01e21bf03d6118998cc55bb447c4
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.yglrn
binary
MD5: 3c5951cdbe1094b5980b089e6f237d8c
SHA256: 8f6ec91f404c65d7d98a7fcb08870e642e6bc87484b887c0229a535e6fc64027
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.yglrn
binary
MD5: 78734a4f3e68eb0ba761433de1624019
SHA256: 257ca5b811ad83d508ad4ac93b374e2142d3bc4ab385a2f000d03f8e19f3bfeb
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.yglrn
binary
MD5: 1e7258f37fb0d3c0bc4cd8714df2b1f2
SHA256: e06852796aa25026185e209cf67c59ec16a12356e689f9875b0d26abdcafb31b
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.yglrn
binary
MD5: b1157f8878b67cf776528c1356cd4ddd
SHA256: 1ad60e2ab16e68d24c49b7ed3c8426d25419c747645abcc3ec0357a8c539ba24
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.yglrn
binary
MD5: 153de2966c9c9985b378fad35b0ade1a
SHA256: ace7283c5dec317b220a22c22a23337880a0a4e66de9a49c745aede87e2f793a
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.yglrn
binary
MD5: 0fc60af7d32b7ae172ee73411be361ce
SHA256: 96cd8a0396c323336f475ed27af46c3f2023bf4ce3977cfb952de7fc89efb720
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.yglrn
binary
MD5: 988417d825ea38bfce962d852b03a41a
SHA256: 30f3ced50375889b9f6386f82d8078d8f89c6541dec418404a23749b8878d6af
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.yglrn
binary
MD5: b558165dee8ac9d0720a5722626ab483
SHA256: 82430fec3513ee7111a76167fd60bac804d347b7657dda4934866f5ffe2c11e8
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.yglrn
binary
MD5: 1b12cd9c5b16972d2db311a7f1808d87
SHA256: 053eb01090033c5237e065cb4905c98f7d178f3b2305f2ccdf0216d932513d0b
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.yglrn
binary
MD5: 47e6987ddcfbb38d325d5de9c205511f
SHA256: 7d53134edabba37325b6f118651b3a97e4f4e1a560a5b7fb17da97615b307028
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.yglrn
binary
MD5: 639dcb6d343306db78d88d56bf668eaa
SHA256: 929b2bb5a2e9b806bc2afbb6ba182895423a132ee1b972af80155d155914dc63
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.yglrn
binary
MD5: 2c8954bb59b0b894e7f21dfcf12d74f1
SHA256: 162374823999446aa9033adf73f4bbe821fc56a530633bee094455799344b514
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.yglrn
binary
MD5: 4a73a2085b0dc0ad2a4afa00b9af34c1
SHA256: c1f52fd7a83cdeb44d7cc0b55714cb0750056b4105f72cc5aca154fbb52416cb
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.yglrn
binary
MD5: a25660250c70ae0e8d395378f36d47b4
SHA256: db2b53ba043bb4037d40e9e69b6eedf5476103e5a2b6578c8074b6a6468c6c2e
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.yglrn
binary
MD5: 413be35ae4e40836c8a13eb11f740ade
SHA256: 821dc86d855d615f53820e017d2f60dfe5b136572450930ac96e2380c0dea4b5
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.yglrn
binary
MD5: 3eb4c334c2c859476f7cc66d461181bb
SHA256: ba79dba9e3db364d90190a1b5d5ae23a280cea719b8245aec87bcda790e801f6
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.yglrn
binary
MD5: 60e9813ee8e6692658e775c5e5b8f85b
SHA256: 7deeb50b9b8fba98ab4a31acd0b2325182987a8abe20821997524cacf951b2f6
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.yglrn
binary
MD5: d248bf5dddce5eb490835ad93d570439
SHA256: 3ed2dd071bf050eb715bdf614003f2e0c342166aab83b99fa77fec870cc68761
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.yglrn
binary
MD5: a62aaf3d271e0ccdf5adf64baedd7129
SHA256: 51e1eb103908351013634b5a79a5a8f1e8a71d209c9b9da93bf2caa19a47932c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.yglrn
binary
MD5: 4ed33c1bc3da882a77070c6833eb2be3
SHA256: 4a06938c8d0be2c2f53a8d67f37736c9632091a1b228342ea72aa852cbcdfc73
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.yglrn
binary
MD5: f4501b27bc9f095dc6f67b805bdc0c1e
SHA256: 497874de5c3c6a87192be65878b468a8c0276feaae60549061804b172f37857a
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.yglrn
binary
MD5: 126aafc33ac04c8357a3a4a9b4e51b09
SHA256: 9cdf79ebf38571717fa16a667556c5c1dfc6726ab5a9ed1bcfe4180b362e205c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.yglrn
binary
MD5: 9379c3f6591ee7b6ecd91e42e137ec8d
SHA256: 9636fc772f36a6612bf0a1ba9ce85ff9822cf13a1d45c3c18800419572d7d86f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.yglrn
binary
MD5: 1bc344d6e5ba3b6440088e266b09caef
SHA256: ea52fb5495c9793794469e79396518ac24a3b71dfb3801ccccba32459bd64c46
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.yglrn
binary
MD5: f734e41479168c561e71abf95d268223
SHA256: 4179cd3aebbcec96d63c84410ba121323445b91dfb2ba74544706386c78f2a87
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.yglrn
binary
MD5: e5c23e46417d98e0fa790799cf6cf516
SHA256: a0e689f190e6939b5a52b3ae3e4895fab4f749ff8e6774b4f6f3d32c44a725d9
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.yglrn
binary
MD5: 81269ab46e6a72d1bd701189f55893bc
SHA256: a2da84eb0776cd4f9e11568518e9fa9a224372f148c16102d0de290bf2966cf5
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.yglrn
binary
MD5: 6172ebafb516158bf617d41b4d047962
SHA256: 097474089d7a566b3b93a0c8d52e5c2c4e330d1e0f9f33a646994869ce4cadaa
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.yglrn
binary
MD5: 03387e35f0dbf343b65f35ab16a8b026
SHA256: 6c3bc12cb61103b273755bb2635cb9808298fd26c2dbfcc1ff46d69a746db440
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.yglrn
binary
MD5: 459a72163c85344a727ce4c31f4d81c7
SHA256: 93cab9b5dfbfc6570ed9ee9141dc14985138d2f420c376d1655fc61f8d125980
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.yglrn
binary
MD5: d90d730da624644f04c314f5cde3e1ea
SHA256: c6537631dabec3b73797605fea2493b3d11289ed75d28c2fad9b73d82939302f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.yglrn
binary
MD5: 23427f6008dd0212cb102f64fcb06e0e
SHA256: f8bfc9b64d1b4f677473fb20c8454155d5096d6db1112b1c6e3c1a4083d07b73
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.yglrn
binary
MD5: 29ff6a4dd79c4a5e5661bad13ead762a
SHA256: bb4572a834297919efab4302e1ea8029802b7edddada11590d07223de6f5866c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.yglrn
binary
MD5: 4f2f10a91b81eb9719052c05f41c8d34
SHA256: ce3ffe176b6d3d82e68465061d068ab2ee1cdf17c543f328ac8a0807a0683d19
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.yglrn
binary
MD5: 92e81e3307238eec5da05f321b96fa20
SHA256: e206d1003512113115035fb092aa8212d74ea07bbf7290ec5b3adf6b1bdef31c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.yglrn
binary
MD5: 921cd69fb59873a161a84091b33f32ec
SHA256: 7784a2453af8561b35c82c7ada2caba0cdecd89ed1325d239ff78950936ceb88
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.yglrn
binary
MD5: fa5be762fbcdaffb44717982d07b5880
SHA256: 00e9a1741fdb8b5cc77eb0975a1dfc81d144b5fec30a39ea59865c948a31850d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.yglrn
binary
MD5: 1ff0d9f85de578609180a2300c50b16e
SHA256: 07fdccd58bf49c0489aebef0f6a1b68d73d837ec5769e1c074c6282fde135e37
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.yglrn
binary
MD5: 5a2523761657f53978103d9dab00f01b
SHA256: e519ee5de0333c62e7d42dc9eeb63964ac403f07834bfe8480532a88b43a41cb
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.yglrn
binary
MD5: c2802aee754cfb5f22807a2574a13e17
SHA256: d692f1a4d698482ad4870b6110dec2ec194acfd73528a46e3fb542bb26d60aae
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.yglrn
binary
MD5: d2086c01266eeb83cb1c88f5668bf0cb
SHA256: b8bc5f6cab6d4d4e2c2fe85ce8b019dd5d8244d74c9e3c92b0b342147df5bf14
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.yglrn
binary
MD5: fb2f5418a73b89851fcca25ad940c914
SHA256: 57e29bb0423122217c9aace9ff26ef59b9575a5566e6f2edad43f4bf099665d0
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.yglrn
binary
MD5: 4a06a516da30f6898b640f05c8372809
SHA256: 1fb1cffb26137140ee8af90698dc732c7119572655383137cba379d6e29f17a8
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.yglrn
binary
MD5: 0f17e5da48ab800389d1a2e04cf29100
SHA256: 2b3b4772d0c96bef3ea625244dd3fb958ace6032300166f47886f0cce2931bf3
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.yglrn
pgc
MD5: 0a7b6e3146167de395fd289c68bbce4d
SHA256: b338234c51c9c467f0ea0a949970f212fae59b9aba52d74b2b7fdedf6dc1c524
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.yglrn
binary
MD5: 57ff1c4affb91ad0c7ffbd3a7d7e618c
SHA256: 46d864026b9641282cdcb101371aafe81b30da446cd2bbd7976cd1e41728c696
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.yglrn
binary
MD5: 9f4bba4b1413e27c10ca69b9daadc90e
SHA256: d01fd7ee571bbfa72159abe81de42d94b6da04d8022b1a016f5e631c96c6e275
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.yglrn
binary
MD5: 3c0dcde57e093edc7eb14c318d7f58aa
SHA256: fc79006057f7e82e69954d01fea22ed0e1a463f0d4d162a66da636e67cccc27f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.yglrn
binary
MD5: 695aa13099f135db8d69721e89980c62
SHA256: d02139979c9bfd39c9bb019dbe9713ff5261cc9788c8a4fb0b5cc70d56d05915
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.yglrn
binary
MD5: cf238055de02236175bd057210beb139
SHA256: 5eb82fbc73cc864db499b21c1e906bd7f13ab9efa83143594f6ef283b1d0a383
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.yglrn
binary
MD5: da40070123e40e67cbb543cb0039c3e0
SHA256: b2362c423a145f5387f492fcee513543490efcc2a2fe704a5b0cace81ec642d9
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.yglrn
binary
MD5: c6683c62b1a57df0ec3bb0b58a46fb66
SHA256: 90d253d9ff0353b33c4e8bcb1372b5081f33dfed0e15bf0c2b85b81218998b3a
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.yglrn
binary
MD5: 2d89e55b949e26a62b0286cefab72227
SHA256: 983b293a6886a22d1f281197391859a83c548338440ac3160ca683525755f15c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.yglrn
binary
MD5: 95969b096f637b32dc923b93b3a87246
SHA256: 3ca69c1d81b5c5a7ff4c2b3fef7da6f5884ca762e4f28997a4a246539ec011a3
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.yglrn
binary
MD5: 5fd02c7ad5ca02108db1a1c24925787a
SHA256: 3ff2e97e901bf905c2805ed5ea79cd00b93892f3b1daf3069e82d40500d4f09f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.yglrn
binary
MD5: 5ea13818a2517ded6a5c56fa27bd0f13
SHA256: 187e55a6a3b882f6d0cac64753da402253748ab581f4d0778022304bbd5bdafb
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.yglrn
mp3
MD5: ac0873ec542a953f2d845e771a48f1db
SHA256: cf993ba01a4b776e5d8e876049fcb8f164da2603d6cebfe368789b4f35704d0c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.yglrn
binary
MD5: ef003a919fceefb0ec36bf54f4c4e17c
SHA256: aadfd58b993f6e676c5df48ea37bba430930d6ad81aa7a43820d53bb5b9cf51e
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.yglrn
binary
MD5: 6ff969fb81302f454a1df4c5f057ee80
SHA256: 0dcec5a41bc8d0c4213e7207049cc0f1bc0cc4de50ae678e325d2ecee9937273
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.yglrn
binary
MD5: d70452ed663ffdae36afcbf277de9f6b
SHA256: f739522ac9b2f2d412651111063739d65d6aa73898751391a77b66c9d6ce6d50
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.yglrn
binary
MD5: 143439f8bb135b26e695459d82adc9e6
SHA256: 0a4621506839a5b2a15c940886f2fc63579b37b4bd1df23b12d6316c605e4518
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.yglrn
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.yglrn
binary
MD5: 4ce28405c1c8ddc5583ed8a958883bec
SHA256: f39321215dec752717b98e7e4274328beedb58b0172e28063998996346b19e23
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.yglrn
binary
MD5: c38d05581228aae8b7c456f6ff3c3748
SHA256: f7066b32248abfb185c56f7eb13a48200d68d48262969338047bccf8ba8b17d1
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.yglrn
binary
MD5: 730ae31ad5ae26a9934934d4d1b67555
SHA256: 275024b98c376b219ab9284ed92fda73e3a670598b8382b83a3314bfda0fd4e9
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.yglrn
binary
MD5: badb917aa91cfb2da45c5aafd3dae6cc
SHA256: 8805ce7c75ec487a2238d054c96edb18a2e0ed04e897f68390681d6a4f7917bd
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.yglrn
binary
MD5: a0d5a5d5cbd14eb189f1a8e6f662a1b1
SHA256: 02271303016c09d38e6cf386de68cf7d03056f56593f9ca47e4db94f88c63c94
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\b7638de2-5f3b-4f0d-acb7-516d3c63ffd6.yglrn
binary
MD5: 33ceea4dc8b4ed28326a1706d8449889
SHA256: e487040e69e4bd3017a49d2f9428f3a0d33e223d69c8b1258c4d7300deb3b215
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\b7638de2-5f3b-4f0d-acb7-516d3c63ffd6
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.yglrn
binary
MD5: c9550f73eb45731fb04295f6fcc7b1c9
SHA256: 295056a6c48646acb3c789435a8c464f8056e390cc2383b6f9fa3acf916c6a8f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.yglrn
binary
MD5: e7ae4a30febdc3bfdb510eb8569c9e70
SHA256: 82ce097419c2f684fdd2766ac26681829715b438298fe19323dd6344ed45894d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.yglrn
binary
MD5: 22678fb5cc0c0a420901b77db681ade0
SHA256: 7c46cd14bbff21f1bbc42c969d5ee08e3ace3f8416500a6533bb278259ff193c
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.yglrn
binary
MD5: c26c0c235a669acb15dd87a447586cc5
SHA256: 930c151abd9c203abc7302ed2ac6595a0f4cf49c48b6c0a2c5e8fe887f94eddf
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.yglrn
binary
MD5: 31c8ead1f2a21f8b173cf40ceb78e1b4
SHA256: 9d8838e1c3aa01313b3a2bc64c8c00305f3047ee7cc2e9a3f72e9b75fee37cdc
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.yglrn
binary
MD5: cd03d4ff1eacec3ee62346c2092bb6d0
SHA256: 2863b0fe093485de547e774b60d2dffd143f743613950ac18062a29f8216f278
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.yglrn
binary
MD5: d1d9945749762a092ab3ab2e841c6d16
SHA256: 69a1cc495f39aa685f8b89568f91c107d5070f66e73f038fe7ab50f8f9b51cba
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.yglrn
binary
MD5: ba720e099da2791e8680501bfba845bf
SHA256: b028e5075357c948cd2f0e9505c6b8895c5bdc257fe21f71c12f54c69026676d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.yglrn
binary
MD5: 506d7dcf4d7fd5d5235c255c60607f12
SHA256: d20a8df63e11111a2c9dc28c1dfd224ea49f82eb9a58a064a4c6abf6af2ac5ac
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.yglrn
binary
MD5: 319b8d2a0bf3a05b09555e96a7a8d456
SHA256: 40cbb047ff67d1dbc594cb4a961ff1702ff9a47c18f534a88a1bf1457d6fa45d
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat.yglrn
binary
MD5: 0f9df32d6f5a04c8491bbd37b584d04b
SHA256: 5826ad1879ee7425ed170bbf9dfead7bb70c1e98a7f438462c97d83fee0ce7cc
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.yglrn
binary
MD5: 9191c7c0da457b18ca1ef5f45d9f3de6
SHA256: 1925fa6d80185cac74eb49341cf109f3c0c359eabdb6834309eba35b8091779e
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.yglrn
binary
MD5: 22293f9ac7473ef37b82af8b567226ee
SHA256: db4e4f35f39c96d2a6a7a801edf75570977d4d89dbc0f84fa189bd148d89f52f
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.yglrn
binary
MD5: 12232e250eeefd8bffc1c0d8156423a9
SHA256: eb9d8122d54189980a485950c48b1301f257bb7eb2f97c2e017384c6732e7a71
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\YGLRN-DECRYPT.txt
text
MD5: 666125d7e884b99eb986eb09b8a9e3b1
SHA256: 32913141d6a49ffbd0ffc5b1f2e9ecd431f8e980c2804db81f87dda6498672c2
3632
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.yglrn
binary
MD5: ac02b3a1f420aa1f5e62c3e6c99bf728
SHA256: b749c0479bb424eebad17fcab90cec03b50bb3e80531ffeb1f