General Info

File name

f2abc66901177e87cc0c01372385a04901a178e4

Full analysis
https://app.any.run/tasks/d49dd41b-0220-41b0-bab5-9492be39112f
Verdict
Malicious activity
Analysis date
5/15/2019, 11:12:19
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

gandcrab

trojan

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

2b0c92cda08f13322c9111d0fe9dbbd7

SHA1

f2abc66901177e87cc0c01372385a04901a178e4

SHA256

bc5d629b615f977b247618d1ed25684a68bdaffbe0bcb7017b47f5eed9281e4e

SSDEEP

6144:x/lIEVIc3OxA+aFaOB4TU6MhYB70UyiobdptQm7OO:nLqfMh60sSxk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes settings of System certificates
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Connects to CnC server
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Deletes shadow copies
  • cmd.exe (PID: 3288)
Renames files like Ransomware
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Dropped file may contain instructions of ransomware
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Writes file to Word startup folder
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Actions looks like stealing of personal data
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
GANDCRAB detected
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Adds / modifies Windows certificates
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Starts CMD.EXE for commands execution
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Reads Internet Cache Settings
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Reads the cookies of Mozilla Firefox
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Creates files in the program directory
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Creates files in the user directory
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Dropped object may contain Bitcoin addresses
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)
Dropped object may contain TOR URL's
  • f2abc66901177e87cc0c01372385a04901a178e4.exe (PID: 3116)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (52.9%)
.exe
|   Generic Win/DOS Executable (23.5%)
.exe
|   DOS Executable Generic (23.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:02:20 14:37:24+01:00
PEType:
PE32
LinkerVersion:
9
CodeSize:
124416
InitializedDataSize:
121370112
UninitializedDataSize:
null
EntryPoint:
0xfce9
OSVersion:
5
ImageVersion:
null
SubsystemVersion:
5
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
20-Feb-2018 13:37:24
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000E8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
20-Feb-2018 13:37:24
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0001E533 0x0001E600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.92573
.rdata 0x00020000 0x000058E6 0x00005A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.14295
.data 0x00026000 0x073A7F58 0x00018A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 5.99596
.rsrc 0x073CE000 0x00005950 0x00005A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.22387
.reloc 0x073D4000 0x0000CF60 0x0000D000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 0
Resources

No resources.

Imports
    KERNEL32.DLL

    GDI32.dll

    MSIMG32.dll

    SHELL32.dll

    USER32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
38
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

+
start #GANDCRAB f2abc66901177e87cc0c01372385a04901a178e4.exe cmd.exe vssadmin.exe no specs vssvc.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3116
CMD
"C:\Users\admin\AppData\Local\Temp\f2abc66901177e87cc0c01372385a04901a178e4.exe"
Path
C:\Users\admin\AppData\Local\Temp\f2abc66901177e87cc0c01372385a04901a178e4.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\f2abc66901177e87cc0c01372385a04901a178e4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

PID
3288
CMD
"C:\Windows\system32\cmd.exe" /c vssadmin delete shadows /all /quiet
Path
C:\Windows\system32\cmd.exe
Indicators
Parent process
f2abc66901177e87cc0c01372385a04901a178e4.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\vssadmin.exe

PID
2716
CMD
vssadmin delete shadows /all /quiet
Path
C:\Windows\system32\vssadmin.exe
Indicators
No indicators
Parent process
cmd.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Command Line Interface for Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssadmin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\vss_ps.dll

PID
2576
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll

Registry activity

Total events
129
Read events
92
Write events
37
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASAPI32
EnableFileTracing
0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASAPI32
EnableConsoleTracing
0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASAPI32
FileTracingMask
4294901760
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASAPI32
ConsoleTracingMask
4294901760
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASAPI32
MaxFileSize
1048576
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASAPI32
FileDirectory
%windir%\tracing
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASMANCS
EnableFileTracing
0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASMANCS
EnableConsoleTracing
0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASMANCS
FileTracingMask
4294901760
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASMANCS
ConsoleTracingMask
4294901760
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASMANCS
MaxFileSize
1048576
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\f2abc66901177e87cc0c01372385a04901a178e4_RASMANCS
FileDirectory
%windir%\tracing
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000003000000090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
DefaultConnectionSettings
4600000002000000090000000000000000000000000000000400000000000000509C6163FE0AD501000000000000000000000000020000001700000000000000FE80000000000000A179B3FF019923140B0000007C8036007C80360000000000000000000400000000000000A080360004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0300000000000000020000000100000002000000C0A8640C0000000000000000DADADADA0000000000000000050000000000000000000000849F120000000000000000000000000018813600188136000000000000000000FFFFFFFF000000000000000000000000000000003C8136003C81360000000000488136004881360000000000000000000000000000000000
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
WpadLastNetwork
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
0F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
Blob
040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D03000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B810B000000010000000E00000074006800610077007400650000001D00000001000000100000005B3B67000EEB80022E42605B6B3B72401400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB57485053000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703030F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE2000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68

Files activity

Executable files
0
Suspicious files
426
Text files
318
Unknown types
12

Dropped files

PID
Process
Filename
Type
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.bvornily
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Videos\Sample Videos\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.bvornily
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Recorded TV\Sample Media\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Recorded TV\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.bvornily
binary
MD5: c26bdd7760715d6fa4bebaf998dc3df6
SHA256: 5bf0da0a34130ca62304a2a793aa616259eb4d5932e31641f174bb20a145b47d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.bvornily
binary
MD5: e7341f263cf6f3f0874f4de4081bdfc0
SHA256: 918778e17dfed793fd36ef2f3d4deda143d80f736454a2c1a8af7a745c0ec6c0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.bvornily
binary
MD5: a7a3fd5141c023b97e8cb645724cc096
SHA256: 9af3ff9bbce50553c599c2787f38adc349409c59b98112b729879ec2441e0f97
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.bvornily
binary
MD5: 910737b51b14724034eeab320969700a
SHA256: 724b58886d1f7125c3ba67d8a108179d3fc0a5d784b17976e26ba7a1d3721819
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.bvornily
fli
MD5: 001b82426d7a7f8721427c8774842293
SHA256: 1da50575eb672d90881e87d6fa9237e4ea27c82a966f2e10a53ac1fcbac6a70a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.bvornily
binary
MD5: 248b1cc21e386353f446511b7c7ba4de
SHA256: 57d00ab9be5d5b5c97405bd07a18be7a2f4ceaec9ce601f7988cb541feaf4877
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.bvornily
binary
MD5: 272054e3c5d6f51bd6c8254d5a2f62bc
SHA256: 0c28b41cd93c66c13384389e87559ff6e95d89a2615f9375281a35f2c9ba1488
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.bvornily
binary
MD5: 027bf84384a9a878094c9843b18d3ce7
SHA256: d9897ea6970418264a8843db6191c6747432dccc1ebae40c5a988c59c6d527df
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\Sample Pictures\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.bvornily
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.bvornily
binary
MD5: 845d675991153ef05da1e45545845294
SHA256: 0ac785e6ea0aded9e624dda8d8635afc9827106e115683e11618a380dbd73765
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.bvornily
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Music\Sample Music\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Favorites\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.bvornily
binary
MD5: f98f02d168140f05779cda344497b902
SHA256: f9009c8e2b3a939f67a762fdca6112f4914989a4aa3171d0000c70ddc8617dba
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Libraries\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Videos\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Downloads\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Documents\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Pictures\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Music\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Saved Games\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Desktop\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.bvornily
binary
MD5: db45e7a6de6a5abde4373456cd51bdc6
SHA256: 8e7a935fe54c7feef18ac96da977fe50cbaec7125ce530c35c95f1a2098444fc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.bvornily
binary
MD5: 6bc4f5a482256851f0211ddb5ef60add
SHA256: 6f90c36ceca6b8baadb289d0f22858a17de707196b13e2cd0be1f83b1b323a48
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.bvornily
binary
MD5: 672d50d801da4fc7144639d45b9369d4
SHA256: bc56700f935b11346a78e044a55a3499e78196d9acd7298a70a0dcd0c18263f5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\NTUSER.DAT.LOG1.bvornily
binary
MD5: 16f63bc4f75274af0382c96ac3a93eeb
SHA256: 677f34a51c76cb3e47ede79379b6e6ffd86fb374fd90475e785a98b80535c67a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\NTUSER.DAT.LOG1
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Downloads\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Links\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Pictures\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Videos\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Favorites\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Music\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Desktop\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\Documents\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Media Center Programs\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Roaming\Microsoft\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Local\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\History\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Local\Temp\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\Local\Microsoft\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Default\AppData\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Searches\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Saved Games\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\ntuser.ini.bvornily
pgc
MD5: ccc15d403105a8ab93bbe14d96c3ceab
SHA256: 1b17bf16144248b9ac70b2f47c9fac87834a0838f2aaafc89704487a0578df00
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\ntuser.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.bvornily
binary
MD5: 72bcbfc9e8c1a52fe289e2bb564e7f44
SHA256: 8f46a4cd7062a148acf9ff1e95885309671967d0d0557c7db8f1e6e5bca23d96
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.bvornily
binary
MD5: 39995a9f81097036e4d5bbaef5c7e805
SHA256: f2c505240a9cb327ddba33342ff0a15a5458207e421854b8bee107ea393b60a4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.bvornily
binary
MD5: 84fe5386b9a1bbb56ac110937188efef
SHA256: 906ea71d40161ce64e54ce4bd71df2183ce82b9359183529937c23994a279cc4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\ntuser.dat.LOG1.bvornily
binary
MD5: 775422506a7ccdeda486159ef3fe28e8
SHA256: 4a6ea1bd696ba55bec03ad43dcf00ff54e759a8ba379cbf25e3b637ee4cb2e56
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\ntuser.dat.LOG1
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url.bvornily
binary
MD5: f622eed6c8fbb6215bae0aa26c111983
SHA256: 2f5e654775e8586d359b00a86d87a9bd648c520b99a9d52e812a191e8479d1fe
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url.bvornily
binary
MD5: ec983ee207dc21c69171ac3065973ada
SHA256: c2e285f4f9dcf728c9870b8efe7903ac92b332d0df4fa4d08fc3f2dc1430f04b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Links\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url.bvornily
binary
MD5: ce925e760455183b46ef9bde747df4f3
SHA256: 2d15af7b8bf40d78c7b2a626b942b07f7fd25c319e8b2bd0583a98f0ab55d21a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url.bvornily
binary
MD5: 5696be303a51f332269bad2dcb090ef1
SHA256: 06f1da1b5c598471bca5e4c5d1bbcfc4a8c891a6007f58222c5e01196406b309
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url.bvornily
binary
MD5: cdc3afddca88ed5746a9aed5e8fb0caa
SHA256: 824927dced57e3e1dc348b9860efe938cb37d39cbe5fa0049eacfad998eabf60
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Windows Live\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url.bvornily
binary
MD5: 6ffb320c4eadfd437262988cc62bb315
SHA256: ee66fa9e0feb631844f95666fbf49814c5ed9f839a7a22553eb240d4cf8f6063
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url.bvornily
binary
MD5: 9fe8ccc3b784ab853a7143c598501e20
SHA256: 025906a6881d41f8ef669590f60fb034ae31313f4fa2af04be744012e62f5e8f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url.bvornily
binary
MD5: f1cc7e49b19358f71d85919cf161ec3d
SHA256: abd0d603a6cbe81754ade77e010108226428c2e10228361a17ebd64270f97698
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url.bvornily
binary
MD5: c344ad394350dce98ef0c96e3e56611f
SHA256: 19f1431d2a80edc665840d89bfe986993e136ac1f468c09b354a19df163284c9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url.bvornily
binary
MD5: 42508046bd8fa38d099b0478260ad2ca
SHA256: 9d3f9f7606b32de04f516bcdf8befec2764dd9305b6b4f337cea89a9fe2c8fd9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\MSN Websites\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url.bvornily
binary
MD5: e80f6cc0517776ade95057a2ff1d0137
SHA256: cbf3dad69996367995d76842713234170fd42bb9344111c14e40d8cf94628bc6
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url.bvornily
binary
MD5: cc2a79af06a087e161f0604e4bad9f51
SHA256: f2ed3b447a873eba11ee8fe859e27a99c19a526e0a3c54a1307d873669c3c355
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url.bvornily
binary
MD5: f67bfe9d88d578649ae263d61b130d03
SHA256: 1ce6c8387071ba5e0577ce592be08ab3f0f3fb12d5e565f643a4c4f76ad0b279
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url.bvornily
binary
MD5: 52097e53d732c7b624f16f37b31b4d13
SHA256: 1e240bb9780cf77f04becc6fccb51834271f3d6c39fba8266f7bfa7ff2c0ea6d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url.bvornily
ini
MD5: 10003218423ce3f87e7aae541457d271
SHA256: 539e94fd6eee39118331715c6ad6841012953053da1cc1b672687b3847004162
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Microsoft Websites\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url.bvornily
binary
MD5: 7fcac30eb0cecb6289d2e2fca3165d3c
SHA256: 3805f84bcb61be61cc9b54965374652f89353fb915907ac98aea1b89ac6f2be3
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url.bvornily
binary
MD5: 31ae355640fa9dcfcde8f94d04d73342
SHA256: 45708ad5b01e2be3708b5a09dd29ce787262e3fe7b8dce843bd7e327daeb7014
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url.bvornily
binary
MD5: 0828a81dd0752bc3945632e2506ca971
SHA256: 6af30d8684886cf64195ed6a39bbc2b54a68deff0e148f12d070e3db2844ba26
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Links\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Links for United States\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Downloads\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Videos\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Desktop\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Pictures\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Documents\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Music\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Favorites\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Contacts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Contacts\Administrator.contact.bvornily
binary
MD5: 662c9ac3ad49c3e45eac6826548c7a89
SHA256: a6c51ab9a9002dbe42c26958430798855f76775ff16140845a5933d598d77fd5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\Contacts\Administrator.contact
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred.bvornily
binary
MD5: 4495fd21fcb34e044317ff9ec0d11bcc
SHA256: f342bc40c8010ae00a8d163ee4a48077fcda960142e42ed50f493283f9452d1d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156.bvornily
binary
MD5: e5ae26147703917236a2be92951788ad
SHA256: 434b5b5388fab7e132a6ab7abe78d2297a925dd913fa7ef40ce42977fa2958f6
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST.bvornily
binary
MD5: fb44bad2e48fca2b118baf3c54f059e9
SHA256: 5472cafdb7f85150c95b4efa7514e1b30d138b619c648b1f1efa9655cb0cb66b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Media Center Programs\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Identities\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\Identities\{BA2162A3-2F32-4850-8D8C-B3C9A2AA9D43}\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Roaming\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\LocalLow\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Temp\WPDNSE\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Temp\Low\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log.bvornily
binary
MD5: 19edb2c5e715224fa9874e265918e8b5
SHA256: bfc714992462712b9e4b65a9d63f8cfc6c0b483c12c527cb4a09d5a4a8b8322a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp.bvornily
binary
MD5: 49dd4fe2f938e0369acfc430030a675d
SHA256: 37d04a9c50f2c027f4803ec1ac2f41c28f28b497790dd932dcd290c2d8603152
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Temp\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini.bvornily
binary
MD5: 6ed8ebe49445c5a27429129d1d3bf816
SHA256: 5b048c75f5aec4819d1396ea7b5638c293c6569bd04d4f455f0baf9683f02a9b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Gadgets\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML.bvornily
binary
MD5: 80824cebd594831bc8d397c0d909c28c
SHA256: e2db25471b4d388295f04f93acf13a0bad545815e5ea70386bec82476cea4040
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD.bvornily
binary
MD5: b8227054650fcfb90338081be554418c
SHA256: 691e779caaf5e5450358823bafb996688091b6e6242ba7533c00b33775e9777d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat.bvornily
binary
MD5: e8cd6f8113ca29325fab23499357a52d
SHA256: c3f681e79d3fff3061a40be08ebb5e527950228bed5f104538a05513f1cbeafe
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore.bvornily
binary
MD5: 595a4901f05747605c09a110c30ec46a
SHA256: 034dec81a42ab68369a64f29fef3e49fffaf95b5e3c1bd11678dd4c7ff557d3a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif.bvornily
binary
MD5: df008d682bef647fe36f80943f9d0441
SHA256: b604ebf877ba6fa6eca5bc1ecb674ad0d2717627de163535a7241d9beb9ae1ee
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf.bvornily
binary
MD5: f9ce9eaf715eff8416ce51c15b4219db
SHA256: 6d925aa339059f750ea3da0c1563a9273a10bc392dbd7e603a28cc77aa618741
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg.bvornily
binary
MD5: 0ef7b8071e1f1332bf1e440978cb6c91
SHA256: 1c53a3a861a334224267cd0a39cef2d1b720c6f528fc5263dfa56d22fc301baf
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif.bvornily
binary
MD5: 1654084ef4d1db6fd5232ecc5e91f325
SHA256: 13ddeec9c427649397e144bd269d9a42ba525ac2ea7b8e1471ed1da930f64eb4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg.bvornily
binary
MD5: f3719140584841eefa36e6192d7cce69
SHA256: 68ca5d0bf13514a2441b5d7f15eaeb0840b68b21f23fbb8ffe88d519f1dd6424
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif.bvornily
binary
MD5: 1a404df9b6b557eeaabbcdc8123aa94c
SHA256: c3cc11201950ff02b427dc0f912e5946cba635957bc9bb3d300d54eb6c275779
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm.bvornily
binary
MD5: 74d1b52be4f88a5532c118f0edc92cd6
SHA256: 007aafbde8e3d869faf5fc216cc088bcd075993be21f0dac8a4f85cc5bb9d1cf
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.bvornily
binary
MD5: 1a809666ed06140ab633396f9b279509
SHA256: ba925a68435f3bb00eb40878cd168a734395e57ab187229860a97570f98c0a3b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.bvornily
binary
MD5: f80969675570ea836fc25e66d410281f
SHA256: c964028b7f4264d26be1c103877cac45c75c0d6572a419c64d3031b9f7aae9be
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm.bvornily
binary
MD5: 5b6b21680bdbb0d0254f8ac6dc10bb14
SHA256: 8854625c8abf119b42946d7d0c00d38ccb8852440e8e545121f283d48246dcc2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg.bvornily
binary
MD5: 8dda88641cf6891e291e728bbd0c6d95
SHA256: 86e4e6c53c590637950230f2bd2b1d6d0b1536f9c4037268a5b4a6aed05565a9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf.bvornily
binary
MD5: 8838531e70f317cfae448677f957f0e8
SHA256: 4c17d9379b072099c121c21144cfb49688a143ef9a2c959fa5d4e03108b7d450
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.bvornily
binary
MD5: f3c4815cd4952e11996e3a3209b56cce
SHA256: 66b2761c842a18eafa5ef0b53507615e336937ec8f52fac40e6e26cba46deb42
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm.bvornily
binary
MD5: 721edc1f96784576cc5bebb36c882d23
SHA256: 0d17402e11d5d3767fb075224bfd67d983476331af71769c193d2714b2f71c3d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf.bvornily
binary
MD5: d8387a19b6c84cb631f5c5de87fa2dbf
SHA256: 4bb5f98dc584f6722a1d873fb545ba7c46885354ecac4f578b427dbbe6e643b4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg.bvornily
binary
MD5: 89e26077fdd6c48401b5f2594cd34954
SHA256: 3f73458072b88eb756aa60f3f407fd1cab449d0bdef0c60de60f335906d5dac8
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.bvornily
binary
MD5: f26a5df9c54303e02ae527dc695619b9
SHA256: 1064273a4922be94922c35058d72da42b3234a754e6851a1b9a10adfc122f4c3
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm.bvornily
binary
MD5: 8d6ee5210975f20d5a3d495da68b55d7
SHA256: bdb5c46db4dc2aa856710c7d26bcce82ff98291d6a3d761642b0f02aa2196dba
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg.bvornily
binary
MD5: 320f16b4d68ca2d990feb92ff9ad8aff
SHA256: aed81d18ffc5c33ebca4f3ecc738d2c8b20f3348f6d7dc219761813144005b77
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg.bvornily
binary
MD5: 134803b5dae5a64166592a3617fcad2a
SHA256: fa4751c84ab23d11fd46fe1ba51ac54699350aaf6e7346071b46bc8706bde4fc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg.bvornily
binary
MD5: 0de719c52946d6b0266a45663647a6b8
SHA256: bf9f69423e5d3f211b72434d55aaabc966be086c5cc6c73459981beb494e17e9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.bvornily
gpg
MD5: bdd81858bb27af1a85f21bf6aabd716d
SHA256: 64ce2e091289f6ade902d4d7de938258734772be8fd3a746ef92a15fed45ffe1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm.bvornily
binary
MD5: 7b9823d9a10ac86179c555da96cc4f92
SHA256: 946f6cd7392fcbed7126ecb4363ccfd8ec939d86d13594030e0ee67fa1a5fa72
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.bvornily
binary
MD5: 8c96ab1512d1f4ecb14b34a27e7f4880
SHA256: 075c50cecf7c5e59610bfa8f0916d06055a20d1dc279acbe43df939da3d9b022
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm.bvornily
binary
MD5: 49178224defebf3bf4f51dc43e909809
SHA256: 7a6b5ec2df03888ba2e5607c9aa0d50674e63957fa9ace34d33e537a27739269
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg.bvornily
binary
MD5: cdcb63cd0ada41d9286a9d09fa4d5e81
SHA256: cbd7ae0d25da334cf14a271725892746d910f3d49b9935ee74b32d3c26dd9469
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf.bvornily
binary
MD5: 46e7c8072df7daf1c2b6acec8d47e2f5
SHA256: dfe75bb647322418fcd0952097fcb3dfc96b678f79815068f045509beae0aed8
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf.bvornily
binary
MD5: e3a9887496b222a3dd9a7f87e2783afb
SHA256: 6aa6d1264998dd10f0ea4fa9cc4f0150fea8eb63c2cb475263b437babbbda6bd
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg.bvornily
binary
MD5: b5338ae43cf8cc7528bd2c9ef8b15ef0
SHA256: f38209eb9b4265cc5958bb5414f3465f01807cb61159aaa2d853b309d5a45ba6
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf.bvornily
binary
MD5: 7ab4f42818cf2194975d4667f30abccc
SHA256: 44fc2240dd040b6d485de7acee14cf2b0443da2271001cb07dc61c0f7a467f74
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.bvornily
binary
MD5: 96497d1f654f091cb29ae147abafe580
SHA256: 8dd6f5417193005c509343a2052669052e539bb495e64b8ea1fcfdacfc566bb6
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm.bvornily
binary
MD5: 5a85b08fcc41ceb662cc0ef42ee77fb4
SHA256: 5a8833401375559339b09d932a4a25fe4535af2228ba21e2907f0543b55a3282
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf.bvornily
binary
MD5: 4c247884775e977f9743d0eb26ddf54a
SHA256: 75599ecabc907b8743510657c05d780403306001ed33726ca39b054e7a48d46e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf.bvornily
binary
MD5: dbde3eb0085709ed604cc4f79a06bfa0
SHA256: f69e15de955daaebbfe74eb2266da86e9ed4828b51400aedd69dc9eefc9da7c9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.bvornily
binary
MD5: a43af2445371aed854ec01ea81e84ad6
SHA256: 5d606e3a1597515a688e8ef5d3965cb3971b1f72558a689a5a832696dae66312
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm.bvornily
binary
MD5: 70cd8ec121430a65e406a4a53fa67fa6
SHA256: a96e1771a3fadf28927ed8a63df9452e106474048f8641485910c2ba8c369842
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf.bvornily
binary
MD5: 227cce935ff161acb8f8f9ef76dd407a
SHA256: 45b083f4e323fa32cae8ec110dada12a66f186dd62633b9e00bf9ba478c8cebe
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf.bvornily
binary
MD5: 46ef6f5cdf0387d8d5e2d1e936c32d56
SHA256: fba47d38603f653b9905a6380bbdd5d6a0175d1705bd54222e72e3faced1781a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf.bvornily
binary
MD5: 8c05803cad77425318bb8706ef626725
SHA256: e2b47b3137629bcfd117636b59e05b436b4cbc3aa9810499e152afe79d1a57ad
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.bvornily
binary
MD5: 515451869fd1d96725599811fb8d9d74
SHA256: a39955570b7552279c9f2a2569e55398bd1ba054a21ac473c6574cccac5eb9d4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm.bvornily
binary
MD5: 7a8bfce3131d1b21ad56996b6877de37
SHA256: 2b79438e64ee635a8e90be22629b030821fa6b7ecb0275bcebdb02a7f188fdb8
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf.bvornily
binary
MD5: 67dbd71ab015b23c0c14810cb8a3b559
SHA256: 23a5fc23b91975fe283fa8c6296c1bd5046fa106ae546d987cc9e260c0d6c65e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif.bvornily
binary
MD5: 36e1eaf1a62a9d6b286b2720fc864d1e
SHA256: fa30db51b6084d5b8918737a0fd02f70f30f59f3952bee41a867a91362a18552
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif.bvornily
binary
MD5: 9b415c3e871f23ea50ea9619ebee2347
SHA256: 0ba870ac228fffec64b654f618d51adf4a3b1aec1c918e5a6b2058d789483083
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.bvornily
binary
MD5: 7a02ddd095ac5d5c5d5c597c7c2ba0db
SHA256: db12ccb33b4542e1b2f36e4ff96ffd95993676a5066a9fd594e84e41d595b51a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg.bvornily
binary
MD5: c84eb62443dd05c285696941d91af7f4
SHA256: 8999f3d1d3c7eac0f0ff44c142c4b5c6da9e9b52d91987162bf6c761116a8d3a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm.bvornily
binary
MD5: bd06feae4529128a4b6e00666d9487c9
SHA256: 8a2108f753919fc0ec098dfecfe873ea3640af0178f39a430a759ee81b4940bc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml.bvornily
binary
MD5: 0d03953bf748c83121b39308ce139f11
SHA256: 7214587ea88b76b7a46310b57cc54618d07d2355d4199b0ee30b29601bbb5a7a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs.bvornily
binary
MD5: cd0fd92b89c5f76fef6a257d23bc193b
SHA256: 33a0a61b711e429867bc194ca8a69e9e4c34046db415441742d555db383b34e0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs.bvornily
binary
MD5: 1e5ad9ce2e3bf37d8c57e64b54b70044
SHA256: 4323fed1dd964bc1aff35210f983c2a045955a021b5d846072e42b97230b1e8d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log.bvornily
binary
MD5: 3014d079a7a54a4554313ee3f40bd4c6
SHA256: c55bf5061c68fe695bde1873d7594e59f502700848607dddb7700f55885bf53a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log.bvornily
binary
MD5: af3642843d20ce88e27acfdc0f254fd2
SHA256: cfd287e5e25e52466d269e9b6c67afcb357e68eebeaa9049b5276370c7542530
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk.bvornily
binary
MD5: b90a04ef8e9c6e742c5fe233378929bf
SHA256: 989ac708ffdc46e07491f44caeb8f112d38ac80100e0d25264070ddbbb9c9913
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat.bvornily
binary
MD5: 0b41e800909561842f77270a33ba1b9c
SHA256: 40975470d316fd77a554eb10df7433d76d2440a55e12ec6d5bf20fff8e66b4db
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore.bvornily
binary
MD5: cfb02ba0f2f1de616422dc7aec72d7ad
SHA256: dfab696e2bfc847e4c728e80fc759e86bc1a0308f632156d8e5ceb083559afc9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log.bvornily
binary
MD5: af828b5d163ad57627d71353c505657e
SHA256: ea87618ba67a3c8a3618b1b039340f6e9fe9e74691f7430f934dc3d5bb1b727f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount.bvornily
binary
MD5: c999b65eaec5acf80b758687d95becb6
SHA256: 3a583928365119344801bd5f5ecf61760a496189e8aad4cb1928592b410e0589
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount.bvornily
binary
MD5: f111aa17c872f411d1e9b4ca6b13280e
SHA256: cdcfa40ab25790ca1849197105906f83c77c71315a9d61fc9274d9e7e8b4330e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount.bvornily
binary
MD5: 5a90d6b8a52605bdbb96b2eef15b991d
SHA256: f408b165f58094ec4ad6f2fc863eb73f10198a7398748302593338133f93a608
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl.bvornily
binary
MD5: c40d95506c5bac0c123aa3f669356332
SHA256: e1057f8b2b0e02579f6f2688049951bbfa1f60d73199d54a470cdcb1534a36b3
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl.bvornily
binary
MD5: 7a72683458d47e6378c984c897647365
SHA256: a2f36b605b77d33d4a85971a7bbe3705c094dec7e5f26b3eb5b67df38e73f0c6
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl.bvornily
binary
MD5: f5685b6576d143ecace546007a1281a0
SHA256: a56da4b3e2523dc2daa073f90ed357779dc7b5be2640a6683f66860f4ba3ea26
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl.bvornily
binary
MD5: 3d117ea31c004c86be55cb3d7bf86d76
SHA256: 9a68375cbdcafde8da59ecf52356c0b9cf7fa4842838fbd8a72dc3dbbf2fe25e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl.bvornily
binary
MD5: 2238ed3d0149bd39fab0e98c19449903
SHA256: 137050a666ba071b26b0e5f9cb12637b35f7c88f1e66f8f4e83986392088a288
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl.bvornily
binary
MD5: 6642435c920fcdc2d48d18aa5b019b13
SHA256: 2048f7c3f6008549d369b9c924955f54dc0199e0699a8097915c187bc0beef94
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl.bvornily
binary
MD5: a9e853f26e04f435856bd464576bd951
SHA256: 5501f0858ecb81b944488fca9aafd4cbe710c484d0d23e9f617a1ea97feac3e9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl.bvornily
binary
MD5: fd61f8cffe6779e33f8ecc6f8460e7bd
SHA256: bba71e82d40100725354a9fc565cc5812e920d4d32b03fce742d463454dac467
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl.bvornily
binary
MD5: be72a468623f4b9a2ef9ef7dd113e03d
SHA256: 5cc1980bead715ccc75150eb71306d4ca24c72c7f22e065da134939f76cc2c4a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl.bvornily
binary
MD5: 3345f652e3be38c5e7aa057b4d59e49a
SHA256: bf1de5f347bc7f0f7bb327e68648f6cc7c661e68ae6565c9941e2695f3bdbc2e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl.bvornily
binary
MD5: 456b8a09afe2a97ba828f98103788637
SHA256: 2a9016e73cf1a48511b2e403c4aaf124f6f0f29253af1668cdd7dc22db4e31bc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl.bvornily
binary
MD5: 1a1bfd04dca38fc9f1f3ce35f80de9eb
SHA256: d776e52fe4a6598eb728383319b3d6bca08bd8520d02d407abf0ac663a9f8808
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb.bvornily
binary
MD5: 89c3508e81cd427869c126faa1fdab58
SHA256: 774624f8bec72864d7c2e1eea34122a69f406af81f56c8d00c9d629469a60ec0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb.bvornily
binary
MD5: de4319b54e6373d35d293d00f0171530
SHA256: 044764bf3efdbf779c314e159de87c43416929fdebc9fd2afe2c14840f49262c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.bvornily
binary
MD5: 690848be83c07380e3e42a61e09aef25
SHA256: 43a111f15669b9934c9426d47f8570d0438c4f6827f2cbb5d46ac04d656366ae
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat.bvornily
binary
MD5: cefb65f06b952833c780dde5760bef93
SHA256: b976f4329aa716f506d73ce517b59873996f86d6ccdfd07bbfb248e51a151206
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\VM3JD5NM\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\HPSK10OB\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\G4PHTCUR\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\9RI45C46\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms.bvornily
binary
MD5: 2d095e62a1481a5d2bdfa0bb18c2d81b
SHA256: bb2254dcd155c05b75bd0e9125916e6fc1691336933ddb8b2b2f527ed10f5c85
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms.bvornily
binary
MD5: 6c80f7f360414b52f7a549acca176d3e
SHA256: 3e90e65f08de98443280954ddb13757d3be38fafd717df261bf7564a48f52f70
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms.bvornily
binary
MD5: 3139af7b89adcc28d66b6f2d57c88cdf
SHA256: 9e3e350fee911f939af5a05de33793100f1b39453b94065ef3f0d34950f896e1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms.bvornily
binary
MD5: 22821b55c77f4fe92000e2d7ec4a25f6
SHA256: 944aada36b9f01033ba664d877b1971cf21a3d47f9ec059031d6164c4eda61fa
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms.bvornily
binary
MD5: df3b3a092a85da2398b6388ec373fc6b
SHA256: c72e0a3429d1c14429a919ad609a2fcbdbd2ac05e07761d824dad5e470c581ed
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms.bvornily
binary
MD5: 978bc3187e508900c4c8707689b1cfac
SHA256: bf7e6a819983eefdd9331a7df00d46e733a5931a2b1e1be3d52537bfe1ead2cc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms.bvornily
binary
MD5: 21e5dea7557a20f26ff1dc6d17b09cdb
SHA256: 5819c82068d85a507edf2b192c1241057ea01c8872df2ca3b7ffd162e23163ac
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\History\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Credentials\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\Local\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\AppData\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.bvornily
binary
MD5: 901f3081ab03f7d7c4a49e8a6cd8fd55
SHA256: 84c7bbabec30f6c6e5c5fc16a96bbd105e753ef8180d84a4249dc46e75b190c5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Administrator\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.bvornily
binary
MD5: 11b576c0e6ae3caa6271c26e6d07a737
SHA256: 986b7329be985620e7c850e608aaf5e68989c83f2c1ea6cdb644f08c69dc4410
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Searches\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Saved Games\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\throughsettings.jpg.bvornily
binary
MD5: ac6c3682aeaa408697ec0882eea0c973
SHA256: c4e6298b9b11ecd54257ba207fae9f5dc4754d27c42d94d37be52f1f5111809f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\settingreally.jpg.bvornily
binary
MD5: 8806cb214819e400ffed089d7495ce0f
SHA256: 1d5640b020635f3619f134aebfabb44fd9cbf487006f1c96668d5e3b2d398222
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\settingreally.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\throughsettings.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\lifeplaces.jpg.bvornily
binary
MD5: f1cbb3dc3309a72990250f08b6de9387
SHA256: f11839cf9fa1912f90f03a0c772c724a573aaac446fa1c7b38210e2eaa9b69c6
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\secretarybeginning.png.bvornily
binary
MD5: 0e2c4753ebb1e8d4825dfcdec000abd2
SHA256: 4712ed4036785d50d23de6995c1c80f27f2c3b34f58f7ce4fde77862919879dd
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\ntuser.ini.bvornily
binary
MD5: 23238bdb59cc676ec875c0102cdfa180
SHA256: 94aa6ef1516388de90b9afc7fa9b0f71c8a6434a470c6e356d4e0170396c7bb4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\secretarybeginning.png
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\lifeplaces.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.bvornily
binary
MD5: 8c9f712903154a4b2f4fa39746bb1c46
SHA256: f4b67d1072b5369bab5e701330ad3d313fceb28dc6654e38fce933f28d5388d2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Links\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.bvornily
binary
MD5: 25a68f88b53bf9e592e7454865d6e31f
SHA256: 58cca12f79545e045a99a9a6bad38fe7f2c806fba72cd7a705e9928f80b92370
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.bvornily
binary
MD5: 3112cbb2e52c1a6b863d80315d80a053
SHA256: c0495200d379aa5c8543d1b86540ff411307363ab1710e914bb1a3e6a0d81069
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.bvornily
binary
MD5: 030dca99e22d4dca524153bb72ed02ca
SHA256: d70af6b48d76b1bb53d81b261acfdc52a521b5ec46dc4e75112429e447c785df
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Windows Live\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.bvornily
binary
MD5: f77d26c693ec10237a6b490af42c4102
SHA256: 9c04fd59db4d3ce652cacefc45b04884d63b0d1e10999cb0825579b1e35aac0f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.bvornily
binary
MD5: 6f086ae7e3b0504e8b0efaaba239d098
SHA256: 5e6aafe8f5ad44083aea108e2e474c6b1b7bcee9fd68604aa582f98f16c63604
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.bvornily
binary
MD5: c86847f055ec3fe0f4279ff8073ee8bd
SHA256: 5a31a49d4620e54ddecf61b2c690c396c4064228ec5fe09fb98d7c0f351826fa
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.bvornily
binary
MD5: 382d753c8fb6dbe8a0203836bcc44bda
SHA256: 4b6659d7ed2f467f21a38cc6354b2ba4284786248f154320d6dad951e98e6542
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.bvornily
binary
MD5: fffc1fe9d5ab0294f907697378a9b997
SHA256: 1a9a375340ee83b8d43768a8354f51e1bb996aff223d94d7f45b83c1effd59c7
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.bvornily
binary
MD5: 94c749dafd57fa7a84090697fc764a0c
SHA256: 8d1ca8b2feb8671933936995840399fde801178f0fd43222b9ac94e42976d50d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.bvornily
binary
MD5: 8242c54d8acd460c7bfdfb929ab9240d
SHA256: 7f342b0d719f7386327829446e42ccbbee53b7444697929926352d71411abccc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.bvornily
binary
MD5: be9628923dde7c5e091dbeb1a56c875b
SHA256: 97c2a7c43b68a6601dcc034511a763bea02257f16360aad10513b57a5f98064a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.bvornily
binary
MD5: 0f224172253ad9dec1a2d7ab2c0612b6
SHA256: 990a90d4325d8f910b25d97f6ec987fca6f86daff8bd2bfcc168b3ac207b7825
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.bvornily
binary
MD5: 3c0ac4f7e98c6299b33166a176576df9
SHA256: f4a9d64dc3333bb40c38f7ac41192c88144995644ba3774572eea86a4b9ac0a4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.bvornily
binary
MD5: 67c4eaf455790a0e1105cf682fc6bfb1
SHA256: 416c789fe974f576bcff7b26c960d09bdd9a85b7e031637df318a68941ef8482
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.bvornily
binary
MD5: d35f74c309d893b8fdeb121815f34b7a
SHA256: cf2e9592279bbcfe7fc1067f70264fe020dab19e7f84657c930e7d2fb1d1c0ea
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.bvornily
binary
MD5: 662ef382f817ab627fa8ae53ce03d8af
SHA256: 15c2653f3956e0e43dfd1318e1ec1d17958e0ba54a07c977196b5ecc39080bfe
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links for United States\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.bvornily
binary
MD5: 86c8428ff574300d7d12c6f8856350c9
SHA256: bf42e50990fbf00a31c04714dedc97f34d485ca9503e153c5f6614c769e07ad5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.bvornily
binary
MD5: 24afd4602cdf404aa828c80885abfc47
SHA256: 083e2c24c6c63eda45ccfbe96b19c6b5eb700ebbe07ae5fa17cc680b7ec74ffc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\Links\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Favorites\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\whitewindow.jpg.bvornily
binary
MD5: 48e4b232f2f9891d4475ce47a88c253d
SHA256: 3658c527731b0203d9a6d6e44e6c4c29bee2750b37c463109635c58338c76d3e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\whitewindow.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\travelmichael.jpg.bvornily
binary
MD5: 0fa509cd7cb2b8f4ad7f9526497636df
SHA256: dfcc08614b76e670fdffcc3bc2509b8beeea4652eb3b12010d48cecea5d2b7ed
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\weresuch.jpg.bvornily
binary
MD5: 92a6bf5d56f56c69ff792899699b5d3e
SHA256: 15ef355af12b50dc14fa35330333e81f19f498d5f7da5763d92f3ea4f13ce2a2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\travelmichael.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\weresuch.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\sexartists.jpg.bvornily
binary
MD5: beb9e7a994b21655507bd4ae5c031cf0
SHA256: 19fff0fc98cf8643c794a3dfb6c6df5a8e00657d8de9365673a1d9a768b27a82
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\expectedcivil.jpg.bvornily
flc
MD5: 5978b27b278466cec988600df0be7b30
SHA256: 947003cbbb9cb9fa80b4887a52411e731adb3afbae9d8cdd3433676fd5db63c1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\sexartists.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\expectedcivil.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Downloads\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\tuenote.rtf.bvornily
binary
MD5: 82356c59bff2c411e13e922325a48d67
SHA256: 1173c73cecb91dfa2a2e004bf4596ead210b9f248e176b4afe2560a3749880e9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\tsell.rtf.bvornily
ini
MD5: 332058bb347ceacc777a9e188c90d780
SHA256: 8da291d53515a2b98518eff3c487d2afd0bb6a1474a0a2c02133bfe4919cea0d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\tuenote.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.bvornily
binary
MD5: 68e5187f8ac9553a36b597d1cd9d2424
SHA256: 13414041859c7c552bb844b648930c60082978773350fdb3552e3a4779fd9bb7
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.bvornily
binary
MD5: b40da0e27d6a113a9c08c994a0360555
SHA256: 9d8b5093356e542a40bc8862a48428d417f59a50812a3d90bcdb7f7d679d2c6e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\tsell.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.bvornily
binary
MD5: 3e2a6d5126eb0149c9e7fa76baef8fbc
SHA256: cf7559294e0cef2c986dc72575091bb0fc23bb1a4df84cf67453f6947ffc1d28
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.bvornily
binary
MD5: 0a170abd15b78636a508a8a18c0e7395
SHA256: 4b9e91c8d2db8b306b422bd264abf577e44bab902392071e9d60def86c60fe56
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: 61c38e6e4033947d096512f8639be6ba
SHA256: 76d25565206f773cad0bdabf8b4eaaa87dd41a92383792aa94e595d1f00bb0d9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.bvornily
binary
MD5: b048c7bfc360d9377d749147cc00bc0c
SHA256: 2d4dfd3dc0ab89249a2334b7fc14f5b953c41671546ac6de07bc6b54c43086f5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.bvornily
binary
MD5: 694afa766e65ceb79d0f382915f3ca20
SHA256: d6e0270146e6e1e2cc995b5fa348779654deb7637394ac6d509d8bc3c17f9209
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.bvornily
binary
MD5: c38389aef87677f643bde8021de53e63
SHA256: 13abd083e109a50d83c59ee8b37a33e68488a0dc8b88cebb0b2450d21d0f125e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Videos\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Pictures\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\OneNote Notebooks\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\modifiedbehind.rtf.bvornily
binary
MD5: e2576ed1b42da73d3a5e1c7885eb5fec
SHA256: dd130dfd78ce45e88369b29fab09b8a5469e95d65b37f05a9b623fb899ad974a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Music\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\matchz.rtf.bvornily
binary
MD5: 664f016d01f0df10f061778a00819bf4
SHA256: f718f17e55288b9a460f04598b0d8793fd5ef8446f6d52417009a7eacd2e7927
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\modifiedbehind.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\matchz.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\hereagree.rtf.bvornily
binary
MD5: 4a77051d7c7891db1373b25428630fa4
SHA256: 1cc1bd36b5686f87b5a8c60235b18634fe8dabe61673029c8ff65fef05c0be93
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\hostingvalue.rtf.bvornily
binary
MD5: 5b4b2adf70e74aa45e5848fbae3c88c2
SHA256: 4b09d79aa0b8c32da6c411ab324a297c55ad59656b52c5734f5c9ef8dfb63104
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\hostingvalue.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\hereagree.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Documents\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\teamtravel.jpg.bvornily
binary
MD5: 6c18d091c92c9f290ecd08f1bf244ba2
SHA256: 926d3e3438d4f4a3cd00f71afbd0241ef0af6c81c302488861724fd9e1029e55
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\storageun.rtf.bvornily
binary
MD5: 35aa9340d8ae1d0e1279d9f5e0d7d211
SHA256: ea8ac56426a39a8f9f81343088cfcd8dbbcdbfe05217ec117aa6b0a2ee3dcb77
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\teamtravel.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\storageun.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\softwaretalk.rtf.bvornily
binary
MD5: fe17f12a6b59d93316a55f53b70c8c2f
SHA256: ab0cef43eb429a43ff69f483d4fff06824074888a1002d19e79cdba1f4075a0f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\statuslocated.rtf.bvornily
binary
MD5: 633c43f743b07d7286e59e1d8c89ed6d
SHA256: 074d2bcd40a6664064e21787d2d29d00cf95a83ebe1dd31d83b8eda28990fd0e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\softwaretalk.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\statuslocated.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\shopspring.rtf.bvornily
binary
MD5: 9520d6fe0562934754b31514a4f9296a
SHA256: fade19f34087861a88c0d3aaf41e2a41e675f7f7db7e9b596d9328cabafa0a4d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\shopspring.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\removefeed.jpg.bvornily
binary
MD5: 1a50b8df6a0ccfccfe8a4a71bc6b882a
SHA256: 65a8bb89105ea96e54fb4d5f44d13a2eccb25415e97d78563700582153b36939
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\removefeed.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\portdifferent.jpg.bvornily
binary
MD5: f36da3589ceb92f90ad5b4a650224de5
SHA256: 7d6b2b44bba58279c5e13d7b1cb2dd62edf25195212a62d94e625e7c7333f41f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\ratesengine.rtf.bvornily
binary
MD5: c29d7578560093a0dd65a166f08e1e98
SHA256: 6009a6fa5e7ee83e04a03197ed450a0654c88dc422c2fa970dd554ed0b6cc8e7
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\portdifferent.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\ratesengine.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\othersas.jpg.bvornily
binary
MD5: 60d9c82f30c40f9f77de7ab7fec0d754
SHA256: 969fac13f5cb08e4cf432b48b8ba7b2c708bec83c94ec9cddf6530cb8c0d7480
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\othersas.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\hotsecurity.jpg.bvornily
binary
MD5: 769ed1d0c8c22e7b16479d4b63affabd
SHA256: 761093dce3e6ac8c84537b38748d6036597445e3e6ea1826d3506c1b0b1953d9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\lostcontract.rtf.bvornily
binary
MD5: 9e39c6c9cc69160f520397f3c182dcaa
SHA256: 44352e78b51d7a90fe3833f3eda40a67604d869e3ddff15fa747cf578839fca0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\lostcontract.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\hotsecurity.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\costfurther.rtf.bvornily
binary
MD5: 7b6e14ce5d1ca10e16abe076fa870451
SHA256: 608bb93853d88ef6564a04eac375e0b187d5fc6db2e7e522b853218beb9a6898
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\frenchfather.jpg.bvornily
binary
MD5: adf27041837fd181bc48edac86e9fde3
SHA256: adb3d1ae5493c9681e806f2a25592f75cee408e83e82097ebd9a4be84b3292ae
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\frenchfather.jpg
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\costfurther.rtf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Contacts\admin.contact.bvornily
binary
MD5: 3292fc2b3df9d189808c1d5cc0ec5b39
SHA256: 536d5de47fc61ac0b99d0476f05700ec8b12f151e9ff80908eb978cebd855977
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Desktop\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\Contacts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.bvornily
binary
MD5: 20ce0c1f12b8a94d8980a363c4d94e3f
SHA256: 7e89710508e57c79f57afc5da2e8c117c65a35c0f39010c3ec4ea2e82e8ed559
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Sun\Java\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.bvornily
binary
MD5: f06ddc632196694bc76b16ba2ee1a622
SHA256: fa78baae0818d143c9db62924c44ffb0d9f1e3d8d75101b05447dfd40e04337b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Sun\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\WinRAR\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.bvornily
binary
MD5: c2dd81bae99a15e0bf29db22a2091c9c
SHA256: b7cf38a1029562d963474a89479cde0fc1b543607d0cbf2376b119163b2f353b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.bvornily
binary
MD5: 46bff7f08032e90bea77f94ee4f45bdc
SHA256: c3fef861900d57b067e6eac94b5df46511425efd4cbc121713e503213eca5e6f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.bvornily
binary
MD5: ad851f9af42d5b64c97b03b04c78de35
SHA256: ad1203b9d77bc4eb3ee8f27ee2fdcb0325cc34654d6083efb2d5832524f526b4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.bvornily
binary
MD5: 1b9190a27d8f8e30624ab0b72e1e98f0
SHA256: 8f247a12ee152316855d53efe463cefa460b8b64642c25e9e9cecb64f6d3997e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.bvornily
binary
MD5: b7ad844addf060077bec90e6509ad50d
SHA256: c9afeb97b13599508f88cd164471a14cfd94064e2b14da2572231e33f2fdafad
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.bvornily
binary
MD5: 0efe4f30942b76417002216cd8fd3951
SHA256: 58d5aed0710e4bf747be92527e25e14ccc417e4914fadf7956a703cc7ba7697b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\logs\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.bvornily
binary
MD5: 76d2a6de79044174a3b630c83c6df1df
SHA256: 1abccd051cfe646671e1aced403806ce36487a73b0069fef4fcb8e1ac95d95aa
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.bvornily
binary
MD5: fe7d53b51b453f436dd4cd3847752606
SHA256: bb45211a248e85e0fb3262c84771dbbf8a15a1fe1ceebc6be9d269dfcda036c1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.bvornily
binary
MD5: b2eee25a7321acf2f5da864b0ebecbd7
SHA256: 030e2ad63f3157d5ce2c1db9cb3fbcea0561a724273fb4d453faab4ed0fd51df
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.bvornily
binary
MD5: 19e5db36ca947d172e4b8170bd33c4b3
SHA256: 4d374554a74c99a666b251429e5b06f175ffcbc817fa022024ca68b5c629a672
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.bvornily
binary
MD5: 2132491c63746060ef4cb92cf6fde339
SHA256: 2ce413991af8dc80bba15ecac671e8a66683d71d61117ffd4f818ca88590dd77
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.bvornily
binary
MD5: 39340cdf7139f5be91db55d771a8ee69
SHA256: 97e62323af1ca4f5e12ac9ddb5f9500e6f30c4e4b23eb02ab78ac6b21d446b4e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.bvornily
binary
MD5: 155f85bfa2c80456f214ada63f388997
SHA256: 45fe03357dfe7bc551cee986b97496d9026b7ea14b22a5303e07c8243ec6762a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.bvornily
binary
MD5: 9dc32e0f563a4d38f2da5330501db32a
SHA256: 78a94c59a438a7e91f48c106e60210a4cdb50f3fac8a3159752a36118d5dfe4b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.bvornily
binary
MD5: 59318abf86b2a3fbad8b27b5c2a0b402
SHA256: 97437c45360b5e74f4fb30965682020e4a34b915e34b9143813981222e1ac7ea
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.bvornily
binary
MD5: 18fffc448b236addbbc14edd9399ddd4
SHA256: 759a74403bc6deb715fe5817da72758012ce2f6efe3af8a50f3aba94a5c89c64
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.bvornily
binary
MD5: 9ef0b7f78abc494825d0c12b04c1ed48
SHA256: 701d1641bc69b4fb184ea8dac7f1ad54f0b8a55e9e4e3b60be2eda10e6907628
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.bvornily
binary
MD5: 0a122784dc8dc4122e77b703f0a7a081
SHA256: d4dcc325f21b4df82a8b666816d9f218905bcfd3764345ce16c02d52fabd5e56
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.bvornily
binary
MD5: fd7daa042b23dc2438f25196535bd47f
SHA256: 3de6080a3306d2ae8b10b02623327ffd3c3da83b83f5865f7432002417f272d5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.bvornily
binary
MD5: d8608d7b61efe3c578b1c253f0d52b95
SHA256: 7774455e70af611b0f38a65f771991b5ae0068f51c43fdd51d36f44e33d6247e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.bvornily
binary
MD5: 37dc7928dfd6ad01064ce12b15b8f023
SHA256: 9dd36b1c79eba20b1156dba1779c9918fe3763f0ca744814baabe94f20900565
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.bvornily
binary
MD5: 5788baa435a7e322c3d9eafd73024121
SHA256: d7ac02a2ae14869ad96f5c2346de35c63fcc3b29446dbe9311a251ffdd9fdafa
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.bvornily
binary
MD5: 0ee003decec4d27b2a16cce1c2e63328
SHA256: 29ae5b0db352cc7d6625e9a04419e4045341ddef003204bb4f5c0c00bdaddb3e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.bvornily
binary
MD5: a945b984bb50f0bf277b8afea728da39
SHA256: 55b46688fe8860134f617d183f093aad1ed6af17a0348c89929e019446a0a556
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.bvornily
binary
MD5: 49c1e71a7d960cf656c65a425c5d730f
SHA256: 5dccb55a0a89d1a4ee94ff060d515574d4bfb60d5d1f59bfb22b35f29fd8ff7c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.bvornily
binary
MD5: 0e9a58b3c4e29420d35ab1463a61f205
SHA256: 481a71b187bee9110abf84c9afd3ec7225edc2439ef02a5228aaa5774ef8a174
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.bvornily
binary
MD5: 56136fb6e2c7eaa2de00a8fcf0d76c11
SHA256: 60ca08c0df6808576bf9a10c57ddea0235c42dd5ddd7e27b8f62a990ec212269
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.bvornily
binary
MD5: 8a07f843cfe254e3297f5056eda3e56a
SHA256: 95a3354aba22c35941c3a8445d616942cd8a5b677470c53813d63052803cc747
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.bvornily
binary
MD5: 5e53d507b18b2811cba557f768103769
SHA256: 67ca2b48ba1a7e6bddc41138591efa8c80228e61eae3123d757b0a6f18b1f488
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.bvornily
binary
MD5: 0b1d4576d3b6d6b837ea57f2ebe6d799
SHA256: 2170270130a73b3ded107ddd030cee2b5c33e053c9919e51b66d8612bd19b7b2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.bvornily
binary
MD5: 133a62b8e0343feffdd636e0920c2a7e
SHA256: 792da6d0b0574d7ad72e03a38fc2c2ba620cfbaa5d9400b606a54eea1f972ed5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.bvornily
binary
MD5: a4194e085b96a3502e0f147701c36c0a
SHA256: e7509ead92a6739c1de3d034794097ef16ec6c1c9a246c0daab82d33da8f91b0
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.bvornily
binary
MD5: 734e9c462b352064978f00aa7b040da3
SHA256: 45c94d581f5b5994612517e8a865ef69379298ece22926ba314f8781a0882e28
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.bvornily
binary
MD5: a037fc66da958a82d7076a10857cd4e2
SHA256: 65f7043fc8f83c0b84887339ab8edcdcecc925136ab78b06f1fe8b6aad686cf5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.bvornily
binary
MD5: 48d1d1a196278939c3a10d4153112ae4
SHA256: 6bd31778e4797216919ea1d1e7ad82ac92f0035f4f8552f1d1c42e985676fe63
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.bvornily
binary
MD5: 38ea15f00ffd35061c9bba372d15021e
SHA256: 2096f64b4e84f19dee463591df13e5beca254a7b54518cdd1c069a5260e9c876
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.bvornily
binary
MD5: bc334ec0ffe4bf6b68f140c488f2a5f3
SHA256: 9a937ca7961a1c7a95f4f729ca846fdb55dbd3f258f38fdf846bfc9151b76b81
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.bvornily
binary
MD5: afa6fc4eec2bfe9ea615941fd1a7058b
SHA256: f140b1b4578b41fc796031e30189de30f3f5ac4a64d496b4e331f74b0312c3a4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.bvornily
binary
MD5: 1610b194dbeab926c019dfdef61ed679
SHA256: 409693f2ae5580dc6a7c4a1597e71d4a197b2a5afd854ff4945b5a7e18a3ed51
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.bvornily
binary
MD5: d4f5a6940f558cb0d43583687a9dcaa6
SHA256: 2faf7950c8d040092088a344531d2d5c4e53f48e7d54bf3724df31c876900d07
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.bvornily
binary
MD5: 9d73af3f847559849a6196add98c07b4
SHA256: ce91c7283eebbeff509e44997c8aa877eb92db6e1f9a239bb314ac309ac7f94b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Opera\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.bvornily
binary
MD5: 643ed688fdae9f0535547da560777ef7
SHA256: bcd6abdc2b5e6f42f3a77d5d7041c2ac1377196797fafa47eb3cf0287a963400
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.bvornily
pgc
MD5: 03354f4e62549b8bce8e3987ee5b3fa7
SHA256: f33395573c11328d9b2a35d5643f50ffecd54ad8856ad57cd603d6a2b346f5a4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.bvornily
binary
MD5: 5406675ea04eda5080dfaa7e3f824868
SHA256: baee9ade3a5b133d5a098fd61c41e20f33f4444f0f8c950d1641a1eb1f6ee2c5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.bvornily
binary
MD5: bf36432ac8c068eaf8547dc8571fd0ab
SHA256: ec2a6dc6dbc185ff98a363aa33eaa00a0d149c8a6cfa56326b06264cb5c5ca65
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.bvornily
binary
MD5: 4bce44b727ac142e9c095af6cf250c28
SHA256: e424ef7e3fbba94108f00069859803b74d5feac7435df293a164c4d8a676d9ba
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.bvornily
binary
MD5: 4b16b2cf4f32705fb466320242dd414e
SHA256: 74a6e4e9b407ed042e61aa8aad43c65b36b8231f28b3856cd4cdfae8a1265786
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.bvornily
binary
MD5: e76519265875dcc05d341e12d1c3e966
SHA256: 73c8f18a390bf951680dd6718ed8a68cbbd9d8d9a7a4f5f0f2d7a6321525c5cb
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.bvornily
binary
MD5: ad731e122ab2eac475c2bcdf369ae010
SHA256: d4d84b127eec5fcf6065d1cd68edb1b6f30068923fbbdb6eb5df451060e9d72b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.bvornily
binary
MD5: b12efb3293cb16a38f25bf90e13c2f7f
SHA256: 5e7c2eb61537d553641288db7f9c62da58581d24bf7d93d6c20554fdee61baae
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.bvornily
binary
MD5: 185215cbb1c7cc8d08e38a8d6af99935
SHA256: c70b50b15bdcd0035c5bbf5a9b13c5e7ce5d021b6b63fd7a8492d38eef9efe67
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.bvornily
binary
MD5: 91ceaa77ad313ed3f1b09c25ea39a320
SHA256: 6a5797dca49856c65ccf125fa6a045ec854d8fcd485923224d83fb45c251beeb
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.bvornily
binary
MD5: c60690f94377cc36bbe473e5fefb25e3
SHA256: 809dc356a5759e3b32ac318ed06f5ca5cf5596e6cab3d2cd661cf187d5865427
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.bvornily
binary
MD5: 5ef40c87404b30570461520e008f1aa0
SHA256: cd4f5ccecdc95adb5281296f96b5df975b28a4d39c26c72307afd5c8413c8647
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.bvornily
binary
MD5: 17bb7ffc86a2d191b0f37ec0c284b1cc
SHA256: 01745e8ba1b29271bada0c80dcf5021bd9f6394dc4a9deaffc668c02adebdf13
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.bvornily
binary
MD5: 32be6878486406b2d81465c1238a4cf2
SHA256: 37bf3d293cdfa00c84004da999f6930f616f002a1ffbdd57cd3a2657a8b9f097
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.bvornily
binary
MD5: e507d72b117d7cd960b7bae816108e3a
SHA256: 7c4d1eb9a228653f3f33793e6fc2d99b29c2bab3341a5428da149d36322aebb1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.bvornily
binary
MD5: df51a87bc8643b25121c63bc2a161d89
SHA256: e38ca7e3a69149115c33f1060ce17312d3c9a529d12fbd18d094a3a0489502e4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.bvornily
binary
MD5: 7ef321ef97550534e6996e00ba32ef95
SHA256: 8a08bd0ab1c7ff2050219f563365da0d6335f022880a7a6affb87594f3effe57
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.bvornily
binary
MD5: 74c4e7e524ca84d87ecc7802f047e990
SHA256: 3e2234e1507d9bfa84fdb7c8cf87ff39f3c8c484354758ca3720cd0a2bb7bbb4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.bvornily
binary
MD5: 49811700f67c684c0aa4d4dc3359e225
SHA256: efc05af007818a374dc8abf0cdbe13df2c637324a789c8ec6f8d72d95b7e5cde
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.bvornily
binary
MD5: 357ad47c20b7fc49995c8ef458ae8b92
SHA256: a702dfede1c796bbcb8e8d98e34c2090dfb23a460b72ac4ec6aecbb1f434e62b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.bvornily
binary
MD5: 9a48e72aedbf379853b9a3cac13398cb
SHA256: 483419f73e6fb54449447f4adb671d63fdfd307653b9834e6b27f25fb4b51ac2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Notepad++\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.bvornily
binary
MD5: 445c39a61d4d056f69f874337dd89c61
SHA256: 86b918969f6376322695ab7b975c0bc97fe9db7546a4d68fd95afd3f4b9a3757
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.bvornily
binary
MD5: 01ae75848a02d28df1127f712e34a22a
SHA256: 3dad2de77441917059c56b13fb9d17768b18ffe21ff76d393c3d162b220c38ca
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.bvornily
binary
MD5: 0ebed6f33baba6db49d240557949b5fc
SHA256: 0742a54bc6412f2b552330d0765270783dcbb22c913698553b8c92bac04640ce
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.bvornily
binary
MD5: 021df10a0e50a5f9218d848848b396eb
SHA256: 86b60c2d8d726466e0d224e18ce9bf1ea7bcdc04b6bb75451a26e803fe9dfee4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.bvornily
binary
MD5: 2c39c735b129cc6d7ee7325af5726a51
SHA256: 8d7ee9cfd31829299470e3dc74fbb186ea958221dbdc517f3d242014f884ddc3
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.bvornily
binary
MD5: fd57014e5743f3d3994d1c70f052387a
SHA256: 1530296e1898bcef4760e87ec96d500db7d06ade17845f0551463ecf490c0877
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.bvornily
binary
MD5: 3ac5b0735869c5d9322e368f365fed58
SHA256: 3bb6f4bc713dc64d0a1e62e386061877af14af2c2593caa175557888e0198377
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.bvornily
binary
MD5: 1f2a9952a38c7feea782b6e15073cbf0
SHA256: 2d2357dbacbfbd058e7f81da230d17c0dd2121683d54e06b8eaab9b2e6785630
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.bvornily
binary
MD5: af9d6073677e7fbc5aa20d8fec6dd499
SHA256: 705fb26adbb29786fce203da2293b347da8d04dd5aa6bdd9bcce661d0131cdb9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.bvornily
binary
MD5: f7760b2616daade87a94861a8f944121
SHA256: 0c5344eda23e9e89fdc71f951772fdbff42829fa6a19114518cf23bb72905347
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.bvornily
binary
MD5: 4714efee7d8f77d8681369dd41b2cab4
SHA256: 80f387ce6b2b963eae1f0695b0c4535147c63de450f88a5d7a920f9859cb7341
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.bvornily
binary
MD5: 3a72c68d6b66171feac54127fa015e4b
SHA256: a4c5013c610e3d59f75a2bf27c801ec9c07fbe4a755f225220005caec9878a2a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.bvornily
binary
MD5: 2850768d135b481156fd5666f65f2a1b
SHA256: ede84e0af2337a9aa53ccad928f3b19a6f06aca54a98735868ae38aa5076aa1a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\journals\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\2.bvornily
binary
MD5: 4b36ffb041d0fad1018259589b702a7b
SHA256: 468aa57db9ff03800cbcfc5f91f05ac0afce2b337e43678a91a6ffd4d0570a88
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\2
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.bvornily
binary
MD5: d71d69ff00daaea34dc39e9817b6806f
SHA256: d2584d5bb1625171c805deb1e18392dd3523e8859a5c4cee7c879eac0d16b767
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.bvornily
binary
MD5: 073c27a7172a369b25b486896f2300e9
SHA256: 34c4eb6fc33829c14bbe521dfd518a0a63af57d16837da6b171fd7b60bea91b5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.bvornily
binary
MD5: 524026da3f87494bcb45ebd212e97f23
SHA256: 4a6937804c7619668d6f2931ce42360c5660f76178d0711eaed78bf8df35716a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.bvornily
binary
MD5: 5265b1f424ddf4dd15fff188437ca3c0
SHA256: 1d42ccf26e44bfc0d74edb7c29da5b0061c339a33780bd157722f33e3c1833a3
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.bvornily
bs
MD5: 8ddaa5556faecb60a8f0e132bbcad769
SHA256: 09b2a60b5b0efedb331e56b33f926541a81bbe995e9107e02de3acfa5c0420a9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.bvornily
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.bvornily
binary
MD5: a729cf05df5a966b06a021d23e562777
SHA256: 716061200187afeee263de9b19cbfb1badd5ecd849530b975610a2beca83a838
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.bvornily
binary
MD5: d772b0669c52e465aac18eed2c7ed79e
SHA256: 04b7dba5cefd04eca6abb33ba3bf2c882558cc7fa531bf570c8d798080dc57f9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.bvornily
binary
MD5: f8c7869475a21e0f75d776e18dd1069e
SHA256: 1deb1c058690da1f47e2dc6e512b291b84e082c2fbe3b71d604b7a4e247a5830
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\2.bvornily
binary
MD5: 0675cf1ff690043f8e233b01cc212ced
SHA256: fc206d45de07739b26d2a0d74a8aa6c4f5a1cafc68b59f3260b6d7c54a91bdc2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\2
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.bvornily
binary
MD5: 71d5a7f693bdc7f1ad3dbebe224615a1
SHA256: bcba8782fd4791fabdc9ef35ee296eea0af40900355a8f223b04bc8d3b11d6cf
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.bvornily
binary
MD5: 6803318004791e9369062337c50ffbc9
SHA256: 2640dd82a6c932a1a04d9d1c9b76dcf217b7d7d8202e2f193c8e3ba2ba73e584
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.bvornily
binary
MD5: 074237656cc8c6599359a58fcf2e0e7f
SHA256: 56ec6baadc5f22c0beb8680d61df909208d8bb03690bf366fac82302f741aa40
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.bvornily
binary
MD5: 2754151e94a5dab505ed5a6370040ec7
SHA256: 2c77b12427c6e12c39a2408b09027bfd9cf3a1802664db4841137ff4d1abdc16
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.bvornily
binary
MD5: 866ebf0e69d74c2cd68841d96c8b2316
SHA256: 671f3094625ac479d80b64d103f2e8b244ff34beaf03f9b974c2b37cf72bf70e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.bvornily
binary
MD5: 60d56b10b469b8aaf1647a5889cc2ee4
SHA256: 859b8aa4be8766f90fdf66ce06893a35d66f511557a30ac7067e816f5d5e7d24
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.bvornily
binary
MD5: c2f668426f7263d3af9444892ff1e154
SHA256: b7f56d4d0dffb45491abdb67a24deb883db1ddadd0c419cf994141e8f000117c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\7e9b65a8-bbc0-4c5d-8cc3-e71a22fd8f53.bvornily
binary
MD5: 808669c30a10b6e3b316f4ebdf3fa5f5
SHA256: 0d89c457f08d18320b322e0954e6b5df9be0842ba86ac799cb7e81da2aa50c1b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\7e9b65a8-bbc0-4c5d-8cc3-e71a22fd8f53
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\6c8d38fa-8188-40ce-822e-2249c9316ad9.bvornily
binary
MD5: 5585e129b2cb71f67f99b509d8eb0ae2
SHA256: 734713926ad3a0f33d47b4fa159d5fc5e386cf5b68caffbdd1593a7bf2e71c38
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\6c8d38fa-8188-40ce-822e-2249c9316ad9
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\4802db1c-08fa-4dd6-86ed-b549a554341f.bvornily
binary
MD5: 051a5a6b915ed5addf36f118b0fbf835
SHA256: 33c15af7eebb42dc7f70c5d18a0596b437ec01ae78a999885490c4a3ab51ea40
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\4802db1c-08fa-4dd6-86ed-b549a554341f
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.bvornily
binary
MD5: 097bae3f885a0c488daa6ecf0b0678a2
SHA256: aa6fbc4af6c5422bc96621442579ea80ace72c02f91168276e464bdf5bacd7e1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.bvornily
binary
MD5: 8958c32dde953b6ff36aaeca4e622ca6
SHA256: a57a908bcf694a80867b2de5bc622871ba4875ad1104d8ae1a630d9560489d5e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.bvornily
binary
MD5: e2a06a725ddb9d50de06d1d4223612ef
SHA256: 71a8d4f8f03fe7cadea9980d449cce132dab7f0db2cf313cbfa297c6eed52229
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.bvornily
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.bvornily
binary
MD5: 746b4e8c4bd533c3342e0ea7eac9d84a
SHA256: 5191888b8b28bf5cb010abe7b1678887eee375955660ea0b8721a9cb8d093be7
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.bvornily
binary
MD5: 3becfa7f5f03eb7316876dda2843b46d
SHA256: ba095c5e1626c7348bac9f86163efe842ab92baccb7a22dc1c00a06f17cbd301
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.bvornily
binary
MD5: e1de3bb8cd9906bcdf5ca5a571b5b34b
SHA256: 7adb6f276df1842217dabd17fb391e7c3a9d49df70dd52ceceb36a46148b91f2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.bvornily
binary
MD5: e667d9cc1543513581364dddce6bb89e
SHA256: e2580f6dfdd78adc938c2efc2fc4d09c081bae80c3b745ba2d50f75c3b0eb564
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.bvornily
binary
MD5: 10603c4baa38cd6d07d73a25c3acb990
SHA256: 4c7f2fa6e8a9e3c8b60ab1214fd9947b3b0fcd42975940e8548e34d6e07d133a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.bvornily
binary
MD5: 937852919cf406927e02ceb3a2bb52d6
SHA256: dc52fa35fd149492347b3228bf26ee7aa1f344706b7561c1ba157011b0bcf022
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.bvornily
binary
MD5: 0dc8efaa382d88b6b29eea4dbb07db4a
SHA256: ca3d13f89ba5102e63e52ca9fd07fa9d4f166f15252cb15538088b64b4d08673
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.bvornily
binary
MD5: 94c1910e3f6f010b6dd8ab116b49868f
SHA256: 590c78b38ba4a31d38cd43bc83171f0612b722019a31a487d83096dbfe5d19d1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.bvornily
binary
MD5: d1ee8eb6a310c9c889602acb9eacc5d1
SHA256: 9324ddc74a32d022ea61070c57e14bdf6fb3fdeb518378c84391d5b508e106da
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.bvornily
binary
MD5: c80a20f237ef72d5771510ab54c9493c
SHA256: cd25846b9a43ec4bd508cd17d6a183c1657c9bab8b9b674ab10d4c40aed1383c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.bvornily
binary
MD5: ed7f96114da5510bda76530677b6928b
SHA256: 26fa0ab4910aa35107e1f9d283e4f9a79321d48fd49c28528252db991f848b30
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.bvornily
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.bvornily
binary
MD5: a9a515dc472788461ef5ef2b3023f146
SHA256: da9f247a221ebadcfcfeb6453671a63fb41240ab608f130c267f932bce28124d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.bvornily
binary
MD5: 2303c25449c590aa106c03a561a0de28
SHA256: 9a1297b54255fb931bbd29d9162e9c8f06fea1f51f3e197f354cc5f2dadd9bf9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.bvornily
binary
MD5: ec118ffaf28ee3c4aa4eaeee3eb252f2
SHA256: cf3e84cd8f9eed068e194a4a830e7b63bdcb08f34ceee05ac70ebf2400640ab6
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553367040859.0194ec90-9aa2-412d-a21d-de074d2bda44.main.jsonlz4.bvornily
binary
MD5: 0b5146750d900797475b3d8bb8736b6d
SHA256: 575c63b4c1b55aa1c17122b44e139fc496897271e7795c57f377f90f03a44e3d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553367040859.0194ec90-9aa2-412d-a21d-de074d2bda44.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553367040843.64e19fd2-09c5-457f-b7da-c6beab032106.health.jsonlz4.bvornily
binary
MD5: 5eb1bd298d3a612e10cc05a518588965
SHA256: c232b2ed83409776798ce40f8afa8adb249c1cb88ac7a6c473392bb46a52de61
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553367040843.64e19fd2-09c5-457f-b7da-c6beab032106.health.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553367040812.7e9b65a8-bbc0-4c5d-8cc3-e71a22fd8f53.health.jsonlz4.bvornily
binary
MD5: 6335ae7f99804a276aab5cbe51c9eae3
SHA256: abc94adb5346580fe6add523b0ab1151f8043ac0f0a7eb20c2865e934aef4901
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553367040812.7e9b65a8-bbc0-4c5d-8cc3-e71a22fd8f53.health.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646937.9c1d5aa7-8417-4152-b187-6829a20b449c.main.jsonlz4.bvornily
binary
MD5: 4d34d9673e6f19d42c1b87227d9b9621
SHA256: 66b6e1d8842b4ad3b0734a01628604455a9e90b11d0bccd6637ea533e217a3e8
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646937.9c1d5aa7-8417-4152-b187-6829a20b449c.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646916.428022fd-1128-47e0-9128-82697384584b.health.jsonlz4.bvornily
binary
MD5: 14f63f6c43e5269d58eb45f34ec4bfda
SHA256: 46e34e31bbb4e7d16475de23d3b4531de62501648965c97c8f96323a24f28ca5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646916.428022fd-1128-47e0-9128-82697384584b.health.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646892.6c8d38fa-8188-40ce-822e-2249c9316ad9.health.jsonlz4.bvornily
binary
MD5: 43af632e0b3f5dd769eb969cb91d66bf
SHA256: 409ff72a00a10f971b78a067bfd7b8f6d81247d5e25fbe0942d4084bf6984bed
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000646892.6c8d38fa-8188-40ce-822e-2249c9316ad9.health.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000637968.4802db1c-08fa-4dd6-86ed-b549a554341f.update.jsonlz4.bvornily
binary
MD5: b81ded0753041f303c7fb8f6a3e93b01
SHA256: e4bf1e722d49713ed327682b96513834cf7e4aa3ddff3fd8ea2db8ee9a6b2cf9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000637968.4802db1c-08fa-4dd6-86ed-b549a554341f.update.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000620729.94b06a80-a39c-46bf-90b5-264680171d04.main.jsonlz4.bvornily
binary
MD5: ecdddade0df22c90fadc26b1b577b224
SHA256: 9449ac106e9b34392258cdb3f3868b4adde712093b57179cbfb54eb2571bf2c7
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\1553000620729.94b06a80-a39c-46bf-90b5-264680171d04.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-03\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.bvornily
binary
MD5: 68ddd22f674f179f060c05546ccedc29
SHA256: ce1fbd095839da41422180abbb93c0a0713ecc32578dc5e950fed72ee744b91a
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.bvornily
binary
MD5: 316abca205899472bd4a8a9cdbed0a0b
SHA256: e2ecdb2a7a693c1fe2b5695d2dfc97900e2f4323a770d9553140831252556aa8
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.bvornily
binary
MD5: 330585d7ca01ab0187ccc6781a186d8a
SHA256: 35417d4562ed12b5d499f268c02ea80308c521e42fa2f37f6b813fd5dacde051
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.bvornily
binary
MD5: 1f69806399eb9ae34ae7a450e8018832
SHA256: f7646fce599617ee03687651594317c721567ac3dfe4656d7b893210a1bf52e1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.bvornily
mp3
MD5: 145a51df0bedbac3241daafcc3e01148
SHA256: 07c77b955be0d7802bb783b380fe478ae33abf164bc9bf5adf9d3dd5b1d478bb
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.bvornily
binary
MD5: c6a8866d591cc25cbd29bac448e59a32
SHA256: 395fa83a32e0c5bd89a9f8c57ae964fb8f0edbcd8ba228667525932bbbe556c2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.bvornily
binary
MD5: 3fdda34eae78cc58ca2fb370d3b06545
SHA256: 8df47bf545059d94141f56afecbaa20b982af32cce551cf6bcc7a840ffa661bd
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.bvornily
binary
MD5: 78bc2ad643ea5080e25929a442721ad6
SHA256: 0f4b2fa11b117d54466bc7fea1054ab51828bde5a1d1f1b9397fe707491853ab
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.bvornily
binary
MD5: 4fc1b01065c472c725176698b9fe3524
SHA256: 21b6af7b328cf1be26d7f379ab8e2d2b622ce5b886dd9c504618246116db3c70
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.bvornily
binary
MD5: 6209ceb9db95e230ee3b112932d66d3b
SHA256: 4cde52f5e27ee7135b3de9f996f03a1816c00ff62c2f1383bcc46b49d742ad86
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190225143501.bvornily
binary
MD5: bf6f8405980d3ede33837281717b2e62
SHA256: c1c753493343a21b5b7d4957e3995085d51bdc6c673a6604965c445c1ba3f002
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190225143501
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.bvornily
binary
MD5: 8045db667a352107f8f39683049059aa
SHA256: e86acaf5890869f933ab2f6c6f075791ed33bc41f0192d13e422d6c9443e3c5f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Mozilla\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.bvornily
pgc
MD5: a3c0aaf2a57ed0d016c93d0f8df794f4
SHA256: e7e2bfc5404410597a1c71222c491b0c5529164720e1f99a2d92106afed6f220
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.bvornily
binary
MD5: 291fb1e34b2cb87ac57886407f4902fe
SHA256: 9d40e9102c3fce02e629de02234fa2e426f32df7ce3c0856397fdc71c4631f9f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.bvornily
fli
MD5: 577ebbd5ed74167eb181da92986e0e95
SHA256: 809366348bdfe70e0b2a270d1744830ddfca308115cf7158c85037f6b0dda0e8
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.bvornily
binary
MD5: da16330b2a9db07ff687e99dcd9e10e2
SHA256: deb4e1e2382dbb9291bfa33bdd7a034790082150a8aea3ac9a1fc3b955ba78cc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.bvornily
binary
MD5: 8b2f20e15dd3347a75c388478a3e083d
SHA256: 450eecaa508b29e9c50077d7e44c052db027a88caa3050119966427e0cb8d366
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.bvornily
binary
MD5: c7b61daad85323b3446b2ff702a31a57
SHA256: a19f20bccc11ca1ef0a685c83d16d21b104bc62ebfc6cf67227c12884389bd65
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.bvornily
binary
MD5: fa67afdf2f992a9c7b90e41a01c6c661
SHA256: 478315a5e083de71de2a8720fa4a394d3a94d4273c4a1c9c2c18c302eddfe0e5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.bvornily
binary
MD5: 529222d2ff6d54310757bf098455d926
SHA256: ce7ca777fc9077856c3d3154fbb7d4e777c59deecef74041c678ff13b38fcfed
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.bvornily
binary
MD5: 73a1064bd249ecad0eb8bc46fb6f82c0
SHA256: ea3666a3304a0da84abafb15e598d2e69539cfae7785cd39ca3eb1da9ac75f4d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.bvornily
fli
MD5: ae9e3bdef6a7c10f487d2df70626589b
SHA256: 06637830b20129cc131f42f8cdedafbbf9ef147a294bb18089db098d2415a4f7
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.bvornily
binary
MD5: b12ba454a883b36099227ea476a6078b
SHA256: 34e924200a54d7ca33f45214c311c1712e65d7aff00a286be46c4434cf558a13
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.bvornily
binary
MD5: c6b162d11c7e772f894fafacaa19209c
SHA256: 15328612fe6e4c07bfca930e08daf3fd66d1056d469f0f95100f1497837bdb01
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.bvornily
binary
MD5: c5e07df925245f9c5c2208438ca42a4a
SHA256: 1733b76268786cc97fc51351daa613d7d2dcebfe846673ae1bfdd7d38e071d71
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.bvornily
binary
MD5: fe83680eae01b3b7583ff6a8a33eab19
SHA256: 3da9a7b0ad7c349b0b6c94ac0fb375c3b670cac24c899bf8cd5051d9061cf53e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.bvornily
binary
MD5: 6283e6018af78672d8f94bacab52b0b0
SHA256: d9cbb7c08f55c272663dc3fc1bc3197c791bc6e95686fde9e9fefded51512643
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.bvornily
binary
MD5: a4802730278d90d37daf5310a8c88a1e
SHA256: c0c3b672b022f82930c710da18437ce56d360dd5e57782cdaf007372321c2343
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.bvornily
binary
MD5: 7639064ac2b7ad3e25b72302fff520cd
SHA256: 65f7f25d87504ff4c26415e467dc776e93b048ed06c99d59dc630e24ea9cb128
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bvornily
binary
MD5: fbf10eed1aed67ebe5d5170b8964885e
SHA256: cca4b384adb8f52c5928fb957d68992f50891774970d7cdaed13e0d4684fe281
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.bvornily
binary
MD5: 9e7e035300e135df7de59cf1a2511cc5
SHA256: 9e29bf09d1f164e4e1dbefc22b83522feb2bddcd87c09e79f8d77ffaf11d603c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.bvornily
binary
MD5: 4481eaaff1d89a449f261f8d6a3ff797
SHA256: 542a5f2d4900cced80533694753628d8b79b917027e635a3069cc1485adef707
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.bvornily
binary
MD5: 33a8a867e22d37ed12b490c1d45a2743
SHA256: 504bd44f0c00a7295a21b292f0a2d53ab26822b90d1d757018c8fb3458206d30
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.bvornily
binary
MD5: b38258cd3241d1b74b8e4f04a3376c2c
SHA256: 2e09663cbb673d2c423046f26fbdcd723ac50570573bee43c6228ba1255e38ce
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.bvornily
binary
MD5: 144834fddbd175902ab5e45a82bb162e
SHA256: c1ff701c6d6f842d8f6056c5fd50bcded90f906e6a4465aa9ed45185116239bf
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.bvornily
binary
MD5: d87b2109ca63a61a937a2870e161dfd3
SHA256: 425ad76706826bdbc0e04bdaf0730182273371f11920f6ab1869db69633185c5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.bvornily
binary
MD5: 71327dc2685f895a870bb1edbbfca77d
SHA256: 30ac654ed08b6324b4dfa9ae9f053dc03800e84fb2233285363b6f11f5802982
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.bvornily
binary
MD5: 3466891a3dcd2bbb2374e6ebab9d03cd
SHA256: 807c6a3201ab5b2ec54a55a3b8c4dc38b02f3660d23f76f1ca78df46f16b67c9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.bvornily
binary
MD5: 04fcf110566518da0f98d7c4da094a71
SHA256: 60869bd541b02fca0103d09663ad45f51c363307709a5f68af30bc2d403c31ab
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.bvornily
binary
MD5: 90b9d810b101c0566d414ca01c10e366
SHA256: 719e30a1c4102c461f5dd4eb2244bf7f848ff8893b345450d056ba016e6e82a2
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.bvornily
binary
MD5: 40051edb78c7e9662894cdc7f8cd56f7
SHA256: 2db78e5c6e7688e99b09d41e2601d32f0e745553155789d839c6b3244bce2af5
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.bvornily
binary
MD5: 5583fe3259b8248ba40c979da79d3fe3
SHA256: 0e2e525890413a313d473e0aebfc79912268c71f65c7b0e694f4fbaec99e6f9d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.bvornily
binary
MD5: dcf6860f3a6b1f62814d04dc6501c3dd
SHA256: 44d216c11be38eb3112dbac75c9bef5cd98276cef33e14b7881c4894c8d17a78
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.bvornily
fli
MD5: cc659f0148ac348570e5abd01b85e7af
SHA256: d6ade09c31aa26f86a0d26434147329951f759d8b3726d86bac61dcd52bbb00b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.bvornily
binary
MD5: b261e8141474fc6661ab9058a53b9e85
SHA256: 67b09306081d4249ca23b1d8473b9936d1ef912df46cfa848ecb70b0121cd83c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.bvornily
binary
MD5: 7be3e34bc3f7d7e070c4a31a2319b03e
SHA256: b0ce6ce1a1544dc2b2298b25d9ec64c2426e62cd069df7b75a59207901183d46
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.bvornily
binary
MD5: 322960339f9e37b97561a0cc2df8c1bd
SHA256: a49fb4ca5c9a34996ca1142d7941cb26bee688af0ae0ed174ae17952f8ad4dfe
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.bvornily
binary
MD5: c0f6db7bc66a2236759e0e7ecd1893b4
SHA256: eb27db3a50f7af4553772628de51b3c6b051cfc9c11b207470c2758b4b0022ef
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.bvornily
binary
MD5: 4462b0071fd5ca66ef79b4671652e1ac
SHA256: 16f9eb0ff237486de3c65fe55a0ecf8e792c6943d3165d4c9642602a357a3ccf
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.bvornily
binary
MD5: 1038f179a8d2196b1dbf92e5e92ab8f1
SHA256: 36fbe82bc01a2d9a44036e1fe4a30fa208994bf14ee125f8e3dca03ac32bb32c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.bvornily
binary
MD5: 68f63dce03f29d28a10adf4e5b273630
SHA256: 2c2c5d0d7d23f297a1613d99d1de40bd70e30ef6afd51013529ac921dbf7596b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.bvornily
binary
MD5: 0e9a08fc1dec4bcf7164c9b3b343489c
SHA256: 32a487dd540ab9dc09897229c95c68d406ecb0fb97268d33dac33380154a2f0c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.bvornily
binary
MD5: 0c628bf5b062ea8173408dba57ec781e
SHA256: 6d5c3ea9846bf2fe9fac1b3285d390c31d8db193f7e504aa2a1175b9cebd481c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.bvornily
binary
MD5: 3dfd4eceaf86700c7f0f4a28a1b4d00e
SHA256: 9e2c62ce77c69da8620f86a3993c95a391f5769a623e71fc5a620e09f4a3f35d
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.bvornily
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.bvornily
binary
MD5: ca34171b53698a748e576beda6e33bf2
SHA256: 6165dc38168f53387f5490e4dac713e036ebe295224cbb479f2ae67120c468bc
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.bvornily
binary
MD5: 454184b8628ae75c3eeef4f33649652a
SHA256: 59d3085735cbff6d41aa57d50b98b63d532daaa00cbf6c1f7f1e9a55acce5469
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.bvornily
binary
MD5: 5a44b883fd55515ccce818ebb5291424
SHA256: 8884aeaa87fd5c937736996720441006cd627b3da9bc04499480fd089bfbd03e
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.bvornily
binary
MD5: 9d6f54192f965badbe9869e40b844fc8
SHA256: 6e8ae46d0e4001bcd4c2c6e31b884153d6edcda4185b12b317a364c35d81b1e9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.bvornily
binary
MD5: c07be6a027dd727854e5f5c0a8ef23a4
SHA256: 6e5fc34f96a94476810da0312e99eee36372f740828a6d4a95e624691b2b21bb
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\fc958741-2c2f-465a-852a-5ea30b2a11d1.bvornily
binary
MD5: 3ae59645ff25f870763fb2c281a0c980
SHA256: dd1ff2887db2a5cb1a12947660d7b60ad3dfedf6aea55878fe1c8e147465969c
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.bvornily
binary
MD5: a2c352f38209cfe1ab3342409e78de94
SHA256: f6185c0d51f75b51c26e643e4249160cf705a6b9968a54087f7f61f250c36c63
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.bvornily
binary
MD5: 1350dd25d36c97e7c00c356235bee4c2
SHA256: 87e41e9b706d5566141c89c41c5b4fe1c5604c726d8836adda588a13f68a0208
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\fc958741-2c2f-465a-852a-5ea30b2a11d1
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.bvornily
binary
MD5: 681cc4aad93d9628df330d90709cfbb5
SHA256: aa7e614de35acbef19a51a753609c63ac20dcd343f071f2a49cf709e9b500c89
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.bvornily
binary
MD5: 10c80023312a0ebd8edd96d788d85a8e
SHA256: dfafea9ce8b1ce7be3cb51e889fac2cebaf35e60bef8308b42155673f405752b
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.bvornily
binary
MD5: b99c4aedd8961a1426d691a3a2ca803c
SHA256: 7df06d4a33cd7276e4cef125e7db180cbef067bca6af931021966ce969d39c46
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.bvornily
binary
MD5: 5f05c317c35ce9258f26225a0cf94b12
SHA256: 2f78ff1af09a60359c6501a31a9c4a47470cd5ab5e1d1ed696d005e452c934a3
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.bvornily
binary
MD5: baca145140fed4ec46435d11f4e5b5d2
SHA256: 7e8d6ee6ef5446dc3d5a0029ac268e561b1bd759d62a0f1734523becdadf8be6
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.bvornily
binary
MD5: da34fb23ca78bbc262ed4d7a3a6a6cad
SHA256: 79fb17a55b8ce00bccaf07dac6c2e43a6358522c41ddf6ee5256d130faea399f
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.bvornily
binary
MD5: 55a7f687fdcd98e9aabb37a26ca8b153
SHA256: a8ecac1ec29a66caabcf0df8f4d0914c49078465df4b3e6c05dea0ffe0413628
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.bvornily
binary
MD5: 8002862d6a345fdab66ed6bb9f4981e7
SHA256: 50de9f983fa376cd82a8d390d4af9c3d203ba706add7926bb6d83bc4efdbde26
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.bvornily
binary
MD5: 54e9a54aa8f94b063e0ca8f1d8918644
SHA256: d54db469c035305a0f6082d6a853d834a601e67266508404cf10836907e8ffaa
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.bvornily
binary
MD5: f0a8604c7e1da4b77238328c079e7960
SHA256: b1532e7ee03a2ffa1c3c680a6cca3dd98cf641f0e8dd3708d96a6ccd2da6d028
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.bvornily
binary
MD5: 14495088be3043ddc2947abf7b1acd6a
SHA256: 38d9161be4e49e34be3943baf1ea8922353d27fb9a215cd370f686e4f46bb334
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.bvornily
binary
MD5: 55d0ab0d2b929005ec9ee248937ac03c
SHA256: 14ee7dfb043ffa78629bca4f8807a718f6adf72ffffce0862d7eb58d1db8ba31
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.bvornily
binary
MD5: e69b53a2de95da13ded8b98dd529e219
SHA256: 726b560219d8a10a6d2045d08bf73ade19fb4c2d869a89bd26c5e425592062b7
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.bvornily
binary
MD5: 797fd761dd5ca34c1156dcda4d801535
SHA256: d8ddc5445cfc0858be477b41d491879327ce11eb026d568b602c912033c280c1
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.bvornily
binary
MD5: d816ce712047ee96764d863dc4c63ff3
SHA256: db15a19e40204b42d2861916c31a59147be95f2590cbc34dbe742d11616d8ff9
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.bvornily
binary
MD5: 93c385d33ed4c51e63af92d0b62146ff
SHA256: afbc04a3e072bb2b76b3ccac0d63001e1dadeb6cff20922627320c1a9b2d64de
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.bvornily
binary
MD5: 7225847caa991985ea074e6a90e2aa84
SHA256: ff48d070ec805f5c773421c102e88b1e13a530cb75af5ad6b391a220ce8b5c61
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.bvornily
binary
MD5: 993a7cef39f096b542ae0ace602e90a2
SHA256: b8733c184cbcc7d3536548152431ccc4d81260ce7b84076c1a6386b3364ae8b3
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Identities\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.bvornily
binary
MD5: 42a7498be0811983c50e47280d257949
SHA256: f5f4d94912a978f0afb9d5996a5cf461434c045d3a72f5c49725daaa20dbeffa
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.bvornily
binary
MD5: 705e94cf2146f8cc8d4df38a6b5a9437
SHA256: 22961f5d5b5eb68b08da91db888efd5bb77fd784c4b350d281a82bfce1ad1b11
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\FileZilla\BVORNILY-MANUAL.txt
text
MD5: 7790f192f3073f3fa085084871a56b20
SHA256: 24241c852a301d3db5826736e77c8d1b4b130efd876503a783be0930205fb471
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.bvornily
binary
MD5: 392e232446ab5a31fae7e6abab1a237f
SHA256: 37ece4349dd93a0fbdbe76d803ea0464800ab9b71808d1a17dba1fcfa22261c4
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
3116
f2abc66901177e87cc0c01372385a04901a178e4.exe