General Info

File name

word.exe

Full analysis
https://app.any.run/tasks/58875dd8-235b-46e7-b770-9b3fa132949e
Verdict
Malicious activity
Analysis date
3/14/2019, 19:42:30
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

gandcrab

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

25dc3086de8bdd780b89b0a7cd9d51bb

SHA1

9d12a67507e8f7df1e060ecbab142205db18dc2e

SHA256

c50167d9a899572e7dba0da1d80e3b9a94b2d3803a8f125119097ed5f92add6d

SSDEEP

12288:fYehPy/HhWunPurNYJ3rwcSARLgBNh8vGI8o6w6GqVIABosrLt:NPwnPcNYJ3rwcLRLgBNh/I8o6hVITsrx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Renames files like Ransomware
  • word.exe (PID: 3464)
Dropped file may contain instructions of ransomware
  • word.exe (PID: 3464)
Deletes shadow copies
  • word.exe (PID: 3464)
Writes file to Word startup folder
  • word.exe (PID: 3464)
Actions looks like stealing of personal data
  • word.exe (PID: 3464)
GANDCRAB detected
  • word.exe (PID: 3464)
Reads the cookies of Mozilla Firefox
  • word.exe (PID: 3464)
Creates files in the program directory
  • word.exe (PID: 3464)
Creates files in the user directory
  • word.exe (PID: 3464)
Dropped object may contain TOR URL's
  • word.exe (PID: 3464)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (67.4%)
.dll
|   Win32 Dynamic Link Library (generic) (14.2%)
.exe
|   Win32 Executable (generic) (9.7%)
.exe
|   Generic Win/DOS Executable (4.3%)
.exe
|   DOS Executable Generic (4.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:03:13 14:26:40+01:00
PEType:
PE32
LinkerVersion:
9
CodeSize:
316416
InitializedDataSize:
373248
UninitializedDataSize:
null
EntryPoint:
0x35342
OSVersion:
5
ImageVersion:
null
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
1.3.5.5
ProductVersionNumber:
1.3.5.5
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
LegalTrademarks:
(c). All rights reserved. djsoft.net (c) 2003-2015
Comments:
Nullable Arsenals Identifier Addpackage
ProductName:
Custody
CompanyName:
djsoft.net (c) 2003-2015
LegalCopyright:
(c). All rights reserved. djsoft.net (c) 2003-2015
FileDescription:
Nullable Arsenals Identifier Addpackage
ProductVersion:
1.3.5.5
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
13-Mar-2019 13:26:40
Detected languages
English - United States
Debug artifacts
X:\nata\ten\ten\release\ten.pdb
LegalTrademarks:
(c). All rights reserved. djsoft.net (c) 2003-2015
Comments:
Nullable Arsenals Identifier Addpackage
ProductName:
Custody
CompanyName:
djsoft.net (c) 2003-2015
LegalCopyright:
(c). All rights reserved. djsoft.net (c) 2003-2015
FileDescription:
Nullable Arsenals Identifier Addpackage
ProductVersion:
1.3.5.5
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000E8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
4
Time date stamp:
13-Mar-2019 13:26:40
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0004D2E6 0x0004D400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.63879
.rdata 0x0004F000 0x0001D1B8 0x0001D200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.39939
.data 0x0006D000 0x00005338 0x00002200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.72215
.rsrc 0x00073000 0x0003BC54 0x0003BE00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.152
Resources
1

2

3

4

5

6

101

201

202

203

204

205

206

207

208

838

913

914

929

967

982

983

990

991

995

996

997

998

999

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    WINSPOOL.DRV

    ADVAPI32.dll

    SHELL32.dll

    ole32.dll

    OLEAUT32.dll

    AVIFIL32.dll

    MSVFW32.dll

    SHLWAPI.dll

    COMCTL32.dll

    WINTRUST.dll

    OPENGL32.dll

    GLU32.dll

    WINHTTP.dll

    SETUPAPI.dll

Exports

    No exports.

Screenshots

Processes

Total processes
34
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start #GANDCRAB word.exe explorer.exe no specs explorer.exe no specs wmic.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3464
CMD
"C:\Users\admin\AppData\Local\Temp\word.exe"
Path
C:\Users\admin\AppData\Local\Temp\word.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
djsoft.net (c) 2003-2015
Description
Nullable Arsenals Identifier Addpackage
Version
Modules
Image
c:\users\admin\appdata\local\temp\word.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\msvfw32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\kbdus.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll

PID
2860
CMD
"C:\Windows\explorer.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
2340
CMD
"C:\Windows\explorer.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
3836
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
Parent process
word.exe
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image

Registry activity

Total events
107
Read events
103
Write events
4
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3464
word.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3464
word.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1

Files activity

Executable files
0
Suspicious files
414
Text files
314
Unknown types
9

Dropped files

PID
Process
Filename
Type
3464
word.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.orgxtg
binary
MD5: cbc4ca7cf32ba21b8ba56e2692832c28
SHA256: 6af57f941b315d5141ae9af044a968205d434c8c8041c5d0b50bd09a3654eab1
3464
word.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.orgxtg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.orgxtg
binary
MD5: 248678259f9edea3c5c39400972a45fd
SHA256: d1cfcbdc06aab9563a4929cc47dba4a2770117d6c232fe6b5ee0f9b5e480ba5e
3464
word.exe
C:\Users\Public\Music\Sample Music\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Public\Libraries\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\Downloads\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\Favorites\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\Videos\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\Pictures\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\Documents\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\Music\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Public\Desktop\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Saved Games\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.orgxtg
binary
MD5: c7c721de7e3faefb33762d5fd8b0d4f3
SHA256: e8ca134dd6baa41f61f374ab142a56e2f54fbd952940d204f95954533668cc7d
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.orgxtg
binary
MD5: f9cc3071244b1ee4ae30862fe0885af5
SHA256: 2bdba5e7a13bd7c4e9cb1b5f005da064abab87dea938a0f911703078fc2340ab
3464
word.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.orgxtg
binary
MD5: 6b77999323880d7206e89321832977c8
SHA256: 02e83aa094ba9dac7842a57ca217b4b14fd220eb51c058d84161ea5b7d1c1063
3464
word.exe
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Default\NTUSER.DAT.LOG1.orgxtg
binary
MD5: 11466eb0b12ad72fa774da3bfb8796ff
SHA256: 2c13b934f75cefdba77d6520cb70ca83ff18f42972a7de9cfdc578b388e77b0b
3464
word.exe
C:\Users\Default\NTUSER.DAT.LOG1
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Links\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Favorites\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Downloads\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Videos\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Pictures\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Music\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Documents\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\Desktop\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Media Center Programs\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Local\Temp\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\History\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Local\Microsoft\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Roaming\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\Local\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\AppData\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Default\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Searches\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Saved Games\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\ntuser.ini.orgxtg
binary
MD5: dd0401bddcc35607bcdb92af062c904a
SHA256: a4ae67b5417d7f7b12dbecd6ef4b9e23c5ae3173aa7e0411f959ef694563250c
3464
word.exe
C:\Users\Administrator\ntuser.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms.orgxtg
binary
MD5: 731769bb23e37567d4a2b585fb0bd31f
SHA256: d03fa7da6422f3a53b1c88b8584dfd84a2581edf01048f08526b5f0d50b56f83
3464
word.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms.orgxtg
binary
MD5: cd6b0e33b50ebed19a5908c2b2e35911
SHA256: 9a4e4dc3728a9ba9ad5a7beba667e08aea5a8402c4d567f82a5187a2cd2edca2
3464
word.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf.orgxtg
binary
MD5: 7ae003d665bc4d415766dc9539a5d7e4
SHA256: c29fc5797f2af313c621a26133522244e01cfaa3d51f70d7a2ac9eb72761d4eb
3464
word.exe
C:\Users\Administrator\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\ntuser.dat.LOG1.orgxtg
binary
MD5: 292a0523458543a3958f632ac3d8a193
SHA256: fc3be6c04d38bfce6fd26e2a7fb7e547018f26e34af797a03667430160889442
3464
word.exe
C:\Users\Administrator\ntuser.dat.LOG1
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url.orgxtg
binary
MD5: 7deff874bc0663ae0b71ec07c909b36f
SHA256: ce7fc93435fe744cae1d0d69f0f6bf9b7161fca41d0120237f15217b4ffb118c
3464
word.exe
C:\Users\Administrator\Links\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url.orgxtg
binary
MD5: eedc40771208848266a934dfb4e48f39
SHA256: ae93176d801752877883e94792224d0e28f6ee70e1f903f07f90902d21d68bfd
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url.orgxtg
binary
MD5: 5e8e3e1f0c71a44ea5dca94b55870960
SHA256: 62a615996ca9159416d85bf03bba85d0d73a04258b6669aff7f37a3ed05af8e4
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url.orgxtg
binary
MD5: 5673d1c7af7662fe42754b0722a37d29
SHA256: a7a430c7372dc065070bce621f8b64c670abbfb69fd9b9d623e6db401df5f88d
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Windows Live\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url.orgxtg
binary
MD5: 538ad3baf29f74129653002d4faa3630
SHA256: d1d425f2020056cb6a7f79cd71153100f452278eaf5a803cb80fddb950428352
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url.orgxtg
binary
MD5: 470d837a25a610413ab2d7b17a3476db
SHA256: c81255534d25d93a3604cad904d486214fd9fce9930cb49da39eb371e76aea0c
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url.orgxtg
binary
MD5: b20576bde2fb2c6ab4a3393cdc15c71e
SHA256: cbac6999b7398adc21e53fde21023421637fb0a0f64c004ee063633abeb9c34c
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url.orgxtg
binary
MD5: 993f0632a76580114ecd01cfc7d9a8cc
SHA256: 463c49517b7cba0c70a1da09ee86dbed877000654c8f0b7586c78e1863982d48
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url.orgxtg
binary
MD5: 3548ed313ea464685a64b3a6164c5965
SHA256: 43f804acefc925c64a0adad7d7bcc671e2dd5bae4bad8f2686a6d350357ad255
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url.orgxtg
binary
MD5: c80b8c8c52b7546f8e0c74fd1f4c8b54
SHA256: 3e5309b53dac1f465688f780a234193515b8d00347fc1954c8ed2336cb911bd8
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url.orgxtg
binary
MD5: 712f00823fc31b769eda1e8d365bb3bd
SHA256: e2e3748d2dd2f1b27e0131f6898246057009b6c19bf01af38220a8a588356caf
3464
word.exe
C:\Users\Administrator\Favorites\MSN Websites\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url.orgxtg
binary
MD5: dd47f34baf29afab16a0fc5946f2282f
SHA256: ec813491172a4bc3d00fdaa9a59ae9c35dbb20e128d1d9b2d03f1898c53d0ca4
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url.orgxtg
binary
MD5: d6f00a2bcbbed0d6d456972568e5d1c6
SHA256: c83ab8af91f97f0843cb7a24f61f9e945e066351d1d78e49e39b553d3b19b4e2
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url.orgxtg
binary
MD5: f6ba18385887c9054f2986f3047027d8
SHA256: fc5557ce5dcfc4858f8867399c5d1b358e791f8f02499973301216d498c34e06
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url.orgxtg
binary
MD5: 191f138ae6dde3ad05fdd46e7d5c7b3a
SHA256: 539b73966122aaa03d15da7b89053b84b71645076c62146e1bc2a1f781686a99
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Microsoft Websites\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url.orgxtg
binary
MD5: 9e27094554d04c699941df5c7d1e22ee
SHA256: 6e4ca87ae55635431d34e28b0f136049ce132e1b505f1703c7257ea18f0cf969
3464
word.exe
C:\Users\Administrator\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url.orgxtg
binary
MD5: 806f2e53d3f6413d95518592c4f1e22d
SHA256: e2bb05dc53063a8ad8dc26403882fbafc3f67c730d9c8a3cda1d2268401247b6
3464
word.exe
C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url.orgxtg
binary
MD5: 8ee8be2572972a1cc4ca4bb668fdf5d1
SHA256: ba698b1645b61ab74bb44344254e25142c26742c173e2300f1ce00461c294375
3464
word.exe
C:\Users\Administrator\Favorites\Links for United States\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Videos\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Downloads\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Favorites\Links\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Favorites\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Pictures\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Music\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Documents\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Contacts\Administrator.contact.orgxtg
binary
MD5: 63c0f38cde213f04100c401c19e10044
SHA256: 16ed3e72e5a124db06a3465da58ebab7df38c62652214b6501501e597adb603b
3464
word.exe
C:\Users\Administrator\Desktop\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\Contacts\Administrator.contact
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\Contacts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred.orgxtg
binary
MD5: 2adec721698955648ebaf6d0c3981273
SHA256: 6ce1c86ca466b2466a2c6b5fce72c3923e8cc7d4101825d176869efc258d2ce0
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\Preferred
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156.orgxtg
binary
MD5: 513f4f010577995c9c32441f3ac9d0bb
SHA256: cd900a1b8cefbd93574237d5b28955896c3d3722b3192e36a7bd8c443fc93c8f
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\e772058d-056e-4021-b783-db194666b156
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST.orgxtg
binary
MD5: 126fe5db77d20a55ae37e43a57f6ced1
SHA256: 171904a18482f24996a8d8340a11cfd105741c3e1b94eecd4efb679ab3fac8d9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-500\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Protect\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Credentials\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Media Center Programs\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Identities\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Temp\WPDNSE\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Roaming\Identities\{BA2162A3-2F32-4850-8D8C-B3C9A2AA9D43}\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log.orgxtg
binary
MD5: 05f4057bbb60b01b2e2d5d0e950684cf
SHA256: 198277b2ca2209d7a81f3146025e22c841284739020daaf49b8a6006474e73f8
3464
word.exe
C:\Users\Administrator\AppData\LocalLow\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Temp\wmsetup.log
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Temp\Low\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp.orgxtg
binary
MD5: 814112eea9400e781e92720d0a4ff898
SHA256: 06372e7abe17b1684206dfa3c8995bd3b3617f1fe369fb5191bd24ef2cb15b13
3464
word.exe
C:\Users\Administrator\AppData\Local\Temp\Administrator.bmp
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini.orgxtg
binary
MD5: bd2bf185ce2d655a8aac2270dece32dc
SHA256: 17a088ed397447c0b4176bda0260362506e911bbb467bfaa971749f79cf0ee54
3464
word.exe
C:\Users\Administrator\AppData\Local\Temp\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Sidebar\Gadgets\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML.orgxtg
binary
MD5: 5c29d7f5d077c2cf18d24cccbfaeaf6b
SHA256: f14e66d4013f917546df627d008a3366d852ca4d7bff9c1483eb5eb8e98d485e
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD.orgxtg
binary
MD5: 9901ed5358b53aa2372f07d2724e574d
SHA256: de9bfe461ec5871e38e1762c48952aa432ff7ff68aa64d74d84da37b836ce022
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat.orgxtg
binary
MD5: 8167880f614829daa50f264941e257ab
SHA256: 492596d5cd739a59e21c3acde865e023bc5e8fbd3c03befddd7a001a340f3c5b
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\12.0\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Media\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore.orgxtg
binary
MD5: 25c3689a95e202bb4eba70ecfc5639a8
SHA256: b7e6b1bb36b939410f90a972ab66f35e748e9a2f78553ed85c2d841c03f61fd9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif.orgxtg
binary
MD5: 15caa65bf2ec179424ad0d2cffdd5379
SHA256: 52b8d268b8081a53b1a8ae2d7f4d1112e9e5a438bfd18877619d849d590527df
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg.orgxtg
binary
MD5: 6d866046baa5f4559bbeba27c9a27094
SHA256: ea08ea50abb72c1ca75b12bd5e2d109b216d521f733bfc58b91a9355a8cf7ac1
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf.orgxtg
binary
MD5: 13e21e031fd36dc23837cf7b474f92c5
SHA256: 3230fa449f042db086307252e94b6706b85c4b3e27b2701407498889d165b0ed
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\To_Do_List.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif.orgxtg
binary
MD5: f52c444731de9525b05e9026519828ed
SHA256: 71054be8c04f7a0ed7ac0ee4c61bb343dfd6187bc2d55b7ee64e4731ab96dd70
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg.orgxtg
binary
MD5: f2da7a56077050349576d4a6d8cadef0
SHA256: de365f941dd86049a7e53eb7683df2ee33a80af543f53ba27e0aa6653c429475
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Tanspecks.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif.orgxtg
binary
MD5: 7bef5a8b8ae123fbd7629cb62569b276
SHA256: d2e098f202d1fe38256ba95e7f26be225cfb737475a34785f2cf2daf6e964b78
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.orgxtg
binary
MD5: 223259425ade103991a99469ee4977f2
SHA256: 4d32cbecf1794a8e2da1c09420eed610a0177f1fd2ee0180346e9283ae8f5934
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm.orgxtg
binary
MD5: 1d8800743f8dda83bc44b3a5f9090ad9
SHA256: 9e39488cd0e3d45e99aaf800c46bfb9d68471534be86bd982ae7e1e71254d4e2
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.orgxtg
binary
MD5: c02d2190a10afdfe90e88d08ebeca402
SHA256: c93bd7c276a42ad354a16a41399d9d63f2f338cf891aceb698c3ebb61007e7b1
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm.orgxtg
binary
MD5: 6ef6d98e1a74beabe47417e92c336424
SHA256: 4957f9baf07089f599bd21eb4847ffb7b7141e138ff7eaac2bae5f237ec36a19
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg.orgxtg
binary
MD5: 325c423973a03e37482b2c124aaf6204
SHA256: 4c64fbd86796f8f3562bdeadf38b3ecd72a6dddddcdc6c44b6073e27f7a85f83
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Small_News.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf.orgxtg
binary
MD5: 5991391748cf37edf273fe6f02a23247
SHA256: 81c11f0b011da9dba172eb35f2732b116ef801870a215eebeeb2b6420790e24f
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shorthand.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.orgxtg
binary
MD5: 8b8be8f66f66cdefeee34869bd384a6e
SHA256: daa21c1c8249641518abeeac04fe186f60da4e5522845f305fc41e6664df40f6
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm.orgxtg
binary
MD5: 065a4cd0a52634ed9d4fe540c2f4265f
SHA256: 23fda252b411e27269f9d955552b645b0e6360740be2e5cbc56fb8271b1dfacb
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf.orgxtg
bs
MD5: 082e1e1615877984d4bbf1649b3c7a50
SHA256: 48e5fd82004c0dfd2b690843a6798f892d2124ae226e89eaacd2a3a2532fdb2e
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Seyes.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg.orgxtg
binary
MD5: d97c99947274890d1694b40697a64b2e
SHA256: ecb5665917eb53aa427b9f1aa17e30adffcb1a36b47c50cda0b2a380c9fdea99
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.orgxtg
binary
MD5: 5bd7803c7c29476f4502736b3fc8a418
SHA256: c38b19387dde096ad5132d69c18dc6424a3d178f0e687c7d9dc54a9317f15f62
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm.orgxtg
binary
MD5: 8ae3d8109bf2dec94bbf4050a06c5e71
SHA256: 7c251557cde89cb2ffd8c27471f82f90ab98d8b606d3816da9f4344ad6083aa0
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg.orgxtg
binary
MD5: 920383fb39236a88cf533d42cb57b51c
SHA256: 357a819e077e3d02c1782851e47dbe0dd2257989dca473c9caf32a5b0ef279f9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Psychedelic.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg.orgxtg
binary
MD5: 82f57213bdc2b14cfcb597678543c25e
SHA256: 962b92b8c0b11c9943df647f50d18b38346a07a1e7def46f14a329672338ad40
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg.orgxtg
binary
MD5: da092cd0944a8877939d13d800645922
SHA256: ce6e10f76f9343c66fd5ef4ed1aff768eb045450ed3a070260b31d5a1d573dc6
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.orgxtg
binary
MD5: b3383d78b36c66867fa210a912b9bf2a
SHA256: 1a0c182d28c8506675508b21c20a6a0fd3cd29aad7a51071d339b74919508fdf
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm.orgxtg
binary
MD5: d6c2e9e81d9d9b5c9a0ff0c17de6725b
SHA256: 64c4d46ebaff4cc2714d803b50d89f4bdf13c68d3a0411848a77e792d148fd2e
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.orgxtg
binary
MD5: fd2f79dccea6cde9fc473c826273e2d0
SHA256: d5fc6a6fe39f7145d64df1a27774541f206dd7333b3ab1509291abb5be48c113
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm.orgxtg
binary
MD5: 0ffc5998f1db60485b4538cb20493ad1
SHA256: 06a1c050bdf158b57e180d1d07306c420b172c013a4194fee961ef2fa47f52ee
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg.orgxtg
binary
MD5: c1500a87a636d570b99560ae37973867
SHA256: 6b7f14149c090cdf912189ff8ec2ce56a1a79f37c901f4af707812c36089632a
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Notebook.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf.orgxtg
binary
MD5: 005c63e19a74d5778570e4c048816b83
SHA256: d753206d76ab39add3a58f2d8509b9610f10b2252973e1137dfed09df9d66dc5
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Music.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf.orgxtg
binary
MD5: 143d4e8a0e2191bb9d6a34ab38e7a5f5
SHA256: 7c8656ba2ef2503f11d447c4a6856ca905faf46873266cd0d7ba80d76761d772
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Month_Calendar.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg.orgxtg
binary
MD5: 5f2510e2cff3bfe57eb725f50d738ff9
SHA256: b4aff9d4c7b68601dcc320c6114adeb163b9bc68f10dc970cf81f6fa3940b4b9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Monet.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf.orgxtg
binary
MD5: e62c3e9387d480b8a225a7674cefa229
SHA256: 69a13d2b3d0fe6d9a29e5d1a1fa92e54dc28453250105bbe1e81fc364d0f2828
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Memo.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.orgxtg
binary
MD5: 9d08511bcc3bdc75b8035ec3ae9ada6f
SHA256: 4f932cbdecf2a1774b8877d4d0d3a2d858b86eb484b62f004448631bdced1d0c
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm.orgxtg
binary
MD5: 763a02d76550b15d24e8285aa8c4b3ca
SHA256: 5a860d2a7d18501864992e490553b0c1f1e47f1268316a0b210c95f8aa3ce6af
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf.orgxtg
binary
MD5: d0dca8c2e1f20e18bd02fcb67e57e6bf
SHA256: cd6cd1db28e419db95d92d39291a111f3a5376bd8e823a0108ad3a60ffb33944
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(inch).wmf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf.orgxtg
binary
MD5: 3c01b1aa81b6ca9fc44283f9c3eb860f
SHA256: 4df5ba1267cbca96cc3660f284a7510ccaf65f37763834b231dc8e37927a68e7
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\grid_(cm).wmf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.orgxtg
binary
MD5: caf2990a1fe2cc1806d8752030d96f43
SHA256: c4dea751674e89fa287b45120b4917c20f69b48b41a2c64c628c8312df13789f
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm.orgxtg
binary
MD5: 17202626ec6a1b574af38ad4ebb414a3
SHA256: 2bddf687896fd56e2d8ff2919eb70809fbfb2831d3a11e453e27e6891bfd2325
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf.orgxtg
binary
MD5: 21370eac35be2bc68602aad261af4540
SHA256: 4e580374c885da1eb338371188aa49ba25bde4af0d0d8b58d2e40ff9ecc4435d
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Graph.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf.orgxtg
binary
MD5: 268c5f39384c6dc6c2add933ad05ddbb
SHA256: e32c10bedf8a6f05ff881f5efc998344d899489c84188ee5f2434d19c762a72a
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_2.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf.orgxtg
binary
MD5: b521e016c1d7549b0fd95fc3ade6a4fc
SHA256: 6c3e58a557733cfcb7ee41515ad329cfc3c9cad4edb6b943ca0d9d16b3f570b5
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Genko_1.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.orgxtg
binary
MD5: 0a8f04ee484eada883b23649624a2701
SHA256: 12e2b51510e5d35d0a5bb6222d573e97937fbeb8b30f43700bdb497bf2dd718e
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm.orgxtg
binary
MD5: cd013fff9255cb47ef3142c22e6fc6d5
SHA256: a83695ef12fca978893a73da497d8c3d4222f7786abe599ce4f784c4010099e6
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf.orgxtg
binary
MD5: 14e007ead7a3bf1b32500c41d6c84ff3
SHA256: 1283656a8700c78645a3bd50434067bdbb32a1837c9ab0d5886eafd265e9d0bd
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif.orgxtg
binary
MD5: 844e4e8a5714638dda91764d7ddee576
SHA256: 8f05e59458a7d8cae9e5901fd06070f9d8217646bd8df7c4295915a9231137da
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif.orgxtg
binary
MD5: 09411d7d7141523ec41db8d27396548f
SHA256: 430577fdfa9831f0b4ff4beccd52198d9370f62a704b057eb62ddfc06cf933c4
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg.orgxtg
binary
MD5: d4808a669bd1ee7539235b3fc79dcb5f
SHA256: 6b1b664e174b1030c6c81964d2dfcaf7dd67184b4d15c58d2082f2a8fd08218e
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.orgxtg
binary
MD5: b9a09ba25c1a89419ab9b8f010771c79
SHA256: 940eb6a8590de93d93fcc80836b077692ddc136cd2f00c7eb73eb8f07a0cf695
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm.orgxtg
binary
MD5: 101c82c0e2e75b28af56024c1f0944e5
SHA256: c2ed0b9300ea84f3cfba701dd8a16077c681a0442ab77a81018db5becea0aa7a
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml.orgxtg
binary
MD5: 53ef6f7e86c1372715108674ed0a41f0
SHA256: a43854284515ee849f6592688388e46094806eebc7049402286e0ae253f83175
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Stationery\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\oeold.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs.orgxtg
binary
MD5: afc34a5cc6e4865756b5b082d507b560
SHA256: 2f2b59042c23ee172da87a408d7a7d348e16c58187961b369094fb1e65b87a29
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs.orgxtg
binary
MD5: 7bd3f7fe5ada2041de05f611b9351a41
SHA256: 7e9fd6f0845d061b7b95d2b5a78e1d0383ef0256dd017b0a1668f12bbd75f1e6
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log.orgxtg
binary
MD5: 5b8622517b45e17a64d33c8faafa8118
SHA256: 981fc78441d7b5040150d730107534c7a71bb8a62c82f7c3e5cfbdcfd1c55869
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb00001.log
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log.orgxtg
binary
MD5: 41e5c70a79aff290952dea0bc3aa0375
SHA256: 1437a26b3aa0c60938af7fbd9649f79292f4fe65fc37ba8898b7aee638061110
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.log
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk.orgxtg
binary
MD5: ed2777ffec4aed4c3896a09b6af19b81
SHA256: 00dfe7ed79766c76844f58ccfad73153da3b140154f70df4cbc91c736e6f84fc
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\edb.chk
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat.orgxtg
binary
MD5: c853c965284f525c63b1f80e5e6066ae
SHA256: e110d58d2cf212582d66288f5f1f688f3959aff046a09d4c639982e2fb224c7d
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore.orgxtg
binary
MD5: a33759af7e13fa460e3bf0c6c1a310a2
SHA256: 034eb5074c718ea5e3b65b885a303894b9ca997eace072487ce48fcdaafcc2b3
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log.orgxtg
binary
MD5: 89479011230479fffe3dcc6cddacdf6a
SHA256: bd52765c271fe0bad177eca51f4eb3c063528da5b09be715b811e11bf409d815
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\new\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\Backup\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount.orgxtg
binary
MD5: f5f9fc10012fc08b605f8765e70edb2d
SHA256: 16f2fa075cbc98f47042d1acc6745153a36417eafb3c54efdafb20c9bad84510
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{CBB626B1-8A75-4171-911F-13C42949168F}.oeaccount
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount.orgxtg
binary
MD5: fed02f19729b6628a2b71e5fcbc03576
SHA256: ca59630a76332991c7effcc1a03a88d0a66e4ca07e08f1a5f14294b139badace
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{C6756DF7-BE4A-458E-9C7E-535BEC29FB9E}.oeaccount
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount.orgxtg
binary
MD5: ec3ced5685d0140d381f36a3a360849a
SHA256: ab5c58a57b4efea9beab07d32617bf40d2b045849df4d5fb621b2bcb839a9190
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\account{A9BA3523-71CE-43CF-BD95-F75C31E87D1A}.oeaccount
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows Mail\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl.orgxtg
binary
MD5: e81f77fd6015477a55dc724268dd850a
SHA256: 6964c8b2bd3f41c5dabd84191056061af59c899b1deba16ed9663a8bcdee81b7
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\12_All_Video.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl.orgxtg
binary
MD5: efca5874b080823879f7acfff250030a
SHA256: 1199ad180c6ad4ec5ddc9e7ea3fbe65924aa85d1e86fd41c74c5e0a26450b517
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\11_All_Pictures.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl.orgxtg
binary
MD5: 75d63e90d482b2ecfa579dba616aecc8
SHA256: 5cf3f98e9217656ad6c5e96862615223a6cfc220cdb9cb8a0cca9759e3cfdc3f
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\10_All_Music.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl.orgxtg
binary
MD5: e3960fa1e1b387bade45267ab9b4925b
SHA256: 7a1498e35f89d944474babf3fed039727b90501c40a32bd87891b4f88159e084
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\09_Music_played_the_most.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl.orgxtg
binary
MD5: 57553e49be1d44e632657a0fced64ee7
SHA256: e2cb6a7f4dc9cd452a02cd2bde6c0d7ebdeb5046824b37c05745554abf715df4
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\08_Video_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl.orgxtg
binary
MD5: 23adbd9f938938b553960fe79eeaf14f
SHA256: 2df2fcc90095f5106b0f49d7743e50389d154069fae23cd3c7d060a31ebf8a70
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\07_TV_recorded_in_the_last_week.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl.orgxtg
binary
MD5: 59959ef7fe027eed2a45c30b96fbc4aa
SHA256: 3e0930f90fddb009e97d59c5afde5d0742f6433fb33250f81d55134df4e4e89b
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\06_Pictures_rated_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl.orgxtg
binary
MD5: 497ac190abf657567cbc25be5cce4543
SHA256: 34d112d8764dc1f44bf5f952d7502c5af26499a8ee733dc021b2d17c00dee978
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl.orgxtg
binary
MD5: 72c94860ac9340c1baacf2cbac2b95ae
SHA256: 5294448cc45271717111e05622e404b571db137af2891d7cbfe9e150b405a751
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\05_Pictures_taken_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\04_Music_played_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl.orgxtg
fli
MD5: f9442f6507d2fa0c4d629893340cbee2
SHA256: 41754aa7a22568bbdad73f0532eb27480e3645e34dec20475e633cd8acdf5c90
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl.orgxtg
binary
MD5: db13565d3d97ce1eae29adfb02829bf9
SHA256: 5805bcc68d075555c90b77615d0430d3232f5459aa1195a55b4ab3548288bf9a
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\02_Music_added_in_the_last_month.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\03_Music_rated_at_4_or_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl.orgxtg
binary
MD5: 33a6cfb559fe92f59b40bec35e8cb8dd
SHA256: 6e98d4c9d30450c8552bdeff138427a657bdfd138ef731b59a93f8394a48d759
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00015D2E\01_Music_auto_rated_at_5_stars.wpl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb.orgxtg
binary
MD5: 5b91d2d3c561b87d688fe7f29f4335e8
SHA256: d01d8e461d70ac71672aac86721eb7ff0cf4976c84081dcee3aba8ea6bc93981
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb.orgxtg
binary
MD5: 1cb16669dd6d87a9ae9e99b6e8d20a23
SHA256: f82938ecbe05df88eb568260f770a947781c2f02b4a1ac739691b56931a55018
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.orgxtg
binary
MD5: b7a6c032dbb6c0cdb339252c57fad4da
SHA256: 2e149ac28a4f68ce2e7cc6f0107b299adb28d423a0eafa61c3bc35ac47535689
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Media Player\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat.orgxtg
binary
MD5: 867384d502364d22543b28ddf62a4081
SHA256: ab2f9c7979e827001cf5a2a254d3577024f60014411830211eb4378cad91ac4a
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\VM3JD5NM\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\index.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\HPSK10OB\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\G4PHTCUR\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\9RI45C46\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms.orgxtg
binary
MD5: f3555aebd43105988a054c81b8093aff
SHA256: 638cfcfa9066f4dba99a5f4a5d6f32a06eba2d0490ee389fea95ab99c8d113c2
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds Cache\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms.orgxtg
binary
MD5: eaf4822ccf9ebbdf0cb56e0fcc7f993e
SHA256: a0fc928a85cd32158f9446ca2c2c0d06339251dac0d56e455fd6c066cfb42caa
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms.orgxtg
binary
MD5: 7ee512f11033f9c115a705f39a208eab
SHA256: b2b4118779be3aa1832c8a1e0ba03fb05e6ed31564b2f263f9db27c4d7a59527
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms.orgxtg
binary
MD5: e920863b83f69107d32c6f7771a19867
SHA256: d0bd94c28f381fad5d3e63759b83b28e20407c02ac7b2d1c39cc8107337d9a34
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms.orgxtg
binary
MD5: adaec9038e7fd471bb6c7fc0c2d3f7c2
SHA256: e888a51e499ca9ee496aeb667460688b041805d864721a38d728a23f5a8a38d6
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms.orgxtg
binary
MD5: 36aa20b66978419f3041851676dde9b1
SHA256: f0e215b6e221466ccf1fadc290074d84c9620a253724847eab5e97290df61485
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\USA~dgov Updates~c News and Features~.feed-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms.orgxtg
binary
MD5: 8ee4ffa4dc611e22791f2c4366808637
SHA256: d608e2dcf667b8dbb9248d38c662baa61af58160ffb1162336a7c76746966257
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\Popular Government Questions from USA~dgov~.feed-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\Feeds for United States~\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Feeds\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Credentials\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\Administrator\AppData\Local\Microsoft\Windows\History\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.orgxtg
fli
MD5: eff98e7e703310a4aa56dc9c0e29df2c
SHA256: 8968b99c26de3806bcd99e156c50dc617151607c326dc5d831e0e8fe4652c2db
3464
word.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.orgxtg
binary
MD5: 81bf3cd6bdadea82571409347f6b91df
SHA256: b1ea7d18d4199c99d0a14524dced9efe9b635813121dd931e03cf78c1b2da43a
3464
word.exe
C:\Users\admin\Saved Games\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Searches\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Pictures\knownsafety.jpg.orgxtg
binary
MD5: 36d5d929b1e70c8b2161b1099cd2f5ae
SHA256: 682b76c0f8f7831b7e3efe833748412118e1f4a327f780c3090596e6a24fbf1e
3464
word.exe
C:\Users\admin\Pictures\octoberrange.png.orgxtg
binary
MD5: 44950b5274a08b846e22e9cbdf4102fe
SHA256: a8d05042898577a5eb3f913bbc7e1ded1371af8b30d20674f17f53d7a8c5652a
3464
word.exe
C:\Users\admin\Pictures\bobblack.png.orgxtg
binary
MD5: 5a67819ddeabfd7b18e9cdb3a853dd60
SHA256: fdb3735b003c1d9527ba1dc8b8d1ad3b269f022e5609c5d8a77898e01845a353
3464
word.exe
C:\Users\admin\Pictures\octoberrange.png
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Pictures\knownsafety.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\ntuser.ini.orgxtg
binary
MD5: d46c5efe71eea429d175606ed6f5bd2f
SHA256: 67a15b15f8b4c833e2595ceb004d323797a9d93f8875d0d906a128703820f35b
3464
word.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Pictures\bobblack.png
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Links\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.orgxtg
binary
MD5: 5a30cf7c51dbe95be051f39ed0ef8af0
SHA256: 4ccec0ed14b88a39fd0c50c7fc0ec8a384d072a6949395d2af37a737004d3a8b
3464
word.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.orgxtg
binary
MD5: 93293cf2a0ba2612e59597a868fb7d50
SHA256: b91e0050ce42d972c41369f7d57f8ed03c027a0aea69596f68a240c5832513ac
3464
word.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.orgxtg
binary
MD5: 0f60c06ebad9696f8505d647c69eadda
SHA256: 1e31a82beb6a17a7034cbc1737a4c1e82d7f995bbfc74078b39ffaee1f94a974
3464
word.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.orgxtg
binary
MD5: 84b353632781deff2938611a7cd29dc6
SHA256: cceef5eedf0c9ce8dff19017562fc8600a8886f259a927f1062a26ba5ebfd436
3464
word.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.orgxtg
binary
MD5: 60b755e8ec2b1e58d7989e790b753370
SHA256: 5b356e00cab00a27879dcb691afb7d66d54c3ecc1c50f68ba867f005ad3c8e4f
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.orgxtg
binary
MD5: e00a10aa3902dc9b094cc23aa5779caa
SHA256: 7e742b7cb9d0547e0258331a4f582e3057acb3c7e937c56475ea7ecc9944f3b4
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.orgxtg
binary
MD5: e70fcbe50b5ff180b112d4fc4db9528d
SHA256: 48693ef0b3841f903138d36b032a961ec5ef76e79bdc75021263a4abf83f1045
3464
word.exe
C:\Users\admin\Favorites\Windows Live\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.orgxtg
binary
MD5: ca3475d4388b9753817c44551b9893f8
SHA256: 30f8de5593e4006a9065d1e6cc624756840e3c34646adbaba39014331446dd8b
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.orgxtg
ini
MD5: 1b40aab9c105c96b84c83b7c0493bda9
SHA256: a900736c72940f90fc33b275e17322ae2559a650a244b0db0f71bf4e215aba5d
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.orgxtg
binary
MD5: 8c31ab1dc3742e9c6584863278f8863c
SHA256: e3398b38cc7cb053acf833589c8961eb4a5d20915691c5d4085b9ecea344acf6
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.orgxtg
binary
MD5: cdc536a3805cfde3326dea5e4b75f54b
SHA256: 4efe11a2b7e030204682e93aa8db9c0aecf1f4ce23540761e85440f9c79c38af
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.orgxtg
binary
MD5: 5a62efd833b1f0f458a044b8ef916570
SHA256: e28fa51b750e177be4de2b729497f2450e5b73351437a26f97477aab375d0248
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.orgxtg
binary
MD5: 3a5779830dc298a330cd8ce40d5d9b8a
SHA256: 570a3dd6d48c275bd6b94fa2034f4b1b1873131d890e9f9187a958cbf744a0c4
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.orgxtg
binary
MD5: a79ac081b3b7f136d06293a81e42f097
SHA256: 1a4969e665cbe948915c2317869cecc60bd56093debd4e39f4fb778911fa6d56
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.orgxtg
binary
MD5: cd7c390cda938d001124fbe93c973a1c
SHA256: 038db09d4971816492805dcc7c17b1ad0c94938c9ffcf09d1a9421d849da8fcf
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.orgxtg
binary
MD5: 89e1713f78c46daeb258c00eaf76833c
SHA256: 3076fd4c9f3e403b84f10264cd682fd881f49fe24adfb54fe1f5250a452a3cbf
3464
word.exe
C:\Users\admin\Favorites\Microsoft Websites\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Links for United States\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.orgxtg
binary
MD5: c6fd0166435f42ff9c12b3ca21a3f4b8
SHA256: fb97050eee40a4cabfbeeaf67d8048d1b01586ef25bd601586a3302d36e13ae0
3464
word.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.orgxtg
binary
MD5: 8deb82c1d6d3016c2f6ef13c843d923e
SHA256: 65d26113863b123e2864a40227a99da07a7576b79afd3b62c503cb3a28590920
3464
word.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.orgxtg
binary
MD5: 2f06f9c9720fa77f425b949a928e28c0
SHA256: e6df3810b09fce34936afe2196e55759ef5c23c7aa32f0b49bc908b2d0a7ab23
3464
word.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Downloads\supplygay.png.orgxtg
binary
MD5: 6f4cd1574638b11c345216a617a7e4b1
SHA256: 6b3a5d990083a8f47b97d0b38840cb9b5a27e339d50056ad5cd230c83a32d6de
3464
word.exe
C:\Users\admin\Downloads\secondactive.png.orgxtg
binary
MD5: 8d0720f30c37cb4fded9192d6ec1e36c
SHA256: a345ff855b0c68f39aab9e6879e94d300acf6183087f5e61bff986ef6eabdf5e
3464
word.exe
C:\Users\admin\Favorites\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Downloads\texasinteresting.png.orgxtg
binary
MD5: 662ae101388619b6fcd5148775602722
SHA256: ceca27bb87a1ee56b3bdcacc8190b959a0985d5af5138ea9ffe07418d2522b77
3464
word.exe
C:\Users\admin\Favorites\Links\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Downloads\texasinteresting.png
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Downloads\supplygay.png
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Downloads\passwordsafety.png.orgxtg
binary
MD5: f06b56e9c7f5690a17e89a7e44791345
SHA256: 724baffc190ff3b640f8b97bc6e576dd6b200317fc1b0f5be51eee0dd039afab
3464
word.exe
C:\Users\admin\Downloads\meroad.png.orgxtg
binary
MD5: f1bf9a1142166d0dcb5c670d67345962
SHA256: 4ce8b9f7786928e29670cca17d949733babe8f31c5f006efe32dcf962b7fe1bc
3464
word.exe
C:\Users\admin\Downloads\crosslaws.jpg.orgxtg
binary
MD5: 514ba018dab73a7c182dd7826779446e
SHA256: 10debfcdc25d77ecf2a8fa09c4b07c7096dd2ea998a19330007527ebc95b55bb
3464
word.exe
C:\Users\admin\Downloads\secondactive.png
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Downloads\passwordsafety.png
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Downloads\meroad.png
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Downloads\crosslaws.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.orgxtg
binary
MD5: 0c71e5c52a37782f3c3324963eecb390
SHA256: e697d9bc9bd75336d471a51e190c1f5bb2ad2e891e20c86eaecbf3c9ae0dcdd6
3464
word.exe
C:\Users\admin\Downloads\auget.jpg.orgxtg
binary
MD5: a9db8b92e9b32272355ff42bf8b3f56c
SHA256: 76dfb31a5ee9d50e1003e97872dd28e9097469bd7fbba4ed9bd1cde0e5794dcb
3464
word.exe
C:\Users\admin\Downloads\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Downloads\auget.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.orgxtg
binary
MD5: b654c4282ebaefb75ad440a961a2f9fd
SHA256: e187898aa9b2d872db6e04bc0ebd0962d852abf10423a1bda5e5590fd71fcd4e
3464
word.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.orgxtg
binary
MD5: 5cd5252111b7e3f9c2c8489d6d03bdb4
SHA256: ec09fcd821d73fe91cadb96390d4f8378b08385cd7f9d17c09574ae8032fa4e9
3464
word.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.orgxtg
binary
MD5: a3a7dbdfc82d737f79e1959969628e28
SHA256: 28a89d62997f56f7210d3421351e628fda20eb4c01f190557cdb75b9c3665f4d
3464
word.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: 83e9d85eaedba1fe39ef1c02780ff9e0
SHA256: 533fe055cc603d5b30373b8819a2b8f7b69b52e8a8cff8a5087f3562bc7c492d
3464
word.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\Outlook Files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.orgxtg
binary
MD5: 98fa8fa95cce0853229ad54518a42014
SHA256: a2ff250b46a49f48eea5aa6af0801becb066805cc973b721ed3f6f1c47d136f3
3464
word.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.orgxtg
binary
MD5: 6c3f2123e7d09e9a49b51959c94c4c4b
SHA256: 7014bcd51205bdea868d16377536f3fec9f13a789750a3b37a7a9d95906061a8
3464
word.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.orgxtg
binary
MD5: 99fad8d14df18ad603d97c53caeb4de7
SHA256: 1a5392603bf5c55d165d04d7ac567f1fadfe33bd9d3db95ed53877ef0cdf0c88
3464
word.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Documents\OneNote Notebooks\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Videos\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Pictures\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Documents\lostamateur.rtf.orgxtg
binary
MD5: 7a9701444e00bc80de07d6a27305b2f4
SHA256: 1aec93c64ab827bcbb4dbea4bb338ca5e603b79b64236dfb30808d9486c00a8e
3464
word.exe
C:\Users\admin\Music\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Documents\lostamateur.rtf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\energymachine.rtf.orgxtg
binary
MD5: 3066a86d5484ee013cd244ce1ee3b1ff
SHA256: 62d82942f98a8657e1799e296c287b174335000e11f0758d5032502e7782e0b8
3464
word.exe
C:\Users\admin\Documents\aprilexpress.rtf.orgxtg
binary
MD5: 3f07594b2804d94ee162d15f000b6615
SHA256: 9b2525c18fefe6d961e59fb539a1d978e2db18b4d21feec4efa305aa587f4e51
3464
word.exe
C:\Users\admin\Documents\energymachine.rtf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Desktop\trackfiction.rtf.orgxtg
binary
MD5: a19054ef345d4cba8cd66e64eee3a8a2
SHA256: d09b0e1e2951764d6588276511752bf4e76c8aa32d7af1887c5078f5335572d2
3464
word.exe
C:\Users\admin\Desktop\trackfiction.rtf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Documents\aprilexpress.rtf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Desktop\productionshopping.jpg.orgxtg
binary
MD5: 97055d41bbc58818961b6d7aba3f8f01
SHA256: dc42627e4f3355772fdf17149c36a703c45d4e4b4a6009ed7f3537a32e3935c8
3464
word.exe
C:\Users\admin\Desktop\supplyproperty.rtf.orgxtg
binary
MD5: 5242c4e3bbf1f9bd6965c02455abf3dc
SHA256: 8ede1b777945207ce2890042c8108da3bbc1bbca8de3b977a731bc3e781dbf54
3464
word.exe
C:\Users\admin\Desktop\supplyproperty.rtf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Desktop\productionshopping.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Desktop\leetook.png.orgxtg
binary
MD5: e55954513b7adff91cc5fa73796f84cc
SHA256: 381ff421f08f810ced4c95bc236603136d36fae18f8ecd6e04f9f2d7d1885a4c
3464
word.exe
C:\Users\admin\Desktop\navigationsupport.jpg.orgxtg
binary
MD5: 69febe5fa96d212504ed07666b73fcd2
SHA256: 9694c9504d626ba925ec341d4dda8fdb808306d3fd71b29ee2232eea302aa015
3464
word.exe
C:\Users\admin\Desktop\leetook.png
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Desktop\navigationsupport.jpg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Desktop\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Desktop\cdog.rtf.orgxtg
binary
MD5: f2c1d5a25094905015634e21fdd5d2c9
SHA256: 799d3ec9dbcfa114e35fef160d50fa168ce73fb0dd67c36facfc2b6f1c309e19
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\Desktop\cdog.rtf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\Contacts\admin.contact.orgxtg
binary
MD5: 683f3bae7604d907056c7eb4e08acc1f
SHA256: 44419a1b2caf45fcd6e37434d157a45787eb395dd9862de6f430ee4560589b06
3464
word.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\WinRAR\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Sun\Java\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.orgxtg
binary
MD5: 0c1efc2d09a374880612f243e4b3fe80
SHA256: 9eba8fee23fbef4b13e9179ee501a4cbb4de54c8996ae9e705fbc06e7d94bd7d
3464
word.exe
C:\Users\admin\Contacts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.orgxtg
binary
MD5: b17d15ddd9b44c2cc7c3f8600ccda4c0
SHA256: 29fe45f23016f103e8c84f1de579f35b63d980f51cfe1b099049a1a450083a72
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.orgxtg
binary
MD5: af2858f1423b81566b001454a34ffece
SHA256: c381d63b6edf451870257a9328172b3b2a87f03966980f59b10f3399fea8edee
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.orgxtg
binary
MD5: 79ad74954ec8e01c2ab35d180e549114
SHA256: 5b3d377f3c40f615ffe46c4d98f8b4f032c32031284bed5dd754517e4ebfdef2
3464
word.exe
C:\Users\admin\AppData\Roaming\Sun\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.orgxtg
binary
MD5: 6d2ced480332fbc5fb6ec86de185362c
SHA256: a82ea5d3a9a3eb071e63d0da5e08065539e4a82e769e9b90e0f6f4fd89bc5a2f
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.orgxtg
binary
MD5: 40512dea1875ba9b3df025fe1755c12c
SHA256: bef2db3127c3a82737c04982b5f74941c4c1142d470a171192e326eeefa273ae
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.orgxtg
binary
MD5: b6f43c232a58cf3098273956b281a808
SHA256: 859df1c77c97b51c88e955cfca76bedaa796b7d8809a306a496502eafa459e82
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.orgxtg
binary
MD5: 03bf5991df4e5ac627a038086360cbbb
SHA256: 013c29ebb7349891f7cbfa7fc2933133f38ee60cf70d557367c26498a9708949
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.orgxtg
binary
MD5: 5d2595643b27bde4f929430fb656ebd5
SHA256: 7b07be6163c38ec56c4ef0dbd1699029bcd5d6793ebf785984d3796b2cff4f90
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\logs\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Skype\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.orgxtg
binary
MD5: 365840bbce4b33350ae7c1c69faedc4b
SHA256: 20b12db96acc74ff7c6f6207f4cca397ff6dd89a7511aa6e831f44631fe184c9
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.orgxtg
binary
MD5: e4508e79e65abd8927d6b32f57fc8205
SHA256: bd33e8c8b17cd5047029e5f3f80391c21d56c57487b979f1e6d4e2d25002e5f2
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.orgxtg
binary
MD5: 1bb89b6efa5abafd8c0279b959601a5e
SHA256: 7757b9e2c56d1b9a1f9f0ef5ef224113bc6ecd76b1e790165013cbd774cb362e
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.orgxtg
binary
MD5: ebb36da23fb2d887f1fdfbe16cc3c3e2
SHA256: 8d4d75c3f9daa6c128938690ddadb544b377004a8411dd811f93bd87c1dcfe32
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.orgxtg
binary
MD5: 529174bb651a20c2ce48c2722f2cf23a
SHA256: ef106d0c0421a072fb1d3a492d8d4eafb779151e4a8eeeec00fec34cc92c5977
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.orgxtg
binary
MD5: 3ad5d67e98fc967519a02726acf88bf1
SHA256: 226edb408af665cb991ca0c6252923d2995cc6e19179b81df51e82f412b5c9b8
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.orgxtg
binary
MD5: edd3e005d35139cf73972ebc63f94576
SHA256: 367fca376825e54579d1aa7b3bc505dfac14d2a05d840933c5f4406480459189
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.orgxtg
binary
MD5: 31b01d3887bb81e71ec6d566fed9b19d
SHA256: ba5a3c27263c75a9ebb53ef1bd2c2902859f5dfa9eb3a1ddaa684fda8444adf5
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.orgxtg
binary
MD5: 8858c2badb55c67ff4cf824674979021
SHA256: ce78af4d194498e4260edd23f1d43226cbae744575b16f1b2fb5d7edadf8e1bd
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.orgxtg
binary
MD5: ac7cf35afbac3b18c5f166672bad9c63
SHA256: c06ff55adbf672caf981986236d8d86638cf048daf22317aed5ac5f1f6452401
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.orgxtg
binary
MD5: 2c6585275ddf4972850b1fc607abd143
SHA256: b75d3256a26b2628203a260f59c0dc9bea3e25f7d74e6a9fd256029ce69ed6ae
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.orgxtg
binary
MD5: 0e0316706b432d1680668127fa461fdb
SHA256: 88ddd59f7a7fa0cfb40dfeb85d7f7688eb790aca928d590f859470b933f3bbaa
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.orgxtg
binary
MD5: 3157451e6ac83c34d25221259fe842c7
SHA256: 600ddd11b902849bcd337d7f7206222f7ee21643330d9c58c73e17a7c0eff3fb
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.orgxtg
binary
MD5: b9aa882450e9dbe43443708d8bffeb26
SHA256: bb65e2e6b18451fce3b3dd63d652f37fec318249ae55deb41e67744938c4c820
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.orgxtg
binary
MD5: 827010b3c71370734a0fab493eefdf5e
SHA256: fed0b85258038c47d6488326400040f4b73632ff6e48b0168fdbd8d713e5063e
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.orgxtg
binary
MD5: 4dcc31ca9848f0a15d2e41018823749d
SHA256: 6a35b1497dbf6dd5f79b323065ad78bde2d4e13db9ab1fcb5bbdf0c653345c55
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.orgxtg
binary
MD5: fce37d5cb452bc3eb71d48ac796181b1
SHA256: d2befd781129d3b6684e0db49e53d0683a1428e400ad44d9c9455aef13ebd710
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.orgxtg
binary
MD5: 3ce694152c779bbcc91f8f502b749ffc
SHA256: 51b2b93020ccf8ce8453b52e11a018c213c07bf81562a4703d971e66ab551999
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.orgxtg
binary
MD5: b8da0e539abfe38dfd6892aaa904d38f
SHA256: 11e320aced1d7832c0d08b77b02b301229546eebb671d2a9dbdf2e58ffb838ed
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.orgxtg
binary
MD5: 301f24e04c1fd4367527f738d7060aae
SHA256: cddad66b0b938e185c258a5526bd6ae9c9378c221e06528ee8c4e4f26fe5d1af
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.orgxtg
binary
MD5: 6552b6003cb611767bcd49747b7e3069
SHA256: 3bae47d29d5faa8b4f9fde3501d47aff53da57a76b3dcde9eab408789f50120b
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.orgxtg
binary
MD5: 28eaca4a60e105582422fec178255f2b
SHA256: 079ce76d14d73fbd2eacfd082959a99fa1f30d7d2a1241184e4d33e0380f982e
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.orgxtg
binary
MD5: f471de8849445b1b2540451900f79046
SHA256: c13d1a1c360a8ac316c851e202f5cf3b409d52feccf3b93ba2818c8b2d0e7ebf
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.orgxtg
binary
MD5: 59d510efe35dfa7ae6321ff9aa8ca4dd
SHA256: 21e781af8cbbeb5f2e078d0ea253fe4b85146d7ae9acf9812abe5ba74a1a6b85
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.orgxtg
binary
MD5: a43705693f54e7f37c2586fe849df2a4
SHA256: 5b8511f12413b5317573277cef526ef39c0c061a7f771b0bd52586f595dd197b
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.orgxtg
binary
MD5: fcc1e02c20deb410f52ce116b4634f85
SHA256: c4b43bb3b2498e4aa3abefdf7dc65ec1b46fac9f5a306b65d23ba47c47eaa0bd
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.orgxtg
binary
MD5: 84bfb42f6bfc284c84c767f4da5be5d8
SHA256: d9e98184089f35280f2086e3bc501814f300b3d07e83f75b7df1103926a2a7f6
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.orgxtg
binary
MD5: dd1a3767a040c93d80ab3bbe89b9a697
SHA256: aa14738171a25b334a52386a2f7c9fa76d7f0c27eaeb56e5de11a0e0670fe0cf
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.orgxtg
binary
MD5: 2e962514bd121d059c30a4593f996aea
SHA256: 24b22baa69fca9e315ef44df4ea7219bf7d8398124a775961e3bd4978b47b1dc
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.orgxtg
fli
MD5: 4c1db3002e4a2dd6dc8cc315cb519217
SHA256: 95a2207c3381a37f7441189cfaaf66ac9269c74e379c18258488cf65f68568b2
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.orgxtg
binary
MD5: ab62437beaf2f8e6e96d12584189f465
SHA256: 593482daf37992a7d3b1d0ae06f30f73f558972157b41b8774ec08e65269ecfd
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.orgxtg
binary
MD5: 2fce8db8f8f882078d8d5b471e071af4
SHA256: 5c765a7a4295a4b767c1dfb90b6ca9e96633275b1da9effdbc4970418c96ab3c
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.orgxtg
binary
MD5: 6b26e479cbf6673851e654be9a122164
SHA256: 289386b30963980c60412358ec4a5824d8ed6122b9f7714298903b8f72b5446e
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.orgxtg
binary
MD5: 392b78de962e0ecf82923c2d463e55c6
SHA256: b280d0d9efe7b3ce3fa1b19f8de3b79d2895c26a6c21a706ee603abcaa301557
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.orgxtg
bs
MD5: 733fc917c1593bf735021ede537d2103
SHA256: f2759a377392716ef1bed0711f20d31bee32701a96aa4c565f7660909c42e69d
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.orgxtg
binary
MD5: ac0db1ba1aabbc66747539b297428ce0
SHA256: d412eff48c6d242b9078696ec2fdd043b6255d35d53b674a547a7d899dbef183
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.orgxtg
binary
MD5: 43aca6cb15bcf88d0ef486766e8148a2
SHA256: de04003d228d45c10b3e692c321695a3e155a2a8f2682ad1681aebf9ea7ddd87
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.orgxtg
binary
MD5: cb902e13bf3e0b97f26516605d8499ae
SHA256: 2f03b6290e85cb0e83cce34a752df4c272a9bcb10001985f1ed33e9eb411b049
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.orgxtg
binary
MD5: 497442bc914726791832f482590f712e
SHA256: 6e8a4f9bd69d2116468e9dda85d6c308a039d2b418f8da77166e097b52b28662
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.orgxtg
binary
MD5: fe2acca7cd5fa44d16dd78c5a8a5a2f6
SHA256: 855514df8d4914e7e7b8cec8ad3753dc40d2d79eb6961e8b02d874bd28f8cce9
3464
word.exe
C:\Users\admin\AppData\Roaming\Opera\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.orgxtg
binary
MD5: 9f257741e8ac76c53f08aa3cdb42840d
SHA256: 0a05987a7bc54d4295a0828ef00f9ea5cda7b3afbbd23f68525e702aba8ef0dc
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.orgxtg
binary
MD5: a8954f905a0888417c43fd8a02249026
SHA256: caa17177bc8df2b1d27abad155d1a0a87298b0aca19aea0c5319c57c088b5b05
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.orgxtg
binary
MD5: 530d3c858c3444f0b3673acdf51ff14c
SHA256: 1b4b076a95263459e0a69ff4f7d2b8dad4f21eac3bcbdb7364fb699983a752d7
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.orgxtg
binary
MD5: 2de510e9be555977ffb215dc261bbdad
SHA256: 4d4acf17235982f6f51cebce75430f7edc0a9ac11d7f6e23f796d148fa217b5e
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.orgxtg
binary
MD5: 84e30f51efd83ba2adde020c5ad062f6
SHA256: 98b4dfae0e89c765e9b9e615e3407255b48ad40269534f07104b4c3b79e7f3e7
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.orgxtg
binary
MD5: f3d66cd021e69d779acf03bee1516ae0
SHA256: 4a843062c85ac364b62bcd6ed9b522f3f67959ef3a392ac22497d50e9074f6f1
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.orgxtg
binary
MD5: d9231d283403b11a81a8ed89be7c0478
SHA256: b72f90210514b8021f828cebb12b88f31128a3a451f235430f599107730a5e98
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.orgxtg
binary
MD5: 53ac9809c4e341c0bf9d3cd763446036
SHA256: e2d349ecb3cd824be57ae15a9fe5ad2704540a4d2b369d1df2faac5817c49d8f
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.orgxtg
binary
MD5: bd363cafd911b1bfba3b1c0efede6cc5
SHA256: d597e5db85ff79d83931e211d04b3fdb0d7ac1eafb86a5976f5e251e01d7e0f2
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.orgxtg
binary
MD5: 1eea3512be9146ee03783cb363c17d14
SHA256: f845714211c0d0d8a4785d0508aad26c9ef7f500b5fe4af43e498dda4dea1a35
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.orgxtg
binary
MD5: f21fe1a54ebd717dd0c5da9e43b85c72
SHA256: fe84d0ef26efeaf88826a81081f9bac5823de78a9d09f9adaabc6e321a70b770
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.orgxtg
binary
MD5: 4805ad49813052aeb962e947f54f4d01
SHA256: 1cf1d30fb40297bba3d7a3df45107f699bbfe1ff2a0bdf6b41d4bab829761ea6
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.orgxtg
binary
MD5: 28d9523450800a2edd20e557fa10ab3a
SHA256: 1c7a5ab0b20a5572d4a452660e06bc21d89d6ae17bf0522caa865dea5432a36f
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.orgxtg
binary
MD5: 04fd4f254398e8d40d281f561daea1d4
SHA256: 2e67e709bdef1663b0b78563c059aaed27b5ab82c16536d33a645fb63d29281b
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.orgxtg
binary
MD5: 9b9c25144326db3394a0dfdfb4301219
SHA256: 3365d5649e726aceded2c0ccd09bc15c7e20d762ec680e48153f069beb50d252
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.orgxtg
binary
MD5: 8ca2533206aa90666d152369ba6566c0
SHA256: 385b4cbd9a6c526df35d03187f2bf2e0e38daa4cee09f99bfcbf68aed79efd7c
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.orgxtg
binary
MD5: 9b822e2324731bbab0c27ed609e2369b
SHA256: 8d65c79d445666278f56db4df1d9cc1e0c34be890d7cd9e50a53aa3f0744d2b9
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.orgxtg
binary
MD5: e59694bd165658862cbdc4432bf6a642
SHA256: 5961457ffc10f36bc0b915a0ab25baec7a362af40de046ba03647adfb3ba3c49
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.orgxtg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.orgxtg
binary
MD5: a9dbd2d5520561bd5aca78a6cf38ea39
SHA256: 38e6a4fea294bf14db8300b09c3c13e8c708460b9d5cb5305a56f5c9c0b76e2d
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.orgxtg
binary
MD5: 6ffcd2680d642bd01fba480ffbc7b3a8
SHA256: 71c26bb76ff56eba82bb3ab9d44815b1610f8fe2f7dd46b2a3f23f53bbee318f
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Notepad++\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.orgxtg
binary
MD5: 955da26caf7a7db8a09d49e40da5c54d
SHA256: f8d48727324752a45baac204a7a702b474e88d9cc1e5aeaf9de438dc96f31fa9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.orgxtg
binary
MD5: cb6e90cafa2fdfb2186d53242eabb37f
SHA256: 48afd9c1b1cc28558db5c8184e1dde8349aa45a61fb80433a3ee131712f6df48
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.orgxtg
binary
MD5: f66101c7bbf6f67670e93a7d45345e67
SHA256: cc7c8773c973cecbe04b7b8a84cb4697939d061da3b395288c12d45d2250ae44
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.orgxtg
binary
MD5: 488b0fb34dbb1f5d390182c23e115324
SHA256: e1657836036ccdd633e2dce2ba84adabc049ffc7f441663c0ff3b44424b0d9ba
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.orgxtg
binary
MD5: e77895b636327e0754280426650077c2
SHA256: 07d1804e489809ecafd4f6f3e0b45a874bb22a6b3957f0a722c5da57c39a60c6
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.orgxtg
binary
MD5: a4d8e15563406c6145747c221f0e2eb5
SHA256: cb2051e7ea7ef0bd87e24a58639da2c3e61a9ac385cbf8bdc3d7efc3cbf58287
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.orgxtg
binary
MD5: 311334c28bfdc01da925c631faaec599
SHA256: 75913aaa7e025536e8185a00dbb3d6ba2bc894a98a2042c1757289eb585adb19
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.orgxtg
binary
MD5: 4acbc2540b6ef0dbfb8a4a7e78dc4716
SHA256: 98357bad773b95baeebf9f0778d12603e179a7fcfc31403d765c2e82a7f86e65
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.orgxtg
binary
MD5: a6aa290c011b9c0cd58d328f1d870868
SHA256: 1857fd51a5f1a6264205b756c5bf887ae8ae23f2fe80c26deda8b3bcc4cb9738
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.orgxtg
binary
MD5: 0a6dcd7273555a6c68af1d30b587394b
SHA256: 1d099372f60740a05f9c25312dbebdda929485fe7f7ce25c9f95680a3d90fef2
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.orgxtg
binary
MD5: 6c4273641d5354f36ff78fc9388898e4
SHA256: 620285ab809f8b78e7ace833fb58ccffde7b5237e30515dec277d17ae3a8f54a
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.orgxtg
binary
MD5: 8c1ed477c36636f145a76c92601c9ce2
SHA256: 417550d286ecf946a9abdd374f0f15e2d7a1d9602feb056fbbc4fe2be9d175e4
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.orgxtg
binary
MD5: 98123302bfb1fffe8e7455d58052b58b
SHA256: aef44c3f2622f485abc42a8c764eb12130ab3e1c3925d49de74c9f672b017529
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.orgxtg
binary
MD5: a7906c036d122e644f14b1e9666f555c
SHA256: e661e8a92482b58756c970bc4e50aea8901a051d99eb02457ee5caa9bfc8c9a4
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.orgxtg
binary
MD5: ffbfd2f1f05f4dd9a3e77ac86b1235a5
SHA256: bea22c7b336bf4207014bda9dbd9d3829800ab44b137e21620876d13526efed0
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.orgxtg
binary
MD5: 97fa5819a124b6df91427fa93e67043f
SHA256: a95a6a4f3433a7fe0fa36719aedba2ba91dde34019e966a0686ffc5e3d39b0b1
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.orgxtg
binary
MD5: 30dd8f38c6f873d744255c264377da67
SHA256: 90066642e090a5ea96a1767a5eaf00b0a8cd9c781885e7e84e164362b79e4fab
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.orgxtg
binary
MD5: fb4f470a5e6a987db4ef87cfcabf5305
SHA256: a741e82a40a672b6589f1cc1a2bba8d23c7f2fec7280363e3a5deba70237982f
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.orgxtg
binary
MD5: 4f11c29e4f687adb74d8fdff1262dfe9
SHA256: 361194fef2f744ff8cccf6f4ab59f3f2de45d137bab1f7274284d735aa382f5a
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.orgxtg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.orgxtg
binary
MD5: 502a6d18e72b81a2b0d49676b6eb7dd4
SHA256: d5606c7af67c0226362cb096d9c6580a2baf4b275e79cd72de8a258fc9b2f041
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.orgxtg
binary
MD5: e77afee4e14efe25d226112f5c07a174
SHA256: b51d3468d1ff4535d81a6ace9f37ecebb97684ac8081c3e397dc4ef6d2d036dc
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.orgxtg
binary
MD5: 9e8e2ef7c72b6df76336ebb37c8f2ab8
SHA256: 645616e3f738cbeadb9edc7e0b306fd19a4ae09e3b65784ffc66502fc98cf261
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.orgxtg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.orgxtg
binary
MD5: e1895c6161e75eed542116e738c63e28
SHA256: 64fc66d9b9ac3255f4da393bd91553042f1d8a0c4806222d1796943ca865fcf3
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.orgxtg
binary
MD5: ec3c1754d7a578e1968836a5c6949ffe
SHA256: e78714feefbd221c1558b5d660b014f8e8253d908eebbed66bfb4cd536ecf578
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.orgxtg
binary
MD5: 65c24e1494ff689ffd36597698a013f9
SHA256: f45654201a43be1a8984a9fb3e64bcb96836417290806f80b26c66830496a969
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.orgxtg
binary
MD5: 9573badbd321b0d744738e6997c53822
SHA256: a9db863452333a5605f15af550fd6a594ff4abfca81a85512408959cb7e7eb51
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.orgxtg
binary
MD5: 5a9a75fc7c08a7f930e6b1f084cba530
SHA256: e51b670143584b2bcf878c59851ed5c29d93df06b43e32ab07e786b079d61d7b
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.orgxtg
binary
MD5: d1773b6df399a146882249442c0df1b1
SHA256: 91ba735625797e9ff71f0cf17e7b296ffc3a60ab465719e2a7c397427d7feeeb
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.orgxtg
binary
MD5: c47a67a011e0dec9a1f0350efcf7cc69
SHA256: e5672bbd92e3918f82c516e474fbd446d475d9b2ed14b1c713acdad963195495
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.orgxtg
binary
MD5: fdd25509632daf920b0b9c4a1279b1d7
SHA256: 643ae0e644319c4ebaa73a6ea9acb929171edce89446f38174d156505277cf46
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.orgxtg
binary
MD5: 30bbc1624c0606698367c9dc7cbc2ad2
SHA256: 4a09bb2c429ca247d15cdb9cc44b723b54a858bd70f84dfc22ec9cbc24d5ab0b
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.orgxtg
binary
MD5: 815d64dc40db5dc1e8850373b59d0790
SHA256: 3029299123d3e119f1b51279c0b6a767fd8eed95f37d55a574a48b03a313914f
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.orgxtg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.orgxtg
binary
MD5: febec22a0f6104942032217a48645b0b
SHA256: b72b9b7f4e8acf973dad915274851febc8de45a83032c0b20842874a84d8bf10
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.orgxtg
binary
MD5: 65ec7f7aa4534231ec31bd6203599288
SHA256: 2e477d090b333e02aad00c619c1cdd15572c48e8ebb425470afa09dc52d8c506
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.orgxtg
binary
MD5: 885cc2857cc6a774005e06a1278af79f
SHA256: cd537dc69a48c51fcaa6de5d10664010740895ab00ad657fffd057966c0d0d59
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.orgxtg
binary
MD5: e64b2bd1973cd85cd178e407b186eb1e
SHA256: e3e830f4e85c0822e0312c0b3f5c8a37e8f809494db42ceac5cfef8493c7e539
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.orgxtg
binary
MD5: 1165d27202c7fd4b00658bbc45a463d3
SHA256: bc9317ced38cc4231fad4eb413d2d706df847f984d92c5632a9d4a947a8c204c
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.orgxtg
binary
MD5: ace55fe4d5ee86a01c9f1365c4b3652f
SHA256: 395cd421c9edba43f4cbaf1c1e278cf597c004b5134a4fe48e48160f7237f98d
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.orgxtg
binary
MD5: c9ef197df0574de3ebc24c565bedce79
SHA256: 1cabb0d4cbfea05054672afa2b1813103b4c0094bf384fecf2c83101229f7051
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.orgxtg
binary
MD5: c48a28b042ba175acfa281b8cb5b441b
SHA256: af75b1025ef9cbf9bb5f67bf02ff143ebb898a7fb89b74193a9097d3d31bbad4
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.orgxtg
binary
MD5: 27355d5678674120aa3800039cddfc03
SHA256: 7040131fd7a746f733112ef7da7abcc39f7d5256f5c4db2bbb620fa2d2311e97
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.orgxtg
binary
MD5: a896aa25410a9e39faaf64f359be8835
SHA256: bc701bea27b4883fe9bab2ed5715e589670ee0bdf648defe1b242dfe774af3f7
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.orgxtg
binary
MD5: b3347920150b1304d61475515a7baeda
SHA256: 0fe985c2e9b88086f21ee96664c3b91200f8a49ed30ae3486a42148574cf1743
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.orgxtg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.orgxtg
binary
MD5: b8811c2dfa46a2953131a9d45cf8576d
SHA256: a0890446c479b20de39167e7e211c2fb56bb9b464bf3d25a7428745f68fa0e52
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.orgxtg
binary
MD5: 4b76289972c457c73bc47df0037ea01d
SHA256: 9c3cef82056926153055e4636b80fad8b207ecb1315b6840f5f6065c98cbe81f
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.orgxtg
binary
MD5: a719e249adb660231908122aea66fbb4
SHA256: 870f110847c5bd8fd383097f26231afb5e8ff714e6652bb54631d2a8491f9587
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.orgxtg
binary
MD5: 4c71e03af02e9fe498622bb4aa23c4a3
SHA256: fdf723e174ce12877fd332401a3d0c5cf7bff96b7af5eeea15703ae67834324c
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.orgxtg
binary
MD5: 8a42df72d9448657ad1e388404b6c294
SHA256: c07588d7def70ceb2ff9838a5a30a69420994a50a1094d4a9505d63cdd8b6b49
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.orgxtg
binary
MD5: 01bfdfb5285661874ef53c93646d08cf
SHA256: 8dce46eaefa395411360bfe563621de0e362a7920ea511c804a0aaccea1185b8
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.orgxtg
binary
MD5: 78242ba09a5480f04e4938f9401af595
SHA256: 5e6f088761a3325ed5e0d4228c799bb2e3bb9150e0683bd4bbf5c4b2b3373a6a
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.orgxtg
binary
MD5: 6de5378544ad1975155fb62ee1975c29
SHA256: 75862aef0d001e7c847645e315d065174b05806c0f9d3358659b62614616866b
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.orgxtg
binary
MD5: 25791dfb81344b79be203320acec11ed
SHA256: a8fbf19bc0afa0c9bc3934fea8a44a90f88fcc09c744339aeb33f0bb9362606a
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.orgxtg
binary
MD5: 199b139fe43e8ef7572ed4dc97945b9c
SHA256: 689e1c6602744668023cedf41eec91b516ac58684a060823fa4502868c2b91c0
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.orgxtg
binary
MD5: a839a4c2e6f40d4631af5189f6f9f502
SHA256: f348741127dde20dfd5ea479e465cc5ef411fbd236e5717d328c086cc4992e89
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.orgxtg
binary
MD5: 96d22797920c3bb78a2d0cfa9e3c4f9a
SHA256: 2d0bb6109319dce29da60464406b1f75419d0403ab0ac32451d366f3e01e6b31
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.orgxtg
binary
MD5: ce272c1c952466a2bb71805bef34e83a
SHA256: 9940a824d5fb7cafa27ecd4726f4868b559f0bf98e270e547fdd999ccab16a17
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.orgxtg
binary
MD5: 2234a3cc25d7d0a2fd2de974a79a2511
SHA256: 248cfe2978cb6e40674f8caf4176e06e24254325db058405c77b9d0867515adb
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.orgxtg
binary
MD5: 7ab4e5ecb261ade0ada20b79f688770b
SHA256: 23fdda57cf1c19404d2a3ced1f043f73ac51f0e3a1d59eb93c26612d5fc5450b
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.orgxtg
binary
MD5: 89c52ec167be1fa8212abf7f3d21fc9d
SHA256: 2c96a683711c49ab45dedadaa69ef62807c4a68c3bb60305746333227de89a52
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.orgxtg
binary
MD5: 82e5aaaa36bd264d1261b1b3e118f8b3
SHA256: 1f6bae98e33acc5f0f06170ac2a39cffb4387119b4e7a8efec3766700b620387
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.orgxtg
binary
MD5: 65447ad025982efe219bd2d21cd675b8
SHA256: 5a975eb47aefaf52877a35bb8a8de2af2d3a14579c4327b3a187312451581e4b
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.orgxtg
binary
MD5: 22581da383aebd4490f2e034cc44c37b
SHA256: 02c6721c1e9ee4f30f352603cd0f6d2a8c98f064b90d7ce7dac53d9cdd58065e
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.orgxtg
binary
MD5: ab361b37d408b55f98f7b81e9331158d
SHA256: 444b432626b0956942f6b083a4682978246381b9c52c43cbc276afad7f41351d
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.orgxtg
binary
MD5: 23f7b04001013781045206520ba329b6
SHA256: 66e8ce6976593f7bcf1f802620500e93f6f137a0194b565f119c5858e3494939
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.orgxtg
binary
MD5: b69169e041658ae06faff861ef22d034
SHA256: 462f370fff5fe971eac4e43cd761c1e48fcadd9c97af3e2b83399594ce0be00d
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.orgxtg
binary
MD5: 46c1f0caea339b8e4789eb49d30dab35
SHA256: d810c89a03adf4bdec968a242f0f39d785879103d675f8de5481770b7bfe1317
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.orgxtg
binary
MD5: b63cd1e29a35e9776c823c0ee50f049a
SHA256: 9d2694659d87356f00ba24064ca938cbbee0ce9d50db0409629ce7a0cb362328
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.orgxtg
binary
MD5: 4d8d5fda91e3811c62bf73e4c00f25d3
SHA256: c1ce2f1a529f0fd0d6ea0858e91d3ead3c0145bc15893d5ec25322b66d81e8ff
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.orgxtg
pgc
MD5: 324afb98fcf469b0321e74fa20c89069
SHA256: 060eea4819c2b849ae91a4f7b2d09f25079c13e00a92918da24c3a31bd340d20
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.orgxtg
binary
MD5: 48af9d65e9a50414de92f344d9417ce3
SHA256: 94c8c893a777cf42659ac26781661b6c139cf002ad5c44cce0b58fa84d7a1894
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.orgxtg
binary
MD5: cefe9ec10633db8cbfb5c87d9b6c91c7
SHA256: b7a2943e1435c6d79fd7ec1569999f12ead75433414f1ad4a72c581fa1dfed84
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.orgxtg
binary
MD5: 9d132a98ead68ccc61feb6bad2eeb681
SHA256: 69c1cfcfce2231d2815d4e881b3c51d3211b01657ef15593234b8b72a63c1e50
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.orgxtg
binary
MD5: 245744a7afd21044e4fd668679f3f097
SHA256: 8ed0e2ff95861aefe86bb2199edc5d891290e9bf9a820a053165ba14be8a523b
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.orgxtg
binary
MD5: c243551635d1909a0b97d9442662facf
SHA256: b855d4ff13f9b19544c1dac4970ff9587db8b8c31e1bc38bf39cf93bf7a25486
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.orgxtg
binary
MD5: 0689081407a23a6db02dc65b8807cc07
SHA256: bbbe985d542fd76f0fdcf4bf52a6937af9d8094ed69591b40eb8cf7b5a45f36a
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.orgxtg
binary
MD5: 695be02f3e5bf1d2a63921c6cb0f358f
SHA256: 739eec7e0a9a2c257c4f7e59c7c5e288105c9f14274e9f24e76175542d1e1079
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.orgxtg
binary
MD5: 1c3671d16565f84e3bea58228bcc52fb
SHA256: 1b1a4ec685c0d314c48ac8ad55ba98037d1a3d0d381440031c61b777b1811bab
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.orgxtg
binary
MD5: 483db4fdc8774ae0ba1dc88d1bb2719b
SHA256: 97a733cb58e41b1481e586c19b826879b6c80b2671b87f6de3466ee6dc878a9a
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.orgxtg
vc
MD5: 179eae3838013c405a2d4e6d463928ef
SHA256: e5489f818627f149d77f0af5fbc836d1847eaf3351b22592b2d5b5bc1dfdd013
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.orgxtg
binary
MD5: 3cad57ba0513e3784c341a9c63bfed84
SHA256: 93b764eb6bddc48a0e92e8fd7384018f1b984b28a6c23a4b77f6d4bde647943a
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.orgxtg
binary
MD5: 4c43974991feb78da7c74de36bc93dd0
SHA256: fad0c985cf990d08201a3736852c4740c85a3bab544bee05c2f1f7599744bc51
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.orgxtg
binary
MD5: 8d3132e70cff9fae1e5f1b62ccf7d7d9
SHA256: a94d806b6cd38462eca9e0652d847995ce700fa470ac4e278d0f4ffaa91a84cf
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.orgxtg
binary
MD5: 51ecdae86bdfc822fd70ede6c9cb6cca
SHA256: fd0cfe58b7fcc42c3d1084c83925a0094f57e7863bd250f03ca09d21e0e2e3fa
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.orgxtg
binary
MD5: 0b5bef3f26f8e0ee786b487368b26ed8
SHA256: 4bc39e43a642f1d38d7dc92b459cc26affecfca21c66004432d4bbf0ac795855
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.orgxtg
binary
MD5: f20c6c70f26fc8a7a90fabc0f4cb66c9
SHA256: 54db229fa46ba385ea3de976caa5dc140f1754df62c6b5df54a2881b00011096
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.orgxtg
binary
MD5: d3710dd0082217f4bbdb4ba07a3c1616
SHA256: 9edd0d7ff01f697f6a8efbdbe5ffbfc7f5dee42e5dd32d8efcee893fbe59a887
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.orgxtg
binary
MD5: 23011c158199f8a0ba2b9fb78eb17b93
SHA256: bbd05b35d95fe3dfe30d85e074a3891f2b9adb29e5a71f50cfdd80b8bb803dbc
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.orgxtg
binary
MD5: b3492eda7ce48cdc40a8100bfd2faab4
SHA256: e3dff9489335ee6cae9bc6e29e6ac9fde2d86743b0d6c641ba968aa7f513ee0a
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.orgxtg
binary
MD5: 47c54247f8d9cefc76a1d739ce83838a
SHA256: 45da7aeec5d1d918d1828d33677d365fd6a9cbb238977b0c121b968d244242c5
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.orgxtg
binary
MD5: 7d04ef7adec13bfd01bc45675f37220f
SHA256: c3f4c4c7650981be582b91a8714978342d93fcd4acfdb83691ee216898139865
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.orgxtg
mp3
MD5: 3b48c9c095244fd42088a433b54f5b1d
SHA256: cab1d1cc0fcba0476cc0322fb50e9575d5fd8a4ea00af48ba047e3a5a06b7cf0
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.orgxtg
binary
MD5: 2948c5b1e8faab0292054e4dfdacc886
SHA256: 594692e2a05b990dcdd7691411e597362b831f144243c41895fc403e2e59d5c7
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.orgxtg
binary
MD5: 29bcfb80b3207ab30df12d7eb1d55a8c
SHA256: 0f2a163836003cd2848d8b2f3acb181fa539c2255f2a21e597600265990f48c1
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.orgxtg
binary
MD5: 9ed3b8ddee053885402f538589859b80
SHA256: e88056add356b330d303d7990822b01ac5637a5ab43ece60898884e6c51be26a
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.orgxtg
binary
MD5: 1e0fc86e2af5d86a51525f95911129a4
SHA256: fcbc05daa11b4784cffaf57bed2cdc099ff4a519ed102979999eaf91eaf036e8
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.orgxtg
binary
MD5: d117bdbe65344ddc066fa2783260c5ef
SHA256: 86277fb9eff4c6c626d53e82d667582405b2f3708b90f4d16e26cb54cf4ba368
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.orgxtg
binary
MD5: 107af8c19c09341c9e9bbf38476390db
SHA256: 24172033375d2e604af731b2f4d9baa1f6f081f16de6615b91c8a02ff0e17a26
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.orgxtg
binary
MD5: bb4a8e3072e5fd91b22b724065f3f713
SHA256: d9798a86b8ebf8adf1d0c4f12a54292ea1187286d5cfb8b71383ac83732c5d09
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.orgxtg
binary
MD5: c77d8662a1cc563dca6ce636ca845745
SHA256: 53138d8aef46b7fc6d0efb280493d5e1b35772ba8216f488c2b0f9db9186d33f
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.orgxtg
binary
MD5: 68b349fd9bf33d1e00c360b1e082714e
SHA256: 6dc0f2c4f46326d68d252fcdd779bc2fbe9ffcb97f83fb000e570055b7ce0ccc
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.orgxtg
binary
MD5: f1532c0fef4b311e411ff9563909c9c3
SHA256: c78221faa9f4bd83227a529be7ced0c572b78878b45713a00ebcd403a8a1ce2b
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.orgxtg
binary
MD5: be6dc621be05e7571078f3404a6d268f
SHA256: c52a87f73b3c1fab90c0ee69e1bc8c69d7f3fd182168bdcef7d11e5bc2951b9c
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.orgxtg
binary
MD5: 63c4f435cd86d76db7c71d635d76b86b
SHA256: 11c8da5c7c8e6f74e535af7850844a9fd60ca266e65436e49e364811659542da
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.orgxtg
binary
MD5: cbef8f3003c38a81c17b005bb6f665ad
SHA256: 3fb7ef8a97b43bf5decc65d021cb6794e6bea53f83a1f5d2f09af1af7d7c09e6
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.orgxtg
binary
MD5: 8a45945f2b564bb274bdba21eea2bad6
SHA256: 2d4c031a2e166dd7a4b3e7121cc4bb3b84d901d74d7623c9d7b23933f2d0bb57
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.orgxtg
binary
MD5: c221b307352773ea0bf101710b5ece61
SHA256: bd68571d62d05cedcb7e08a9ef9df77d207fbe08392910fb1ed3ca05b5e805fc
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.orgxtg
binary
MD5: db83a624251d736afe9c126f12c75fde
SHA256: 96d60d6f6b1c97288ec301940924a1a0c231e6a132b882df5420318520f45d51
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.orgxtg
binary
MD5: 286c6d5bb69510d3c54e5d7d22eb88cc
SHA256: f94e0cfc7b8f07abde08ee8ca54550c1c72dc9bd461ce0de493b3414f32501c9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.orgxtg
binary
MD5: f9b192036444d44f15653daddf8f8bb6
SHA256: 7623e2b67a1251d11a97497e4647a3d94131df0b2d23ef68f9e673fed31d296d
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.orgxtg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.orgxtg
binary
MD5: e5e9d9dd7b4bd243a84d9b8359ca82fe
SHA256: d47a7a58d20fe1c8897a3f36c17093a53d8e04d4f6fabdd75615f01e53fc1037
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.orgxtg
binary
MD5: 1fe11065c9fb17ec9c2177e44088ec40
SHA256: 53df32dfd17507a69e5e23dd6aca3eba6f43bf6cf57378b7b35fdcfc0c223c63
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.orgxtg
binary
MD5: 04c8b7900261a3fcdb6a909554744e7f
SHA256: 3b5581aab9228fac49fd8433064070d1a3e6faecaef3ba6243b15cb4bf9253a5
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.orgxtg
binary
MD5: e01c78c44509258f5c03980d40133773
SHA256: 1844556693d00833446bb7c5deae2ec59553380e0c0ea0371a227079af3f2e9b
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.orgxtg
binary
MD5: b345d026c4e0cc985a1e3b3b62521e8f
SHA256: 694b02856dc75073b86efc9569ab53edeb37d1a7d301fc017f700beb7a249ef7
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.orgxtg
binary
MD5: cf90bd17e920ffd70136872c727521eb
SHA256: 3605c8eaa06d56c61217d7051e90e3548810484f8bbd95e45137489dcb389a88
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.orgxtg
binary
MD5: 8aa56bdfa9ec3a860782a590c3cbab6b
SHA256: 187540b4ee7410c1a4f4fcb6e895022fa816d8f99e29bf2419b148ed231a4765
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\1b67f441-6a97-4efd-aa88-0f101784f872.orgxtg
binary
MD5: 9eb06e70a33631c058182beeb88b035b
SHA256: 95031a7f09753432e0b3e2145344a341e7796d84c8090724832a31f682957c03
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\1b67f441-6a97-4efd-aa88-0f101784f872
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.orgxtg
binary
MD5: f476b94065c2360c3600f9a862239ee6
SHA256: d4f5758926fae369a5362482b43ae0abcaac8ae97c862e492541eddea3ed9f57
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.orgxtg
binary
MD5: 82a18dd4d27ec4460f476044f4a565e9
SHA256: 3da46df5bce3c4d25b3a5f5b7ac6ae82ef5ffe37299e8d7ff3e87d7c9703c60a
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.orgxtg
binary
MD5: abce6306336aeaeac602876e9b302039
SHA256: 8ddea2baf78fd2f1985c7557d336aaf810b56bc8f0797cb6e001308e77086bbf
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.orgxtg
binary
MD5: 9f16066339d8972795c25c912303858e
SHA256: c1057a1ec82d051c16db68a39298a28a009a7a316c53312713bed6014efb12bd
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.orgxtg
binary
MD5: ac57105bf2cbf407bb5c6f4abcf5c091
SHA256: 8027ab6bac9ede49a91caa0f818a89d2b2daa8d6791319510a15dc266b60ca61
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.orgxtg
binary
MD5: 179b9063829efdf70d1aa68dc02f6782
SHA256: 1406871c8f66f23c70304921c6461076aacabaa8be05e8540ffb9db62610f18c
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.orgxtg
binary
MD5: a2cf0c173aaa22415b0949b0433cc227
SHA256: f60495d05f79f4df1e10873a828414d75ace925c21e515be0b7f10bf74781fe6
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.orgxtg
binary
MD5: 89df17b8316bd7397b214c0452a5b68e
SHA256: e246b5151032838f4d22c634f225d3f017f02c0ed443dd3a1be7c760dd51ed66
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.orgxtg
binary
MD5: 58dcc948024072d1f8472d76feda373c
SHA256: d21f52f27c37824654921336359332ce08ce2c0b3f9eda174d37afc954564725
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.orgxtg
binary
MD5: 45571c67da60ef001cd4657ef3cbc980
SHA256: cc0def32266b72c564ecf04a6989ca1e2797b418f90bbd7fc03e2d01c867691f
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.orgxtg
binary
MD5: 3fc6d43280f7989997d1d6f45f2809ad
SHA256: 8dd51e3479c37b3857d1178121f01917175f3c19e0186b746eeff0ac53ca9a48
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.orgxtg
binary
MD5: 1688b9479043e01a014ded91fe19e067
SHA256: d444324e9925553f6dd842c6bf634ec78ed22cfa9f8d074cd16d6f51adf15521
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.orgxtg
binary
MD5: a47ce400be32ca1d6d804038ea168197
SHA256: 47ea63ba64844c513fa6566b5d0d26c1444bc77fecd494d884fc7571f701b725
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.orgxtg
binary
MD5: 37cfd14d0acff72787a8755ba1a4301b
SHA256: d331df35e114d344df612741127b1d18aeeefcf34d04e3d25bfadd57e8aa5ab7
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.orgxtg
binary
MD5: b31cf0c60eefffd9638584f6e4c072a7
SHA256: 1097523c961915872f9d58bf7cbaad97d19315492e82a2184bdcdfbc9fa4913e
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.orgxtg
binary
MD5: f45852b1e44fca75545174d05aa670c9
SHA256: 5140bd65fc77c659bdf0fe1ceffcc6c5686ab6057122749881c76517dea582e9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.orgxtg
binary
MD5: b7372cf8f12cc610660e3135344dec08
SHA256: 024db862368d3c6247f09345410330eefadf1212ded034f47facc70caa64a084
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.orgxtg
binary
MD5: 903ef3cb7b669e4e06aaa0c2ce7dcc9c
SHA256: 00f641b2f555b4a060917e3ce2aa17235c6ea5facdec554ebc8207467cd4c4a8
3464
word.exe
C:\Users\admin\AppData\Roaming\Identities\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.orgxtg
binary
MD5: 2fdfb05195be3c7dff43b2fa921df6b9
SHA256: 464fc84413b1820f913dde17346c88020bb0aca2e57f54931b2789a358957b93
3464
word.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.orgxtg
binary
MD5: 2a810b361d66147ae3be86e0c28e41cd
SHA256: 5185911830565e4d0744e2567aa29951de29483e3381a69f9b4e7f2ceed8efd7
3464
word.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\FileZilla\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.orgxtg
binary
MD5: 9cc19dd4b58e4c5897a5c20fa487be10
SHA256: b9191b209495ebac69e73f411f67e95c03bb42c5573bee73def68cd73b3b4cea
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.orgxtg
binary
MD5: 672874a165a99c5a231c77d8272b6cbf
SHA256: d24ad4d63b3dadc31a56295af03a925e1e9ba42c0c7600a362bb34a8c52efd65
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.orgxtg
binary
MD5: a22467c3f3237c3e2fcde2e21a8eb7fb
SHA256: 6cde2502cd8b078d3cbb9749eb76ce17b1d370e4f2310d4cba86e17a5434a0b4
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.orgxtg
binary
MD5: ca1b3a00d68c8a23f72550347a59dcde
SHA256: ee18c5833b0e9c15847c97a9eee71b37d589f8e8e9d87e55a76dc020567cb012
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.orgxtg
binary
MD5: 87f0c469a5d357e50f7fe4d602f45492
SHA256: 75ca130a524961908560f527825418de5c24dc2195698ff43e83f13516066062
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\ORGXTG-MANUAL.txt
text
MD5: 9793ad489b78fa0b173441b5fe5a8b48
SHA256: 1fef4f832fbfdbf16382944d60a6c1e554b6570152217c5efae28dcdd9fccbf9
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.orgxtg
binary
MD5: a416ed2f58c05dda7e9ddb327f0fbc7f
SHA256: 249c8d339ff8745611911f31e0860b288d736bd2e9bbdc03b51cffcf590884cf
3464
word.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––