\n\n\n\n \n \n \n\n\n\n\n \n \nstart \n \n\n\n\n\n \n \n \n\n\n\n \n \n \n\n\n\n \n\nrundll32.exe \n\n \n\n\n\n\n \n\n\n\n#SODINOKIBI \n \n\nrundll32.exe \n\n\n\n\n \n \n\n\n\n \n\nunsecapp.exe \nno specs \n \n\n\n\n\n \n\n\n\n \n\nvssvc.exe \nno specs \n \n\n\n\n\n \n\n\n","processesValues":[{"rowId":"6aa40437-579d-4a12-aabf-99b86a3af91e","rowData":{"threatLevel":0,"values":[648,"\"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\admin\\AppData\\Local\\Temp\\stage3.dll\", DllRegisterServer","C:\\Windows\\System32\\rundll32.exe",["crashedApps"],"explorer.exe"],"information":{"values":["admin","Microsoft Corporation","MEDIUM","Windows host process (Rundll32)","","6.1.7600.16385 (win7_rtm.090713-1255)"],"modules":[["c:\\windows\\system32\\rundll32.exe"],["c:\\systemroot\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\imagehlp.dll"],["c:\\windows\\system32\\apphelp.dll"],["c:\\windows\\apppatch\\aclayers.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\windows\\system32\\winspool.drv"],["c:\\windows\\system32\\mpr.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\users\\admin\\appdata\\local\\temp\\stage3.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\winhttp.dll"],["c:\\windows\\system32\\webio.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\rstrtmgr.dll"],["c:\\windows\\system32\\ncrypt.dll"],["c:\\windows\\system32\\bcrypt.dll"],["c:\\windows\\system32\\netapi32.dll"],["c:\\windows\\system32\\netutils.dll"],["c:\\windows\\system32\\srvcli.dll"],["c:\\windows\\system32\\wkscli.dll"],["c:\\windows\\system32\\samcli.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\propsys.dll"],["c:\\windows\\winsxs\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\\comctl32.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\urlmon.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-ole32-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-shlwapi-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-advapi32-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-user32-l1-1-0.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-version-l1-1-0.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\api-ms-win-downlevel-normaliz-l1-1-0.dll"],["c:\\windows\\system32\\normaliz.dll"],["c:\\windows\\system32\\iertutil.dll"],["c:\\windows\\system32\\wininet.dll"],["c:\\windows\\system32\\secur32.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\sfc.dll"],["c:\\windows\\system32\\sfc_os.dll"]]}}},{"rowId":"c7982fa2-2efb-44e0-9fa0-011fd33dd05d","rowData":{"threatLevel":2,"values":[4024,"\"C:\\Windows\\System32\\rundll32.exe\" C:\\Users\\admin\\AppData\\Local\\Temp\\stage3.dll, DllRegisterServer ","C:\\Windows\\System32\\rundll32.exe",["autoStart","knownThreat","network","stealing","privEscalation"],"rundll32.exe"],"information":{"values":["admin","Microsoft Corporation","HIGH","Windows host process (Rundll32)","","6.1.7600.16385 (win7_rtm.090713-1255)"],"modules":[["c:\\windows\\system32\\rundll32.exe"],["c:\\systemroot\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\imagehlp.dll"],["c:\\windows\\system32\\apphelp.dll"],["c:\\windows\\apppatch\\aclayers.dll"],["c:\\windows\\system32\\sspicli.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\shell32.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\userenv.dll"],["c:\\windows\\system32\\profapi.dll"],["c:\\windows\\system32\\winspool.drv"],["c:\\windows\\system32\\mpr.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\users\\admin\\appdata\\local\\temp\\stage3.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\winhttp.dll"],["c:\\windows\\system32\\webio.dll"],["c:\\windows\\system32\\winmm.dll"],["c:\\windows\\system32\\crypt32.dll"],["c:\\windows\\system32\\msasn1.dll"],["c:\\windows\\system32\\rstrtmgr.dll"],["c:\\windows\\system32\\ncrypt.dll"],["c:\\windows\\system32\\bcrypt.dll"],["c:\\windows\\system32\\netapi32.dll"],["c:\\windows\\system32\\netutils.dll"],["c:\\windows\\system32\\srvcli.dll"],["c:\\windows\\system32\\wkscli.dll"],["c:\\windows\\system32\\samcli.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\winsxs\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\\comctl32.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\ntmarta.dll"],["c:\\windows\\system32\\wldap32.dll"],["c:\\windows\\system32\\propsys.dll"],["c:\\windows\\system32\\wbem\\wbemprox.dll"],["c:\\windows\\system32\\wbemcomn.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\wbem\\fastprox.dll"],["c:\\windows\\system32\\ntdsapi.dll"],["c:\\windows\\system32\\cryptsp.dll"],["c:\\windows\\system32\\rsaenh.dll"],["c:\\windows\\system32\\rpcrtremote.dll"],["c:\\windows\\system32\\wbem\\wbemsvc.dll"],["c:\\windows\\system32\\drprov.dll"],["c:\\windows\\system32\\winsta.dll"],["c:\\windows\\system32\\ntlanman.dll"],["c:\\windows\\system32\\davclnt.dll"],["c:\\windows\\system32\\davhlpr.dll"],["c:\\windows\\system32\\cscapi.dll"],["c:\\windows\\system32\\browcli.dll"],["c:\\windows\\system32\\iconcodecservice.dll"],["c:\\windows\\system32\\windowscodecs.dll"],["c:\\windows\\system32\\credssp.dll"],["c:\\windows\\system32\\mswsock.dll"],["c:\\windows\\system32\\wshqos.dll"],["c:\\windows\\system32\\wshtcpip.dll"],["c:\\windows\\system32\\wship6.dll"],["c:\\windows\\system32\\dnsapi.dll"],["c:\\windows\\system32\\iphlpapi.dll"],["c:\\windows\\system32\\winnsi.dll"],["c:\\windows\\system32\\rasadhlp.dll"],["c:\\windows\\system32\\fwpuclnt.dll"],["c:\\windows\\system32\\schannel.dll"],["c:\\windows\\system32\\secur32.dll"],["c:\\windows\\system32\\bcryptprimitives.dll"],["c:\\windows\\system32\\gpapi.dll"]]}}},{"rowId":"9c1221d3-0e30-4248-8f86-eccf035a838b","rowData":{"threatLevel":0,"values":[2464,"C:\\Windows\\system32\\wbem\\unsecapp.exe -Embedding","C:\\Windows\\system32\\wbem\\unsecapp.exe",[],"svchost.exe"],"information":{"values":["admin","Microsoft Corporation","HIGH","Sink to receive asynchronous callbacks for WMI client application","","6.1.7600.16385 (win7_rtm.090713-1255)"],"modules":[["c:\\windows\\system32\\wbem\\unsecapp.exe"],["c:\\systemroot\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\wbemcomn.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\ws2_32.dll"],["c:\\windows\\system32\\nsi.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\cryptsp.dll"],["c:\\windows\\system32\\rsaenh.dll"],["c:\\windows\\system32\\rpcrtremote.dll"],["c:\\windows\\system32\\wbem\\wbemsvc.dll"],["c:\\windows\\system32\\wbem\\fastprox.dll"],["c:\\windows\\system32\\ntdsapi.dll"]]}}},{"rowId":"8d08a4fc-d3f6-4b4b-b168-98f0b7d541ea","rowData":{"threatLevel":0,"values":[1528,"C:\\Windows\\system32\\vssvc.exe","C:\\Windows\\system32\\vssvc.exe",[],"services.exe"],"information":{"values":["SYSTEM","Microsoft Corporation","SYSTEM","Microsoft® Volume Shadow Copy Service","","6.1.7600.16385 (win7_rtm.090713-1255)"],"modules":[["c:\\windows\\system32\\vssvc.exe"],["c:\\systemroot\\system32\\ntdll.dll"],["c:\\windows\\system32\\kernel32.dll"],["c:\\windows\\system32\\kernelbase.dll"],["c:\\windows\\system32\\advapi32.dll"],["c:\\windows\\system32\\msvcrt.dll"],["c:\\windows\\system32\\sechost.dll"],["c:\\windows\\system32\\rpcrt4.dll"],["c:\\windows\\system32\\user32.dll"],["c:\\windows\\system32\\gdi32.dll"],["c:\\windows\\system32\\lpk.dll"],["c:\\windows\\system32\\usp10.dll"],["c:\\windows\\system32\\atl.dll"],["c:\\windows\\system32\\ole32.dll"],["c:\\windows\\system32\\shlwapi.dll"],["c:\\windows\\system32\\oleaut32.dll"],["c:\\windows\\system32\\vssapi.dll"],["c:\\windows\\system32\\vsstrace.dll"],["c:\\windows\\system32\\netapi32.dll"],["c:\\windows\\system32\\netutils.dll"],["c:\\windows\\system32\\srvcli.dll"],["c:\\windows\\system32\\wkscli.dll"],["c:\\windows\\system32\\samcli.dll"],["c:\\windows\\system32\\clusapi.dll"],["c:\\windows\\system32\\cryptdll.dll"],["c:\\windows\\system32\\xolehlp.dll"],["c:\\windows\\system32\\version.dll"],["c:\\windows\\system32\\resutils.dll"],["c:\\windows\\system32\\setupapi.dll"],["c:\\windows\\system32\\cfgmgr32.dll"],["c:\\windows\\system32\\devobj.dll"],["c:\\windows\\system32\\authz.dll"],["c:\\windows\\system32\\virtdisk.dll"],["c:\\windows\\system32\\fltlib.dll"],["c:\\windows\\system32\\imm32.dll"],["c:\\windows\\system32\\msctf.dll"],["c:\\windows\\system32\\cryptbase.dll"],["c:\\windows\\system32\\cryptsp.dll"],["c:\\windows\\system32\\rsaenh.dll"],["c:\\windows\\system32\\rpcrtremote.dll"],["c:\\windows\\system32\\clbcatq.dll"],["c:\\windows\\system32\\vss_ps.dll"],["c:\\windows\\system32\\samlib.dll"],["c:\\windows\\system32\\es.dll"],["c:\\windows\\system32\\propsys.dll"],["c:\\windows\\system32\\catsrvut.dll"],["c:\\windows\\system32\\mfcsubs.dll"]]}}}]},"registryActivity":{"stats":[{"name":"Total events","value":"425"},{"name":"Read events","value":"397"},{"name":"Write events","value":"28"},{"name":"Delete events","value":"0"}],"modificationEvents":[{"pid":"(648) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"znq","value":"B17408F62A0A950E3119F81A3AB37031542F3530FFE2B096584F6BDF966D9462"},{"pid":"(648) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"X7Rn","value":"34CA0E6E26AAFBE01BD82C574C84ECBA1B347898A37E5448894B45A44CA9CA6B"},{"pid":"(648) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"ezjIT","value":"D19737BD6090825163F7408837DC66C4A3A4D72C28C7C27DFEED2BB9835F968931139EFC46A03596CB079DA78CCB63B0C3F50928900E79DD8EAAEE2168DC3582EDB4387DF4F986F5A9736626079A77EE0ECE61ED2F0073CD"},{"pid":"(648) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"FfSEAQ","value":"01EF6C44CA13226E0B72E5CBC2AE78E07910BD50FB9A54F58ADFAFABCC84BC174B9215C5426CFC730D78FD5DD283C30A12272E0F91C5BF2EF4BF3F9A826E54B377B97B1DD5C52821483841A6E0296C4AEC99F2D84C055123"},{"pid":"(648) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"U8ngBWt","value":".r3s0v3lg"},{"pid":"(648) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"vMUQJe1x","value":"971C723E29C7408BD170651D7608669D693D1868C0C53075E9315FAC42C322892068B23EFC5A9C7EB6510CC60800D8DB70F9588916085717F95D94FF714843C112C77767858AD94DCD690F522F7C7A65F03548F8E80F00B698E68200B56952DF1108FDF34B4FBEDB4E1BA0CDECE63D5DD9A53DB365D374F69A65E4C2C5CE78A023A3E5596AA03CDD8C1AF65AFAA8A709585A401C474E6327000FC87003D53A0D91EF96CAF532CDB4C2820083250CCAB7CDB3ABD8965556033822189C52DF9B7218181B1F001A54B79C2FE31FE13E67947633F570CB4E5F464DCDB1A64E595394D3FA87BED4EFA9D76FBCD5072D29DB39983EE5C12C505BE98B3D52EFF7D46BF5B2D0D2B1090880F0D8A7FCFD1FC9B631B5E4A9368D7CC42C098390089B221150AFAE820E71B1F9B332FB5E183E35BC5B451E08A9FACF2556F4547B58CCE2FA92EE19D3A5CC8EE987E0A2FBF16E5A056D76B20CD6BE75CFD7B1EB6120D242B626FC348DAE5CE0466B64F73977BD6AB08430D6A99AD487E8AD0D1F62070242E6E8960588DA710B127ACDA163A70E79EDE570E2E1C25D854991209AA8D6829C047748E1E5326740E4A7C08BEB251B9E4A514C2F8D0567B0BF0996C8D1C9FBB4AED91863B1BA2077D811407CBE281F5891787495B7B273CC98E042D9A115F1F7112D3D05243357EDD97ACA2EC44C26DFEE73C16D425F8C0BF47069E7B04236D72986DB2A2B49DBD6BEC79A842880AD831C01C18C925BC033683C62C1DEEC990F0D4FC4CDAED6DAA35118812E60F56ED3344123E29E9F9C3F224947D496C9BD387BE7AA4773A6972768697D4DEF45BBE224CE743F54465F87E0C6760E111D4BFC52A1B48FAD242573E20DA13BB9D09C17D5F15FE4AC04A32843BF407A93E8821F535FCDE21AB4977D904815D54A7F9CC4D5BC73E57DDC52590399630CD6D092B4BC71091EA8D629D8BE1EB45EF1E486AE907C19C2E1F170C84F659B4A9BABD636203C9B5A7A223726A0B730BA366EE9AD074E188BF2F9BE5381B1428E67D084EFD0C890F4816E12D8C97A5686EF8D0F8680CA4D2E51D2A8061A7D349E8CEA408F98E491A58CA01E270E7262D2903514C360E6DC310EF3E8517DCA28B8FB699AE735B845C19417A65C24D956ECDBF0F196492F3148CF4278DAF9A08758318A5AB72FA7DFD827D723C2D8BAE4C86A3C0ED3E976783AC711A70AF41C2C3078B2B5E390EECF675D7C36F21D7B0A4B50C99AE8D1161BE88FDB6188359796FE79D076EABEB6BC6C2EDB3CBB4AA248B0E105DCB8B985AEB4B1FEB46E7741D9FCE6C78ABF5A5CD25342B2F6FB455ACBE5B6B0E6A44973A02623526C0B86A50E69F325C0B3526000A0DE4B33202AF108B0B67220213079A508DF880679D340"},{"pid":"(648) rundll32.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap","name":"UNCAsIntranet","value":"0"},{"pid":"(648) rundll32.exe","operation":"write","key":"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap","name":"AutoDetect","value":"1"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"znq","value":"B17408F62A0A950E3119F81A3AB37031542F3530FFE2B096584F6BDF966D9462"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"X7Rn","value":"1A529104AE0AA31882A577003815651E455ED557C2C41DF052B00BEA709EC70A"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"ezjIT","value":"3E5D352E0663DDBFE57D58C96FE3AFFF51D4A9DEAAE6BB7A7636BABF57E390F874CDB343C8D274EBC6C7486D55BE1DE05A45AD2E1ACD9EE0174CF97426EC494ED2DC015FC615EC2E708EBCB4089998526C27B9ACF4820ADA"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"FfSEAQ","value":"53D103B6D656DE92592792E552D797909ABB4575689D26CCD7994647A7DCADAE790517243C562829B439E861E6BD550FD115A7266435A2E5E70B8CF80A4BE538C18E1474067067D08C715016F0AD09B481130DD73F86DBC6"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"U8ngBWt","value":".g1p3okhzl"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\BlackLivesMatter","name":"vMUQJe1x","value":"A508E39AD2991539DB1B195CCC20AEEB68922D0195F4C2165693AD6A9A56A469D0100EAC131A4D175FEE4B1780259506450BC6379D4FD8E84B27CFA46A3A7C38FE4894D108226D063D8EBC34D87E6491B0FE3E49E28BC2A5446204F7C9415DAD5811A4E65573398F3C5880802420B8F624E1819ADB9430C94321887B941FB8D39F7DEF2B85F657C8BFC40455EC3E556ADFC753CC5F362C7023D225D2F84DF95F3B8C0C70AD68E02F02B89C94F73D519E944D5BBFFA49F1AF8E5CF4FCBBBDD462E88941DADDEB1EF19EE240645B46FEABD70AEAC4075DE970B8A517B63537C7F61417DCBC38ECEAB1A9A384249553C9219E5ABDD633458E8AD2C6E9309C86D425863351E3DC08F2B981663726ACB1E5B8751F1539BD7795E794F4ACC9E0AC2E45A13CCF8039D8DC7CB2C0377A723E7A0E8E70F86EC1DB9E4BCC760A986C02EDAC5C5878305AC25ED53766026E9622E47CC79BBE20BEB5F63CBF51F20A2536EC6FA1E185BA990ACE36C3909AA3BC95100B31D36B9B014FA37B0BFB451942B6FDA54838023A125B20DB80E0B35E841ADB380ED8B051CB5A9403B5115DEAC1D544772A0D6220C883A3E9047854BC1132737F4183B673280E984CB92D6193656EE3F06D7ED1DC2FC0139FF9AD92FBD795BA04D9235FB4687B82A86525DB1869775F33CDA6E34F15851F4D34ABFAEEE27FCC01F2CD666A1802A8ED87D775EF62BB6C4380E49CB451E3AD50AEFA7E075D6436AC2C8F76B75ED76A5DC99598B1AE36CBC0F435031246B563BC0B9F7577CFBC040CC296543575F8DD306BC3A1EE03133B054C0F36CEA89E2CF8568C76AA2E90B86E2F53B05CE75A393664041F3302ED4C00317F84CC06DD64424E29A5DD49F1DA38D620F96BFD6D169647897FE8D422530FFCE3F67DC6A825D71CAE4C80EB202243CFC5B8F821AF67273598A88FE73A5500C8A14EB29D3565CBC68CDAE3C46505E528C4890EF89DD22EA8A44FB4D8D84001A47DA3D01915FAF18B835DF98CCDCCE75796EB31EC23E48A607C21EEFD4A8C56679368D12F3A8CD063A933D6F2B6BC5C8929C23C0C8AF915E0E64DEFEFBFD76BC654EED4A84B66684F38E1F91C956195662FCA5FBDBA90709CB9F31D03B953EE527FDB43B12E07C373B6E866F40355F6DD96D566E0AD33E8AC432FD292BD6EE279442FC06233880D8FBFB3F6A89C0F2B7CB79C3D79A8E6B21E12E11617ACFAAAB907F2857AFEB91F7913E934E8B46B3A1265CE6D8806D7B065BA5B0CBAD3AFA70B4FC91EB9D628FB107572D170CD05964A091D05F4FB322F32BB2114361B46D9646012240F8BE15A6FA12746535E53F833ECACC876E9FD13C9996642B32CBC19A9339644E83DA665A7C090447736D1E61ABE2DC9DF692238018A"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_CLASSES_ROOT\\Local Settings\\MuiCache\\13D\\52C64B7E","name":"LanguageList","value":"en-US"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8","name":"Blob","value":"0400000001000000100000000CD2F9E0DA1773E9ED864DA5E370E74E0F00000001000000200000003F0411EDE9C4477057D57E57883B1F205B20CDC0F3263129B1EE0269A2678F63030000000100000014000000CABD2A79A1076A31F21D253635CB039D4329A5E809000000010000000C000000300A06082B060105050703011D000000010000001000000073B6876195F5D18E048510422AEF04E314000000010000001400000079B459E67BB6E5E40173800888C81A58F6E99B6E0B000000010000001A0000004900530052004700200052006F006F007400200058003100000062000000010000002000000096BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C61900000001000000100000002FE1F70BB05D7C92335BC5E05B984DA620000000010000006F0500003082056B30820353A0030201020211008210CFB0D240E3594463E0BB63828B00300D06092A864886F70D01010B0500304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F74205831301E170D3135303630343131303433385A170D3335303630343131303433385A304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F7420583130820222300D06092A864886F70D01010105000382020F003082020A0282020100ADE82473F41437F39B9E2B57281C87BEDCB7DF38908C6E3CE657A078F775C2A2FEF56A6EF6004F28DBDE68866C4493B6B163FD14126BBF1FD2EA319B217ED1333CBA48F5DD79DFB3B8FF12F1219A4BC18A8671694A66666C8F7E3C70BFAD292206F3E4C0E680AEE24B8FB7997E94039FD347977C99482353E838AE4F0A6F832ED149578C8074B6DA2FD0388D7B0370211B75F2303CFA8FAEDDDA63ABEB164FC28E114B7ECF0BE8FFB5772EF4B27B4AE04C12250C708D0329A0E15324EC13D9EE19BF10B34A8C3F89A36151DEAC870794F46371EC2EE26F5B9881E1895C34796C76EF3B906279E6DBA49A2F26C5D010E10EDED9108E16FBB7F7A8F7C7E50207988F360895E7E237960D36759EFB0E72B11D9BBC03F94905D881DD05B42AD641E9AC0176950A0FD8DFD5BD121F352F28176CD298C1A80964776E4737BACEAC595E689D7F72D689C50641293E593EDD26F524C911A75AA34C401F46A199B5A73A516E863B9E7D72A712057859ED3E5178150B038F8DD02F05B23E7B4A1C4B730512FCC6EAE050137C439374B3CA74E78E1F0108D030D45B7136B407BAC130305C48B7823B98A67D608AA2A32982CCBABD83041BA2830341A1D605F11BC2B6F0A87C863B46A8482A88DC769A76BF1F6AA53D198FEB38F364DEC82B0D0A28FFF7DBE21542D422D0275DE179FE18E77088AD4EE6D98B3AC6DD27516EFFBC64F533434F0203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E0416041479B459E67BB6E5E40173800888C81A58F6E99B6E300D06092A864886F70D01010B05000382020100551F58A9BCB2A850D00CB1D81A6920272908AC61755C8A6EF882E5692FD5F6564BB9B8731059D321977EE74C71FBB2D260AD39A80BEA17215685F1500E59EBCEE059E9BAC915EF869D8F8480F6E4E99190DC179B621B45F06695D27C6FC2EA3BEF1FCFCBD6AE27F1A9B0C8AEFD7D7E9AFA2204EBFFD97FEA912B22B1170E8FF28A345B58D8FC01C954B9B826CC8A8833894C2D843C82DFEE965705BA2CBBF7C4B7C74E3B82BE31C822737392D1C280A43939103323824C3C9F86B255981DBE29868C229B9EE26B3B573A82704DDC09C789CB0A074D6CE85D8EC9EFCEABC7BBB52B4E45D64AD026CCE572CA086AA595E315A1F7A4EDC92C5FA5FBFFAC28022EBED77BBBE3717B9016D3075E46537C3707428CD3C4969CD599B52AE0951A8048AE4C3907CECC47A452952BBAB8FBADD233537DE51D4D6DD5A1B1C7426FE64027355CA328B7078DE78D3390E7239FFB509C796C46D5B415B3966E7E9B0C963AB8522D3FD65BE1FB08C284FE24A8A389DAAC6AE1182AB1A843615BD31FDC3B8D76F22DE88D75DF17336C3D53FB7BCB415FFFDCA2D06138E196B8AC5D8B37D775D533C09911AE9D41C1727584BE0241425F67244894D19B27BE073FB9B84F817451E17AB7ED9D23E2BEE0D52804133C31039EDD7A6C8FC60718C67FDE478E3F289E0406CFA5543477BDEC899BE91743DF5BDB5FFE8E1E57A2CD409D7E6222DADE1827"},{"pid":"(4024) rundll32.exe","operation":"write","key":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","name":"Blob","value":"040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131D00000001000000100000004558D512EECB27464920897DE7B66053140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589100B000000010000001E000000440053005400200052006F006F00740020004300410020005800330000006200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD6770739090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C1900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510"}]},"filesActivity":{"stats":[{"name":"Executable files","value":"0"},{"name":"Suspicious files","value":"1 902"},{"name":"Text files","value":"7"},{"name":"Unknown types","value":"28"}],"droppedFiles":[{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\adobe\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\recovery\\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\adobe\\arm\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft help\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\skype\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\program files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\mozilla\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\oracle\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\svpost\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\recovery\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\adobe\\setup\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\assistance\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\media player\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\devicesync\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\crypto\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\network\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\drm\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ime14\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\event viewer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ehome\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\netframework\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\mf\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\identitycrl\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\user account pictures\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\vault\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\office\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\rac\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\officesoftwareprotectionplatform\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\search\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\Hx.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\Hx_1033_MKWD_K.HxW","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\Hx_1033_MKWD_NamedURL.HxW","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\Hx_1033_MTOC_Hx.HxH","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\Hx_1033_MValidator.HxD","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\Hx_1033_MValidator.Lck","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\Hx_1033_MKWD_NamedURL.HxW.g1p3okhzl","md5":"461D4F2E0108082ED51860994750B2C0","sha256":"FB7FA61F501A8907085147438632575E42C8F57CC79A73AEC7AEACE0D256A6B4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1031.hxn.g1p3okhzl","md5":"266ED57F9BCA17BD3E7334C9285C8DFB","sha256":"1F2CE5F092185E36724F436D22589EFE320A8352F81B0FCE953E347074298D31","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\Hx_1033_MTOC_Hx.HxH.g1p3okhzl","md5":"178FA52FB4B246F37BB35AF9FF56673E","sha256":"4E71A02588709F102FA7C36D51EFF89334665A4BB04BD4BAD84A54A1B4224FCF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\Hx.hxn.g1p3okhzl","md5":"87EB700B4343A5E9BA390DCE7DC24427","sha256":"24219F335589A1D9C15A4698A417E24AC1350B999137779ECFD9308832A99F66","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\Hx_1033_MValidator.Lck.g1p3okhzl","md5":"E31FE90F45CE746C72943F35B5F04EDF","sha256":"4859070E1DC3A19619FE27D157AC9D68BE8091E293F0C09B307F0DB9398A417A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1033.hxn.g1p3okhzl","md5":"513D8770F5D30B0D1AB7C150E6E8963B","sha256":"A83D36733C32FCBA36455A9ED546F8A6F3C58A1E94FF0517580CC92A8133BF75","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\wwansvc\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\Hx_1033_MValidator.HxD.g1p3okhzl","md5":"5CB015324FB9B9755C0CDBD04541AB84","sha256":"DF0ABBB979B030E85E996832DED896D6CB482674E24A28C22767EA2CB030F57D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\Hx_1033_MKWD_K.HxW.g1p3okhzl","md5":"50F00D25D7FC23DAD364D5F36B696C98","sha256":"C12F8FCE1EDC5C012ABB4CFF8E3F0111017B6ECC24764F05D203B1AA6A19085B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1036.hxn.g1p3okhzl","md5":"4D64BBCA80532B1D4F51F491A1ABDB4F","sha256":"C334647EBF638306F36B42256175143CE61CF39D8CCD69AA3A70E5A1F9E99C38","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1040.hxn.g1p3okhzl","md5":"B1FB97D0DD857FEF1BF0B019E33B8E07","sha256":"9E4F161E60D5BF52C002D852D6D7018F4514EF33171FE7BFA3E4B39B7AA9D21E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.DEV.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.DEV.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.DEV.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.DEV.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.DEV.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.DEV.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1055.hxn.g1p3okhzl","md5":"4A142D06BC43FEB1FAB5E5BDBA62467E","sha256":"8B6951067522C2A824A76C285CDA3AD7163AA168E054876493E36871D8C1A060","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1042.hxn.g1p3okhzl","md5":"7C30EE78E992B3BB879FD062401A7ECE","sha256":"EE97E9312A6D62AF8D5798FB634A25A7451B5D3555A32E7607E6843919ED395B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1049.hxn.g1p3okhzl","md5":"C39C3FDD831846EC9E510C3E1E9A59B5","sha256":"BFE7C665FF32C3278F38A4DA9EA66006046FC61547BD20828C8F6CB20971A593","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1046.hxn.g1p3okhzl","md5":"1D8F2AA3DF4875A1F27135133C622B6D","sha256":"AAB2173BA47C7D547F28A9216DC95F2BCBC675CC6AE99B3DED8D878FE714C3F5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.3082.hxn.g1p3okhzl","md5":"1345E2A45758078D6331A746DC073B35","sha256":"513129496CC7E6E0FAC3CF57EA1505601514E2C4FD5F3F2B79E93846ADD46CBE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.14.1041.hxn.g1p3okhzl","md5":"A33C6D686C6EAF684C91E1866A8464E8","sha256":"ED9F1C1AA4F2F3AAFF978AD1376B2E0CC0669529FFCD39DB5677E262A1A01F7A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1033.hxn.g1p3okhzl","md5":"4E0F526F900BBDA9893E2AFDF6862075","sha256":"3D2D5D737C8BBD92F150FCB45EF33F85556746F6D9B18B043143953A376357F7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1049.hxn.g1p3okhzl","md5":"2008D0B4AA9FA5B2A40C1D52185F8A1C","sha256":"EBF20A1789A7261FDC0750923C57ED1C8F5B368EDA4163B22EA64387A84981B8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1041.hxn.g1p3okhzl","md5":"FD2710201AABBFB720106D2A24C32C8A","sha256":"EE4D3332C8BF81C29C458C7146A8BA459AE148C683331D5FF2369AFD47071C70","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1046.hxn.g1p3okhzl","md5":"A4E13B89AB0351D179ED4F1058417ECE","sha256":"3834F9B40FB15A1C722904BDC2C05789B30D49E28687CD762E7DBA200E251EEE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.EXCEL.DEV.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1031.hxn.g1p3okhzl","md5":"A475B1BF686114377AC64CCCC17F7787","sha256":"B1F0DC8B4BEC7C6F7B673C78AE143697773B632A8FB701712A63BC78AD16EFB2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1036.hxn.g1p3okhzl","md5":"E8D5C964E914F434BA2AA585EC075167","sha256":"48BB64C9135F64B124345373304CDD89917D53139B42EF6A00F2FE34A3F70292","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1040.hxn.g1p3okhzl","md5":"A8FA749EC7B5514399D60EB35D679AF4","sha256":"7A04724245094B9A8044F415C06730AD681A0541521285881E20687445252B2B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1042.hxn.g1p3okhzl","md5":"3215B0DC82B2C6BC6AF1390AEE8D8C50","sha256":"A39A1FE8DA02A228CD9CED14781D156AF78358F4E556FDE22508370A26F33D7E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1033.hxn.g1p3okhzl","md5":"C61BFD09820DFFE7BD6D877EEB2605CB","sha256":"564D3071B511143FA243163CB476419BA29FC9168F8A0569C947FE0C90B02CE4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1036.hxn.g1p3okhzl","md5":"FC2D5F8DBCA1D621439AD862E19B4371","sha256":"402E250DE7E0FE5B35814F0FBF406681425E05E17A2908903E35A020B0267193","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1031.hxn.g1p3okhzl","md5":"434E16F8DC7F057A9BDC0CAFE9087161","sha256":"38A0676233D67DD84DE9632CFFAB5D5231F4EB3A6FA403F1A32AD4DA1DA62E65","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.3082.hxn.g1p3okhzl","md5":"481A6AEA04AB8ED1DF187FDC84188BA7","sha256":"309D189DB41FF55E24EA10024B79C2973AE7CCDE6691ED5BACFAED6B60801082","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1040.hxn.g1p3okhzl","md5":"5195B51DCEA3591CE65465D6F319E3AB","sha256":"98DBAF0AE1AACC3F31205C8E3AE9321D33A832818B2B2990C13A8D1F284C0010","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.EXCEL.DEV.14.1055.hxn.g1p3okhzl","md5":"EA6D5FB173F6477D3474C5E778952EDA","sha256":"705EE6E234EB98547A88508DE326CB76F9A134F3267DC8514DF5DB9719E70FD3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1041.hxn.g1p3okhzl","md5":"F5772DB3C31779C7045DEE42F4DDF3C7","sha256":"CAD16482A94CD06203465E325DEEA64135D0ADEAEF04698B3364310FE8D394CD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GRAPH.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GROOVE.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GROOVE.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GROOVE.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GROOVE.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GROOVE.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GROOVE.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GROOVE.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.GROOVE.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1042.hxn.g1p3okhzl","md5":"167345A8823F000DCC1E2467AF26ED17","sha256":"27470F79959E8959A05139B00BB6D36AD9AA8B51BA576A32B19AD4F4B1F48467","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1046.hxn.g1p3okhzl","md5":"CA3129EAA3DF853A7FE85C14A21C4134","sha256":"D5B4E64EB5E121F6C32B2FBC2DF87FBD1AF406A19FD8A1B91EDA096A5EE596F6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.3082.hxn.g1p3okhzl","md5":"33146395BBC97C6E2338495C9B84B5A8","sha256":"5882C230B1A6F027DF2B88F36FFAA7EC2976FE8F4056EA04A2FBDCD4321E9042","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1049.hxn.g1p3okhzl","md5":"2553DEEED539C841866F983F607393D6","sha256":"9C8D06A7FD3B828F901F45AC37A7863379D1795FC556AAC28182615EAD50D480","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GRAPH.14.1055.hxn.g1p3okhzl","md5":"3C579FCEBB83226507639DC629CC6A6C","sha256":"FFE7152E982CDB66B9CCB4D9EF05BDB23E785AF25291AA071AED615E13231D2E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.1031.hxn.g1p3okhzl","md5":"7A13E3CF198BEC70E213C19E6A6F4530","sha256":"48B7CA1BD669F6E646BD7EE2810A13EE8577B611F6A82398ABB20D1EF988DE3A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.1040.hxn.g1p3okhzl","md5":"46E5CFF192C3D3536830B54E4344DFB0","sha256":"FC314909D64A18FF66406111D32C420C4C733A6FB2D22406DFD238CD5F4D17FC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.1041.hxn.g1p3okhzl","md5":"BFC285C42022B0E859DC23D01E9F4567","sha256":"F4B38FB607E12CC67F38EF5A572CA45C2DA366A4FFD67278EF7659510D1260A9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.1036.hxn.g1p3okhzl","md5":"82EE8270F87C3B654B0C3062CBBDA316","sha256":"DF85FF652DC6EC18FB3BA014881FC8AC1433B79DE2A373A05931BDD63F93D448","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.1042.hxn.g1p3okhzl","md5":"14CA8DFAAC8E73DBC0C1245CD3E73F81","sha256":"DA448E5E1B0A3D90093F4D2A7996A61D021BD7DFF5BDA065F8E99B5820EA5738","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.1046.hxn.g1p3okhzl","md5":"EF0E36DB81768DA7FC91EC125EF0640F","sha256":"4434D279806B6DCC919BB9976591639293AEBF936885504EB51F6F5D4AF60B4B","type":{"value":"bs","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.1049.hxn.g1p3okhzl","md5":"9997A80CCF4273C888596FE1E0A303C1","sha256":"9C53684A458FC4B39E7CAD01FB4DF72D6B1EF707EA654CF3DAC37CB9257576D8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.1055.hxn.g1p3okhzl","md5":"8061CDCA22C6B0D8A6889D23A9520950","sha256":"EEB3D49D9CA2CDCB07AE1F6C72CE3DAF116A55E25E18F37942D4F427D948B560","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATH.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.GROOVE.14.3082.hxn.g1p3okhzl","md5":"EA1C9CDB2AE5D7C0A28A2A4960C6D441","sha256":"0C3380B201270CF1EA164E6B2238FA2AECC1A1896B758ACC08E4CB6FD7D97A48","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.1031.hxn.g1p3okhzl","md5":"F2FD5E93A238A21542613A7FCF751430","sha256":"A1C9B9C336FD16D8F4A703EEC651A5BDC88144DDEA0995FEBD6CF215F98D1675","type":{"value":"flc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.1040.hxn.g1p3okhzl","md5":"B640E6877B8D1399D31E020EC5CE9F94","sha256":"2B7341110E6CC3284FBD2093E79FA59E8DE0C2720D93CCCCCAFB53A18D94ADED","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.1046.hxn.g1p3okhzl","md5":"D6DA7E3F8D21588F44E15662810A0662","sha256":"58B69B95862C7392EEEB60A1299D7DBA2362D01A4477E689316C711A113A7DEB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.1036.hxn.g1p3okhzl","md5":"BC1A72F8D79A61BCE268D83B01238F3E","sha256":"66FCC3D94FC0E8E5FF95BC6862CD137F5B4B102C994F6DD54773B4079B6BD829","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.1042.hxn.g1p3okhzl","md5":"5C35DFF595FA35527B1E7A93AE02EBEA","sha256":"4ADF07B536D21DC685CA1F627FD0FE4DE3A3ADCC1CDD3B22B5C93A7C4C18031E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.1041.hxn.g1p3okhzl","md5":"3A0A7048BA8FBB25A5580DD34DC215F7","sha256":"191ED3986DF9D2408C6E1EFAFF88A72FF05853CA1F37CC59A2B1068240CA4FFC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.3082.hxn.g1p3okhzl","md5":"135CB5899A2276F6D17E6722950B17B3","sha256":"D0E78FAEB1D719FA452E1415CC7E1750CEBB88600C40B7F4F2FCF36542A29F28","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.1055.hxn.g1p3okhzl","md5":"6B0EB9FEA4B72740ED9F157C18850E0E","sha256":"8CE8A4CC43728062DEE9BB8840D6B173CE0EC46A46FE74FDA21C64A583E58E1D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATH.14.1049.hxn.g1p3okhzl","md5":"313C048EE3FD66F6F3A724C72AC5A8B2","sha256":"354B7C0AEF2C0F9FFB08CFFC5C7B7A4325E0F0C4015725878EEA6A57A8C4301B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.1031.hxn.g1p3okhzl","md5":"7FC63CB9AFD01EA8E3BF985CF8C6B281","sha256":"173FAEC850F42F3BA363C3E79561BF3E9488356D659107F7C20F7F89D0FB3332","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.INFOPATHEDITOR.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSACCESS.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSACCESS.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSACCESS.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.1040.hxn.g1p3okhzl","md5":"F40F3F2D72DF33507CEA2B116DAF6DA6","sha256":"841442FF8B74E492E4E902974F754DA30385DBA56E14D9B2C40E19E2E30B1A62","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.1041.hxn.g1p3okhzl","md5":"100419E42FA5CA54A1A71D4D95968EDA","sha256":"86AF1D7AF84D8AC2160B438818CEF507E346595A1209D874327BD9FD2D1D4BBF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.1036.hxn.g1p3okhzl","md5":"30EEEFDB26772168D4569ED97185F176","sha256":"EEF252AE2FBD770FFA3457A56A9F37E55B86AE512DF76391D0E9E01BDECD4199","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.1042.hxn.g1p3okhzl","md5":"FBE4472380393952B613C52F17662356","sha256":"3E37ECF0C6EE9808480488AB92ED77A5F99771F4A78456F5F15AAE20068D0A32","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.1046.hxn.g1p3okhzl","md5":"FB13504B98E38BE98C483CB812374D80","sha256":"B4EEFD2A89D63EF4F976A6587E8100BF1B591E7F424C5937112CC52818FDE6E7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.1055.hxn.g1p3okhzl","md5":"5E877BF0B65D01FE8AE5A7109D6259BC","sha256":"E1E96193E0979356CCD00A1DC8351A2606A09B58B0A10D78FF213D9FD507047E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1036.hxn.g1p3okhzl","md5":"29DAB794295E062DFE95A8DB543CB4F8","sha256":"9603C48EAA40765ECD2B3EC3DA0C2C0F54E49A55E8968D95B7AF2246206637F5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.3082.hxn.g1p3okhzl","md5":"47860BB17F8C4281A7D44E90B1A0F20F","sha256":"E33DA963B983620EB9354C1ACECD347A91D4D26D559179123B1ACD61FF190C09","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1046.hxn.g1p3okhzl","md5":"C46433F4D5B8CB124FA31BE0E500C92B","sha256":"DD3E54BF1F91E22E77FE8E886C969C228161AF1FE5C140EE3AB4DE17EDD057FB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.INFOPATHEDITOR.14.1049.hxn.g1p3okhzl","md5":"2EEA2C08320931C3C4417ACFE8781EE3","sha256":"9F900A43582B316B94EE90B4EEA36198868239455F921FA0B3BE4E2AAF730D67","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1033.hxn.g1p3okhzl","md5":"C27489733EAAFBA1800E5210A4A631AD","sha256":"1F9E8A3BCC7797407F1556C07B0CBFD6BA8C8B599968FDBE7B22A0484B1F3842","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSACCESS.DEV.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSACCESS.DEV.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSACCESS.DEV.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1041.hxn.g1p3okhzl","md5":"8613D7535290EA8BDDDDAE83C1A6CFB5","sha256":"8C4025CA09829CE3AFF1878790B0798F67D13E77A0220E6A52013F4C03E2AF95","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1042.hxn.g1p3okhzl","md5":"065FCA3C271B89F3A969C60EEB654265","sha256":"10DDD30EBAA40297455287759CFBF31CDB8C310178664FBDBE16FCB476882BB9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1031.hxn.g1p3okhzl","md5":"F2E3DD2479A0699DAEF4005A6A00D202","sha256":"AA769867463CA1C4EB14AEB863674BAE019EBE5FCA8B859C6CC09F691EFBC22A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1040.hxn.g1p3okhzl","md5":"CE29F3620819AC039826D52562DF7465","sha256":"5B44A80B2D81C45389DBFA7E7BF821EB3E0B2D7B340B0AA765AF42D2E61DD1E5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1049.hxn.g1p3okhzl","md5":"F0F54BFB9C0DB70B5F217766F3A489EE","sha256":"49CBF3727A6F9532C036947B77A162B9F82B8C7B1DB7E37D48E5C37AB38C2794","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSACCESS.DEV.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSACCESS.DEV.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSOUC.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.3082.hxn.g1p3okhzl","md5":"DE341D9195F038637D9C51C9A9316902","sha256":"5201D8D2FCE3F3BFB9D86427B1E8515EC0BE5A1771D4ADCDF0FE9CE96889D64D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1033.hxn.g1p3okhzl","md5":"03B3E70176B7D186BA0A5CD764B0F1F8","sha256":"9A0BCA6776305468131673DF256BC502AEFEAD554E3762850DE00152ED96356B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.14.1055.hxn.g1p3okhzl","md5":"281FE37A49C2E04BBA1523403F611E2B","sha256":"8F2CCC15E0E651A455506C0558F5FC3DF7290BC4205F6027B4D140946CC949CF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1041.hxn.g1p3okhzl","md5":"136A5ACA5706F36651F6335264269ED4","sha256":"F166B21E2994074B0C8D4278D81011846CF566C0125924E2FD96696586E818E1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1031.hxn.g1p3okhzl","md5":"220C9DEA3876C38CFD2AA49BCC2718B9","sha256":"2D2CC0BC9B8441C0E463FD69949648632960D696C578264509C9D9C41804A3AB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1040.hxn.g1p3okhzl","md5":"69B393AB9F123B844CB1F86C75971C2E","sha256":"281E8539CDD299C8D23936935F9B86213C8E321D0026679A4C7CA26301675484","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1036.hxn.g1p3okhzl","md5":"EC9EDE104586DDD4BF6BEEA2E526139B","sha256":"CEDBF2F71EB4169DFA69DA7F90BD4BD19982B1AB828DD5160EBE9BB35A0F9438","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1042.hxn.g1p3okhzl","md5":"2D335226D1146B45A7C2807266C4037A","sha256":"7885C957886E3818852A02F3041BDD654C1E36C9977DF21EF3A380AD91092591","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1046.hxn.g1p3okhzl","md5":"F2038ED884CBFD3A3C2B31963C6BF831","sha256":"BFC1D60F83638681C67BCAED03F222383A799C437A81FBAA19207B025F4F278D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSOUC.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1055.hxn.g1p3okhzl","md5":"EE6BFD18F5669E3FC238B63F3994973B","sha256":"B83B85BD17899AFF0FA6999C78A3E6E62BB6BA217B1A830C950A335884910564","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.3082.hxn.g1p3okhzl","md5":"15C986BEA42286E49B64B8883A6A0F8C","sha256":"64CFF3EE1A66DB639F8C48109A8BEEE4A1796FCD92B189D7F15173FBE4222446","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1031.hxn.g1p3okhzl","md5":"B4102C304795C3F98DE22F0072BA2E6C","sha256":"5FFFE46AC56D7854BEF9A23CD2EC6CD99A52ABCD9D6E3BD4F0FB86D707DA3820","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1036.hxn.g1p3okhzl","md5":"5890311271A7C7590D052FBFD86B8028","sha256":"5C60E36B16F7911FECD811AC8AE317F07D91E44B1B6F0EB97E1CBE934C14AD4D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1033.hxn.g1p3okhzl","md5":"4DBF7C3B773493EE2A6406719C6D9912","sha256":"F03A87B47C4B568F3CC9FF8E76B08A7BF9716EE69ACD2E2B283E57356C74C430","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1040.hxn.g1p3okhzl","md5":"662A86CFE6E4461ABDA21D81D8535CCF","sha256":"AF3D1C32B77235FEE71F82ADD25AE6312EEDD242E22C8B28F4DE53FA4DF2D2B9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSACCESS.DEV.14.1049.hxn.g1p3okhzl","md5":"62A17455C2E01B0415BE7EFC6E693E42","sha256":"CB57034B83124477C3EF3CEB3E61CE70616F257C7D5CCFEFDA593BD59F320663","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1041.hxn.g1p3okhzl","md5":"0CC99C38EE7CDC3843D7ADFB422E9353","sha256":"584E72AB59F98930335CCE672ECFC8BE72B15DFC25FDF140D9D7C414EE684B16","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1042.hxn.g1p3okhzl","md5":"CE13660D0316826B15E3D6A07867E452","sha256":"6612393DD7EB5D5B11228EC44EADC366A412B5C15D77A536FC00B36836C39EB4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1049.hxn.g1p3okhzl","md5":"95F58DFAEB4F82044AC174EF59757DC5","sha256":"AE7B5FC36454D50903D22E710EEFD1AC6B7331EFAA0E675B23146A51222C093C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1033.hxn.g1p3okhzl","md5":"F87DAF0AB6C6616336FD243820553B0C","sha256":"4A598ADD54D4833EF3BD393B326119E77629B28E5B8A320ECD77B16E9983A6B3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1046.hxn.g1p3okhzl","md5":"C249CB93CB5C6AE429575C21B27D8693","sha256":"2ED9C0BCAF1353F45EBE316F3C4A7A346EDF246AA504E17AFF6C98A786AAE0BD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.1055.hxn.g1p3okhzl","md5":"2846B4153870CA7CB2CAA793299C999E","sha256":"14454342FA94B110B18A8E5BDA273B21C4579E817F764AF5427E5F85E26B362D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSOUC.14.3082.hxn.g1p3okhzl","md5":"CA7CD6A654CBECED99A7A6EF0DE166B8","sha256":"CCF4C94A72E9FCB4B66BF511D51473035AF089DAA30C85B7244D6B7E70F34F9F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1031.hxn.g1p3okhzl","md5":"EEA6AEC625D8BF2F6E0801403F791BFE","sha256":"3EC41608E3CF8E01C543A8C265510A72AE5BEE10309F4A2F51AA37478A49AB42","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1041.hxn.g1p3okhzl","md5":"7BF2533E91DC2A5D8F5EE5CA61A554BB","sha256":"F65CFC2F294B36601C89618BB37B819789B140532B603DB2F29DB4637D7F92D8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1040.hxn.g1p3okhzl","md5":"2B212B9A605095139952538EC3179330","sha256":"46D12F7515E675753C3368A429EB15823028F53A0775897827FDDB20CB637601","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1042.hxn.g1p3okhzl","md5":"DC1BFC9CEB422010557848C30C8E363C","sha256":"CC881A7EA034A97AACB1B744028AB7F6FED6EB262613922BE94AC9A9239E2A8E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSPUB.DEV.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSPUB.DEV.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1036.hxn.g1p3okhzl","md5":"6B7B49AF4DB5521F8A331CF4CD1AEB39","sha256":"8BD0E3637300208976B33F8C7DB6B10EF6951653340012DD86D67F2275A9F01C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSPUB.DEV.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSPUB.DEV.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSPUB.DEV.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSPUB.DEV.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSTORE.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSTORE.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1046.hxn.g1p3okhzl","md5":"7A139D92021F74D64039CC0C1DDF726C","sha256":"1AB836D1D2AD135CBFCC7935CDFCB086D6BFB11E9100B5B68E021376B2BF4AEA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1055.hxn.g1p3okhzl","md5":"79FD7AC71F3BF0A8196D8ABF74858512","sha256":"BFE23F695A520E9440DE73C03B3FE44F17DAD076B13FEC411C78A69F1B0B2935","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.1049.hxn.g1p3okhzl","md5":"4C6E94FB67B2094A5677F06160B58325","sha256":"8882EC689226C0CA2B0CDAD3500EC16609A3F5FCC6ACBF82EC53C0074DE54938","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1031.hxn.g1p3okhzl","md5":"6EEA41FF808B5C6F8E009435B1948270","sha256":"F8D27F6B263010799E239415082F9517ADE058B5ACD991F7EF4DA3EAA2063A50","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1033.hxn.g1p3okhzl","md5":"D5EA94720F06DEA2586F55D3E3F2F678","sha256":"B9AAC9BFF29342B4BE97ABDA7ADB15BEE007034D3512E0CD5980B7CBEB004DAD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1036.hxn.g1p3okhzl","md5":"FC5C797CCE0A0BED17F70C4C0EDCEF01","sha256":"DFFEC0DCA9EE57F321862DA6CE0A850AC572CD1896A81FC2B65A7F9C062BE1C8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.14.3082.hxn.g1p3okhzl","md5":"EC8E7379E7E6AA2EDC41CEDC08D08EE8","sha256":"5904CD6FC1D49303F91976BA341F45B9A900D626B90180BECDCF6EACED39BB5D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1040.hxn.g1p3okhzl","md5":"3A7AAFF9971624507D998F4AD9E4EB64","sha256":"A4EC5569E79FCBD10FE27D1E82B4380700234CBDBB8E5D2B996CC0CC778621BB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1041.hxn.g1p3okhzl","md5":"5AF585E5DB544D27A0C186658BA47540","sha256":"FE34DF798AFE5263AFAF72775B66F79BA4425A0A5756CB9A244097FD46563B5E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1046.hxn.g1p3okhzl","md5":"CC8209A64CE93D286EF785A8E5A16D97","sha256":"A241D2889C872ADFC7D3223D3FD4BBE08102C0474A61176EEF69D56574D4AEA8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1055.hxn.g1p3okhzl","md5":"871914A06775A457460B06556D82D0A3","sha256":"A9CE71BB80AECCE9B7BFA201682E0C5F7FEBD5D9F5FFFBBE18841681791CD588","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1042.hxn.g1p3okhzl","md5":"A8CA7EF549688C0E001BEADE2287FC51","sha256":"59C948896EAF2D3A86E35EA1D32A88B174F722E5AE0981A6D1254C4E40979FE8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.1049.hxn.g1p3okhzl","md5":"0D0D62DF88DBC675B85CDDABC7CEE1CE","sha256":"B4290C209FADAC2E1FB5FD95212850EE95FF9E5B022B925E3B6AF80651C81842","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSPUB.DEV.14.3082.hxn.g1p3okhzl","md5":"43C97860ED4E31A54974FD303AD60BED","sha256":"49C5D82372D35663FA6B5DB75B953106D1FA5655B05876FC4FB9F9330046B4A9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.MSTORE.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1033.hxn.g1p3okhzl","md5":"EF3590F7E4C46A7861D7C6A9E19D512A","sha256":"502C6E8EEB75B27A98B9594070B84BE6B46F7A40CE65823ABB2C7CE3F33EBE26","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1031.hxn.g1p3okhzl","md5":"CC6E117C04650D10EC6742D3CFE64839","sha256":"B29CD3C55E74282251885452EB1D54DC26CAA796599F0301CE70E9F52188C6D2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1040.hxn.g1p3okhzl","md5":"40CE51EB93C3350A5D7E3866C23AC2B8","sha256":"D06B74497FBFBC89EFD30BCF6497F4B54AC6D76D50561353838E2CC09D17DCF7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1041.hxn.g1p3okhzl","md5":"3F3644CCEF504FDCC6BBF5A1540A916C","sha256":"54FE8B89410B8F935374D9246813E0803D21F194568346FCD47E0A43E0F045B5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1042.hxn.g1p3okhzl","md5":"F6AF8559936546B482FABF9156BD08C3","sha256":"661EEC1280C28C9C266D4870FAB2C6C01749DC2CAAF9C2063E21EB5A281DD2F3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1036.hxn.g1p3okhzl","md5":"6EA5BD60248DF0C7D492BF05999E19F8","sha256":"2C359C6B103C2CC487B1E9F7E8B949C695D597349B0EABB5F05453F0DC8C9D03","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1049.hxn.g1p3okhzl","md5":"8BF09D640C293F07389B85CCADE3F82A","sha256":"27E68468B5FFF4CF0A5ABD1B6CCB67ABF81D7A35BB0D03C56A567C5B762347A1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1046.hxn.g1p3okhzl","md5":"CB4D63B07B0B1255A316986E859CE298","sha256":"821344CC3B9274A7674303750CF20C7FC884D651C72D41568267926C91744187","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OIS.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OIS.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.3082.hxn.g1p3okhzl","md5":"0E963A4216150BA6E05CB8AEC1755F91","sha256":"60B1E0D71DB71AB2650C35C287095D1789CA40709A6A4872D5838F8290944A8D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.MSTORE.14.1055.hxn.g1p3okhzl","md5":"F413CFE993EDE28EE7556A97C41DEFC4","sha256":"4A185B9237FC1520CC7AD6A7BC1ECE25F4930AEE95D5E96DC5825068CB4BCB78","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1031.hxn.g1p3okhzl","md5":"415DCC2F2EBE6E16E946756B346F9AE2","sha256":"55CA854825AED33F2EF174DE6CDFFC409ECDFB8444381BD88AA0CC831B5DBC1B","type":{"value":"gpg","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1033.hxn.g1p3okhzl","md5":"BF9BEFDA7EFD227934919545755AB43D","sha256":"F958CAA321789B14A2A3E487B6D9B203D664A3051F807F89D0FB5A11ACA97E95","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.ONENOTE.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.ONENOTE.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.ONENOTE.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.ONENOTE.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1036.hxn.g1p3okhzl","md5":"3C439788A88F38D2EBD00A2C0C72C171","sha256":"ED049F5A23FEE67B66314AAE321D410115F26BEE02596DD466DD9C6B8A34FA36","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1040.hxn.g1p3okhzl","md5":"D5D5CC7750FF4C85FD3E9DF70564E431","sha256":"E5712B4F8B5C6C02E19D1535E899D9D82C417DF9F6CEFFFF9C5F5DD5DA77A804","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1041.hxn.g1p3okhzl","md5":"8DC7B6E7AC2B9FE9409F370A975517B5","sha256":"DF00A65CBD977B855EB3E42C260C71F1FACD3F240A11C9A5ABAC9630C37FB51B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1042.hxn.g1p3okhzl","md5":"D3C4FBF389E59794769F074F97AEE8F1","sha256":"D64F5CA4399293919AD5F64FCF36CA8AF2EA9EEB7A2EE15875D4AA8EE0B040D9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1046.hxn.g1p3okhzl","md5":"2EFE301AFAE76857000828700C85D3F6","sha256":"B13C199D1A08B2DBAC1D0DDAA9705A580C8A29E3CE703EA8DB2B6B5B80DC7F69","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1055.hxn.g1p3okhzl","md5":"0C5AFC4857C175D76535111FBBB44727","sha256":"FA4050AFA82A6C8BA46F66870A74954C2AC0D99AB1985846E29C169589A752B2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.3082.hxn.g1p3okhzl","md5":"0C169C8EB6A221D47F8C2B83DDA5C0EF","sha256":"1968A73138BCA7132DB9B25F541386647E4A12A5EEB73A9586D2EF705A958644","type":{"value":"pbm","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1031.hxn.g1p3okhzl","md5":"851D1FA0A41473D9AA027F7395C742D7","sha256":"D55BDB589F956CE7C1B8A22636116477496D3E27BD810505ADA6CC001861E678","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OIS.14.1049.hxn.g1p3okhzl","md5":"1F173EF84C536F53CDFC24313F4E9E3B","sha256":"C0DDAC2A2E70969D3B985795222066FC9AB697B9E3D178EFDF7804B8E5760A58","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.ONENOTE.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.ONENOTE.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OUTLOOK.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OUTLOOK.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1036.hxn.g1p3okhzl","md5":"B93E1A71B2A4EB4F063100BEBF6C63A5","sha256":"98A0A19C0DDA1301F7F74EE024614F713E1E129401200201850FBC483890252E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1040.hxn.g1p3okhzl","md5":"20AC7126C5C3E5A0276C3BF973BD7E34","sha256":"8A75CA51FAF88F9099BC74BB4BDB03707207DA5BB972D29E288687DA80301F12","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1033.hxn.g1p3okhzl","md5":"DE9C84FFAC30948F8E0E94C7A8334C4D","sha256":"5B95046D1C1B165B1A3F0D74FE28A8E83FA5D604C1A30D51A22840E81592B55E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OUTLOOK.DEV.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1041.hxn.g1p3okhzl","md5":"986CF16845DCF4AD47C53CD849FB2BED","sha256":"50FEE11AD5030533B48BC09FBFCB097DC072E23C4380580A4BDFF18F6A777F54","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1042.hxn.g1p3okhzl","md5":"805A61CF7923E38445B85AC085D15D9E","sha256":"7E19B16BE465971F60EF0107E7D9D8B15389A71D5CEB971075F53BFE5A902A8E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1031.hxn.g1p3okhzl","md5":"32B3900D433752952343A160B868E917","sha256":"1CD526BABDA8E4750664740D474A0782B0FD3A20432A5C895B52A49D586C93AA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1055.hxn.g1p3okhzl","md5":"FE95F882375356A9F762B08CC9FC0428","sha256":"1EBAF502AF4A979CF021057FFBFB34647E20D89D147FEA1D50F8B3DDC274C9BD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1040.hxn.g1p3okhzl","md5":"3408FEB6637D637286C0ACD3FA968E04","sha256":"FFD6F7304D6F76C0A299673410C0925ED582B7818CC922B668E5742380053B3F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1046.hxn.g1p3okhzl","md5":"D285629B5D2B1639D91C079295994DF4","sha256":"75BFDB7DA37F564D7883C778A8603ED9B79146A1716766CCE5072587608B8751","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.3082.hxn.g1p3okhzl","md5":"74F0564506A6587C503049E074A69578","sha256":"5AF2CA5700492FFA4E868D01E3CD25F20189297EB42FC71E189AE1CFA0F617FD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.ONENOTE.14.1049.hxn.g1p3okhzl","md5":"583BA505E1EF92F6263EC956BC133DF9","sha256":"82E454E5D4032F18545D6830C56A47B0A4946123B6E42E96D238BD21E90B4337","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1041.hxn.g1p3okhzl","md5":"873D51515AA0AF901461702E39A9A94C","sha256":"ABC4CF6725566704AE910DBE052E192BB590E531356C5D5C6FCEF9B30F7C2210","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1033.hxn.g1p3okhzl","md5":"9CCD4B1D2F5F8BBD7936A438DA907A6A","sha256":"A3D4C510F607674B66DD0642244724E84CA15CE2E45222218D640A151AA456D7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OUTLOOK.DEV.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1036.hxn.g1p3okhzl","md5":"91041B09E97A192F29DE6F1EE203CA39","sha256":"90F9FB3BA2C47FF561A6DDBEC3B514DDC119D9AB0C18EF950B5C9CE471A827C4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1049.hxn.g1p3okhzl","md5":"415C7AA5FBF16ECAC422C58EA46B127D","sha256":"96FBCE1A3AAF8EB1F3A8AF7CCB24A8572B73EE5817788EC529497698B711430F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1046.hxn.g1p3okhzl","md5":"1076A1F93D5EC711C64EAB6CFC187124","sha256":"8BBFEA1F8F0E0A6131114847459D9142ADE9B5F7BF066CB6DDB1D00E99AB01CB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.3082.hxn.g1p3okhzl","md5":"D9FADC01888012A165C8CFDBCD2AACDB","sha256":"663D49AF933D48CA33E224CA7C2480B5F225FE6BB167A0A872FF1BBC81CD29EE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1055.hxn.g1p3okhzl","md5":"96EC72191ACED4FC5E5E7627B8E9EAB2","sha256":"F35EF79EE6A7446BA485AED20C38DC3E29938EB506EA3C0F9B89EEC594BA03B3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.14.1042.hxn.g1p3okhzl","md5":"DDD1B30EF5A8E7F91560E6BACA8A1884","sha256":"7822AEBC52470554F2FB33188477D175C80D9BF30762B8A5DF6CEB93FC0515AB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1031.hxn.g1p3okhzl","md5":"E6A3EEC10152E75639CEF368B4F555FA","sha256":"4E30BFAA6D9BAA84FA44D245B5FA779CBD7F5DEE195481A3A629ED3AA9FBAC7C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1033.hxn.g1p3okhzl","md5":"6DFDCFE0B1EA5D9430F1123B60985E07","sha256":"A17E108DFC773D36999E0659EC5F67304543781727E3F5724E7D685AF7D0A6F9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1036.hxn.g1p3okhzl","md5":"4E8CB2C12E412D04CA563FF13996668E","sha256":"E99856DB2422BEC8F223CBE9A789BCA6D64DA6BFF3337B1FB0E658910E562D24","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1040.hxn.g1p3okhzl","md5":"A2FAB5153106C60A1D090C23751C9FE4","sha256":"79F377F2B3B85F2C795247E06A53B2DFD4540E42BC741F3BE2B67F2D42FAB262","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OUTLOOK.DEV.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OUTLOOK.DEV.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.OUTLOOK.DEV.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1041.hxn.g1p3okhzl","md5":"5A2AA7BB3747BBC8AB032197FEE220AC","sha256":"2A6DDDB26783F9AEF43486B14E62C791E753375E6A6D29EBF33364A8DB41AD93","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1031.hxn.g1p3okhzl","md5":"7408BB8F15BD57F6B660E9BDAE9F19B9","sha256":"8618B001EDFE70AC70CA4B1DC26131F4CAC51EC8C272E0C8C824F16F58255EAD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1042.hxn.g1p3okhzl","md5":"93E440161027F6669A98D4190FC97B08","sha256":"3C6B5837DCFACB896AAF1043D410A15384562EE993963E1BD28A644D6C21FE2C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1033.hxn.g1p3okhzl","md5":"6F3094359D1315B32FB4FF60BD72E7DB","sha256":"66C4DB852FB1BB5A08340E2662D4A50456599CDAE5938792220F2EA4D0CC1473","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1040.hxn.g1p3okhzl","md5":"73633992B1841D0FAC4AA43FC4F82F48","sha256":"354F2220E4B079C4347458ED215B023B088B7A3456165A743E49749BC44F36EC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1055.hxn.g1p3okhzl","md5":"FA43D3ADE30DF4EDA5ACD6D004190C8B","sha256":"762ECEDF8311D393F990967059F8921814789043FC00B708892464F7BEEDD79C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1042.hxn.g1p3okhzl","md5":"4B799A8E81D017192000FA451D51BD7A","sha256":"29B7DBD15832AFBA610721EE519DF13A43F99921460E39E90E6A1FC09A8A36CE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.3082.hxn.g1p3okhzl","md5":"BBB47C14033AE2427718F53A4D46DA33","sha256":"2C7165E06BBAA5E09885CA6F92A77DE06D0932E8CA4403B7418538F5B262AA70","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1036.hxn.g1p3okhzl","md5":"1610A940406362126B20423FEA4E318B","sha256":"068D853EA316A13A47427C5D864493429A83053252B1093E88348A0BAF9B90E4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1049.hxn.g1p3okhzl","md5":"478C526253F17E72F46322728F9DCC92","sha256":"9D9B2DB97349419EAAA26479B4CDFD33F0A3CD64D05BBC52BC0713204029ACAF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1041.hxn.g1p3okhzl","md5":"867DA390788911ECFE322D24EDA85A73","sha256":"1B67AA2516F7D402A3A51C7B48BAD2FEFD9B2E5F506A070CA6ED7C920F20B8DB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1046.hxn.g1p3okhzl","md5":"F1DD32E5D9369CBA4764B980800D7AD0","sha256":"8DC555DF61F3838C7E87D8C9F57BD04C5FFACD339C60972D2D08819A6B62E408","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.OUTLOOK.DEV.14.1046.hxn.g1p3okhzl","md5":"DE42B2FB6DCF7BA9E1A0776A6E70CDF0","sha256":"E3C0FA12899FBA96BC48B599F7980D3E122569C4994B6099B064ACBE551D9E5B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.3082.hxn.g1p3okhzl","md5":"1F3C8857015346379AD05BBECCA3764F","sha256":"F1E05D9CB2029079010F62B3DC669D41821811ADCFB11CDAE8F2E3A97B66709A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1049.hxn.g1p3okhzl","md5":"BAE1BF0FBFB88A8EA77A83C88F310A69","sha256":"0946D4F254AE04C451F2F94DD66CB892A50997F6BE05EE04FD679AAF7573C652","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1033.hxn.g1p3okhzl","md5":"E6B772519ED538B4644D6A6FD74C77F7","sha256":"65CCEEE6B2D4021E394D9D806BFCA2FAE42A88C62BD36EA937EC08FC9BAB4BE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.POWERPNT.DEV.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SETLANG.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SETLANG.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.14.1055.hxn.g1p3okhzl","md5":"F8F97C08F13B49E2148B8F0233795030","sha256":"002A51106CA41558310F59D53F6D79EA9E4FC415FD98226A25B90AE57D991AE6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1031.hxn.g1p3okhzl","md5":"AD55743E1A8A6E36B1ED4B1038C8483C","sha256":"5727CD4ACBA2A1C71F317173786CC7E3F10EBBE5DAEF964DDC6C493259C129FC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1040.hxn.g1p3okhzl","md5":"4A8A8D7EA663E0F904497D2BBF370999","sha256":"366BBD00ACCB0082D6679D77F18268F1D97C7E134E13823C32B34962243586AA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1036.hxn.g1p3okhzl","md5":"35376AAC7DA51EF298497E8608AF62C3","sha256":"DCB745C127C1256FBF06AD57CD1BF15E48D65F917ADE49E32F5497B124615AEF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1041.hxn.g1p3okhzl","md5":"AD2A3BFE642C232501A234E0BEE1F16E","sha256":"FC2DF57B610820913F3A31E40AFB0B389E15A97FC31495022C16FD06DDBE3BF2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1046.hxn.g1p3okhzl","md5":"BBEDA36CD203EF2E9F2C5CF6193A921B","sha256":"BC25CFD12A899072EF7A9DD41ED4E1D7B6CF06AF22DD4A4B13D4B9D1FD873AC1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SETLANG.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SETLANG.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1055.hxn.g1p3okhzl","md5":"E450D50F479E86A0C0E90D19AC158C86","sha256":"4130229FE9310F27D60052F8749BA05CC3E12A5D3F33AF6A3070AA7469900A8C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1042.hxn.g1p3okhzl","md5":"268C7694C8965D880FFB1EEC18987984","sha256":"EA9E24409349298C992C45AF152A3B3A14698E3B45C6C4844257A8C4D8E81A47","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.3082.hxn.g1p3okhzl","md5":"00C01FEEC71056AFF5398348D2190998","sha256":"C4632300E4E6480373B60A74D05FD80710C2F80797CD28B4C3C0B863CAB34FCF","type":{"value":"vc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1031.hxn.g1p3okhzl","md5":"EFE2E13AFD31BF2C2C4F6D890362F7D9","sha256":"EE7513A5E80BE310833D759438B27E0ABD3C4E17A242EDC2DC8B10CD5109CF5B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1033.hxn.g1p3okhzl","md5":"B165E629F333A89B29AD12A2DFCED1DD","sha256":"16807BE41C6CC3AD71BD818C812D9654CB604C394C2A2A89AADC71634B7AD93D","type":{"value":"flc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.POWERPNT.DEV.14.1049.hxn.g1p3okhzl","md5":"5E3EAC2B3A24B924C5E9182C3DC4ECC1","sha256":"2BDAC5936A5E57A1ED8F84CEEF00C02184923467147DF6752F6F359753254AA4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1036.hxn.g1p3okhzl","md5":"4BA07F7CC979979D6C022892B55C8787","sha256":"E1D7DA2B287176541D8538E00843A8BFAA386DD131EC34C2AC2CC56158D29B56","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1055.hxn.g1p3okhzl","md5":"E740076E7D797817F04EEBB0F087FA02","sha256":"F5D402AC7A27E1A56CF35826DAE084FDC2FA959FFFA74F90BAA6E2C9232C6831","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.1031.hxn.g1p3okhzl","md5":"6622FADA25E5C08B284929DDF135637A","sha256":"41E8FBE96DA0962E311CF4B2772446D93F337ADCDF5D7C86BD78FAF136ADD656","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1041.hxn.g1p3okhzl","md5":"79B39818850C1B66DC2787C3CFEB74B1","sha256":"666EC388DDA47C38CEB469E89503485CE25798F3EA62778F6218254152A5CB82","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.DEV.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.1036.hxn.g1p3okhzl","md5":"7F69DEEF4D5EA51BF0E45AB0EDEFE0EB","sha256":"1F1FC194905A4036787065B2CB000064819E71D58C4FDC25A89D40399663C949","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1049.hxn.g1p3okhzl","md5":"5A14CA97B46140B81030DE40C27D1175","sha256":"B7D18C78B8CBA6FFEF3E88214A509A90912BF6985F8C835173986F00B83B2F6A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1046.hxn.g1p3okhzl","md5":"D0CA4F95F316331E1259F7C8B5B46885","sha256":"005E67785CC0D7B873463D25B55BABCC52E554DF117C892D6F491372FC46F610","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1040.hxn.g1p3okhzl","md5":"A7169FF1F2C32CE5A4AA723F67492CE3","sha256":"11CE8392A1015D1743B7CFF87D4834030749686A5C71331A651EA6490AF8F122","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.1042.hxn.g1p3okhzl","md5":"09ED24232569A213C771951E535EC3FA","sha256":"E10DC4E28FBCF1E00EB4241B2314109DE54652B24BF602FD2062F1C9EF120AC4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SETLANG.14.3082.hxn.g1p3okhzl","md5":"A385150413EFFC9723BDDD9C5628B7D5","sha256":"9EA20CE049A24DB1C3876C86B6D78AB075720D2F525A7606585F4B706F845665","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.1040.hxn.g1p3okhzl","md5":"756A7FD9220CAF14BCC1DA46C799D6C3","sha256":"F4868025AE9C6CAE9B059A4599355CC852B0ECF0D8F43D38C83F5F46CC4371E9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.DEV.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.DEV.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.DEV.14.1041.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.DEV.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.SPD.DEV.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.VBE.DEV.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.1041.hxn.g1p3okhzl","md5":"99AEFDD67518CF5BF1E1FA5A16ADC08E","sha256":"EC6DF0F5272BDF0ADADA02C6F73E657957BB1D9A695F1F29FA85A6FDCAE828F2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.1049.hxn.g1p3okhzl","md5":"4513D890F27E38CDBEA80E0E53F5D579","sha256":"EE9791C7EAD0BCAD2CBF3A9E1AE39DE377EFF6AF4E2F15F1B5E791CD0DE30BCB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.1055.hxn.g1p3okhzl","md5":"73A039DB1940EB65121D35DD5BAE846C","sha256":"0F7C24DE8D666694691A0335D191CE0B4D06B0B31CDA0454C7C0C67C828C4909","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.1046.hxn.g1p3okhzl","md5":"5649C2C9E058BAADB30F5A551F74E2D5","sha256":"93FBD43281A39F56F4DD4B5CA56B494F011BF5FDDED0BE46D34F6E7B5ACB1C02","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.1042.hxn.g1p3okhzl","md5":"A9DEF6AF9D756FA745D9BBD08187F9AE","sha256":"8687487E035C8D6B435D07EE00A777E7461084F5EB203A0B65DC602FFE3A0530","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.14.3082.hxn.g1p3okhzl","md5":"CA1B1CFA1DD63429F4BC9470E581128C","sha256":"E7028B03C740779559DB03B9460F66762E559ACDDE6A02A059CA541296342D81","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.1031.hxn.g1p3okhzl","md5":"86BCCA02E1A64A73E22382ACAF8655EE","sha256":"9DCF42711D69E8AA18CB1B20A02DDC00796075F4FC29CB3748B35B13E97E775D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.1042.hxn.g1p3okhzl","md5":"A614510D3336EF4515EE735A48125076","sha256":"85CF2E81147953129398A6ECA29F8CDABD53D9B2DF7DC053035E69E8B0F3975C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.1036.hxn.g1p3okhzl","md5":"D24CCA973444B540549266B54B197E41","sha256":"7A087FE4E9BBEE3E62BAA9997AC81D2BA43AC917A320A42335692D6AD59DB23C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.1041.hxn.g1p3okhzl","md5":"7ACC465F6F7EDFF92BC81AE615587AB7","sha256":"6754E6B227441839DEFFCE5657BA128F7EEA7E259FBDE23C0BE4FC979DFFF5A9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.1040.hxn.g1p3okhzl","md5":"B7246D0D2F804C53C3C81C3241F59964","sha256":"94063DF2AFC76EF353ACF7DC3517F1F40C0F3C4D679A95BD5CCB957AE095607C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.VBE.DEV.14.1042.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.VBE.DEV.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.1046.hxn.g1p3okhzl","md5":"CED092AD6F5B3DA16B394FA861A404B6","sha256":"691ACE73CDC0862E94D22954C4CFD903764459DA3BDF6B777B9E23DF46D0502F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.1049.hxn.g1p3okhzl","md5":"34D848EC566E87667469E870F6A6418F","sha256":"FF32BE2A3E780B56BF768847F50D0B90F897C31D973C314DE5CFE6774C2E7D51","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.1055.hxn.g1p3okhzl","md5":"1F6CCAA74A9644407F002C984702951B","sha256":"927C9FED226D07A54ED23EAA4D9C2A138138C1995B746F0BF132FA76DAF3CFF4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.SPD.DEV.14.3082.hxn.g1p3okhzl","md5":"F6C2394636054807D54433B4EC2DB723","sha256":"8BBE7437348EE5B81F56026F633A8448C2A0DDA18BF30A8FEC73295FB4A695EA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.VBE.DEV.14.1041.hxn.g1p3okhzl","md5":"3C5D94B03301A4E54093EC00E9BA2627","sha256":"573346CD0C0CCF5144C69E8119C0F91944B134216D8E9C3B7E81161407BD3997","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.VBE.DEV.14.1040.hxn.g1p3okhzl","md5":"934530E11909B3D5E0AF29BD69E8180C","sha256":"84A7A3A0BAFBC67E51D7DA7294B896DD241272BD60BAD66FA0EE4F74284B69A9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.VBE.DEV.14.1031.hxn.g1p3okhzl","md5":"DB83B71842CCF23357FE241AE67CF60F","sha256":"7EDBC232DDC95F0EF0134677010DD7CBE21E32D36DC4C1A3B6A6B2E504EBB22D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.VBE.DEV.14.1036.hxn.g1p3okhzl","md5":"F85CC0D8F9EE4929A55101003EE77BCF","sha256":"8DF7842262ED89D381586453280C24CDF2C2365D3966563F512517B32A16C8DD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.14.1046.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.DEV.14.1031.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1031.hxn.g1p3okhzl","md5":"664C320DBB427BFC465D27B1339B3ABB","sha256":"EF783474A8680D631C8A95784911476FA75E538016C1F20061EFD1708242F22E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.VBE.DEV.14.1046.hxn.g1p3okhzl","md5":"64CE3E00E89454B2845D818D97409311","sha256":"6C48E189C2A1B83452708AB11FA403BFE6675A17CAD53BBE0595CA0B9B06A3CE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.VBE.DEV.14.1042.hxn.g1p3okhzl","md5":"4A286AA597FD4918BB511EA74E34B1FC","sha256":"3FD5DBB2F4608F48507BEC523E91968F822ED616416B5B43D36C31EA302731E9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.VBE.DEV.14.3082.hxn.g1p3okhzl","md5":"1B82D12C1E8C016860BA9EBC4421EBAF","sha256":"FA8D0D8A7D90EC75422FEC02BDA7EEB96792FC9B92ABCA2562D8B61EA4904D6E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.DEV.14.1033.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.DEV.14.1036.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1040.hxn.g1p3okhzl","md5":"7A677E47B1F9D30C7164207DA0F22742","sha256":"443DC15825CCFF711E75A03A5B2F30D219B5434E865296615103325608AA79C1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1036.hxn.g1p3okhzl","md5":"4FCCF6F109F09C0DC5AD89A71663F425","sha256":"F19EE49EDAC8460FAA0092949C64A4E978B67E408AB5DD123DA3185241C1D3DA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1033.hxn.g1p3okhzl","md5":"1E5DC2EE616FBC955DF17FEF1E422076","sha256":"8D8E8A4EC4C49A34E2E9028FCFD1E61B686674AEB38A71694A5218170CC7AB19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.DEV.14.1040.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.DEV.14.1049.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1041.hxn.g1p3okhzl","md5":"4A6C7649B34F70E108CE3B11F6B0671F","sha256":"53F6956673B295BA1B8D7A4BBB03DCE030D90CE8FEFD8D63A06398CC62991B95","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1046.hxn.g1p3okhzl","md5":"AC0AD242074976E50A61B01A66E33FA7","sha256":"FDF6F6B49330D5F3BC960D6E6A8392407ABF4C3A55096AF735F6AD02FE88671C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1042.hxn.g1p3okhzl","md5":"076E39D6E674ADCEA17C78438BE41A8B","sha256":"28CD4221742F45E78F6799604605F873C1884B3DA3BEFC50D4886AEA648620A4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.DEV.14.1055.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\MS.WINWORD.DEV.14.3082.hxn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1055.hxn.g1p3okhzl","md5":"928374516C58A534EEBE4D7669904306","sha256":"62EB254835DD14B3F97C7EFAA2EB1A4CDF9F7D32E182228837743646043D949B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.1049.hxn.g1p3okhzl","md5":"3B5F182C32FFCC99C3D88499B0D969B2","sha256":"B79FCB7C72AECF476AE38F6C2A3E3FD3D5981FEC93C1A9F55AD36AF7D0CA517C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.14.3082.hxn.g1p3okhzl","md5":"F993FF0AA752661BB56658C9440C2F7A","sha256":"02E239F58BB904604A35817D13C20E6E079CD624E84B177B83E789F5EBB0BC76","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1031.hxn.g1p3okhzl","md5":"7548AF153224F029542A1BADE06C0C2A","sha256":"D1A3D64D4481D4E5D3DAF8700C1A0FF3AE347A84A805EE36C1A31CEAB45D5F52","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1033.hxn.g1p3okhzl","md5":"5B7939ED39F6EC819623F4FFB107FA88","sha256":"8D8D64B929F3CBD1534675FF9843354F738326537C8383C122F0D94548928F69","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft Help\\nslist.hxl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1036.hxn.g1p3okhzl","md5":"9E728189ED16B43B927B6FBB15D73562","sha256":"0FC37E6D0F7EF63321AD3A73547D4E6C2C822E1572AB1C94D2CE36760F82A102","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1042.hxn.g1p3okhzl","md5":"3D1CDDDD359D772501E9A3E5F793E5F3","sha256":"16AB978B130673F84887C67A49CCE97161269D3E913525CB62862F422AF90A83","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1040.hxn.g1p3okhzl","md5":"C4B433369ECE60CBB760C0E51D8911B8","sha256":"032FF171CA1528CA7573148E5331C24E811CC6EB76C2A0ABC66CEDD545308009","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1046.hxn.g1p3okhzl","md5":"F1C3E7F91DE5FEA0D60D1DE55B88DE55","sha256":"66B574F63B18106346B733BEB8A0BED23B1994AB3EEC8EA4FD6793FF059908F4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1041.hxn.g1p3okhzl","md5":"E839E75C7C6A8DFF9A85904FA652C968","sha256":"E6DCE2FD3C28FE0B03B0F4CD0B45A8BB8927285CB421BB36EC00B81583D3EBC2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1049.hxn.g1p3okhzl","md5":"5BCF7CC4AC824C28F24E5790FEE3DCD7","sha256":"0AAF32E016D2EFA7B2EC874C911BF4918435FA24220FE507354A27F90A3AF911","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.3082.hxn.g1p3okhzl","md5":"9ADA5FC77C1C8986EF6F668A532C8387","sha256":"60E9C3A8A87CA6FF9C384DE0E495FBC561C4C49A918E9EEA45B4B2131CFEF581","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\MS.WINWORD.DEV.14.1055.hxn.g1p3okhzl","md5":"49C5CD0A41FEE0299BE63D2734B384BE","sha256":"84A722CC02E3C08E922DB72635DD47E3E4D8BD5E51EA0BDA6AAF15A2B4EC4257","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\svpost\\svpost.state","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\mozilla\\updates\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\oracle\\java\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\564f02e6419b9858949b0cd5a65e2c8c0944dd88\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft help\\nslist.hxl.g1p3okhzl","md5":"E62E9B78DFC1B685A3693CFDD3EE958D","sha256":"FD1476EF2025344654732B264BAEB0192AF728BF242AF335D27869F1DE58FE77","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Recovery\\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\\boot.sdi","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Recovery\\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\\Winre.wim","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\recovery\\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\\Winre.wim.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{19f7e289-17b8-44ec-a099-927507b6f739}v14.21.27702\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{029da848-1a80-34d3-bfc1-a6447bfc8e7f}v14.11.25325\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{213668db-2263-4e2d-abb8-487fd539130e}v14.21.27702\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{568cd07e-0824-3eeb-aec1-8fd51f3c85cf}v14.11.25325\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{49697869-be8e-427d-81a0-c334d1d14950}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{f65db027-aff3-4070-886a-0d87064aabb1}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\skype\\{7a3c7e05-ee37-47d6-99e1-2eb05a3da3f7}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\.oracle_jre_usage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\svpost\\svpost.state.g1p3okhzl","md5":"8119887F2AB16C0E2A1F51D75F0E88BF","sha256":"C125DE39905A10FF7F17B569EA046862E4929416C054A89C710519985B8DE3EE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\recovery\\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\\boot.sdi.g1p3okhzl","md5":"87266D57878B25BB0FAAC9AC6417E2B2","sha256":"CB5775D096CD5E66CC26ED7CE8E874BBB29668FAA1451E607CFCE8572BB954C3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\contacts\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\downloads\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\desktop\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\documents\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\pictures\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\links\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\music\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\favorites\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\desktop\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\saved games\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\contacts\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\searches\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\videos\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\documents\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\downloads\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\favorites\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\links\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\music\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\videos\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\saved games\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\pictures\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\searches\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\appdata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\favorites\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\links\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\documents\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\downloads\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\desktop\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\music\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\saved games\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\pictures\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\desktop\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\videos\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\documents\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\downloads\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\favorites\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\libraries\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\music\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\MF\\Active.GRL","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\pictures\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\recorded tv\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\task\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\adobe\\arm\\{291aa914-a987-4ce9-bd63-ac0a92d435e5}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\crypto\\dss\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\assistance\\client\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\device\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\videos\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\crypto\\keys\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\adobe\\arm\\reader_15.007.20033\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\crypto\\rsa\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\MF\\Pending.GRL","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\event viewer\\views\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\drm\\server\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ehome\\logs\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OfficeSoftwareProtectionPlatform\\tokens.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\officesoftwareprotectionplatform\\tokens.dat.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\guest.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ime14\\imejp\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ime14\\imekr\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\mf\\Pending.GRL.g1p3okhzl","md5":"001D4EE0BFB6A1EF3398565EB008B2D5","sha256":"51DF38ECC9BA6B451741C59C9D4F914232F7AD77EDF632FE4A4CD0D3823FE729","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\mf\\Active.GRL.g1p3okhzl","md5":"4D94B0572E5165863EF7E53EA56E606F","sha256":"B9F54BC0121DCE8BD119AF0EE92120D7CCC5718679978992A6E459E7F457527F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\officesoftwareprotectionplatform\\cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\netframework\\breadcrumbstore\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\network\\connections\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\network\\downloader\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\office\\uicaptions\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\rac\\publisheddata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\rac\\outbound\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\search\\data\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\rac\\temp\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\rac\\statedata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\user account pictures\\default pictures\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\guest.bmp.g1p3okhzl","md5":"2A73B2655E9604848F8914834A2ADCE6","sha256":"7090F8F70A7E1569990A63CE2B9B5CC0CAF0E27A1C933CA3DDBF56AAAD3EF2EF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\user.bmp.g1p3okhzl","md5":"2E31474D2146C7EC931EFA1FDD82C405","sha256":"780ADC87E05C39C5FB9120A75D221D42B4BBD77EC900135A9AA6FE74E9DDBD04","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Oracle\\Java\\java.settings.cfg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\quarantine\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\vault\\ac658cb4-9126-49bd-b877-31eedab3f204\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\definition updates\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\localcopy\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\support\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\scans\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Package Cache\\{49697869-be8e-427d-81a0-c334d1d14950}\\state.rsm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Package Cache\\{f65db027-aff3-4070-886a-0d87064aabb1}\\state.rsm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\.oracle_jre_usage\\90737d32e3abaa4.timestamp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msscan\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\wwansvc\\profiles\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\mozilla\\updates\\308046b0af4a39cb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\oracle\\java\\installcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\\packages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Contacts\\admin.contact","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Desktop\\acceptedlondon.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\oracle\\java\\java.settings.cfg.g1p3okhzl","md5":"85B41FAB7BFA6BE5312BCCFD3F5E4F4D","sha256":"2F962CAF6F334630887924AFA0F885F977C8AAF48E09CC9089E8AD3DAC9829F2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{029da848-1a80-34d3-bfc1-a6447bfc8e7f}v14.11.25325\\packages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{213668db-2263-4e2d-abb8-487fd539130e}v14.21.27702\\packages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\.oracle_jre_usage\\90737d32e3abaa4.timestamp.g1p3okhzl","md5":"CD8003CBEFF15953406E0A637CB4242A","sha256":"F23D6E3EA1483BDFB9A21E76BDB08C626E68299FB423B1E23009B1F878A73527","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\package cache\\{49697869-be8e-427d-81a0-c334d1d14950}\\state.rsm.g1p3okhzl","md5":"0509E7F95C9BE4C5A14C7664238DA1C5","sha256":"52C7AA60D94C65E6E118D0A12CB8618594593B2177BB56582EA68F576C6E92B1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\package cache\\{f65db027-aff3-4070-886a-0d87064aabb1}\\state.rsm.g1p3okhzl","md5":"344A95A33F15D6A9413CE302AF03965F","sha256":"4BF2232BBA22A66E85903D4030DA11B667D557F2793205F841F7C07424EFAFFB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\oracle\\java\\javapath\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\564f02e6419b9858949b0cd5a65e2c8c0944dd88\\packages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{568cd07e-0824-3eeb-aec1-8fd51f3c85cf}v14.11.25325\\packages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\\packages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Desktop\\balancejustice.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Desktop\\insideconsider.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Desktop\\dtool.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Desktop\\fitengine.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{19f7e289-17b8-44ec-a099-927507b6f739}v14.21.27702\\packages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\contacts\\admin.contact.g1p3okhzl","md5":"F66F214BB097C5DCE962F09DAB8CAA78","sha256":"828C232F03D2A6A26DF212718DB610DEFBF0E32341C42B43762A73D190F84405","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\actincrease.png.g1p3okhzl","md5":"0CCA280BF8970EB08BC2A5C779D5EE0D","sha256":"F6EA80B1C89C30B8BD1FC6FE62E1841F7FF4B4DBE72A582594371D8C0740457D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\acceptedlondon.jpg.g1p3okhzl","md5":"23151B3910F2BAEB3587DAEFD88368A8","sha256":"6CEBD43BF5D73AB9F8356AA459D664EAABB56B41AB3E9EC3075D0D1731A5A0CC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\insideconsider.rtf.g1p3okhzl","md5":"7C8C093E39C66D78F2B6D3E9D8DE7F56","sha256":"B5231D14A6E65183D1CB72F7A852D4368E2BD43217BA8C900C00C97F67DD467E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\balancejustice.rtf.g1p3okhzl","md5":"AB5E4BF7D079DFEDF9030B8B37320A08","sha256":"AC2D6BB202577B0767B55A67A0F8F98D3BB113A18C9C955EAFFFB4130BFB089C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Desktop\\movingsec.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Desktop\\nicesummer.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Desktop\\teamnote.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\declient.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\doneestate.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\leathera.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\makeprices.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\publicyellow.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\dtool.jpg.g1p3okhzl","md5":"5B3BF48E87439FFD734B071C7C035AFE","sha256":"5C3F3C9A031BF1B8484494FA0ACDC89A3160CF053E71571ADCB1157D7E2443CB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\summersteel.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\transportblue.rtf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Downloads\\devbetter.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Downloads\\everythingsaid.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Downloads\\forumafrican.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\doneestate.rtf.g1p3okhzl","md5":"C5FB8937E99901941AD78102FF083E16","sha256":"70E513BCB0736111DE1FCD65FCFE705ED2AF22AF6E4798830E72D6A76AF1437D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\movingsec.rtf.g1p3okhzl","md5":"427E387C1FC7982AF527884FC990C7B9","sha256":"922A018744B2188B4C0098DD991359957156E0C0C69AA517DF59383FCD16603A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\fitengine.rtf.g1p3okhzl","md5":"FFB4F16E9AAE09CDF502109D98C14890","sha256":"F85E8DDA48F1FB9C792E47B111E5CA41060DC8A0ADF7ABF42B9CBEBEE311C5DC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\leathera.rtf.g1p3okhzl","md5":"3EDEEB662BCE436A6EBD7F25665A84F4","sha256":"EABE2FCBA9009B92DDB08F0140226ABAA3BCD328ADD80398E931A434DD34F539","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\declient.rtf.g1p3okhzl","md5":"9175AA4D90E5FF810A47A2C7A02FEE40","sha256":"F289F3564D7F8B6D16B94EDC21F67E99939ED7CFDE675CC0594CCAD9DF0B2CCE","type":{"value":"gpg","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\makeprices.rtf.g1p3okhzl","md5":"C49169C19BF738D28F2CE8F8DBA6E539","sha256":"FD6671594637F7DC2F1212E70AA3918D20280642D0925FF0CEA773237C22F65D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\documents\\onenote notebooks\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\teamnote.rtf.g1p3okhzl","md5":"EB353B147A0F1A33BF82374ED53354E7","sha256":"B2A03B5D5B6B3FCCA20403FA7B7820CDED56EAAB28DB68368CAC15081678DBAB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\desktop\\nicesummer.rtf.g1p3okhzl","md5":"D759C9916D80FED314962FAA0042AAD3","sha256":"CA1FB13C0D5BD7B4103DDAD75EED8CD23C7F0D9C08763905DDF65BF6F0277A30","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Downloads\\mdresources.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Downloads\\reviewsenter.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Downloads\\showblog.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Downloads\\sostatement.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\documents\\outlook files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\downloads\\everythingsaid.png.g1p3okhzl","md5":"CDF15A3EEED458D99C0EDA7E66151A9F","sha256":"E185AE72F816E4C2AA509B052D8B2D0544C9C2BF4C1A496FE5CF3057B0076FAB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\publicyellow.rtf.g1p3okhzl","md5":"48731F0617683D6E955B1A286A4B0271","sha256":"5E767354EB1ED75EC52ABA656E4C4C134787D92C2F006B8F44D790F490F903CD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\transportblue.rtf.g1p3okhzl","md5":"4BDBEAE2A24771F76FE5976B204AE744","sha256":"39C0D8787D2F59B6E4C6091298A2A7C7AE17E79674DA9A0FA43384F218D4DB5D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\summersteel.rtf.g1p3okhzl","md5":"F061386270302CC2C02F2FA3A290849A","sha256":"EA7FD662E0DE498BF29EE4BEA9B895C99DD511D647DE7C11ED3FC5D05260F832","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\downloads\\devbetter.png.g1p3okhzl","md5":"FFD5E796CFE196A2ED32B8A68D5BC8DB","sha256":"7FDCE100C441626EBF9730800C7742EFAC9294992999C6DE04B5DA8E9E7FB638","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\downloads\\reviewsenter.png.g1p3okhzl","md5":"43B3A6A62E083F3505A0FABEFA87C5FD","sha256":"9E6FD64BD23F79D99898EF6960F1964EB7AADB4444D5ECC544CFABA51A3C8E8E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Pictures\\allowtheory.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Pictures\\bankensure.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Pictures\\compareoperating.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Pictures\\gettingbetween.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Searches\\Everywhere.search-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\downloads\\forumafrican.png.g1p3okhzl","md5":"F271FEFC483A560161FE718BF88425AB","sha256":"115B5EB7858C0FDB71696B7AFF33BDD517EC9151235CE0C6D19FFE9398C1C601","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\downloads\\mdresources.jpg.g1p3okhzl","md5":"088DE869C74D7AC2FAD2DC8D233E7A4A","sha256":"C72DF729A25A4F42E7C00F3E7B386F06A7A91941300E226E09A7A025B94E868D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\downloads\\showblog.png.g1p3okhzl","md5":"2B0C57D669D57ED57CD2FDB581920A7F","sha256":"70600D38FB0D2A7F72B4D7F1128A2815EF358A421A6852B141A30025AE5AED87","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Searches\\Indexed Locations.search-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Searches\\Microsoft OneNote.searchconnector-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\downloads\\sostatement.jpg.g1p3okhzl","md5":"3B1434C0E67CF24310F1B2950E5C6567","sha256":"69E3BFC64D6CF9C8BE85716BA29338704FDD29AAF1D6E98DCB82508DAE11494F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\favorites\\msn websites\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\pictures\\bankensure.jpg.g1p3okhzl","md5":"E7E3141C6DC34D2B0CD5FD23DC5E57F2","sha256":"C582EAB5979161857839498F52FD31D9FE069EA68EB994AA856F278D916C2E77","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\favorites\\links\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\pictures\\allowtheory.png.g1p3okhzl","md5":"78DFC67DA6AB260BF222F1239843AF28","sha256":"6062D8F00477ACD148316FFD880EE79D9EC3754E3072AF1972D82C0052FE2B9A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\pictures\\compareoperating.png.g1p3okhzl","md5":"20AC319460E7E651689327EAAF42C89D","sha256":"2E92C67B7B6A3F72A4E46076C9CED88973A90E0F476BFBAF665042DE57C785F9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\favorites\\links for united states\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\pictures\\hotellargest.png.g1p3okhzl","md5":"E7CD2613DABC60E6A04265127377B059","sha256":"15A8F7FE35D567A9B0B392C066A0CD78EE48AA2B12A6D9F049829C552995F372","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\favorites\\microsoft websites\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\favorites\\windows live\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\pictures\\gettingbetween.png.g1p3okhzl","md5":"CB11E8AAFEC92D6ACF74C4957EEE570A","sha256":"0EA8B4D06080D36322DCC9C3E856C93D0AF0675E77910A2F27286C5CB3BF6113","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\searches\\Everywhere.search-ms.g1p3okhzl","md5":"B7C7817F61190CC1D330EE8D9D8815BD","sha256":"9D39757F4186E8C99935EB9BFF1415D7E77BD9E6B1AE06EC4E40FCA3E6CB9AE3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Contacts\\Administrator.contact","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Searches\\Everywhere.search-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Searches\\Indexed Locations.search-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\searches\\Indexed Locations.search-ms.g1p3okhzl","md5":"6FDDD4B8109439CACFAB4FCF20E9864D","sha256":"69D5EBADABA95BF4BFD6C8B15C817B5A320AFD560BFF39E90573C89EDA735943","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\searches\\Microsoft OneNote.searchconnector-ms.g1p3okhzl","md5":"6FBBFE20590A386D12E2A9D7BCB499EA","sha256":"733A0914B9F606B075E67080677212140282927F2AE825BEB37895320301C8A9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\searches\\Microsoft Outlook.searchconnector-ms.g1p3okhzl","md5":"726D244A27889B9F3F47FD974946C4E4","sha256":"6F03052435FB75F14519818A49FC1EFDBA79042E45C4B0A36158E9E6A5A28A1D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Libraries\\RecordedTV.library-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\locallow\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\contacts\\Administrator.contact.g1p3okhzl","md5":"183B900530B7D23572478B72A410A22B","sha256":"549695E2477BDA5D08C3C74A44D552D471A02EDA0D9D72ED921649C8D829740F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\favorites\\microsoft websites\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\favorites\\msn websites\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\favorites\\links for united states\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\favorites\\links\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\ABCPY.INI","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\setup.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\favorites\\windows live\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\searches\\Everywhere.search-ms.g1p3okhzl","md5":"5B0763129C83905C71B3CA3A0EFDB59F","sha256":"CEC4BB0F3A298F3DC2A0EDBAFEE45576890B01D5E3CCC007826B2B8802BBDFD8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\pictures\\sample pictures\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\searches\\Indexed Locations.search-ms.g1p3okhzl","md5":"F96F3D98FE878C316DCBDD26A07CD5F2","sha256":"39E45FF1E9B02A62EF98B8E9947B38902FB69B2A3B781DA094CD09CA191BBFBE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\libraries\\RecordedTV.library-ms.g1p3okhzl","md5":"89B22E5B0B756814E584ADDEEB7BB4F8","sha256":"91755DC684E5682FA5F0E1D578D891DFA64FDBD6048293636C8C2A7583A147DC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\appdata\\local\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\appdata\\roaming\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\music\\sample music\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\crypto\\rsa\\machinekeys\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\recorded tv\\sample media\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\setup.ini.g1p3okhzl","md5":"5FD28D986496433230243B7AC689A59B","sha256":"7F443D77C8854C6DD08541E2FF42CF3803A1F17103A8113A963A148439965D03","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\crypto\\dss\\machinekeys\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\public\\videos\\sample videos\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\ABCPY.INI.g1p3okhzl","md5":"8D46C2BEC7F12EF7B03A1B738C241638","sha256":"8AA19D901057D56BE0C9D330A5387CEA29A8E6C16A7C7D7E66CE87B48FCABCE6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\assistance\\client\\1.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\crypto\\rsa\\s-1-5-18\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Network\\Downloader\\qmgr0.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\network\\downloader\\qmgr0.dat.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Network\\Downloader\\qmgr1.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\network\\downloader\\qmgr1.dat.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OfficeSoftwareProtectionPlatform\\Cache\\cache.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\event viewer\\views\\applicationviewsrootnode\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ime14\\imekr\\help\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\RAC\\PublishedData\\RacWmiDatabase.sdf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\RAC\\StateData\\RacMetaData.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\RAC\\StateData\\RacDatabase.sdf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\RAC\\StateData\\RacWmiDataBookmarks.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\RAC\\StateData\\RacWmiEventData.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ime14\\imekr\\dicts\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\office\\uicaptions\\1031\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\office\\uicaptions\\1036\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\office\\uicaptions\\3082\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ime14\\imejp\\help\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\ime14\\imejp\\dicts\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\office\\uicaptions\\1033\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\office\\uicaptions\\1041\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\rac\\publisheddata\\RacWmiDatabase.sdf.g1p3okhzl","md5":"0ACBB80E2BBDEFF696071315604E216B","sha256":"14DBED0D031E72CEC5CFE3A4B1D9E674216B15ED42BDA47032F2989721BEC7BA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\rac\\statedata\\RacMetaData.dat.g1p3okhzl","md5":"9BED04DC3071881498C83BCC4B3156EB","sha256":"47B4756119CA5C1D1B3B1BBEF22F9D421CD68BC9E1E61CA35E3C5AC545BF6893","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\officesoftwareprotectionplatform\\cache\\cache.dat.g1p3okhzl","md5":"2B53EC0E0B191F7FE7C535F7D5F7C1CF","sha256":"A598780A551B94D3842DC72D8115E4AE9CE1ADD95B5EE3EC3970961A36478A28","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\rac\\statedata\\RacWmiDataBookmarks.dat.g1p3okhzl","md5":"C82BCD3A4F6DB28A1D4CDDCD6B981CD6","sha256":"A123BEDDB6719E78785E1A01CE58B4C6BBC5A99BE21B6F7E46EFB77417243EFE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\search\\data\\applications\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile16.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile17.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\rac\\statedata\\RacWmiEventData.dat.g1p3okhzl","md5":"5A3EB6BEC1ACD93FB83923597278F155","sha256":"C3D676816DB887F4881ACBC68B1D6B6B355DE9298E86F493CFB0218A26BCF299","type":{"value":"vc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\rac\\statedata\\RacDatabase.sdf.g1p3okhzl","md5":"E531ADBA31CBFF41014CE79A50BCDD5A","sha256":"6F1F43079D6D8A96C0B056EA06A0BA120673FE88481A2434A1D320CC4E69E7D4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile17.bmp.g1p3okhzl","md5":"A28E8AC88E436B9A4D145191375288F5","sha256":"751C77D3B212FDC6F79B4F66A6265B6CB7B665EE73A5D8A5EC810E5C6F925D8D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile18.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile19.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile20.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile21.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile22.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile23.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\search\\data\\temp\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile13.bmp.g1p3okhzl","md5":"44513D5FFAD82634994CF8B6953DBE36","sha256":"5E15B15A1B90C8D72800E90CDDA74155B65C2EF64828E609017FD2E708A57DCD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile12.bmp.g1p3okhzl","md5":"5EE96CE8AE46A5AE37FFC9468EF3F573","sha256":"1A46A9DBDBBD5E64EAC14BA75921CF14E9CDD80B225F492FD470DEAA2082DB8C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile10.bmp.g1p3okhzl","md5":"881707904CB1D5602EAA22E863722CF1","sha256":"6A4C00DAABB64DB82EA55B37D1D6EC140837249F68A58793F3EA57D9A52D6317","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile14.bmp.g1p3okhzl","md5":"9B46FB79FE30E1D15946D3ED1AA9AA7F","sha256":"572F1C074349BB94AD152DE737E7B44EBFDE9B8E57A7AAEB13BDC0B4838CB414","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile16.bmp.g1p3okhzl","md5":"EF091E715E4870FA8355A0E97649D226","sha256":"0E6406214FD613798A31B7BE934F9E89A8DCA55622B05C63D743C715F98F892B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile11.bmp.g1p3okhzl","md5":"CB56634D27AA45394E47135481B9D96C","sha256":"1729E64BE6690D935D98B4F2B2CE219319DE6C589172F963D274442223A70496","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile15.bmp.g1p3okhzl","md5":"E34A8892B17A8ED6A592DF62391BCA0D","sha256":"86481D95832D9E9C87EFFE1A98B9F8D4084804A4F8007CF28D23AC86F448BDD5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile24.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile25.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile26.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile21.bmp.g1p3okhzl","md5":"5E0D53CC0802C7047D29BF0004390253","sha256":"090288E49695BDB29A856251ECE795C0E3ACD27AADFFE43B71138EAD33506D52","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile19.bmp.g1p3okhzl","md5":"0D5EC7051DC69415D5930735E705BCF6","sha256":"31B91F23C876D0D0741EF735827EC06E304AEE1208A81A591ADC938C1D6FDA1F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile18.bmp.g1p3okhzl","md5":"A1173886DD82104819FB6147D8F09BDD","sha256":"E6D19CC61E794748496DDC5499BD892447525AB8E94D8404224400C1170EC3F5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile22.bmp.g1p3okhzl","md5":"C0DF9C1D7CD5F853AC1E9472FB9A0758","sha256":"ACCE589E167A5D2CCF405D68E4A2E3040A26C81C684A69A0D13666BAD558D3CA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile20.bmp.g1p3okhzl","md5":"592806C21FC8A90E1A56E7BE037EEA15","sha256":"1C51CC9D674A777F3E7AD52ACC293CB13EFAE7E844683D65B62F4E90AD018A19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile24.bmp.g1p3okhzl","md5":"77CBEF4E0B3B2B083C29010E5F7A781D","sha256":"4BE609716E78FA6E7AA3F462FD7E237514F4C874EFC38E2938D7335D36026465","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile27.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile28.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile29.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile30.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile31.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile32.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile33.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile34.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile23.bmp.g1p3okhzl","md5":"0657D5FF2EE001D34E6E52C7C764DB42","sha256":"F6CEBFEF32B014483AAF5F429E5F65BFADF589F5CF9F8ACBFC2C68389A1E1388","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile25.bmp.g1p3okhzl","md5":"A950DF7D3FF672441CE9B66DE348569E","sha256":"72612918F5C06165BC506D5592F20A6FAAB272524EF17885784DA4D1BD95F622","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile26.bmp.g1p3okhzl","md5":"D06DDD1930421C8538D26E2C73E2D5FE","sha256":"37E48D1E827DC53F3E1504DE0BBE14205DDC23A5140C25160102FD2B133E7AE9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile35.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile36.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile37.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile38.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile39.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile27.bmp.g1p3okhzl","md5":"A869917A098FEE316555DC1A2D812F14","sha256":"08C58F83B6FC01ADE93B7EA2C11F22DE457FC63F10F86F8DBC8F65A6A668DBC0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile28.bmp.g1p3okhzl","md5":"89F5861810AC8F09AC864E6F0BF8A4D7","sha256":"5CC2F251B72514389491052E56BEF01AE1411FE9166598D5F880DB58B5FF238F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile34.bmp.g1p3okhzl","md5":"4BBBD5C6FE717D07EC9EB615FF088BF4","sha256":"F58242ACDB8D8ABCAE69A30E4CCEEFF707BE662D10CCD704E3B75EDDD3FAE572","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile29.bmp.g1p3okhzl","md5":"582A08960562E3219465D70DF8005AEB","sha256":"B0E48AC836108E070024EBBFBDF37175B35244C774600AEA53C84786FD9CE412","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile33.bmp.g1p3okhzl","md5":"15349B4EEDAF0777DAED530031340C7A","sha256":"C4AE3FC3FC03DED8F6F501DDED3D157E162D1A151F06C61872FD2DAB1E2B612D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile31.bmp.g1p3okhzl","md5":"B56033DF5E76650BBBFB4200DAD908E6","sha256":"EB0871DFA521E3F0119D6CA5FED02B606D870A4F6A12AD0E413B5EC8E62E3D39","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile30.bmp.g1p3okhzl","md5":"27EB297ED49267C165EB44262E5A6EF6","sha256":"D0603EE6145B44B47351BA3690DF86833F101396E610949A9274B3A7B50E6FEF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile32.bmp.g1p3okhzl","md5":"7904577C1F42F0349F8095E98D6A3048","sha256":"D7C843FA266E109847F08CCB4D95606808FBFA252EE7AEFD8284329850889F4B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile40.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile41.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile42.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile43.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile44.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Vault\\AC658CB4-9126-49BD-B877-31EEDAB3F204\\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Vault\\AC658CB4-9126-49BD-B877-31EEDAB3F204\\3CCD5499-87A8-4B10-A215-608888DD3B55.vsch","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Vault\\AC658CB4-9126-49BD-B877-31EEDAB3F204\\Policy.vpol","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile37.bmp.g1p3okhzl","md5":"8CDCFA2D42FC19BB5A022371EC3D919D","sha256":"3CB3FC52A120697F6F79ECDC732CB1D94DAAEDB3C8BEA6677FC9AED390002E89","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile35.bmp.g1p3okhzl","md5":"99C42DE77A3FB4560CF1A0A3312CAAC5","sha256":"A3AF1363D1BB5DE80694A1AA7BA152C2945C89A9CC456A205CAEA5EC2CA20A85","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile39.bmp.g1p3okhzl","md5":"66A39A10C3502900E380D0FD610C0EC5","sha256":"719C7637AC1D60AFF57619F1D2F5FF760FBC665CCE4835DCB1ED48C62A84CE8F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile38.bmp.g1p3okhzl","md5":"335AB07B7329C5B06ADB8CD04646EA4F","sha256":"EE66AFD9E40C4F670095C53739A6F0F2E1C6129F7FBDE9C68ABFD0908D000400","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile36.bmp.g1p3okhzl","md5":"E1420D69392CE4428A57AE81337BF97F","sha256":"B2F5DEBB64DD78DFB1F77240201FC5B5C108F544182A2442C035D5AA24EAE454","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile43.bmp.g1p3okhzl","md5":"3A15832F94AF70104F704F5222D75EF1","sha256":"4B5E3A1266368617B68AAF337ED12563BF64E6E41865E3D69899447CA912A10B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Windows Defender\\Support\\MPLog-03192019-130535.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Mozilla\\updates\\308046B0AF4A39CB\\update-config.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile41.bmp.g1p3okhzl","md5":"76B85F36133409FE671AD58FC83FEEED","sha256":"ECB3650E246D7F02C9D3B7C8790D1AE1E18ECB92CEB0579CEAB24DD18A99BEFB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile40.bmp.g1p3okhzl","md5":"3299E3B3A9B5EE3EB85B36CC67B1CA28","sha256":"2A1ED2D674E94E0FF25C9636612586A1965C85CEF20E5B9404E87514F713726A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile42.bmp.g1p3okhzl","md5":"5297D6870937E60742E84DCA9A1572A0","sha256":"BEED37D46237D403E696D8242A9B27B37E66896AD0865AA77D545BB2F784BB13","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\vault\\ac658cb4-9126-49bd-b877-31eedab3f204\\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch.g1p3okhzl","md5":"3AE70A18B3C4BF9A69CBCC875F85F9FC","sha256":"537E456392D8FF14D45ED2F0AE1B9149021283C039D937BF11EA9BD13171A23A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\user account pictures\\default pictures\\usertile44.bmp.g1p3okhzl","md5":"A78527AB45A2E364A3040F2DA1CCBE33","sha256":"65638DBB96047D873F202903DD4D31BF68D4201C4BCAABDD0E583B28FD9211C7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\vault\\ac658cb4-9126-49bd-b877-31eedab3f204\\3CCD5499-87A8-4B10-A215-608888DD3B55.vsch.g1p3okhzl","md5":"88CB1C19530FBEC62783DCF358FD8A86","sha256":"441DF619A380D0FBED626D0564D2A92E33190EABC319797EBCD29B5776ABD982","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\vault\\ac658cb4-9126-49bd-b877-31eedab3f204\\Policy.vpol.g1p3okhzl","md5":"7247AFB71E21CB4439862AA03021F1B0","sha256":"A5568269A504B3BBAE721911312E11441109B0D70E9F8A2EA7C95C57FC62B61C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\definition updates\\updates\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\scans\\history\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\definition updates\\backup\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Windows NT\\MSScan\\WelcomeScan.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Mozilla\\updates\\308046B0AF4A39CB\\updates.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\virtualinbox\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\activitylog\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\inbox\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\sentitems\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\common coverpages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\queue\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\windows defender\\support\\MPLog-03192019-130535.log.g1p3okhzl","md5":"5F456344CFB2BC466EE350EA91E4DEF6","sha256":"496AF4B1FAB31CF120AFD5C4F7A936F0915D36B9988566209B34489ACD9AECE3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\mozilla\\updates\\308046b0af4a39cb\\update-config.json.g1p3okhzl","md5":"7463C82ADB54761FF16B04E506944416","sha256":"3E1866F325EB5D920204C02AC426148BD2CB917121BA5DDCE888976612EA416B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\\packages\\vcruntimeminimum_x86\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\mozilla\\updates\\308046b0af4a39cb\\updates.xml.g1p3okhzl","md5":"891C3631094868A2E0730953F0881313","sha256":"55DB37691632F6451A8B2B67A7B9D29C56705F03DF08A783819B88FF4CFBF6D8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\windows nt\\msscan\\WelcomeScan.jpg.g1p3okhzl","md5":"95282B9019BEDB2C913FFCF59BB25270","sha256":"6E459FB62F89D9E99B005AD085C0CCC391753F085B3B11038210B73B229B8968","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{568cd07e-0824-3eeb-aec1-8fd51f3c85cf}v14.11.25325\\packages\\vcruntimeadditional_x86\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{19f7e289-17b8-44ec-a099-927507b6f739}v14.21.27702\\packages\\vcruntimeminimum_x86\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\564f02e6419b9858949b0cd5a65e2c8c0944dd88\\packages\\patch\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{029da848-1a80-34d3-bfc1-a6447bfc8e7f}v14.11.25325\\packages\\vcruntimeminimum_x86\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\mozilla\\updates\\308046b0af4a39cb\\updates\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{213668db-2263-4e2d-abb8-487fd539130e}v14.21.27702\\packages\\vcruntimeadditional_x86\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\GDIPFONTCACHEV1.DAT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Oracle\\Java\\installcache\\baseimagefam8","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\oracle\\java\\installcache\\baseimagefam8.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\cef\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\elevateddiagnostics\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\\packages\\vcruntimeadditional_x86\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\filezilla\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\GDIPFONTCACHEV1.DAT.g1p3okhzl","md5":"9A13194EA2970B614626BBB9709688D4","sha256":"88B5B4D6B87B3C3C9AF963A2A162ECE8643B4DD314F0D36ED9DE2F6FF7B1B57E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft help\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\notepad++\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\steam\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\virtualstore\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\programs\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\temp\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\mozilla\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\oracle\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\Outlook Files\\honey@pot.com.pst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\Outlook Files\\Outlook Data File - NoMail.pst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\utorrent\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\filezilla\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\microsoft\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Links for United States\\GobiernoUSA.gov.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Links for United States\\USA.gov.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\media center programs\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\opera\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\notepad++\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\identities\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\skype\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Microsoft Websites\\IE Add-on site.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Microsoft Websites\\IE site on Microsoft.com.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\sun\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\outlook files\\honey@pot.com.pst.g1p3okhzl","md5":"08332A545D92EA43EF7B47CD6434A4A1","sha256":"6E60D1E6F60A380014A2D2EF3D6974471AD0D904B1E014F923D35C15BD1733D9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\documents\\onenote notebooks\\personal\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\winrar\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\outlook files\\Outlook Data File - NoMail.pst.g1p3okhzl","md5":"1A1A6B2B1754A06DB8D6BE775ACCBD92","sha256":"29A3E07AD8FFD834528B9A2CDC63BA5D271788D528BB3B6D2832AC2243BA9BC6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\outlook files\\Outlook.pst.g1p3okhzl","md5":"2344FB385C419393B17F62567C250197","sha256":"9DAB887260AB2D34B13D049A7FB4F3AF525A5C92955C17628E231D51BDE5FBDC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\links for united states\\USA.gov.url.g1p3okhzl","md5":"D2C06802F114A501DC804DBB173F1211","sha256":"5F19DB5BFEA69CF98A95495BF0CD2E9380A483FB93B261D5933376781E859ECA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\outlook files\\~Outlook.pst.tmp.g1p3okhzl","md5":"C5A2DC2484D1B99220D88CB6D04CD153","sha256":"1BC522833FD49A5B722D12A440A59490E5CEB1C36DCE8CC4924F21650DF5A6C4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\outlook files\\Outlook Data File - test.pst.g1p3okhzl","md5":"D06AFD0992D7C34E40550BCB3847F659","sha256":"98A9AA83BE5A3A8EBF7A02623A6A89785DEF625E855C739398E1517F22F858BF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\links for united states\\GobiernoUSA.gov.url.g1p3okhzl","md5":"DF9EE4115FBEEA1714241111B710E669","sha256":"4639F4791CF1E3C2122501D5253C22DEFBDAEB66E0BA0DB37100309F5F3085DA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\microsoft websites\\IE Add-on site.url.g1p3okhzl","md5":"12BCD2B1A881C2B5E93AE7B443A8EB1E","sha256":"FD83E516CBD9660671D5B9D6D998287E1F84D8640F9ACA1E5B21AD2C479F0EAF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Microsoft Websites\\Microsoft At Home.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Microsoft Websites\\Microsoft At Work.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\MSN Websites\\MSN Autos.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\MSN Websites\\MSN Entertainment.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\MSN Websites\\MSN Sports.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\MSN Websites\\MSN.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\MSN Websites\\MSNBC News.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Windows Live\\Windows Live Gallery.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Windows Live\\Windows Live Mail.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\microsoft websites\\IE site on Microsoft.com.url.g1p3okhzl","md5":"3C953B46809CAC636C0909E19FA6E69E","sha256":"0438183026A148B62730E28CDFD945195A45E272550005D7CD371C10DDCDF48A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Favorites\\Windows Live\\Get Windows Live.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Links\\Web Slice Gallery.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\microsoft websites\\Microsoft At Home.url.g1p3okhzl","md5":"FD2FBC6BDA9CB0A7E8D0D3C40D690370","sha256":"1D263A51CD9BE6E6E201857121E677DF4190727F4BE7817D1E85539B489FAB79","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\msn websites\\MSN Entertainment.url.g1p3okhzl","md5":"83ADF6D76E5FE97FAF13C4E2E43B72E5","sha256":"4D5CD46FF881A1C163DC2D2149B997BE6BE97C2F6EDDE0AECE2633CF383B4E7D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\microsoft websites\\Microsoft Store.url.g1p3okhzl","md5":"30FDEFDCC96536B24BAF4C0DCD38A62D","sha256":"374763BEFD6408F29ADCCB6C287CAA28B515B5DB7E417C93E547E07B40DAE8C1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\msn websites\\MSN Autos.url.g1p3okhzl","md5":"21636BE45773A6FF895636D65A39FEA3","sha256":"4EF1ACF2A8D6609168EBFF0586A13A461F6DB3ABDE0D02E88852DF644B21E445","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\msn websites\\MSN.url.g1p3okhzl","md5":"8A4DD7207D847E96B0D5AE2184BEC624","sha256":"D31B5A02EBE30C55C3E8BFF81D00ED8473D3BF0244FBCF0F1A6BDCDE99C49DF0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Links for United States\\GobiernoUSA.gov.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\msn websites\\MSN Money.url.g1p3okhzl","md5":"F2DA847B74ACDE1A80F025689689B32F","sha256":"2E2E463D5E8EEFCD2D04B6C7743AA80AD7E1C794B15EC282996906B81DBB9B5E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\msn websites\\MSNBC News.url.g1p3okhzl","md5":"140FCE621EA314ED01761EEF0741A6C9","sha256":"39D10734419977B150050962B1019561E032D4418DBE4F25677DCE81E04FDB73","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\microsoft websites\\Microsoft At Work.url.g1p3okhzl","md5":"564C5EB27A60B8BA6BA4FE4E4DEBD5C3","sha256":"01644C3C9D8CE9498DE4B5904D542E005FD01A190B28A60701FFA1109A03EF82","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\msn websites\\MSN Sports.url.g1p3okhzl","md5":"86DF7314B96C542E37AEA96F93C20883","sha256":"2F80A7AA4897D205108851F838E794418B054D558881BAE850DC0A1AB37B1293","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\windows live\\Windows Live Mail.url.g1p3okhzl","md5":"C89CF61CC1D7C0856631205AA60DDDED","sha256":"0EF7A4A8F85609AD783DFEFC4418A13A6BE407779C75A803D60D6CD9760AF93F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\windows live\\Windows Live Gallery.url.g1p3okhzl","md5":"E596B8CD18CDDFFB4025243C81A3AE02","sha256":"E4229F3342896C0B3036D801F85653EDA5C1CE2E4D7194C161AE32AEBE124610","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\windows live\\Windows Live Spaces.url.g1p3okhzl","md5":"36628A3C96E22952428670B0753CC28C","sha256":"68AB6DC045183293B1061CE81A32064BEDD4DA092BA1F3A8E0469C330ABACD1B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\identities\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\temp\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\favorites\\windows live\\Get Windows Live.url.g1p3okhzl","md5":"12801D81D41AC48D8F609B1F82924D6A","sha256":"D14B362F3A6853F7CB14BDB086A89A2F18FBD2545EFE6BCC91B9DBCFC403E1FC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\microsoft\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\media center programs\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Links for United States\\USA.gov.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Microsoft Websites\\IE Add-on site.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Microsoft Websites\\Microsoft At Work.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Microsoft Websites\\Microsoft Store.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\MSN Websites\\MSN Autos.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\MSN Websites\\MSN Entertainment.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\MSN Websites\\MSN Money.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\MSN Websites\\MSN Sports.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\links\\Web Slice Gallery.url.g1p3okhzl","md5":"23AC40892729B916156278DBAF4C8A1E","sha256":"241AA2D67D649AF3C87042605F72B68A22E49BE35807DF8983E0413A6D3EA1CE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\MSN Websites\\MSN.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\MSN Websites\\MSNBC News.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Windows Live\\Get Windows Live.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Windows Live\\Windows Live Gallery.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Windows Live\\Windows Live Mail.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\links for united states\\GobiernoUSA.gov.url.g1p3okhzl","md5":"9DB26D8B4EAB1BBBEC06674C1DC3377D","sha256":"D01E558C3C24DB2A96D5E0088684AAD0A05DA7C919250AFCF5A1505A623FC282","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\microsoft websites\\Microsoft At Work.url.g1p3okhzl","md5":"B361DC9A76E62CA66BC157626EC313A9","sha256":"ADF07B569B5DDCCE22DECD79650EB204E78A02CC1EDCDC5CF8474CCCD85E5B0F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\microsoft websites\\IE Add-on site.url.g1p3okhzl","md5":"3E45FBB2FAADA883754EC834B65C42E1","sha256":"D8CF2E32834868D964FFE74743075CFA393F40AE8E5819021788C0C8B3208DF3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\microsoft websites\\IE site on Microsoft.com.url.g1p3okhzl","md5":"3A6F8F14EE87958E6BA3C2ABCA801B2F","sha256":"5F56F3E54CE28E1EE87B4A1CAE3CE2D69BCB01495690E900F8179AD5A601ABB9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\links for united states\\USA.gov.url.g1p3okhzl","md5":"9CF29D6009AAEA77D68F5075D2524F81","sha256":"1B099A226D3B1EAF7EF41B2C475A633E0CCF3C3171095D87570466EC54CAE62F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\microsoft websites\\Microsoft At Home.url.g1p3okhzl","md5":"BD0B196EAB5DD0B1766494CD9C6418AF","sha256":"1E434DDAD43B29DF52D3300B272E51916E031E66263317FE35C6CEB04192504A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\msn websites\\MSN Autos.url.g1p3okhzl","md5":"EA9096A7892DF6567837FEDF6414B5C4","sha256":"3A551EF5953B2A6150BC7A1C9E2630C32147B98F965849CEB8D236703B059180","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\msn websites\\MSN Money.url.g1p3okhzl","md5":"0ED5CA2FB19A70005868B404E75B8631","sha256":"FB704A570ECB9C30BA6C4F98D1FEEB3BB7E7A0956AE0E23163E2FF9DD5D59EE0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\msn websites\\MSN Entertainment.url.g1p3okhzl","md5":"84DE3FB00AF3DF2417A88ECCD0485540","sha256":"EE2BE4938E5C161C1BF4B2D853358509B575F5E823EFC9AADECDF0448A5775AF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\microsoft websites\\Microsoft Store.url.g1p3okhzl","md5":"6BE7D9B84B382298FF9978E4FB91CFBD","sha256":"EA86FF27EB1F24464BBE04506E1C5A06CA846D94238B1228D31CC12B6C6EF269","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\Favorites\\Windows Live\\Windows Live Spaces.url","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Pictures\\Sample Pictures\\Chrysanthemum.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Pictures\\Sample Pictures\\Desert.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\windows live\\Windows Live Gallery.url.g1p3okhzl","md5":"C75E9BC1DF03FCC6A2EDFC6B2617870C","sha256":"95310A7C223A22AF22EEA981B69A4CF599F10038336F6FC5E98ECDCA9B4702FA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\msn websites\\MSN Sports.url.g1p3okhzl","md5":"4642A2BA4192E0AAC9375D241A52CAD6","sha256":"0E5E9F8E5367507C9C1FF895FE395E5566D4DF92C8F3C1A3701582DA65CDF1B0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\msn websites\\MSN.url.g1p3okhzl","md5":"0AC3C863661DEA6696BDF5E551B730B7","sha256":"E5CECCA39DE1F67A22C0EE91B72971780395A84FAE92D58446375A99576D6488","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\msn websites\\MSNBC News.url.g1p3okhzl","md5":"8A25ACC4AEC3D25A004FFBC29E038249","sha256":"B697257DD0C7D1DA1F1797EE3E15C8DC83164FCEBA9D6389E1B22FDDB8967F81","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\windows live\\Get Windows Live.url.g1p3okhzl","md5":"25DDD70D39D178FC87E22CDAF6E7CD4A","sha256":"8417FA40E97FDB0F1019099FB8E47AB9A24A1E77C8D27E5C75EA6DE6F152AF59","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\windows live\\Windows Live Mail.url.g1p3okhzl","md5":"C217CC37C656356C853736987FB06284","sha256":"534EB98C06216DBAA60289E2A886F440219BF7BAF918F2B59B970CD8E00C08EE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Music\\Sample Music\\Maid with the Flaxen Hair.mp3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Music\\Sample Music\\Sleep Away.mp3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Pictures\\Sample Pictures\\Jellyfish.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Pictures\\Sample Pictures\\Koala.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\music\\sample music\\Sleep Away.mp3.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Pictures\\Sample Pictures\\Lighthouse.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Pictures\\Sample Pictures\\Penguins.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Music\\Sample Music\\Kalimba.mp3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\appdata\\roaming\\media center programs\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\appdata\\local\\temp\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\appdata\\roaming\\microsoft\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\appdata\\local\\microsoft\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\favorites\\windows live\\Windows Live Spaces.url.g1p3okhzl","md5":"8144469DE4E0489E1C08F9BFF1465FD2","sha256":"3FD360339661D171214D87826A04E93FFD444850FE83FF58CA15FD12E26C6F3E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\pictures\\sample pictures\\Chrysanthemum.jpg.g1p3okhzl","md5":"FF3D6B210B411AF56FA77E746038DEDB","sha256":"D1DF0B16F1A39DA98151848473CA4105260FABCB456799EE17FD154EA9EDAD22","type":{"value":"app","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\music\\sample music\\Kalimba.mp3.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Pictures\\Sample Pictures\\Tulips.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1027.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1028.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1029.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\pictures\\sample pictures\\Desert.jpg.g1p3okhzl","md5":"A9670BB8EC1206B257535441391BC153","sha256":"71AA78589811A6B6E24428F92B6956CE71B78D98E5C36228E4CA3BFE8656843E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\music\\sample music\\Maid with the Flaxen Hair.mp3.g1p3okhzl","md5":"6ED1EF2598C94E01D613139CEB6A2777","sha256":"AD39E109F9989DEEF2F9CD64C87C23D660AFE1DA5EC6BCC98B4CC85C7F02F0C5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\pictures\\sample pictures\\Jellyfish.jpg.g1p3okhzl","md5":"436CAF4B525347F70F6E6854700667A6","sha256":"9D2D2911AB20CBA886F635E1D10036458A21585066C379A3AE2CA83229B8CBB1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\pictures\\sample pictures\\Hydrangeas.jpg.g1p3okhzl","md5":"6D036139E431EA2FC64A4D7A865C74E1","sha256":"47C7CD36337A8E694940335255F236E95AC0E4574830B9CE430ACE517A786433","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\pictures\\sample pictures\\Koala.jpg.g1p3okhzl","md5":"264804D974C908FDCBD305BD0D11CF5C","sha256":"56A70A3306886629AAE86DDC48E17D5BD639A9FA4B5CC780D6F30463CD2E5E1A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1033.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Recorded TV\\Sample Media\\win7_scenic-demoshort_raw.wtv","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\recorded tv\\sample media\\win7_scenic-demoshort_raw.wtv.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\pictures\\sample pictures\\Lighthouse.jpg.g1p3okhzl","md5":"D789B6AE385A0AFBF54C60DF42C9FDDF","sha256":"16F7AC79F9ED43A19FE39275545FF50E7079DC0F73D06979B4353F1C44E5004E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1027.mst.g1p3okhzl","md5":"900DC178CDB1D95E4E90FD0A385B68E8","sha256":"A86FD800CAA2685984EBB4CA63DF67987F0009BA43381A06F48E1F2FF79F8053","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\pictures\\sample pictures\\Penguins.jpg.g1p3okhzl","md5":"3CEFB8D4CFEBE33D713B5AEA0BFF9270","sha256":"E89F68AA13D18D60FE3EE4055EB0235277137F640A65503FE7915B59128A355F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\pictures\\sample pictures\\Tulips.jpg.g1p3okhzl","md5":"626BA5DF52DF7B7377943A179246D6CC","sha256":"66BA0396B24D025FD2C849EF59DA52BBBF1E2C3AA0996619A61FE8562F8DDDDF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1028.mst.g1p3okhzl","md5":"AAF419C22FB0E166DC1FC0D6315CF50A","sha256":"6F7DF97F79EEF0736595AAC8381CE7FB13FAC33527928181D2F6A2AC62FA26B7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1029.mst.g1p3okhzl","md5":"945270D8CAA1936D1F0AD0D3B5601213","sha256":"6AD93E350C3A8610CC3F2B3ABE7A3666E3847F5A0E0561E72F3041E27445C96C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1034.mst.g1p3okhzl","md5":"C2C7F58BF4000FF5F46693159EFC3C08","sha256":"13137B7B87F5EB7C4F11BF204560F2DB7FE0387D1BD03C6C3566AE3975D43307","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1041.mst.g1p3okhzl","md5":"0DAD4DD8C9B17ECF2FB275CDAEE43B84","sha256":"09432710EDE6A3B486F1E6302139928C7D758375B096DA8F5FF9E76D9AF13AEF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1031.mst.g1p3okhzl","md5":"AC00D460B4DDE264CE7113F4AEBA3C24","sha256":"D78812CDB0AD862F2699E5E0E1193EA71000EB6C64ABA6C3D010163C22ED788B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1030.mst.g1p3okhzl","md5":"CEB0787C5F2DA96796DBC750E11B7478","sha256":"D74C4D54207E92CA8380A9F93E8AFA7321DFB6B97B73ADDB5FD76306D318A755","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1045.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1048.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1049.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1033.mst.g1p3okhzl","md5":"2FA4785BDC0A6670C9BEE31FC3700AE4","sha256":"B2D33B80C6C826C5A13F724B9FA0847E3050823BA3BC48286764EE479D9FA6EE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1042.mst.g1p3okhzl","md5":"677DB642351027C4B2B65B9894C9FBF1","sha256":"44B8E99E63FCD5700B6FC84F013A15D2F5CCC64ED45372F535BD507DFCC97A7D","type":{"value":"gpg","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1035.mst.g1p3okhzl","md5":"B5A1E95C8FEE9FE8B3D9195F8D23072A","sha256":"E80E037FEEDDC86A1688DC901EDF4CFA129EFBEEEAF0488E1B2657B2B290560F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1036.mst.g1p3okhzl","md5":"69FE779710B3501EC9DA857DAED14B7A","sha256":"B973F6526F96883E2D569AD5528A060AAAE6B0C86FECEB257AC3080A323F0A60","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1040.mst.g1p3okhzl","md5":"632169A82FEE7343E3AB206A9BB3F088","sha256":"2958BC6F9B5482DF6F634CE3D046CB0446EA06ECDC632D15B1E1AEC422A6E1E7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1038.mst.g1p3okhzl","md5":"7A4E779635EB6F70751381540943EEF9","sha256":"F1EBE39F59E400AE32077B94E4530BB5721AE7C2BA64CA3AF7EF62241A50BFBB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1043.mst.g1p3okhzl","md5":"82D7395658C600AE3DEC817755DAD463","sha256":"AE4B2CB9E997D36593EE71AC1B1273739388751D1DCD37A649F5C430D86B07F9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1053.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Adobe\\Setup\\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\\Transforms\\1055.mst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Crypto\\RSA\\MachineKeys\\4e844619b945c4008163b9cac550bfce_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1049.mst.g1p3okhzl","md5":"C3152284DCBEF906AFEAD117C5E7609B","sha256":"CC4893C01339D5B7DB6A999FFFFC2BA4C0F3671396BE1CE08E8F4345C3CA6A62","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1045.mst.g1p3okhzl","md5":"36306A91FB9FC977F0372C05D274AB98","sha256":"CC52DB46E1EF408E40C16EFADDD0025BDD17B41A63ED040796B9AFC678E946E0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1046.mst.g1p3okhzl","md5":"F5D4751A98B686073ACF661A7398FE00","sha256":"584013C35ED5E42B9550394478B8B9B94C65C64A78783EE78372565D3EF6687B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1050.mst.g1p3okhzl","md5":"4F462BD1C002C542422AA4ED03758AD1","sha256":"CD6A4245A5C1B91BB96CBB0EE8C8D71FDE7FF57262E2DF86D400F3C68D861C1F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1051.mst.g1p3okhzl","md5":"D46B1380EEB352F749F05C6349A43AD0","sha256":"6F8F2365D766EF0F852ED5B4A3A807DE8A5143E1943257F29A10F6B5F2C7223D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1044.mst.g1p3okhzl","md5":"FE3B8FE37969E9DD02C324593CDD3F5C","sha256":"F32A5C4D59FFD04F188BADD1998D38B6936D22531C2A285C4E7C1DAA2D1CF33E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1048.mst.g1p3okhzl","md5":"ABD9A6203A4F20A34BA74CBBFABA3877","sha256":"1B3F1BE40B2BC2D64A3BC7188F291DF88060D70E1099EDDF68669A8DF995A38B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Crypto\\RSA\\S-1-5-18\\6d14e4b1d8ca773bab785d1be032546e_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Public\\Videos\\Sample Videos\\Wildlife.wmv","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1053.mst.g1p3okhzl","md5":"AB05F1C728ADE05D734D95287DA2D636","sha256":"8FD62F764F6CCE01EAABF6B19D90ADB78FA35FA6EFEA0841ADAE3852CE3F4A4A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1058.mst.g1p3okhzl","md5":"1D7AE2583550DFEAD591E51FDD1213BF","sha256":"7C522D23E8270D4EB763ACF47DF7A946CDE90AB0D126EAEBDFAB391D3D2E6F28","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\assistance\\client\\1.0\\en-us\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1055.mst.g1p3okhzl","md5":"CBD0AAB01AF78F9168F1F22DE0F32AB9","sha256":"4C51065B6FB00E988207C8AE8A38A50E27DD185744A3DB63544A29FB73816D9B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\2052.mst.g1p3okhzl","md5":"D2F63831B51DCB568598C47E06519BD5","sha256":"FAB25F64E132BECCAFCA8C5B14435D3656BEBB72589B623FC83A3D7C2314B7CF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1060.mst.g1p3okhzl","md5":"10B9674E8913F2FCE3BB7DF89D940DE1","sha256":"FD0D69CD78A5398B20709958B6CFAD317A612CCB8EE12341A6CED6CC76D64378","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\adobe\\setup\\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\\transforms\\1069.mst.g1p3okhzl","md5":"62F4526179FB5B738C46EADEFFEE2D55","sha256":"85419FE630422F0EB470C1B9CC5047FC2CA09AB9D082CFBDD7E4AF993A91A606","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\crypto\\rsa\\machinekeys\\4e844619b945c4008163b9cac550bfce_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"7AE8DBEB642369AFC1B2C3BF0C565147","sha256":"632D8DB1D518253D97096460651E42E0B4E998A884870E70BA7D91701FEEB8F5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png.g1p3okhzl","md5":"1BB87B893FCF53672D97B7E042D16295","sha256":"B46BBA1667354959F5BC5BB8C2124280CA93B4D4ACC2058C8320354ECAFF45D8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\crypto\\rsa\\s-1-5-18\\6d14e4b1d8ca773bab785d1be032546e_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"2874306FA7AF5671C8A6CCE6F2BBD032","sha256":"CB3706168493BC5CBBC6D0787761B8B0E3D8BB5FEAEB5D298E1572C3A46B1421","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\public\\videos\\sample videos\\Wildlife.wmv.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\behavior.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\behavior.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\resource.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\tasks.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\tasks.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPABFN.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPABLN.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPADFN.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPADLN.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png.g1p3okhzl","md5":"16BA6C5B80645154AA4EB438A094DBB9","sha256":"8FC8DAF401313EC891E4E1DCCC86833659F747FD64EF23ED787765BB0FCAFA7A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png.g1p3okhzl","md5":"1F5E1B6F6EFDB5396598CFF3510458B5","sha256":"3BD33C8EE1667BBB5E0FD5AFEE96F3D197E19227F8A36A1470E6A3773AF95D11","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\behavior.xml.g1p3okhzl","md5":"D28979EAE82FBDB6373A2885B50AC516","sha256":"69E7CA32AEB72F9AC7A6A64C6A78122DC84EE532EE1685B733E3C0F582414901","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png.g1p3okhzl","md5":"811148A22A6AF9A1FFF99D94D3A5B914","sha256":"B322F6C4B47756E34897F4A12B80525B881D0406B74768CB75F394C51B1AAE10","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png.g1p3okhzl","md5":"837043EF13FAB6271BA8FF3A450DA5CB","sha256":"E96F69B94640689DF93E49AE999CC701DD44B843AFBEE4BEF1F61B7C9BD480AF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\en-us\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png.g1p3okhzl","md5":"C558D73E1114B62C545D77440A1337CC","sha256":"177EBE3C03C9FB2C653C069E0BDAF5E23448DB162517F93E8D97756F964E1531","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\behavior.xml.g1p3okhzl","md5":"F91ECB20523D958689A71A9D9AB87B3F","sha256":"5D957EF7AA916450F21FBB724522E0B8A1DA9E2577FE224318019FAE78389067","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\resource.xml.g1p3okhzl","md5":"D32D75A5DB930390BB6CE283433CBAC5","sha256":"C2E56A255E446944DCB7774F1CCFD71A9157425493BC568F1B31D633BFBDE717","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\tasks.xml.g1p3okhzl","md5":"F40DF866F2BBBD2CD6D3E05D7563DCAD","sha256":"FF8DDE67D8E932ED08B5E1875A55EF57814750C786961C326FF9883182DF8307","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPCH.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPDW.GRM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPEX.GRM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPLN.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPNC.GRM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPPR.GRM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPPSGF.FIL","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\tasks.xml.g1p3okhzl","md5":"30BE1ECD199CC36E298FCB73D529C60C","sha256":"BBB8C894293D27A77E3EF7339755E05A9343C0F870D7B32A31761F659E8DB271","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\device stage\\task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\en-us\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPABLN.DIC.g1p3okhzl","md5":"96FAABD845329489F036D6CC83A3E2D0","sha256":"389A3717D7E091D5426B2C3088EBD680E4DCC5F0C670ADE6991C74A1ECF20E2B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPADFN.DIC.g1p3okhzl","md5":"C2403CB0177768ED32C04B314E648927","sha256":"F86FC1091EA34BD4E087E2F06BEC36A1745DE8E90332B7C62D9B863536C0D0E5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPABFN.DIC.g1p3okhzl","md5":"BC7F580B7523447118E1FEFCDAA1C208","sha256":"5BA6B1A57D417E51AB67082E16022C4EC111E32D584889E477DB10381F31F80A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPDW.GRM.g1p3okhzl","md5":"8B5891B3CC4D96BB02017CE99BA4E035","sha256":"26F724B89DA87B5AB6B93006454A2940D0D0428564417648E52580AAAD845B0D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPNW.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPSB.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPTK.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPNM.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPNM.DIC.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPZP.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{0199BAF4-AE21-4C86-946D-54E39EE6A6A2}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPZP.DIC.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\IMJPGN.GRM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPADLN.DIC.g1p3okhzl","md5":"CA138D3217021D6268AB854658EC8669","sha256":"A63F27B41F5C4888827C4ECD883AB4D2549C91F9867BCDE8ABFF41D9A2BDAFA3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPEX.GRM.g1p3okhzl","md5":"539921DBACEF62DE3F7972A9662C6A5F","sha256":"6ED7E1FEEB4D4A204C3A9A4D615EEA4597FF46939C8CC46FCB8EB607A0DD4E08","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPCH.DIC.g1p3okhzl","md5":"8CEC22D98C125BA8C109872E3BFF227E","sha256":"4DBA13C3F51CA5150CD7A8E7E218FBE5C021D90C6F4FA2092F6EB7FC7BABC72A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPNC.GRM.g1p3okhzl","md5":"A95BFB36CA97C59A3353464D1ECB5ABF","sha256":"4AD2CEE65D99A44025A65C0D9C40FD4B35D86BB7FA0743C08BD80D76324FA26D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPLN.DIC.g1p3okhzl","md5":"03735AEF0D36933F0FE15C000346C0C5","sha256":"2DFBCA4DED492B4B1BA9A0F4F3CAC264817695512BB358CF3B65D6564E19758F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPTK.DIC.g1p3okhzl","md5":"EE23284AC08A9E5840AFC3716418F57A","sha256":"457185542AE86F27357F3AAAEC06A1CFADFD769AA4DE5290B7AE39904C994433","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{0199BAF4-AE21-4C86-946D-54E39EE6A6A2}.pld.g1p3okhzl","md5":"441B00397EAE45B0A86AB887EE0A8363","sha256":"4753601E8CA58AD02942FD67B247A2C957DBE4D7690BC556540C4B725944B585","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPGN.GRM.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{4517AB11-588C-4E27-964A-661F347E1133}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{2E034BC6-A47A-4892-B772-8C4D610B84B6}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{58AF34E9-2F1C-46E6-B65C-713E7780FFD0}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{5FA8643E-9110-4853-A536-C3BD7350022A}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{2E034BC6-A47A-4892-B772-8C4D610B84B6}.pld.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{6C79051A-1C85-4BC9-9AD2-946B1C10BF0D}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPST.DIC.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{759FD0A2-827A-4980-B78A-BCD4A9FD73FD}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{C3E1CAA2-EA34-4196-AD90-AB38B4D4B776}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPNW.DIC.g1p3okhzl","md5":"3905049FDC1C3941B9EF48EF461D7197","sha256":"21597BEB7F817BB4DE6BCBDEBDF86EBC71BB7EA80C461851BC02C27A28AE70C0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPPR.GRM.g1p3okhzl","md5":"32AF03575DEA197F20D361CDDDC55A75","sha256":"D91085E3483A4E1A19966927C75B2A93F4974611BBCACBE291E7EDD827C64B6A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPPSGF.FIL.g1p3okhzl","md5":"369E7B43C0F0A7C87012A4B18196F46C","sha256":"A9023C585210BB6C0D0A7F0E07D8D1D3FF7772D0A37A9B22A27DE558561955C7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\IMJPSB.DIC.g1p3okhzl","md5":"0725824AA00E03635DB689EB8F582B13","sha256":"7F07EC09AAF1C8E81C5E731A83C15B484EEE8731E9E8B4101BB542C9BA758AD6","type":{"value":"bs","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{6C79051A-1C85-4BC9-9AD2-946B1C10BF0D}.pld.g1p3okhzl","md5":"A3590D8B33B53A368358B093946831D8","sha256":"7E544203E70125DAB248FC1EC367827EA6434EFAC6AC9724CFD35EF0345420B3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{C51A4D7C-23F6-4CEF-AC76-BAA05ED7C19A}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\MSHWJPNR.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\MSHWJPNR.DIC.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{E41AD7A4-4C2C-4E07-B0C2-E9C2B3499FA7}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{E87CC8C1-6F9B-449A-A719-1FC442EC9CB7}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{2EE333D1-152D-4063-B5E4-0D5A90F7C6A8}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{2EE333D1-152D-4063-B5E4-0D5A90F7C6A8}.pld.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{9AB83BEE-14FD-4682-81DA-713217F4D5B0}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{9AB83BEE-14FD-4682-81DA-713217F4D5B0}.pld.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\HELP\\IMJPCL.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\HELP\\IMJPCLE.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{759FD0A2-827A-4980-B78A-BCD4A9FD73FD}.pld.g1p3okhzl","md5":"BFD0B164780281B31E49138043388109","sha256":"73429D1C60E72AECDAE5956487854A2FD5129EF776D7839F21328A311D87FE37","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{58AF34E9-2F1C-46E6-B65C-713E7780FFD0}.pld.g1p3okhzl","md5":"873A546884080F1C749CD214B4DE2C83","sha256":"C04F907111767BA0F087AC7AB94DF5F9DE39592A14B48A0E3F9D8BCBF1C6AD3D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{5FA8643E-9110-4853-A536-C3BD7350022A}.pld.g1p3okhzl","md5":"905F07004619EAC52F37FDBC1D4E3E05","sha256":"0F6D5285488442E4648400D6E59A2520D6BF176E5A09D681CA83ADE43A2DD9EC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{4517AB11-588C-4E27-964A-661F347E1133}.pld.g1p3okhzl","md5":"539C1B304FA15F6B519EA97014E795D3","sha256":"880420236FA19112D366697DC7F1D0E10C33E74A708DA54BF6164171706E8A7B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\HELP\\IMJPDT.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\HELP\\IMJPDTE.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\HELP\\IMJPTU.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\HELP\\JPNPADEN.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEKR\\DICTS\\IMKRHJD.LEX","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEKR\\HELP\\IMKR.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEJP\\DICTS\\{DBC8CC9C-C557-4F93-A061-36F2B0A695A7}.pld","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{C51A4D7C-23F6-4CEF-AC76-BAA05ED7C19A}.pld.g1p3okhzl","md5":"094274A30217990665812549AE4035CA","sha256":"AC83D03A7F452E90B7962E3FADD3E4E49933832B5FB64832FA59FE7B138D5091","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{E87CC8C1-6F9B-449A-A719-1FC442EC9CB7}.pld.g1p3okhzl","md5":"CD4A17674C2FE9200F43D88871B27B26","sha256":"B61B59668CECBBB558640732DA35A8934A7F98653CDCD966E5AB6CE3C7E1244D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{C3E1CAA2-EA34-4196-AD90-AB38B4D4B776}.pld.g1p3okhzl","md5":"9D13A4899BC1CCA4337A448AFE5046FB","sha256":"1D6B8B9C1A7A945879FBE67C7CCF430D426DFC209FA87F6CC177F3C4CDC4F047","type":{"value":"ini","type":0}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{E41AD7A4-4C2C-4E07-B0C2-E9C2B3499FA7}.pld.g1p3okhzl","md5":"3B07D203014E8C4C4F5A06ECA9423041","sha256":"E54A7F6999CC68ED3DBF5749B107242D7EBAA2B933828129D78ADFA5B36D7219","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\help\\IMJPCLE.CHM.g1p3okhzl","md5":"5CE46C8C1257650723235C8567DE9D02","sha256":"91D7FAC6D59B0869AA18B73DB64310CA2351F2A76016616710681554371F3653","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\dicts\\{DBC8CC9C-C557-4F93-A061-36F2B0A695A7}.pld.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEKR\\HELP\\IMKRPD.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEKR\\HELP\\IMKRPDEN.CHM","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\ENVELOPR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\GRINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\help\\IMJPDT.CHM.g1p3okhzl","md5":"964138890E30613AE1AD54106CE1B5F6","sha256":"DAE59875E4908F6EB258456890167477E33A1E175C0F5B12F9E01A9735CD0635","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\MAPIR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\help\\IMJPTU.CHM.g1p3okhzl","md5":"46BADD5C9117DD97A1A4841A9BC9801B","sha256":"F60484A87BEDE3E4B0758D8A15626A7FC7FEF2680DF760AD7025D220FD0E3F81","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\help\\IMJPPD.CHM.g1p3okhzl","md5":"F51D23C6DBF761581F3A9A9161BF72F9","sha256":"9BBAD0E821E12F016C65F6F8A06E0C4AC8E039A4CB961AE2CEEE3EF39DD4E934","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\help\\JPNPADEN.CHM.g1p3okhzl","md5":"ED9E407897086660B05BD980F5EE0B05","sha256":"1556C08D90710E29B48DB0151A8738A089495067F912BA9485883D94EA263DC0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\help\\IMJPCL.CHM.g1p3okhzl","md5":"5F6794619179C7DC2CE236CF49FC23B5","sha256":"79A9278600F225BA5B56622562FD48DF4DE1A16F8BD53B0BA5A9B36FCC2AFEFB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imejp\\help\\IMJPDTE.CHM.g1p3okhzl","md5":"D23B6BD69BF9EBCD79548D42BA61957F","sha256":"5186334AA2E63213F92B765C57C843A86445926A54492D19B688440AFEF84913","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imekr\\help\\IMKR.CHM.g1p3okhzl","md5":"54DFE7325343839C81416DEFC493BF21","sha256":"F3BAB7460FA611D0C02851D387F003EAC33D93F89B775868946C36F4AFC03E44","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imekr\\dicts\\IMKRHJD.LEX.g1p3okhzl","md5":"F134CE6E9F4776A3158338CE11281F74","sha256":"A035D6F2741A26E40957C01D87720F8A1B2686F80324C24D11B9247DFFADAD62","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imekr\\help\\IMKRPD.CHM.g1p3okhzl","md5":"D3032FDBDFAFE7DA109475165E8BB39D","sha256":"003F02487106560537E03E3C859D9C7DCFA8202D470CC742916F7565C2659686","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\MOR6INT.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\OMSINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\ONINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\ENVELOPR.DLL.trx_dll.g1p3okhzl","md5":"20F213E906D337772985F321BE924BA9","sha256":"09CCAB4BE080DED31125ABF04BA8B7D96677FCC1B451F30A6956776AA833D34E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\GRINTL32.REST.trx_dll.g1p3okhzl","md5":"F81C58C6ED013D72A34B4CE6A15BEEC7","sha256":"68EA94DD9E311F66706580D00695DFCE3E264F04D882C382C74DC5663C03AE47","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\GRINTL32.DLL.trx_dll.g1p3okhzl","md5":"7533208E9C11E1CDF85A7F0978A463DB","sha256":"377BC62765B700592635628A7B2CF399F73A3A1E7D3B6F696FBE06B474CD226C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imekr\\help\\IMKREN.CHM.g1p3okhzl","md5":"1D6F5BAB21BF1F3D78C650299F6C2775","sha256":"B7F34E7D988F022307D8CDAC480D1869EC5496E3439A3A4A321D215F4298F884","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imekr\\help\\IMKRPDEN.CHM.g1p3okhzl","md5":"610FCC02605493DC08058A5D32F6F529","sha256":"5ED80EE53EE221D1B81FA18E222153244D6B869FBCA56CDD55E7571C9914C36B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\PPINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\PUB6INTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\IME14\\IMEKR\\DICTS\\MSHWKORR.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\MSOINTL.DLL.trx_dll.g1p3okhzl","md5":"4A84B06584310BEB648BA0DC8B56BFCB","sha256":"2C357D3B4D2A78BE408DE9758EF8137E65A092560E35EA6F4691D816FE8C8FE5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\MOR6INT.REST.trx_dll.g1p3okhzl","md5":"FEF28849B78BB39BAC767545D51D803B","sha256":"8407CC061F56F7EE7C1D595F90B7B57E1A7E1D7419255B25F919A945624F292D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\OUTLLIBR.DLL.trx_dll.g1p3okhzl","md5":"B42F21CD84F38E3C3DB6958A46606F37","sha256":"CCE712DB79107137A59B93D13148CBE9440EAD5139F957FE0931C2EBB2C34782","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\MAPIR.DLL.trx_dll.g1p3okhzl","md5":"C2B409EAF870675F2A4288BAC7751C13","sha256":"1F000F05A02ED68CBD8268B74C41B97D832797DC9D2F2F62D16DA43C7DFA141E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\OUTLWVW.DLL.trx_dll.g1p3okhzl","md5":"18A5D9C2858B287729782A0CE17A1E68","sha256":"A59FE0ADEEB149998C4AF55EB42CFEDF217AF438D55143312A1A0C56DC0CF161","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\PPINTL.DLL.trx_dll.g1p3okhzl","md5":"1647F435BC1E63837349B4E2EA97B6F1","sha256":"ED7806FFD5E258241CE4CE7AFF34074F39362E9DA6A6663B807A704124A9858A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\ONINTL.REST.trx_dll.g1p3okhzl","md5":"D97F682367DD498C41B10E91610604BB","sha256":"30DB75C9E317D9168D4DB1B0913462C226FC058A0CBCC859651FEF9DE88CE96E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\ONINTL.DLL.trx_dll.g1p3okhzl","md5":"D9E2468478306011F4BCC9E5A5FCDB94","sha256":"168402D239352215EC97769F3550781EDCC4E506547338F6C4E3DEB60AF6112F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\OMSINTL.DLL.trx_dll.g1p3okhzl","md5":"997F326FE18651E190D3A5FB5E874FE6","sha256":"6B146A2D7EFAAC268BE3BCA34EB514860D7A4C580F4F231FB6D409EFFEDD16C2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\MSOINTL.REST.trx_dll.g1p3okhzl","md5":"AB42DA2B961D6FFFCCFF1A6520F54337","sha256":"4DA3E4534D28D0A829603F15BAE991103EBA44033D2D2E1EFED5DC287FE01C07","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\PPINTL.REST.trx_dll.g1p3okhzl","md5":"08DF0A8D2581EEABF91B48178594F2C6","sha256":"2A3551F73074EE583B0EC0F65B06800222A43F31D3BEF6CFA7989B5BAF5AE34F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\OUTLLIBR.REST.trx_dll.g1p3okhzl","md5":"D43CBDFC9C230CB48B7F472A04C68298","sha256":"9F47CECB0312DBF7AB55517324DD39139C98A5D13CBC5D656C26FA2CA7E23D27","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\PUB6INTL.DLL.trx_dll.g1p3okhzl","md5":"B29F87B6AA9C6B5002F26EFFF81F0CD1","sha256":"58B48FA6417FF583DB5A0CFE17F7E662B9F5AAE2ACFBB183BDA6465D397EFB07","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\ime14\\imekr\\dicts\\MSHWKORR.DIC.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\PUB6INTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\PUBWZINT.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\STINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\VISINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\WWINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\XLINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\WWINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\XLSLICER.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1031\\XLINTL32.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\ENVELOPR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\GRINTL32.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\MAPIR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\MOR6INT.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\PUB6INTL.REST.trx_dll.g1p3okhzl","md5":"860A60C1B93DCD7C9C34C3C7F9656791","sha256":"374E531FE48A6FB7ED155CFDFA6BE67D0D2D7C29EBEA2C798EF17B890066A862","type":{"value":"mp3","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\PUBWZINT.REST.trx_dll.g1p3okhzl","md5":"8B8FA760892A5A85DB9A99E665104569","sha256":"18F6B4ADEFF9E4F3FB0F82FB94E7D050F2B6806F396EBA7940FF121088E60AD5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\SGRES.DLL.trx_dll.g1p3okhzl","md5":"67879026A29F3D9C5EA3FBD8D2D9BCB1","sha256":"0DCEBAE4B34B2686B843A77A284661E2C1C24A174A5738C062B908B6410E02F2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\WWINTL.DLL.trx_dll.g1p3okhzl","md5":"AAE94077CA8F76C904E7F6912470842D","sha256":"EA306519DA4F8D1B48EBACACFF326A7CF97C9E38041E25DC2DDB9CE33D225503","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\VISBRRES.DLL.trx_dll.g1p3okhzl","md5":"258452117E285077A1EB0339F7428806","sha256":"B370C735183CC6A42C0612ABAD16F5924D6005F96B013986B6BB1CDF7752C725","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\STINTL.DLL.trx_dll.g1p3okhzl","md5":"04109763CFFA39FF61859F7CFF5EA347","sha256":"467CDF99FAD9CC6FF6150B7349B3B1DF6933D6EA1877BBBD06C6ADC5F4F4FDE9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\VISINTL.DLL.trx_dll.g1p3okhzl","md5":"BDA0E09CB69CC1C716ECCC130BD21417","sha256":"043F78E826BE6CA088BE0227F19C51BDE011F293EC582A340469D6EFFF256DA5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\XLINTL32.DLL.trx_dll.g1p3okhzl","md5":"BBD231CF23E851909E65AA793E770AB5","sha256":"96E080991FB8E651615441DF9D444A4080BD50DF3C62E430383FCFA83DF65700","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\XLSLICER.DLL.trx_dll.g1p3okhzl","md5":"8D00614343FB0AA035775B6E7985FFED","sha256":"58B387D95153B7E949EAF275486DA249B047BC5BCAE5775564B760A276829677","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\WWINTL.REST.trx_dll.g1p3okhzl","md5":"C6720F34D99C11E644BC724D51B23F03","sha256":"6DA35360CD6A364E47B1958C924DAD290AEE7159A8F26B359C7BD80CB6FD6921","type":{"value":"vc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\ENVELOPR.DLL.trx_dll.g1p3okhzl","md5":"AD18DE6F9882F97B120E0CCA52D55884","sha256":"0D48031114630A7509BED016C1D9AE529A4245869DB68BC32EAE087102543F68","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\MSOINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\OMSINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\ONINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\OUTLWVW.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\PPINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\MAPIR.DLL.trx_dll.g1p3okhzl","md5":"C94CEB7AAB30F71C66488D5FF305159B","sha256":"1D37EDFBB4CCB3A9D63A35C90D18324993620AB997259A7C26981396C2E75AE8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\MOR6INT.REST.trx_dll.g1p3okhzl","md5":"B0744A1A583511F17BEA73A657ACD73F","sha256":"C1FCD7B3AD2AEF99500577028E0D2B22245313F771D97A5D7D1866C11016EBE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1031\\XLINTL32.REST.trx_dll.g1p3okhzl","md5":"B6AC6B93FA626B665BD11E6E6EC2CDC7","sha256":"FD9992ECB5C8123111B81C2B6C38F16A7D7F0CC9B20521587D64B5095377E811","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\GRINTL32.REST.trx_dll.g1p3okhzl","md5":"5448C8513379739728A2CBF9A81E4159","sha256":"E8C57DDF4E7DA99701F80C32067339BDA7F1047E00839B1EB0C00B297430A50C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\GRINTL32.DLL.trx_dll.g1p3okhzl","md5":"F829CCD574A9D243FF56B8878179420A","sha256":"BE3170659FE64AF34D269597D499BAE84862887CBFDF4FDF269BE1678FE484ED","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\ONINTL.REST.trx_dll.g1p3okhzl","md5":"6BDD5351B941A333C9A1E8983448F5B4","sha256":"DA6E60B8EDFC9D52CCF0CF493413259A2FA65DE6936F78F5088848F802B5C4F2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\OUTLLIBR.REST.trx_dll.g1p3okhzl","md5":"1C4267625F47C5F793F41214940300AD","sha256":"F6C266031684F05D2D0EE52B55A7876EB0ACE090048D5443D696775063D642DF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\MSOINTL.DLL.trx_dll.g1p3okhzl","md5":"3D0E27BA1730F197833811F1A5A969A1","sha256":"91416D2C2C561F3341AA2873BB65F4BC14523C62EB369C83933A6A09EEB6935D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\MSOINTL.REST.trx_dll.g1p3okhzl","md5":"685E3E2A4DD0E2089F6837AC398E0D59","sha256":"B9DEBB06BB410C17308C16022C909FB04CA32FCC6D943B5134F5B6713B838AD6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\OMSINTL.DLL.trx_dll.g1p3okhzl","md5":"2B9A0D9C5457569DF82D1C91F965BBDF","sha256":"0E7D17DD2675E3FF7DB96AB1A52DA08809B5909CAC52E332B2B15AD6C46CF795","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\ONINTL.DLL.trx_dll.g1p3okhzl","md5":"CE9F1DE79663E668116B256FFA7FC215","sha256":"B9E77DA81FCFE375CB351EE292A12875EF1130C36DFB02DA1A17CB7F4F3198C6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\OUTLLIBR.DLL.trx_dll.g1p3okhzl","md5":"6F7C585BBA379A24D50FE6F000FC5258","sha256":"475221AAB25A4D444898BDE6A852F967D369C8DCFDF0206A1C08964882CF66A8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\PPINTL.DLL.trx_dll.g1p3okhzl","md5":"3B851413A8BCA21A7FD28F7C02CBC4EE","sha256":"BAE0F9261048D5C99DD4E7A01741FC4E930A09058F5D21989C5FA5FE92F041D3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\OUTLWVW.DLL.trx_dll.g1p3okhzl","md5":"82C0C0EE90A0A26C823671187E94474E","sha256":"6BEE722B4A55A0C66DEFD871ABD4BF6A386BA681206278C2FC5FF625384BD551","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\VISBRRES.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\VISINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\WWINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\XLINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1033\\WWINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\ENVELOPR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\PUB6INTL.REST.trx_dll.g1p3okhzl","md5":"6738CB43C75CFC895B854B2BB67B507A","sha256":"ED2A98B371D28DD73E5F2EB7384AA787A175623315BC978D3D639D12F7723162","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\PUB6INTL.DLL.trx_dll.g1p3okhzl","md5":"A6BE94FD2AC004EDB08D50E146F2784F","sha256":"75CA15AF078E220A5A53CFF6DD44AF373FAD3CE1A6E8580BFD3E7BDBCB8422A4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\PPINTL.REST.trx_dll.g1p3okhzl","md5":"0D701F6762F3FCD16F777423AF11DD5B","sha256":"7279B92A2DEF7A09C1DDA926D80B7190FA0204F73F8E39F4B797033099CDBDF7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\PUBWZINT.REST.trx_dll.g1p3okhzl","md5":"39288845D2C04B0674C57DEF2FBA7267","sha256":"147A68AE554700FB63CD7CE9F830D843AAC0A53E672A635EBA6B01F33CDA7A72","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\STINTL.DLL.trx_dll.g1p3okhzl","md5":"BDBC0A72DD356AF0C912168E6FBBB61B","sha256":"6C418E5CE6E5D84B10FC1B360C05A722EBA1343EB7BBCB40F53DA2338CA32D95","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\SGRES.DLL.trx_dll.g1p3okhzl","md5":"E5C17955F8E1DD07D7924979AA83062B","sha256":"02A1371CD8F9705C4562C1D7264641876AFA43F7168E2CE2FCB3E36B19DB59DC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\WWINTL.DLL.trx_dll.g1p3okhzl","md5":"6ED62AF3737E6E69457D988747C66408","sha256":"EA6EA6638039578087B61B1E5152A4EDB6DF5C6C779BEC58F040174A982AE8C5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\GRINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\GRINTL32.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\MAPIR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\MSOINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\OMSINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\ONINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\VISBRRES.DLL.trx_dll.g1p3okhzl","md5":"AC9CC4220BC4CCE8C652253C4495B807","sha256":"872476A54A205402307479F91C79845B2EC109485E34AF45E50F433039B45D4A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\VISINTL.DLL.trx_dll.g1p3okhzl","md5":"44B555DD0BCA72F831EF6B3FC76905BA","sha256":"D19A71B077B96869E08F993CE906C70ACDB34574BE2473B05F7842C8F5326939","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\XLSLICER.DLL.trx_dll.g1p3okhzl","md5":"6B8472EC1D7C9E69859062617498978E","sha256":"1A2DC06BBD4E0E5971F3AA28A0217AAC5C58CBDDD6500451C7C94862DEF313BD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\WWINTL.REST.trx_dll.g1p3okhzl","md5":"C446F430E751D0323E04E1FD8314254C","sha256":"903CF3E264AA2D50CB6D3EBD5B07AD1CBB6AAEC67CC91914906F368AF16BD0C8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\XLINTL32.REST.trx_dll.g1p3okhzl","md5":"C0C2B98335F2DC2A2425AD5B4DA33189","sha256":"6472644D58400116A7ACC6CD7B658E400723C783D27593FD0CAF8B35FBE6E241","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\ONINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\MSOINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\OUTLLIBR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1033\\XLINTL32.DLL.trx_dll.g1p3okhzl","md5":"7AAEB9CD78AF5BE10B4F0E9EF3FE9E5D","sha256":"7D1A5D0C4BA657B74325ABEABBE3A35E6A6A4CCBFEBF5C550D0DF64F6EA04BF0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\MOR6INT.REST.trx_dll.g1p3okhzl","md5":"D78AFE1C0A2B7441A47E108EF79E378B","sha256":"6F4896CCDB27543FE26ECB9C9802307227E776BA2059925E0C4031A6D61BAA93","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\GRINTL32.REST.trx_dll.g1p3okhzl","md5":"ED57E9D58742F56DE8D7815FC6190890","sha256":"A2B4469C4A4B779391E30F6B83F878ED1940043B1E4EBC9F648B57728875288B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\MSOINTL.DLL.trx_dll.g1p3okhzl","md5":"911F581C5D75C669C58ECBE099852CC2","sha256":"B3537AA2D4CEC87F0A6FC897425884BF2A0C372F1EDA81EC23870E9CBAF2DC19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\GRINTL32.DLL.trx_dll.g1p3okhzl","md5":"D36F7FD886BAE5891D93A10EAAB4A93D","sha256":"6E705184AF994B4E3659277CA47A7C486578763B2302D989C6428E79EA551E35","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\ENVELOPR.DLL.trx_dll.g1p3okhzl","md5":"2E0239C0C6D9CB0CB3D0F5D8EF7B3AF0","sha256":"8D041F9A64CEDBEF62463E7B59F7D4A5BB566053374C9D6574A314EB639CA5EB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\MAPIR.DLL.trx_dll.g1p3okhzl","md5":"745E7F5C85361955ED08993F27F0BA7D","sha256":"9C5C5EFF6558FCFA545E08FC33E8EF04AAC6E304F7C7EB364E34A9B635A98EEB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\OMSINTL.DLL.trx_dll.g1p3okhzl","md5":"DA8AF2701454D5D711D61806A498BCB2","sha256":"6EE137297A683C0A5E00BDE35BB3AD37D7992A61C7CCA9B30658B5039C4F4253","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\OUTLWVW.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\OUTLLIBR.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\MSOINTL.REST.trx_dll.g1p3okhzl","md5":"D71CF0B7950EB395C052CA6EEE920C2F","sha256":"229E1D24835C1D1ADFAF33CDE6BAADBBE89F7A821D9784C93DB1D56DA9529E96","type":{"value":"bs","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\PPINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\PUB6INTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\PUB6INTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\SGRES.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\VISBRRES.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\VISINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\ONINTL.REST.trx_dll.g1p3okhzl","md5":"8BA88FDE5A2A8A082CFD55EE746DA4F2","sha256":"06CC197A149B0D18F5E510DA4A95517509C48978ED332176B8BF22EDE7AD9FF7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\ONINTL.DLL.trx_dll.g1p3okhzl","md5":"C62ACE1E6EFA632B2EFF4F1BE1E230EF","sha256":"B22685070CAE03E62BAAAC9625C079EB6CEE5E901BB6B4AB8B0438488DF67EC3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\OUTLLIBR.DLL.trx_dll.g1p3okhzl","md5":"37954E2EEC420E6E4FC89AAC0C4E60AC","sha256":"5F837FB8C6FC1BEC577124645329C41A9BECD35DC3D3D1B3F25A09A0DFE235B6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\OUTLWVW.DLL.trx_dll.g1p3okhzl","md5":"FA2E6D8B28396B51E662FFC9709CFF41","sha256":"A44978E718072F7FA6FCB3B8EC0EB49B60216BA279A6F7170C89FCB646145678","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\OUTLLIBR.REST.trx_dll.g1p3okhzl","md5":"9FD5D4BEAAEC806F2A3D7FF5964F7361","sha256":"75F4A5C14AF387504D1BA4006A056C3E2FD5EC9D7B7D44519EAEBD55782ED627","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\PPINTL.DLL.trx_dll.g1p3okhzl","md5":"071D2FFB7D289C6AEFD182A56A8D65D2","sha256":"D418940017C10671A741B6A4FF399D5E23218ABD75F0B1B8B2CB50ED821F00F1","type":{"value":"img","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\SGRES.DLL.trx_dll.g1p3okhzl","md5":"4C42BC0C68A28E09110AB169F783729C","sha256":"F8815A3C069F173EABC10847AD1A279E2105EE10F45945EE27E2B12236D47DDB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\XLINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\WWINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\XLSLICER.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1036\\XLINTL32.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\ENVELOPR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\GRINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\PPINTL.REST.trx_dll.g1p3okhzl","md5":"72F4FFF876B5F26F3720C85146D3D7C0","sha256":"8EF2E58A5A3B4C43D78436A85B13B9EA8A3CAE82883B6E566B0BE1559125683C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\PUB6INTL.DLL.trx_dll.g1p3okhzl","md5":"20D4832E4E77B71103B48BBC4B01B0BA","sha256":"2E84E5C203C98A079CBCE040063420C3D8DCC03E8E6F0AD251630A231AEB2111","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\STINTL.DLL.trx_dll.g1p3okhzl","md5":"63593E819CD057589BFBB9D500B18108","sha256":"7B6C5FD4DFF086AEC0B0CD1B89E67934121E9FAC2A94A2FC88A04B72AB813181","type":{"value":"ini","type":0}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\VISBRRES.DLL.trx_dll.g1p3okhzl","md5":"82724224EBA590C7F1D845D3B54C7EB6","sha256":"26F2A29A444F47A30DD198A070CD2097C3942F6BC3B0751D88B3DDA73061BC6C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\PUB6INTL.REST.trx_dll.g1p3okhzl","md5":"8A7F62162C9BB69E4A0001D8E86050E8","sha256":"216AD3BA6581A6AF93AEE95B07FF5ECFE0893581FE53F6F570CB41337EE7AF62","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\PUBWZINT.REST.trx_dll.g1p3okhzl","md5":"DEE0B99F42D06715DDB590FD7FE0F974","sha256":"A907C9FD7DAA46B637E93B38ADA102674F38968E7AA1535E42732B7729E321AA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\MAPIR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\OMSINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\WWINTL.DLL.trx_dll.g1p3okhzl","md5":"EAED355F34EFF6EAF610309D8B7150BE","sha256":"59EFCD2269220D6CF819D33BB8F675FD3AB616383BB16D8E0481A902D9473AD4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\ENVELOPR.DLL.trx_dll.g1p3okhzl","md5":"37D2B9771BCBC51788C0E5CA67FD9444","sha256":"E689BE68590777A6D1D2B216BA12737C681FB682FAAFE89F61A0A0E2F50CB056","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\VISINTL.DLL.trx_dll.g1p3okhzl","md5":"D9BE5B62543D3096D9879B6128D61394","sha256":"5E8DDBE30591F597D772941ADA740BBB3DA2146F54C0F9FAC5B9E6ADDAA70A9E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\WWINTL.REST.trx_dll.g1p3okhzl","md5":"9ED568CB3AACA8CC530E8E3A22D6F50B","sha256":"F155CF4F9A79685F7346F650D33173C51A26FE722421C3D4DC5D0AA39A4C80EE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\XLSLICER.DLL.trx_dll.g1p3okhzl","md5":"8CC08A6C37778A6080FE1BE7E9A30049","sha256":"CC0A5FCDAF9DBED0A880F8B5D783A9B41F78791D26AAB56CB70158F0540CB0B5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\XLINTL32.DLL.trx_dll.g1p3okhzl","md5":"40F3A82AFEC54EB342719AC22043A321","sha256":"4EE9D762A0B6383E07B2DB180A76711BE39753A9FDBFACA0AFF474DBC85B1434","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1036\\XLINTL32.REST.trx_dll.g1p3okhzl","md5":"BE0318A8763F0F1BAD8578B52BBB6228","sha256":"677520B52AE093BBDE0649289CC2B6094C25BB9B307BD8BB25C97505323B4EC0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\MSOINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\ONINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\OUTLLIBR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\OUTLLIBR.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\OUTLWVW.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\PPINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\GRINTL32.REST.trx_dll.g1p3okhzl","md5":"3D2BDC3152279724A1968581CD263188","sha256":"6B6E2582C528778527A2C0A7DC20B525FB26ED124467CC0D4D4A8EEA311E417C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\GRINTL32.DLL.trx_dll.g1p3okhzl","md5":"A72CB88A8E7945AFD7CFE7932914485D","sha256":"BAC9C731BE413251CA61B9D8F2CC33E000DA9AE7EACA45D1674605FEBDA7CE39","type":{"value":"mp3","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\MAPIR.DLL.trx_dll.g1p3okhzl","md5":"879FD0F44FA4A192F279892789D667A4","sha256":"CD57CE6AEA79C36A445A44B075BD830F86E60A80D9900B438FEEC65F63A3E377","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\MOR6INT.REST.trx_dll.g1p3okhzl","md5":"A00E7B8EF455CD40FCDF440D96726BD6","sha256":"C44B84C94E2FD3CFBDB7B078A4E02EB8D4DCC58ED38595E4C54C43012BAA46E1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\MSOINTL.DLL.trx_dll.g1p3okhzl","md5":"154E7FB13E15497378E8330A45A06A62","sha256":"B83EDB7F4417E781C63D781784B5A610B08938FE02247FC628EA3CB9C6598121","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\OMSINTL.DLL.trx_dll.g1p3okhzl","md5":"1E504B3F63711A3FEA0AF324101ED111","sha256":"98094FCFC2B7EB9DCEFDA03493AEE1FFA9C16D45451202ED75D8B4F84C8C167A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\PPINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\PUB6INTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\PUB6INTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\PUBWZINT.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\STINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\VISBRRES.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\MSOINTL.REST.trx_dll.g1p3okhzl","md5":"084551E544372B956489E32DC56B613B","sha256":"6685106DB881D87291E37C3BF49D19DFAD8863F966196866EE60C84E265AB694","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\ONINTL.DLL.trx_dll.g1p3okhzl","md5":"3B6F8862862C10ECFC69A6CC64D40994","sha256":"7B75837AB8269817CC5A24EB612DEAA41DB23375DB741B1677A034945BF5EF0A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\OUTLLIBR.REST.trx_dll.g1p3okhzl","md5":"60D7C2B32C41A39FF63521DB434C33F4","sha256":"F7E787E47B0D7689F7C79377340E21599EAC85282CA8AEB3F82541AE04C5E1C5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\OUTLLIBR.DLL.trx_dll.g1p3okhzl","md5":"FD8D04F72F0132B689EB7D52C6EC3DFE","sha256":"5188EE42173FEFE20D8FCA17239458FFA961B2BEE997D9961125FD614992E1D3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\PPINTL.DLL.trx_dll.g1p3okhzl","md5":"DCB509F10F6D63374DF51013C80A2C78","sha256":"430B7124FD896DDDE39898ACADBAC0BBA5EF1E3114E6EDF8DF730EADE9FB538B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\ONINTL.REST.trx_dll.g1p3okhzl","md5":"2DDFEBE16DE64200591140D7D888AE26","sha256":"1BE2D16BA252CDD6604ACD39FD566E42750865DB600E29CE9A575CAFB4099950","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\OUTLWVW.DLL.trx_dll.g1p3okhzl","md5":"BDB4DBD31AA4681636F11C3B0218CB03","sha256":"438FD17572C2069001DE7BA164A01EE61E1188B1C1367AD09C7ABDB5EF2ECC4B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\PUB6INTL.DLL.trx_dll.g1p3okhzl","md5":"46EB5FD55235FC73A014E727184FFC15","sha256":"D8FC0C2885D8D78426C43A121A6640243406DB7F99F8BF7D35D42572F09E3320","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\PPINTL.REST.trx_dll.g1p3okhzl","md5":"0359378B57C771DD0D65F97FCB943BFC","sha256":"6E84D08EF118635C1F26E75A35AA8591B6DF0DDDCD2E664A5A085F8E3A43C50D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\PUBWZINT.REST.trx_dll.g1p3okhzl","md5":"8B0DAF7B474BF04E981E25AA0F15E93D","sha256":"CAC884D489C09506685B6B2C5D731C06063C9FE14C1E1383BE6C2B9F25697926","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\STINTL.DLL.trx_dll.g1p3okhzl","md5":"D2483C0F30F63EBDE5670F34F03E85B7","sha256":"C59ADE03090FB5C0CE98025C63BDDBF70C5CC8ADCE92F16DC0B32B224089ABAC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\SGRES.DLL.trx_dll.g1p3okhzl","md5":"7AB6D63D01ACBD445212EA510367F887","sha256":"41E23BD88280A4BBC6EEFA3CA24446C546745DE9529F010EF1CFCFABBD97AC3A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\PUB6INTL.REST.trx_dll.g1p3okhzl","md5":"84A95448375997973928C0B2747F826A","sha256":"0336CDE1A281DD7C349631305CCFDB8F3BF9778AC903237232364C6E63BD71A3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\VISBRRES.DLL.trx_dll.g1p3okhzl","md5":"F25BD789C15ADEF5E5B46BD64C2C6F12","sha256":"7E8C2638E51D59B1BA2BFF7752FD3661B86971C5A24AFC21A9AE3A89A3A76781","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\VISINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\WWINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\WWINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\XLINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\XLINTL32.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\1041\\XLSLICER.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\ENVELOPR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\GRINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\GRINTL32.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\MAPIR.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\MOR6INT.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\OMSINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\ONINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\MSOINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\ONINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\GRINTL32.DLL.trx_dll.g1p3okhzl","md5":"009311F098A453234DDC5BD4865C04EC","sha256":"F3CF686892281D6642304B6800E7DF015E266873B4DACD4CAE86F54B31462E60","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\GRINTL32.REST.trx_dll.g1p3okhzl","md5":"3865862B4EE2D2C9FBCC1A0774AB67A6","sha256":"0491813C3511A67730BE36225C4BBDA734863E457AA3766A03841B9AAB847224","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\XLSLICER.DLL.trx_dll.g1p3okhzl","md5":"0EE57348A50776AD56CE808DB52E1460","sha256":"10B8EFEEB0EFEC158C274078183F38EED91FC45D2707213B06B3EEB73FB98883","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\ENVELOPR.DLL.trx_dll.g1p3okhzl","md5":"23CD784F58F7AEE6A9F53D74279E88E1","sha256":"136E33F1954FC342E4AA31C6399D30B11AE2BAE0016E3D72E6587AA8F26570B9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\WWINTL.REST.trx_dll.g1p3okhzl","md5":"8B47FAE8C02CDD9A2672CB5BAA46DE6E","sha256":"3B830C533D87DFFCBA2B0C5F23B74497F88FA55DBFDBB8B16AAFF5C8B94F2A8C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\XLINTL32.DLL.trx_dll.g1p3okhzl","md5":"EE076A85731798FE5A7D686F04BD42B6","sha256":"D8D793FBCF99C8A73A5DDC299A21D6C632959E9C34267E9D429BF6E6E85C9350","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\WWINTL.DLL.trx_dll.g1p3okhzl","md5":"D942B79D0CC61AB28AC9D166B4D2C3F5","sha256":"EA238D3B1F98CC94AEC6D94A46E5BE51F0522E2D665507DB29282083EADA6474","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\XLINTL32.REST.trx_dll.g1p3okhzl","md5":"C6516B4A1F85F211A6F5A164F111D379","sha256":"64EAE2A61334CF21A75C1DFDEFAF810F1BF311B770C67F5D3D09F23F9A5D9EE5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\1041\\VISINTL.DLL.trx_dll.g1p3okhzl","md5":"280EC4FC5F69FD117C06719AC1A37783","sha256":"B5FB5FFF8927901759A557B83C7B0559F3A5E20FF57201EA26040EF986A493E8","type":{"value":"mp3","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\MAPIR.DLL.trx_dll.g1p3okhzl","md5":"BE7708BF39C3499EEB41F56711188933","sha256":"644707EC4C38F434D438B8973187CA116665A3219F43633B29B0D88757E4E80C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\OMSINTL.DLL.trx_dll.g1p3okhzl","md5":"E3CF95555111C2D9BA0604F0B6B66286","sha256":"51FFDF36D14EEA18AE63E8081BC363DA9B2566F64A71A071AF498D2647531E36","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\MOR6INT.REST.trx_dll.g1p3okhzl","md5":"BFC666569B15655C9EB1371B11FBF1DC","sha256":"DB1B661920433906248B204EDB770EAE83CF81C5177ED9F20641139AB8C1D539","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\ONINTL.DLL.trx_dll.g1p3okhzl","md5":"1D1DD1D374FDE6C6EB733F1ACE9FB1EF","sha256":"0C5C7264066DB5993201ECD7D22A56B8235ABB3C13E07FA07259E817EEA32FEA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\OUTLLIBR.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\OUTLWVW.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\PPINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\PPINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\PUB6INTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\PUB6INTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\SGRES.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\MSOINTL.DLL.trx_dll.g1p3okhzl","md5":"F2F070D2650886BB80341373350E6FAC","sha256":"1EFAFB7E58E5CB1642EE7C44572B8719AEA35FDCD06956DD87DB223B3AE80064","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\MSOINTL.REST.trx_dll.g1p3okhzl","md5":"4D0D8B02EAEABA97E5ACDC17455FD76A","sha256":"F578D6172A5AAEAEF541AE1B6D21CB2C6CCCA6332F593A927E4F4C4763784FA9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\PPINTL.DLL.trx_dll.g1p3okhzl","md5":"396DECB4F5C8CA4F323F76DA61AFDE10","sha256":"21EEB16CDFF1242DD020E9F97BFD9416598723A5795F13D9368F1FB8E1568AB6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\STINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\VISBRRES.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\VISINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\WWINTL.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\XLINTL32.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\OUTLLIBR.DLL.trx_dll.g1p3okhzl","md5":"DC4BF6D6C6714C74B86B0C3985E445E9","sha256":"AE2206BF023C43EBFF38A6335836DEE254783EB98D1EAF9C6AD9D8009D70F36E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\OUTLLIBR.REST.trx_dll.g1p3okhzl","md5":"5F0FCD4294FF7CB73814CBD02BAA0C98","sha256":"F7A9D57595A65E45DE9FB360EE28A34546A6FA2F3D92985802AB7463534BAF36","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\ONINTL.REST.trx_dll.g1p3okhzl","md5":"E8475DD5CA8D6EF011D0D53A45DEA96C","sha256":"BE6A3816FE8746ECEECFDBC909D62D3DC9C9D2CF890686360609279CD26B8F58","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\PUB6INTL.REST.trx_dll.g1p3okhzl","md5":"69E05B525A3A6DDC210B2533954779CF","sha256":"2163A9C5F16FADBD3B62BA0AADCBE9465F801DF8FC5C7025F0760E44D3CAEB07","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\PPINTL.REST.trx_dll.g1p3okhzl","md5":"AD4F517890F006569814A2D4EF33EA9D","sha256":"C9E0AD3EB58EF8CA26C0AC03FD52A23BDB30D5695FD3EE434B9746BD128643A9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\PUB6INTL.DLL.trx_dll.g1p3okhzl","md5":"BE7C54712CFCC17E1CB66DE3EF3F9B03","sha256":"D465DD4FBDC883B3D67FFF011F149AAFF65949F999E8A49F6BAF190B4FA82D5A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\OUTLWVW.DLL.trx_dll.g1p3okhzl","md5":"2FCB99AD08BF95EE6D809D96252A8769","sha256":"45AAF30A1BA6B95ECF6B9BF6352395E1E00F9E12B6E62E25200A26D33C3696FF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\PUBWZINT.REST.trx_dll.g1p3okhzl","md5":"4FBE3AEBD38BE5102E98428031B4C385","sha256":"451A4F027B6EB2C00CC15DFCA3A1C74193673E62A38B6D4204DC708297012CD5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\WWINTL.REST.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\OFFICE\\UICaptions\\3082\\XLSLICER.DLL.trx_dll","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\STINTL.DLL.trx_dll.g1p3okhzl","md5":"83D953A1168D95895ACF94257995BE14","sha256":"3F72E0A5328074C4F2362E2386F44EA50ECB6DC19A2F830A2D2D5700112A985B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\SGRES.DLL.trx_dll.g1p3okhzl","md5":"4A509CF429D357D437A709DE5510099B","sha256":"A8FE9E711963DFED16E4895E055C6574D71DCE40AB5E2D548FC2E0597D7910B1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\VISINTL.DLL.trx_dll.g1p3okhzl","md5":"EA823C9458675382DD9661878D197858","sha256":"D482D1758D3A42B5FB0DBB12608678BF3552944C8B1EE88F6C0B8D1959C45E52","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\VISBRRES.DLL.trx_dll.g1p3okhzl","md5":"D80F549BBC766985D18B909D8EB5E59B","sha256":"1669AA65F52B40E8AB580634B87C2474C7DF31FD07ED19CDDFBF098BF8C5A512","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\XLINTL32.DLL.trx_dll.g1p3okhzl","md5":"4948B4F8042C420F6756650462A411A8","sha256":"39CA0EE1AC9EE887BCC16C07D9B8B9DB01468F9A9E0871FF58D5D613BEB77F7D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\WWINTL.DLL.trx_dll.g1p3okhzl","md5":"8E0A12F50D86BA24CF935D310DACD119","sha256":"D347999FC0985282BF9B2232212A6219B3F526EF69CB90B40AA0D80816E9E807","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Mozilla\\updates\\308046B0AF4A39CB\\updates\\last-update.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_auto16x16.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\XLSLICER.DLL.trx_dll.g1p3okhzl","md5":"ED10933EDD59D016775E7EF4DFD03272","sha256":"0112C07392901310CC4EEBD776741C01CC15F57257DDEFBE680EE152BAB1C29A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\WWINTL.REST.trx_dll.g1p3okhzl","md5":"B8CA37BFBE5C79D4EE1087FA3FE7BFAA","sha256":"C8BE13CCEC08DC27344D87599117B62EA02CEABA542C496E9FA27B679C270E64","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_cancel20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\office\\uicaptions\\3082\\XLINTL32.REST.trx_dll.g1p3okhzl","md5":"24364DB806B3A4DF218A4C034512C3C9","sha256":"C8A963881A0812BE23ADE32B55CC419AA8D4E8559E6A3051EA2675F4B7876E70","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\search\\data\\temp\\usgthrsvc\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\scans\\history\\service\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows defender\\scans\\history\\cachemanager\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_cancel24x24.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_close12x12.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_compare20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\virtualinbox\\en-us\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\microsoft\\windows nt\\msfax\\common coverpages\\en-us\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\mozilla\\updates\\308046b0af4a39cb\\updates\\last-update.log.g1p3okhzl","md5":"19EFD1C7D9B37966CC4014ACF47435DD","sha256":"8B61FD055656F4BE1E39162BDA7B4FD69AA4D180A90DD9E4457E545E794F2966","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\acrobat\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\mozilla\\updates\\308046b0af4a39cb\\updates\\0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_dropdown12x12.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\elevateddiagnostics\\460911090\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\programdata\\package cache\\564f02e6419b9858949b0cd5a65e2c8c0944dd88\\packages\\patch\\x86\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\acrocef\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\color\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\cef\\user data\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_auto16x16.png.g1p3okhzl","md5":"DFB9697C925A965FA829091E5BBD5D81","sha256":"C53AE48421840842E41BEC2BD23708E0759E6AAECFDD809ECB44610052247F48","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_file16x16.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_filter20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_find20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_folder16x16.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_compare20x20.png.g1p3okhzl","md5":"84C47A1E5BB098870809DE250342EFCB","sha256":"98906519580DE5D24DA2D549A0613B234147BCC406002DF1CA9B03B89BF93C9E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_cancel20x20.png.g1p3okhzl","md5":"5B44990BB13EDAB94DEA6B13FC59286C","sha256":"1C2A94F84EC81D057DB7BA6023488AF88AC991D3CABA3EC41982DA163CC516B0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_cancel24x24.png.g1p3okhzl","md5":"24C5B0FEC0428A70DE5A826ABCDEEC72","sha256":"B4E685B6B2D0905456473E777DA2276CDBCF8C78797E9FFBFDCD4F58DCBCB6A2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_close12x12.png.g1p3okhzl","md5":"41FC1A5FAD299C91429F2F635FEE3570","sha256":"73CDAFAA1A471CCD604EA09F553890E2A238736237DE29473EE336433F0A5F29","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_disconnect20x20.png.g1p3okhzl","md5":"606616119D1070F110793D9C46ECCC7A","sha256":"2FB37D7D0B21AC26A26672280C395CFF55DFEAA91193533C18123EA546083DF0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_localtreeview20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_logview20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_processqueue20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_queueview20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_reconnect20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_refresh20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_remotetreeview20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_dropdown12x12.png.g1p3okhzl","md5":"41AED192B79F5A04F3AEC9AF3D2A4495","sha256":"8520D276C62C0158728CFAB32FAEF8946E2BEFD47214DF6AF4B23E251CBB1A51","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_file16x16.png.g1p3okhzl","md5":"1AD6C8A31EF25D4C024816165BCFE383","sha256":"1847B61CDC0B5CCF673DC54B03E9FE27248DD6128BF9613588FD79D82B778B86","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_filter20x20.png.g1p3okhzl","md5":"0C4F0C8422961616DDF1B51C6185AB13","sha256":"DCF46A461F0E6F5CE4F6AA6C1E07FB006FDF558183F876BF7469FF1A0402904B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_find20x20.png.g1p3okhzl","md5":"67589A714E4E6BE6901601E153457407","sha256":"73A3C3653DC4B9642FFB849E359F252B332A897A6E56EC54DB50231012EE5DA3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_folder16x16.png.g1p3okhzl","md5":"E6B8618E8DA3C37B18D9F1AA69693DB8","sha256":"14C1B5D1B5CF7ED112DAAD8D8C81372A618D1857841B99968FE53EAB15441493","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_server16x16.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_sitemanager20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_speedlimits16x16.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\FileZilla\\default_synchronize20x20.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_localtreeview20x20.png.g1p3okhzl","md5":"F841B217C95F30A7EEDA5B9D4138C32F","sha256":"6D31305FC54D5316910E53100B76D422F0AF77AE25504B29B095972FE00C1266","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_leds24x24.png.g1p3okhzl","md5":"9D51B476D4819C39D8CF92261FCCE1B4","sha256":"810F343124878E3CB7AB7CD4546B8C3E4A6D3374F713DD83FC5627F473B7EC8B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_logview20x20.png.g1p3okhzl","md5":"525FF4EAA84A833BB3A84680CE72A3B5","sha256":"3368676265110DB2C75950EC5623C44809F46C7CBE35E436285D43392318D89B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_processqueue20x20.png.g1p3okhzl","md5":"30254901F963ABEFE68E54F397CF95FA","sha256":"7E65A826A32C1BBA981AA62C6D2A151738DD0C47B76AE1656B48EC26ABD347ED","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_queueview20x20.png.g1p3okhzl","md5":"94A26DE59EB06E10EC4E4AE6BA3043CB","sha256":"83B2093AD75F546F7E2FF90B30247EC1CAC4A8153377BFCC8C213BBBD926058D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_reconnect20x20.png.g1p3okhzl","md5":"659EE1899216E23370FA80ADDBBDD238","sha256":"C9E34C8C4EC0D29C856D450DA0CECCF1E7883844C9628D7266C026CAA0BBFC19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_refresh20x20.png.g1p3okhzl","md5":"E3712C100468008A5120CD7676A74D09","sha256":"9B06ECB024B87DEC8AD4B7663AAB06327B4276006D0144864581119057711C56","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_remotetreeview20x20.png.g1p3okhzl","md5":"DCA74C8F25A960F61E9E868E046912E8","sha256":"5ABEAF27151E567841BB6DCC7B2A7BF5D87D227D7B92C79D69A2D505BE20BEF5","type":{"value":"ini","type":0}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_server16x16.png.g1p3okhzl","md5":"19C5DB73DD6E7E8B58CA221D28E21401","sha256":"609AB8B14417BEE176E46EF664B05E68073DCA6ECB3766BA6A7CD998332FFDC0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_sitemanager20x20.png.g1p3okhzl","md5":"063944DCAB6D54E36B2BBEDAFCBDD544","sha256":"53E247E969FC4B44995389C03D4DD84206BF6F4AC420410DB8459223F6639268","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\software reporter tool\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_synchronize20x20.png.g1p3okhzl","md5":"2469993665FDB3BC2B96D684ABAA636B","sha256":"E736ABDD1E4815D8144B016A6A71D0215EC17087C9AEF7A1A198FD55FCB8521A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\filezilla\\default_speedlimits16x16.png.g1p3okhzl","md5":"78AA54677B613D057787E3915916C022","sha256":"F53875BF773B7D4404D8F63E47BA004EFCC308A69F49A76E4CC5DA8A7B6D86BC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\crashreports\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\credentials\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\device metadata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\media player\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\event viewer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\feeds cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\forms\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\feeds\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\onenote\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\office\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\outlook\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\playready\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\publisher\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\1zocpqtd.f0w","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\2421jc2j.sl3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\bpjw3ftc.gmn","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\ccj5trj0.5ji","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\taskschedulerconfig\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\vault\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\updates\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\windows sidebar\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\windows media\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\programs\\common\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\steam\\widevine\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\steam\\htmlcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\cglagoum.myl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\eyjfd3ut.c1b","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\gwajh2cp.eul","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\h22ee5x2.ezx","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\1zocpqtd.f0w.g1p3okhzl","md5":"276729AA88A90323F205B55D555FAD71","sha256":"7CAD320126AD2AC1AE5A12F7CA28D489EBEE5E0C02B8605501D8DA900C7464C4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\2421jc2j.sl3.g1p3okhzl","md5":"7F594A8FD3ABEEF63611AE8AEEECEB06","sha256":"B0D66F5DA478A966B60562A8460C4940F18D8A4B8A16AEF74AB3BFD7A427F3B5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\bpjw3ftc.gmn.g1p3okhzl","md5":"765A3F448229BC5A1FDA9D0444EA53D8","sha256":"96DBEA9F4F174EF0D5B9705AA21BC8B8EDC23BDC39FCE32E257A99B923BAA122","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\ccj5trj0.5ji.g1p3okhzl","md5":"8E0EE9C5FBBCBA3F46F8B8953E967C55","sha256":"0DFE01475883E7ED8CF2A6077CEFC00BC5EDA278F9A57E8D0EF1F74193451815","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\ioochww1.jem","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\khfz2s5o.agc","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\pfye4ag4.gog","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\pnkaee00.gk4","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\cglagoum.myl.g1p3okhzl","md5":"12CEFF8CBBC60A4F3F6C5F793636EC40","sha256":"70C03082BFB4CFEE0AC637A0B201E122DEAAADFDC516C8A48D4C72CFE4B64423","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\temp\\chrome_bits_4040_2303\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\eyjfd3ut.c1b.g1p3okhzl","md5":"FBBC3687C17DA2A9F5A908AD4BBEA76E","sha256":"2B3A1ADC8B46964A929E059E1D84D486E3FF217B28DAEB9265B9995206EB447C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\temp\\cr_e2cfb.tmp\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\gwajh2cp.eul.g1p3okhzl","md5":"7BCAF456CFC1C3910AB0667FBDDC766A","sha256":"05F6E10D6CD2C9A55A191F9470A5E14249F6B864C29843DD4980858AD04CFD6E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\szl41eam.znp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\vyjxpaoz.gak","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\wu45kdfk.3gf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\wuxlmtgb.dbu","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\h22ee5x2.ezx.g1p3okhzl","md5":"318BEDC52F05E599B0E72471512C82C3","sha256":"6F37F7736BF2E2D8BF558704FAB44109445D13BA9D9C50444CBCE73E44B2F998","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\pfye4ag4.gog.g1p3okhzl","md5":"9B9B7F00DC3E98518DCF02C1D6350601","sha256":"E2F94D1D982C963EF83E77346D3D45366F0D19E987E6260FA48D5F054FABEDCD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\temp\\low\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\khfz2s5o.agc.g1p3okhzl","md5":"682A9A921B377D5F5817E6061D9FCAC8","sha256":"8CBA0DD8056B03DED6D5B4278768854246D0401178B43DE24E68231F1F46550A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\ioochww1.jem.g1p3okhzl","md5":"9AA8931349B502D55C47C27D326D6F11","sha256":"08D463C579F866B25761F3A0A43C3A88A2239C04DE4A869870855E640190C9AA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\pnkaee00.gk4.g1p3okhzl","md5":"11348C15BF39FCE2C2180810CAE462E3","sha256":"6AE9522D50B02B7C56B47A673257AB354A8EFF7C77C29055A9CAA2C74A925F25","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\y4t3qyjv.fps","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\uTorrent\\uTorrent_1912_00399530_1720152261","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\uTorrent\\uTorrent_1912_003995C8_1283006145","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\temp\\msdtadmin\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\szl41eam.znp.g1p3okhzl","md5":"665F22DEA0B36B48D041DBF3257416A4","sha256":"9B91C04D62F5702901783AE4D8DB6711453A91D9ABE446F698FD4851BC489D4A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\vyjxpaoz.gak.g1p3okhzl","md5":"78B2D288F41A09118416D553C67ABB2E","sha256":"F06B725013A35E42BE85355D2335BA6B71B12AD8A8F4AEE04CFAFE2B1772DD5C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\temp\\wpdnse\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\wu45kdfk.3gf.g1p3okhzl","md5":"0F0D966E73F79E16FEF736340D42546A","sha256":"EC8DBF74A4F2BDF506E89082D7A80C884E452E5E7B544354E0E2247338928790","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\FileZilla\\filezilla.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\FileZilla\\layout.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\microsoft\\internet explorer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\y4t3qyjv.fps.g1p3okhzl","md5":"125A32AA20DD4458A00C9BFAFF770CE7","sha256":"0630D54B9FE791BCE1202347ECB7E35E65C78E9468629795F42170A764AA64B4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\acrobat\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\temp\\wuxlmtgb.dbu.g1p3okhzl","md5":"0B5BDF16FCFE5F3BECE0347BD0A9BFC9","sha256":"530CB54FDEFD70C6A4A34A70EC4D3E79E41E9D736C99390CBCE6B29BB2009AC5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\oracle\\java\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\locallow\\utorrent\\uTorrent_1912_00399530_1720152261.g1p3okhzl","md5":"E8AB1575B32DD1A42483ED3BD1C3AD89","sha256":"B6A5553B981D0B47F418C8DC106434ED9301991F51E9310C8B2084C400C862E8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\microsoft\\cryptneturlcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\FileZilla\\queue.sqlite3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\logtransport2\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\flash player\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\filezilla\\layout.xml.g1p3okhzl","md5":"D9B64979E245C22946B00E9235D98A54","sha256":"3A23FAAA2EBF430CBA04C5E21EE62C891C46BC4B63850FFF25B2C3320A293E38","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\locallow\\utorrent\\uTorrent_1912_003995C8_1283006145.g1p3okhzl","md5":"141C839B77185D04BE3CC8F6C471984B","sha256":"BD42098C54A4DFE6D2E06DE7F72781C54F176D6416B03C90431A8F167148F6DA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\sonar\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\filezilla\\filezilla.xml.g1p3okhzl","md5":"AE144DF5A0713C601092E4A2413AD55E","sha256":"7A97CF2E30A31564B2A06FBC9BDC3758404B25067BC54C5297BCF03623BDB5D6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\filezilla\\queue.sqlite3.g1p3okhzl","md5":"ABC8FD6C6A7B6D54E35133835231EE42","sha256":"0C60E26DAA66DB704074DFF273CC73B848A30987125698609E16FB7F7601EB6B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\linguistics\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\headlights\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\acrobat\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\identities\\{e4ce17a7-fc47-4cd1-8ff6-45436c8f45db}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\addins\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\credentials\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\mmc\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\document building blocks\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\html help\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\internet explorer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\excel\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\imjp14\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\network\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\outlook\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\protect\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\office\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\word\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\publisher building blocks\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\systemcertificates\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\uproof\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\speech\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\publisher\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\powerpoint\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\templates\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\proof\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\signatures\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\vault\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\config.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\contextMenu.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\functionList.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\langs.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\session.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\shortcuts.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\extensions\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\onenote\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\stationery\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\systemextensionsdev\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\notepad++\\backup\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\stylers.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\langs.xml.g1p3okhzl","md5":"04E6473E66D7706619F2E1496DC674F0","sha256":"37FCDA2BB560491E3D1830E2DACFCC1AD59BB0C01F839D5344011DA9583D0516","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Skype\\shared.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\WinRAR\\version.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\contextMenu.xml.g1p3okhzl","md5":"A87C9F64278264C7D0E82CE0A20D1418","sha256":"F022EAC1A1F9169FF065F28790D5A363C996FD4B0CAA61F28D084CBA84FD0623","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\OneNote Notebooks\\Personal\\Open Notebook.onetoc2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\config.xml.g1p3okhzl","md5":"FEC82FFE616D3362CDFBC046334D93DB","sha256":"3867C4438BAB15AAB27A0B66C80A6D7254E79C7990FBDD06C1DBD4F1BFCD03C7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\notepad++\\plugins\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\functionList.xml.g1p3okhzl","md5":"1215ED16A7D7238B8BE3FC9AC94BD652","sha256":"0E08BB763EBA099CBE7D98FB3D42FF3EDE84EF6EB20D611DA362E73C990B000C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\session.xml.g1p3okhzl","md5":"4998F58318BA63629BF2EE9A6186F9B7","sha256":"61DCCF63C0A5CA4B7B5F645F8B18455C372F38211E0C4BCE179CE40472722A4F","type":{"value":"vc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\shortcuts.xml.g1p3okhzl","md5":"90A2F7DED180E8652FF3ACD4D21E0CD9","sha256":"BEE92831C12BB3323C3F7D13B52DF7B02DBFC4FCF719954CC7BC58DD219683A9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\stylers.xml.g1p3okhzl","md5":"BD71EEB29DDC14D898398016E00D1374","sha256":"1D798FAFCC92507AB0412867F32A334583C652FFCE49CB2850D09581B82E7557","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\skype\\datarv\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\OneNote Notebooks\\Personal\\Unfiled Notes.one","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\Documents\\OneNote Notebooks\\Personal\\General.one","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\skype\\shared.xml.g1p3okhzl","md5":"6F713F42E2F30ED80BD98AF1DE009040","sha256":"EC7B1351E993EE99E1DF1D6B494504F7A3C9BD04D92FA467719661106BBC3406","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\sun\\java\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\skype\\skypert\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\opera\\opera\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\winrar\\version.dat.g1p3okhzl","md5":"7B430F3A99B8776081B9464D28B8CCED","sha256":"3BB5C0234ED7EF5C0718D5A481D04D27BDB9E54DE52DD0BFF3BBBBE142B81E80","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\skype\\shared_dynco\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\skype\\logs\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\skype\\shared_httpfe\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\onenote notebooks\\personal\\Unfiled Notes.one.g1p3okhzl","md5":"CD273B9E6F11A3273C33CE45DA46B66A","sha256":"A8DAD205A0CC00B4A5A0020BC1519FD23305AD805F147E6096C3B2E641201E1A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\onenote notebooks\\personal\\Open Notebook.onetoc2.g1p3okhzl","md5":"81548CE1E8E99C3BA4A30C254CF23EF9","sha256":"D5613863BA914A72B3A09598E52CC83184F167F037AA87D234C51F44EBFCCBA3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\credentials\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\documents\\onenote notebooks\\personal\\General.one.g1p3okhzl","md5":"5FA75B8AAFFA776BD963BD75E46C8DFC","sha256":"65CEB42010CE4142A6B54B92D8E9CF3D905AAA763799486AFE2247167C81D357","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\internet explorer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\media player\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\Administrator.bmp","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\wmsetup.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Assistance\\Client\\1.0\\en-US\\Help_CValidator.H1D","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Assistance\\Client\\1.0\\en-US\\Help_MKWD_AssetId.H1W","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Assistance\\Client\\1.0\\en-US\\Help_MKWD_BestBet.H1W","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\windows media\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Assistance\\Client\\1.0\\en-US\\Help_MValidator.H1D","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\windows sidebar\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\temp\\wmsetup.log.g1p3okhzl","md5":"2267774EECA0D3CDF248EBAD03123ED8","sha256":"83B4CA6FFF9737A963B8BF8888E5C517A22E4A5D09A69B81416BF4C33F127F12","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\temp\\Administrator.bmp.g1p3okhzl","md5":"4C926CCBDAE7982A73466CA146CD9AD5","sha256":"ED6DCFF7BA3181A31AF763BE08F024C8153127D92F11A811B81A4D7E1637FE58","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\default\\appdata\\roaming\\microsoft\\internet explorer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\temp\\low\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\microsoft\\protect\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\microsoft\\internet explorer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Assistance\\Client\\1.0\\en-US\\Help_MValidator.Lck","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\en-US\\resource.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Assistance\\Client\\1.0\\en-US\\Help{9DAA54E8-CD95-4107-8E7F-BA3F24732D95}.H1Q","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\en-US\\resource.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Windows NT\\MSFax\\Common Coverpages\\en-US\\confident.cov","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\assistance\\client\\1.0\\en-us\\Help_MKWD_BestBet.H1W.g1p3okhzl","md5":"0B501B3FA970E32F39273162B45697AF","sha256":"093C5AFD216A4D2318EB1993829229CFCB446142F43BD001F574DABFA961E947","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\temp\\wpdnse\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\assistance\\client\\1.0\\en-us\\Help_MKWD_AssetId.H1W.g1p3okhzl","md5":"5D1F6CCA036E706FF109E4D93B831452","sha256":"9C26380D9A92E4C00220423DEABBA70762492B58C6A1B0A5BBF795B4767EDAF6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\microsoft\\credentials\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\assistance\\client\\1.0\\en-us\\Help_CValidator.H1D.g1p3okhzl","md5":"B60A4E99652FEFA48371F8EA6BA19920","sha256":"F4DD43FD7466BFF8F9E78E7D19B625009D818BEFA72DA9B01D3A45C660A35CD2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\identities\\{ba2162a3-2f32-4850-8d8c-b3c9a2aa9d43}\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\assistance\\client\\1.0\\en-us\\Help{9DAA54E8-CD95-4107-8E7F-BA3F24732D95}.H1Q.g1p3okhzl","md5":"0DB49B9AE04642E809791308FE316351","sha256":"D4F334F0D121E18CC3B2218CE33936B1C2D97FFC26BC4946D4DD2F35E055D85C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Windows NT\\MSFax\\Common Coverpages\\en-US\\fyi.cov","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Windows NT\\MSFax\\Common Coverpages\\en-US\\generic.cov","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Windows NT\\MSFax\\Common Coverpages\\en-US\\urgent.cov","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\ProgramData\\Microsoft\\Windows NT\\MSFax\\VirtualInbox\\en-US\\WelcomeFax.tif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Adobe\\Color\\ACECache11.lst","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\assistance\\client\\1.0\\en-us\\Help_MValidator.H1D.g1p3okhzl","md5":"DDD99278F6B47ADE6533B90A76697EF3","sha256":"07727EC54000F36D374566E2BF2BE17781D4803C8DD02B29ED5A523133ACA5E2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\assistance\\client\\1.0\\en-us\\Help_MTOC_help.H1H.g1p3okhzl","md5":"8038E78FF413B0AC63B10516E84F3DA6","sha256":"136320AF49AD387B69BF4ECDCD3B495EE5BAB05843679AD8DA90C9E5CBAC8E45","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\en-us\\resource.xml.g1p3okhzl","md5":"DB46B1C5DB15C9C13F9CA8DA701A276B","sha256":"1F319B364C8A665F98B7062EC3E2F6F52AB0FC20C221D2FA8C95D5361A7BB8F9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\assistance\\client\\1.0\\en-us\\Help_MValidator.Lck.g1p3okhzl","md5":"C9F27C0CBADEE918A1CCFE31B88366EB","sha256":"DFFBF2B8AFC39188B7F3293031D499FC20ACA51BBEA5600BF93096ED02D0CA96","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\windows nt\\msfax\\common coverpages\\en-us\\confident.cov.g1p3okhzl","md5":"31A6B9CEDA614D36C725FB7518A45565","sha256":"FF96A2634AEA345D4130388623ABF06EBCF1CDEA5464536D62631B6EF4B7C141","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\device stage\\task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\en-us\\resource.xml.g1p3okhzl","md5":"7E63A9F8F58011845CD18AAA127E1F99","sha256":"15C3B255BED16EA062160BEB2261D39405931111A02D3E69BB4EA7278342160C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\windows nt\\msfax\\common coverpages\\en-us\\fyi.cov.g1p3okhzl","md5":"5163AD1C8CB7ACE4A2E363CDF0E87174","sha256":"6F319EB5CB120CA28C569AC01E0EF3E03A34DFB27681DCAB841C83E49105ECD9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\windows nt\\msfax\\common coverpages\\en-us\\urgent.cov.g1p3okhzl","md5":"AA286EADB76BF5256B4E51A3D80D2FE9","sha256":"551B6D031F8B3F140CFB99AAEE98680B25EF944AC2D169B2E79F2D8B262EE92F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\windows nt\\msfax\\virtualinbox\\en-us\\WelcomeFax.tif.g1p3okhzl","md5":"C5E9FA50A6BB588574AFE45E16DF136E","sha256":"2B17C2B8E5F8D2F6D9FB555CED9636540DD034D0493DEC0F4A5EB0C4C9D2857A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\acrocef\\dc\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\color\\profiles\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\acrobat\\dc\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\CEF\\User Data\\CrashpadMetrics-active.pma","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Software Reporter Tool\\settings.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Software Reporter Tool\\software_reporter_tool-crashpad.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Software Reporter Tool\\software_reporter_tool-sandbox.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Software Reporter Tool\\software_reporter_tool.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\programdata\\microsoft\\windows nt\\msfax\\common coverpages\\en-us\\generic.cov.g1p3okhzl","md5":"111D41BBCF2CB25683BC95DBED81D931","sha256":"87ED70609F9E21D796A27E5CB2F61F35977788808D3748CAD45FE56526450757","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\adobe\\color\\ACECache11.lst.g1p3okhzl","md5":"32E29185C9D833386F83C587EA42633E","sha256":"5D99890E25E0FAC4B90B3E46D9FBA800B7E3C0450323A05BD1E946934EAF4497","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\cef\\user data\\crashpad\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Feeds\\FeedsStore.feedsdb-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Internet Explorer\\brndlog.bak","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\FORMS\\FRMCACHE.DAT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\elevateddiagnostics\\460911090\\2019073012.000\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\cef\\user data\\CrashpadMetrics-active.pma.g1p3okhzl","md5":"802E1F44BADB68AFD1FE30F9B9CF3AEE","sha256":"F072D436E60D73CE5ACB8CDC5880E0602F8929AA2FCF2D913BF1238123B12118","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\cef\\user data\\CrashpadMetrics.pma.g1p3okhzl","md5":"CEC17CEBFD83405A978F205895C1A306","sha256":"4F880C2CB696A05E79772B9798C76A2041A45875CE69BE497B64DB0C3255B1E5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\cef\\user data\\dictionaries\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\software reporter tool\\reports\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\software reporter tool\\settings.dat.g1p3okhzl","md5":"8268485308449521763CD2965437A005","sha256":"B889F16019C68AF034A3D0FB6EB49BD2E271D4F7539B971523CD7B19F2CD9DC8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\software reporter tool\\software_reporter_tool-sandbox.log.g1p3okhzl","md5":"D29DF050895EE0ED859BFEC2C9369E56","sha256":"1A9B63D8B2B1C81F83BD1EEEC1916A7E7C064F25D0ABBA51F7A5946975B5D648","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\software reporter tool\\software_reporter_tool-crashpad.log.g1p3okhzl","md5":"7CE2E82D9246754648EC2677661AB627","sha256":"4734DD61B4306A83A7AF064850D7F42EB73DABB887CC4BA045CA71508A4B0ABF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Internet Explorer\\brndlog.txt","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Internet Explorer\\frameiconcache.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Internet Explorer\\MSIMGSIZ.DAT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\software reporter tool\\software_reporter_tool.log.g1p3okhzl","md5":"65D67825589AFF39CF88A11905A9E7DF","sha256":"6CED0116F22C04DB2E54EBD79F70B9E11FD210CFFC7582CB562C83BF4855F8CC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\feeds\\feeds for united states~\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\device metadata\\dmrccache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\forms\\FRMCACHE.DAT.g1p3okhzl","md5":"561715CB21D61EE757F1E43620FF355C","sha256":"6EED2956D575C33368A13F92FA848F209B2CB1E628EDE3DF59E116AB30BF0D22","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\brndlog.bak.g1p3okhzl","md5":"20603071621B1BA20A87F941F7311486","sha256":"19BE95B6B1B1DE8F7FC6803BDE5FEA450EE26439FADE51CC64995FD62C565D7A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\feeds\\FeedsStore.feedsdb-ms.g1p3okhzl","md5":"21D1E46E1C346E0D11313C53A1AD610E","sha256":"8881B09BFE164D04CE9CAFABB2B94A45A92382EC0B8FA1DB273E24A414171E14","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\feeds\\microsoft feeds~\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\feeds\\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\MSIMGSIZ.DAT.g1p3okhzl","md5":"0F680E4501D402CF8EEC4F86A1344985","sha256":"1FDFFFE8ADD16746EAA2C0B42438657971661C88A8942FA1ECCB2AF58804EBB7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Media Player\\LocalMLS_3.wmdb","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\PowerP14.customUI","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Media Player\\CurrentDatabase_372.wmdb","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\Word14.customUI","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\imagestore\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\brndlog.txt.g1p3okhzl","md5":"2EFB6AC60061AD691840BF4A41E079AA","sha256":"18F9983D717FB492C99722356A7AFDA7A79DAB485B20D67EBDA17207B06B3027","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\iecompatdata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\frameiconcache.dat.g1p3okhzl","md5":"DCCE83F0C3E9C00125F992D514218296","sha256":"B72DC8A2145AC1A8ADFBD65DD261DB45EFB78A6CE0AA18DA8E8180E329176855","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\tiles\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\tabroaming\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\recovery\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\mapisvc.inf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\NoMail.sharing.xml.obi","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\office\\PowerP14.customUI.g1p3okhzl","md5":"4D7856ECC5BAA6501CEC0F1CC4C52E34","sha256":"58F80AC232B191B95D226B8566EDB3765CF296DCF9D60BEFD415A408F65E963B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\office\\14.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\tracking protection\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\office\\onetconfig\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\media player\\LocalMLS_3.wmdb.g1p3okhzl","md5":"54CE69508BA65B16CA7BEE9B5201053B","sha256":"AFE57D955FAAC0227EB18488A68872C91A3ED0DD722C1B8AC031A509ED5944FB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\account{30CE7C98-AA27-4327-91CA-78FA20FFA850}.oeaccount","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\account{CAF66E94-0031-4430-A4AC-CD19F582E35C}.oeaccount","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\account{D300D4BF-215E-4D22-A101-492F708A0702}.oeaccount","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\edb.chk","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\office\\Word14.customUI.g1p3okhzl","md5":"FBF1872A9B15091B7938E5C53E2C9970","sha256":"405F679E545E0924BBD0907A0C2352CB81E1DD4B9A02BDF164E91A2FF124BF5C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\media player\\CurrentDatabase_372.wmdb.g1p3okhzl","md5":"C89377A8CD11189371806606024C9A31","sha256":"48684ED50B51EA81DCFDEC79E108F219F536A1320FBFD0F0F57ECB9806FF2919","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\mapisvc.inf.g1p3okhzl","md5":"35DAA70F57606F1FF19E5570E0BFFCD4","sha256":"A9C36626F5DF65501FA0DD052BB1BA5265841E7C366BFFED80983FEF48E1A09A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\media player\\sync playlists\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\NoMail.sharing.xml.obi.g1p3okhzl","md5":"D7FBD24A29742E803A4B0F030BA20E85","sha256":"2EC3A2AACE001511451597A4713C06D0A9A721E8429D78ED7EA87D2D28C2308E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\account{CAF66E94-0031-4430-A4AC-CD19F582E35C}.oeaccount.g1p3okhzl","md5":"C3773D510B4513AE7E36E5B4C0137E39","sha256":"9966533B3125F569590814C6C0845B8B763B02E9950567C77AB563362F6CE962","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\oeold.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\edb.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\edb00001.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\edbres00001.jrs","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\edbres00002.jrs","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\WindowsMail.pat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\vault\\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\account{D300D4BF-215E-4D22-A101-492F708A0702}.oeaccount.g1p3okhzl","md5":"9B5612129D1525A1C0A6C5AAE3346335","sha256":"FDE605A25E3E337C8D704D09D0D77B5C313979033493CD4D0C640C5747B9700D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\Outlook.sharing.xml.obi.g1p3okhzl","md5":"0EB1E6C8DE0ACC2AB710077F4E429A12","sha256":"C029649539890191F5AA0ED870E3411DD1324F1DF49AE3D0CFEF768E908ECA4F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\account{30CE7C98-AA27-4327-91CA-78FA20FFA850}.oeaccount.g1p3okhzl","md5":"BD4C650D6A00228A570459782A02E69F","sha256":"D9BF1D556149266833D7398618DA81FFFE138555B078DF4FB53247F0ADFA9A9A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\backup\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Sidebar\\Settings.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\WindowsMail.MSMessageStore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\edb.chk.g1p3okhzl","md5":"88B9EAF59028EEF6F41570F0D3005076","sha256":"856C77B59314CE6FD24D52D82281DD52C13E996560C9B05E85A2AD25E170470E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\oeold.xml.g1p3okhzl","md5":"EEB147BC239C25282BB243DDF27D918B","sha256":"AD87FB9E8D3F071C55129EFB25637074DAF113CAF1F868FE782EC05F60F1E05C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\edbres00002.jrs.g1p3okhzl","md5":"0025E0DFFE787351ADD38248D1CDFCE1","sha256":"04BEFE13CEE72A9EB3B67BBA58442C4856BA90A4DCCDF9455F5385280FDFD039","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\edb.log.g1p3okhzl","md5":"810371C5CFA95CD1F83B427368D4A0D1","sha256":"AFB6D4664FC6EE83E2EAA02CEFCB60B1C5FA9A85874E2E6D6617BA3A26CA6A58","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\edb00001.log.g1p3okhzl","md5":"9ACC7C43A263B0EEC4433C902E879DBB","sha256":"862B3646F811F6B960821922D8B572043D33AEE2967E10C653139493ADACCCD8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\edbres00001.jrs.g1p3okhzl","md5":"38C3C494E1B3FC78B4E0061C35F978FD","sha256":"EF412C300C44A1FCB529A6443A8EC477B3A244ACA4F77C11EB4E117B3C54E7EA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login.js","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login.md5","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\WindowsMail.pat.g1p3okhzl","md5":"D9306913397871312200C99D9FFEF3C1","sha256":"B81A0B187DA3FB88624A791DD52CFB45A774655B57CE67CB9A29DE9C76BD3AAB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\windows sidebar\\gadgets\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows sidebar\\Settings.ini.g1p3okhzl","md5":"F4C04C01B564EEECCC8200CDBBEAB24F","sha256":"FB1D5D2EFB19FBE3D126A7AB26100C75E48CDD3AC07F5B40FD54818FCA4BFDEC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\windows media\\12.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\WindowsMail.MSMessageStore.g1p3okhzl","md5":"94606E5353E8DA034D7FC08266F9D2E4","sha256":"78F7FA452FD46107EC13D6BCC06668C40FA0EFCF93711F39A5D719DD46B37880","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\application_cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\opcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\mail\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cookies","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\pstorage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\thumbnails\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Visited Links","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login.md5.g1p3okhzl","md5":"058A1BFFA57FF2CB7CE7DE349FAA29CD","sha256":"E635292AB528A91BBBAE5D37B81EFF96B8F0CA05BD8902358B66ACCBA54205AF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\vps\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\steam\\htmlcache\\cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login.js.g1p3okhzl","md5":"87939E97907382E71D6C9427D33A7D76","sha256":"97F6392FB3031475C90711768F05EC7DADAACA42D13B09A3996DE3782E70EECB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\CURRENT.g1p3okhzl","md5":"42B2BABE46EBCFAFF9C025DE0E170EB2","sha256":"3AEE6D37BAD58759ECB2E626CC73190720130F217F9396F7903DF14DBC1D810A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\UserPrefs.json.g1p3okhzl","md5":"6E0F215A6E224E39586B979BCB6407FA","sha256":"9CB7049D98E32F648C09C7A8F1EBFB06F7B3F2B5115AA437677075928234C573","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\steam\\htmlcache\\local storage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\LOG.old.g1p3okhzl","md5":"77BE95157FDDC9A91F1F0C7F082D65AE","sha256":"5CA04518B759E42F61503B2A7C02F515D6C3A693CAA2F659BDDF4B152C86A5CC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\LOG.g1p3okhzl","md5":"9922BC876DBE1720A8F04DC5BA954A98","sha256":"6A9B09A5E377A9E72E316C872EDC0FB8AA4D2F724FD8A55A0F8F2E33209390F2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\steam\\widevine\\win-ia32\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\Cookies.g1p3okhzl","md5":"F8AA34BDE139079D614A1190EFFF8459","sha256":"A99643215573B92F709255E01D6601D297C77E6D7E4C1A81E73CA9AF21D11BB3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\MANIFEST-000001.g1p3okhzl","md5":"001FA632DAF808DC53E7D7B20F9D3A8D","sha256":"CBA725A2DD119F3CBC35100D5366120D5402B4ADB118DE0BB6C63FB90BCCFFE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\steam\\htmlcache\\gpucache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\Visited Links.g1p3okhzl","md5":"F5A4BFC06D9482FBBE0D9C158899CADA","sha256":"A1ECE5F3AD4F116E2DD51778DDB615252CD74FBFFD823D81BCF268033E598262","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\acrobat\\dc\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\userdictionaries\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\microsoft\\cryptneturlcache\\content\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\microsoft\\cryptneturlcache\\metadata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\microsoft\\internet explorer\\domstore\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\flash player\\assetcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\acrobat\\dc\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\microsoft\\internet explorer\\emiesitelist\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\microsoft\\internet explorer\\services\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\flash player\\nativecache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Adobe\\LogTransport2\\LogTransport2.cfg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\HTML Help\\hh.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\IMJP14\\imjp14cu.dic","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\MMC\\taskschd","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Office\\MSO1033.acl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\document building blocks\\1033\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Outlook\\NoMail.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Outlook\\Outlook.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\adobe\\logtransport2\\LogTransport2.cfg.g1p3okhzl","md5":"2B448F313F7A708727218EFB5834C669","sha256":"A7ED7F472483AE9C4B58B0D4C6297E44012DA6234A0B914682E61944E58C068A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\logtransport2\\logs\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\html help\\hh.dat.g1p3okhzl","md5":"450B4D0C31031A6FD8E72A4AA573EC20","sha256":"55B27479E672632BB6FBA76F635A13ED788D58B7BDF84B39F758813256256864","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\mmc\\taskschd.g1p3okhzl","md5":"92EA7B31C0DF39B265BA54132AB43638","sha256":"C51D7AD0B83323BE4A867C9C284EC0D933998E9DD8637ABFE3FB54FA789F77C8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\office\\MSO1033.acl.g1p3okhzl","md5":"86E1764877C881D62D4B624ADD94FFB7","sha256":"854E48E3F96535838FE881F6356A86040AAEAC58EBFC540A35CC0544E02359DE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\office\\recent\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\network\\connections\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\internet explorer\\userdata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\sonar\\sonar1.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\internet explorer\\quick launch\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\imjp14\\imjp14cu.dic_bak.g1p3okhzl","md5":"4E58130911328B8C7D6617C0F4A008CA","sha256":"9EE959A562ECCE31B0B68CC6BBFEB1701CFAA24823E806AEC6D4B793C15B5D1F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\excel\\xlstart\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\onenote\\14.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Outlook\\test.srs","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\outlook\\Outlook.srs.g1p3okhzl","md5":"B030BA24227E63AEBE0514E7954FC6D6","sha256":"C945944B49956359AED9E674209558B29F642EBE6F2C93CEDE17C53E85DF0CD5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\outlook\\Outlook.xml.g1p3okhzl","md5":"F4356601F758C3770BF8BB3A8820C862","sha256":"F5C9073F5268824F547DACB5BCBABD3089FFEDDC9BC305F023E7540813FE22FD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Outlook\\test.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Protect\\CREDHIST","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Publisher Building Blocks\\ContentStore.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cookies","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\device-info.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\ecscache.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\outlook\\NoMail.xml.g1p3okhzl","md5":"CF4056CE857D0FF6BCA761B2A881824E","sha256":"E3BE6FCEDF9D967E5E1DE7CDB4989FC473C46DD5BDB22E05622CD4E78B766DD2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\device-info.json.g1p3okhzl","md5":"62DB058B154F27E2A8988C91A18B960F","sha256":"D8B244C51AFF27122D844C155721BC0EEB83476575C8C68272D056F2BB93A043","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Preferences","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\QuotaManager","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\settings.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\protect\\CREDHIST.g1p3okhzl","md5":"CD9728903B88AEB3B5A1348222CE66FB","sha256":"13414D984863F2D71C1D146BC9A6215365674173A37978E51E94CB638CCD8E07","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\Cookies.g1p3okhzl","md5":"C553F28D6295E441502BB369B8D8DBE0","sha256":"C41B8E8D22659EF88FAA5144DB3132DD227652B7A12EEA306717D2116E6BA9FA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\protect\\s-1-5-21-1302019708-1500728564-335382590-1000\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\databases\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\ecscache.json.g1p3okhzl","md5":"5774E04210DFE88D12387983466EB754","sha256":"365BBA8F099AE7210FECDFE3A99DF9894D97EE54B5C1F9E6A80C69EA0759E99A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\outlook\\test.xml.g1p3okhzl","md5":"3D18735E96DF6A1907DD3FFFBD8889BE","sha256":"57D8E2D6718439253EE681F62479B129B3426190410DCEF9A534CC07B2B9164A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\publisher building blocks\\ContentStore.xml.g1p3okhzl","md5":"3EEAE725D05CC962AD6E9FB051176AC8","sha256":"3C0149BC16E9CC0D80853D839A042E0137963DC7D1D38A9B5CCBEE457D12586E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\outlook\\test.srs.g1p3okhzl","md5":"F2FA46EBAFA3201C0E7074E6EAE98F99","sha256":"325923391845FC246D1A17AC754736F43052D5736ED1EE3C6431267CEDB9628E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\dictionaries\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\indexeddb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Templates\\Normal.dotm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Templates\\NormalEmail.dotm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\UProof\\CUSTOM.DIC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\installs.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\media-stack\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\Preferences.g1p3okhzl","md5":"3792E621485D40B072E3BAD33CDFFC77","sha256":"0A600A4F6BA91192C6427A62006EA5413EE54FF94A208EB294542BBAE10D17FF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\QuotaManager.g1p3okhzl","md5":"14905A168F1C71F939A2CC0D208CE468","sha256":"0ED29495D97D3D639EABF221E2A0308E863AD58872E173D11ACAC2BA4ED7E38D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\logs\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\settings.json.g1p3okhzl","md5":"9AC87A858BB9FE58A4023A44D69E479C","sha256":"52934EB3A0C64A3444AFAC2C27A53734C4736E2BAD18546E0E8AF349647582FB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\systemcertificates\\my\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\templates\\livecontent\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\crash reports\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\word\\startup\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\profiles.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\backup\\manifest.json@2020-09-28_064732","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Bespin.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Deep Black.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\templates\\Normal.dotm.g1p3okhzl","md5":"32933AE789B15B178C612472E0B717E0","sha256":"042B2518675474082BF60448EECCCBA4842EA340587D4FE9E811C871065A5425","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\uproof\\CUSTOM.DIC.g1p3okhzl","md5":"2799534AC5F4F5B72DA5D3E834D85182","sha256":"1F9E31CCFE99F47B5331AD51B8CEC0AE06875A65B5BA5BB8268A7CB4A6FA8D57","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\templates\\NormalEmail.dotm.g1p3okhzl","md5":"851A79B4F04B391C73DBFFE3F1908061","sha256":"AD83F21B3EB49059E65E0E72DEC95197CA754BCF515748B6821C749AF7B328A3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\installs.ini.g1p3okhzl","md5":"CE2501FC663DE2431C020D69079AE28C","sha256":"BD6526E3A23AC0DF9E91B06A129A9C7913A92350FF4BDCD2F1BFA523F3CE6BDE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\pending pings\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Mono Industrial.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Monokai.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Navajo.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Bespin.xml.g1p3okhzl","md5":"64089F8FDFF9A928138CD421350F84AB","sha256":"1E8958A7E25C607F27FA85D73FC788386AB679D155F50867AFED593831CF19A7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles.ini.g1p3okhzl","md5":"9290C64202E2FDD1537F0B26D9B06C8D","sha256":"80C5EE603E4CE39B6D8B775D1A45ABDCA2DE419C52A80C7E5243B8907DB28301","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Hello Kitty.xml.g1p3okhzl","md5":"2D8D4EBCD91D44E1E5C2442EA3A646F6","sha256":"0D690D91EA2752CF2E22183D4EAEB7BD9AF906B605D94AD613C20BB1C625434C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\HotFudgeSundae.xml.g1p3okhzl","md5":"68876EE850102D9F7D3BA5533B31A7BE","sha256":"39F36564366780D437D43C910EBFA6BB7E6AD9D63DD6872827E772145AF5997F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\backup\\manifest.json@2020-09-28_064732.g1p3okhzl","md5":"BC06DE17FE3A0E0EDECAD9EF908BAAB1","sha256":"006FB91632EAEF6EA54893A79E65EF0A55195617E586B4E3AB146133336D0795","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\notepad++\\plugins\\config\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Black board.xml.g1p3okhzl","md5":"AE718C10F9A92129D288D3497439BD33","sha256":"83D30AD0BF5FF3C1B9946ED1262ECCE1DDB0D88F1296E5E95B1CB66095E5F290","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Choco.xml.g1p3okhzl","md5":"C0C1168A8681FB08C2C61C9DD4F555CA","sha256":"7FA97520024DC8A0450B429F2DBE558F7F2FC67A217B79FEFDD92AB641348E98","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Deep Black.xml.g1p3okhzl","md5":"E3E750A882F710A6643A5092649BAF81","sha256":"510C4D24F3DAFC24BB8D1F44F8C41A7B344743EC6EDE8B1EB41BC0CE1345A936","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Ruby Blue.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Solarized-light.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Solarized.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Monokai.xml.g1p3okhzl","md5":"2C1B81615F80D9C3FA5251D11A3DFC47","sha256":"BBB3827FD784974256F0653550D9169D816318871528AF39D379C0786A90DE93","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Mono Industrial.xml.g1p3okhzl","md5":"92863E5A7514DDC25FCB0EC2EBE72689","sha256":"65EC079E3ACA08CD36AC58F5B6CBB989356B112312D83D8D00E40169EC41F82A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\khaki.xml.g1p3okhzl","md5":"82CC4FA65B15CF46DF4E53AC0DBB67D1","sha256":"811BF7F45E1635F527B250EAB1E6703D8AF7B41631171A4405F9AD19455D31CC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\MossyLawn.xml.g1p3okhzl","md5":"157C2766DFAD3AFB5DF3C02E2CAA8B2F","sha256":"2618B1D9EAE56CC63215229B235B4A1AC06CFB1560DE3CA62E79E016C61D7FA2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\Vibrant Ink.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\themes\\vim Dark Blue.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\bookmarks.adr","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\cookies4.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Navajo.xml.g1p3okhzl","md5":"B622899E16105351131C50D703393560","sha256":"35CC28F802E8A2483773FFFF0ADA222418B68EC469B16507796215239F6686D8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Obsidian.xml.g1p3okhzl","md5":"502FB32B1AA36E8ED159FD2EB9E0A162","sha256":"B553FE9FC6527AAB9A792E79AF1EC5DB7071B1BF2EA7729551D0C1305264497B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Solarized-light.xml.g1p3okhzl","md5":"AF2F8FF23AE621B1306331F1C1FA530E","sha256":"DD1225520DA0EF8AE251BD409948847120091D855B21E9FF9AE921ED3261D6FD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Solarized.xml.g1p3okhzl","md5":"A31F9A69102B0B5E38E770F584038253","sha256":"7E837692E8B64DDADDE442AB8422C1F97489A0B65D736C63C802058CDA451E73","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Ruby Blue.xml.g1p3okhzl","md5":"1D81D30FF2A5B0E8DA8A3EC2D8944044","sha256":"E518B2C720EAE5F42DF644A350A7511FF4AA9439BA3DE1D2923C38EC8386C2D4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Plastic Code Wrap.xml.g1p3okhzl","md5":"4B33EF4F3F4903EFF1E47AC851058673","sha256":"925B1DC88816C027A2F31518E99569B2E888E7CE0311652D7426BCDFB3F4D929","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\vim Dark Blue.xml.g1p3okhzl","md5":"0558079009570AA67517FD89380B9E07","sha256":"019F69829A699587884D6B0D25E8C0112BCDE93644F21AA940A64CB202D6CF4B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\handlers.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\opcacrt6.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\operaprefs.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\opssl6.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\opthumb.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Twilight.xml.g1p3okhzl","md5":"0C92763E137D5A8BF79DE77EB4B8319A","sha256":"7F3E936524F8D195CC583CB8CEE0C06EF84B2F69CCA3B43734BC3114E91D24DB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Vibrant Ink.xml.g1p3okhzl","md5":"C0182CEC390A71F7504B986157DA43DF","sha256":"E3C902085EE762DF43B8D190E02D8BAA9AC01DF03690B6ECA0062F6FB41CBAFF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\themes\\Zenburn.xml.g1p3okhzl","md5":"4C705716AAC5652CD1252C96BB617A10","sha256":"1635A678FE296BEBE9D1D8F78AC065B3674CA8388B8AE2A2A5D9B0FDDA220BDE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\bookmarks.adr.g1p3okhzl","md5":"9A31190527C3FBF0A4DC173F0D342B93","sha256":"CF92345BC06746A42ED17C0EC667991D86B256548AFFF5D3DA2B35013726D471","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\cookies4.dat.g1p3okhzl","md5":"09D5F4636C3DF0CF9900ED3311D36A41","sha256":"500C6CFED6C64ECF6319BF3965C997C4BE3D267E8596484C6FBF82ABA5383061","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\speeddial.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\tasks.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\tips.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\handlers.ini.g1p3okhzl","md5":"84055A909BF612B9510B9BB5182B002C","sha256":"AC9E229AC51C055D6A6C1E9C5BE1A670E64E8A195D6E7FAA66F5E2A887620148","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\opthumb.dat.g1p3okhzl","md5":"D8DFB44E921C08F9A92EBA0366A6CA09","sha256":"390DE1A1A0A0363FEC761A357C53618504441E328D90FC11AD767F9A4637BBF8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\opcert6.dat.g1p3okhzl","md5":"62A81D42803BCE66661EAA6F000CE723","sha256":"DEB4F18F104222F52797E8B80F4D7F026BAFF586C34111A9F7B51A9AFB50E5BD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\opcacrt6.dat.g1p3okhzl","md5":"37754C507B2A9A820D6B1C9EE755172D","sha256":"3FC9656641D713236DA08BC44B5A8C175EDA8CA4A4AA658370E30E1A43C36F61","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\opssl6.dat.g1p3okhzl","md5":"F5C4A45B59FA5E440D759EC9BDF24188","sha256":"332399380B55797E75DE681DFED6E0BD55DC151C67639925AF034AA648FCB83E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\oprand.dat.g1p3okhzl","md5":"217C407F53A0E60AB9098A27F07E39EE","sha256":"2EA2446BE5919BF42A7E6BF5013998C7ED031919B31BFE82CB3353A0BFCDADEC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\optrust.dat.g1p3okhzl","md5":"0E63823884B80ED5DFBC82E76C9F4616","sha256":"2B5CC007441DF57317B9E57C443108C42DFFD87121477323FDB45C012ED4CFB0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\opicacrt6.dat.g1p3okhzl","md5":"09ED8E94BFCD5F799D18D1C78C4AEC18","sha256":"26B7EEE3EA41B9FE0778745E57FB6194B0D54512EFC4397BAFB8303D46F5B3FB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\operaprefs.ini.g1p3okhzl","md5":"2A35746204F63F7FB5F2F18658E4DFE2","sha256":"8446CEBA398B148EDFE27E076A652B312B92D6C4351F346BD7886D3EE37C8467","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\opera\\opera\\sessions\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\opuntrust.dat.g1p3okhzl","md5":"2D1005482DB137F7AAFE17F4B8B1B9C2","sha256":"0E111B3E35637240B30E1CF80D202EB90C5D65D9FD58342BFB578542F9367E24","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Skype\\DataRv\\offline-storage.data","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Skype\\shared_dynco\\dc.db-journal","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Skype\\shared_httpfe\\queue.db","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Skype\\SkypeRT\\ecs.conf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Skype\\shared_dynco\\dc.db","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\speeddial.ini.g1p3okhzl","md5":"EE9EB4C07A8F8AF960DF81B22A7A77E7","sha256":"B79EF8572B0BFE80DFA5DB404BEB5BE326FD35004D6FCB4EEABD4F7F54E077EF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Feeds\\FeedsStore.feedsdb-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\wand.dat.g1p3okhzl","md5":"E884EE6F310C862A4F8A2C4C763F4EA6","sha256":"8A7DF994D86ABF130AF86CE4683C91ED0ECC54CF1F86755C83CD8992F8A379BB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\tips.ini.g1p3okhzl","md5":"7FAAFDE3B595157682168FD8EF3EE519","sha256":"E3198F90F973B9C313BF42143DD774B8AD24171208FD8AC84922EE9E7446BE03","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\skype\\skypert\\ul.conf.g1p3okhzl","md5":"8F77308A05676BCB4246AD999423D653","sha256":"AF9BEA5DD2435CF70846D5B30AC6A547F54CB87BFB54186F81D9B348961BD847","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\skype\\shared_dynco\\dc.db-journal.g1p3okhzl","md5":"3B4B376406187D73C9AB58347667D2C8","sha256":"AAB6F314382776D2FA6FC0B15CBEB933E9019412ED5AEA1B945A3B5F1E45C458","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\skype\\datarv\\offline-storage.data.g1p3okhzl","md5":"4F9904FC2D789A000E10A904B90F4A06","sha256":"1CC8F43A2BBFE26E08A4ED343BAE7AB738566BB308999F414702194C2F940075","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\opera\\opera\\webserver\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\sun\\java\\deployment\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\skype\\shared_httpfe\\queue.db.g1p3okhzl","md5":"3841163F8F35C0C9CA70E0FA62C066A4","sha256":"7B1481E98E6491DA029D436AD544ACA4BF5BABD55D978C89FDD0312B1A6D0B69","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\skype\\skypert\\ecs.conf.g1p3okhzl","md5":"C554DEC311D372A1B1E6867914694D59","sha256":"DE70E3AFC168613A08E74E6F37D3E2A55B5D86282D4710B827BA125EBD239B48","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\skype\\shared_dynco\\dc.db.g1p3okhzl","md5":"8D8FEA2794CBB5C07B80D5452D6A3A14","sha256":"DAB28C01B7A56B3BA338EA763E95E928C957E5823E3DB6B395F069ABFF8EE7B8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\tasks.xml.g1p3okhzl","md5":"B99F8A52B3088D067DD5A41F0D9C0E6C","sha256":"E52746F871D7C5ACBEA97D6834265454B9545C4321950BB6D91A967882E8876C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Feeds Cache\\index.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Internet Explorer\\brndlog.txt","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Media Player\\LocalMLS_3.wmdb","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\skype\\skypert\\skypert.conf.g1p3okhzl","md5":"9E8B5A42491FC654369590F88DAA4B88","sha256":"987831F2C4FF70CBEADAE07597B7ACF11C07F0F286211F7B17C144C7CFD83D5C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\feeds\\FeedsStore.feedsdb-ms.g1p3okhzl","md5":"7FA96E75C967C5A498354A84739BD930","sha256":"FC5B4C3D57146645DB68ECBD4E2B2DE38FC2E846E89367A802FFF0AC827D7DA7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds\\feeds for united states~\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds cache\\9ri45c46\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds\\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds\\microsoft feeds~\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds cache\\hpsk10ob\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds cache\\g4phtcur\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\internet explorer\\brndlog.txt.g1p3okhzl","md5":"F8DEFB749F5344D15743F422405875BB","sha256":"E8541A18A0EA95B2302DF1B895EFF92E7956120921543D5DAA97699DC503D95E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\edb.chk","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\edb.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\media player\\CurrentDatabase_372.wmdb.g1p3okhzl","md5":"A062AD2FDBDAB6C1429D5B2909F60A06","sha256":"D537F25A926A3CC0A730616BAF0449492ADFBB23E408B85E7CDE0551301DAD50","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\feeds cache\\index.dat.g1p3okhzl","md5":"BEDFF846CABBA045E3A8DA8DF508FFA1","sha256":"C7CA39FE4DCCDCBAA7BAE259D349B16759B82DAC2D18D4FF9EBC9B8477AA3A3F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\feeds cache\\vm3jd5nm\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\media player\\LocalMLS_3.wmdb.g1p3okhzl","md5":"8421F165CBA97A6B7A95607FF17BEAC6","sha256":"8DC623C5B2E0C92A7A840676E6351A2E1EE5494B0DD2D49B1D3EC2EB2D61128D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount.g1p3okhzl","md5":"C3EF1361EEE675B980774FBFD696350E","sha256":"2C6CD1581509CC76D450DF3A8FD2D25CF57713A520939217B323AEBEE392350F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\media player\\sync playlists\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\WindowsMail.pat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount.g1p3okhzl","md5":"61342E6034A221B6A62957920BC3A8ED","sha256":"B2E59050AAB15742A648F0D1639DBA0D7E46D2D04E1F67A6BFB19ABE35BCA366","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\backup\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\edbres00001.jrs.g1p3okhzl","md5":"238A5158FB99931A777F40FA94B9C580","sha256":"225D1CC142955DDBBED44E42DB8B3EA944232FB5C29FE366DB5C4101F761C0E5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\edb.log.g1p3okhzl","md5":"83524B2BB95C3332FB4152F9C79CB390","sha256":"9C37B6D9D6860E84537C074EAB7DFC20F027CC6D80893ECD0E9BECEE392FEBF2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\edb00001.log.g1p3okhzl","md5":"6E234936F519E594DF0E7A626A2EDDDC","sha256":"EB9CD7001146AB2B9C45BF8DEA596A4835237D88DF7CA5D75FC95FF1AF180E5C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\stationery\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\oeold.xml.g1p3okhzl","md5":"AA6A79569C4D45D3F2026095B297489C","sha256":"B330F8ABA2966EF9FEF11A65F5FEDA9A5A658ECA4C2086EA4780AC0AD45EA79B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\edb.chk.g1p3okhzl","md5":"A400D6D3EC64CAA5689E7A3410D7234D","sha256":"B5E6E97E128396CF7FF70946F881EF71C77DE6B6B34234FB09CC43662D85C189","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount.g1p3okhzl","md5":"85FE44AD351BBF778F9A1A1D79BBFB30","sha256":"9F9C54A2B942B2D7DFCDB5B6DF4BD4F75C0A4F8537740757E84289FCD04C6007","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\edbres00002.jrs.g1p3okhzl","md5":"2A3DB3D87D86ECB64CA67ADFAD3E3A5E","sha256":"2181C2F4A40A75C70BCED4FDF3AF94E1C285BF8663535490FA1920F72E5D3169","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Sidebar\\Settings.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\WindowsMail.MSMessageStore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Protect\\CREDHIST","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Adobe\\Acrobat\\DC\\IconCacheRdr.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Adobe\\Acrobat\\DC\\IconCacheRdr65536.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Adobe\\Acrobat\\DC\\SharedDataEvents","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\WindowsMail.pat.g1p3okhzl","md5":"E892664E66FBE8AA639C513204A1CDC1","sha256":"10A3BB93811103332BAD1169DE2E1B66AF65C6BD53CFF13F7912AFBBAC581A3A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\windows sidebar\\gadgets\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\windows media\\12.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows sidebar\\Settings.ini.g1p3okhzl","md5":"557A8D662F14648FE5B165B37E106866","sha256":"4607A50E277F57AA845CB3B56060480081D79D7E2AE72D029BDF6F597EE89E63","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Adobe\\Color\\Profiles\\wscRGB.icc","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Adobe\\Color\\Profiles\\wsRGB.icc","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\CEF\\User Data\\Crashpad\\settings.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\ElevatedDiagnostics\\460911090\\2019073012.000\\NetworkDiagnostics.0.debugreport.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\ElevatedDiagnostics\\460911090\\2019073012.000\\results.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\microsoft\\protect\\s-1-5-21-1302019708-1500728564-335382590-500\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\adobe\\acrobat\\dc\\IconCacheRdr.dat.g1p3okhzl","md5":"1AB50A47514F1F38A74601BCD4E6D796","sha256":"F8FFC31816981267DADAC21DA687CC71E55EBB5FE0EDB44526D3A79F6ECB4CEA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\adobe\\acrobat\\dc\\SharedDataEvents.g1p3okhzl","md5":"130263390C0C995EBAADC898EC0E8B73","sha256":"9D8D1F30B3C371FF9C331E6C3303A4C6C006C7E11D92C55E29515CD87A76D134","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\microsoft\\internet explorer\\quick launch\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\roaming\\microsoft\\protect\\CREDHIST.g1p3okhzl","md5":"04C7C2BEA65BEF194E56D752AED6F390","sha256":"710F9C257443A8904D893F2E3101A37AC8EA901FBDA4A7B070583A4B482A1F58","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\BrowserMetrics-spare.pma","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\BrowserMetrics-spare.pma.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\chrome_shutdown_ms.txt","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\CrashpadMetrics-active.pma","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\acrobat\\dc\\toolssearchcacherdr\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\cef\\user data\\crashpad\\settings.dat.g1p3okhzl","md5":"AF3316D28049A9BA3A4C77ABE89AFAFF","sha256":"2C5E887C21F3EAF1CAACAE7D93F7E9C489CE7B3A2538BB3860E836CB0AB62A3E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\adobe\\acrocef\\dc\\acrobat\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\elevateddiagnostics\\460911090\\2019073012.000\\ResultReport.xml.g1p3okhzl","md5":"16F37FF36062367F09C4EC55DA10D1B4","sha256":"A9CAC4FF171C6327364DD964216D5DC2AC51AEA39B8540DE1BEA5CF518468620","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\adobe\\color\\profiles\\wsRGB.icc.g1p3okhzl","md5":"393976ABFA88F334911F6B7397E5F8DC","sha256":"429BA5C485D30F0634518988E8E7CE474315D580FE92B982D14D0C6237C083E8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\elevateddiagnostics\\460911090\\2019073012.000\\NetworkDiagnostics.0.debugreport.xml.g1p3okhzl","md5":"5F38D48E6D412AEC4F4D0E691C667C34","sha256":"4FDDA689DC01A0F9115501B2841C141B03097DC053E3EBFEC086D62EA6ABD16B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\cef\\user data\\crashpad\\reports\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\adobe\\color\\profiles\\wscRGB.icc.g1p3okhzl","md5":"2CB4BC32F3EB5AB1A8060A857F58FAF5","sha256":"1EC5DB0D3F5147BA8CC6B3B495BE39B9E97C855C903249E68013CA32181EC09A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\elevateddiagnostics\\460911090\\2019073012.000\\results.xml.g1p3okhzl","md5":"D5CDA451C193CA93D22828DA98A9E3A9","sha256":"54E6DECA91EF0B547EB4C3F860F4864015C676B4AE5B7C0825706F00487A35F7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\CrashpadMetrics-active.pma.g1p3okhzl","md5":"94BB29AF57416646E2A80372322B29F4","sha256":"73C11C9012967BFA57B27105662B80E5DF8510B0D277CECA7553B3B9DAED5200","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\certificatetransparency\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\en-US-8-0.bdic","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Last Version","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Local State","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing Channel IDs","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\elevateddiagnostics\\460911090\\2019073012.000\\results.xsl.g1p3okhzl","md5":"2840A6220F91E3EA22C0E406A69F6BE1","sha256":"DCBC55D1B9C7D61445810C280D234E3883CB553C5D9389FE65FB32B30DF3490E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\crashpad\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\chrome_shutdown_ms.txt.g1p3okhzl","md5":"111A4D64ACFD6AF3624F8B059081F189","sha256":"3EEFFE36A8E9C6FE6E036017B6D7FC0976BC2BB52D4AAF7E30555CBC2FA1517E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\en-US-8-0.bdic.g1p3okhzl","md5":"BBF73420BB0DD71E6256DC8BF7B6E24D","sha256":"FE5A912322B7F99327B55A5266DC445A64595CAB556F56A49A0EBE21EC015035","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing Cookies","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\Last Version.g1p3okhzl","md5":"6DDADA32A402D4874CB723F164D33CBE","sha256":"BF9B55DC7CD588F7F758391317617C04836E21D61A5BE080590BF8AA099ADB2F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\interventionpolicydatabase\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\filetypepolicies\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\meipreload\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\origintrials\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\Local State.g1p3okhzl","md5":"6F5F1320CD3F86439F3E2072A46EF3F3","sha256":"588A97C027378272C779E84B17CEBD6499A439050C330F40803C2759C66C236C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\recoveryimproved\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\pnacl\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\pepperflash\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\Safe Browsing Channel IDs.g1p3okhzl","md5":"406565E17F0BC17EE396998E9393A444","sha256":"0263B39F925E3129E9505FD3283D2777859AB33632F51D64F0BF9A838A855E12","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\Safe Browsing Cookies.g1p3okhzl","md5":"2539BDE3B25DB627D394ED64FE562017","sha256":"0A122BC97F68B540BA85050235379982A1F91D5BA014305ACB9ADC79874866B7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\shadercache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\subresource filter\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\swreporter\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\thirdpartymodulelist32\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\sslerrorassistant\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\device metadata\\dmrccache\\downloads\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Feeds\\Feeds for United States~\\Popular Government Questions from USA~dgov~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Feeds\\Microsoft Feeds~\\Microsoft at Home~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Feeds\\Microsoft Feeds~\\Microsoft at Work~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Feeds\\Microsoft Feeds~\\MSNBC News~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Internet Explorer\\IECompatData\\iecompatdata.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\1393006d820cae7905d0cd57314ee6ac.sig","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\widevinecdm\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\feeds\\feeds for united states~\\USA~dgov Updates~c News and Features~.feed-ms.g1p3okhzl","md5":"4054B9B839EC07019E3B547CCF21634F","sha256":"E611F8F4AEDAA302A97E098B54B51A3E03A9F64E9C17D0580EA4AFAEBC04D5EF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\feeds\\microsoft feeds~\\Microsoft at Home~.feed-ms.g1p3okhzl","md5":"03A27544F1F3BDD77830291C27B8BA49","sha256":"0C648F4E984348D5A72CE384C8F2032A1D536E7CD3BFB70A7525BBC4DCBBF56C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\1393006d820cae7905d0cd57314ee6ac.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\350db95df4cbd94b2a1c300510e12e11.sig","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\350db95df4cbd94b2a1c300510e12e11.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\54946941a2b45a5ba7f3e1b905b42959.sig","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\54946941a2b45a5ba7f3e1b905b42959.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\5a09d74f269ff6241000b9def1b5daa1.sig","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\feeds\\feeds for united states~\\Popular Government Questions from USA~dgov~.feed-ms.g1p3okhzl","md5":"C9241C356D2060CE3A2308DD71C6604E","sha256":"3189EF6E9963C5DC8BA79EF9F76EA759F4F95A6F78275B507A8CD28CB9F9AB9A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\feeds\\microsoft feeds~\\MSNBC News~.feed-ms.g1p3okhzl","md5":"8EE6319CA4FEE8B8A15B20316B9FD1F2","sha256":"30275280187680D9CE929CEB9A5296D57AB0C7C8A7F1472FD83C6081AB8BED5A","type":{"value":"ini","type":0}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\recovery\\last active\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\tiles\\pin9728060290\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\media player\\sync playlists\\en-us\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\recovery\\active\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\feeds\\microsoft feeds~\\Microsoft at Work~.feed-ms.g1p3okhzl","md5":"9A6830E7343D39707528DCBE857BE7DD","sha256":"38AF4BE1B9B2BFF718E5D0C00E36ED8C4B69D45BE8FC8BC7F0B4D96304345B90","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\iecompatdata\\iecompatdata.xml.g1p3okhzl","md5":"0D729C065D1AD3BD857B032C8BCD1B2A","sha256":"90F31AC7D8E59A285E22BFF84E8ED0C9915F1ED002015DB3C54104D2DE206F53","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\internet explorer\\imagestore\\f7ruq93\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\office\\onetconfig\\1393006d820cae7905d0cd57314ee6ac.sig.g1p3okhzl","md5":"C662A3FE931FE574361F1DF16DE4B3FC","sha256":"DAC282F089185C1F65D874B7A546A30F59742D9CD57077E1C51C5943E8E3CF08","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\feeds\\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\\webslices~\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\office\\onetconfig\\1393006d820cae7905d0cd57314ee6ac.xml.g1p3okhzl","md5":"70F597AC21A2283C7822081A7619947D","sha256":"55E44FC7C503B528D936B4CAFD9ED69DBE4558DC68EFC6EF19312EF5D56E7C30","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\5a09d74f269ff6241000b9def1b5daa1.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\786b7d3a5372048de949b5ce333fe46e.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\b6419f5bc3093b5f22142ce454e02407.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\f0008bc476267c1e98c0470af48ad1f1.sig","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Office\\ONetConfig\\f0008bc476267c1e98c0470af48ad1f1.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_AvailabilityOptions_2_CD58CB9DEEE452498F56DC1A846E5975.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_AvailabilityOptions_2_23FD1CF2FAF3F94682CAD351A9FDDEA2.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_RssRule_2_96F3484B9ED2D94B95F3AD8E7B97CB78.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_TCPrefs_2_45E962C95E9CC142AD866F2A79C07496.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Outlook\\RoamCache\\Stream_WorkHours_1_6802D3577154DA4CA0ADC4DEF069DFF3.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\office\\onetconfig\\350db95df4cbd94b2a1c300510e12e11.xml.g1p3okhzl","md5":"D5F9F4673B50FBCF2CD8442D9670BD45","sha256":"CFC03D037EBE7A67FF057826C920B78AAF48B18AF35BDC15BEE5F39A4675EA5C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Vault\\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\\Policy.vpol","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Bears.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Cave_Drawings.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Connectivity.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\Stream_ContactPrefs_2_62969AE26D446C4996E38BA49FC32ECB.dat.g1p3okhzl","md5":"06BB64FC680F7332C804791A50922CF9","sha256":"62D6D56E699391D8C77CBF92E62206B9BDF45A3F1DF135669C8F25D89CDB52E4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\backup\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\Stream_TCPrefs_2_45E962C95E9CC142AD866F2A79C07496.dat.g1p3okhzl","md5":"07631F2AC5236391AE393C5EF97B43A9","sha256":"F3C8562C507F67E885C57442320B6C6CB08CCFF174742D9A9CAF1C3D7401B885","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\Stream_Calendar_2_48B40665B99DEB428CFF32F0AF94F96D.dat.g1p3okhzl","md5":"04208DD848360C472650997D394EF60D","sha256":"035E21C4FEE01EF5D71B6755250059DBF931AECD75629C262CC62C89BE7E5D19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\Stream_ContactPrefs_2_6EE9E0986F47D24E87D65C60540EF19E.dat.g1p3okhzl","md5":"38590F6D4C2F96194D007B409693B676","sha256":"C2188457AD0C7CEDBEA4626318A9663FBD0F1A899A1CDA134B9EBFE9DCF4A09A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\Stream_RssRule_2_96F3484B9ED2D94B95F3AD8E7B97CB78.dat.g1p3okhzl","md5":"300278777AFD7F3401A07C794198C337","sha256":"288C613F32EB4667F51DF03B09F4A67981692570B07145910564201FD77AF7DB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\Stream_WorkHours_1_6802D3577154DA4CA0ADC4DEF069DFF3.dat.g1p3okhzl","md5":"0A9BA03DE56F167729201D9C392FF4DB","sha256":"CFFDDB7A5293F1CFB0FA6F5F164722F9A212606591CD600DE37D478176D6283D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\Stream_TCPrefs_2_73A40DAA9DAD6842B5772AD2C56B885A.dat.g1p3okhzl","md5":"7AC3EFB891E05DA8A9918DCACE2BF6BF","sha256":"9842194E336F9E665734DFBB94B3D7D77F9C23B27DB26F6E326CD35A5EFACC0A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Dotted_Lines.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Garden.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Genko_1.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Genko_2.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\vault\\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\\Policy.vpol.g1p3okhzl","md5":"4BF8A42D00BDD713640C1887D08A1A99","sha256":"7162232944F3490E6902D5397282FA36E8CF1AD867F10A03E5D6AD24D90A6341","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\outlook\\roamcache\\Stream_WorkHours_1_8FC9729CF512CA4FA746794186CA09FB.dat.g1p3okhzl","md5":"2AA5CF02D33D02F6A4EB557470517526","sha256":"7774D12B26F886CFEE30CAF370B92BB5B09823DC32A906B7CE11E1B684245325","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\backup\\new\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Bears.jpg.g1p3okhzl","md5":"9C45CE85422A197CC78990B84BDEE02D","sha256":"0C73CEAA11FA6CED84A82269D1920E12F58AFFA2C7008D241AA4C16A6C6AA719","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Bears.htm.g1p3okhzl","md5":"7044F3B973D2EFA3EBAACB8810675E36","sha256":"FCF1FA457AC7AEEC9C403B1F1BB2DF331D6FCF9F233EA3BDE198D62632F8B97F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Blue_Gradient.jpg.g1p3okhzl","md5":"C327D783214E70981DE7022A60A3525B","sha256":"26420958506F4CA20687BF54EDEA1DB43815959F06EB5527DF53777C20D0975C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Cave_Drawings.gif.g1p3okhzl","md5":"13DDFB44FFD265FD51D49A80C6390916","sha256":"CB124439C0D01FD9EBC59CC39B482634C8FAF881F1839E5FF8F3EEE890D88FF2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Genko_1.emf.g1p3okhzl","md5":"780449AC335A1A5B7233C7170D34DFB8","sha256":"98D596F51A407AD61B724A736D7C5987C3058DF522E65850DD5A9062B42DB961","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Graph.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Green Bubbles.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\GreenBubbles.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\grid_(cm).wmf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\grid_(inch).wmf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Hand Prints.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\HandPrints.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Dotted_Lines.emf.g1p3okhzl","md5":"BE2ED9EC355DAA189634C106110528AE","sha256":"AC8D44E20D177458C1FCAD96D21F8F2B99087A1F0375BD0DBCC68F5349A4CDBE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Garden.htm.g1p3okhzl","md5":"ADBE4C6A0856EDE226F14294E5ED2EE3","sha256":"D3D8E476886331752E41BAF1E02FA526841EE52A642F9EBA00CB6CAC2C48D0E1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Garden.jpg.g1p3okhzl","md5":"046E7C7D654B5C0E5AC29864288A074E","sha256":"6FC4084BC050285CC471AEDD8436601984543E96B596C80387FDC776AA26B1A5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Connectivity.gif.g1p3okhzl","md5":"E507AFD81406C2E29406910C377F65F6","sha256":"758AF58C11CFA0697777E72FE5B08BC940FFAF6C614C65EA8625A06C2BB1C2E1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Green Bubbles.htm.g1p3okhzl","md5":"D5A0C45F8045495B9CA9EB20DB11B350","sha256":"8F3E5211AEFB620651F0C46C2E71915BC608DACD4FA6E6D24424027C96C1D9E5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Memo.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache.onecache","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Month_Calendar.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\OneNoteOfflineCache.onecache.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Music.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Notebook.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Orange Circles.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\GreenBubbles.jpg.g1p3okhzl","md5":"FF5A72C4F02245FA1B41CAEC518F9EBF","sha256":"7991BFF9B1E9296CC4798864D705267D3A44217168B5B765BF73A99C24ADFFCF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Genko_2.emf.g1p3okhzl","md5":"C352C73FC1FAE829D942898DAB8073A9","sha256":"A900EBFF1D309DCB1235E0EB252281601052563DD019C35785F935AF628299CB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\grid_(inch).wmf.g1p3okhzl","md5":"F56EDD2BA259D3925C68B55F50BF0B68","sha256":"7C0A562A77842EB8AF01ED156752E5370D78F5C0205ACA45904BD8F9B3D90F30","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\HandPrints.jpg.g1p3okhzl","md5":"9B877A71AFBB077BE916126C06A17B96","sha256":"4061EE8C5AE3548942E53646A7CF79E3E5A4C5C2348CC65976243E48B9CF432A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\grid_(cm).wmf.g1p3okhzl","md5":"B9E341D7B7B67721EB188648ECAE9558","sha256":"54B8571C2234F2C9E3E038D454B851BB765822ABACC3C50307DB23353DE02CB8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Hand Prints.htm.g1p3okhzl","md5":"BE68CF551F8880576888EB0E90C9BF3B","sha256":"02FF5D813B31F8944CB434228746C477D28BBC0E99EFB7B1F0A94A8179A0D703","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Graph.emf.g1p3okhzl","md5":"30D38A8744F2AF2402792C21A26510A9","sha256":"E3A216219430371E2D6B346889C5F46ABF7E3C7EE76E3E1E621D65E90FC2635B","type":{"value":"flc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Memo.emf.g1p3okhzl","md5":"E40240B20D3611D5F29B61A5B20B26BA","sha256":"CD728C6AB75E0916C56634459295D6DC2205239A6AFD4BFDD1BF8A91FDB40E19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Monet.jpg.g1p3okhzl","md5":"F57AE13DB3B7E8C40755255495353824","sha256":"68EE73ED6C18746246D6A6F447646EEE513CC08F658A7EF8682BA19968E1A3B0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\OrangeCircles.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Peacock.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Peacock.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Pretty_Peacock.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Psychedelic.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Roses.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Roses.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Sand_Paper.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Seyes.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Music.emf.g1p3okhzl","md5":"814362A190A538E599409A910AAC734A","sha256":"A08951295D1F5942185BAEC2331ADFA253669D617E7BC251D09A948FAF2E923D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Notebook.jpg.g1p3okhzl","md5":"AE3A7E2D36B2AF65C2EC9D828A8E8AE2","sha256":"DF73F38E1BEE3AA8F91BEB6AB48BB03E66103791D906562E4D647579F878D7D7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Month_Calendar.emf.g1p3okhzl","md5":"A8A09687939F56ECF4D58A050C843FA1","sha256":"0A1D5FB9043C78F08716E5E3B136DE60FE8660B799F4ADF9863037EF3E876022","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Peacock.htm.g1p3okhzl","md5":"A0CDD19616A59F40873E09FF87542429","sha256":"68051B28D4DCC38D45B1E1675C33B4DB614C17609B62BE3C34886E305AE7AB03","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Orange Circles.htm.g1p3okhzl","md5":"A56F47A7A8DD114D70BD7452C4CD04EC","sha256":"11AD9E6BFB6480896C5172CDB099102327DA3FDD4FA533D859AA33FD8A4DBABA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Pine_Lumber.jpg.g1p3okhzl","md5":"32AF0AFA03435D6CCDA02397AC9A9B94","sha256":"8A947683D6A16C42EFD9C68DFB5DD40B13C911EC949FF1376398D1C7F8F79B7B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Peacock.jpg.g1p3okhzl","md5":"456A5DE2B95BFF8204F72C7F42F84494","sha256":"7CF0B6414282FA99A31FCA0BA3E514862791D6C8A7DD81927549787B4208D841","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\ShadesOfBlue.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Shorthand.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\SoftBlue.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Stars.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Stars.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Stucco.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Tanspecks.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\To_Do_List.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Wrinkled_Paper.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Media\\12.0\\WMSDKNS.DTD","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\application_cache\\cache_groups.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\OrangeCircles.jpg.g1p3okhzl","md5":"14A14529752AF6AB535A9A535CEFBE14","sha256":"774F0E28731493D608B7B752032E1F3B4A35EE5E56BC6595ECE292D438B5EC99","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Roses.jpg.g1p3okhzl","md5":"FCB72810F14095FD075C51B801AB7F55","sha256":"727D283391D682B6FC653595F7B948588E6E57507469D38E2B70F286F742A369","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Pretty_Peacock.jpg.g1p3okhzl","md5":"732DAEDB2AD5C10A8C05C9174D67B187","sha256":"CBD03EBF2E6C1C843BAA07183F235F50DD67FB0A514B11BDF9685B7E7D046EF8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Roses.htm.g1p3okhzl","md5":"62C58EAA79E68A040E848665BCAC3E22","sha256":"247EBB0A203E71EF026E91360D19B66306725518F14BC413DCE76428C626758D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\Wrinkled_Paper.gif.g1p3okhzl","md5":"5C03A062E437D88912F033C3203124A9","sha256":"B5CCF764704CC4E26891BC6586B5C254AA43198E3042E53E5FADDBEE18F2FBC0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fimg.imgsmail.ru%2Fr%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fimg.yandex.net%2Fi%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2F%2Ftravel1%2Fde%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Falternate%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Famazon%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbigpoint%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbing%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbuecher%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fdownloadcom%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Febay%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fexpedia%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Ffastmail%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fgame%2Fde%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fhawesko%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fhotels.com%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fidealo%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\stationery\\White_Chocolate.jpg.g1p3okhzl","md5":"4555B9895085AB2F188D80C6C39FB9C3","sha256":"E40B31BDE11D77888EE7963F56E7106124DB3FE810BADDE19F8A921078B5153B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows media\\12.0\\WMSDKNS.XML.g1p3okhzl","md5":"9E7612433EC00247CC8453010448932F","sha256":"B658009D22D658A782747A665530336A34AC3E8E82BE133BE265ABEFA0268F98","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows media\\12.0\\WMSDKNS.DTD.g1p3okhzl","md5":"6074AD8FE288AB35F4C2852EC0CC8A13","sha256":"14C5A12BD010407BFE7FABC67CDDA4C303215495C3BD450148D079CDB23B953A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fjavari%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fmeingutscheincode%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fopera.sports.com%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fpreisvergleichde%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fproperty%2Fde%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping3%2Fde%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping4%2Fde%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping5%2Fde%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fsportscheck%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fsuperdry%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Ftravel%2Fde%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fwikipedia%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fxing%2Ffavicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fproperty%2Fde%2Ffavicon.png.g1p3okhzl","md5":"167537C0B2EE74A8130EBAFE2A573B5C","sha256":"89224A8DE3C56F8D511A84AD7EA869020425A03399B2E4FF097599C10BA883B8","type":{"value":"ppn","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fwikipedia%2Ffavicon.png.g1p3okhzl","md5":"F55F500CBE52BAA6488C8DF5D0E0271A","sha256":"FEBC4E5F0A5D7C46B1CC51172C15A47FE1034FB4C749A8D371BC58B871422BB6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping4%2Fde%2Ffavicon.png.g1p3okhzl","md5":"2C909180BF2CDB216AE5B280CCC7AD83","sha256":"1A150E6BB84516DA6884D9E9C594FD064E6B2D29A4AEC827C79684F55C707120","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fsuperdry%2Ffavicon.png.g1p3okhzl","md5":"A2DA641184A89743F5BC663DA43308D7","sha256":"F465E6D4C619E8119D1BC050F7861E89A2FF27777E720684FF8E499C7D9F2587","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping3%2Fde%2Ffavicon.png.g1p3okhzl","md5":"3E003D325ECCFD9B9B567B177B8B5C3A","sha256":"05C4ADCFE136CBFB5E50AB583B9D3E3814E74D004A12DA8CE139196C27E54866","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Ftravel%2Fde%2Ffavicon.png.g1p3okhzl","md5":"03368C93AB0A56EC7461A1BD967A7DF1","sha256":"7C9642E73A3291674C43C50E644FF315F3FA6DF7A245B3278BB2CD6CC35D5357","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\icons\\persistent.txt","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\mail\\accounts.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\mail\\omailbase.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\pstorage\\psindex.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\thumbnails\\2a5473f7-518b-6946-8c75-2ef10224edbd.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\thumbnails\\78922692-3601-de42-ac06-e30a85bf5633.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\thumbnails\\88d94439-10e6-1a4b-87ed-7e884296ac9d.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\thumbnails\\66114aa9-90a0-a846-a71a-1b301e6d3436.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\thumbnails\\a39d20f8-580e-9042-8d4c-c6be0dbbdc85.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Opera\\Opera\\thumbnails\\db8a2a05-cf67-924d-aebe-4f3590c88d40.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fxing%2Ffavicon.png.g1p3okhzl","md5":"0AAA50F332EF239DDD0C83F570C49244","sha256":"D78D1A04A4EB13426F67796B7836908613C970B4583CDF6AAADACABA5B72BA0E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\thumbnails\\66114aa9-90a0-a846-a71a-1b301e6d3436.png.g1p3okhzl","md5":"7996D03A0373A3EF12245BE33C2CEE63","sha256":"2BEB70F452162C228A8EB648EEE89F2CD25E8BA28A8B34F7BB7B27FF40E232C9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\icons\\persistent.txt.g1p3okhzl","md5":"886E14B391C70BC28ED600EAE644E6B5","sha256":"8D2F874D5C99D7C22A392AB7CE0986C572BFC055E2161FF620F518FD1BA9D653","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\opera\\opera\\mail\\indexer\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\thumbnails\\2a5473f7-518b-6946-8c75-2ef10224edbd.png.g1p3okhzl","md5":"0174DFA5B208180E116184B943D73066","sha256":"CB02A18BC3AB72C4FCD88BA2D990D165E88E143EF1B95411296313BF531D9056","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\index.html","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\data_0","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\mail\\omailbase.dat.g1p3okhzl","md5":"2FB2D1B2764936C4F4502F6126861275","sha256":"851F7749A8A2BBAEE678976F26CBEBC1E3A1E221F76641946B68C9F15ECD006A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\pstorage\\psindex.dat.g1p3okhzl","md5":"90FB21441EF2BC80E0DB382EEE489E18","sha256":"40B3542CEC2C93EC55C2E1AB44D767FAF9A4ED3B2D79B5AB9B1350E46E6A8510","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\thumbnails\\78922692-3601-de42-ac06-e30a85bf5633.png.g1p3okhzl","md5":"FB7D4787B6005F44E78B55FDACD7B360","sha256":"51CC225C86E083A05E6C86D1540C9D0437692757774FB8E4151F657B6788F2FC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\mail\\accounts.ini.g1p3okhzl","md5":"4F82F9DAB8FC8CD0ECBACC77589D7DD8","sha256":"28EABE66D644052A66F84D28CA6DDCF413F211E2823C0D33250F059FCDBA455E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\thumbnails\\88d94439-10e6-1a4b-87ed-7e884296ac9d.png.g1p3okhzl","md5":"F33D77A2CF5E98AD0280994E4DAFEB0D","sha256":"DF18B1532FB7B787B3697B5481D342F2AE3526E5226325B52676F3D2565C61B5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\data_1","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000002","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\css\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\cache\\data_0.g1p3okhzl","md5":"6B6D0B2A92BDF617B8306A43692BD258","sha256":"427F4235D9C1D9CDB63D58FA009405A2AE26760DCE85BAC6CDA85FF6851D3E9F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\thumbnails\\a39d20f8-580e-9042-8d4c-c6be0dbbdc85.png.g1p3okhzl","md5":"C61BE4B4F4891C8F9DD0206650BEB943","sha256":"DECFBA80AD9CA185CBD833FE049D1A000693E81270B3163256CF9F6C100E32B8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000003","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000004","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\data_2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000005","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000006","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000007","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000008","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\cache\\data_3.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00000a","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00000c","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\opera\\opera\\thumbnails\\db8a2a05-cf67-924d-aebe-4f3590c88d40.png.g1p3okhzl","md5":"6B1F7C5D50B18E34E0CBE2A55715D830","sha256":"E03FBC6CCC07B537A6003BA223BE0ACB49884BCC18F3EC06FC5E323DE85C8028","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\js\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\index.html.g1p3okhzl","md5":"92CE904FED035FDF0C53D851A41C2B89","sha256":"6894A5FDD8C9846B7612B38B2EFA42392438FDA866F7574DE59A7B9F788AE442","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\fonts\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\cache\\data_1.g1p3okhzl","md5":"EF50709F8CC04281BDA6C76D3D3D5BA0","sha256":"D3AE9EB31EFD57657E0A80218A113F65F0EDE896D206B22A22C734237B837006","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\cache\\f_000002.g1p3okhzl","md5":"779EC8966EDBF528745B7C6AE6668F55","sha256":"5481E3B4FFC72369F3AA24C06A4E76C4AC7293DCC9963CAA9C685672F605B61D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\steam\\htmlcache\\cache\\f_000004.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00000d","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00000f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000010","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000011","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000012","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000013","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000014","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000015","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000016","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000017","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00001a","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000019","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00001b","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00001d","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00001e","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00001f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000020","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000021","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000022","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000024","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000026","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000027","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000028","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_000029","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00002a","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00002b","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\f_00002c","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\GPUCache\\data_0","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\Cache\\index","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\GPUCache\\data_1","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\GPUCache\\data_2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\GPUCache\\data_3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\htmlcache\\GPUCache\\index","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\widevine\\win-ia32\\LICENSE.txt","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\widevine\\win-ia32\\manifest.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\widevine\\win-ia32\\widevinecdm.dll.lib","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Steam\\widevine\\win-ia32\\widevinecdm.dll.sig","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ReaderMessages","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\0177A2B8C3D6561744552D69E6BD54B0_B5357881C6869885123E561DAC437ED4","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\37C951188967C8EB88D99893D9D191FE","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7396C420A8E1BC1DA97F1AF0D10BAD21","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7D47591F685839F691F1B515B0DB0F25_59063E60BE874E8CE69B5F73CD0A6F4A","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\9FF67FB3141440EED32363089565AE60_44236A066113E3C74C35190DEC1279D1","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\C0018BB1B5834735BFA60CD063B31956","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\C8E7EC0C85688F4738F3BE49B104BA67","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\EDC238BFF48A31D55A97E1E93892934B_33E8F98A524575FDD27708D6D61F97ED","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\CFE86DBBE02D859DC92F1E17E0574EE8_FDB452422670E72EDD3FB3D65568F821","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\F5F320A94D4D2B4465D8F17E2BB2D351_60A90EF97C6DC44545D376D099B4C503","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\F5F320A94D4D2B4465D8F17E2BB2D351_A99A07230F6CAED4AE3E1AF557CE3A48","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\F5F320A94D4D2B4465D8F17E2BB2D351_D87AB72AFD41327FE27102668732EE67","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\F5F320A94D4D2B4465D8F17E2BB2D351_E869F13BA1AD9D03A59135BB0775734C","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\F90F18257CBB4D84216AC1E1F3BB2C76","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\0177A2B8C3D6561744552D69E6BD54B0_B5357881C6869885123E561DAC437ED4","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\696F3DE637E6DE85B458996D49D759AD","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\7396C420A8E1BC1DA97F1AF0D10BAD21","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\7D47591F685839F691F1B515B0DB0F25_59063E60BE874E8CE69B5F73CD0A6F4A","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\9FF67FB3141440EED32363089565AE60_44236A066113E3C74C35190DEC1279D1","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C0018BB1B5834735BFA60CD063B31956","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C8E7EC0C85688F4738F3BE49B104BA67","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\CFE86DBBE02D859DC92F1E17E0574EE8_FDB452422670E72EDD3FB3D65568F821","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\EDC238BFF48A31D55A97E1E93892934B_33E8F98A524575FDD27708D6D61F97ED","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F5F320A94D4D2B4465D8F17E2BB2D351_60A90EF97C6DC44545D376D099B4C503","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F5F320A94D4D2B4465D8F17E2BB2D351_D87AB72AFD41327FE27102668732EE67","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F5F320A94D4D2B4465D8F17E2BB2D351_A99A07230F6CAED4AE3E1AF557CE3A48","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F5F320A94D4D2B4465D8F17E2BB2D351_E869F13BA1AD9D03A59135BB0775734C","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F90F18257CBB4D84216AC1E1F3BB2C76","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\LocalLow\\Sun\\Java\\Deployment\\deployment.properties","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs\\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs\\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs\\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Adobe\\Sonar\\Sonar1.0\\sonar_policy.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Office\\Recent\\index.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-1000\\29fd2168-360f-422a-a685-e6961ea74ba8","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\OneNote\\14.0\\Preferences.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-1000\\451dae28-ab14-4bab-ad67-c408b61f9bf3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-1000\\54ba308a-6a9a-4e0e-b137-b89d3579498b","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-1000\\695afb95-3f91-48ff-ab15-a381eb1da4c2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-1000\\a7df5a71-8b48-49c7-a232-b87da37a17c7","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-1000\\fc958741-2c2f-465a-852a-5ea30b2a11d1","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-1000\\fe07f945-3a9b-49ff-b54f-5b2e9331906f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cache\\data_0","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cache\\data_1","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cache\\data_2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cache\\f_000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cache\\f_000002","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cache\\f_000004","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\f_000002.g1p3okhzl","md5":"AD9A671664B3F27B9EE4B52EFF955272","sha256":"85B712C16D080FDBA24E4D82E848142CB0EFD547D01F5F1808B3A3FF35C3543C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\f_000003.g1p3okhzl","md5":"87351EF874873547CB3BC41D8BF14164","sha256":"FE24514F1EAE03E0E582DF5754EAC98B39EBA585A8F2C66CF3106122D231929E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\data_1.g1p3okhzl","md5":"368469C2D46F3FAB8252CD7D395CB410","sha256":"5520041A49068E1456B5324C858CD89791891CD835F77916537F29AF6658C8F9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\databases\\Databases.db","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cache\\index","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Cache\\data_3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\data_3.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\dictionaries\\en-US.bdic","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\media-stack\\Skype.msrtc-0-2576771366.blog","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\media-stack\\Skype.msrtc-1-1870167131.blog","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\media-stack\\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\media-stack\\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\data_2.g1p3okhzl","md5":"82AB2B16AEC05430D87127DCFF79B73A","sha256":"61628BE2DFA0C78EE6B30ED8DAB47F32C51396B41614FCE9CCD964163FB35FCF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\f_000001.g1p3okhzl","md5":"52CA5D82AE0CBBF9BD55BF569202ED48","sha256":"FBAE6B9982A95EB827FA37CA0757CCE23E15A034111C198B375FBD8F13F65800","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\index.g1p3okhzl","md5":"A26B31411A7ED2488D86AB51DA73B117","sha256":"48F3BE33250FEE0988D6CCE614C0B777435FD48E3CE12D9B4126FDD042668A40","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\skylib\\shared.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\skylib\\slimcore-0-4223384469.blog","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\databases\\Databases.db.g1p3okhzl","md5":"69282099AFFB4F6BCC6C388E60ABD2F0","sha256":"3E77F10FE9641B902DC43B43BD84AECBC6FADEB745863EE6D0EC1F8420A4B91C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\indexeddb\\file__0.indexeddb.leveldb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\cache\\f_000004.g1p3okhzl","md5":"454549EC9E495289255B96F6AC080177","sha256":"B28C7460C5981ECFE1A3F6C8E5DBBA7E3E536AC94B1DAF3364C2643D68EDD671","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\leveldb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\media-stack\\Skype.msrtc-1-1870167131.blog.g1p3okhzl","md5":"25EBD50F4128A8497C5AF3AB9294588A","sha256":"DFA752885F61F80FBC4320B3827414E8B47ACE6C74281318BBB6AD86277982ED","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\media-stack\\Skype.msrtc-0-2576771366.blog.g1p3okhzl","md5":"79C5575E2FFD97BC6F41AD31B26F9C6A","sha256":"B706D6281C1872F52F5AB41110BDF7C32ADF3FA971DC5A241C1CC4823003567B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\dictionaries\\en-US.bdic.g1p3okhzl","md5":"98F4F6180091D33F93A32A598D3A6903","sha256":"F1C0AE6B807F8990E8885DEF4B17E5CF3122D34C19CA1381E25B5DC59925DBDB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\media-stack\\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.g1p3okhzl","md5":"3E1013794996B9BED8E3B549EDE12D42","sha256":"4CAE96673793B9C8342AA6860668433E9B5A18B47FC9B99F0EF67935D58C5C0F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\InstallTime20180807170231","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\live#3agabriel.radrigos\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\datarv\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\slimcore-0-4223384469.blog.g1p3okhzl","md5":"59B1CD7F3EF1B26C7E8BAD603D49C556","sha256":"25FDCB6A7859A2B3D48ADC1EC9E4234F27A8AB05E0033E78916C5ECC816C4A4A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\systemcertificates\\my\\ctls\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\systemcertificates\\my\\keys\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\media-stack\\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.g1p3okhzl","md5":"A81B3ECF98FF32DE1BF1D51090916C86","sha256":"46D3EFF96045A83B7E1C613A7BCC6921EA0358A875019EFD9E6FA253484BE1A3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\systemcertificates\\my\\crls\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\systemcertificates\\my\\certificates\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\shared.xml.g1p3okhzl","md5":"598B03ABFC40774BC9EC57A98219E175","sha256":"71B93E206E50B86BC601612116EE535E81F09A885D3306E332F0A164585E1989","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\InstallTime20190619235627","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\InstallTime20190717172542","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Notepad++\\plugins\\config\\converter.ini","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\webserver\\users.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Feeds\\Feeds for United States~\\Popular Government Questions from USA~dgov~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Feeds\\Feeds for United States~\\USA~dgov Updates~c News and Features~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Feeds\\Microsoft Feeds~\\Microsoft at Home~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\crash reports\\events\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\crash reports\\InstallTime20180807170231.g1p3okhzl","md5":"E40E97E3480B8B117EBCE624784645FD","sha256":"BEDC06AFEFF5775521CC1BB7087FEABAE934D62ADDF81C1F48BA675E474C330B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\templates\\livecontent\\managed\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Feeds\\Microsoft Feeds~\\Microsoft at Work~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Feeds\\Microsoft Feeds~\\MSNBC News~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Bears.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Bears.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Blue_Gradient.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Cave_Drawings.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Connectivity.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Dotted_Lines.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Garden.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Garden.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\crash reports\\InstallTime20190717172542.g1p3okhzl","md5":"356861090719CF294818F6F362E90A3C","sha256":"7E48CA685CBC3D40BEAF4BACDB67757B2E3830C223EA7E18C6F5464C17BC46CA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\webserver\\users.xml.g1p3okhzl","md5":"7B2245DAA01C4993660CF343F6660560","sha256":"6C530BEFEF04382E1B90C2FB89646679E386890348D443C6747C62142F6DBE1A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\crash reports\\InstallTime20190225143501.g1p3okhzl","md5":"D9FC3E31F0164015B0F17D6B95626C7C","sha256":"10CC11B6C0E721F52E11DCDB9258A8A63CEBACA2A9BF24AF4A0FD8D188EA6005","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\crash reports\\InstallTime20190619235627.g1p3okhzl","md5":"6711DA67911094C691B4A6288C4045DE","sha256":"6D7E9375001135B0953956B81B1886475C1B5944FC86CFE037617F51AF3B0BCF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Genko_1.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Genko_2.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Graph.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Green Bubbles.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\GreenBubbles.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\grid_(cm).wmf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\grid_(inch).wmf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Hand Prints.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\HandPrints.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Memo.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Monet.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Music.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Notebook.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Orange Circles.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\OrangeCircles.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\notepad++\\plugins\\config\\converter.ini.g1p3okhzl","md5":"20070C3F97B9EB7C8B3F68D1065903C2","sha256":"2438A6A7D4EE11B3AAA14B485C2BF19AE615BDFE200E71FD1DF1CE4B73C429F0","type":{"value":"bs","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Peacock.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Peacock.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Pine_Lumber.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Psychedelic.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Roses.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Sand_Paper.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Shades of Blue.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\ShadesOfBlue.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Shorthand.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Soft Blue.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\SoftBlue.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Stars.htm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Stars.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Stucco.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Tanspecks.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Tiki.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\To_Do_List.emf","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\White_Chocolate.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Stationery\\Wrinkled_Paper.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Media\\12.0\\WMSDKNS.DTD","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Media\\12.0\\WMSDKNS.XML","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-500\\e772058d-056e-4021-b783-db194666b156","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1302019708-1500728564-335382590-500\\Preferred","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\BrowserMetrics\\BrowserMetrics-5F718DAE-CB4.pma","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Crashpad\\settings.dat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\browsermetrics\\BrowserMetrics-5F718DAE-CB4.pma.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Favicons","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History Provider Cache","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Last Session","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Last Tabs","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Favicons.g1p3okhzl","md5":"DA911892FD7047FC58C26B7D98397DD9","sha256":"FD196D3A92F7D5116FD8518C922C68FC3AADD954549770A9F0AAFC1E1BA87983","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\LOG.old","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\MANIFEST-000010","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Network Action Predictor","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\feature engagement tracker\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\indexeddb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\gpucache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\History.g1p3okhzl","md5":"1E6EDD6FA5635B2F39598FFF6DF30679","sha256":"44B252D8B1A9602D3CDC789F244AA05E9C0633A8F4EDCADA2096CEB33844BA9F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Last Session.g1p3okhzl","md5":"5E42E247A27A3C58BB42D5D08614DF44","sha256":"1FD84D57AA4FD021A25A422F386DC1D899EE2B5CDF3622C561714487ED314314","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\History Provider Cache.g1p3okhzl","md5":"B57F298861BDBF48A2FBDC99697F2021","sha256":"B9ABC88DDC1A1F2C7AEE5C7EE7CF47FCCB6010649C9C9E74FA2777309D742638","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Last Tabs.g1p3okhzl","md5":"4D1B4B0A5CA6CDACD3CCD2EF8D904559","sha256":"F529C1CD2CD63F15E6C8CE6FED0AC25B75DB1D22A490F5983974BFF0185A7AED","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Network Persistent State","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Preferences","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\previews_opt_out.db","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\LOG.g1p3okhzl","md5":"587C182FECBF2CECE836F3333341B4C8","sha256":"9A4D72A28D423F6C8D653069997889AE3E854C543F72797A35982B1FBB92412F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\local extension settings\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\local storage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Login Data.g1p3okhzl","md5":"5DE41582DC2D1B6E8F78FC7E15239569","sha256":"E5E9022DF2EF412C406D108A9C9C761A4FF5601EE1B07604DAF4010952EEB220","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\MANIFEST-000010.g1p3okhzl","md5":"7FA933165D52373EE9A265C525693E4C","sha256":"4281D78B4CE9B7F2366BFD5F9156CC6D45B1E5A8E14E7693A52C6FAD68DE767F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\LOG.old.g1p3okhzl","md5":"A48DC08602EF8067DF89DD526FD472AF","sha256":"6D66C4D7478F238DDFA47D035654C20356C6587931347F9DEE5C6F3DE49B7DA9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Network Action Predictor.g1p3okhzl","md5":"7CB4D9AE793AE2E35A73D665DB122AEB","sha256":"EE4622BF8B343019F2338B8A7E5BF65DB292D60751B30F6B6A02DFA12EAB15FA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\QuotaManager","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Shortcuts","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Top Sites","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Translate Ranker Model","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\TransportSecurity","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Network Persistent State.g1p3okhzl","md5":"E2E4F318EA758BB62B38EBB16933A97A","sha256":"50C0F9BCA9AF83BD4FE76CDF259E28745F574C101A4AA2935526D9B493F543F0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\platform notifications\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\previews_opt_out.db.g1p3okhzl","md5":"EFFA9A5F786717D38F6780A5EFBE8EBA","sha256":"4733465C6B23074E0F1E52AE76B22F8642A034869E9A197C9A399A2420750BCD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Preferences.g1p3okhzl","md5":"9B31529B3A9A2D90D522712B9E7F5F88","sha256":"F1D946EAEE079D76FB2EF4EB01B756071591291C6070F013A420EDC078D644D8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\shared_proto_db\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Visited Links","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Secure Preferences.g1p3okhzl","md5":"42CD0C681592408437CDCD72CAC309FA","sha256":"601E596EE0B85AA57F83ACF3340160E933287544B05B80164AD230935D8EAFAC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Shortcuts.g1p3okhzl","md5":"383B51305F21F88BF754215629EE2D09","sha256":"266FDBE446E40F8792A4607A3AD62791A1DDE12629412756FBF9B7464F268DCB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\site characteristics database\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\QuotaManager.g1p3okhzl","md5":"41D8E7E000DA552C9A7308E8CD42596E","sha256":"CBA83D55E6EB2D563FD3324021EA19ABB11C850C89010B7215DF4FCA0BE7F241","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\session storage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\storage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync extension settings\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync data\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\CertCsdDownloadWhitelist.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Top Sites.g1p3okhzl","md5":"F31FBB0D7516F23329C64B85817784AC","sha256":"F18463C6698B17E45D595C039E5B2606AAA75057BE9FC4837939FFBA2E9A941E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Translate Ranker Model.g1p3okhzl","md5":"F12D80E5A689D1FFB1F779093FA97522","sha256":"2272145D82507689B3E4608AF55EAFD1131B21C89480869AC6060F19082C5D80","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Web Data.g1p3okhzl","md5":"7E545E56614D0283DE62DAE0C2E446FA","sha256":"94A42D0F6312197F36506B85CE2EDF77AA5A4A2A6E799B9755332F5280A00907","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\ChromeUrlClientIncident.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\ChromeExtMalware.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\UrlBilling.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\UrlCsdWhitelist.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\UrlMalware.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\TransportSecurity.g1p3okhzl","md5":"EBB70EA76709E7EA407D7580EB9C75BD","sha256":"14700C6AB1141785955903F7C9D1962A17DA25315EB3308EBBFAC9C7F828E366","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\Visited Links.g1p3okhzl","md5":"A6165F89A618B24F26CAF70C3E0C7B23","sha256":"10FD89BFD2B8DFADBF2E67BB9B4B72741562E4B17D35E296951C4CABA83C017D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\pepperflash\\32.0.0.433\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\filetypepolicies\\42\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\pnacl\\0.57.44.2492\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\interventionpolicydatabase\\2018.9.6.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\meipreload\\1.0.5.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\UrlMalBin.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\UrlSubresourceFilter.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\UrlSuspiciousSite.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Safe Browsing\\UrlUws.store","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\ChromeExtMalware.store.g1p3okhzl","md5":"4C9FF41DCF5A82B9BEFF161D4BF4D4FB","sha256":"5076C9180A36AF269AB3686347BC400879D328FFD20BFAB04D996C205BB27AD4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\UrlBilling.store.g1p3okhzl","md5":"F135C3A3BBE236101B7984BB315F3411","sha256":"42F66A774AFC543781D2EBF7A06E72965927FEE52387D96B0446626766651353","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\ChromeUrlClientIncident.store.g1p3okhzl","md5":"AD8D2BF7EB2EA4C769B7731303E60152","sha256":"E021A7D002EBD1550766881660D145BF095046C507114DA556EC2657778AE6A5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\CertCsdDownloadWhitelist.store.g1p3okhzl","md5":"0061D35798219587D67679D12DECBE4D","sha256":"71190F0CA0340E2210AB5C99B8B0BCB79A228599394CEE27245DB2996958A984","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\62e3dfa2-4350-445b-8693-d1d04a74543c.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\6a8b0e06-e9a5-4761-afda-29391149e64d.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\6d6e34b9-0e90-470c-ada3-2b00b4b8ffac.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\70c3a864-35fa-4245-802a-dbda1e3f4c00.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\UrlCsdDownloadWhitelist.store.g1p3okhzl","md5":"EDDB48A9399F9BE9D5FE5A4F8B147779","sha256":"0B0A9FDD6C16C3D9F70FB8CF1DB4455A16295B9F7F3096BD14D2531CFFD1E1A9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\UrlCsdWhitelist.store.g1p3okhzl","md5":"D85E1C71FB84FBD5ED2CEFF31051572F","sha256":"2D05A6F1122627E249C940729B48B523CEB36E5D12AE257C354367458E65E495","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\IpMalware.store.g1p3okhzl","md5":"622012B2B8BDEDB8679E57BADD227621","sha256":"9E08972E24F03A99A6FB12CEBCA0606D21988DBC4AB524052F57D8155DE14963","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\UrlMalBin.store.g1p3okhzl","md5":"A27387443818EB637910BAF6D8DF3773","sha256":"242B94E0FF1D5275A65C6685B0E3FFC915CE1041DD073AE2F630D7436E6D5E8C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\UrlSuspiciousSite.store.g1p3okhzl","md5":"FF5B78E55BFB987F3B8D69CB112B7BEA","sha256":"D89F3288715962FC2E03CA7E7729730B21C6E306FBE2410EE09F5BDA9BCB5534","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\UrlSubresourceFilter.store.g1p3okhzl","md5":"B772C527A569C4319F3CFFA32A6D6720","sha256":"AD9A80C593464915611BB65F9A97765B7DEBAA6B16D11AFCDEC698A77A343F70","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\5394c05d-dc33-4d24-bd45-2d8954648f28.png.g1p3okhzl","md5":"721AB2DEFD456598515114FAAA2226DC","sha256":"CD354A57FA3ED91A9F633BC7CC5C2E827D7BF53C0F5DB3C0F5BFE1F3F7CAB2DF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\70d1f452-966e-4e28-8da5-8b2eeadbe078.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\79a073b8-0713-4166-af23-3272c394a92a.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\7b168dd1-e39e-4b39-918c-53b9e78365e9.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\7dceec06-0991-43f4-8af3-601c0ebeb910.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\8339d228-5ca6-486f-8793-633aa6af18d8.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\a4f6c176-53e1-47b9-8fe4-8bb920684ff3.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\safe browsing\\UrlMalware.store.g1p3okhzl","md5":"0D09A1577572BD60BC8F2356083D5F89","sha256":"D9E7DBDE82A8AA653322F1CA88DECA4C6F5D7C5710DCA490D85C3650C5C6ED47","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\62e3dfa2-4350-445b-8693-d1d04a74543c.png.g1p3okhzl","md5":"B23BDF4327657EA92C1214AA39B7EF4A","sha256":"572C290CEC926F4F8C9DB290B8DF126BA631935DC4806B47D8F1ED0077E0E04C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\6a8b0e06-e9a5-4761-afda-29391149e64d.png.g1p3okhzl","md5":"537986FC61492322CE1486E7C2F4F645","sha256":"1E22E42724BD6E18D9E6840B8CC9C53718BF5574E3F331BF6015793FEE24D5DE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\6d6e34b9-0e90-470c-ada3-2b00b4b8ffac.png.g1p3okhzl","md5":"02AA822234F4845F177D93293B2820B5","sha256":"4C1E8F4556CA25AB0DF198A74E6764649AE75F95F171BC2A498EC7DCBCFA137F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\70c3a864-35fa-4245-802a-dbda1e3f4c00.png.g1p3okhzl","md5":"4FD187E919A68CFB169F3C0D362F0558","sha256":"895FE7D18169E96721148372AC5EAD2FA170E74CD2C74A6F41A6B3C0DC14CD73","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\a4fbc2bf-8cc2-4a6d-b3c7-0ef749399e7f.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\a507cd65-0038-49e4-8cdb-b6082f566351.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\a6f0f9a9-e50d-4612-9e8e-f5640793680c.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\a9e6bb3f-0b62-4410-86f7-68bb36989df7.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\b1503304-9b12-4d90-89e7-df30e304e6c2.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\70d1f452-966e-4e28-8da5-8b2eeadbe078.png.g1p3okhzl","md5":"45E7CF010D237761A5F6FAB0DADB406E","sha256":"D66B0F451344A4CB8DCEC26637D423D44350CE8F8DD6F304AF86E82D3ABD1680","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\79a073b8-0713-4166-af23-3272c394a92a.png.g1p3okhzl","md5":"9FBB83FBDE9BBD8DCE7C344D28ECC165","sha256":"C7451216B83BD3D9AD116EF834CDC596F8F5114EA250B419DFD0A032181E0776","type":{"value":"ini","type":0}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\8339d228-5ca6-486f-8793-633aa6af18d8.png.g1p3okhzl","md5":"59085DE5D0B6DBA44DDD718BFEA042C9","sha256":"C4AD6C4E265ED3373CEB2D48999311099A9CE0BF4A95BD350A6EA3D559FC6FD1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\7b168dd1-e39e-4b39-918c-53b9e78365e9.png.g1p3okhzl","md5":"8D6EE669F2E44DC03C7EEA744406FBF6","sha256":"9ACA15C300FA63A850B41AB7AE84BCE533DCA00154731FDA55A4F2082E74FF2E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\7dceec06-0991-43f4-8af3-601c0ebeb910.png.g1p3okhzl","md5":"A46F083A00DA788566B4A861777C2082","sha256":"C53144E8EB184D9F8A7B4577A07D03538C583E78A3ED75841CDFFB46653C4F42","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\b2a67a4a-c116-4c88-9fd1-c5b9a23d7929.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\bb4e150b-7e2a-4556-81dd-590d7ab07dda.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\bdde27ea-6a12-4825-bfac-f600b0f142fa.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\be1e893c-ed6d-4ac9-933e-dd5340e7c76f.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\bf4e96cf-9460-4049-8172-cfb4bec57f8e.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\c129b038-2a0f-4994-b354-64ed233a0973.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\a4f6c176-53e1-47b9-8fe4-8bb920684ff3.png.g1p3okhzl","md5":"23242FBF70C06B7EE41362D42CBCCD47","sha256":"781B1272172F2013E744A2B813DB6D56094549B48B46566B289FB87603D2B39A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\a4fbc2bf-8cc2-4a6d-b3c7-0ef749399e7f.png.g1p3okhzl","md5":"27F10EF8B67439530A8A09C057738199","sha256":"E87C4DB8A7C39C320B934C0EB2F68ABF9931B77C46AC5B046BDEE58E0C1D2D13","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\a507cd65-0038-49e4-8cdb-b6082f566351.png.g1p3okhzl","md5":"445ED93846AE59337004BD9C8ACE465C","sha256":"06651019206290B895C5F01B186661D659D3B2ECCA25B333EA3574A86CBBEFDC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\a6f0f9a9-e50d-4612-9e8e-f5640793680c.png.g1p3okhzl","md5":"56F446A9639288849B3F96A450A76E0F","sha256":"9846E6BD0EF9E6E8C6B5710DF8E884C5D8CB710495B371943E9A11854A380D13","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\a9e6bb3f-0b62-4410-86f7-68bb36989df7.png.g1p3okhzl","md5":"8FBFEE321B85D5E5CB30B9363AF2A170","sha256":"8EF141A3B6FE09DE9466501986077DA3B5B066E53F2E714F0A23F1584E8510D7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\b1503304-9b12-4d90-89e7-df30e304e6c2.png.g1p3okhzl","md5":"BCF36BE71002A129F68FB27E39F301D9","sha256":"0625065C5D0E1B1A42DC03DDE164FF4634292B0A541B0E9A265AECF0DDE9C874","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\d024a53a-b32a-417d-8f75-e1998be423af.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\d137f4ab-4b3d-439e-836f-ffbbc700bef1.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\d13b95bf-2bb1-4c3d-a85c-9ac5e1cb3884.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\d2a0e881-e736-4694-b4e5-62a677ac17bf.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\b2a67a4a-c116-4c88-9fd1-c5b9a23d7929.png.g1p3okhzl","md5":"96B737A068A4575E1D2E193D74988F98","sha256":"255C16854A94752892EB3EF3A8C165C6B862377604E950B7D36C46DC47ED16F9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\bb4e150b-7e2a-4556-81dd-590d7ab07dda.png.g1p3okhzl","md5":"113E5F573B8D5503DFBA409A7FF1EDF6","sha256":"72FD6A81718B063E533990CC3645E4CAB2CBEFEA575716E23A2EF63C19BA9BB5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\bdde27ea-6a12-4825-bfac-f600b0f142fa.png.g1p3okhzl","md5":"C63DED58972EA242E6ABC5D7CDC3B3E8","sha256":"AC1BECF84AE124C052B3F8A054175D3208040A1764D06A8F26E1D70B86F61A7E","type":{"value":"ini","type":0}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\bf4e96cf-9460-4049-8172-cfb4bec57f8e.png.g1p3okhzl","md5":"C497B2729344A8BA68774160F1FC313C","sha256":"048F687F864FD3B163D2574746E330398AD82565BDF53513965A1EFB0C4E4EBA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\be1e893c-ed6d-4ac9-933e-dd5340e7c76f.png.g1p3okhzl","md5":"E84EDC4F8F499909A750FE0CD535C0E5","sha256":"265850F2D541EC45B36F3C685F6A88392068EC341FB0D6808447290A2AD89A21","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\c129b038-2a0f-4994-b354-64ed233a0973.png.g1p3okhzl","md5":"FEC7D1B46DC9559C4F15F391A808443B","sha256":"8E1614FD7F8905B9DE3636D211D600405BFB15FA3C3B0C7613B39C6C7803E33A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\d2a0e881-e736-4694-b4e5-62a677ac17bf.png.g1p3okhzl","md5":"A88FD675D2CF3A02CC9D44279390853D","sha256":"8D4DB1983A28A839CB5F867CFE208C39A76FBEF9FB6B1D5576E75E2364C2B3B4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\d32a2c63-e181-4374-a527-d8ec3791e0cc.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\d6f82e07-6756-4003-877a-af43e54f9781.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\e29a7eaf-32ad-400c-9927-05c358358ffc.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\e5116f77-b907-4c46-8bfa-006092a6714d.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\e51cf594-e321-4d1c-88e7-df9cde80904c.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\e7a7c0d5-0e34-4323-9576-f37e394faa8a.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\ee4479ee-b960-4d54-abc8-c9e95e2bf81f.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\OneNote\\14.0\\OneNoteOfflineCache_Files\\f173a3a2-bd1a-460f-b78a-faf2a51f6d91.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\d024a53a-b32a-417d-8f75-e1998be423af.png.g1p3okhzl","md5":"77DF27294B4C498F71AB480028F6D079","sha256":"A8A82039A95005C6C1CEC0BC3F6B26D33E4C6EEFEC23F053532620448D280A1F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\d13b95bf-2bb1-4c3d-a85c-9ac5e1cb3884.png.g1p3okhzl","md5":"9A65C0F04F819D747F5D2DB27E25B295","sha256":"040EF381F8B15615F5948348A0301CFD5A77A0A0963F73420B57254307CDC09B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\d137f4ab-4b3d-439e-836f-ffbbc700bef1.png.g1p3okhzl","md5":"B58A2282881CBACFFEAB1EE82FA82472","sha256":"FC8F2E726D9E89B0B0EBFECCE9FF0F2B98862420753DE6372C5E0865196172BE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\e7a7c0d5-0e34-4323-9576-f37e394faa8a.png.g1p3okhzl","md5":"E474D6067992E54257F5B81883F82456","sha256":"3E352223D99BB02F2D9239F3212A6D1F96A0D1D894D9AEDACCE1630949C25828","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Backup\\new\\WindowsMail.pat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Backup\\new\\edb00001.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Microsoft\\Windows Mail\\Backup\\new\\WindowsMail.MSMessageStore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\d6f82e07-6756-4003-877a-af43e54f9781.png.g1p3okhzl","md5":"D10F34DC3484CBDD28DA6EACF1B850EF","sha256":"4A3FCE62FC84DF30A0F2029CF7D9B5916922E6FB751FF2CA8F9924C414363892","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\e29a7eaf-32ad-400c-9927-05c358358ffc.png.g1p3okhzl","md5":"E7FCB3E4302915164FD5641B4D21510E","sha256":"815C1E778F63A57002ED8D1995C895E67CFE5BA9EC2152FD0B01B150700A9EB8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\ee4479ee-b960-4d54-abc8-c9e95e2bf81f.png.g1p3okhzl","md5":"ACAF7B36511E910AEDCDCB259B418336","sha256":"DE310CCDC8DD400A74E635A3F8F19BE7D00657BA1DCFA59F539DC19488EEE0E8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\backgroundNoCloud.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\f173a3a2-bd1a-460f-b78a-faf2a51f6d91.png.g1p3okhzl","md5":"C7F6A9A1B3077B377FE82A0B1341C4D4","sha256":"F9F30983EAE33FAEAEAAFFEA3CE898D77AD3F1F369B32540C2282488E3BD7F06","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\e51cf594-e321-4d1c-88e7-df9cde80904c.png.g1p3okhzl","md5":"6E6BDAD5428474125460D521672BC7FD","sha256":"3B131DC885A58CFD1DF91B5AFF18D135DE0A86131C519D5284E995731C9439F6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\e5116f77-b907-4c46-8bfa-006092a6714d.png.g1p3okhzl","md5":"C1B84B0A7DB2ADBBBD9BFD76E63FC49B","sha256":"A0B7BF5BB714C0C41693B4D53B2373A1AD943758FE5D453A5F5E0D171D713FC1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\onenote\\14.0\\onenoteofflinecache_files\\d32a2c63-e181-4374-a527-d8ec3791e0cc.png.g1p3okhzl","md5":"0D1E36436FD1F02ACDD42F188E8C5AD7","sha256":"D6B71A594B7DF3E25DE70F0FCE8EBE8677700039DEBC02B88089AAD57E9BFB24","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\jumplistcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\buttons.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\capsLock.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\capsLockShort.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\checkbox.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\connection.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\backup\\new\\edb00001.log.g1p3okhzl","md5":"4DA8C20AFE0CF4A1BA4C570003160524","sha256":"BA409A35404E84DB16865569960A4F637AD3F31F55F8B77FA82E7C91F0842067","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\backup\\new\\WindowsMail.MSMessageStore.g1p3okhzl","md5":"E33D5C5A1348F235C1E3FD86A6973E52","sha256":"7CC8D4DB449926C3FC24865FF1B086F31AA73E76C58ED1D943AC54F37FEFAC64","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\microsoft\\windows mail\\backup\\new\\WindowsMail.pat.g1p3okhzl","md5":"35D6360E1D76BA1AA550107BEFE5530B","sha256":"8C51A514E7F40BB7E26EF4015DD238A0057BFB91A6B1F380028E678C059EF8B2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\thumbnails\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\startupcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\offlinecache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\dropdown.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\facebook.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\icons.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\backgroundNoCloud.png.g1p3okhzl","md5":"851EC4E562D8E1BB7DD310DACE5539D3","sha256":"8269BCE0441C55494B251382F7554FAF9EC403708B4321C55420E205C6457751","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\capsLock.png.g1p3okhzl","md5":"25ACA1B2CB7B906EA13B07709F1CB456","sha256":"7C448FCE81AC7DD29D9085249D6B0C0C929FF0761EB11FC53E382F901731D26F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\checkbox.png.g1p3okhzl","md5":"E6E9D503D2F677E5F70702F134A69062","sha256":"552D61A2512A4DB0D105BC86ACD8E73975C879460AD45B2C87900C1663669DA0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\black-on-white\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\capsLockShort.png.g1p3okhzl","md5":"FB737FC2170EC11F0DAA58B08F531727","sha256":"09C8B39953DD7CAB9F23AE0149FE7F91B5EB4E9816714728E8BA1C43FAE761D1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\buttons.png.g1p3okhzl","md5":"EA3E1076939F0A0504A28A92B33156B9","sha256":"CC2ACD43571F447151A6043C4050D3E74B6DF0F2C89C047D40D4261025EDE8F3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\connection.png.g1p3okhzl","md5":"F268C7327AD8AC91FA196036EE1395F4","sha256":"C2590D39BAD0823DA468E861359F58B3E4DF4D570977FA5B884C4EFFDBC2268F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\inputfields.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\loader.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\loader.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\logoanim.gif","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\messageTop.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\messageTopShort.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\msAccount.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\facebook.png.g1p3okhzl","md5":"6F6DF0333AB0E191587EA389857E0FB4","sha256":"4CFD8378262911BFD5A0A758A862A020B8B22F0CDBEE08BE15B675AFAF6561B3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\dropdown.png.g1p3okhzl","md5":"6B307C267A3DD79EEF3810F292BDBC5C","sha256":"F178DD6102C261878EDD44272C86353F3B97C784A3934149E86C9350E1E5D42E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\messageBottomShort.png.g1p3okhzl","md5":"AAF12145DE31EF48F206D25F52139570","sha256":"2F7F727A00ABB47BF357915A0FD5032929ADBCDC79DDA832F4AD21213046C612","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\msAccountColour.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\msAccountOverlay.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\msDefaultPicture.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\picture.jpg","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\plus.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\loader.gif.g1p3okhzl","md5":"44247D90DF10CA42A7695EBB202EEEFB","sha256":"A7F794B5D6F27E19E867972B238289B141C8B03AA515FB935BFBF7FB7BFA3274","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\inputfields.png.g1p3okhzl","md5":"17BEBA8C9F57846F909F0CF90CE0FF26","sha256":"D490D358577F043537831E0915DC248B7F4A221E05239AAAB6396432F2A0E022","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\icons.png.g1p3okhzl","md5":"6DAC832089269AF932C4B56CB07D3639","sha256":"B3AF0054D4076F068C1F823A196F716318B5B4F775CBE548B24A4847A9EEFD39","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\messageTop.png.g1p3okhzl","md5":"D305BC0E5C9125174396A5846FE51EA8","sha256":"A6FE1932002BBEFB1310CEFC53B9C9C5A8180084542D0666DFB50EB6750C95DB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\messageBottom.png.g1p3okhzl","md5":"79D17C4A488739DA1AB65D2961F1E6D0","sha256":"3D0B349F358C1B209A63684F3B828812121DB6C8DA56F0C36E095EBE941E6BF1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\messageTopShort.png.g1p3okhzl","md5":"71886AF0A8FEC0F04B40DBB1ABA0C1FE","sha256":"4A76C322366F27070B29EDF09854C3DD0CE4AA4D2D5159E6822BAE1E69BED47B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\logoanim.gif.g1p3okhzl","md5":"0EF2D5816C6D28DB82A629B135DCE431","sha256":"890639ACBD483D597BD3676A884519951F2A1363170BE27CA9998E93B54D4C80","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\msAccount.png.g1p3okhzl","md5":"70983FD38056E114D682A364093B3801","sha256":"FE6EB7652F2ABB92EF306474CA7B960386F4FC156505521B71D086B85967E0CF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\loader.png.g1p3okhzl","md5":"4FCE52D7B338425E29591A13B47D4E9E","sha256":"99F1A39F26118F6ECB815F6272726E57C4D2189E5B110251E85F7EA9C4AAAD77","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\skype.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\skypeicon.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\picture.jpg.g1p3okhzl","md5":"55660B4FA06868BA0F883BB13D6F3ED9","sha256":"61460FE52BB9C7DE1E70942FD2282F5813BEFAF2C488E77292B25CD004F5CCCB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\msAccountColour.png.g1p3okhzl","md5":"6E74A8B922540320390D86B24025F9AA","sha256":"225487CDEBE4609B462154058503BB6AD6F7A3CA7B91655B4B72A590718ABA61","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\msAccountOverlay.png.g1p3okhzl","md5":"6D20005A3C1E6570D7B9DD5D671EA73B","sha256":"65976C316BBAA96C52BC819F2E11ADEFEFFC54C7054340E9CF4732B7EF979BD4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\normal\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\skypelogo.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\js\\login.js","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\languages\\ar.js","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\languages\\ca.js","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\languages\\da.js","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\msDefaultPicture.png.g1p3okhzl","md5":"AD3B2298C7AEF8DFD14F7D100CC40210","sha256":"2749F38B88ABC57E23827C1E61CC55CCDFDA1528B191BAE04532189F3F905DF6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\skype.png.g1p3okhzl","md5":"88AAE877ACE6B69FB2815B7DCDF535F1","sha256":"D1A26B69923E2EA9EEF096865842EAC83AB037F6DEA9621AB176EA264C79ADD3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\plus.png.g1p3okhzl","md5":"4E4E1A9B85103158FE24CC1B9111167F","sha256":"682A86615EBB69A4D78E9F19A0EDA59E8D8C4C33FBFE3E3C06EABB3ECE042E6E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\skypeicon.png.g1p3okhzl","md5":"296A5C37F724247B58FC3A4546750641","sha256":"F8A7D9AEB5ADF6123FC34A8BC7C2386DCA2A6A9246C5C46B7C674102A6A21709","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\retina\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\languages\\es.js","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\js\\login.js.g1p3okhzl","md5":"B29C70631F82FABD2A230E60B6A6A569","sha256":"007C42E0BB8C3EC295479CE3D92B4830C9AA3741B725F60C4D1B2DF69D391C7C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\ar.js.g1p3okhzl","md5":"5BA4BC3ECF1D2DFC090900BB44E2F30F","sha256":"D781CE755E0D028BD982976493F84E1B4C01B1D04979791C73E0236C18221D58","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\skypelogo.png.g1p3okhzl","md5":"DDAF7B62B5EA54DCE1A13BF3D911D7CE","sha256":"EA7BDAD93799AC783E3536D28CC718AEF37DE5EF47141877B95926B55E0A3AFF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\ca.js.g1p3okhzl","md5":"9EDE10661AFD30ABB304FF8B3C3B54AA","sha256":"58C4A5C58BA89E781EA98DD75F68953C8AC926A939A7AEB394431FE5C1362827","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\de.js.g1p3okhzl","md5":"F4F500FEA18C0F217BBB78BA83581A51","sha256":"EEC622F20F04945FE8AF79A4A1D4066559C3915749D14AC08018DF9FE6B7DAFC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\cs.js.g1p3okhzl","md5":"BEC6D230A910FBD715938981EEC756C2","sha256":"479C0B723C6A0B7F37F7A76D4DA17C5B5A4B3709773C472765934FDE19E2A37F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\bg.js.g1p3okhzl","md5":"EA757F2D9ADEC2BC735BD016D06F38B8","sha256":"D4C08D142AB824E82854962AF477C9632988CF04EE70F5946228E1B9A2ECBFA7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\el.js.g1p3okhzl","md5":"1C5C960DD12FC98471526A6C8A4BAFDF","sha256":"4C900FAC0DB3C0691E2846A4783E4B8633286C9A2A53492A9D2FA3432D618E0F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\da.js.g1p3okhzl","md5":"9A546D72989C52F5A1468494F1D1CB45","sha256":"F6B8F0939787975F4CF4A0ABC058C1A5E67007A14C114FD184BB013F929E142D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\en.js.g1p3okhzl","md5":"A8F323D96F5334F7CBCB5197E13E363B","sha256":"27095EE9FBFC6B31428C95482312A2C08A6AB23523A34340389F7E9FBCF435DC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\et.js.g1p3okhzl","md5":"1C8DDBC43B7501D534FED91259622727","sha256":"D74C0E47F22853ECAD1113B7EC152524E3696DBD7DA6F8C968CE8EC4EC460472","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\userdictionaries\\adobe custom dictionary\\ro_ro\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\userdictionaries\\adobe custom dictionary\\sv_se\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\userdictionaries\\adobe custom dictionary\\sk_sk\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\userdictionaries\\adobe custom dictionary\\ru_ru\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\JSCache\\GlobData","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\JSCache\\GlobSettings","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\addressbook.acrodata","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\13735edd58ba69fd9ff943a6a7e4cd07_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\userdictionaries\\adobe custom dictionary\\sl_si\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\userdictionaries\\adobe custom dictionary\\tr_tr\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\languages\\es.js.g1p3okhzl","md5":"54BAAEA3BBF7A66DD6646F9436A5B39C","sha256":"42EBEB8988166E01A9E7B41EE72AF37A0EEE9AE6850DB2F01CCEDE543BBA464B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\adobe\\linguistics\\userdictionaries\\adobe custom dictionary\\uk_ua\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\adobe\\acrobat\\dc\\security\\addressbook.acrodata.g1p3okhzl","md5":"8FC6317767145ABAE2802CB52294D38A","sha256":"967586BE7FD2D059F6C4341639F6FBB733C0A03B59024397297B0A403078FDD7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\2b335de75c9b9df0a85be783395d0ccc_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\5c246f64b0f738abbb4b1956aeb51c13_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\dc333a59796da8660c545fe25a64e721_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\adobe\\acrobat\\dc\\security\\crlcache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"FA7E5A9EBB3510DC382927FFAC9E60E2","sha256":"77E4599DD17A24F5F9AFAE54F2C1AEE9D3E43824E63C8E8E42AE409A8080469E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\adobe\\acrobat\\dc\\jscache\\GlobData.g1p3okhzl","md5":"E5ADA2314EC24DCC741CC5B5989472C1","sha256":"BBBE73F44B0A6D509C2C02C3004670C5CCD7094D79E047FEE36369E6EE820360","type":{"value":"mp3","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\adobe\\acrobat\\dc\\jscache\\GlobSettings.g1p3okhzl","md5":"2E4506A9FAE474DA3842FEA3B7C30466","sha256":"D370777E838122D139A4C33B6953E0CA3A403975825B39EAE6FBAD01EB4F6C77","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"33A9DD8D37112AD7DEC38506A9A0E5CE","sha256":"B3F84DF4C6BB5A353CB83CFA97E7087AB4B2FF67A2FE3D0BA80A8F9DABEA6163","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\13735edd58ba69fd9ff943a6a7e4cd07_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"29D5E209E4B416E6ECEEE39E0D37CD16","sha256":"858B72E59ADB9CA9ACD76C0FC661316D8D95493F0F7E817FA050B936668EA85A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1302019708-1500728564-335382590-1000\\f20f4af73fc57199cd4ab061806640e8_90059c37-1320-41a4-b58d-2b75a9850d2f","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\IndexedDB\\file__0.indexeddb.leveldb\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\IndexedDB\\file__0.indexeddb.leveldb\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\2b335de75c9b9df0a85be783395d0ccc_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"29254CAC38CA62577E15A682137BD529","sha256":"AF0AEA8EB4896DE04B8697E7CC3505EC31BE529234B2535FB8A33F2E77884245","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\642978ae92ee034c4f6b9a2313397d5f_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"0AE3F5A1ADB78E281CF41D518E628369","sha256":"68BD2D0A5226CA0D2FCDB2DBD592F9DC5A7A3A24F836B9468B491B842941F5BB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\5c246f64b0f738abbb4b1956aeb51c13_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"B3BCAF9B0B5414FB63004CFF177F7D50","sha256":"A0B8154468218148709634281BA357138C8861CC4E2B38B178A601DDC2591A8C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"2427EC84B23B68D17DBE57739310BC30","sha256":"881D38EDCA6BF462BD132A3A4FD4AF4BEAC1AA6FDE8A06B463451937C3AEEBDF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"AA6AA504A445F76AE8FE9E9EF07285F9","sha256":"C7A95A2A720E5769B9B5EE5E1B670B497E70D025388EA7A4C8CEC5CEDAB980D1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"E097F7FE20EA2F64DA7FC4A8BFE839A7","sha256":"B72E621C73275D3F54E781956506181ADA8D41995522C42B65A0BA3D08ACB5A1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"8EFB8D832E6F4C01A8376DDD2B5E8B37","sha256":"0EBF3475923C60B131C23D8CCC5364B7DF16BD831BD36877D5BD7249241741B3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\dc333a59796da8660c545fe25a64e721_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"EB5F5B7C673A07B21D9E1DECDB8428C7","sha256":"9976035303C2EA8A3D1D11C2ADCBED00C7D50B0AD0453887F8BC64B0D80256A8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\indexeddb\\file__0.indexeddb.leveldb\\CURRENT.g1p3okhzl","md5":"52BACF30CD9EB6D9B9B3ED355EC95FE9","sha256":"51287C49F0A38D278E262FE58B0C2959B16F27A564356A266EB95082C786429D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\IndexedDB\\file__0.indexeddb.leveldb\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Local Storage\\leveldb\\000005.ldb","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Local Storage\\leveldb\\000017.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Local Storage\\leveldb\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\14\\Built-In Building Blocks.dotx","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\IndexedDB\\file__0.indexeddb.leveldb\\000003.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Local Storage\\leveldb\\LOG.old","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\network\\connections\\pbk\\_hiddenpbk\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\internet explorer\\quick launch\\user pinned\\taskbar\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\microsoft\\internet explorer\\quick launch\\user pinned\\implicitappshortcuts\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\crypto\\rsa\\s-1-5-21-1302019708-1500728564-335382590-1000\\f20f4af73fc57199cd4ab061806640e8_90059c37-1320-41a4-b58d-2b75a9850d2f.g1p3okhzl","md5":"A22BA4C74A04AB0D3EEAF273CF3D0F21","sha256":"AB42330961CA9974868282B6D32FA0B12290C5CE7F74F778449A76E353569112","type":{"value":"rnqs","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\indexeddb\\file__0.indexeddb.leveldb\\MANIFEST-000001.g1p3okhzl","md5":"9FDC44EC5A1AA0026FA3BDA8CA85D542","sha256":"32D59237C75D832456C882C3F0DD1B5119264934A2FD3D779BCE76ACC087CF00","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\Local Storage\\leveldb\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\skylib\\DataRv\\offline-storage.data","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\skylib\\DataRv\\offline-storage.data-shm","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\skylib\\live#3agabriel.radrigos\\config.xml","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\skylib\\DataRv\\offline-storage.data-wal","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\leveldb\\000017.log.g1p3okhzl","md5":"F4927CF9A2D738562174C1C71BD409C9","sha256":"98F1267D296E292AEB7E3527CFAC77E8C391D0A27B2494C5982C075711FE012F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\leveldb\\000005.ldb.g1p3okhzl","md5":"5C0F5CD02F2C048A2F8402AE2AC64F8E","sha256":"B7E06BFA38018187F8E77CB516D1C7F4C59858AD5EF8FA0433FC18128E3274AA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\indexeddb\\file__0.indexeddb.leveldb\\LOG.old.g1p3okhzl","md5":"1988BF5C5F01F9B1C97B308BADCD6B51","sha256":"7EB56B5151B6D3C67DC8B45C27662962A45AF539845C74CE0704CC514009A28E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\indexeddb\\file__0.indexeddb.leveldb\\LOG.g1p3okhzl","md5":"CF3D9B92A35BC7FDADF4D07E105CEF82","sha256":"CA221832D97D311EEE8B2705DE35BD3B06C34DA8CC6D1EFD944DCCB40F366D10","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\leveldb\\000018.ldb.g1p3okhzl","md5":"392B8F7C958DA764EE04C2CF9E738930","sha256":"D92F777EE85C9D34FF184666C43E21D9DE53797693E01CF302B4C449D8DA3AB7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\leveldb\\CURRENT.g1p3okhzl","md5":"23BEB8D68ADFA92B9E4430E39254B81B","sha256":"640FFBF9B259848411A902404078A63F23A1D3FB75C60774AE7513679C0BFDDC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\document building blocks\\1033\\14\\Built-In Building Blocks.dotx.g1p3okhzl","md5":"3313C4C8A12BCFC790B41D8D23754411","sha256":"B0B11A27072000282C950D9887A4D656A485EA239AA44E94996F6CE5985E7814","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Microsoft\\Skype for Desktop\\skylib\\live#3agabriel.radrigos\\main.db","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\leveldb\\LOG.g1p3okhzl","md5":"AD83E81944B44D2F6D51333A683ED78C","sha256":"1EA3439352AE188ACCB2665BBD8C48BA6F7D8994F0DCE668A517086FE484B003","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\leveldb\\LOG.old.g1p3okhzl","md5":"96468956A81B6CCB1B7358293B3C4C35","sha256":"6DE3128B8E1F4CCD9170A4D5A4C4AE8824EDD1FEA7FBA155CFE50FF18566E086","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\live#3agabriel.radrigos\\config.xml.g1p3okhzl","md5":"A28B449EC6E96C1A77186302D7AE6E52","sha256":"E272343D73E97DCEF9407CDA9D7FA0AA415F452C81F14A2DA148ADEE87E55CCB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\local storage\\leveldb\\MANIFEST-000001.g1p3okhzl","md5":"F1DCD0C2B11C0789C7355CE60AA9ACAA","sha256":"5FAF4227938D6C1370E6866ADD05376F4C2306FE83CD05A5BBC83D849F302667","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\indexeddb\\file__0.indexeddb.leveldb\\000003.log.g1p3okhzl","md5":"4512CF70EAB504D18A42CCFF482FA3BA","sha256":"C1BB82D2B1CB968962FD8DBA31D5DBC5E2A4EBD349F5DF83A1A087910E914FA4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\datarv\\offline-storage.data.g1p3okhzl","md5":"5B0AABA27AE63F50690E631F99A6A719","sha256":"A5CED7C47C9B04F6C45E1EE5CBB6AB8410498898BD0E1BAABC004C6DC7C0A23B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\datarv\\offline-storage.data-shm.g1p3okhzl","md5":"5128DB2BF96AC1368F4B1FAAC469D00A","sha256":"C254A262B51CBBDF4C87B39351BF8486D5DB2B3338F39310C788C5727DAFE27C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\datarv\\offline-storage.data-wal.g1p3okhzl","md5":"132E927E3A398E2D6FC3E47DAF6358E0","sha256":"34983539928DBED934DC41AF4F5C21FC67FD4F4F0D094CCEF6DFF6E4F9095980","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\Telemetry.FailedProfileLocks.txt","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\times.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\webappsstore.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\xulstore.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\accessibility.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\altdebugger.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\classid.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\contrastbw.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage.sqlite.g1p3okhzl","md5":"82A362F5F2C09D7BB8FF85B040AC21D4","sha256":"BB8C671AEA9FBC261262CFECBB27E86E3FE8A18CBDE7CC8742E30D83B67BE20E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\microsoft\\skype for desktop\\skylib\\live#3agabriel.radrigos\\main.db.g1p3okhzl","md5":"CEB11F7392DA6F2F3313D23EF87AB5F2","sha256":"D6854A219B2F941DFA03B7DB4809B3A54C81C22B35BC2D3FDA4883F4608C10C4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\altdebugger.css.g1p3okhzl","md5":"D828929A1A7571076DC4FEC0FB12DF20","sha256":"1337E8D292927217FFB4BE96F646058D66B9CB2B14BE82A60DFB5DD9210E33F2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\contrastwb.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\disablebreaks.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\disablefloats.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\disableforms.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\disablepositioning.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\disabletables.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\xulstore.json.g1p3okhzl","md5":"6F5F2764B7C0B9606E3C26DC4595F637","sha256":"378111B18000EDD3B26720B2AA521A3BFD313D07C884025442537A6923C51AD4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\weave\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\Telemetry.FailedProfileLocks.txt.g1p3okhzl","md5":"1DA1451598A4D0727AE3F4601303F907","sha256":"0AED914B590334D65AE4FF0AF2D798536CAD764AF5678219E0B4782C9C14D293","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\webappsstore.sqlite.g1p3okhzl","md5":"7AFD3C51EE1E4EFFDDB93AAEB0D6683B","sha256":"FCBA6C3098AC12774A833858724ABF39B556890558CC9394EA8E74B5BCC181CF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\times.json.g1p3okhzl","md5":"3CEEF6D35172E3DAEE1D54913E80151C","sha256":"49CFED642A2012D3E15A0E44AA81780D2ED909EE71AB13B956F9F5B85E1D35A4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\classid.css.g1p3okhzl","md5":"60E5E88EFB3ED6FCC8AD1671DF48B3D8","sha256":"016EE32BCADC14C118949889B95D76F836AFAE944E7050DA741F73B74BB192D1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\contrastbw.css.g1p3okhzl","md5":"F8265DDA52F2ACB464D187821B25D09C","sha256":"D0779C956D7DDED7F3A0A46BFE15AAA8606B60BCF1B1DEDC10BA1EF495401D19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\accessibility.css.g1p3okhzl","md5":"E46DFDF7C77F95B57802D2BF6EEF6B29","sha256":"80769B916BC3E899B31096AA80773D1E098A1594E80929799C7B41FA8E813A8B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\disablebreaks.css.g1p3okhzl","md5":"4E5B29E4A6BF2B51FC6B823A279DE5BD","sha256":"219494852D98BEF7220C1F3851049225CDC7A82FAC58F13F93733391531E1E8C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\outline.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\structureblock.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\structureinline.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\structuretables.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\tablelayout.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Opera\\Opera\\styles\\user\\toc.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Feeds\\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\\WebSlices~\\Web Slice Gallery~.feed-ms","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\contrastwb.css.g1p3okhzl","md5":"C0FDB1B4E2A8786142E561D66749348C","sha256":"9F05D52005D5091A94279451D5260052BF45411DA10BF0CC941A10A7682A83EF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\disablefloats.css.g1p3okhzl","md5":"9E45861E6AFDEA4096469B54B6374A77","sha256":"B3E52A44003910EB5748C397CB2B267BB702165058AD3DB86F7DDD869B508FED","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\disablepositioning.css.g1p3okhzl","md5":"3AFD2842F56F16D7E800D2DA4E618184","sha256":"561848792D9762FEE882B220BF0304B71F6BB8CACFF5EE4C5023A6F4284A5E01","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\disableforms.css.g1p3okhzl","md5":"05DE0E625BCB69DCA9BE8CEEED32B759","sha256":"0C1840182AF9B007897A7542A3EC32E0C8CCA3C00ACDC7AAEA63C560D93C7E65","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\disabletables.css.g1p3okhzl","md5":"1BD2E90095116F4C003B398B398A6837","sha256":"7791E8C4F89CEFCC0AACACF13182FD3A0D6181BFDF3A8F3D41D6CFB45C38FF8D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Backup\\new\\WindowsMail.pat","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Adobe\\AcroCef\\DC\\Acrobat\\Cache\\data_0","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Adobe\\AcroCef\\DC\\Acrobat\\Cache\\data_2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows Mail\\Backup\\new\\edb00001.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\structuretables.css.g1p3okhzl","md5":"31B35A5B1AABBFFCD52E5EFF848FE0F7","sha256":"C1F6FA7636CBE5FE9B7F01445AC08752D7F0357CDDCC8B7FF0ECDC8B4EE4C2BE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\outline.css.g1p3okhzl","md5":"A5D52CE19281A98B31BBF5BB298C6359","sha256":"A9404A83A45460A6D29768FB400DC26AAE6EE485DC7F3F0EC338EF66966B5AF3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\structureinline.css.g1p3okhzl","md5":"EAA415B09AC3A07588298BFBA59D8AC0","sha256":"8FF261ED22DE77E67C4C8536E958A63037166814F00E804C42818F4270EFEC9F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\feeds\\{5588acfd-6436-411b-a5ce-666ae6a92d3d}~\\webslices~\\Web Slice Gallery~.feed-ms.g1p3okhzl","md5":"9DA9172C4B116E4163CB7CCE868A8D61","sha256":"C36A3E68701D41B108854E0EF3044244195827C8E5F39D31C33D8F72CF873716","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\structureblock.css.g1p3okhzl","md5":"DB13BA0FE845647DAC597A6FA7FD65AE","sha256":"837B14D774A74FD3E52DD00CD8CCC27939C854FB3109296C19EF6988B3481613","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\local\\microsoft\\media player\\sync playlists\\en-us\\00015d2e\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\tablelayout.css.g1p3okhzl","md5":"B163BC883415D3E63487F4A52AD393EC","sha256":"4DC82AFCF8849E8407F359750C20AC6CD5F487F9E1EEE9CE5017B47504153DAA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\opera\\opera\\styles\\user\\toc.css.g1p3okhzl","md5":"63F5C6E3E2853893AADC65C4B120E57B","sha256":"3D25112DFBE4D796EAB17920A90EA7B178A7D7758A7AB61DDF2A6EC36F1D2F60","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\databases\\Databases.db","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\data_reduction_proxy_leveldb\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\data_reduction_proxy_leveldb\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\data_reduction_proxy_leveldb\\LOG.old","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\microsoft\\internet explorer\\quick launch\\user pinned\\implicitappshortcuts\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\administrator\\appdata\\roaming\\microsoft\\internet explorer\\quick launch\\user pinned\\taskbar\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\adobe\\acrocef\\dc\\acrobat\\cache\\data_0.g1p3okhzl","md5":"C1BAA8E92C8824BD23662F57249D5FD9","sha256":"91E024EC31BE9EB8568845E668643BFA5BF6CEDB2442EA89084A723817108E1E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\administrator\\appdata\\local\\microsoft\\windows mail\\backup\\new\\WindowsMail.pat.g1p3okhzl","md5":"4ADC62E5988F776A045E73EE24EDF94D","sha256":"8FEDDD6533F7BF23AE189F1B88F40E70442C799F658D10D849A58F99454FAEAC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension Rules\\000003.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension Rules\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension Rules\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension Rules\\LOG.old","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\code cache\\js\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\databases\\Databases.db.g1p3okhzl","md5":"AD063CACC22DB5CDAB1ACBF3705F35EE","sha256":"9409C1D6C15E5AB58AF3119D5C64188DEABAA7E9F895CEDD5F8A6727B40E80A3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\data_reduction_proxy_leveldb\\LOG.g1p3okhzl","md5":"4932DADDF8A4E80F8A087DC59882B160","sha256":"4B1BE1EB2FABA112050BCE4AC6731F1D52A63FE73946931FB378739FFE41FB9B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\download service\\entrydb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\data_reduction_proxy_leveldb\\CURRENT.g1p3okhzl","md5":"334D4B9DB6E6ED32D9EBAA5A3AFE3C47","sha256":"E2A2D619BFAD19B19108ADD4262C7D16B9A6C46DEE3B33F8982662906E71F00F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\data_reduction_proxy_leveldb\\MANIFEST-000046.g1p3okhzl","md5":"4228904A7ED0598D98C82B0AC26D1626","sha256":"60F857677B8A2DE0F128BDB50449D0CFEB42F001603B3D3FAFD651EF53B844A8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\data_reduction_proxy_leveldb\\LOG.old.g1p3okhzl","md5":"38E5E92A842292060FC8255CB0EB23E5","sha256":"C20666D496A1E6AA6D6B898269D3D2231891CA2D7FC63B0AAF6F69D908A6FC70","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension Rules\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension State\\000003.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension State\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension State\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension State\\LOG.old","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extension State\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\download service\\files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension rules\\LOG.g1p3okhzl","md5":"0B4FF677D54772689C93B5BA83D032DF","sha256":"C203946F2952780363B5FC5457327722E0DC22148592EEEEF6F2A727DE96683F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension rules\\000003.log.g1p3okhzl","md5":"E6209C2B53D5752E91CB7D37B8C57FE6","sha256":"619575B1494EAFD6D9620D84F72E0EAF1C4AC607627929AD0BF0FD5018EC21EE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension rules\\CURRENT.g1p3okhzl","md5":"0DAA32548055A0CCED5B884C67533FCE","sha256":"09400CA97CC6E67E24E170C6390AABCB8A32997B95E674CF37ADC662FCD2EEB2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension rules\\LOG.old.g1p3okhzl","md5":"B4EE1DDB98EF1E600C9C7140CF01C3D0","sha256":"BC12F21C61B249B7EED15F793F5763F475A2B4D66053BACC78B4A101BF7F2E1F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension rules\\MANIFEST-000001.g1p3okhzl","md5":"DBA2B11653B826506AEC80538643331E","sha256":"19F92073948D50BC13FDE8E65AD2DF91C6A61B4689B209381979DC9F07FD4CC3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\GPUCache\\data_0","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\GPUCache\\data_1","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\GPUCache\\data_2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\GPUCache\\data_3","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\GPUCache\\index","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension state\\LOG.g1p3okhzl","md5":"656206BB67F6AB9A0D51A5A5CCF869B0","sha256":"B20AA583901ACA28484E3049440EAC4E2DCEAC1615ABD7F9636457FE4FEAB5BD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Platform Notifications\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension state\\CURRENT.g1p3okhzl","md5":"64D5EC03A9AB231883941CDC72D8F671","sha256":"05ADCDE4FED2E55DA1C355AD99C09D014B581232004B2CD187993591215D9FD4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension state\\000003.log.g1p3okhzl","md5":"3A98BC4D54A4E879DB77246ED3E23280","sha256":"AC184726A139FA92952DF7C3844F9508174D94A1539DED48AA161EB90AD585BE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension state\\LOG.old.g1p3okhzl","md5":"F2E1AFD24077BC389249CAE5E4504E70","sha256":"30F13246584E4E8376C12E2DA0D031E7AD884986EAAEEA4E7747EF70799B9B92","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Platform Notifications\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Platform Notifications\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Session Storage\\000003.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extension state\\MANIFEST-000001.g1p3okhzl","md5":"CD580BC403302FA403269C4A823A119E","sha256":"A6957A2FE1A2008CF1B85440AF415AE42FA5274B1A1680D1E8927FF8B9A10614","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\gpucache\\data_1.g1p3okhzl","md5":"83410F223C1481455F0A6EB0EA805BF4","sha256":"F900E04698160222D253DDEEDD75D9F6A3AA176FF7BE92E3B4B158F3C2488802","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\feature engagement tracker\\availabilitydb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\feature engagement tracker\\eventdb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\gpucache\\data_3.g1p3okhzl","md5":"A323947940A8D190549ADF3503BA6A01","sha256":"478F250BEDF97777178F0719E640E414A6EB8B21B941DE0118C1A5E13BD3D548","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\local storage\\leveldb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\gpucache\\data_0.g1p3okhzl","md5":"E74F2FA70280BC499E60C9754D182B22","sha256":"77E6448392DC73058DA02C5D1FFB4A9857D74AA11AEF8C5C25E033CAE1A9CE49","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\gpucache\\index.g1p3okhzl","md5":"62710341E27AE9B80B91A1374FBC49F5","sha256":"1428A90BA628D21FBAF5B37372C19F6DCAEDE11BE176790F6D19C3C6169DEFBA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\gpucache\\data_2.g1p3okhzl","md5":"0A84F2EF36769C34AA62364239CE874E","sha256":"568B6D2344E5605028147904DC1DD296F81EA862B546C0A1AED23A98B68782E1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\base-track-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\block-flash-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\platform notifications\\CURRENT.g1p3okhzl","md5":"3BB0E0990117461E7E284511C6DECED2","sha256":"1724EE2EEA41FAC7E25CCC18A828CA6D2E2D0ED9A054F987FE46D65D6BC54F8D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\base-track-digest256.pset.g1p3okhzl","md5":"F41E89DBCF9D520F6B8F8908B599F372","sha256":"7D84EEFEEA81D9575C2FB1B398510C417FFB37B2B37355032B594975BDA879EE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\platform notifications\\MANIFEST-000001.g1p3okhzl","md5":"71EFEEC97D0C545BBBEA1F87D695E33E","sha256":"E32414BD92CBE132742F05838B5BB067399F9D4CC60C1C48F60B23457043ED2A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\platform notifications\\LOG.g1p3okhzl","md5":"BF447BD68B7B612F91B195B0783815DC","sha256":"D3F9CA5B0AC557D7ADBEF1255FD226F696A95C93574BA2B6C9DE22D6B219983C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\platform notifications\\LOG.old.g1p3okhzl","md5":"CD1B9B7103B1C292B521FC37ADE833FE","sha256":"B4E67285FDFF43753CFEE67DE9AC3BCC6CAA99293A5C8B4652D530B04F15DD2D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\offlinecache\\index.sqlite.g1p3okhzl","md5":"5E09F51BF4A17E3EFAA7DB151653CC0E","sha256":"263F6C53A1642A3D73A0C4744599FF06DCFDCAB3FE8241441B7216CF8853C581","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\session storage\\000003.log.g1p3okhzl","md5":"A42680DB4C95A63914025E26164809B7","sha256":"4139DA5405816A5A38F6C7159CDDAB08038F13234F959CA59A1ECCB24984BDB4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\block-flash-digest256.pset.g1p3okhzl","md5":"0115F6CCA88EE1FED44447D5EE589E00","sha256":"695B8C555FDCE927BC81F3081B0E16A5B5F19F77A9D30E7A388D8A88D8A9A1C9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\base-track-digest256.sbstore.g1p3okhzl","md5":"74A29D18F5A3B66E696F5FD4A035C0C2","sha256":"1A3095BAF30E5EDBC29A63D6D1FA822EC287D8072A2C1C47A7831FD8803C611A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\block-flashsubdoc-digest256.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\block-flashsubdoc-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\except-flash-digest256.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\except-flashallow-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\mozplugin-block-digest256.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\mozplugin-block-digest256.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\mozstd-trackwhite-digest256.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\except-flashallow-digest256.pset.g1p3okhzl","md5":"309B247555EA2FC794D8A2D76F31C9FB","sha256":"386A6E90DB700E8B540E38D0F9F62EAC32DD537F1FDBAA5A588A4CDBA565D93B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\except-flash-digest256.sbstore.g1p3okhzl","md5":"8A965097FA70A6263DDBCB58CC0594E9","sha256":"46B750EB659BC8F9B8B4B63C180D6D06E42BB7B985E66E7C1AC7DC62E495533C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\except-flash-digest256.pset.g1p3okhzl","md5":"C98C6C113EBCD699951C872DF2D3C1B0","sha256":"CE0439507580FEE7C52C156AF4438694A5A8B99FD55D81C567423337E6B7D0E4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\block-flash-digest256.sbstore.g1p3okhzl","md5":"F4A2104C355EBE0275B11618A057877B","sha256":"5B17BB0A4E8A121BFF85D6AA4F3070D3CC4CE5260E1976D9D3D021EAA7562849","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-block-simple.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-block-simple.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-harmful-simple.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-harmful-simple.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\except-flashsubdoc-digest256.pset.g1p3okhzl","md5":"8F5DAFE748A154AB7052A6E0F7DE8B9A","sha256":"67C58B6ABCF5D85D600A23982643CCC2D94AE5A1112003C27608065321812A3E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\block-flashsubdoc-digest256.pset.g1p3okhzl","md5":"6E2064403E5CE681446EF299FCB41FB7","sha256":"36C6AC862669E2D8C169A616071540AD93004DDADA7E5B6F33AF91E202DE7E74","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\mozplugin-block-digest256.pset.g1p3okhzl","md5":"C0C3FC8AD8294C02F31152818B2F4A58","sha256":"4C731B9939C199D4BFED7BF0B88442C552A7DA05A8A06F70774737E66E806DCB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\block-flashsubdoc-digest256.sbstore.g1p3okhzl","md5":"EEFCE825643E78E73E9CA28436BFA279","sha256":"2C664113B4CA9C50690768A2E5EE6FF5D899076CE2AC9D78B382A8AE74031FCF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\except-flashallow-digest256.sbstore.g1p3okhzl","md5":"EBFD2BE3CD4C9AD038CD37A35F69007C","sha256":"B3CB3D7F26FE63FBEB7796F74D1EDAC484BC04EE639623FFDAFD814D480D6DC2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\google4\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\mozplugin-block-digest256.sbstore.g1p3okhzl","md5":"F503563BA5B387B0987EE0150B8169B9","sha256":"53367D3B0B6E8867B970941F162763A4312F8A9968230897B4C6714EAE6410C3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\except-flashsubdoc-digest256.sbstore.g1p3okhzl","md5":"C397EF8895402AF61105FA671F0B97AA","sha256":"14E372847F9A84699594EB68419D58E5A48260CC6277FA5970E6E2BA6E989251","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\mozstd-trackwhite-digest256.pset.g1p3okhzl","md5":"1F1F549D858D7353E1517C7F7F248B48","sha256":"409F6B4FAA0B951C1B5273F309472237F91B85BB8E8EC94321262C942B277ECE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-harmful-simple.pset.g1p3okhzl","md5":"A544B5F04033717877ED1BA5141C0143","sha256":"4E58F4596B0F9FE23E6208220F38385BA2F2B0FC128E3CA5C947C048B4278913","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-malware-simple.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-phish-simple.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-phish-simple.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-track-simple.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-track-simple.sbstore","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\safebrowsing\\test-trackwhite-simple.pset","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-block-simple.pset.g1p3okhzl","md5":"75724AE5B02E27B9CEF8279C20985D69","sha256":"57301EF284220F37E0F4A89213ED415B0A8CE8C0655230B0DB22E4D227AAE092","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-harmful-simple.sbstore.g1p3okhzl","md5":"880F1955D48EDD88F48BC82D34CF74D4","sha256":"9EC2B1102D44F3688B5D692B33C79565F68BEAB105A3CBE9272C59FA615FA2AA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\mozstd-trackwhite-digest256.sbstore.g1p3okhzl","md5":"746E16DEE601F38D26FE31FBF0E3B6FC","sha256":"720E92D000A4FEA4BC50E32ECC90B525B0E9FA352E4FA5EB1836413F759DB49F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-block-simple.sbstore.g1p3okhzl","md5":"2F6EA14EF4CDB62B6E63143936045209","sha256":"AD58EB7DDDAF9864E3509717AB47662DA3EAC7468A091212B698B2C9DD4385E0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\startupCache\\webext.sc.lz4","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\thumbnails\\ad5a4453bea49203135688a7b8db842d.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\thumbnails\\b3e037a842ba4ab0b367be22be9a1c95.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\css\\platform\\mac.css","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-malware-simple.pset.g1p3okhzl","md5":"292EE47D9707C186E3E71CAA9063E068","sha256":"83FF8676FF7D2ADCD0FF98D24B807999D94D8BBBEF7E1F8EA6F60C080370DBCB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-malware-simple.sbstore.g1p3okhzl","md5":"F56BF7A8EE92FE8A5C135B03D8427D93","sha256":"420D1A2924495C1C57DD7F481E6A4C5FE21F2A92FF20BEF342878962A6C8A417","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-track-simple.pset.g1p3okhzl","md5":"B5A9FBC90E02725ADC1057E3A33A37C0","sha256":"DC160334181E4BC4B6576D1F2E7B1F5AFE20813BD2DB17D41D88A93233A88F80","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-phish-simple.pset.g1p3okhzl","md5":"3F1FD44569D86A8E60BDECA1F370BF37","sha256":"3BE73353BCC4B9C3B4C6DAE8958F0C87B64169F1F785ACEA0B4B0E0AE2909611","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-trackwhite-simple.pset.g1p3okhzl","md5":"8F4958B1AB95E7EB25E9554F40EB6012","sha256":"C5119CB041D8F2AB8A451405A5E4B8D894BB3EB7F6073A3886310648116679E9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-track-simple.sbstore.g1p3okhzl","md5":"18297048247CF831678F59D3031A62B5","sha256":"78C198616F012E66961A59286EF0A48D78F196CA54292EB302195981B1440DBE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-phish-simple.sbstore.g1p3okhzl","md5":"2BBB7232577F5FBFB4C10CB795E28829","sha256":"007F9AF6BC09CB3B524ECDE6826667AEFAFA4EDA248E67B81D35991E54CD6DC7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-trackwhite-simple.sbstore.g1p3okhzl","md5":"5760499DAE9CD8556FA7663877782A7B","sha256":"2ED21543E187641986F54A33E2C771318F704626B7153963088E3B65A2D09BE6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-unwanted-simple.pset.g1p3okhzl","md5":"3AD6F1E9E7EBB6D3EB4B1C4B19F30B6F","sha256":"451211ED1891264270026325117EFFAF7473A81239A50897F2716BB3A845B74E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\safebrowsing\\test-unwanted-simple.sbstore.g1p3okhzl","md5":"8ADC89CD4D44E2D2697C7B5CA6223ED6","sha256":"2DB26032FF92E541D515A47178553F2C44D6473174685A9E032E002F52CF7163","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\startupcache\\webext.sc.lz4.g1p3okhzl","md5":"1DE3D3E08C9FDEDFAFF61157F9F0E63D","sha256":"8E9E4E73322EDD78AAC2A666D9F76DFB6D89398650A13C0AAD26357B81DE1CBF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\white-on-black\\logo-office-25x25.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\white-on-black\\logo-office-25x25@2x.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\white-on-black\\logo-win-25x25.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\white-on-black\\logo-win-25x25@2x.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\white-on-black\\logo-xbox-25x25@2x.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\white-on-black\\msa-logos-135x25@2x.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\thumbnails\\ad5a4453bea49203135688a7b8db842d.png.g1p3okhzl","md5":"C35C69F252A0F62D96BA91F41F58565B","sha256":"EE749F75DC1FBB43DF85C7B9963F20970FC8B49227F10799B826950F3D6739B3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-office-25x25.png.g1p3okhzl","md5":"6B5E7761A9FBE83159C56EC7762B5BA7","sha256":"ECF7E1B0E0784639E3A4E6139254C5D9C7C0B741B113F01856F2FE67A1D6821F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\white-on-black\\skype-logo-136x60.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Skype\\Apps\\login\\images\\white-on-black\\ticked_10x10.png","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\thumbnails\\b3e037a842ba4ab0b367be22be9a1c95.png.g1p3okhzl","md5":"CADA06CEB1C7B964FF46B30317CAFFE7","sha256":"B43CF2A5158B3C67F17E265783AAEBB925E9E5A1A26F4F24F02B457BD798E9D4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-office-25x25@2x.png.g1p3okhzl","md5":"FC2C8F8B02AB3C1E5A891DC4090514CD","sha256":"9267F49B912C633306451A7F0DCA8675BE12186C13A7D4F4EE6B59A44AA70CEF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-win-25x25.png.g1p3okhzl","md5":"3D05A8AF5D088712C4E1F511AED5ED3F","sha256":"2EE48D696DC08B54A4D0BE205669840148226FBC60425CA3B37BF9F33FCDE9C3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-cloud-35x25@2x.png.g1p3okhzl","md5":"754235D8277C68D6A8424D68DBBA95FB","sha256":"C7282251815D2C90AA8429616F0C5BF726B5796AF59EFD13221F4A4321A04F5F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-skype-25x25@2x.png.g1p3okhzl","md5":"DB0CD8D07C4119AB04F4C263D8A3A8EE","sha256":"B88419DBB6E4577CAF9B10263934F10BF5B58617B1E4B8C056B16E398D5F54FC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-xbox-25x25.png.g1p3okhzl","md5":"49E703454B4149F6359F3FA2D9403108","sha256":"168ACEF6C80CD90695D4C12B22143C4A9951AD8D1C8A2FB50138610E693CFE41","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\msa-logos-135x25.png.g1p3okhzl","md5":"E67E0A3521C60DA8EE8ABBD8352EF03A","sha256":"736BDE43974AB6769A6B7789C8CB7DDDC647327B4ED77FE3835A07F8D5BFB90B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-xbox-25x25@2x.png.g1p3okhzl","md5":"3DF9190E2FF734BF192AA8AB71F12284","sha256":"14522546A3CAE2AA2C99CA437DA24C4C3AF298D329DE55C037129251F52142A0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-skype-25x25.png.g1p3okhzl","md5":"3B9382105EDE0C3FA6EB5BD53373E5F6","sha256":"3AEE7BD5A6F6BE6B449F2229CB382940D4F6219EF2D48E102A3BC7A6D2FB08B2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-cloud-35x25.png.g1p3okhzl","md5":"1CF36960B937880CD7CA101C4DCD45CB","sha256":"BCD0DCCD7806C34E642D20C853373E92DCE4D31E453D904E3B9B32C5BAA4C3D3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\logo-win-25x25@2x.png.g1p3okhzl","md5":"BEF1C037FA5E1FEBAFE5106A911DC864","sha256":"FCA482AB3C21816A4B57F5DC99E1D3484FA2FAB4B3A6648AF51571FE7702345F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\skype-logo-136x60.png.g1p3okhzl","md5":"A963CF84E5D4D72590A7F0490AE4BB40","sha256":"5249964DA81ACD5BC7BE07641650AF074AC958E8D05477C1368E55FF340E16D8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\skype-logo-136x60@2x.png.g1p3okhzl","md5":"64DF2108D22BB25B1DD5ECA82F82C8E9","sha256":"840959BB93432118BC5B88F0E4C4D3F0A490FC2A34DAAF1D3D968C2B66AA4188","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\msa-logos-135x25@2x.png.g1p3okhzl","md5":"EA635880E31FA0A7FB34FED3CF22F564","sha256":"F69264D5BD457F1D40C3B004AEB2F82015F1FDC639146A03710648B00F6B525F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\ticked_10x10@2x.png.g1p3okhzl","md5":"CA50B771DDFA2D12C5EEAFD5DAB06AC3","sha256":"B4AFD294E2B85F95CE9DB0DAB079535FFC6F2CF5464441C03692CCD6B0A16D11","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\ticked_10x10.png.g1p3okhzl","md5":"218207C1D4260814793D85041A7F7E7A","sha256":"51A22F9038E241557178173908D951B402A0BC9E85537F0F671BFC5AC622EDF1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\ticked_not_10x10.png.g1p3okhzl","md5":"79B7BB6F4DB93317909A049655F190D7","sha256":"6BD830B156B264D504DCE8B8336CCBA1C5BBEC31925341E364C615D424E550D1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\skype\\apps\\login\\images\\white-on-black\\ticked_not_10x10@2x.png.g1p3okhzl","md5":"DD3F3C2E3EDA5930BE236A2E723774D8","sha256":"6CB8E3A49B397952A215EF3DE7FCDBCB81E3454C465F14509B4282B8B90FFF36","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\1\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\10\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\13\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\12\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\17\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\19\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\11\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\25\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\2\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\15\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\23\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\21\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\14\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\22\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\20\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\24\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\18\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\26\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\27\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\16\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\28\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\3\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\32\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\31\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\30\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\29\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\34\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\33\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\35\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\36\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\38\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\37\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\4\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\42\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\40\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\44\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\41\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\46\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\45\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\43\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\39\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\48\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\leveldb\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\shared_proto_db\\metadata\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\shared_proto_db\\metadata\\000003.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\shared_proto_db\\metadata\\LOG.old","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\47\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\shared_proto_db\\metadata\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\5\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\50\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\51\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\49\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\52\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\56\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\53\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\55\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\local storage\\leveldb\\LOG.old.g1p3okhzl","md5":"5635E4F56FF2B5440607813187A822AD","sha256":"28F6AD7C10ACC68FAE785A9AC21F589DE561A09FBBACE1F854DA19411CE5EB5C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\locallow\\sun\\java\\deployment\\cache\\6.0\\54\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\local storage\\leveldb\\MANIFEST-000001.g1p3okhzl","md5":"5A17336B32F0804C2AEF13A8777B519B","sha256":"BB9B6E758D3DCC6F227F5E1F9D32A25EA85C9F138FE13DA83867B3667039E3E1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\shared_proto_db\\metadata\\LOG.g1p3okhzl","md5":"52B0D5682D42733761583C9FB794F9E5","sha256":"D961212A624DB1425F582C57E2E0655D765CD53874F41FD331883A269BE9FDA3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\shared_proto_db\\metadata\\CURRENT.g1p3okhzl","md5":"E24274496EFB5DD117655C18A06CBA94","sha256":"87DD40FA0199C62F3FCFC55A58D6CC99DF5E676B3E115B60C0AF35ECC086AE70","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\shared_proto_db\\metadata\\000003.log.g1p3okhzl","md5":"970C4881DE5E194E5DDEBBEBEDB148B8","sha256":"BD8E8BDD375BC9E39224E20E9E50442ECDE765C880CD980FFB83FAD36201D859","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Data\\LevelDB\\000003.log","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Data\\LevelDB\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Data\\LevelDB\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Data\\LevelDB\\LOG.old","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Data\\LevelDB\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Extension Settings\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\CURRENT","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Extension Settings\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\LOG","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Extension Settings\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\LOG.old","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\shared_proto_db\\metadata\\LOG.old.g1p3okhzl","md5":"3302534087F837ADE3FA720236B531CC","sha256":"6EAE67A8542A22AAF6376D3B7FDB2CBAACAFEA9D253B8541EC07330E0181586E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\storage\\ext\\gfdkimpbcpahaombhbimeihdjnejgicl\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\storage\\ext\\nmmhkkegccagdldgiimedpiccmgmieda\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\shared_proto_db\\metadata\\MANIFEST-000001.g1p3okhzl","md5":"60F9EB66B99AB5F71FC23075B23A18BE","sha256":"1FA686095706E6A9746A04293E8975CBECB1F1A273CEDE9D43AD885251088BB2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync data\\leveldb\\CURRENT.g1p3okhzl","md5":"16E8BAF3B0EF5D2E069C9FFF40AF922C","sha256":"1314DDE858B17F8D3AFC2F072B84907FD31E8316F629898EBDCB0181718B6A73","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync data\\leveldb\\MANIFEST-000001.g1p3okhzl","md5":"8713C63E8F7A1C06ED1687A1003070D3","sha256":"E3F0E0A694BB7F4395D57FFF05808DB37DB28BC7A8FCA915E540C2E5930DC6A6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Sync Extension Settings\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\MANIFEST-000001","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\FileTypePolicies\\42\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\InterventionPolicyDatabase\\2018.9.6.0\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\MEIPreload\\1.0.5.0\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\PepperFlash\\32.0.0.433\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\pnacl\\0.57.44.2492\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync data\\leveldb\\000003.log.g1p3okhzl","md5":"5A19CE9B61C784CAF51DD52F8B4C33DD","sha256":"C7411D5C76EDD1D22FC4F9B20CABF8F57B61F056D3D5FD4503050A7C9AB232E6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync data\\leveldb\\LOG.g1p3okhzl","md5":"0448B21DA29F452411B854FCF4885C85","sha256":"5CB4261A8C7618F1431F1CAC943A40C88521B0AFB91F1A6F33CACB58CCB36098","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync data\\leveldb\\LOG.old.g1p3okhzl","md5":"90D62A7C7B2E115C6FB699B48B4DCBAB","sha256":"DD45A81C36EB7A0FFEF3D78AC0C31423A27126AA49A29E4253C4D976A499287A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync extension settings\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\LOG.g1p3okhzl","md5":"044DE9FFFEC651272E98BB8795B35E20","sha256":"DCAA3F6D1CC2B480D1AD1082A0967C347D90D7C5D5DD4A175A1F95186F60D409","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync extension settings\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\CURRENT.g1p3okhzl","md5":"898DA9288B8ED3426019576D56BE41D2","sha256":"40E464BD28D5393058B93EDF552CB37BAF1ACEB0A6947D170D96C8F6716FB146","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\SSLErrorAssistant\\7\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Subresource Filter\\Unindexed Rules\\9.16.0\\LICENSE.txt","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Subresource Filter\\Unindexed Rules\\9.16.0\\Filtering Rules","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\interventionpolicydatabase\\2018.9.6.0\\_metadata\\verified_contents.json.g1p3okhzl","md5":"FB8595E5820DBC5EE3C2675887D64C55","sha256":"76094FB8C61BC723ADB1FE94D3ED5C493D4AF38CFBA2C018D2AD3C575442CDB3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync extension settings\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\MANIFEST-000001.g1p3okhzl","md5":"E61E625BDA434AD30A31A1558D3012C1","sha256":"0CC8697710D8DDFC73A575A36F00EA5229193FF2C914F88DDB07FBAA6C3565D7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\meipreload\\1.0.5.0\\_metadata\\verified_contents.json.g1p3okhzl","md5":"84421791DB20E88288A4F6B489206300","sha256":"229605B7BCEAEA93DB16A33236D39DC542291CDAA5893B5D68F6385BCDA7BEB6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\sync extension settings\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\LOG.old.g1p3okhzl","md5":"68B8D3F1F26D17A7B25E2577ABB7FDA5","sha256":"1A577BBAC3C038096C73C075159CBAD3635F24CA9BDC32155CA407B3D1A4FBC9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\pepperflash\\32.0.0.433\\_metadata\\verified_contents.json.g1p3okhzl","md5":"CCCC6CEB7EB680AD4469F960EBA51CF3","sha256":"001AAA5C27647D68A04130947D91C92A681932BE4BB2AC94D98AB89B4711E851","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\filetypepolicies\\42\\_metadata\\verified_contents.json.g1p3okhzl","md5":"5F68DDE9C040C97F2E4E376EA8DF7043","sha256":"ACACEAB12A68EC09D0410B9EEA9A38959CF392271D3D66E8881A63655E1DA179","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\pnacl\\0.57.44.2492\\_metadata\\verified_contents.json.g1p3okhzl","md5":"50EC2E2AE85EB76E5DBEBC252408D400","sha256":"9C784518D2D282D1A448F3DA7E73B8058233B212F72BB2F753A8922EC6E27BCF","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\sslerrorassistant\\7\\_metadata\\verified_contents.json.g1p3okhzl","md5":"679ABBBCB42C4189969C4AD05514D728","sha256":"54DB77FEF866DEA190A3B9C39F7C4C8AEDD89357FB7893FE684F43E6E7EA34A0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\SwReporter\\85.244.200\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\ThirdPartyModuleList32\\2018.7.19.1\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\01D0DD38562297B051A041C28E8F1FC0E7D49A4F","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\04468E2B50576025D5846F5CFFBF089C4339342E","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\05582FF5C196A4485F189490FEC9ECEA0890DA32","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\0707F53CEA8FD3DD7A8E53BE76F04B9969C6E59E","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\subresource filter\\unindexed rules\\9.16.0\\manifest.json.g1p3okhzl","md5":"77B62A56FE9FB2D86B2F628AD99DEE05","sha256":"A227752D3FA4DC128E71C5DF091434EE3A81557ED2587869D4094E8A46DF16BD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\subresource filter\\indexed rules\\26\\9.16.0\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\subresource filter\\unindexed rules\\9.16.0\\_metadata\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\subresource filter\\unindexed rules\\9.16.0\\manifest.fingerprint.g1p3okhzl","md5":"D1B241994B30D0E9247B38167EBCDB2F","sha256":"EEBC2D334ACBE0DE977DEE3EBBDB0C5C610F8744216675F6A9A16F0CFF107A38","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\pnacl\\0.57.44.2492\\_platform_specific\\x86_32\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\subresource filter\\unindexed rules\\9.16.0\\LICENSE.txt.g1p3okhzl","md5":"3465820A5656B3E71DB061C93CA2A96A","sha256":"2DD5F6AF742099244F785FF346D64CDF6CD77B33B3DC87066E4244F90F74855B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\subresource filter\\unindexed rules\\9.16.0\\Filtering Rules.g1p3okhzl","md5":"8830147B1024BE388D6A72DD3FCCDF80","sha256":"E149D283C375F4A91F676BF226DDD53AA99D811357C4ACCF7DC7867E7F4B725A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\thirdpartymodulelist32\\2018.7.19.1\\_metadata\\verified_contents.json.g1p3okhzl","md5":"C8185EA817BA8D6AD95523AE84BFC3CF","sha256":"99E05565C70927E901738F9E7F4E3C28C1CDCCA39C003A2DD00E20F5475F78C1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\11C0B9B50A10A244AEA4875CD060AB17E6E31EA5","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\1679441B8AA7B4D31717C773CC4E86A25B37532B","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\179977EC1B5CF43A769203F2E63E4D2CCB00C0BE","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\18A6495046607BAD4D56D96B473312BFC83AD033","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\29B83D7F137D89C7266BD4CF7C5E5CA6C1A2DCC6","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\2A6D89B4A0D42C207BA6D0E429CF7F25887F96BB","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\swreporter\\85.244.200\\_metadata\\verified_contents.json.g1p3okhzl","md5":"CD47D173269E93FA445AFC24FAE5944C","sha256":"6A77E605722132EEBCD49E65C082757C4F417118255E70BAE0B4B3752E4C8AC3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\05582FF5C196A4485F189490FEC9ECEA0890DA32.g1p3okhzl","md5":"502721D0A158535B519881D41E644DEA","sha256":"8645046766BC3BA55CC89AF6BB3E34264C9FD8A5B297D9D13B43E3B5837F20E9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\04468E2B50576025D5846F5CFFBF089C4339342E.g1p3okhzl","md5":"33B326A9A875D36BD4E70F8763EBC46A","sha256":"B1D11EC6472734C1BFE44CD87C1CBB2152C808C36191841E00C2AFE40E7FADC5","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\30DA536D4A5D56FF0D85DAA6CA4D6E70F41C5F38","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\318765B470BEFFCFC68E05DD03734E91B33619AB","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\330267770E2FB0A0DA82D59920528C50932F8B78","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\340A10D652987DF5E54312E31F5C22F6E8DBA574","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\35320FE922CA1BD4D312985EEE300F41FEC78B74","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\01D0DD38562297B051A041C28E8F1FC0E7D49A4F.g1p3okhzl","md5":"635839A2858977D42DF68CBE315DFF86","sha256":"CF9B43F8AD362B1E48EA87D5C0188EC4B2CB5634BF2EDD75B352EBFE10F90FFE","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\18A6495046607BAD4D56D96B473312BFC83AD033.g1p3okhzl","md5":"8C48AC10175C74DB4CDBE2CE593902BD","sha256":"4C3E058B8258C88C692491D590D4703C26A2E62E49E76AF46CBC38A73F70B328","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\179977EC1B5CF43A769203F2E63E4D2CCB00C0BE.g1p3okhzl","md5":"C5D13E22ED5181342F8432D5D341C6A1","sha256":"D3323832C845E3E88257E17AE07D2969B5478E4A1B827FF1664AF5CC04908185","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F.g1p3okhzl","md5":"49D9B88AAF05ACD935938E3363A95D1C","sha256":"5D15E5CB8D3630A3B4F639BF9BC3A5721F553A103A056E921B01A65C41A79533","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\11C0B9B50A10A244AEA4875CD060AB17E6E31EA5.g1p3okhzl","md5":"D0305B246A2F1A9FC723D73BE9D4836C","sha256":"8D150EC94276AAA1809A085A3C40844D9FF683B70C2DAAA7C3549786D9C35C4D","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\1679441B8AA7B4D31717C773CC4E86A25B37532B.g1p3okhzl","md5":"618EF205BF43A987F06449492787C72E","sha256":"E71D0393466376798894506C2138024D9A26EE594A7CE916522CA325AB25EE62","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\29B83D7F137D89C7266BD4CF7C5E5CA6C1A2DCC6.g1p3okhzl","md5":"40AB4D4E9D69E0CECFAEE81868B092D8","sha256":"BC25ECC40628DF1E107D10D056AD1983BD6C8451824296C3220083661DADDF72","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\25218EE79CFF5F3AC18C58CFDF44A674E3560C47.g1p3okhzl","md5":"375799EE2B0E2E61E31DE744DE1120E1","sha256":"1A6B0B8051BBBE8B97E85190DD97459DC366B21FCA9CC1B0EC73858C7AF7F058","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\0707F53CEA8FD3DD7A8E53BE76F04B9969C6E59E.g1p3okhzl","md5":"D21DC6DF876A3D8B84E89BF54404FE89","sha256":"0BC9C1146E09723EF3D859A079AABD9119894B1F80FD2B29E35DE35837811B27","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\2A6D89B4A0D42C207BA6D0E429CF7F25887F96BB.g1p3okhzl","md5":"355E244AE8566EE08AB80FD0C83FEE9C","sha256":"2A2C5F3DC3AD74938C571FD062C5265AACDD2415DAF0353987366BB2769486F8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\330267770E2FB0A0DA82D59920528C50932F8B78.g1p3okhzl","md5":"C50AAFBC86A865287AF19DF37AEB9AB3","sha256":"FF89396B4258F9E2CA92A901F27EA26796A92D5B90445596B1920ABA8C5CB1F3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\7D724FC10BB12EAFD653DFBB690A9CDC27994E38","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\89DBE1DF558BB8439E2062ECC3272086F2E3FF1F","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\8D43FABE9C01AAB07BA11DD1AFDF808AE5AB7D11","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\340A10D652987DF5E54312E31F5C22F6E8DBA574.g1p3okhzl","md5":"550AF4A4283588DCB83359AD46C81AEC","sha256":"92FCA83FA630F3BBC0AA7E83C73D14C58C0139EFE55B65839CD7309A476898D7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\318765B470BEFFCFC68E05DD03734E91B33619AB.g1p3okhzl","md5":"C8A031E144488A31CAA184A780813AD5","sha256":"22C360A4F7899DD83FC5D9D11A868BE54C8F08972114583485BFC2FC814253B0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\30DA536D4A5D56FF0D85DAA6CA4D6E70F41C5F38.g1p3okhzl","md5":"85F204E882DDD5DE0E2FAD7FDC0972B4","sha256":"BFF8CA69FBD30C4E1AE68E762DA4912B7B1DC04924D131299F99DC6A27D89983","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\8F24C42CD7AB5FF6F8ED6779A8D07F0B48B693C6","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\914B97CEDA823C5D18A7681F63F0B3FFECC553BE","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\7D724FC10BB12EAFD653DFBB690A9CDC27994E38.g1p3okhzl","md5":"58129673A294E52E5058CE90E5D3E84A","sha256":"256DE543252C41C40C05AC7FC8F9A598CEE4459DA9DD1103CC9299B166B9D684","type":{"value":"mp3","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\35320FE922CA1BD4D312985EEE300F41FEC78B74.g1p3okhzl","md5":"6353CFDDCA0C821B6683021B322425A1","sha256":"CD7F4DF8077D42BF0D2A40EBEC8F879A3E0192CB06E0232097D68D95F60BD4B6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\7B53CF6685B5770D835BFC980814E9894AA672E8.g1p3okhzl","md5":"286D32D15C8028B0963105B09F3D3E5F","sha256":"84006642145BD384D1B330C3AE74C792FD1CFD55FD4C8EB855D352C812B77AC6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\8B058B5B2ECA97C617FDA8EF19D732C44830D6BA.g1p3okhzl","md5":"0AC518D0E2F4948249DD65D9459B3495","sha256":"45A0270D78A522D5E557AEDD0A047098944F8DBE0165E3B8D9974219963412AD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\7B230AB1AF8D8511EACCCB69C1917AB2C031B2FC.g1p3okhzl","md5":"BEEA6B64AF8A14FFDA815F572C0264B3","sha256":"A627FCEBEA74F7859BBF43DF6FD6A4364B72F07CDD5CA7512D1FB192C1CFE556","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\80A82883576719D7B89EEEC2CF3967189B31068C.g1p3okhzl","md5":"09E13CF57AAFF53CF5F6513A43F762D7","sha256":"BA10E7A74D77AE315EC0B93CAF50A78527BB59DB7F7C244659A1B8237C31C1C4","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\841DBFDC24299171F232F8226013717097D07FD8.g1p3okhzl","md5":"76CB481DF1E31073BE6B1C81EC19D771","sha256":"D8695B0D42F780BC0BEE73B436D3371A7FC862D086803359820E270E3437DB5A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\8C70D422CB3B014FE7709427CA578131D5D41AE2.g1p3okhzl","md5":"9B1DED089B826DE6AA5CF2CF72E38D91","sha256":"89D00C517CC3F04454FD770E4CD6230CE49429B7887F3E1CFF90D2E642640F37","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\7BEE6BF0D5EF8A0D33640CCCCEB56092DEA4F870.g1p3okhzl","md5":"5007C51A84F60F79BFD7B711DB074252","sha256":"90C2582CD2B6CB01A3EB89FA17F166924874CC7081E9FB7D41F195C8A841A86B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\89DBE1DF558BB8439E2062ECC3272086F2E3FF1F.g1p3okhzl","md5":"6BA8459F71B4ACE9F06A5516FA573908","sha256":"B990689B287295AEF43E0909302C2C1FBF7219EB5F465DBBA9115643E140577E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\8A9329B82BDE2D42F55037384629389689BC5F61.g1p3okhzl","md5":"A9086545B514A6197DC2E172BD72A0BD","sha256":"1C0EFE4A88D559DD7AC109F72384BEA3E89D50417118F535C8489359B76A5EB6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\8F24C42CD7AB5FF6F8ED6779A8D07F0B48B693C6.g1p3okhzl","md5":"883F1ECEE87128A2AF8466526909EC1A","sha256":"076C00F52CD463FA16BCD9042C35B514DDE2559479C26D73A40A2085965F7934","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\89E9FD087732EC6286721D4A15DB4339E45F84AD.g1p3okhzl","md5":"665A3830A69AA3568B7A45A6CE2DF80E","sha256":"D810E28FF54530691FF7E46E04882CBE45DC183F282EB08101B0ED5EB90560E9","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\944A8DF3EF1A971B73D890E7E77E7A4108571771","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\96E3CDF8FA4A0DCBB81F0A922B22FED61FC7D2FB","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\986D5DF00D4494D860F66C3C6FFD2A9029DDA103","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\9A3EF8133F0FA6C3DE8D839A13E7E624CC01FBCC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\9DABC358BEAD366F136A67373B7B1380AE3A3864","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\A201867DBF2B181BC094585C1A3E8C5E0E6ABC0A","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\8419846677B29BEEB4DF8BC9E3303A94C5506E22.g1p3okhzl","md5":"5B4487B8C0AA5F2D12FAD954402441A4","sha256":"34EAF144AF477C693804C6141E72F4CDDC197E2667036EEF957AEACAE9177301","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\914B97CEDA823C5D18A7681F63F0B3FFECC553BE.g1p3okhzl","md5":"367F6E80CD3A3D3611C9E593B071B108","sha256":"F7B1450E98230ABE737551647F77AA3163EF7ADCF5600F1A98D6FFF728A883A6","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\8D43FABE9C01AAB07BA11DD1AFDF808AE5AB7D11.g1p3okhzl","md5":"0D23BD6691DA841C57214E9D49DEB45E","sha256":"F9C91467F6D38B503FCE382A57D726692C963E91708CE7A7C79A054431F754FD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\94C10C680753D2685493431DC8B683CD6D03B629.g1p3okhzl","md5":"1DF753752AF0199620BBB37BD2AD9A27","sha256":"234A17529FB2543052B8F5DEE4D9606A2C778931460781AABE7061840B2472A7","type":{"value":"flc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\A4318AB5C2A2B8721BBC3C55E5DB82BE3E7EE010","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\A5D93CC48B83C8124FEB6A2E9448677EACA5BA86","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\A0FEF4A1B1C037F6324C6DB3ED76BA306BC3E260.g1p3okhzl","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\93229E1018C8A6C7F82F0A6D9617059A75260010.g1p3okhzl","md5":"4298CD3334E101FD6E38259793621F72","sha256":"D4DE679D5F2D68D03A7B7B1AB299B1DBDA8330976B78A5C5FF8F62AD49A3A5C7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\9A3EF8133F0FA6C3DE8D839A13E7E624CC01FBCC.g1p3okhzl","md5":"6FF8A47413EDA7A8B2844969D6EA7890","sha256":"07C2716E29027D3DD43B1A65EB1F8D2F04277C562C2BD2DBC5F7F7548935FE14","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\986D5DF00D4494D860F66C3C6FFD2A9029DDA103.g1p3okhzl","md5":"0B4386286BE724705955270479E1855F","sha256":"A53EB71DD4667936835CB49F0ED0C96FC46DD060BA85D9ED5311073C78B83EE8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\96E3CDF8FA4A0DCBB81F0A922B22FED61FC7D2FB.g1p3okhzl","md5":"D2C1C0F45C60144D224F23788F3F3670","sha256":"7E21DD460D42C24BE826BFE7BB0C3D58CE78FDAD149D39E99F2A17F50AB8FAFA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\9890DA1DDA4D423848BC1B4F7B815E79B5819D31.g1p3okhzl","md5":"04FD515B59355EB343F4193B28818448","sha256":"E66AC07516402AA19FD6D07860510C715A26B136BCEAC503CE7A7A241B6AB78C","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\9DABC358BEAD366F136A67373B7B1380AE3A3864.g1p3okhzl","md5":"DC24B359E65A3DC96406638FAC699956","sha256":"B864ED25AA725A8B728C122B2D9CC023B4797EEB33A823D1223BF27A218D6169","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\944A8DF3EF1A971B73D890E7E77E7A4108571771.g1p3okhzl","md5":"7AA57BCDDB3039804FC819EA9AE6F52D","sha256":"4B9E641580EF9F46DE7ABF8A51ED5A898846204CF1DAF07E6FDC833629B99D12","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\988A0810D2E1FA4A349E14D9720B26085378034D.g1p3okhzl","md5":"3C0FEAD49A4286D230CE72FAD58F9FD7","sha256":"C9FF75028C2AD3E098D9DD3B3833DD7F5956EC9FEC95FB1ACC6E7B82E15EFC05","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\B5A28D3E93A7C7935CFCFC3DB5D34C1DD3B41F7E","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\B6F3FB36D9FE3D14A4D9AF63479F9544B256F130","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\A201867DBF2B181BC094585C1A3E8C5E0E6ABC0A.g1p3okhzl","md5":"CA7085AA7DF524B081F537A580F0A79F","sha256":"567943DC5D56B5C155BDCF484C1CC2BFDA74DE7A6D4DB2C9B481889C5156CB43","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\A5D93CC48B83C8124FEB6A2E9448677EACA5BA86.g1p3okhzl","md5":"ADD9E6B5B232BCAB8B23C3AFD92AFF10","sha256":"3369564F935ED61731E23F134C0AB8FB99AA66E619C8482AA33037116266E7BA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\A4318AB5C2A2B8721BBC3C55E5DB82BE3E7EE010.g1p3okhzl","md5":"B39EE25390AE34FD27121225F75AB843","sha256":"2FED70ACD8FEF37469FDE0BC93061C700B9DCFC2E8D5EA0766BC190C6FD7BD1B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\A8023AE9DC58F4247227927BDAAB7019DF7926F0.g1p3okhzl","md5":"66703F03A052AE524E415A8786B7767B","sha256":"56639EAD1E159E087BF5236B534FCBD8255D903BC5A424D3763C95ECC227DAA0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\AC5E012C1887C7B691A8EA00C4E754025E25C235.g1p3okhzl","md5":"F136792FB8E699115A0F7B526C24EA7A","sha256":"5278F238CBACDF07A06832819E349D775E13D79F4E4091C9F38B6F50AF9BA304","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\AD0A5DB22D964451CE05349773D5F92E51FE0709.g1p3okhzl","md5":"78CDF8C3BB01D2034F560457ED4F9B35","sha256":"6A5017EC8AF5B46DD49FA4E7E02A53CA519EF983086BC714C033F95A955114AB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\A741C5DDC88A06360A65559CBF3D3F01B4027F92.g1p3okhzl","md5":"99BE98CB2F28AEE8A66F81EB63DD1F7B","sha256":"4174972667991EB1758C958D7E3163823560107ED868CEA9F47B11E47A85B005","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\A8C0B1AF6E195C575B07028B364AA6AADAEB2074.g1p3okhzl","md5":"7EEFCF0E08D93B73D4CDDD9B78D45DBE","sha256":"137B8FDBA7C3CA2C1F406A597B0C62953C2E9AE25380D6CF58D0F08D30C69B81","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\B5A28D3E93A7C7935CFCFC3DB5D34C1DD3B41F7E.g1p3okhzl","md5":"794BAE2EABD1D719D40A3966F01DF972","sha256":"11024B496C64B8D41112D4712BBE23835F9DBF4BF3572D267106501D9B76169B","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\B9667D755101C1D21E786F253C654BD086964020.g1p3okhzl","md5":"4386409B8A6F873F1FB896787CE18F8A","sha256":"1DA11D1D2C117815BF79FC8ADD8149ACFB9C704F3465783DCFC2427A710F382A","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\C0E9F320570B7C1A7FC338962A14427DA654B1AD","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\C328EAD2880AC9FFCD6A1F189ABECA85F0DBE8A7","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\C459983FDD69265B480E21D9B162C268AF3E7FFC","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\C664ABAE6A070392F60C7BFF721450AA0CF7DBA0","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\CF1D0D83995A806894F0CA0FE7281A00B0108BFA","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\D00A688072D5E651DFCBF1F615D0FF8CC68B8989","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\D03846D8AB99A1AB07D2F7D3B5326080E2A709C2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\B6F3FB36D9FE3D14A4D9AF63479F9544B256F130.g1p3okhzl","md5":"F1D6C92882EC9AAD00DD4628FA1C559A","sha256":"FE31AF54AA41217DCC71EF25D911A6CBEDF63023572FD74FF5731E1F324A6136","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\C5DAC5AAD8E9B777F3CFCF7EE8B12DFB16E1FD79.g1p3okhzl","md5":"89453EFE6F8D35CAF9A1CD49E9A454FB","sha256":"4EF4D6817D75AB29F882919C2B120208E534B7A8963E3A5AD5C61F06E85A2F84","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\D17FDEA053F042E7C1F46E73FEFE25911325753D","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\D4F87DA3BE5E1B4EF26B02BE9438F82378DFC993","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\D66FD91F7FD1FF967BEAE9D217B63DFEFC67D0A5","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\D68169F91A4232257A5C9887787D13C2DF475804","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\BABD4AFAAF48CA2255CA2E5EC57CB0B09AA1B64A.g1p3okhzl","md5":"C338CC756668310E5BED6EF25882F8C1","sha256":"D95BDC31A5997ABF516DAA90794C77DD93F1E0DD9193FF496215FC40244749FB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\C0E9F320570B7C1A7FC338962A14427DA654B1AD.g1p3okhzl","md5":"7C3519F562299C0AC2EACDE2292C8C35","sha256":"B24F9BE3B557E9880C620FF95D3CBFA088946D82A52F85CC4D535EDAF803FAC3","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\C664ABAE6A070392F60C7BFF721450AA0CF7DBA0.g1p3okhzl","md5":"92D203CD5FEA06138052B3ED6F941383","sha256":"0E4EA0A27C2AC891C7B71623A246325AFDBA812D87BA3A9C8DF6C70AE9263AC0","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\C459983FDD69265B480E21D9B162C268AF3E7FFC.g1p3okhzl","md5":"F621EE722D339D7CD520F715E9F1DB13","sha256":"F3DA29FBEEFF80FD197E9FB19A062A0AB5008475DD5F6F7D09325F6B5C3E7135","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D03846D8AB99A1AB07D2F7D3B5326080E2A709C2.g1p3okhzl","md5":"BFCD5E681E36A0A386BCF686E3EFD901","sha256":"2942F0A3DBC5C7094CA9EECF58ABE2449FB866C9FE42C7D863B30171318E4F6E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\CDBF138E0282E30B44DABACDB2FD97F0AC36A903.g1p3okhzl","md5":"6D397520201E8E3497BD0809798F5C11","sha256":"E294E8343DE584FC0B817911E4A2666CD244997ACCBA25D82D7F9D5CFB2FEFB2","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\CC272A84C437C06018182F241F266FFC52770F69.g1p3okhzl","md5":"ED644E73FE4ECAD64948A294101F3AFB","sha256":"CAC516AF458199BFE56B786FC10C11CF22ECFBF92EE3BA366D38DE7ECE54F173","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\CF1D0D83995A806894F0CA0FE7281A00B0108BFA.g1p3okhzl","md5":"999023F2D97CF52C775C13E960ECC51E","sha256":"84D0FF1EC932C5E4782E4B9916D6D2AEEC275A9074EBB139E2FBE503BB901C13","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\C328EAD2880AC9FFCD6A1F189ABECA85F0DBE8A7.g1p3okhzl","md5":"2F5B0556344C10B8CD1D7C8670DF584F","sha256":"7044DA3EBE9CC419D06AB19B124BDF09944692E0687FF805AD9891377A6B6977","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D00A688072D5E651DFCBF1F615D0FF8CC68B8989.g1p3okhzl","md5":"B04FFAE77D3FD143FBD72C4C94E7D189","sha256":"D27776053490FBC31CD598577D98052778E2A3666BBD70FCD96B052BD4465581","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\D6E5CC05500B28C7AF717C256E6ED2546C1AD325","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D17FDEA053F042E7C1F46E73FEFE25911325753D.g1p3okhzl","md5":"9A3FC94703EE0ACD034F9E930538C7BA","sha256":"245028C3E65F14B0B8F65969ED17C6BEF8025506BCDE5A960D12872FD5B8EF19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D0A977A7A298370CD3E401D9B352925B4EC1AEAD.g1p3okhzl","md5":"422FCE1D84E76814CA17E1309B35C31B","sha256":"E8AF1A7EC937557DE0342B2B929549C321C2BF4F6DB9427BA3EA833C4141EE74","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D4F87DA3BE5E1B4EF26B02BE9438F82378DFC993.g1p3okhzl","md5":"6A294308791E27FE67E6B146347A8C02","sha256":"63C1F8B0FCF32F0A0F648DAA85519FA63E19F7FF5241320D33B8544A077AFB79","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D66FD91F7FD1FF967BEAE9D217B63DFEFC67D0A5.g1p3okhzl","md5":"EFF834D10DAFE722FA6BD9396522F450","sha256":"B4AB2E7CF501F489E4F69CF379C307CCF2E6B79AFB05A88C5E8FC945902BCEAA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D13785C8931AFCAD8823E6AD79DF4F4F61CE1CD9.g1p3okhzl","md5":"78E801AAFDE7BAD0546E08FC15F1E6CB","sha256":"EC6DE1294A40DE8CAA5D85A276AD001E359167C8455D5676C26397A4301DDCB7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D14E89E9C0B1611A544D1BF058490F1AB052C547.g1p3okhzl","md5":"E5C3CAD77C9E1504C2155791471D45A3","sha256":"B85B486F8483974BDFDA7E844AB58EA9791031972CAB35A1F95044BF8EC7BFFB","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\DC1A0E32A76EB0FC87514517F6EB6114D1B46BF9","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\E21F074DBAD1CB7994F383C419228B689766FB1C","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\E340C06B68868CA3286476F5EA19A3D7AFFC8F74","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\cache2\\entries\\E64502DA6ACFA22EA3F0DA848AE8D39FFEB370A2","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D68169F91A4232257A5C9887787D13C2DF475804.g1p3okhzl","md5":"7DC7BAB6A446C1EBC4AA419B1862A33E","sha256":"70C4B463DF993100AE45D997D4FF1FF3FB2976167D7C54B624BDA77A406194A3","type":{"value":"vc","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D7688A7E797DABA101A2940A4CA68A0F07DF59AA.g1p3okhzl","md5":"E351F28362C52A25A0D03BB3599DBEF0","sha256":"0B407E836DA4A44A638BDFB6D3D5FB25406538A2995BC3E8EA0C1060C4155B85","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\D6E5CC05500B28C7AF717C256E6ED2546C1AD325.g1p3okhzl","md5":"13684D1FB139B715A2ECFD3A2AAF9C2B","sha256":"70DDAA738DE096AE658B411B5E3B97BAD1E03C27DD91F175001B0A25C50EB5DA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\DC1A0E32A76EB0FC87514517F6EB6114D1B46BF9.g1p3okhzl","md5":"13E3D46B93199A73EC5046535BB11FD5","sha256":"8118208289554B2DD0C260353CA595C2B0FAE2C09776424EF4DE9F657F961184","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\hu\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\hr\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\hi\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\E21F074DBAD1CB7994F383C419228B689766FB1C.g1p3okhzl","md5":"6AEF61B114A6C1352D999DD39C88EA69","sha256":"73B6A20D70112D708743D89DDF5AC94FEC1073949BBED9691772492DBD2BCEE2","type":{"value":"ct","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\E340C06B68868CA3286476F5EA19A3D7AFFC8F74.g1p3okhzl","md5":"623EAC9D1D776E6095C3EF8D65370C31","sha256":"09AC74C70A58E76ADFF7A0C762A47BEE25BE11288B87C2994F251B727FBA5D38","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ja\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\it\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\id\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\mozilla\\firefox\\profiles\\qldyz51w.default\\cache2\\entries\\E42586E3A72B251BCDFA05168A233D03C33F6546.g1p3okhzl","md5":"2BBBDF35DCFD9076D0DC41C9D5184244","sha256":"01CC2E9FD7725A52BBC453842EE4F67A4CEA041B26CD38CFDC74FF5F38C7B203","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\kn\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\iw\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ms\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\mr\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ko\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\lt\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\lv\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ml\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\nb\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\nl\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\pl\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ro\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\sw\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\pt\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\sr\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ru\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\sl\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\sv\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\te\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\th\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ta\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\sk\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\tr\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_metadata\\computed_hashes.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_metadata\\verified_contents.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Storage\\ext\\nmmhkkegccagdldgiimedpiccmgmieda\\def\\Network Persistent State","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\default\\about+home\\idb\\3312185054sbndi_pspte.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\default\\about+newtab\\idb\\3312185054sbndi_pspte.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\default\\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\\idb\\3647222921wleabcEoxlt-eengsairo.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\default\\about+newtab\\idb\\3312185054sbndi_pspte.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\uk\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\vi\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\storage\\ext\\nmmhkkegccagdldgiimedpiccmgmieda\\def\\code cache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\zh\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\storage\\ext\\nmmhkkegccagdldgiimedpiccmgmieda\\def\\platform notifications\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\zh_tw\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\storage\\ext\\gfdkimpbcpahaombhbimeihdjnejgicl\\def\\gpucache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_metadata\\computed_hashes.json.g1p3okhzl","md5":"CBACF4448F8607B2C8252DDE60B99F8D","sha256":"03B6DCFEC689AB161825E790AF077FE4E675AC4B24FA983928444E8003608C6F","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\default\\about+home\\idb\\3312185054sbndi_pspte.sqlite.g1p3okhzl","md5":"D48F811AE75B30B7A5907D8BB5E560A4","sha256":"BCC5EB3C0BFE2F86A374F072627B425D367E90BAC75143ECB710347376DE46DD","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\storage\\ext\\nmmhkkegccagdldgiimedpiccmgmieda\\def\\gpucache\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_metadata\\verified_contents.json.g1p3okhzl","md5":"DBF04D3C6F6B36E3C04F158EB2403FD6","sha256":"2FCA18C3E87214A4CADC88C28EFB6381773C3F7F5C2F66FB220EE26554074A7E","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\storage\\ext\\nmmhkkegccagdldgiimedpiccmgmieda\\def\\Network Persistent State.g1p3okhzl","md5":"A9D84F3922F77FCA92B39A44A196F583","sha256":"2BC7857A126E8AE04E1A5883891CD5CA471BCCFE82615E1CB252E8427147FCB8","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\default\\about+home\\idb\\3312185054sbndi_pspte.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\default\\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^usercontextid=4294967295\\idb\\3647222921wleabceoxlt-eengsairo.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1059394878bslnoicgkullipsFt2s%.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1451318868ntouromlalnodry--epcr.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1657114595AmcateirvtiSty.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1725441852bxlfogcFk2l%isst.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\default\\about+newtab\\idb\\3312185054sbndi_pspte.sqlite.g1p3okhzl","md5":"D4C6B09FD4E75EEC20FA42C10D39F0B2","sha256":"F79F8FF6FBC416A321F331FE71602736FEF54F17D357176C46015197114106BA","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1059394878bslnoicgkullipsft2s%.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1451318868ntouromlalnodry--epcr.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\default\\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^usercontextid=4294967295\\idb\\3647222921wleabcEoxlt-eengsairo.sqlite.g1p3okhzl","md5":"F9B5A43BEF19B03338D2CD38C9DD1283","sha256":"A1E7ED4F176FF6335AE9383EEE948FD45D64C20F122B574E9B84112C97F4BD19","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3561288849sdhlie.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3345959086bslnoocdkdlaiFs2t%s.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3899588440psinninpiFn2g%.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\am\\messages.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1059394878bslnoicgkullipsFt2s%.sqlite.g1p3okhzl","md5":"4555208328E71BA9CBC1DF81E779A471","sha256":"D0E0743BBFA160A70BD2B1870605E433068D5E899159B677CCAFC54D099FA590","type":{"value":"gpg","type":4}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3561288849sdhlie.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1451318868ntouromlalnodry--epcr.sqlite.g1p3okhzl","md5":"878504EB1CF95964882A27E35A0D3954","sha256":"604A93E2011CA1682FBA5B820393768EBEF5EF9BF6BCB396F7413943D119F338","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1725441852bxlfogcFk2l%isst.sqlite.g1p3okhzl","md5":"69B9189A26FBFAF9946D11A5982A64D1","sha256":"ABFCA0891A14312D1D5863B28CC8FCDD95372E433E3804F87D6631CD56CA1122","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1657114595AmcateirvtiSty.sqlite.g1p3okhzl","md5":"A16A638F16BD47A6EB743D9D1CA115EF","sha256":"A79B657D031024D713BC6F8AEE5154DC01C7DEB6A2C02270C22FC6A63413E3A7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3870112724rsegmnoittet-es.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3345959086bslnoocdkdlaifs2t%s.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite.g1p3okhzl","md5":"C03EE70769CDA7B77569B53ACB68EF0F","sha256":"695F74195CAA7B5DB2EFBB6FEA5DE4541280EEDECA2CFF73C716723DBB04F747","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1725441852bxlfogcfk2l%isst.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\1657114595amcateirvtisty.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3345959086bslnoocdkdlaiFs2t%s.sqlite.g1p3okhzl","md5":"2CC7EB1CE39C6A36AADD011ED1AAE723","sha256":"1D4D70752857DA7EAA3F52DEE508F418FA3F1CC7F8449548B3751514DEF38213","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\727688008bsleotcakcliifsittsr%.sqlite","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ar\\messages.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\bg\\messages.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\bn\\messages.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ca\\messages.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\cs\\messages.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\da\\messages.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\de\\messages.json","md5":"—","sha256":"—","type":{}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3561288849sdhlie.sqlite.g1p3okhzl","md5":"21984B47BAAA920FD125457DCAD6D5F1","sha256":"3C4B5AD9825A20E8C82AFA98F47C50B6C733F09CF07087F27D7BF5629334E745","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3899588440psinninpiFn2g%.sqlite.g1p3okhzl","md5":"95F3305349D7CE651CB23063594B36ED","sha256":"FDC4467D86E4386D196715D014FC8F26D799E4D17CD2ADA7764A745DE9385593","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\3899588440psinninpifn2g%.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\727688008bsleotcakcliifsittsr%.files\\g1p3okhzl-readme.txt","md5":"92E9AF251CC632E12B65B8E210E8B4E6","sha256":"B8BBE516F96766CB5026297C4E9DD707ADC158147988CC90351857B89FC39CE7","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\am\\messages.json.g1p3okhzl","md5":"7C2C8CC8825E9119ED6C425DAE9FA545","sha256":"A62F06C82C5BB2C517A160286A0D7BF63615940F11BC76166465A28439221867","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\bn\\messages.json.g1p3okhzl","md5":"8ADB17E8C00DE76849D597CDC3AB5896","sha256":"5BAC28D5CB199BEE69375991042775C09B160CCA2684E04E6954F71FF1E941FC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\ar\\messages.json.g1p3okhzl","md5":"C15754D0E6D964E5BB1C905D75645B0C","sha256":"2E48EBF9567E77D726CE33B41D4CF254743CDFFC8E1F28193312D4D53DEE34BC","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\roaming\\mozilla\\firefox\\profiles\\qldyz51w.default\\storage\\permanent\\chrome\\idb\\727688008bsleotcakcliifsittsr%.sqlite.g1p3okhzl","md5":"24CD909C4686861FD5F7D4F6A236F194","sha256":"A8A077B99573085D61EF1066A12C9115DF9FBC9422060EA28EACE5EEA42675E1","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"c:\\users\\admin\\appdata\\local\\google\\chrome\\user data\\default\\extensions\\pkedcjkdefgpdelpbcmbmeomcjbeemfm\\7919.1028.0.0_0\\_locales\\bg\\messages.json.g1p3okhzl","md5":"2A58CC056330746F85E92A563DAD5F48","sha256":"6A3786341131BB45E5E1A22EE1C5A9E5C611B68950233CA4BE03C4338ADE8B31","type":{"value":"binary","type":1}},{"pid":4024,"process":"rundll32.exe","filename":"C:\\Users\\admin\\AppData\\Local\\Temp\\hf8l.bmp","md5":"7A9D99F6A8F4E62847820CDC00166544","sha256":"C43D13F3DB3E56C616E9DC37432B7D0825CEEE715E2DCFB9A1E8FC33BCFB4B6E","type":{"value":"image","type":0}}]},"synchronization":{"values":[]},"rpsRequests":{"values":[]},"networkActivity":{"stats":[{"name":"HTTP(S) requests","value":"0"},{"name":"TCP/UDP connections","value":"12"},{"name":"DNS requests","value":"8"},{"name":"Threats","value":"4"}],"requests":[],"connections":[[4024,"rundll32.exe","142.93.110.250:443","oneplusresource.org","—","CA",{"value":"malicious","type":2}],[4024,"rundll32.exe","45.33.30.174:443","teresianmedia.org","Linode, LLC","US",{"value":"suspicious","type":1}],[4024,"rundll32.exe","185.162.66.158:443","bogdanpeptine.ro","T-Mobile Czech Republic a.s.","RO",{"value":"suspicious","type":1}],[4024,"rundll32.exe","185.42.105.5:443","deltacleta.cat","10dencehispahard, S.L.","ES",{"value":"suspicious","type":1}],["—","—","217.160.0.197:443","plantag.de","1&1 Internet SE","DE",{"value":"malicious","type":2}],[4024,"rundll32.exe","217.160.14.132:443","tsklogistik.eu","1&1 Internet SE","DE",{"value":"suspicious","type":1}]],"dns":[["oneplusresource.org",["142.93.110.250"],{"value":"malicious","type":2}],["bogdanpeptine.ro",["185.162.66.158"],{"value":"suspicious","type":1}],["teresianmedia.org",["45.33.30.174"],{"value":"suspicious","type":1}],["deltacleta.cat",["185.42.105.5"],{"value":"suspicious","type":1}],["tsklogistik.eu",["217.160.14.132"],{"value":"suspicious","type":1}],["www.tsklogistik.eu",["217.160.14.132"],{"value":"suspicious","type":1}],["plantag.de",["217.160.0.197"],{"value":"suspicious","type":1}],["kingfamily.construction",["—"],{"value":"malicious","type":2}]],"threatsProCount":0,"threats":[[4024,"rundll32.exe",{"value":"Potentially Bad Traffic","type":1},"ET INFO TLS Handshake Failure"],[4024,"rundll32.exe",{"value":"Potentially Bad Traffic","type":1},"ET INFO TLS Handshake Failure"],[4024,"rundll32.exe",{"value":"Potentially Bad Traffic","type":1},"ET INFO TLS Handshake Failure"],["—","—",{"value":"Potentially Bad Traffic","type":1},"ET INFO TLS Handshake Failure"]]},"debugOutputStrings":{"values":[]},"meta":{"sha256":"7ac75d8d4390707428b148cf3cad23d804930141fd8ea53cf1a7790f7d1c3c88","uuid":"c68425b7-5d5b-45da-acfc-c20b3f3cf578","isUrlType":false,"taskName":"stage3.dll","title":"Free Malware Sandbox Online","isPrivate":false,"tags":["ransomware","sodinokibi"],"copyrightYear":2022},"vue_isInlineMode":false,"vue_publicPath":"/report/"}
We're sorry but any.run reports doesn't work properly without JavaScript enabled. Please enable it to continue.
General Info Add for printing
File name: stage3.dll Full analysis: https://app.any.run/tasks/c68425b7-5d5b-45da-acfc-c20b3f3cf578 Verdict: Malicious activity Threats: Sodinokibi
Sodinokibi
Sodinokibi, also called Revil, is dangerous ransomware-type malware. Among other tools, it uses advanced encryption techniques and can operate without connection to control servers. Sodinokibi is among the most complex Ransomware in the world.
Analysis date: June 11, 2021, 22:06:03 OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) Tags: Indicators: MIME: application/x-dosexec File info: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows MD5: 612F5B62182B5C3A8EB64ECAA2827462 SHA1: 9D2BFCBAF44F9E59BBB451DCE29E4C7AD6778808 SHA256: 7AC75D8D4390707428B148CF3CAD23D804930141FD8EA53CF1A7790F7D1C3C88 SSDEEP: 1536:OgzVnCcFqy0+A1raqG/33+92Z9i0C1b5rprOEGICS4Av3uZs38oP/GgmOpSFDrKD:OCY7F2sb5dHd3uW383rvDrKr
ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is.
ANY.RUN does not guarantee maliciousness or safety of the content.
Software environment set and analysis options Launch configuration Task duration: 60 seconds Heavy Evasion option: off Network geolocation: off Additional time used: none MITM proxy: off Privacy: Public submission Fakenet option: off Route via Tor: off Autoconfirmation of UAC: on Network: on Hotfixes Client LanguagePack Package Client Refresh LanguagePack Package CodecPack Basic Package Foundation Package IE Hyphenation Parent Package English IE Spelling Parent Package English IE Troubleshooters Package InternetExplorer Optional Package InternetExplorer Package TopLevel KB2533623 KB2534111 KB2639308 KB2729094 KB2731771 KB2786081 KB2834140 KB2882822 KB2888049 KB2999226 KB4019990 KB976902 LocalPack AU Package LocalPack CA Package LocalPack GB Package LocalPack US Package LocalPack ZA Package PlatformUpdate Win7 SRV08R2 Package TopLevel ProfessionalEdition UltimateEdition Processes Add for printing
Behavior graph Click at the process to see the details
start
rundll32.exe
#SODINOKIBI
rundll32.exe
unsecapp.exe
no specs
vssvc.exe
no specs
- +
Specs description Program did not start Low-level access to the HDD Process was added to the startup Debug information is available Probably Tor was used Behavior similar to spam Task has injected processes Executable file was dropped Known threat RAM overrun Network attacks were detected Integrity level elevation Connects to the network CPU overrun Process starts the services System was rebooted Task contains several apps running Application downloaded the executable file Actions similar to stealing personal data Task has apps ended with an error File is detected by antivirus software Inspected object has suspicious PE structure Behavior similar to exploiting the vulnerability Task contains an error or was rebooted The process has the malware config Process information