General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

rechnungen.doc.zip

Verdict
Malicious activity
Analysis date
1/10/2019, 20:34:54
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
ransomware
gandcrab
trojan
Indicators:

MIME:
application/zip
File info:
Zip archive data, at least v2.0 to extract
MD5

93b8a960c9bdc145cac212c84091eaa6

SHA1

964610793676dd023d3e5080d3b3ea2231a222b8

SHA256

66695450843deb563e4e8cc11655125367ad54a84f3c277d4283cd6df0d1b13b

SSDEEP

384:s96rTiO8h/dGuVlMkYEPxjk0fr5mBQs8nPugK+T+Vipm44g1o42edIa:JrTXE/cu8kzjnjwOPugKmgipm9g12e5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Requests a remote executable file from MS Office
  • WINWORD.EXE (PID: 2364)
Executable content was dropped or overwritten
  • WINWORD.EXE (PID: 2364)
Unusual execution from Microsoft Office
  • WINWORD.EXE (PID: 2364)
Application was dropped or rewritten from another process
  • yeZjqHFMWjXi.exe (PID: 2872)
Writes file to Word startup folder
  • yeZjqHFMWjXi.exe (PID: 2872)
GandCrab keys found
  • yeZjqHFMWjXi.exe (PID: 2872)
Renames files like Ransomware
  • yeZjqHFMWjXi.exe (PID: 2872)
Actions looks like stealing of personal data
  • yeZjqHFMWjXi.exe (PID: 2872)
Deletes shadow copies
  • yeZjqHFMWjXi.exe (PID: 2872)
Dropped file may contain instructions of ransomware
  • yeZjqHFMWjXi.exe (PID: 2872)
Connects to CnC server
  • yeZjqHFMWjXi.exe (PID: 2872)
Unusual connect from Microsoft Office
  • WINWORD.EXE (PID: 2364)
Reads the cookies of Mozilla Firefox
  • yeZjqHFMWjXi.exe (PID: 2872)
Creates files like Ransomware instruction
  • yeZjqHFMWjXi.exe (PID: 2872)
Creates files in the user directory
  • yeZjqHFMWjXi.exe (PID: 2872)
Reads Microsoft Office registry keys
  • WINWORD.EXE (PID: 2364)
Creates files in the user directory
  • WINWORD.EXE (PID: 2364)
Dropped object may contain TOR URL's
  • yeZjqHFMWjXi.exe (PID: 2872)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.zip
|   ZIP compressed archive (100%)
EXIF
ZIP
ZipRequiredVersion:
788
ZipBitFlag:
0x0001
ZipCompression:
Deflated
ZipModifyDate:
2019:01:10 00:19:24
ZipCRC:
0xd0ce65af
ZipCompressedSize:
25629
ZipUncompressedSize:
65536
ZipFileName:
rechnungen.doc

Screenshots

Processes

Total processes
42
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

+
start download and start winrar.exe no specs winword.exe #GANDCRAB yezjqhfmwjxi.exe wmic.exe no specs explorer.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2952
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\rechnungen.doc.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\installer\{90140000-003d-0000-0000-0000000ff1ce}\wordicon.exe
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
2364
CMD
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\rechnungen.doc"
Path
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Word
Version
14.0.6024.1000
Modules
Image
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\gdi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\microsoft office\office14\wwlib.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\program files\microsoft office\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\program files\microsoft office\office14\oart.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\program files\microsoft office\office14\1033\wwintl.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwmapi.dll
c:\program files\common files\microsoft shared\office14\msptls.dll
c:\windows\system32\uxtheme.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shell32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\progra~1\common~1\micros~1\vba\vba7\vbe7.dll
c:\program files\microsoft office\office14\gkword.dll
c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
c:\windows\system32\spool\drivers\w32x86\3\sendtoonenoteui.dll
c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
c:\windows\system32\fontsub.dll
c:\program files\common files\microsoft shared\office14\usp10.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\sxs.dll
c:\progra~1\common~1\micros~1\vba\vba7\1033\vbe7intl.dll
c:\windows\system32\fm20.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\fm20enu.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\users\public\yezjqhfmwjxi.exe
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\prntvpt.dll
c:\program files\microsoft office\office14\msproof7.dll
c:\program files\microsoft office\office14\proof\1033\msgr3en.dll
c:\windows\system32\oleacc.dll
c:\program files\common files\system\ado\msadox.dll
c:\windows\system32\netutils.dll

PID
2872
CMD
C:\Users\Public\yeZjqHFMWjXi.exe
Path
C:\Users\Public\yeZjqHFMWjXi.exe
Indicators
Parent process
WINWORD.EXE
User
admin
Integrity Level
MEDIUM
Version:
Company
Abbott Laboratories
Description
Succession Directoryshell
Version
Modules
Image
c:\users\public\yezjqhfmwjxi.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\oledlg.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\tapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mpr.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\browcli.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll

PID
3032
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
No indicators
Parent process
yeZjqHFMWjXi.exe
User
admin
Integrity Level
MEDIUM
Exit code
2147749908
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

PID
3968
CMD
"C:\Windows\explorer.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

Registry activity

Total events
1486
Read events
1306
Write events
176
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
2952
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\rechnungen.doc.zip
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface
ShowPassword
0
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\AppData\Local\Temp
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
name
120
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
size
80
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
psize
80
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
type
120
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
mtime
100
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
crc
70
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C800000000000000000000000000880103000000000039000000B40200000000000001000000
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C8000000000000000000000000003C01020000000000160000002A0000000000000002000000
2952
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C8000000000000000000000000009A0103000000000016000000640000000000000003000000
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
"*.
222A2E003C090000010000000000000000000000
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
WORDFiles
1311375382
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1311375500
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1311375501
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
3C0900005CD2E8AC1BA9D40100000000
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
z+.
7A2B2E003C09000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
e,.
652C2E003C09000006000000010000005C000000020000004C0000000400000063003A005C00750073006500720073005C00610064006D0069006E005C006400650073006B0074006F0070005C0072006500630068006E0075006E00670065006E002E0064006F006300000000000000
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
VBAFiles
1311375364
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
{5C9BBD45-EA93-4111-BB84-7204AD23276C}
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
25
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Item 1
[F00000000][T01D4A91BAD83BC90][O00000000]*C:\Users\admin\Desktop\
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Max Display
25
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Item 1
[F00000000][T01D4A91BAD83BC90][O00000000]*C:\Users\admin\Desktop\rechnungen.doc
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\24ED4F
24ED4F
040000003C0900002500000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C0072006500630068006E0075006E00670065006E002E0064006F0063000E00000072006500630068006E0075006E00670065006E002E0064006F006300000000000100000000000000806BB3CF71A8D4014FED24004FED240000000000DB040000000000000000000000000000000000000000000000000000FFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\TypeLib\{9A82E156-9BDE-4766-94EB-FD785B5267D4}\2.0
Microsoft Forms 2.0 Object Library
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\TypeLib\{9A82E156-9BDE-4766-94EB-FD785B5267D4}\2.0\FLAGS
6
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\TypeLib\{9A82E156-9BDE-4766-94EB-FD785B5267D4}\2.0\0\win32
C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\TypeLib\{9A82E156-9BDE-4766-94EB-FD785B5267D4}\2.0\HELPDIR
C:\Users\admin\AppData\Local\Temp\VBE
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}
Font
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{EC72F590-F375-11CE-B9E8-00AA006B1A69}
IDataAutoWrapper
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{82B02370-B5BC-11CF-810F-00A0C9030074}
IReturnInteger
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{82B02371-B5BC-11CF-810F-00A0C9030074}
IReturnBoolean
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{82B02372-B5BC-11CF-810F-00A0C9030074}
IReturnString
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8A683C90-BA84-11CF-8110-00A0C9030074}
IReturnSingle
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8A683C91-BA84-11CF-8110-00A0C9030074}
IReturnEffect
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC6-866C-11CF-AB7C-00AA00C08FCF}
IControl
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC7-866C-11CF-AB7C-00AA00C08FCF}
Controls
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{29B86A70-F52E-11CE-9BCE-00AA00608E01}
IOptionFrame
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC8-866C-11CF-AB7C-00AA00C08FCF}
_UserForm
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{9A4BBF53-4E46-101B-8BBD-00AA003E3B29}
ControlEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5B9D8FC8-4A71-101B-97A6-00000B65C08B}
FormEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{CF3F94A0-F546-11CE-9BCE-00AA00608E01}
OptionFrameEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC1-866C-11CF-AB7C-00AA00C08FCF}
ILabelControl
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC4-866C-11CF-AB7C-00AA00C08FCF}
ICommandButton
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D13-EC42-11CE-9E0D-00AA006002F3}
IMdcText
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D23-EC42-11CE-9E0D-00AA006002F3}
IMdcList
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D33-EC42-11CE-9E0D-00AA006002F3}
IMdcCombo
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D43-EC42-11CE-9E0D-00AA006002F3}
IMdcCheckBox
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D53-EC42-11CE-9E0D-00AA006002F3}
IMdcOptionButton
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D63-EC42-11CE-9E0D-00AA006002F3}
IMdcToggleButton
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC3-866C-11CF-AB7C-00AA00C08FCF}
IScrollbar
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{A38BFFC3-A5A0-11CE-8107-00AA00611080}
Tab
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{944ACF93-A1E6-11CE-8104-00AA00611080}
Tabs
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC2-866C-11CF-AB7C-00AA00C08FCF}
ITabStrip
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{79176FB3-B7F2-11CE-97EF-00AA006D2776}
ISpinbutton
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{4C599243-6926-101B-9992-00000B65C6F9}
IImage
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D111-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLSubmitButton
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D113-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLImage
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D115-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLReset
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D117-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLCheckbox
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D119-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLOption
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D11B-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLText
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D11D-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLHidden
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D11F-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLPassword
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D123-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLSelect
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5512D125-5CC6-11CF-8D67-00AA00BDCE1D}
IWHTMLTextArea
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{978C9E22-D4B0-11CE-BF2D-00AA003F40D0}
LabelControlEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{7B020EC1-AF6C-11CE-9F46-00AA00574A4F}
CommandButtonEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D12-EC42-11CE-9E0D-00AA006002F3}
MdcTextEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D22-EC42-11CE-9E0D-00AA006002F3}
MdcListEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D32-EC42-11CE-9E0D-00AA006002F3}
MdcComboEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D42-EC42-11CE-9E0D-00AA006002F3}
MdcCheckBoxEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D52-EC42-11CE-9E0D-00AA006002F3}
MdcOptionButtonEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{8BD21D62-EC42-11CE-9E0D-00AA006002F3}
MdcToggleButtonEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{7B020EC2-AF6C-11CE-9F46-00AA00574A4F}
ScrollbarEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{7B020EC7-AF6C-11CE-9F46-00AA00574A4F}
TabStripEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{79176FB2-B7F2-11CE-97EF-00AA006D2776}
SpinbuttonEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{4C5992A5-6926-101B-9992-00000B65C6F9}
ImageEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{796ED650-5FE9-11CF-8D68-00AA00BDCE1D}
WHTMLControlEvents
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE0-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents1
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE1-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents2
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE2-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents3
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE3-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents4
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE4-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents5
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE5-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents6
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE6-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents7
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE8-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents9
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{47FF8FE9-6198-11CF-8CE8-00AA006CB389}
WHTMLControlEvents10
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{5CEF5613-713D-11CE-80C9-00AA00611080}
IPage
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{92E11A03-7358-11CE-80CB-00AA00611080}
Pages
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{04598FC9-866C-11CF-AB7C-00AA00C08FCF}
IMultiPage
2364
WINWORD.EXE
write
HKEY_CLASSES_ROOT\Interface\{7B020EC8-AF6C-11CE-9F46-00AA00574A4F}
MultiPageEvents
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2364
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1311375397
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1311375398
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1311375397
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1311375398
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1311375414
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1311375415
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1311375399
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00000000000F01FEC\Usage
SpellingAndGrammarFiles_3082
1311375400
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1311375399
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC\Usage
SpellingAndGrammarFiles_1036
1311375400
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1311375416
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1311375417
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1311375418
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1311375419
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1311375420
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC\Usage
SpellingAndGrammarFiles_1033
1311375421
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Licensing
019C826E445A4649A5B00BF08FCC4EEE
01000000270000007B39303134303030302D303033442D303030302D303030302D3030303030303046463143457D005A0000004F00660066006900630065002000310034002C0020004F0066006600690063006500500072006F00660065007300730069006F006E0061006C002D00520065007400610069006C002000650064006900740069006F006E000000
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Toolbars\Settings
Microsoft Word
0101000000000000000006000000
2364
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\24ED4F
2364
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery
2364
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
C00010033001000034010000040000001E0000001E0000001E0000001E0000001E0000001E000000220000001E0000001E0000001E000000060000000600000006000000060000000600000000000000060000000600000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000C00000002000000020000000200000002000000000000000000000000000000480000000600000006000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004000000DC000000E25024A1100A00633090060006000A002D00F9FFFFFF56000000C0030000F501000004060300000000000000000000000000040087010C000600C80009000180FFFF000006000000040000000C0100000502000000000000A004020000001200000000603090000064000000000000FF0000FF000000000000FF01000000010000005C08E0100000000000010000E40400001D000100000000000000020050000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D000000000000000000000000D4944600D49446010000002F91010000080A000600000003333296040000000A050C0C0302040600000300000101010606060000000000000000000000000000000000000063631900000001000000000000000000000000000000030000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002100190000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000B01300004B0000004B000000640000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000009002000002000001010101010101000101010101010001010100010001000101010101010101000100020003010301030103000301020003010301030103010000230101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101020101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010301010101010101010101010101FFFFCFFFFFFF00008602FFFF00008602FFFF00000C00FFFF00000100FFFF00000100FFFF0000010061000000610064006D0069006E000000000000000000000087FFFF0300003E00020200000600090034000000000090009000000000000F000000FFFFFF000000000000001400140000000000000002637800C80000000000140000000000900090008000FFFF00000800FFFF00000800FFFF0B00040001002000018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E00650077000180140001002000018014000B0043006F007500720069006500720020004E00650077000180140009004D005300200047006F0074006800690063000180150007004D0069006E0067004C0069005500018018000600530069006D00530075006E0001801500050044006F00740075006D00018014000100200001801C0000000000
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
BackgroundOpen
0
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
0
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\VBA\7.0\Common
PropertiesWindow
4 23 180 640 1
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\VBA\7.0\Common
MainWindow
0 0 0 0 1
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\VBA\7.0\Common
MdiMaximized
0
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\VBA\7.0\Common
Dock
02004C010500080004001E00FC03FC02FF02010104001E00B800FC02FF02000104001E00B8002F010500000104003501B800FC0201000001BE001E00FC03FC02FF020001BE001E00FC03FC02FF020101BE001E00FC03FC0200000001BB035E00FC03FC0206000000D300AF0109033202FF030100D300AF0109033202040000009301AF010903320203000000D300AF010903320202000000210072016C021202FF03010021007201E800120204000000EE007201A901120203000000AF0172016C02120202000000F8028100AC03010105000000590030020D014B03010000003A03BC0079031F020600000016001600D901C400040001002C002C00EB01E30003000100420042003B02F70002000100000000000000000008000000580057003701FF01010001000000000000000000060001006E006E007F01520105000100000000000000000000000100
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\VBA\7.0\Common
FolderView
1
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\VBA\7.0\Common
Tool
000000000700000047656E6572616C00FFFFFFFFFFFFFFFF
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\VBA\7.0\Common
CtlsShowSelected
0
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\VBA\7.0\Common
DsnShowSelected
0
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1311375502
2364
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1311375503
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
92
2364
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
92
2872
yeZjqHFMWjXi.exe
write
HKEY_CURRENT_USER\Software\ex_data\data
ext
2E006700750061006500660078006C006C0061006E000000
2872
yeZjqHFMWjXi.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
public
0602000000A400005253413100080000010001009304BB27A4A4D556F388C71EB62F753F4D550D328CF5F63BAFB4D8786C46736ADBB209CEA36F30DF40800DF7BB241D37A23CAFFF80001269831E0D275966C4A6E35D6902068CF9DE8F60D12174FDEAA7ACE86A2CA308C7ECA9A1262FE4D9A7F89AE44485821A9AE492B6EFEEB5C932CA39A1585DAF9DB9F856B186CAA29EBB298393686001E7DFD1C37897C751F35F350D84AD1577B4D323D8D10C0880067315D9199217C8E7C1916E718F212CB3391410B19867DF58885FB61419B5CC63D1E27E4DB2FF0192EFB412FF35B21225373254C9584FD84C6F7D331076EC60CB712A37C87B53A048CA3B4B69E13D1EF5F2ABB205A7277892C3EBF2A0293C7CDC72D6
2872
yeZjqHFMWjXi.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
private
94040000C807E6E649445B83E07BD43AA56BA1417DAF2E4BBFEC49D76203B321566B640107E83041D76813C61DB6C6B8502EAA8FA0E6F4EC194B092D0DC38F1323F6CB1172474CFD37BAFCE8AC8E37A958E660BEEE300785593EEBE4C14B240CBF21B3894CD7711B881E24F8D873AC4B6D5621187A564E5E8E7225A6ECA334A3A813589D1858893C91CBA512B7F1DEA58F9CB26B267327AD014294CCD50D44AAB30F1E4654B9CEE449FA0A69B42FAA948F16E4E14089C6D0A65D743D17E4BEAA7279D4FFB80AE85EC4AF771CABABC7542DB1C6EAB857EBCBF595A9BA1A06983577413DA5FB4D6FE8F42281037192EB837D5EA20BF60B33A03962E6F99F9388CD7B5B538EF17FFFBB87CC6B12B6DE2E270B453E1F688783293295943CE85697521053C20AF26B9055E01FB563BEDF2F99CBC031A8FE8E9CBB6FFF2630E665530AD69E5617AC330971FAC810A2FB6E367A435AF915AF75381CC0621AFCD0995BACF1AA12265E8E86DA0D5C817EB23D81EA1AACC6BE913147CCC6AA76B4915EA6613FADCE59A5F6CA1AA1BD4A8E2C5EA105115F4BEF7EA069F9A4A5B3EF1790190C158D181C5B7B1A70B9BACC22CCBC79A8C3C4B3E06FBA4C79DDE19F8C742EB3D22A7E824A144A5B0A44DBEE8A6A66BC7CF8FEC783778CF1CBDE80AFF82CF52000FD265B04AD81A06A26E45F6FC10ABA30357F2426F3C1120D26CAB1A904C9C7D8FDE4DB2424E40C7D238738B1AB25D293AB9F085D9A301C721C0D1231F7030E8EB451E275015BC9BA8BB50DA5602AFCA97DE20DD6C979606EB697E1A97617290F689FEC427E50C4F54CB69AB9CF1A680A60F6386CBF7CB59026B33F2EFEBCB6E1D92B0B3A2CBA03B78DCC410072A93F6EE20B0D3AC4D2DA6C9EAEEB49178355AC9C4E5F9E43FE8B911E21F1FE60010C15CD1689BD38D0A4D06C8F765DAFC90A8B0E00E00DA2044E0CBD628C51BF5DBD8CC518B9F92A714095011C52087CAF8CDBD1DC62782044259B8072CD54514FF5BA01DEAA545EB7E637ED8D5A9CD1D79D74DFC3DC8AFC65F9093B21CAAE07B0E3AEA052436E7E3D359012210F6B6DBD02BD2B4B3D81D90DEB92F15148CA6C4DE7E9A2C15252EAE94D54F7FBE2E0C6ECC2947212A116D81339EB77BD090BA274B5AA7BC24D551C2E662C56DC0D37432142E67D6A5CCCC5C81A313863190154FA7C61DCA8D28A59006635CDC52B7AF37B47E94FE618BCEAF3179171F20E82A5514AE846DA96348CE270A50CBA1F9C1608C8A0DD9CAEFADF3E88E3FB3C5CD70E9538688256B81CA644729C430583BD971BD4A9F0AF9BD4263275B2D726767E1EFAA9A5139CC1AABB1AC2E7C42AF690D3507C84CB7C73DFDAE0A7467309BD6E30489769FA534AD3BE238F5A3AD546BA0580FA3F4720253BB524B369E422D9D524E7C11A91986B71F8A34FFDEE44EC1B8A60EE907A8E7F981E0B3485F13D4994FA28BF29A2E898BD09BBEB4F9ABEE01E62549715E8A210228961933385DFBB78C6F0B3A479844BB39A68FE5483A9A3FFEFB333BB9A451FE989AA8CE0621633E7D0A2218BBA9BDAE3A25C0333D5430DAC1CA637B78B4B9FC89BF83DD4888071DD0C7DC7690B338593DD23695E3056D7BC18D314C74BE4EBBA78A17AE1579CDCEA3DC2F47BA121049D0F8018BD2131F39265F7ED32D8CB309EE9FD568DA8B318BBA3F2B6335E583BF74893FBB193FFAECFB63F4728DAFBA4C13A7443A4CDAD0FE7F283E14054160AC98445B0870B0913AAFC228A1798F5E05B4C781E355F3625DDAA0C63A72375FD72C6D5A48376CA4966311996A53F1ECD6B857CD18E50ECB42E1B96D6CA1A7BD9755677569CDF15FF250476E27A179284E4B342D322C87CC454C59B3FB151D3E0C258D677389A4D7CBFA83E1ED3BAA5B3419391204F93DE812233098BB60DE687D0F081598C384E8C95C414B0A93FD9F90314DB77A2A3042422611DD503EB4BD42962973288A8F8D89E1B06FA4FE5FBFBF32AC5EB2C7273B04820CDF86166ED73C8A2F9A5BFB95140F6124A3BF6A44E40EE1B00F2498C62E18C9E41A58983C730A0D520EF4427F19402C94ED03D0964D2FECB1654285FED8CD91A5EB31D5F0D7B7FB83AF5DF734F6235DA58050C7B73F3D1526D12EC1EDE5761900CBE4C6EE2A4A00B5FFE1F95F40AE7EBA47CABD651D90BF7FA9488095C28CDF4E65A114E9B26C719ECC1C8F4331385BFC7BAF37FA04BF2DB6A46E27AEA727741346E978FDD5CEA0B9523C1E8B38121ECAB84E6A16E3D2867C000FDD9A165ECE7988B7B1F71C16BC435B73C5AB2906D93AD8AAEE506AFBAF8B7D5E981208FE1EDB854DEE9C806BABF872DDAC62BB89849D053B19ABFE4C804A590C467A318AD111DFFF8FBE00D5A0B1BA670
2872
yeZjqHFMWjXi.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2872
yeZjqHFMWjXi.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASAPI32
EnableFileTracing
0
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASAPI32
EnableConsoleTracing
0
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASAPI32
FileTracingMask
4294901760
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASAPI32
ConsoleTracingMask
4294901760
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASAPI32
MaxFileSize
1048576
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASAPI32
FileDirectory
%windir%\tracing
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASMANCS
EnableFileTracing
0
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASMANCS
EnableConsoleTracing
0
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASMANCS
FileTracingMask
4294901760
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASMANCS
ConsoleTracingMask
4294901760
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASMANCS
MaxFileSize
1048576
2872
yeZjqHFMWjXi.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\yeZjqHFMWjXi_RASMANCS
FileDirectory
%windir%\tracing
2872
yeZjqHFMWjXi.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2872
yeZjqHFMWjXi.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2872
yeZjqHFMWjXi.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US

Files activity

Executable files
2
Suspicious files
289
Text files
235
Unknown types
10

Dropped files

PID Process Filename Type
2364 WINWORD.EXE C:\Users\Public\yeZjqHFMWjXi.exe executable
2364 WINWORD.EXE C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\rundll[1].exe executable
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@alimentarium[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@hotellido-lugano[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.hotelolden[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.elite-biel[2].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.elite-biel[1].txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.staubbach[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@16eme[2].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@16eme[1].txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.16eme[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.16eme[2].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.stalden[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.stalden[2].txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.stalden[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@kroneregensberg[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.kroneregensberg[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.hotelgarni-battello[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.hoteltruite[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.hoteltruite[2].txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@bellevuewiesen[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.waageglarus[2].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.waageglarus[1].txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.bristol-adelboden[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.bristol-adelboden[2].txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.bristol-adelboden[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.arbezie[2].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.arbezie[1].txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.arbezie-hotel[2].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.arbezie-hotel[1].txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Local\Temp\TarB334.tmp ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Local\Temp\CabB333.tmp ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 compressed
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Local\Temp\CabB275.tmp ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Local\Temp\TarB276.tmp ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Local\Temp\CabB264.tmp ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Local\Temp\TarB265.tmp ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.morcote-residenza[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@belvedere-locarno[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.pizcam[1].txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Local\Temp\pidor.bmp image
2872 yeZjqHFMWjXi.exe C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Videos\Sample Videos\Wildlife.wmv ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Videos\Sample Videos\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Recorded TV\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Recorded TV\Sample Media\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Koala.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Desert.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\Sample Pictures\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Music\Sample Music\Sleep Away.mp3 ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Music\Sample Music\Sleep Away.mp3.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3 ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Music\Sample Music\Kalimba.mp3.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Music\Sample Music\Kalimba.mp3 ––
2872 yeZjqHFMWjXi.exe C:\Users\Public\Music\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Downloads\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Music\Sample Music\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Libraries\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Favorites\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Videos\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Documents\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Pictures\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\Libraries\RecordedTV.library-ms.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\Public\Libraries\RecordedTV.library-ms ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\Public\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Saved Games\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Searches\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\organizationshalf.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\southernjames.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\octkeep.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\octkeep.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\organizationshalf.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\southernjames.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\desenior.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Links\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\jank.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\ntuser.ini.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\jank.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\desenior.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\ntuser.ini ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSNBC News.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\Get Windows Live.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN Money.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN Sports.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN Money.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\MSN Websites\MSN Autos.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links for United States\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links\Web Slice Gallery.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links for United States\USA.gov.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Microsoft Websites\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links\Suggested Sites.url.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links\Web Slice Gallery.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links for United States\USA.gov.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links\Suggested Sites.url ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\majoran.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Favorites\Links\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\recommendyes.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\listingsvision.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\recommendyes.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\listingsvision.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\majoran.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\sexyspring.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\centerinvolved.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\farmdepartment.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\servicesislands.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\farmdepartment.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\sexyspring.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Downloads\centerinvolved.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\servicesislands.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\requiredsony.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\requiredsony.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\Outlook.pst.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\Outlook.pst ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\honey@pot.com.pst.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\honey@pot.com.pst ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\Outlook Files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\OneNote Notebooks\Personal\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Pictures\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Music\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\OneNote Notebooks\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\applet.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\floorsolution.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\commerceworth.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\marchvision.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Videos\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\commerceworth.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\floorsolution.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\marchvision.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\applet.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\priceslisting.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\someonebill.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Documents\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\writepolicy.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\retailnaked.jpg.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\shophaving.rtf.guaefxllan pgc
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\someonebill.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\writepolicy.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\shophaving.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\retailnaked.jpg ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\danceen.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\devicescover.png.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\finaleditor.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\enterpolitical.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\danceen.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\devicescover.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\enterpolitical.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\priceslisting.png ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\finaleditor.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\cashbasic.rtf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Contacts\admin.contact.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\Contacts\admin.contact ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Desktop\cashbasic.rtf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\Contacts\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\WinRAR\version.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Sun\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Sun\Java\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\WinRAR\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\WinRAR\version.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\SkypeRT\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared_dynco\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\logs\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\shared.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Skype\DataRv\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.guaefxllan pgc
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Opera\Opera\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.guaefxllan mp3
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\themes\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\plugins\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Notepad++\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite ––
2952 WinRAR.exe C:\Users\admin\AppData\Local\Temp\Rar$DRb2952.42043\rechnungen.doc document
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Vault\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Extensions\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Word\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\UProof\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Speech\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.guaefxllan flc
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.guaefxllan vc
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Stationery\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.guaefxllan ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Signatures\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\30d5b9c8-e982-45c1-9766-9841c55774e2.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Publisher\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\30d5b9c8-e982-45c1-9766-9841c55774e2 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Proof\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8 ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\OneNote\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Office\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\MMC\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Network\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd ––
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Forms\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.guaefxllan binary
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\GUAEFXLLAN-DECRYPT.txt text
2872 yeZjqHFMWjXi.exe C:\Users\admin\AppData\Roaming\Microsoft\Excel\GUAEFXLLAN-DECRYPT.txt text