General Info

File name

1 - 복사본.doc

Full analysis
https://app.any.run/tasks/cd2f6eaf-fd58-4fb8-a39a-612c8fdfae76
Verdict
Malicious activity
Analysis date
3/14/2019, 10:00:53
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
loader
ransomware
gandcrab
trojan
Indicators:

MIME:
application/msword
File info:
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Administrator, Template: Normal, Last Saved By: Administrator, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Mar 6 21:40:00 2019, Last Saved Time/Date: Wed Mar 6 21:40:00 2019, Number of Pages: 1, Number of Words: 0, Number of Characters: 0, Security: 0
MD5

07140b0e7305542ebf450f53f0517a39

SHA1

0d1b3610ab9ae61aac8d315efe9445ac7ac4a37d

SHA256

c275677ddabd7809d060040c2bec631879e311094676a854e54ecb59df294cf4

SSDEEP

384:wq8iS8px8SMD4vHU4oYga8sosBti0qCpkZrZbN0joWmjytgq:L3yqVnga8sJmCpIf7Wm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes settings of System certificates
  • file.exe (PID: 2480)
Deletes shadow copies
  • file.exe (PID: 2480)
Connects to CnC server
  • file.exe (PID: 2480)
Renames files like Ransomware
  • file.exe (PID: 2480)
Executable content was dropped or overwritten
  • WINWORD.EXE (PID: 2824)
Application was dropped or rewritten from another process
  • file.exe (PID: 2480)
Requests a remote executable file from MS Office
  • WINWORD.EXE (PID: 2824)
Downloads executable files from IP
  • WINWORD.EXE (PID: 2824)
Actions looks like stealing of personal data
  • file.exe (PID: 2480)
Writes file to Word startup folder
  • file.exe (PID: 2480)
Unusual execution from Microsoft Office
  • WINWORD.EXE (PID: 2824)
Dropped file may contain instructions of ransomware
  • file.exe (PID: 2480)
GANDCRAB detected
  • file.exe (PID: 2480)
Adds / modifies Windows certificates
  • file.exe (PID: 2480)
Creates files in the program directory
  • file.exe (PID: 2480)
Unusual connect from Microsoft Office
  • WINWORD.EXE (PID: 2824)
Reads the cookies of Mozilla Firefox
  • file.exe (PID: 2480)
Creates files in the user directory
  • file.exe (PID: 2480)
Creates files in the user directory
  • WINWORD.EXE (PID: 2824)
Reads Microsoft Office registry keys
  • WINWORD.EXE (PID: 2824)
Dropped object may contain TOR URL's
  • file.exe (PID: 2480)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.doc
|   Microsoft Word document (54.2%)
.doc
|   Microsoft Word document (old ver.) (32.2%)
EXIF
FlashPix
Title:
null
Subject:
null
Author:
Administrator
Keywords:
null
Comments:
null
Template:
Normal
LastModifiedBy:
Administrator
RevisionNumber:
1
Software:
Microsoft Office Word
TotalEditTime:
null
CreateDate:
2019:03:06 21:40:00
ModifyDate:
2019:03:06 21:40:00
Pages:
1
Words:
null
Characters:
null
Security:
None
CodePage:
Windows Cyrillic
Company:
null
Lines:
null
Paragraphs:
null
CharCountWithSpaces:
null
AppVersion:
16
ScaleCrop:
No
LinksUpToDate:
No
SharedDoc:
No
HyperlinksChanged:
No
TitleOfParts:
null
HeadingPairs
null
null
CompObjUserTypeLen:
32
CompObjUserType:
Microsoft Word 97-2003 Document

Screenshots

Processes

Total processes
37
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

+
download and start start winword.exe #GANDCRAB file.exe wmic.exe vssvc.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2824
CMD
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\1 - 복사본.doc"
Path
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Word
Version
14.0.6024.1000
Modules
Image
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\microsoft office\office14\wwlib.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\program files\microsoft office\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\program files\microsoft office\office14\oart.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\program files\microsoft office\office14\1033\wwintl.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwmapi.dll
c:\program files\common files\microsoft shared\office14\msptls.dll
c:\windows\system32\uxtheme.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shell32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\progra~1\common~1\micros~1\vba\vba7\vbe7.dll
c:\program files\microsoft office\office14\gkword.dll
c:\program files\common files\microsoft shared\office14\usp10.dll
c:\windows\system32\mlang.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sxs.dll
c:\progra~1\common~1\micros~1\vba\vba7\1033\vbe7intl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\users\public\file.exe

PID
2480
CMD
C:\Users\Public\file.exe
Path
C:\Users\Public\file.exe
Indicators
Parent process
WINWORD.EXE
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\public\file.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

PID
2300
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
Parent process
file.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
3288
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll

Registry activity

Total events
661
Read events
606
Write events
55
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
?i%
3F692500080B0000010000000000000000000000
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
2824
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
WORDFiles
1315831829
2824
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1315831948
2824
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1315831949
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
080B0000F037EF7544DAD40100000000
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
9j%
396A2500080B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
3k%
336B2500080B000006000000010000007600000002000000660000000400000063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C006C006F00630061006C005C00740065006D0070005C00310020002D00200007116911A8110911611107116911AB112E0064006F006300000000000000
2824
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
VBAFiles
1315831812
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
{CE5E57A2-842F-4DEF-8A8C-01E9C56F0E1D}
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
25
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Max Display
25
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\1AE225
1AE225
04000000080B00003200000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C00310020002D00200007116911A8110911611107116911AB112E0064006F00630010000000310020002D00200007116911A8110911611107116911AB112E0064006F0063000000000001000000000000002E4CE37544DAD40125E21A0025E21A0000000000DB040000000000000000000000000000000000000000000000000000FFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2824
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2480
file.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2480
file.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
EnableFileTracing
0
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
EnableConsoleTracing
0
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
FileTracingMask
4294901760
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
ConsoleTracingMask
4294901760
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
MaxFileSize
1048576
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
FileDirectory
%windir%\tracing
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
EnableFileTracing
0
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
EnableConsoleTracing
0
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
FileTracingMask
4294901760
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
ConsoleTracingMask
4294901760
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
MaxFileSize
1048576
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
FileDirectory
%windir%\tracing
2480
file.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2480
file.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000003000000090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
2480
file.exe
write
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
DefaultConnectionSettings
4600000002000000090000000000000000000000000000000400000000000000503B188044DAD401000000000000000000000000020000001700000000000000FE80000000000000A179B3FF019923140B0000002C4A28002C4A280000000000000000000400000000000000504A280004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0300000000000000020000000100000002000000C0A864940000000000000000DADADADA0000000000000000050000000000000000000000B4881B00000000000000000000000000C84A2800C84A28000000000000000000FFFFFFFF00000000000000000000000000000000EC4A2800EC4A280000000000F84A2800F84A280000000000000000000000000000000000
2480
file.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
WpadLastNetwork
2480
file.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2480
file.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
Blob
040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510

Files activity

Executable files
1
Suspicious files
430
Text files
320
Unknown types
15

Dropped files

PID
Process
Filename
Type
2824
WINWORD.EXE
C:\Users\Public\file.exe
executable
MD5: dd2e2f61e48c2d436882f2f3c92d1c43
SHA256: 1b19faaf7439f97bb0a16fb03334656bb7de11b43cc04427fddcc997b88fe09e
2824
WINWORD.EXE
C:\Users\admin\AppData\Local\Temp\CVRDDBF.tmp.cvr
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Videos\Sample Videos\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.cigioed
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Recorded TV\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.cigioed
binary
MD5: 60617db83f73cda29b51aa8db180b112
SHA256: 9b41157da4938b313b00163141468db357ab1ccbfb01ee62bd4ac17518ea570c
2480
file.exe
C:\Users\Public\Recorded TV\Sample Media\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.cigioed
binary
MD5: 23f1e7c2ef92f184bf2584876c6ad673
SHA256: cf995ae0ed48d724cce759d925408d567f3e4c83e51d721ab3dd63817cc72dae
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.cigioed
binary
MD5: 0c1bd7f7e6d5e904c9f2739689cf425c
SHA256: 8a847eeeb6724f1ce8d6288dc8e6c836b552ee3dc07394c1d15a882fa1b70f12
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.cigioed
binary
MD5: 3893631672f44e95b601471e5f2ccc6a
SHA256: 366dbc86f7ad3129af1a26b440cad2746a33d9d27480f469ba26956a89d3864e
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.cigioed
binary
MD5: cc329d718b2eb6d7de640d44099ec214
SHA256: 80b85825a7faaa5fe2eb4fd21dc8b20c5de35fdd85ba72d1b4a693b585f30a9c
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.cigioed
binary
MD5: 59f31644d522b7e3f52ad753729329fa
SHA256: b13c5c811c1bc1edaa5366026301ff90b4b036f202588c517b088c839e0c8a30
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.cigioed
binary
MD5: 13e9592a13e8815594e36f6938bbec56
SHA256: 2a0013b14f23f08b1afad25266e69ff89b04272196d05804fae47dcb786d2f94
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.cigioed
binary
MD5: edb7534ab74d04bba84100dc53cea3af
SHA256: 1324475441e45c0e2cb824e48679a0b7f5fc3baa60429681f418becfbee96801
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Pictures\Sample Pictures\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.cigioed
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.cigioed
binary
MD5: 8564a48d26ed39c69abe60cda59ad635
SHA256: ac75d7588c7b492295ab6c536aed792b527f72fa7663e24717722a84e7cca4af
2480
file.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.cigioed
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Favorites\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.cigioed
binary
MD5: c701fbe7c87042aae635535994d41572
SHA256: 9d7f36d562ecf41343b5ef7f9772b935c57bd8b100f39bb58141bbe40e450721
2480
file.exe
C:\Users\Public\Libraries\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Music\Sample Music\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Downloads\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Public\Videos\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Desktop\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Pictures\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Music\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Public\Documents\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.cigioed
binary
MD5: 7ba4b9b7862c0e7b501659c2a3bab886
SHA256: a42ee2384ac17bdb417bfa7030e92e088259cd3db875c03200b4d6c11f3a9605
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\Saved Games\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.cigioed
binary
MD5: 399fd5e3f31e2ef3e6c1edb05faeeb48
SHA256: e6be09ca26438d7f812554d74729a2ce0307ea93e3f0c957884dcf32b6f5a6f2
2480
file.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.cigioed
binary
MD5: 6fae647e49f0033f2cd4b7d76d97b60e
SHA256: dbf402b743c278f799abad90b5a22730f358a5ad329e42d26c1ce746b6f57fea
2480
file.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Default\NTUSER.DAT.LOG1.cigioed
binary
MD5: 21e6f0527f0c5ec27707090ea4e2125e
SHA256: 90229eb298f83550da0c77dc569457b2a6cdc2b1ca3c85a96db5f9c614f03f58
2480
file.exe
C:\Users\Default\NTUSER.DAT.LOG1
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Default\Music\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\Pictures\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\Documents\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\Favorites\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\Links\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\Downloads\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\Videos\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Media Center Programs\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\Desktop\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\Microsoft\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Local\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Local\Microsoft\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Roaming\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Local\Temp\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\History\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Saved Games\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\ntuser.ini.cigioed
binary
MD5: 220195fdf9cafc494498d3207d423bd4
SHA256: 9b8c2b5b4c71ea95321c12a31f023d783f4f8bb692d2583931d402126350234f
2480
file.exe
C:\Users\Default\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Searches\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\ntuser.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.cigioed
binary
MD5: c5697a2e1e2c406a912f82123f42c856
SHA256: b1c4971836ee207b9ac8b88df34ff5e5845cee0c23804f41b8f6506b81099731
2480
file.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.cigioed
binary
MD5: 3809fd0aefa4725b941b062496a8a923
SHA256: c83bd585e778808189e84812a8891e3a2c610fce7d1c1af37ba40032bd3c0c43
2480
file.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.cigioed
binary
MD5: 42329d5b5d0065b10fee6bf09cc8d4bc
SHA256: 09c98880888ccde6920056c1ecb704c97f4fc141b0a1819b088877350d1bb3b2
2480
file.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\ntuser.dat.LOG1.cigioed
binary
MD5: 4db3a49c6a0a36875f791fd276132cf9
SHA256: 0918b071f97b67df5c38166cef343cdd93e2b054cf36b71053c49cfcf249557a
2480
file.exe
C:\Users\Administrator\ntuser.dat.LOG1
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url.cigioed
binary
MD5: c1c1fe5a430ad1863d2901a3fa989938
SHA256: 4bbdfb0f81bc337a85c1d82f5ffa08c0944db28a33f959683efde015a41b0ab8
2480
file.exe
C:\Users\Administrator\Links\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url.cigioed
binary
MD5: be9db921e2d28f7a221eb87e6acab50e
SHA256: 3f31a05c7825043358435bc88ec24cb7437ac401de7e9efc87b9a5a6ff71c4da
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url.cigioed
binary
MD5: b31c83769063885e740672e6cda90b6a
SHA256: 9a9477046ee18fd6c3a19ba23139abbb1e5c4aeea9a6c19689393c2f7f45f9ec
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url.cigioed
binary
MD5: 11affd49389d0035b3942c71d940574e
SHA256: 74beb0cdac4b24ce796855da62655e4d2980b385090cdc792a11e4d507a20054
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Windows Live\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url.cigioed
binary
MD5: 813ab30ed153c2f3e5b82fea283a9208
SHA256: 6d7560379727ab15c244e3b291ecb9b9faab075a5ced9bf92f95ede42e34d322
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url.cigioed
binary
MD5: 54e3fa43301b1714b2e78029b06c3a84
SHA256: fc2d70685d6910c659ad72d0de4a3a8071e274a554ba3942249ff380fc74f04e
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url.cigioed
binary
MD5: cc72c753993857cbecdb0968082e8592
SHA256: 484be31fc1557eb76c214fcaaa683508b70b1bf9a4d31b13d208a3aec6f25cf7
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url.cigioed
binary
MD5: d4e2f59b4c9f5cce0453b1299b597418
SHA256: 96b52334c9d1e5ed46fda63b9c6a67f74c1d2fab988abf55349e845e2717c008
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url.cigioed
binary
MD5: 4bcfca95ac7ebe3613c3f08830bb4aa7
SHA256: b4aabfd12b15a2bfda0449a114cdf5bb0a25db62072f5cda521b1ddaa0240ddb
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url.cigioed
binary
MD5: 5e23c65b072be68c74f9568a1650888c
SHA256: 29c350dcf54771d313490653d1a2a91df8c9ef831835619902ccbd842eecdb26
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\MSN Websites\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url.cigioed
binary
MD5: 15ca18c9f10e90b7d0d67d9f119ec44d
SHA256: dc700d3b1cf2793ae21f166e8be4994975cec4b7a58e6a60177f98cf28d710c6
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url.cigioed
binary
MD5: 4d7d5c0f543c1e58abe5578933c92b7d
SHA256: a0f5f7de1c14b731c368934f438fd9af524992b96a761edd491a559dc3c0defb
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url.cigioed
binary
MD5: 21c07defa705999cc2e8d6d72813e629
SHA256: b8551bb1d1e38d5c2322b50397d8e6b3b833b05ffca30f7d63c91b0c3c3b10a7
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url.cigioed
binary
MD5: d940657349d64859affdb5c983c3ef63
SHA256: 66014fad1e1c5eeb1c05b2ab473d951091b27cfc21eaf6469a6e24e2319b4cda
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url.cigioed
binary
MD5: 58e1ee22ad6f70467efeb4dc01766a0d
SHA256: 0ca39ac998ad8a7d5bb2f6ae80fe94b5d6e830cf7a011fa197499c83cea9b66a
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Microsoft Websites\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url.cigioed
binary
MD5: 9a81640af6751f5da1f2ead30c6d8939
SHA256: de6926f2ee4c17cdc7f5b5db0f7701c4b2198ee048891f50334647b0508642b8
2480
file.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url.cigioed
binary
MD5: b8f1075ff3156daae2755f5eeed7646e
SHA256: c7e3edfda12b3ea8c7ebf75a51b5018ba86ac8f8fb9215c2e2740dbb1c7dc180
2480
file.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url.cigioed
binary
MD5: baee01ae78f4fb6442a549fa9606e125
SHA256: 379df91e23ee95f2f385ae8aa9a51aa69b54f8a5439da8beff03567c1416272a
2480
file.exe
C:\Users\Administrator\Favorites\Links for United States\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Favorites\Links\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Desktop\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Pictures\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Music\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Videos\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Favorites\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Documents\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Downloads\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Contacts\Administrator.contact.cigioed
binary
MD5: e03a0252c6563b54a2a8dd385bf37bbe
SHA256: 28913b9dae992f115eee38ed66ba9a4ab8719842bf40461f789bdf71c6c0d08e
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\Contacts\Administrator.contact
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\Contacts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred.cigioed
binary
MD5: 2a31cc87d2a88d02aae3042f6a0da14b
SHA256: 22cf64c642a54c7556ae9099baa35480ba63f8adfd63ca8ffe51198c0def9f31
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156.cigioed
binary
MD5: 64054ceaa08359f45476eb69f690f012
SHA256: c0c12090aba3370ed24439d8617286003ca856c69d22337de05ecc74944d10c9
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST.cigioed
binary
MD5: 10c487c8bf4d8fddbe5de8619c52900a
SHA256: 0681121dfb1c8bd4587dac7f69b5adc35b7fd52b907a96794c29d811959377c5
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Identities\{BA2162A3-2F32-4850-8D8C-B3C9A2AA9D43}\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Media Center Programs\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Roaming\Identities\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Temp\WPDNSE\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log.cigioed
binary
MD5: 2b8b5cc3f52e2d002ce4f7c2590d35ba
SHA256: f6c7de7f98d435d78612fbf64d17868ec23057c63aaa373488e0ae49233ef9c3
2480
file.exe
C:\Users\Administrator\AppData\LocalLow\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp.cigioed
binary
MD5: bfc0d49369b19f0460479d830f759f95
SHA256: 9d0180d1ee704a8ad0c15d2a1cd89a9e93bab2a71a31f2f81d72fc8eb715f807
2480
file.exe
C:\Users\Administrator\AppData\Local\Temp\Low\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Temp\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini.cigioed
binary
MD5: 22465b07a255aa04e5477178616c8fca
SHA256: e37b5a5cd56346a4df18732e52b3859ccbd0e1ff455a72cbae72a49beca21b73
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Gadgets\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML.cigioed
binary
MD5: 6a1aa4a8d89a06ffe6bb988dc91f893a
SHA256: a64cf0f0d72cdf88484079e7e39657c9c31a2cafd7709ae0c60dcdec20862f83
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD.cigioed
binary
MD5: 50333504f9cb954a683807d24c1603e8
SHA256: dcddc919786b2cccca103db18502073726987aaca5838bcb43a323c62f44285b
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat.cigioed
binary
MD5: 9270d6240d660286197b00276f1f4beb
SHA256: 33e35088aa8fb30519fb4235a8ff99bdc48b72e959286ccc011592191326902f
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore.cigioed
binary
MD5: 346ce1357516029cd9ae229b2a5bf1e2
SHA256: b596aeb246d1862a7e5878c66b512884bb3b858a88e847d07879fb8473ae0553
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif.cigioed
binary
MD5: c29ed9f12690afa22417381b5f34067d
SHA256: 3ecda1bf32e07c9474b051e4c4e08aabc572e5c57a2214f278590a740097e371
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg.cigioed
binary
MD5: ed9d2bc1fbdec4ee25ff2f456ec077a6
SHA256: 368dd5c21498903c54870eeb046dd18727cf38d1bad576a44ba17c2ebad2c3d1
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf.cigioed
binary
MD5: 696f0c2d49f5979bf5b28d5b6621cdb8
SHA256: 7365b54fa4446071b9433767c2a216562d9445c8f81ee608f5da2858a7b59f3d
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif.cigioed
binary
MD5: 73bde917486f2b759264ee7364639dff
SHA256: fd2560cfa68176dd4b845007d029ec2741cfb8e83b5d2c8cf1afbf46a8a1704c
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg.cigioed
binary
MD5: 772196902fc956c37f2b31143ef7580c
SHA256: d4ebf142be9dbff672eabdc3c4d4c3e12c36c5dc4105190bf822c2e9837ec615
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif.cigioed
binary
MD5: 9c7cb728009b473ab99d0c97add29f20
SHA256: 595ef1a3a7dc02886096411a4774090e5bda7427d6d4c85992cf4659b536f27c
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.cigioed
binary
MD5: a740c2c9b327a6229b80b33b6a593879
SHA256: 7128cb66aeee7f2e2faf3384c4c81e1b836507f7858451145fc5dd114f790c10
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm.cigioed
binary
MD5: ead8680b70dc9b6ca63a13adef870f6f
SHA256: cf097796df5af7539603ffbcafbd323b12c9d9e3360ff0d3e89b9181f3729883
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.cigioed
binary
MD5: e9754bbf19ea00b1d682d30567145f96
SHA256: 95bcd3366045d972d901537cd2691eec45c78d6ada84e5cfed2c684e533989ea
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm.cigioed
binary
MD5: a637735c9993f851bfdcbaec6a73b01d
SHA256: d30fa592a7168a829f3982ea9021bbe91c4b3ef11de1f9e7befd1c959ddc8458
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg.cigioed
binary
MD5: b2d9384cc8eb8b4bb8427b5761f77645
SHA256: cf594fa3fa85774278cb84b1e0fe57427761eed046f115614ecdfc261b407e15
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf.cigioed
binary
MD5: bf7db4802f1d8b0acb0c97f45310a2b3
SHA256: eeed7c1239a1791285d02d07b6ce25759fe7933bcc2d1c900fda920f56915b4e
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.cigioed
binary
MD5: 1acb185208dc25e4b5ee05bad87f3bb0
SHA256: a54317f846958da79558fa40ddc663993ddc126623fd6aafc48cf8deeba9b6c4
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm.cigioed
binary
MD5: 880431037f7dbccf1b462b5c24796a25
SHA256: 68a8ab6378a5d84fdea29c31c4e37b6d8eedd3d1c2744dbf26cc9036cad071ce
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf.cigioed
binary
MD5: dff38e5d126499e36311c51931cf4a6d
SHA256: f17280bf89c4d60d8a164c069bebd151f170cf1d1ed009d5521b794712ce6798
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg.cigioed
binary
MD5: 15a96998ac087bd1dc0788be3f5248b5
SHA256: 15ffd32c4df6a41c4fa39371c97d6797bf1c621948e911d11ea189f7932c27be
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.cigioed
binary
MD5: 8160fd9b6f88ef29621c1cc730833bb0
SHA256: f21d45a55f36eaa4c7a7156741a5c98e03dc760e7f5659cb64e10f7f07c11784
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm.cigioed
binary
MD5: f94e28c410391372746a10814cdcdf2f
SHA256: ca84e6426c1e57cdf4a558971573fd20c9d76168b6dfb4df25896b8fb5093407
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg.cigioed
binary
MD5: c2584c32bbe20ced4dec3d8ce2022f16
SHA256: bbfd0e9fa243d608839b89baeefe46a53c3792e377f1c3bcb4572d8941121bce
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg.cigioed
binary
MD5: 070f7b180e198ba9b0e66578642f067e
SHA256: db13e5272686865eb63dfb7d53b31da7636b827d8dde2639871e17983ffc8812
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg.cigioed
binary
MD5: ff4b2543cd76f958e41575db789a0cac
SHA256: 7220230b1d2391b1b017b069087e0daedab35ef1898f8b8ea4f2b7a4f87df0e9
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.cigioed
binary
MD5: f5466015fea0b48384023e491a3adf6f
SHA256: 3c65de8476f4fba4e2eda959bb352e84da36cb65d7683106acbb00aa7d779f90
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm.cigioed
binary
MD5: ecfd82965a97363922c5ea6493b44660
SHA256: 7c6555262b0652499c3e835f8e290615b84abf1ddf540e79f89bb085d71e70c6
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.cigioed
binary
MD5: 855875106559c4f1a83ae1bed6b4fff0
SHA256: 227475eec38eb9e3ae999f45ea0ed43c73d6813cc3f2f34814e3f5ebed22d652
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm.cigioed
binary
MD5: 45d0937c3e726e04fb48a8f9ac4af75e
SHA256: 5d09bc4ca3dca025f5c21faf53a985dbb4784f0eecacaf369689a80663c3784e
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg.cigioed
binary
MD5: 5093f7eddcc9201f35c4bdce5dfd8982
SHA256: 6017e62d482c949d04c0261b8ca337742c8056b4a6ab7e8dba6f7faf7efe0ba9
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf.cigioed
binary
MD5: d3d0bbab98faf307e1757a7dc9914fce
SHA256: ea4a07f4a01497845de516c54fca6fe1c2c06d82832d0fa61664ed0b8e65fcb4
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf.cigioed
binary
MD5: aa7b3b97f6fdd1e1d46d9fd3d462cd8a
SHA256: 4c2aaf3a85269cc4dddfed816dffae752b43192909324e1b55b2487cf4b9fe92
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf.cigioed
binary
MD5: 32869355e9b3b153b83d384fc5bc7cd0
SHA256: b2008671dacd7e837ee3add4233cf444acc6bd4297b19ee53331de50ba5419d7
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.cigioed
binary
MD5: 450e1935ee3b5043a6f6168b354384b1
SHA256: a5bde402ece70931f74e0cacfad7789042e429c701ba20e56bc64d7ee38a46e6
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg.cigioed
binary
MD5: 608f116e4f8ac8c52574d000e40e73e2
SHA256: df6b83adf38f7012c36951a60123d752674ddb83936c9e605d1a040cbda24a39
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf.cigioed
env
MD5: 7c2f25ea352e532fda4d3f070deb3722
SHA256: ccfea2f902669ae99bf434920c381df15ce21556ac27cbdb8891b04fd9133f89
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm.cigioed
binary
MD5: be10baefb9b2776d1712aeea5ad13e79
SHA256: 721b6d37ea665b3e888608514a4ce2bba0bafaa8dbaf11f1677503ec4af0afc6
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf.cigioed
binary
MD5: 774650cf6bb5be4824d37632c6ca68ea
SHA256: 6fb320e7e122fbad22cd7652ea14146b0cc3845f1edc84c9fcf7c7a06c46dcbc
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm.cigioed
binary
MD5: 96abc6c4b5ba0c741e8f86f75e29fb3c
SHA256: e58bee5d3f65ba62683e27574feb2ae9efaba7b98b983976907e47c7ec4f34f5
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf.cigioed
binary
MD5: 390cb6656be34836ab9d83b6dc941994
SHA256: 74c6507abca85db5d0a3b71ddb98aef15f0cc57c3601ec1ffea5cfad0a8fb62b
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.cigioed
binary
MD5: 32a673053d11d2018b13bcdd8472e52b
SHA256: fa808a26859ea19e0967a840fc543b44827f497b7e044d4b7464a1c2b90a947e
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf.cigioed
mp3
MD5: 2c1c607d8b701de9c8c4622c8e2bf507
SHA256: 403d1e5aec4be44c0d9c59eddffe259f485506452ab7c166a5df6c794724bab5
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf.cigioed
binary
MD5: 768f83859a6e5919ebf4eb42f0f4354a
SHA256: 9f0d1efc7fd83640f03fd10c137d2ecad5aeb96c185fb360f43cd23790830600
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm.cigioed
binary
MD5: 8366a10a15df11207fd4b700a910b58b
SHA256: 360437a2d43d481171ed9bb0034c274682d5df5811b11523db8909e3511ba5e8
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.cigioed
pgc
MD5: 916ddfd49287276baa2c05936f393166
SHA256: e842276666b954a6d059b2465e842e29475c751418b6d3e14540c233eef12f8c
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf.cigioed
binary
MD5: 9bde4316c2866f39b8b5045db824ddde
SHA256: cccb6c69090968d05b8506b363c74c0fe5cadd9b42344a94e13b3c933920b125
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.cigioed
binary
MD5: 75d30103daca6dcc46cc8fd95fac5a08
SHA256: 3e619502fb809d2c2e508d7c5ffce62c391b8ca373e84c3feb8a5da41ddfc181
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif.cigioed
binary
MD5: 021af6ac8f4c30696775f6b0c33f74da
SHA256: 0c3e659837429e656b12c2a554cce0180571d06c9d8da74bbec047e2f9fb5d2a
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg.cigioed
binary
MD5: 82f97fc332c8a0c576216a3ea3940e3c
SHA256: 2101e4141d7dffa57ce85effcdd83b9a4879a1bc7d63f0f5e09f691fa061ddcd
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif.cigioed
binary
MD5: 60a97578821bb21f2fa196a6dce67fa8
SHA256: bc2027ea85ba043843524125e559f6a7a55145243249ad47ac2f1604baa00855
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm.cigioed
binary
MD5: f577d33ff3e77942fd1ef55b70db6159
SHA256: ed0ef6dff9938d2baa775c65c1bed688adbe7c8961ccd7bf3d138b3067b033e0
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml.cigioed
binary
MD5: 325e9d5c26285f9d88026a79af7914c7
SHA256: 0e4eb8c5f1d191d1d1e815d8faa11ec7cd5774e446d54600aaa6c8dd8cb967cc
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs.cigioed
binary
MD5: 0babaa8908fe905ff730ffa5b66fe5ed
SHA256: f7e11088af39091d10d62d58579dcfb702db7563d11e19ac9304e396be54757f
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs.cigioed
binary
MD5: 27c57c25ae757db3316e09a8f29464f9
SHA256: 5f7193ac692ab63c14d114dcdee3cbe3bc4543bd6221d5a733999223477a1289
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log.cigioed
binary
MD5: 9157d0d16873f57b20f8737021d24961
SHA256: ca5ecb724bc9c78880bc901c64568449eb6e73215715b5715db75649682aacd9
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log.cigioed
binary
MD5: a497966dd72a37b1f1930c70ec5a4867
SHA256: 4179a989e5d4de40586e9445033ce75290b40b74e54f7979daf051e89b7d727c
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk.cigioed
binary
MD5: bba3b682762f29aec9ae394bf2c51d70
SHA256: 8b3b761e6ebe3c02aa7a71c6eba810813836af86f98127b3148be0fd0b497d48
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat.cigioed
binary
MD5: 528231252ed0f6c3cd1f768eca9972ce
SHA256: eaea11732fbe4d3310d5e2a0e889761a2fd8d8e0f84a46983060201f34807058
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore.cigioed
binary
MD5: ced2d495b202d46b3d5461df97080e36
SHA256: cbdde9459f4a487ba598804560755470d56970d43352ab63e3f329bf99ef6c52
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log.cigioed
binary
MD5: 4a7c4b3673ee1440334a4ee48a48f2f1
SHA256: f24440380f0b7b10b968a8644c1c5d786c074ef6ac355a1fcbbfb8db3e5b19f1
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount.cigioed
binary
MD5: 83f271529da272d9c548bbe04b99ef27
SHA256: 18c5ed6a6a09133b4c915b3d91153322f5b43981dbedaafb91169192c8ec6280
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount.cigioed
binary
MD5: c4edb5e4559bc9650350c7b656ad846f
SHA256: 3fdbfadfc50f89991a23fea873ac507978dbdbbe19518924c673e872b54135a9
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount.cigioed
binary
MD5: 830737ac9be0afacb5faf0192a0be0ca
SHA256: 9ef0eec91e0eaee7bf7771324e8e9a4ce53f8147def2a4014526f21d5938cbc1
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl.cigioed
ini
MD5: c1f38f8df28af07768d55bb9e244916a
SHA256: e69f4907415290f1bec5c4d9e364768c293d9e83aecfea4a1752029954603bd6
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl.cigioed
binary
MD5: edc020449e148188b4add55af386a20e
SHA256: 2d5c1bed94d2421b26083b0a208e73d3713f665ebdd466493a2f61e83790db00
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl.cigioed
binary
MD5: 5da9b0eee489ae0c635281c006b9a267
SHA256: 71bd436d51f26eadc4f93c12fabf002ad135e2868cb0e401194c88e40c9cb3f9
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl.cigioed
binary
MD5: 881693c4fc8720bbb9c575966e6b57e7
SHA256: 6d6f0589901a3145ccf07b5fe0d761a0b553964f5af2b2ad64ed711c39e0c0cc
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl.cigioed
binary
MD5: 47c616d1e32a5163db073af91750219f
SHA256: c79f170bbebfdb4c7da12e948f7d9f310358e01335c9ad964d6c9330609fe366
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl.cigioed
binary
MD5: 03fcf51aef740e0775f76e8bdf7eb5cd
SHA256: 8441f97e106f1d44160b5897100c6f7a15dde312f4fb6b9fef3a225788c70e60
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl.cigioed
binary
MD5: 4231eba8ab94dc02d19b6eb8be0a2efb
SHA256: 65a8b4367217544ba0535336973dda0665cd823ae45a4872adc9be510d9332ca
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl.cigioed
binary
MD5: 03822580000f1971a65caa672b2cfdba
SHA256: a4cb8e24d31e4e52b62f1ddb2e8a0749129fb696311de8396ab9eebdc2f65753
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl.cigioed
binary
MD5: 1f63377fba6ab3cd0fc882a55f54485a
SHA256: e29d01a830bc187a87a4cfc5fe160c5eabdd2a0861c63e3c2d61b420117bc35c
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl.cigioed
binary
MD5: 7d918803399f91aee72c68ec70172bc5
SHA256: cafb6e2d7b07eb58fe89b8a779a62f94a5211e332df546393258e70c8b1f991f
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl.cigioed
binary
MD5: 11c87d57ae6ba3a02f05e4ccc35fd536
SHA256: 9c9feac01eb5a84df44e30f2dccc84d2eb9bf3de2d6bc8c886b4154fbacb6785
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl.cigioed
binary
MD5: cecaaec70e21a4fb07a5a59308168213
SHA256: a1e6ed63410af5a4bcb550fddef2a31a51f62dd5ae4f8d51e06db8e26a8e35ae
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb.cigioed
binary
MD5: 2df6688b91bfe7c0d9aeb20f47882317
SHA256: 3d1735be73b42e04564d5f5eb1b7c92426815d7713ff05881e46410d2c93fc40
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb.cigioed
binary
MD5: 499dff1bb7275cf7786f7794acfbc1eb
SHA256: 4aebb990bb9aa87ba7322da691d502e64b4056dccd18c3a2e2a5e278a9cf5225
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.cigioed
binary
MD5: d77033c1f28f7ff913119526ab6f487f
SHA256: b37e3c402976705b59404b1c5b3436b00a628a6c5c30a2b346569474dcad2540
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat.cigioed
binary
MD5: 3b7758c00dcb1937d0597862b5be1758
SHA256: 6dbef8a32b447f14d2ae486e6c230d9d98910d8e88c524745c9162ebdc5fb251
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\HPSK10OB\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\9RI45C46\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\VM3JD5NM\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\G4PHTCUR\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms.cigioed
binary
MD5: 4e861aa27fecae43f3277ac086987a25
SHA256: c0705346c996f9d6930b212423371ea61a840804c84872cc1bcc3d56f38be078
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms.cigioed
binary
MD5: ddfbd799c4b66a8c5a9f6e9be27b49cf
SHA256: d9d97729337779cca3c4577b66330adc0a1e96a8ed3b8410f5f6a7e384460276
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms.cigioed
binary
MD5: e9245ef1e7ffa957aafbd9e39c201094
SHA256: f4a5582a49c55d1325629d2380652a18859182bd9e85854956b4f229d88c7221
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms.cigioed
binary
MD5: fc4d8b7a0a6395ce54f8a7e0b1891541
SHA256: 1a13d816a19c60e6d9038a38a735ce8bcfdd2e60d2dd2ec42b1261b498808b0a
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms.cigioed
binary
MD5: 3798fae8bf03baab4c6b61e8c89a2f84
SHA256: d36da6595033e84a3f03a65793d4034cebff3945668faccf6b33006981a00c9e
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms.cigioed
binary
MD5: 988094158c236f8bdf807c164e860066
SHA256: 00215ea341e0fb546bdf521b43e3bdb74f0e80f82f9bde225dd901f7ca5528a8
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms.cigioed
binary
MD5: b276ba99bc5eb2d3efd557cac8fb439f
SHA256: 66bbc176d0d2dfdad1e3eefd2f2d3522be4d43e8c0b7d206df2c0bcbf28cce41
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Credentials\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\History\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.cigioed
binary
MD5: 31111152d4ed7423d6c4c64632ed7748
SHA256: c78691130c2674930c2fd5597dc31f3d83b8fb929687ee3e0f3ccbfc9d353daa
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\Local\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.cigioed
binary
MD5: ceb371ac262ec6b453398aa4f77ea649
SHA256: e3125df5a14bcac26ee79ce21fb09962d007ecc55e2d8f842281837e0b443964
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\Administrator\AppData\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Searches\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Pictures\setsresources.jpg.cigioed
binary
MD5: 1dd1b35b204481960a4f02e7176d33d6
SHA256: 546580d44dcac3dd37336ba8fb4ab79abea1ce8825c849ff1c01bd9ec8dc21bc
2480
file.exe
C:\Users\admin\Saved Games\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Pictures\volclosed.jpg.cigioed
binary
MD5: ceda9e5fc688438b67ba23252404c181
SHA256: 951f253a424969b5716f9bf5c370af597025076cc0513b251588be37ea5cb820
2480
file.exe
C:\Users\admin\Pictures\setsresources.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Pictures\volclosed.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Pictures\leveldvd.jpg.cigioed
binary
MD5: aec28b215bd3e6d24d22f5f25ac902af
SHA256: 34250181177e0fceb6e4b8b47a357fd349511a889293cd470d6743163d8f6c9c
2480
file.exe
C:\Users\admin\Pictures\insteadcold.jpg.cigioed
binary
MD5: eb5b42118740f234f5d6b549f4ca1f1e
SHA256: 3d73a0fd89983a3e91b48089c016e8436f7610856fa15bfeeba9f8e78f78c7b0
2480
file.exe
C:\Users\admin\Pictures\leveldvd.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Pictures\insteadcold.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Pictures\flowfriends.png.cigioed
binary
MD5: ba1b5f722836a69c941acbc4ead4cd51
SHA256: a694684ada81522e9f8cc1ec0c64b00373190f619257d35d3cdf8e942ff8a007
2480
file.exe
C:\Users\admin\Pictures\flowfriends.png
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Pictures\cartappropriate.jpg.cigioed
binary
MD5: 642d6f54843180978822527cd4d3fae8
SHA256: b10bb210e67c23dfc8debdcfa41c6a657341bc87d8b3bbbf430d6160447a348e
2480
file.exe
C:\Users\admin\ntuser.ini.cigioed
binary
MD5: cd03c7659420939e2ab141b8d4b123a4
SHA256: cb4bb1e77c967bf744c765e337fc543aae335b65274787a627022749c517517d
2480
file.exe
C:\Users\admin\Pictures\cartappropriate.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.cigioed
binary
MD5: 381e715a977aa6ab767bf3282776d916
SHA256: 64cc34a07e156a0f0de06bab84138df5630b25efe79ed0e22668c446603fbf83
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Links\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.cigioed
binary
MD5: 9b128c83269b0065c21c64de2f4c9d07
SHA256: bdcab755ee649895aa0a0834b09becc827b509cfbdc6903fb6f06fbf77e79faf
2480
file.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.cigioed
binary
MD5: 20416770f34b95a7889e95b2fdf2c71f
SHA256: 9480c810212055ba79906007bad7d670e902a31e59a2f44e78f0bb0278b8554e
2480
file.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Windows Live\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.cigioed
binary
MD5: 8e4db24e740d1409ab2aad802497347b
SHA256: 74a05ad65a987fdaa2c320b30cce65ddec519fa33b635272a5fc19e79ba6a010
2480
file.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.cigioed
binary
MD5: b7958e25097f32c49ddbc1dae888f284
SHA256: 95707e86d3c1964dfd1dfb9955c98ddf53411d391f50bc8b0d1c92142f16d816
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.cigioed
binary
MD5: 1e3ae93815286b8552a2b5e547f41e0c
SHA256: 49c4d83200e84766e64e0d1b019e11c3917bf0e072ac3965c65c4d186a253084
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.cigioed
binary
MD5: 9367ffb92b25b39d704282401445e2ff
SHA256: 0ac34c4d7848f45d3c11813c7a194eb3c03a2389ccdacb5090f449f7cf6ba3d9
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.cigioed
binary
MD5: aceeb13e57379d013478f5ce5e0ac293
SHA256: eec99c71afb1faa5cbec1bfb906ec0499daca2f79541699be5a77d84c5c03d11
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.cigioed
binary
MD5: 5330bc46970ce7e18f94bb7c940cb7af
SHA256: d8433c9d85c7f09f0342610e684e9288628b69fc66aa14b08d7e287e27d75963
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.cigioed
binary
MD5: 7e34131a9937f328118ddb63c24c5f01
SHA256: 2490dcf7059f8e9f70db58cc01a32374af7ccdd274785e3e9997e43466e7a116
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.cigioed
binary
MD5: 064cb4aa9a4237941ee653010b3e1d99
SHA256: 54574f161d4f8470436e637921832137854eab6a8d571b6834f3a4708647ae2f
2480
file.exe
C:\Users\admin\Favorites\MSN Websites\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.cigioed
binary
MD5: 64ebbb6cf54c065d88dd8c94aa2b87e3
SHA256: fa9e95ed598cedb7d4de49c95d24d7b4d6c59a5a85634a9ec620933d5eafb84b
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.cigioed
binary
MD5: 1613f298ebc6f9df463ee99366f057ae
SHA256: fd4913394ee57ffb0176bbc8a3b68d8eb6f1df825a378367e4263a45a35942e6
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.cigioed
binary
MD5: 400d84fb579e892a58674dc073f18d0d
SHA256: 22bae344c68cb739b874b7d58a192d623417cd7592efe5ca5eae0602be9da10d
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.cigioed
binary
MD5: 9926925c07d9a799dc4d15cb4c9dca0f
SHA256: ae1c71362697d469be93491a534a09f83d116af64c35558b211ba620d570ff47
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.cigioed
binary
MD5: f5e8cdec81833273e1de95d5f927054e
SHA256: 105216d489e2457bf12c55049ef27ec12b7130f94f1583b75f13905c2cfba666
2480
file.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.cigioed
binary
MD5: 9c8a5793db0cd42846f87e7e7aa9f5eb
SHA256: faeeed36bac420b980a1895d2d42a3619cee57a7b260ada153820199dd43ab65
2480
file.exe
C:\Users\admin\Favorites\Microsoft Websites\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.cigioed
binary
MD5: 389d85895c557f692d96ada233c7f361
SHA256: bdfe95f3e3930e10d1e24fe8fe6f2225f1810cea35f43e785be379b9c79e3ebe
2480
file.exe
C:\Users\admin\Favorites\Links for United States\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.cigioed
binary
MD5: 59ba3117bc28b0444213296bf3899507
SHA256: 7b454e91277cfb116b4b42a35f0845c653afdda7e4ac9de2e8945af4eb28e719
2480
file.exe
C:\Users\admin\Favorites\Links\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Favorites\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Downloads\usingoutside.png.cigioed
binary
MD5: 1d1ac69396c7c5667461bf7e355d0812
SHA256: 314df2fb673eba5ae7b0a66a79d8e0a12b8254d8fe847c3f61e93b29f8d246da
2480
file.exe
C:\Users\admin\Downloads\usingoutside.png
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Downloads\salesilver.jpg.cigioed
binary
MD5: 57509cbf2ec6e7978f94025bdd08d99a
SHA256: f71cd1877f3930a8c2bbdf21b48b50060634aae177deb7552b1379e929413e18
2480
file.exe
C:\Users\admin\Downloads\lotclean.png.cigioed
binary
MD5: 2b940c3fa360b5d0a58483fd35555205
SHA256: c92c598c31e9cd647bafda3382a4ca9d25bb6af2d2c66f10beb1f9d440aad094
2480
file.exe
C:\Users\admin\Downloads\fitnesslinks.png.cigioed
binary
MD5: 976b62efa12f6e8b5346e706a4fa8c55
SHA256: 05e6cb64a53ea4ab8ef8fdf3db4449dfffdc9a67589966870bcc53a4a45b3ced
2480
file.exe
C:\Users\admin\Downloads\fitnesslinks.png
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Downloads\lotclean.png
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Downloads\salesilver.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Downloads\casinoblue.jpg.cigioed
binary
MD5: 064e6c0f75e625fda5c5c3122937e0af
SHA256: 55e6448ca2c496b274273bfb84286fc3677f177ef9c0ba5b067e2a195220c700
2480
file.exe
C:\Users\admin\Downloads\benefitkb.png.cigioed
binary
MD5: 1e2536ec9c80b94496d45d922bd9a826
SHA256: ca866b80bc73fa2bb111dbd4c8caf3e3741ded6e6b5276bc3cb8eee5b5f225a6
2480
file.exe
C:\Users\admin\Downloads\articlesstand.png.cigioed
binary
MD5: 766617fcefcc4a2c3dc2f8215fb7ac1f
SHA256: c23ac8fda510f33cf9b193a7876e29102080fc2f6ec6d20c3276cd9afe3c3890
2480
file.exe
C:\Users\admin\Downloads\benefitkb.png
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Downloads\casinoblue.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Downloads\articlesstand.png
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\withoutnokia.rtf.cigioed
mp3
MD5: f11af11e407fb30fcc5aa03b58cffffb
SHA256: 3d8c50c8db2ad3896527568663c0e9dca8ba8517a485585a8f2a8f12f00030a0
2480
file.exe
C:\Users\admin\Downloads\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Documents\washingtonstudy.rtf.cigioed
binary
MD5: 357fc4e4f46a881354fcfadbe34481d0
SHA256: 1f4bdfc0e71be3521992815ea0e8fb5be8168f42a11c65b9503aadbc7152b865
2480
file.exe
C:\Users\admin\Documents\withoutnokia.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\washingtonstudy.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.cigioed
binary
MD5: c7dd0a8fc5158ad5536d1dfe7c111259
SHA256: 996a33932644fe7a005244cceeba49856b4ab8085ae4062642e9e4c259f07c05
2480
file.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.cigioed
binary
MD5: 97a4a7a8064eaa3313ab8cb0fc56173f
SHA256: 6fa143101760c64257d2a61e1a31e8262d4a318b277096bbb31d5a46bc6f8a8c
2480
file.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.cigioed
binary
MD5: 93948d7fe74834f64276b9aae88b3ae1
SHA256: 250db914be3ffc5b8d8cb5f99035ae5b90971398852fcea3a304bc986014e6f5
2480
file.exe
C:\Users\admin\Documents\planningcommission.rtf.cigioed
bs
MD5: 57d57ccc7dada601a5377a5050e6bc50
SHA256: e7a12d951577a16b73b1511dd942b870e2a7329dbfeb8adf4b90e30f3777b668
2480
file.exe
C:\Users\admin\Documents\planningcommission.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.cigioed
binary
MD5: 4955d29ad3703c9627ae26ec9c4dd059
SHA256: 93a4ba16def58b8f7085bec527c89fc43107e34da025ebf4b620102f40880d5a
2480
file.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: e019bdd3e1e3efbdfa97636ee58b1b6f
SHA256: b34d9f9cad113a999c7625fe6e37680e4654ff5d03e1f37b4a8c9857d92c00cb
2480
file.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.cigioed
binary
MD5: ca4c86ba94e5ab94bab68f852a79e5ab
SHA256: ff40dcc215cd7e7bc9a1b30abdcbad9975f22d43be6df23acbe43329b4e3d242
2480
file.exe
C:\Users\admin\Documents\Outlook Files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.cigioed
binary
MD5: d06629235226ff41944d087a11f40096
SHA256: e629950eaac7b6abf4b0b998e6b110939ff58f27ca8a8210f977efd28e747495
2480
file.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.cigioed
binary
MD5: 2a7d0a66382c5a37fd5403517fae5962
SHA256: 0ddf8b542851f8231f833bcc2f66c2f457808c168d357f070aa33bab01e57455
2480
file.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Music\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Pictures\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Videos\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Documents\OneNote Notebooks\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Documents\artistperformance.rtf.cigioed
binary
MD5: a9abd128d2ab2610de67df70ed579d74
SHA256: affde944457cde4711c23bd92f3ad6cf1aac1ec368d2413fd8d36720a1a67beb
2480
file.exe
C:\Users\admin\Documents\aboverussian.rtf.cigioed
binary
MD5: a538ba97e91022ea33df35c6b075bb64
SHA256: 99f519fa1bf2be344257f27a8daaced3a2b0d9963b64032aa85dc6ff69d73d19
2480
file.exe
C:\Users\admin\Documents\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Documents\artistperformance.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Documents\aboverussian.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\sampleprofessional.rtf.cigioed
binary
MD5: b208ac5c083183f40b5b80ff993864ca
SHA256: 83336eec82d6b074b354f0b3948793ff97d9630adbee5165f7719f34473cb428
2480
file.exe
C:\Users\admin\Desktop\strategyroom.rtf.cigioed
binary
MD5: e81baa7dbc8d39200715422a2d34fcae
SHA256: c7daa646f0438c3e9ce556aa5e2c64175b25b349ef0dd334fde10abe08b6f522
2480
file.exe
C:\Users\admin\Desktop\prettyglass.jpg.cigioed
binary
MD5: cb20573a8400258aca2065b7584c3da1
SHA256: e56ced63d712f492c9606c1548940f904251eca8be328fe9782b40719f797b57
2480
file.exe
C:\Users\admin\Desktop\uniqueclosed.jpg.cigioed
binary
MD5: cad5ef972f765582cfb4e17c1a815ae3
SHA256: 55257c9a57311550dce0d4dd6d927acaa5f4d635224a194bc97d3e1a84e51cf2
2480
file.exe
C:\Users\admin\Desktop\uniqueclosed.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\sampleprofessional.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\prettyglass.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\strategyroom.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\golfproduction.jpg.cigioed
binary
MD5: 5e866755bf964155b4d9b67f741d3e77
SHA256: 8d7dc7baf93eb679bbf556000ec09c14524024398932a01862bdd8a7d52cc64c
2480
file.exe
C:\Users\admin\Desktop\macresource.jpg.cigioed
binary
MD5: 7da8eb1046a80748930506d1f18eb008
SHA256: cb998994ed21994afc55791001278afe4692d1d52a05c6657b45817c4bb0899a
2480
file.exe
C:\Users\admin\Desktop\orderrecords.jpg.cigioed
binary
MD5: 59298cd1f008ce9beacc53466f988a3e
SHA256: 25fc4c3de98117e091c7e42f72c10d060b9710c3acccf1d6e742a83480725948
2480
file.exe
C:\Users\admin\Desktop\manufactureraudio.rtf.cigioed
binary
MD5: 3db01353927178d1487091a4cce7b870
SHA256: 0a77a0096819c544ab620fbe7705cd2af2ba8f4ec11982d51ae44ce363515f71
2480
file.exe
C:\Users\admin\Desktop\macresource.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\orderrecords.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\manufactureraudio.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\filesparty.png.cigioed
binary
MD5: c80964fa351a6d8cf4d823e2cf57166c
SHA256: 8bac155cecfa9c37bb7019b6a2e0a04b078c0914060f832b5f22442823f3546a
2480
file.exe
C:\Users\admin\Desktop\faxfeel.rtf.cigioed
binary
MD5: 23d419bb4d9718a54a50451dd2f4a028
SHA256: ffc21bae8659c6e8cf366c6a3c603de78a340f10c9769345b221a401799e92a4
2480
file.exe
C:\Users\admin\Desktop\bothoffers.jpg.cigioed
binary
MD5: 69e1d84bf457beead582b6443b96893b
SHA256: 47cdaefd6845c34a66a55ddbe6e1c4bc1fd77f744d75e23a819537401e5cd48e
2480
file.exe
C:\Users\admin\Desktop\faxfeel.rtf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\bothoffers.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\filesparty.png
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\golfproduction.jpg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\Desktop\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Contacts\admin.contact.cigioed
binary
MD5: 1a9441004cec19310dddb634e70252ae
SHA256: 045f79752a7c7ab9c95404ca88fa10edb60f1b4bd38706dae9b0146e75e83da9
2480
file.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.cigioed
binary
MD5: 753e6e9743cd2c7ebebd5de0f2d98cb3
SHA256: 8f36d93667994779db7a67fce9c38e588cca076b9bf86d7ed240dfe249aae1c2
2480
file.exe
C:\Users\admin\AppData\Roaming\Sun\Java\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\WinRAR\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\Contacts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.cigioed
binary
MD5: 6e248686bae5e870e9d56d637d3b73f1
SHA256: 1136018b79ca88e1e8c2c191b5a1d36cd67a82472f30dfbfecfa4e9fb6c6f834
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Sun\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.cigioed
binary
MD5: f4917389a0c1ce994415b431e755f892
SHA256: bec404058e7cc4a42b9457cfc2171cfdea0fcb2892f70a03653a76b57cb93fbf
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.cigioed
binary
MD5: ce7e30e726b260b70a0538c763a7c55f
SHA256: 2e14ff40fd529d90585af433603682d46647f70b8c805458754ea8339fe298ee
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.cigioed
binary
MD5: 08785e9e8d9514f6895c0210658b83de
SHA256: b479a37e1861aad965f6b5341a6c30e3d7991e10e7cc806a390b99506bcfadd5
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.cigioed
binary
MD5: 16c67671d52fafad912a5f02753e7a55
SHA256: ee1206199dba4bbbb01a6f519c68c57ffb9ad1abd2727c41d8da21a281334a7b
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.cigioed
binary
MD5: 0fd522b99942979649e6e72157199362
SHA256: 9fc2e1163fe631a972b2e836188a8fe55545962953311cb071b45338be0aee6e
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.cigioed
flc
MD5: 40e9d954528fc8917c30a5e6e29245f7
SHA256: c06846f0e48832e07920a1f4880f63d02c092f1be8e6460ec99c58d3edd119d8
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\logs\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.cigioed
binary
MD5: b2657c9ae1e719c9a4f431a9ba543e91
SHA256: 55de1927aa81027e3e27f7db48cc088f58291888ab7a055af52eb88366f0fe85
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Skype\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.cigioed
binary
MD5: cdd43ef4e8c9bda183a916d707176da8
SHA256: 848592f84830df81f43fd0cbd594e808c2cea3d010883e410c6a5cd3c720efc3
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.cigioed
binary
MD5: 263c869768d0f18f71de6fc5845e881e
SHA256: 813fb0424bf38aeb38af31f315f473ab6b1d252725ea61233ef0ada5f1b40b28
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.cigioed
binary
MD5: 05acb5081b43f5748d1ff78a611998fa
SHA256: 5a1cb57c417a7b1872c2211deeacf54528962a60cfa1cde4b58e09bf6f22bcd0
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.cigioed
binary
MD5: dea787746bfc9f1983068f19b6fe109f
SHA256: 40ace16ff7e75035c8bafdb9a6f43d98cd28e4fd070836f2ab266c6f1c0b5782
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.cigioed
binary
MD5: 3582c5eb556fec7a43464fab4f53f95b
SHA256: a97e01d346d03a25b60b57906652200efdbbe653d59dbb30505ffd157862cdcf
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.cigioed
binary
MD5: 23402c0b133ea2c2c10614f499d6f349
SHA256: 1306ca5c7ba68b7bb20d2be3bcd730043140134f3b283ea0859a7551230e81f7
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.cigioed
binary
MD5: 8b2032762ad3c3d5601d06793ceaf507
SHA256: a68b902776b04f6d8894c007c439999be98a954d492d65e0fb73fac16a56d7e4
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.cigioed
binary
MD5: 681abc51968be601e69e765444ccf99a
SHA256: c3f2952c5d2e946d24db94e5f3659108b6dd90403dacb01bb2779c8c0b5ae7d0
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.cigioed
binary
MD5: 8d1ed95d81e2f4331db1c2ff6a26b06c
SHA256: 76470b6d77240e903232ba8af8f670d92b0d3e9d66e97dceea6b863cdbdc9877
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.cigioed
binary
MD5: 3e40c89cc38411e001cbc2546aa2b32c
SHA256: 06d9f8be72baa9b4cde2dec4cc079f4ced26930fe84a697fd57558f3add9a1a0
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.cigioed
binary
MD5: ad8fe78fd3e7531c175f9b1526a341fc
SHA256: 5fe5d986236e01be4d8e89dd5c295b652857d22838aefd1788915474f3ccec8c
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.cigioed
binary
MD5: 41a8f7f4787a8d4da40eb3e3677ad5b8
SHA256: 919ad20238cc2c7f2e81d0cde3b538ed30f0d8da616de88ac6b9258b7a1283d9
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.cigioed
binary
MD5: 2dcf400d07483a949fa84432efc936e5
SHA256: ede6c2c07bf6e94524faca00374b692384ddd2c3e2cef2f4b2132e554f1c2d7c
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.cigioed
binary
MD5: 2fac3cda33babb97277a64ae6b59fa47
SHA256: 635d33dab12e4d3fa6800ab6627812189b2021c5e59146625bc7985a5964f580
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.cigioed
flc
MD5: 6ea00f8e54c14f63434b0f8b7864a90d
SHA256: 7ef67f5f3b7eac8d52cbb680d1c876d40e30459e9ea4622a4d77bd20c03e019b
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.cigioed
binary
MD5: e37f8ed17a6d8ea7916fa2db0d41fca1
SHA256: fe125541822548f82ea94c830c63157eadf23ed30068b036cf1e2bf3d6ba8fe0
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.cigioed
ozfx3
MD5: c3e3c5d1a0cdbce16ffedc656d3f8980
SHA256: 15a45794e3e668b1c232a0f94a36400a3ac369fbe06d31af3d61fc2720938b4f
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.cigioed
binary
MD5: 511d67f9842a3818cba6aaabab33704b
SHA256: f1f144f8596434f4322a192648c216839deaaab44d6c69fa6d4dca4a936d7f34
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.cigioed
binary
MD5: 8bfd4bc300debc795767d1d8ad557920
SHA256: e1844ae7c41d26f6ce1af95791e780829b86416d976c31b6d1e0a2879d6f3037
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.cigioed
binary
MD5: bd4f03a7bed351a8e6feceb71b070de9
SHA256: ef98f3d74af259d250d6c3a1fce0468149d34be5a7b1dec9047302c02d27411b
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.cigioed
binary
MD5: 129694535050280698be807e7b028be4
SHA256: 0a81db28ab09cd4e52acec2277e5be1aed04dcabe12be62b26ba84253351904e
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.cigioed
binary
MD5: d0b3759088d9352e771499d75129e38a
SHA256: 308eaa28a39dbbb756a4e158f057db071e01bb70dd61d2f7b089307dff5a30cf
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.cigioed
binary
MD5: 7fe8ab3ca677838370a021a1a424144f
SHA256: 6c29630992a6f720142c920f0ad6ce84fbb0104084636eeddb3fcbf7bfc381f7
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.cigioed
binary
MD5: 8dae3129264ab2afe4a7b0aa9ee870a2
SHA256: 0769935719bcedd87c9bcc7973e93b720b49b641202456d2af2c4cd81bd46dc5
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.cigioed
binary
MD5: 4cf4d62acdbe2110d3127faa952b595e
SHA256: 2e6392d0d32a42750e0c1c299e842e800343e81b480ca7a6e1e2964faaecd164
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.cigioed
binary
MD5: d122e928828d244763ed0ebcfc480fd4
SHA256: 66c2132b57f3feba890463d294b3ded680e68a40898b099b4a9ef32486914f70
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.cigioed
binary
MD5: bd13f3272ba72f203698b0ee72110cbe
SHA256: a341032a75ae313ba086d3d46158fb769097fd628b59c7d439e2874f39abc174
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.cigioed
binary
MD5: 4353f0f5b471bfa911d2918fcaf13f3e
SHA256: bab6bcc57e3e76e0791371bb26060568ceb1e5cf54f72b4a123a4e4efa35511f
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.cigioed
binary
MD5: ce1f3dfd02af782772bb20e6d75ba106
SHA256: 8937f45f6e0f711039b6942894d9926fce75821bda69cfbe693fd0e424ae8465
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.cigioed
binary
MD5: 9617afbb234fcc97aa6ca0bef78cb7ef
SHA256: 180548554934b126072adf51a5e1317ad3fd19c719282c7a587e145136728de6
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.cigioed
binary
MD5: 5e31df4796d4c55cb26ba93b8a1e82f7
SHA256: 85668aa12c696451962d4fa924775c204c11ea1d18ae141207b1d5c97b801c93
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.cigioed
binary
MD5: 74a8d7f7119722df8b3f14c4a325d3ae
SHA256: 2a72011981584770ebf4ee3d1673ea2e728bf09a66e5b8b509e3cae7884a3cce
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.cigioed
binary
MD5: f586cd124155b98444794f169a116741
SHA256: 3f7c2d2b2d1944e51dd5422eee8e7fcaa1245411453bacc9574320ec08d7a150
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.cigioed
binary
MD5: 3cb4407407c6a7a752cd80e891bf370b
SHA256: 8467153893326bb700d460dc6686267a337560f7a96178870e6369bb64f0aec1
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.cigioed
binary
MD5: f8edb840e496cb58f7a8e64d4c1792cf
SHA256: e532daaa1b6904e54641f5ff4204b69c6e0688bbb359093554abe6415c8637e3
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.cigioed
binary
MD5: 04a1bb79d406968b3a157ea588699663
SHA256: f92343f1766fb9f1e8161fee18e6d3a9a75c04fb1e0c5c30c4d577b119073488
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.cigioed
binary
MD5: c0029777a39d69e7826f613ce59c7c91
SHA256: 81e094165555d97710fe3adcb25bc3fe0211454756e4c11e70859bce07303df5
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.cigioed
binary
MD5: c8aad26725fc3ef8818c28be94c0f42d
SHA256: 1419ea4f7130f20582fb00923b1d0c56b49fefa1584e1ef43cd06489d071390d
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.cigioed
binary
MD5: b46e1ba9f762d5bd867b29d713e8705c
SHA256: 06d09d26532c2273c4cd2e98fc79489ba5d2d0545ae514d791eede1d8194c9fd
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Opera\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.cigioed
binary
MD5: 2dea398a040885f0d34630ceaa6f24b0
SHA256: 9fb10620cf607380d496d692432a0ac67a91eb9fe9f666f08e61a6eb87cc284b
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.cigioed
binary
MD5: 3271b78d6cd28a260ad37627bb63ecc3
SHA256: e5e9d80b9b2f1422a649ba8cf18e91ed4e89c92444efaa815ab51b50eb550533
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.cigioed
binary
MD5: f1e73c50910fd6adc0abca37380bcbfd
SHA256: 1fb97720dcc9be2864dc637e7f3aba6eb6a2c7b17a5f6b782d5b16dabc4c798f
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.cigioed
binary
MD5: a5865c3f3a3294d43a8f23ddd9174851
SHA256: 3cc1c720168f84d8fe8a517d196a953639f779b0d7571c4b38000d096f1104af
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.cigioed
binary
MD5: 13ddc81455af95ac97abb309e0614565
SHA256: ce9bd9426a114b42146269b6135dfa95672624079fbf9fde6bb8049a6b7cc2c0
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.cigioed
binary
MD5: 77c7bd8d78b8a4c99fdecc790121e5ee
SHA256: 8002e5aec92a2069c1e8b84becf4008ef8023c7facb8865644b9ea2731bb5c9a
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.cigioed
binary
MD5: ee4b6f18e005510dd75d543ec3f471b1
SHA256: 3a9d6924a409ca90e04742f470774d362b18d4c29a4837db9178ffea52a4c02b
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.cigioed
binary
MD5: dccb939a13f461b374573abbf880c130
SHA256: 63df8136971d911dcda29698f26694beee316ce5fc3bc9b1be5af7fbb31f4d27
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.cigioed
binary
MD5: 641d08adb0eb2c64b4bde50948ecb7f6
SHA256: 7ab3eb764c0fbc9bcefdd9f904130ac1a23b124eb7ba0d55eefade086214501d
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.cigioed
binary
MD5: 77f49289a015ae61a93253347b033f82
SHA256: 2bf466ba85ed3a57913489eaa320164685c62e7e5ae2945af1c0b47e336d4be0
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.cigioed
binary
MD5: faf8ac50ec82cfae518c041f24fd06a2
SHA256: ba82bdca16078914f3501a6f6059b97e84f99dad5c639c57a3511c00422cae71
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.cigioed
ini
MD5: ca83656e4130d0940df0bb63c995ead9
SHA256: 5edd13bcc2fcad5bf36c81bf62cd069492ea9be9dfe2112c9a0541954cf2fe1a
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.cigioed
binary
MD5: fcc3d8df58a80d19371b223e0c1664b6
SHA256: e3bcf8711e8c1b52b72b77f6546e2629d856f6eca43a4f16e828610d16b0b0e8
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.cigioed
binary
MD5: bb31331111d1c5a818c7917c50d5de43
SHA256: 0bd77d6087dcab9fb4e1b46388a17a59025f9073b075ca79e6fd3901822eb60f
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.cigioed
binary
MD5: 840391808020d16022d78d5b19943ac6
SHA256: d5f36c71ebd2881772687d15cb95f0ff33e92ff7c0f34c896c94b38665cb94c6
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.cigioed
binary
MD5: d5ecf35f4f104d6e6533d319e325828c
SHA256: 4d7552f73f6ad7f8952b4c21bc22e0aff42caed129c735121a209377a9d48f2c
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.cigioed
binary
MD5: fab44fa6786fca51fbe54d193eca70b5
SHA256: e25e43fb8edf1d4129fedc4085c2bdffeb95c588086d813d11b3f0a27c29fa0b
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.cigioed
binary
MD5: 353ee59ce0ba21e4abeeba6c7daad0d0
SHA256: bc2056f9a8890c364aa663ee4dcf7477e45d390337a03ccc8808404f4f80cfa0
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.cigioed
binary
MD5: 2c37b160fbf55e8595fc44170dbda711
SHA256: ba9b2657cdec8e2c1196da9e5585ef9b785ec171fdd94bf1e87f0ed0ddb5833b
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.cigioed
binary
MD5: e486785afd62ed3bd5156adaa2409e99
SHA256: 8f16f8498f7f77da2859ad5714515db9a28e4aa5cd85ee5a1646884d918ad252
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.cigioed
binary
MD5: 1f59bbfba6f893c5961049ce632ce45f
SHA256: 04f89c4b80d79360c9b7b051053f636dc8e72e192291620836044597b3a7e930
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.cigioed
binary
MD5: 7bf5da6f0126a67d843b6f7e3f72f75f
SHA256: 94b730eb41f04889e0c15ecd8afb933aaa9f0fcdb0b16050772f3c50f8b3ab4c
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Notepad++\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.cigioed
binary
MD5: 535caa95542f1fc92b1217d2730629b9
SHA256: be355f2d3cf9e66204e5595f572d204ebe1986e0d3b6164cb3f1e270183c1283
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.cigioed
binary
MD5: a0a602dd133ff35b2008642bc4b73ee6
SHA256: 833af31aaa1c2140e92043c2abca2ce56e862e055fbdb95b8a13ab8cb96d9742
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.cigioed
binary
MD5: e071fda9bff6168aceff9448a4721fcb
SHA256: bc70e85a89098bc98f8de3d0335b4c6c7328fa622017960ad37c385d29dc7b6a
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.cigioed
binary
MD5: 0a9adf9f4f618887132dbacdd2d7209f
SHA256: 78f132721a04161c7a533719b301df174385ea0aa48bb20263c0cc1cc83860a6
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.cigioed
binary
MD5: 9b10ebd4c994e2bb0e64bb6aec5e2fbe
SHA256: a186c3468ae46a82d221ad722f539cb5af0affacbd31bce54a1addff2e9aca88
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.cigioed
binary
MD5: 14e374c28ad9be3d24c9426570c6cf8f
SHA256: 4e98dacfe69ae19d67444334db00ea40d323af5dca6fa28057339e08e23f686d
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.cigioed
binary
MD5: 060177964f074eb867a2a503543fa096
SHA256: 8609985f804e5266166418cd08b797fcbc44c1c7cda0c3a6336179074511b33d
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.cigioed
binary
MD5: 6d518c3d3df0e38299ce431ef9f903c1
SHA256: 7519e732ef3f714d9b19b08675b9de4ef73ce31f5ef8a8ee49e0f9d77ecd014f
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.cigioed
binary
MD5: 30762abc9d9010cfeca217acbd567190
SHA256: 3b2f128ebc894300ee050c8187391ef6a3ba2ab0c853ad27f3336849302122b1
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.cigioed
binary
MD5: 837a16cfa0d29db4e289eaef6cae040f
SHA256: a16abc3f9a62936aef856518048237690cbab18e6094c0c7abfc1e9029482522
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.cigioed
binary
MD5: 78d4336818dd462ccba873fee05e8df9
SHA256: 364aa2c755d7d80500fa4ba7125b836e3737cd4e01587194ca9f459e344f57d7
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.cigioed
binary
MD5: a1aae5802ee81bea9e77743def98458c
SHA256: f5e171bcab87d3d3045a3aa222692fedbfb57dbb78ceec6b9ff9412be496d483
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.cigioed
binary
MD5: 501d95d620d355f947cd040653215c77
SHA256: a2d6b0cc7ce16a17205c50a6835d141ba1a90264984b2d8ad7a2b1d0f11ecfe4
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.cigioed
binary
MD5: 64e633f3ee97b75d0cc7e88806fc2241
SHA256: 7eb22aaf0de119bad86dd585e6e630b8bccfbf9312d5bba3778ff7be4871ac25
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.cigioed
binary
MD5: 47d8530732fb5000544c1e062e0211d3
SHA256: 06484a6f7d7c81b0915f7c246bcebd622e57384b05fe4de9770bd2c34cadc8ec
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.cigioed
binary
MD5: aa04787ddff87c93afb96b48e97ede88
SHA256: 9070ad235d5de48775459f8845ca07e642d3905bdfc4b7687f9d00b63d4f1ac1
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.cigioed
ini
MD5: 8c8db5ffeaf85d837b5d49fb4d009f5f
SHA256: 9dd55b0d05fd6f1a22143d1dc9891255e3fb836327715f0fda904e6e7ad343d3
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.cigioed
binary
MD5: 1116c2c67fcd7beb11ee85bc749aa2c7
SHA256: 9b5c2f152668dd3ea1a1105ce4356106146ec3c7d0900b141cae5cfaa9b2fac5
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.cigioed
binary
MD5: 71675b0c1c46ed72209e0f1109f47dcf
SHA256: 3acdba045b970a7b7328decee681b800364d1afe53c9949a64f0c3bfe1463875
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.cigioed
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.cigioed
binary
MD5: 0d3545f43ea50fcf895f9606b819a4e9
SHA256: 581f006b033f61e760582d4b9358e1bd0aaaf6c57699b7a040020738e5b98836
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.cigioed
binary
MD5: f87fa46a6062714788190f2801163626
SHA256: d69fd0f4794a89403adf08fdc7766dce98a5298b338ce8660b7aea2eed231c47
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.cigioed
binary
MD5: bc9d15f98df5d8202952e53caad868a5
SHA256: 29591f48c17498b8fe9b13047a13d644b82665f37271d5a992c7b813e1c74553
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.cigioed
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.cigioed
binary
MD5: 05a670c8a58d3b2384749453dbf5ce11
SHA256: 4bc202ff14a6dd2fe33179ac035c3f800fa5b3ae5077ab8d3acfed9e95566bd6
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.cigioed
binary
MD5: da2e40d8c316d04e9c84b9b1ec1c26ec
SHA256: 6358395acdb837c1fd04b4514dd93bd48a78df78b6afcd7066a832089ecf2106
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.cigioed
binary
MD5: c48fcb7c1e2134bb7145600ddf07cc30
SHA256: ad59d87cb925f23cf5144a791c180a10dc8bd6434576dbd7d2e6bc08d05428a9
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.cigioed
binary
MD5: 55a446fff6d1a184127e819db7b9be72
SHA256: 46c9feae4f54693f98209038689b6c45c9aa07b8693b112021eccf38fc38c502
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.cigioed
binary
MD5: 00b913d8f8645334f1f7fdd9f4222485
SHA256: 5bacacc5a7508e67436f17860a1dc4c195365aa5374c6d0c931c0ac1ecf57b67
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.cigioed
binary
MD5: 88c7baec180439ffebaad935d40cd16d
SHA256: 0c2fdb7e3c820fbf6b2b21a37870ae5c5d5e0cd602f11c396b801bb766d415d8
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.cigioed
binary
MD5: 5213d3348a8469c01526881d8a46660d
SHA256: a93a6b93ac7ae1310669ead901fb8365996695d19d6da1ef4a04e799939e88ff
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.cigioed
binary
MD5: 1c977f9178ee91ac22714fc3b48b55ab
SHA256: b1d229d6887a65484b2a94b2c6b9764975ed608c19cbbf5e35b6a552479247fc
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.cigioed
binary
MD5: f8853f9ea2cf3cb90a478fb497ba044d
SHA256: f8a2ae1f658ad0c0cfbc7b0801cc5c3d63124256d7f38f5bcadc41b11995312c
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.cigioed
binary
MD5: f1666293a8ae27e2fb5798d338affac4
SHA256: 91f23e0a93f0c3864fe71de36b6b1d7c163297be77fec761d3603151e61bec72
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.cigioed
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.cigioed
binary
MD5: bf1f9eee77985e1f521e7cf351c025ae
SHA256: 011587c578ff2edc9de3b5e8b7c2fabf4ac3853b295624ce2a73cfe9b3da47ee
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.cigioed
binary
MD5: 19ed8e1127cdd5bc8277baff18d1c7a6
SHA256: 6992649fe6052accbed6b01cfdd68038e0a922ad18318f4afcc6771ad0252a7e
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.cigioed
binary
MD5: d3d8fe29fbf4e7b872e8fc0e742afac7
SHA256: e02c14ed8842f6314a2d0e45e21829555fc833a8c5b137ff079cea13018cfea3
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.cigioed
binary
MD5: 5f3a37145fb67d1c04e10c4c1ea350cf
SHA256: 4414a03773b9c91f317b845eac87d5f19ada61a527af1233d0557f43d71cee7b
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.cigioed
binary
MD5: a124a2c791131cc3d4c360f3258eda0b
SHA256: c3c0d8ca1243ed278d184660526d2777ae0c7f8e83c473e801895f005707db4e
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.cigioed
binary
MD5: ff7458057dc30bbe8e74b73919d7b42f
SHA256: fb265946c0e890d9db136bbf1fe951a784b2e40e240ad392cda6940b78ccf276
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.cigioed
binary
MD5: 62eed7033c250f1e2b05b8eb3482bbfd
SHA256: ab49d4fc8e148adc5bbf76a724907580fe8852aedb4ac70f5779be4464bb3bf6
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.cigioed
binary
MD5: 896a4babfac5932da33fbeeaa0732752
SHA256: 7e7078b4495d36544bb58d746a7a7007a8a8f45250671a65b05c91127b1c4eaf
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.cigioed
binary
MD5: 62038d18b4828e38bc85aa8c502efb53
SHA256: 557640ce05a5f05d80969cbacf3ff96850c114c966be9163cab7e25e356d7923
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.cigioed
binary
MD5: 32e9937e1f3212676dca3cf3103e9136
SHA256: 44784db510774c0d93a2874e799167a2ab2094b72e98ec8921ca416509855804
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.cigioed
binary
MD5: 0d56ca1a57a4b4859d4495f7be27cce8
SHA256: cebe41132ab6f061870c0751e045b0439184c8bfe32e7082eb1e50f0d9163beb
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.cigioed
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.cigioed
binary
MD5: 44a3d748f502b0e30c12a6b2a9ab66ec
SHA256: a581aed02bfdb37514a540ee5824c047e6d7970df51b396b33da6b6b57be057d
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.cigioed
binary
MD5: ce0be71ef0612ec9fefaeda0f64b0201
SHA256: ad015229d6fbfa73f81a5b892f0c264e4fded5532d48360a7d872806db88e8e0
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.cigioed
binary
MD5: 4accd8024ca3886c2097efe63027bac7
SHA256: efa2b818bdbe8ad5f8f5422b3af38d136f2b4cf2b54a931656505a3887cb0081
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.cigioed
binary
MD5: b508bceda566c9ac3befe92c3375486a
SHA256: 419859fa2677a7493da9692ba29dc6ba0883213aecd06f29f00cf9b9e4092f40
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.cigioed
binary
MD5: 8bcc8c6be1b7260ed9309e000cc3f382
SHA256: 6c7d8fe312e5835f03252f52ffb45e9d634eaabd4b87c3f4f2ee972b463af978
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.cigioed
binary
MD5: 66ac3c751b3a23d1153c1110fde39707
SHA256: ab90a17957e9ec4a28bbbbca4d5a082a5dd340b904a320db68da591917966278
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.cigioed
binary
MD5: f0746b55fa7bbdb3f5ca5d6893041b69
SHA256: 79871e2dae391a15221dabe8682f8451810566f2a046659166d52c916c73102b
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.cigioed
binary
MD5: 9da2f61c6261b4fd5c875f2fb15fe421
SHA256: 61bb8a1d7314a58efc477d08ec72eff4e8638d5a57d88584ebcf457a8463bee3
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.cigioed
binary
MD5: b02c6882edf8a35bc8bbe699d4e28c54
SHA256: 5183eae806bf82d7f4c829af100813f0aef0eb606f448c584636892d23f8093d
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.cigioed
binary
MD5: 9c005ed22e900fb6b6a0ad19c4191b87
SHA256: 5f36ac61d578463908060a29674de054992a7578b93928b8b199a840e46380de
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.cigioed
binary
MD5: bdbd14c260b7b829ed26b4dcef673120
SHA256: 6ddaa554b12d735b160c5facf5bcd995ef6f65e2226ecad0b0c0f28458837d36
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.cigioed
binary
MD5: 88574176dd311322f57ed41614176ad4
SHA256: c4beff7cb47954e73c57aefc0ae5627306580cae36ae3c07d2adfbcb51aa38ae
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.cigioed
binary
MD5: b8022f834c3526db077cb6d3d7e892f6
SHA256: b112f7017cd16c23271a3ba6d4b399d53fc0499eac0f5462f8bec00e2cc1aed2
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.cigioed
binary
MD5: a83530fc140a28692a114c8697347bbe
SHA256: 34c74ec367409fb4c7c24241b77161637da02140694933fff1f159655516646d
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.cigioed
binary
MD5: 167b2544e92a33dcb6dacfba149b0679
SHA256: 7ef8787df6c86a2b18c8b419af4034d1b6da6bccf03a9c79be8090512f5bd6ea
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.cigioed
binary
MD5: 9bc726780a8ddd620a1a4e8628112f4a
SHA256: 54d04f948f6a67176c6946a3e15f5bfd0ddead9f1708b3a66b0f583a60e487c7
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.cigioed
binary
MD5: afe5f2e109a1b80125277aba994f09ff
SHA256: 5d3f229312f8294e1c9484166b496f690f7436c92b023ecd8bbdf531d86d8577
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.cigioed
binary
MD5: 3635cf33efd4471c713d321460e64279
SHA256: 3da217aa1fda07cf098723728a537d30732035aa31f84fa9b65c282e19156c79
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.cigioed
binary
MD5: 738496ba0e6958f0e0be5deaac828619
SHA256: 6919daeb026517031d055313caa386448de7edbe82c5997a82dd6e177de7645b
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.cigioed
binary
MD5: c0e4c37b84d7f41e555585090931e98f
SHA256: 197966dca724f75922e4475cb82ac2cdfd4c7898acb1f39dfa00b074146e3f0c
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.cigioed
binary
MD5: 28c662a9179236bd65d0f849426c9789
SHA256: 6ca7ba66cab568ff9ed1eb00382fa63e5112fa7b4a550862a963473dcfd0f628
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.cigioed
binary
MD5: ef12d60e85b59201e3f01a8ebda24685
SHA256: e55a97cb5067ca2185d709c9431c1b3f0ab68d4ae52af4d9a6077874e199b4d7
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.cigioed
binary
MD5: 303222b8d899d82627ba9a7e490ea3f8
SHA256: acf4059b3224c0b2a17f0e5e536e279ebed1d0a041ff008aeb3b356a8c2283a4
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.cigioed
binary
MD5: 22e23ba8f5dfa9d774bf3382db5beb1c
SHA256: 33f2e3de78324f69a1a58b12a9541cee354b77536f35b8ec6947ea3925342aba
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm.cigioed
binary
MD5: a2172402afdf8bd69d6ab6d143749a42
SHA256: 325044ae9bc5d52e8f557a6a1321168598d4e651d0183c1e83cc662033ecb957
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.cigioed
binary
MD5: 67f501329ff5d8d8b543ca40c81bf532
SHA256: c54f1dcb93fd45d26b1ca0af8869950ebd21a9b79255e20c4e121dfe7361273b
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.cigioed
binary
MD5: dbf997507e8f352b19613e3149262d60
SHA256: 7fe30ed0dcc160df2123df5dc6f25dfc4618d1af677b411feaea49b32f60bd5d
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.cigioed
binary
MD5: 7435396bf8bea1bca916da8a0e78d9dd
SHA256: aa24030c11e4d3481e4d462a13412cc436d872c8cab763f237caf8d04d6fcda4
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.cigioed
binary
MD5: 8f2f60707937508f99f1cf01896de90b
SHA256: 56cc0305822c0947a7c5bc15940eac9e7cfa626859a88a44fe0fc1b2e7aa9a23
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.cigioed
binary
MD5: f0cc43cb8c365b2f5c2b896a818267b5
SHA256: c0bb052450871674548f9b6f2c624509c41d81b02a7b612f874bf559346076c3
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.cigioed
binary
MD5: 7cc6ba00e4359a664bd8967d6b9b4c79
SHA256: e04582fd82758fbb3238f053c646ca590180be3d1b7f7e13fd8e22fe9535456d
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.cigioed
binary
MD5: 6eb1df0c621a89404dedc2c3574abe65
SHA256: d107308ee173830e384860cadc14637b55c133ec64e8b51a4a5c9647809e48ed
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.cigioed
binary
MD5: f1280863a1e9589fe8f6177bb0d18721
SHA256: e80f19a86c222b0112cc585f0efb08f1277f6f0680cd76918aadf16203aeab55
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.cigioed
binary
MD5: 9aeeced99cc5c06625f66ab967ce1f15
SHA256: 98d565c5a19016adcbfd9883554c0245f1ffb48bfcfef0935f7e8f4f2bb32110
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.cigioed
binary
MD5: 61ec09662f60563cdc0d32844f44fcf9
SHA256: dbe6e788efef9b8e314b5f2c24ed731ab2fa87b8afc68bddfd3542b9f170509d
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.cigioed
binary
MD5: 4047447b8079d37123d5d63cd45d77c0
SHA256: 68a07ba312ec8fc1796bc0435be9699c9f4e569d6d1e214f1ec893d9af920461
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.cigioed
binary
MD5: 04caf4980fa21fbab218c4ef922272e4
SHA256: ef3c2924f213805cc826e315a49f2100da917d44a8ce87a5e662179f1f15f637
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.cigioed
binary
MD5: 8c549b8d478f0eecec4a3e1161139f9f
SHA256: 6dbce371a645c833542ee164063e915702f3d861bd9fe818973aa5ba39d6f483
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.cigioed
binary
MD5: 672bb16533ff5f657895e697cd9f40f2
SHA256: 2bfff3409e29acee6ce230263d92627481f8e495524c6cb43aa9935010c622d6
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.cigioed
binary
MD5: 29d9368451b9e4c6f6ea01bd9b754465
SHA256: e311e60c6925234e6953a378667ceff1d59d21fff1fbf8fe21d7acabfb511bc8
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.cigioed
binary
MD5: 8ead1515c9b2632019bb1525b7942fd0
SHA256: 74f5d9c68163f1ae7132fa8272eebd5758d62791c8234a3505c9502c654c0139
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.cigioed
binary
MD5: 23ef7e1f9fa142f6e3c23636d8c2d5db
SHA256: f7fe14fbbd1d66e0aa507cc320fa1306e23f0e181d7a9b717f9e7c33f695f57b
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.cigioed
binary
MD5: 4c3fc760c7897a97d6116c9ddafd617a
SHA256: 8bd2729b8eee45230313a8393e8a1cee30f6ef2821d0d36059bde4e24bdcd3a5
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.cigioed
binary
MD5: f45d5cf88088eaff0e75986990e5e6e4
SHA256: cc234be250e8f27109993d67ac748501fc54c8c34a09fa5b40626501ca1cc262
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.cigioed
binary
MD5: d96ddf37cbb1290954f5a0f20c248d07
SHA256: baa8981b136e0b5a6a37bf419431fb59f75bb1f9ee309a7054815e6f29d1dd4e
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.cigioed
binary
MD5: 2ccc076208f8e3f1982ba8a9b7ecab80
SHA256: 9224249bda70add16c05a7ed03bb74343c2f9689b3636e39667067fc59607939
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.cigioed
binary
MD5: 4d6282c948b799b99ab47f77bcb5d3d2
SHA256: abadf5fff87542b4af3822236e7cbe31695307afbd82562cc538e71bc9245918
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.cigioed
pgc
MD5: ba17ecbd73f1760ed3bfd0fab5a38f26
SHA256: 8f66bbe96610a407a6d503d412a82c7d1f85a5c07d87108598db8e5136f9eb21
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.cigioed
binary
MD5: 12e713a1901162a62a1abac54c59877e
SHA256: ead3e6c3eec39472bfd28f1aacb28e4eb8663f32fe4d07e57f3f8fc9ce701390
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.cigioed
binary
MD5: 5f2ba4b9b52e3c1944728bba1b7ff970
SHA256: 14071a53d9d05ebd6901c8bbf4944f3629a6cb7b060e8e93d073f4ff5144a8ac
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.cigioed
binary
MD5: eb7375d3efd539a95b176c14088f2c53
SHA256: f18071d429e36c4843c260a464c77554cedd3d04e1d79aa3f58b11e9a98f2b48
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.cigioed
binary
MD5: 66391d9ad070ee01a36a53d5afb22e31
SHA256: 254fe6614fcae176f6a8a4864119cbf33b3f868abed652438b9044bb23ad65bc
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.cigioed
binary
MD5: 71c0918d8298c23d98b5805e8ebd8267
SHA256: 9fdf3079f4f67d25ae85fb9a815bcba6d702c459d394b94af7aa637b0a94558e
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.cigioed
binary
MD5: 74b23f5ead2f179667efe402d870a060
SHA256: 117d0c7d75484c0debba4cdb3afa6fa06d07a39a701d5f2437ac38820906586f
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.cigioed
binary
MD5: b624c5b441f4f77e8013b08395b9cba8
SHA256: 5bf4d1db314c7972133846eaa6af9e879b3c40d34e95c24e0aba33961e74104d
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.cigioed
binary
MD5: 0a7f2e496fb3acc370d23238d2dd0263
SHA256: 809665d7c910a93feaa520b691a2cf882258690ac96674114c7fdcf1547a338e
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.cigioed
bs
MD5: 320769d943d726d6196d6ab9b7b2b2f7
SHA256: e2517f0eb5e447ec80aa8ca2b5ce8dc23dc2ddd5415597ec1ba49698c0791ee7
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.cigioed
binary
MD5: 1f3fb94bc2b0aed58f54ebd8f95e980c
SHA256: 4af1f5a1b59afcd3e922e6b4de8aa429c2410f1ad850d19e4abdbb0ca7fa15ad
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.cigioed
binary
MD5: 6d79467ef59ac07e835f8d1c2cd72cb7
SHA256: e3d688e9c1e36965cf0e35bdf37065783a519464313c18945ef59fb42c9b222c
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.cigioed
binary
MD5: f0a1dacf7e2381ca3161c02ef2d95bfb
SHA256: 11dae4022b4669b326ae6ab7a4a43ed1404a1171d2ca226aec50e6dd84d0b402
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.cigioed
binary
MD5: b90889824cd4567d18a3bde983e4db09
SHA256: b3edc34d48553fa112b622e340abf73b3aa81320fac25df7de8a3574f0e47175
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.cigioed
binary
MD5: 328d7ccff4dd05c8d89d9159ca146001
SHA256: 23d403d55ca0b254a015821b992852a40411a9e5ae716dff0a006c548c8e9daf
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.cigioed
binary
MD5: f17f895a5370e03138aad0726fee61ed
SHA256: e749bf808efc1c76e4344caa33319689b131e5eeaf8c41f2ef89eb9877f74d4a
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.cigioed
binary
MD5: 259d78d655b5a83830efa16f05783cdf
SHA256: eca07ca45ac4bbf0293a14daafbd0c359085b1f2aca90f177c9c2eac2c8c54d3
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.cigioed
binary
MD5: b8f80bb36c0dace9bab82ab2945f2a15
SHA256: c97e3ad96a3168689ca1fea59f51bad47beb639251f7d42f5f2806e80ea57d46
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.cigioed
binary
MD5: 88403e946a8aebd7e9102ea171b7c469
SHA256: 8eb05a298064511bef683505b9086171a0d3be30aa0f191d6823ef0714890644
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.cigioed
binary
MD5: 3071cc5ae0889349e2f935fc3cf19b85
SHA256: 8cb4fe591f08daf05c07da773014e7865cb053805c13c88a5578aefcc3bb4e7a
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.cigioed
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.cigioed
binary
MD5: e8180d65387d791b83f57da37ac3f2e2
SHA256: 1dd8f1b8f16e9c29e036cf6a5327c65d224668b6871566507b370dbade4e8e79
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.cigioed
binary
MD5: 8499aeb95002cc7b7038bcf3f060034e
SHA256: e191d12fe9f255fc6737e68d6d544136741314b46a0b8873444afc00dc2ba282
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.cigioed
binary
MD5: 7ccd2edc6b991f0485e9ed660da79067
SHA256: b86c24383917031126fec9bb8fd871ca7f683927a422ff36bef59677987cec83
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.cigioed
binary
MD5: 777f2e79138c58289d3599be97c7a8c5
SHA256: e8ca3fd94d102670fc83920bc29e8ed849ff536c2dcaa5af1400602ac0937323
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.cigioed
binary
MD5: d1c75c168a8c2337e2a025ea04e95bdd
SHA256: 3643525bbfeb88be24b137461c349494bf8a86aa212f08cb5f6dc3d4fb31c374
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\f528372b-b951-4b96-84ae-70e097b4ccbe.cigioed
binary
MD5: 6e7bc62127dfa19e32ed1aa464bf4cf6
SHA256: 09000f56b1b45df599777c4e4b0bcfab6bf0536555a83019461a8d4767b35a3f
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.cigioed
binary
MD5: 1cd6d622d4c65af42c35397867f02d58
SHA256: c5bfa23743ec8959d6d0b5f8c154c2a1bad8948d28208eeeae1f5cca0c8592c1
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.cigioed
binary
MD5: 099f51740ae9b719b60e38cefc9e19d3
SHA256: 7c2177d5d165bcbf8c0757758b1dde9cfbddd76afa398b8cc85df2b30fcfcac4
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.cigioed
bs
MD5: e2ebec9c92541c526a123101a952ddcd
SHA256: 3865650e738a6d2c62c9ea1ac8be0a7dcc1bf95ddd15e972b152e65629c2dfc9
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\f528372b-b951-4b96-84ae-70e097b4ccbe
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.cigioed
binary
MD5: 08cb9d579cc7403e6081fd1b24a42acb
SHA256: 9b648b11a3af76037f736ecbaa899bdb2dc0b485995276d64e426a624389b588
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.cigioed
binary
MD5: bd0dec65beb9d685c0ba9ecd96201c55
SHA256: aa265a7dd0644f32c9cb8e347cdd75aec26f635ff789833eebabd3746fda5e8f
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.cigioed
binary
MD5: 9ba5e288928ede46134af284c53c0670
SHA256: 7f1f6c7c099cf6603174b46f9bb9fc0ed8e8c61cff881f6532c4c96d800a3a77
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.cigioed
binary
MD5: 004347282cedd1743a022220dc3bcc0d
SHA256: d4b5e6bbe4189d0d220014bcfc302936c13c1fa1fa84a8a0dcaa4f0db9bbbb05
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.cigioed
binary
MD5: ce1cd99ed2a3a59561c2c1dca8443c53
SHA256: 89a8d85f8c52bc167c11977b32045743d0856d84a8747b9727aae1e72db7adea
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.cigioed
binary
MD5: bf5f93ce74b4c7ee49d48e55f9ed441c
SHA256: 3d13edfdc4baa2af30c60043b4e3a4735b0907e9b72df923a0a46921b755fa38
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.cigioed
binary
MD5: ffd6013164af6ef6d0e9526f995db869
SHA256: d1d4759baaa09010b12053ae19d3d5ae3aedbf4ab32d67603d3928172d642ad6
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.cigioed
binary
MD5: 4c3432a993dc337ff2d81858f38008d4
SHA256: ad39fd0936d5c7f234866b0b8cc8ca79f78f77b05e1d4be99609e2c416c1f1e8
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.cigioed
binary
MD5: ba9ad508d12534a8c0b50b9753283d59
SHA256: 348e6db82fc67130f006456efb788dd454ffee90ea84be569b89a8c24b206ea2
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.cigioed
binary
MD5: dbda03f08ddf10214e04d7903fd3ba0b
SHA256: 9417bd33e8fffe3a1ef38a402adde2c04906beaea9244edd3f69fde04393624f
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.cigioed
binary
MD5: 4382e1d62faee40ea58bd5356b797a2c
SHA256: 89c61260441139997e1d554c5ae3100f5d0599533c0cf2503c2a540418623e21
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.cigioed
binary
MD5: 5ebc867deff1bf3c754b8b5e3a21890f
SHA256: f9895eecd65f9c1e7900f0bb75f5eb529f8a2b836984900b84ee4cbeabc9a869
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.cigioed
binary
MD5: 7ee517cc5ea8197dd5c02dac730c532e
SHA256: cc4172de9752e81184d8d1f52e906c3fe073a8c7d45ca35d7303eba6a1c8fed0
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.cigioed
binary
MD5: 741768778d8d179bc3297c9a9a83b35f
SHA256: 2eede0943c4178383f1c1477d3d269ece09c8f5eb74479fe8a11d2dd32d58256
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.cigioed
binary
MD5: 056d4335b4b119ab0ba6b021ca4dd71e
SHA256: 94a9538be72b6cbb18d038130c6bbec8703efb92cd27fbaeb14620db96a3ebf2
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.cigioed
binary
MD5: fa94cff9aece0296ae92e892974b908b
SHA256: 149f580fecdc6988dc1f484ab4e7f11980aaa8626c2adb3557d6365af6a53f55
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.cigioed
binary
MD5: 9244fcb13629f13f20490a45a18ec82c
SHA256: 923a1988a830ab19ee7ea3b6bacaf03fa2ebe174975bb8e113ccaef1efd210a5
2480
file.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Identities\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Microsoft\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.cigioed
binary
MD5: 07fc5b4d628a03e8cf6a24c06f44bf58
SHA256: 73a093872dd89f3cfc7102f0eb685cab84528a57c3f6f0e5016f00d596e8354c
2480
file.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.cigioed
binary
MD5: 56245733b45a65041806f323595d998a
SHA256: 315658615f034e599430fa7cd6bfb3e08c836e5c1f192f57499ba1717d3e352c
2480
file.exe
C:\Users\admin\AppData\Roaming\FileZilla\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.cigioed
binary
MD5: ce398de9d7b358239f1cb7a91c2578e2
SHA256: 978f5d4e5a305cfcbcb2bf0a0fac3b60628d790dee96fcf2e005f19f79eb2c93
2480
file.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.cigioed
binary
MD5: c5585e1976a5bfffffd0d0bf305ea4ba
SHA256: 099fc925aed99551bcd27f03e773daf0401124b29c0e921810de11fdb4b62757
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.cigioed
binary
MD5: 7dca7a618152a50a0d578d4ab9c08bf6
SHA256: 2ae26f8f5fd10aeec679f7d7d8c27ea9daa0b61c90b8173bd0ae529aeb77fae9
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.cigioed
binary
MD5: dc6ab082d0bb58bf207221eaad0e8ad0
SHA256: 1adbfbf03e28db69d2426c1fbb968e0eaebd418961daae26fc31d00911242089
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.cigioed
binary
MD5: 3592f5fe618df42360847a9c5ae0e73b
SHA256: f66e8f50cdc7ec5477050ac793210860327b8db2cd8809c669a3786ac669dbce
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.cigioed
binary
MD5: ed4e504fed10f8b1b561f7e5cb7b89eb
SHA256: 646263005f89a5ba9e7d0c6a408057a2f4bac8bb75808b05cb1ca1f4d5f194a0
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.cigioed
binary
MD5: 62d8de85ab1a82f6ae5bfbb55fb97a80
SHA256: f59472ea81e3293fb99251c948b0f93ba866d0419735cafdeed33e00702614a1
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.cigioed
binary
MD5: 9c7071d693624f76f6553e6826f07a0f
SHA256: c8cf71ecb66aa3ad484611a8fb90b30f35f1a2bd384ab730cb3dd1fcb2696668
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.cigioed
binary
MD5: ef3896ec81afe932c4643334832efba2
SHA256: f527caa5600c34777c86b5863fc5f16b731d013ebc16896e6891a0d184a57a2b
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.cigioed
binary
MD5: 41112bc389c72371bd7a559edc84cf4a
SHA256: 5a56154f23bf759a367fad2ae8748ed3e7ccbbf9d3b9575b0275030599de2a1a
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Collab\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Forms\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\Roaming\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp.cigioed
binary
MD5: 758ed131c9aaa8f537f5f1c848157d0e
SHA256: 15113ee1c7ca2ed8911225feb8bf045a2c1167e65b6af379e5fb0e57914043d4
2480
file.exe
C:\Users\admin\.oracle_jre_usage\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\Users\admin\AppData\CIGIOED-MANUAL.txt
text
MD5: 18cb9572c4ccddbd74c14e62d1cae705
SHA256: 366e68f668820c2d78c8c9e6fa0d129fd3666a6c72fc56f12a08f76f1676bd95
2480
file.exe
C:\System Volume Information\tracking.log.cigioed
binary
MD5: 79160073d336aab1296e44edb6a6ad68
SHA256: 9470a224634a7d6bc14764d39899dce89e7af175ed48f5b134131da47283a3e1
2480
file.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\tracking.log
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_WindowsUpdateInfo.cigioed
binary
MD5: 9be2259c5535335e9f2f6d00a78b7d4e
SHA256: bd5602719ff93e81dd94d19c8cc0fd59cffa150abcb101a5b16cc770577a272b
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_WindowsUpdateInfo.cigioed
binary
MD5: 8d220af0283a72e554892ac162d8996a
SHA256: 6dfcf5b12f54e977fbd9ad8db353baa721c88846727f678464eb2a5ed42dd559
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_DriverPackageInfo.cigioed
binary
MD5: 5bfb257e51ff0d797656bb5673f3ca5a
SHA256: 9ea33e4f0ef6185940b2a403a794b53b626d43aeb82615187775c2caa9a8666a
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{FC5F241B-73F6-4813-9D64-4E4F00D39C97}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_DriverPackageInfo.cigioed
binary
MD5: 1f0ff1405b45452a6c4fe4ef2b61e956
SHA256: 8b9eaaadfbc28e96f700b76a47e382363a1a0a58236da955c069b609ec221909
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_WindowsUpdateInfo.cigioed
binary
MD5: 7c2122b35596dd764c3714c821f29a73
SHA256: d7ad0e0e39feca9351da8c09af45340d6a9b7cedcf623504c6102842353840e2
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_DriverPackageInfo.cigioed
binary
MD5: 82c986536e83bede7d1f31ec752d747d
SHA256: aaf28475ea1864ddbc01a288586fbc3febf3a884dab5d19f10ebc423a6a18cfc
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{FBC1D708-BE70-4DDF-91EA-C05528F7BECB}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{EE321E85-0E9D-4572-B152-5E2DC9F9BCBE}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_DriverPackageInfo.cigioed
binary
MD5: 52eb7d8f15b6d12310bd1a9900f9cc27
SHA256: 8e01ed9a490dd146eb771516d9ed91b0079e42b7c10e68f7193a5d5c678e1f22
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_WindowsUpdateInfo.cigioed
binary
MD5: 5ae5b6a9e954544057cd7c4b5a4df9b6
SHA256: 95c656c2203592c9fca812cc68404b9b127817606ebb47ab60ce4159986cf46c
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_DriverPackageInfo.cigioed
binary
MD5: c85433c022402f164d006bd9deebe0d7
SHA256: cb5c76c4937a78457973c06b6495e91407645259f8b14431cd9177c43e36068e
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_WindowsUpdateInfo.cigioed
binary
MD5: c7eff25644563a6444aec5454f2e5c0b
SHA256: 205b04f16e56743fde1601a6b25f6342854c492b3612cf91d51298af8454af60
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{EBAFCF70-55F1-48BB-822A-5412291C8B75}_DriverPackageInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{DE4FB673-C96D-43AA-A06E-DB0853B54BFA}_WindowsUpdateInfo
––
MD5:  ––
SHA256:  ––
2480
file.exe
C:\System Volume Information\SPP\SppGroupCache\{94E6C3A2-599E-462D-9C45-78274DADED0C}_DriverPackageInfo.cigioed
bs
MD5: 4f12cb1700d980bd2d541c803f4b0f7c
SHA256: 6c209ac40c9bbe8114dc962d21b2fe747986067805fd84d9f9f4226580e77b57
2480
file.exe