General Info

File name

VyprVPN Checker by xRisky.7z

Full analysis
https://app.any.run/tasks/2280758f-5f90-48e0-a4fa-b9649e87fd2f
Verdict
Malicious activity
Analysis date
2/10/2019, 19:29:54
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-7z-compressed
File info:
7-zip archive data, version 0.4
MD5

0aaa661fbb5966da2d79b735e2bcb0de

SHA1

75f682e5389f8a2233239b153c8f8e790ac8e6dd

SHA256

de540068d1cef53d0a21e8ab67341a5c97beff91b202713db3321150cf72ea2e

SSDEEP

49152:0EMFgBulqA5tnKB0c8FERUGbTU8tdE0KBYq0t:0EP8BtnKVVmUTU800KYq0t

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • explorer.exe (PID: 116)
  • VyprVPN Checker by xRisky.exe (PID: 2856)
  • VyprVPN Checker by xRisky.exe (PID: 1712)
Application was dropped or rewritten from another process
  • VyprVPN Checker by xRisky.exe (PID: 2856)
  • VyprVPN Checker by xRisky.exe (PID: 1712)
Executable content was dropped or overwritten
  • WinRAR.exe (PID: 3608)
Creates files in the user directory
  • explorer.exe (PID: 116)
Reads Internet Cache Settings
  • explorer.exe (PID: 116)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.7z
|   7-Zip compressed archive (v0.4) (57.1%)
.7z
|   7-Zip compressed archive (gen) (42.8%)

Screenshots

Processes

Total processes
41
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

+
start winrar.exe vyprvpn checker by xrisky.exe no specs vyprvpn checker by xrisky.exe explorer.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
116
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\mlang.dll
c:\windows\system32\imageres.dll
c:\users\admin\desktop\vyprvpn checker by xrisky\vyprvpn checker by xrisky.exe
c:\windows\system32\structuredquery.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\explorer.exe
c:\windows\system32\twext.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\zipfldr.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sendmail.dll
c:\windows\system32\mydocs.dll
c:\windows\system32\wfsr.dll
c:\users\admin\desktop\vyprvpn checker by xrisky\xnet.dll
c:\windows\system32\notepad.exe

PID
3608
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\VyprVPN Checker by xRisky.7z"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\program files\winrar\7zxa.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
2856
CMD
"C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exe"
Path
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
4294967295
Version:
Company
xRisky
Description
VyprVPN Checker by xRisky
Version
1.0.0.0
Modules
Image
c:\users\admin\desktop\vyprvpn checker by xrisky\vyprvpn checker by xrisky.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\version.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\sxs.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\microsoft.v9921e851#\7ca6a7b9413844e82108a9d62f88a2d9\microsoft.visualbasic.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\accessibility\44a4ab91e8e11c7cb95343e2d9ffe621\accessibility.ni.dll
c:\users\admin\desktop\vyprvpn checker by xrisky\metrosuite 2.0.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\desktop\vyprvpn checker by xrisky\xnet.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runt73a1fc9d#\647f9e8a4465888d8348c3f66611c463\system.runtime.remoting.ni.dll
c:\windows\system32\psapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll

PID
1712
CMD
"C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exe"
Path
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
HIGH
Exit code
4294967295
Version:
Company
xRisky
Description
VyprVPN Checker by xRisky
Version
1.0.0.0
Modules
Image
c:\users\admin\desktop\vyprvpn checker by xrisky\vyprvpn checker by xrisky.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\sxs.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\microsoft.v9921e851#\7ca6a7b9413844e82108a9d62f88a2d9\microsoft.visualbasic.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\accessibility\44a4ab91e8e11c7cb95343e2d9ffe621\accessibility.ni.dll
c:\users\admin\desktop\vyprvpn checker by xrisky\metrosuite 2.0.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\desktop\vyprvpn checker by xrisky\xnet.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runt73a1fc9d#\647f9e8a4465888d8348c3f66611c463\system.runtime.remoting.ni.dll
c:\windows\system32\psapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll

Registry activity

Total events
4691
Read events
4546
Write events
143
Delete events
2

Modification events

PID
Process
Operation
Key
Name
Value
116
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
116
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z\OpenWithList
a
WinRAR.exe
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z\OpenWithList
MRUList
a
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z\OpenWithProgids
WinRAR
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
3
5600790070007200560050004E00200043006800650063006B0065007200200062007900200078005200690073006B0079002E0037007A0000009E003200000000000000000000005679707256504E20436865636B657220627920785269736B792E377A2E6C6E6B00006E0008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000005600790070007200560050004E00200043006800650063006B0065007200200062007900200078005200690073006B0079002E0037007A002E006C006E006B00000030000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.7z
0
5600790070007200560050004E00200043006800650063006B0065007200200062007900200078005200690073006B0079002E0037007A0000009E003200000000000000000000005679707256504E20436865636B657220627920785269736B792E377A2E6C6E6B00006E0008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000005600790070007200560050004E00200043006800650063006B0065007200200062007900200078005200690073006B0079002E0037007A002E006C006E006B00000030000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.7z
MRUListEx
00000000FFFFFFFF
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019021020190211
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CachePrefix
:2019021020190211:
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CacheLimit
8192
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CacheOptions
11
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CacheRepair
0
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
MRUListEx
03000000000000000200000001000000FFFFFFFF
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D000000FA3A1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0000000001000000020000000700000006000000030000000500000004000000FFFFFFFF
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
0000000000000000000000002D800000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D00000027BB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
8
78003100000000002E4E957910005659505256507E310000600008000400EFBE4A4ED2934A4EE1932A000000F5DD00000000050000000000000000000000000000005600790070007200560050004E00200043006800650063006B0065007200200062007900200078005200690073006B007900000018000000
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
080000000000000001000000020000000700000006000000030000000500000004000000FFFFFFFF
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8
NodeSlot
95
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8
MRUListEx
FFFFFFFF
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar
Locked
1
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
SniffedFolderType
Generic
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
NavBar
000000000000000000000000000000008B000000870000003153505305D5CDD59C2E1B10939708002B2CF9AE6B0000005A000000007B00360044003800420042003300440033002D0039004400380037002D0034004100390031002D0041004200350036002D003400460033003000430046004600450046004500390046007D005F0057006900640074006800000013000000F00000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
exefile
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\IlceICA Purpxre ol kEvfxl\IlceICA Purpxre ol kEvfxl.rkr
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD05895CC6EC1D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003D00000027BB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
000000000600000009000000F2060400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003D00000071E81500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A000000F2060400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E00000071E81500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\IlceICA Purpxre ol kEvfxl\IlceICA Purpxre ol kEvfxl.rkr
00000000020000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFA08150E16EC1D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000003E00000071E81500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
txtfile
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A00000062520400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000003E000000E1331600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000B00000062520400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000003F000000E1331600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000625204007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000000000000000000000000000000000000000000020000000100000002000000000000000000000000000000000000000000000000000000000000000000000000000000030422C033C9A880A000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB9257502005B0AD8EA37020000000000000000000000000001000000015B0A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A770100000000015B0A00015B0A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA370200005B0A1F00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702B8E937022795F075000000005459EE02E0E93702CD94F0755459EE02C854EE0284EA3702E194F07500000000C854EE0284EA3702E8E93702
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
MinPos1280x720x96(1).x
4294967295
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
MinPos1280x720x96(1).y
4294967295
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
MaxPos1280x720x96(1).x
4294967295
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
MaxPos1280x720x96(1).y
4294967295
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WinPos1280x720x96(1).left
22
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WinPos1280x720x96(1).top
22
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WinPos1280x720x96(1).right
822
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WinPos1280x720x96(1).bottom
582
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WFlags
2
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
ShowCmd
3
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
HotKey
0
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616193
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{137E7700-3573-11CF-AE69-08002B2E1262}
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000B00000048590400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000003F000000C73A1600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000485904007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000003C9A880A000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB9257502005B0AD8EA37020000000000000000000000000001000000015B0A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A770100000000015B0A00015B0A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA370200005B0A1F00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702545900000651A06BC8E93702B69CF0755859EE024C060000E0E93702C854EE02ECE9370211000000B8457800B0457800E0E93702E854EE0250EA00005E51A06B00EA37028291F07550EA370204EA37022795F075000000005459EE022CEA3702CD94F0755459EE02D8EA3702C854EE02E194F07500000000C854EE02D8EA370234EA3702
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616209
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\GlobalSettings\ProperTreeModuleInner
ProperTreeModuleInner
94000000900000003153505305D5CDD59C2E1B10939708002B2CF9AE4100000030000000004E0061007600500061006E0065005F00530068006F0077004C00690062007200610072007900500061006E00650000000B000000FFFF00003300000022000000004E0061007600500061006E0065005F0046006900720073007400520075006E0000000B000000000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane
ExpandedState
06000000160014001F8080A63C324DC29940B94D446DD2D7249E0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F4225481E03947BC34DB131E946B44C8DD50000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F43983FFBB4EAC18D42A78AD1F5659CBA930000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D0000000000000000002000000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F580D1A2CF021BE504388B07367FC96EF3C0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B00000000000000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F50E04FD020EA3A6910A2D808002B30309D0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
3608
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\Desktop\VyprVPN Checker by xRisky.7z
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
0
C:\Users\admin\Desktop
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\Desktop
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
name
120
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
size
80
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
psize
80
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
type
120
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
mtime
100
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
crc
70
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C8000000000000000000000000001C0103000000000039000000B40200000000000001000000
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C8000000000000000000000000003401010000000000160000002A0000000000000002000000
3608
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C800000000000000000000000000200101000000000016000000640000000000000003000000

Files activity

Executable files
3
Suspicious files
1
Text files
150
Unknown types
6

Dropped files

PID
Process
Filename
Type
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exe
executable
MD5: f1e7a9c93ce5ed301e748daafd1c2646
SHA256: 3e1dde1d47bf20aa21f3e1f47f09bed8532249e0282e3f3fa75399fb6ed5a84c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\xNet.dll
executable
MD5: 158defd55a804aa8d4d67bfdf7a4af9c
SHA256: 6c7ec4cc31a2ce0b97703b7a42e3448e9b87d96dda12761ca24d8787ac27cff1
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\MetroSuite 2.0.dll
executable
MD5: 0d30a398cec0ff006b6ea2b52d11e744
SHA256: 8604bf2a1fe2e94dc1ea1fbd0cf54e77303493b93994df48479dc683580aa654
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (15;31)\Locked.txt
text
MD5: e9228166ac064c6f2d6ba408c3b092bf
SHA256: 18e5531dc91483f15e787ce257d923b164b7de4d6e62e2fcb9b3df55cad35551
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\YouTube.lnk
lnk
MD5: c7056a1f92245eec9e5ca71f406c4811
SHA256: bde117478e44d3aa7d55122cf450f10b5af74cfb4ce82ae4fc6fb7dd414c2469
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;46)\Locked.txt
text
MD5: d9b891cc9ae6d3f5b8f615f09e6a55c3
SHA256: 43d537b6e58ade09be01f878f6dba0f6a785665cd1b6e0bc5631692ab5f6fc0d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\YouTube 2.lnk
lnk
MD5: deb42bbec322cd0b8319f788312e28c4
SHA256: b3bb48a747cc7078d4c4c5bd872a270b59f328ae90a85ef3d955b8a4892bff41
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;40)\Locked.txt
text
MD5: 8eef1070903da25e7985f292174feef3
SHA256: 5e086971d26068bdfdb732a97a3e00498cc605b963cb53da319c8dad87164379
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;38)\Locked.txt
text
MD5: edb415969d2b6e9e1ad6f78f1ba048e4
SHA256: edffcc17af3244da0d3cfeff59758cf425bf2a2e799f5f9c764d8679ceee3c0d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;39)\Free.txt
text
MD5: 464337f2259026c2f975b5614bee9e08
SHA256: f17cfab1151326e636cbc71df4eadfc369972d34c08db4598ebfe8ec17a17d6e
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;40)\Free.txt
text
MD5: 88a250c7c3e0d2b8484a639d7a8c461a
SHA256: 9464a994b32f3a9cb3eede96ae21428f83aa707e1a93408a8f89f55ab3cd1ba7
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;28)\Locked.txt
text
MD5: 29a7d706c517a383d315a17d8212c59e
SHA256: bb854b84d770cc31974faf9411feb64f96405e14dd21053d98fd5a36a7dd08ac
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;24)\Locked.txt
text
MD5: a7f270fb454919202b5c3db441f8f8c6
SHA256: c0d69623ccb511ccb8c515fa371ad4fd46b86f21f08ec251672164779f06ed90
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;23)\Locked.txt
text
MD5: ed0f045cf9303d9bb05e6ff15aa9dbfb
SHA256: 241c1e200be03b9ec8787c6d08f53f298cb9587546cceb05fc18f55900098d57
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;19)\Locked.txt
text
MD5: 33453dd4b47fefeb81376a3477ee5172
SHA256: 57c8d4168d9321f55aaa1199bbe7289020317cd4e55c2ac84d52c5fb1b5aa43d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;14)\Locked.txt
text
MD5: 755ab20e50e95090f657a2f0070e985b
SHA256: f3288fda4e3079437a2bb848de8d8725d72eaac5617b6ddc5a812501531daa00
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;13)\Free.txt
text
MD5: 4294487eceb574cc3f6adf3b6db5c442
SHA256: cf655a3e868c523d0f0b13796bd894a1c0129e5008e74d91bd51d0b0680b7e24
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (19;08)\Free.txt
text
MD5: e46a32147cb430fdd4eaf40fa2a6275b
SHA256: 5314fb26d81d695cf957cbf6b7d5cd8b072ff625a346f871fddcd21b008818f7
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;59)\Locked.txt
text
MD5: 6f9b03547474ab076cd165a8597aaff0
SHA256: 6f6f51a49317c006312c16d3c41d68b2debe2913fcf37b28a58551545bdce73c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;52)\Locked.txt
text
MD5: 11fd50bdc677cc3217b3a93f44361161
SHA256: a9b7672a776e9990e9cb9838d9e25f58ff7ef573a8e32dca723442942d0ca347
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;50)\Locked.txt
text
MD5: 1eb168a721fc2d18c1ee0cfa0c93c2ab
SHA256: fb17a9d8f967be1e650a9568238c16d35905becbc9f3ed08951a80f27f5c2f0c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;58)\Free.txt
text
MD5: 740783c083286071a90b74fa9a156f9e
SHA256: 51f50de755b59cb54969e2a9317d435e9bdfb34fde5db9d62acee817c12909b0
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;45)\Free.txt
text
MD5: ed8db731e1ba9c9cf2af987c7916edff
SHA256: f101ea5d7cc1653a93203af1b7d6250ae03a2c736dc4741cc05d489a66b7ba97
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;42)\Free.txt
text
MD5: 5256718c15c8fc52e52f6fee89cba0e0
SHA256: 5a1d6ed57edc9f7ed1b5df580affc704fecbec5c462f7db65d2f27a9a42f06ff
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;43)\Locked.txt
text
MD5: f1be598e22a34e93f82b6b7771b27209
SHA256: 22244c3e0bff7030c21a88ce6f9bdb91d609ffa12460c56ccdb05a9ee9735297
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;40)\Locked.txt
text
MD5: f1623f5880ead293923d737bedbfc987
SHA256: a3bdb67af8b99915e64496387920bcc6043881a82b3b2f91e5810ebb364e15ac
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;27)\Locked.txt
text
MD5: 7c267336f0129e3ff9cb13e26570685e
SHA256: f8c44e057a39a3b2d22c3e355d42c4fd869514c0f5eb31016723d0f4aca70a15
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;17)\Locked.txt
text
MD5: f0f21e9b96bb7868ff95497108808a4b
SHA256: fd9684e4f787bcba215daf57b6d2ce77f68ec016334b9091aa870ed3b952c09a
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;27)\Free.txt
text
MD5: 6d47cbe05653cb0bf53e271e8c7e8fcd
SHA256: 3d8b6462dfdada787f5396452a0f3a8a39c647c6f40fcf3be8d4d2a0f99ccf33
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;19)\Locked.txt
text
MD5: 39ce9a8b33f99155e871e897b0523ccb
SHA256: abb8def3514c73a621fd7cb09e3858cecf1d2f8bb953da235e599d4b51051e45
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;09)\Locked.txt
text
MD5: 117ad598e8f87a36db0902d3e55dbf89
SHA256: 7b2db3114da1853ea33c4aebe5ca215034e80d97b2545cceaa2d69cc46b01d30
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;57)\Locked.txt
text
MD5: 156a2f17556841a4459fbf9da0e5cabd
SHA256: 499f7be278b7fa989773fd865d724487344196876b9cc6b1396691fe4e447475
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;06)\Locked.txt
text
MD5: 53e6089faaf9ea5d2981578961d0ccab
SHA256: f25e358ec45d61e667948298ebade6d7878d6309d99a0dc959ce82ab0cb1bc0d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (18;00)\Locked.txt
text
MD5: dceecc863aa4ce1da0b6b3e062324b97
SHA256: 1ba9bce29a8ad3af4be0b823b5b2a4f01ab9e0dfb2b452367471818903141d7d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;54)\Locked.txt
text
MD5: 7c8e23d7efd585e00a16e525e274f919
SHA256: b1deb394abf6dc39134f0902289baa47734e62dff171390a0f049acae1f9c7ec
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;45)\Free.txt
text
MD5: 8373b0c0e6bf4fda8c6cd3f2322ab3b3
SHA256: bc2e3820589d4923612be9004235f2c1c3fd39747bd41a218bf67dff5d9c8f66
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;40)\Locked.txt
text
MD5: c5dacbd9a44368f33c4fe7d8e5e949ec
SHA256: 7e74e02055e578f241db9e77811ba9f31bd51126752ad894407baaf0cc215bd8
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;38)\Locked.txt
text
MD5: 9f782e417b9d08cc759a26248b8b06ca
SHA256: 055c3e1ba97a7b7c3f630cc8767252d8139650a969dfc29a54382a6937fd45f4
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;43)\Locked.txt
text
MD5: b6ba41e88a8a55e0b05ba3ecb7a88452
SHA256: 09bc5b0ad750ed558716a02ffa0a729d5f7fae503d322df519614cb7837e9c90
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;38)\Free.txt
text
MD5: 15705e4c45a122b698acd6a0543a30da
SHA256: a6a8769a941e5570b17a5f244c597a99fd1903e6889635572817e799a7bb7e8c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;36)\Free.txt
text
MD5: 7c3c9efb9bc63bf58a707f4b7b35e81d
SHA256: becf98b0c16123c9c698e91a9d6b488e014de05504e28ce9990123192214d30a
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;33)\Locked.txt
text
MD5: 5b71386da89a43258a6e56409359aa4b
SHA256: c04222e0d11710e66458ac21c68ced78d44a6d22cebbd8b31571f64a64b39db6
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;30)\Locked.txt
text
MD5: 40773bbb355382a342629488bcde375d
SHA256: d1d72dd3fcafdf9f437a00020be84e7912c8d7e645d570bb9d997a5340dd2be5
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;30)\Free.txt
text
MD5: 1f15113dc2c18bf80582c75154bb4efb
SHA256: 11cb310e4b2759cb8821a71515ccd51f97ee8cfb24a28d3f4baa7811c74ba83c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;29)\Locked.txt
text
MD5: 0d4cff580e8b67a8507e751e7c29fde7
SHA256: fd3c0aca66bfd540b67487d4b795f2cf1d7980009fd1a56e0739c5519827dd67
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (17;21)\Locked.txt
text
MD5: eb68991506f85c291906cd316ba08637
SHA256: 7225bdcb3403ceac6f5fa9e7211f347ba2eef1f8185606143304a1b97712e37a
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (13;15)\Locked.txt
text
MD5: ce2bc14dfc9b75bd43b47b7c628b0179
SHA256: 3dc45a2ce2ee579e85e4af298118b74f28cab7622fb5ac994659bf8cb76d5d6b
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (12;45)\Locked.txt
text
MD5: ce2bc14dfc9b75bd43b47b7c628b0179
SHA256: 3dc45a2ce2ee579e85e4af298118b74f28cab7622fb5ac994659bf8cb76d5d6b
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (12;17)\Locked.txt
text
MD5: 85c59b1666eb812f0cfc529b533bef40
SHA256: fc81da77a244916ed4645e8d175d77f3b4afff88a41601f5c5326e8604f08a20
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (12;37)\Locked.txt
text
MD5: e15f8efcef8375a2c957e417ef78d641
SHA256: 52eef8cfd4808b1edb9ae6c4bc149cfb1810038a9b07d967a5a96984ee10eeef
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (12;15)\Locked.txt
text
MD5: c9651241fc7639291e876b5ef2a43582
SHA256: eab14de49383c80749e40bc34b644c6fb799611da25ee58131671ac4553f32af
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (11;56)\Locked.txt
text
MD5: 96c4804b45ef28724a910b7ab1650e03
SHA256: 26665bdd92139bc1a6f535094a2801bfff916ab7bc9dd2276f06027600520f85
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (11;46)\Locked.txt
text
MD5: 3a1f7683c9785570f161b26827d6b43a
SHA256: f608749ec6d9bf3b6618e6aaa4a4f0ca26068409a58eb7805b5d4d841c07a7f5
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (12;08)\Locked.txt
text
MD5: 40e59646e33b392da4ebe4f3d6ab986f
SHA256: b468686d5f0f52dfa42e2222a09c27be4c680e651a0e4aab95937b12bb4e9c23
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (11;47)\Free.txt
text
MD5: 57f80e61509bd954d0eb12523dc4ab55
SHA256: 2ea5c3f435f61cb1ae80bf789048f25aade57b58978ffeccd04e49049736b44c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (11;35)\Locked.txt
text
MD5: dc30ea27c79a98901b741eeae7bbb334
SHA256: 3f46e5ad4731e43d3459a7d7da5dec405c1373745d0f185a0292797a7d5907fc
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (11;17)\Free.txt
text
MD5: 8a78df666b9ab120d76643a2a5f3debe
SHA256: 513a7cf6fe88bec47d33ffa10017ae2a2fbcd65c8b00cd948901bf3c9a77229d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (10;49)\Free.txt
text
MD5: 7a25cb5dffc0dc2fb3489fefd5812654
SHA256: 36b5188cc666f18863f8dadeb2ae1dc9e0119539c1010ceb393dbfc14f2c8098
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (10;24)\Locked.txt
text
MD5: c9651241fc7639291e876b5ef2a43582
SHA256: eab14de49383c80749e40bc34b644c6fb799611da25ee58131671ac4553f32af
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (10;06)\Locked.txt
text
MD5: 4c3a533567097021781334cd47eeb6bc
SHA256: 27f4198cd535fb653ded7d899ff9d5f94a575f610e9cbe7b01cc1d754b937e2c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (08;31)\Locked.txt
text
MD5: a9eabb2e0bf7f38cdd5de0ac32820a6e
SHA256: 32a30c554481ae1cf1fa9963191aaea5854b3cc430a0821f34eb99700f7badd2
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (08;46)\Locked.txt
text
MD5: 8126a6ef465786387caa4474d67bf2f4
SHA256: 87e5ecce620c3ccd8c1e9ebe8ae4035de4968b6650d9ea2f2f6848aab8ae0275
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (07;57)\Locked.txt
text
MD5: 60cbc7d4510af73e74807e4b645d78cd
SHA256: 3cda34aa7c1cb59722c42e7518b7176111d742101b6453291d8ddb0b7d225b52
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (07;10)\Locked.txt
text
MD5: f8f4b810820d73deb93159a458a3f265
SHA256: cb4b707f731981b22c88b7150614558521cbfa6ddddc1ef5f3fe13470f4ba587
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (06;56)\Locked.txt
text
MD5: d13539785f17306d77770cb480e52255
SHA256: 4f92c2c7e5aff9edaccde82cf5fe6fe559897d1aa40859a9ec90645c875ffcbe
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (06;35)\Free.txt
text
MD5: 1f0d8621d1719f43e2d935da777c9578
SHA256: ba72999e3a59869f1a6033af714c53f2dfc8faa0d4dde27667cdab0f2b7e1621
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (06;45)\Locked.txt
text
MD5: 607a014d6db9d41f26bba6f4ce80d216
SHA256: af2aae9b06f1c5b1a4b8ba2ad76e298c5eb58d6f33dc569f025f2f51f7a9a96c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (06;30)\Locked.txt
text
MD5: 16b22913646e7479100e1662de23d2c2
SHA256: ec10243a611b5a67eb3717561dac251e5d8e2c578f3396f4a5cb12cee99e25d6
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (06;29)\Locked.txt
text
MD5: c064b58bad3c5e2ee8073f2f07211fee
SHA256: d41544c7757e2c9a89b298b0633e8da9a1e9a2bfad9a2b76f34193d208d8bc5b
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (06;19)\Locked.txt
text
MD5: b065a125386437e832797c19d4f5c342
SHA256: 0c70d3528d1f557bf9549a974eddd2e9e62b03482f6b30dbdc8c38f775ee9f8d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (04;01)\Free.txt
text
MD5: d6d71d34f049e1d9e5d8d7824f99dd3d
SHA256: 1be84284ef80cd233380e4a7280715dbf7bee7fc2ba24f5e2628bd515b5d12b5
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (04;08)\Locked.txt
text
MD5: 51e7321bb553bc3103fb6881b3a72900
SHA256: 24894f57a1432821329c6f0a08b025a569ebbd0c627856e3024c7a1a77210bc2
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (04;00)\Locked.txt
text
MD5: caadb25adb306d3c25b5c0b817ccdda1
SHA256: 7476625910feb7d83aae86edfd49cd1cb8d5ec84674c9c2b02c1dcc4d6c48aff
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (03;44)\Locked.txt
text
MD5: b8afee75e1c69ab00ec5fbf1e8e39995
SHA256: cc477c776fd52f3a4314ba508ad417d2bad3b36445af98b4cfc69c562a35f163
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\29 януари (03;48)\Free.txt
text
MD5: ec1399c6d56df4b0d17968260096c850
SHA256: a9b86f07b97805fb10d105be0239701a1239042d1c758163160305e7d5c9999f
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (16;41)\Free.txt
text
MD5: 94bfde14d105d1a07379c1a6a3a465c6
SHA256: 7f0ecff52b0dc70ba93cf0cf354da8bc8faf295d5990a4c80035e3d4c6da0788
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (15;44)\Locked.txt
text
MD5: bca46a834930439faa2ac4e8ca923427
SHA256: 85a06a2eee6539f2e56634ff22281680199c319d99ceb709b802afa5de91e6c1
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (15;46)\Locked.txt
text
MD5: 1ff8f712a4b340cae67aa4a3aa6b7e56
SHA256: 49d8c7a46e3ad7a61ed0014209101b59793eb6e7d130d68d8c3b79a6a17c445a
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (15;32)\Premium.txt
text
MD5: a463d0518c45da2027f9ddc5d739c901
SHA256: c0ac39b83d1c6e207b1bcb23bcd2429eb5ef803eae64d7054b0cda96b4501d5e
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (15;21)\Premium.txt
text
MD5: df8b5dd9e3029f47cf747010d0a42f28
SHA256: eebb931142e19ba60701273f8773e3663fd231df7212630c25cec8e2865591d7
116
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
automaticdestinations-ms
MD5: f5f7ef7748660b26680da476ead3b1a5
SHA256: bec9fac8e417cc5c5eeb8f1b438c9c0bb63dfaadde79e63cd3ff364a1aa39ad7
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (15;21)\Free.txt
text
MD5: 57f80e61509bd954d0eb12523dc4ab55
SHA256: 2ea5c3f435f61cb1ae80bf789048f25aade57b58978ffeccd04e49049736b44c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (14;10)\Locked.txt
text
MD5: c75ee9f5f74ee8b26db4601e4e08c44e
SHA256: cc97081c9c52bb024f729793060ad50db5ee71027d5fc10f1660261c0b14e42d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (14;47)\Free.txt
text
MD5: 82441f2427f8557b765a6f35dc4f626d
SHA256: 9f2a68a10241bbcbee90a963bcd518490fdb84eae04e1fe058c5c0732c7d7d8b
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (14;02)\Locked.txt
text
MD5: b689e935c5bc20ccf0c1f38d036f76ea
SHA256: 2555ab27c913d2daf63d1142e69494139d585e2c655caf6adf2c24f2fb3a2764
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (13;30)\Free.txt
text
MD5: d6d71d34f049e1d9e5d8d7824f99dd3d
SHA256: 1be84284ef80cd233380e4a7280715dbf7bee7fc2ba24f5e2628bd515b5d12b5
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (13;30)\Locked.txt
text
MD5: e5f14b3186871b7f2278be59afb3afab
SHA256: cbdde7d48b9a72f780e84fe645780ec40a3398619483825f7179640f9c0ad227
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (13;40)\Locked.txt
text
MD5: 130de8754cee2d21450cbc91331f2653
SHA256: 0ca8e46066219d2b2ca428b128006cc28c6c8a9d23e1417f256c56df5c5fad1f
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (13;26)\Locked.txt
text
MD5: 0e93382c7bc92c0092eb062fc7732af0
SHA256: 568604668039c344d79f7027c1e861cc327e21d3e3ccec0618c0275930adbe81
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (12;28)\Locked.txt
text
MD5: bdbe5844c5a580ea0b4711be5068c29c
SHA256: 7f64ff95ccf08198c683012a99068e0ed8299be1c4e69dd4ea4b8a5fd0f69347
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (13;03)\Locked.txt
text
MD5: 5fd32d27fdce2c1ccf83013a8f0a20b9
SHA256: 06b822d58027cfe2ff5491a9d28e8afa5ac6f00485d7e978d5edc4337a9a62d6
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (12;27)\Locked.txt
text
MD5: cc5a8b3c2f331696790e942f6bed014b
SHA256: 6a0b38dba0a911f0fa3ceba9f030b71f9d9e6e902b04b463882f001e7dafdb87
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (11;48)\Locked.txt
text
MD5: 549e9c8d3f3f9792423d5d15c7fff881
SHA256: 9e418661d0f9f9a0f1b13c5e1005e30923b7193b671daf64ed574cdb1ea9e6bb
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (12;18)\Locked.txt
text
MD5: e8c3cb7f63de5fb7fae1f03dcf00def5
SHA256: 68e109d1714fa69969db37f5c31e10b5a0d5d767956779c022ff0751e654899c
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (11;50)\Locked.txt
text
MD5: e75cd7c32b77b22b1401dceeca4c8eb1
SHA256: 8bcc8dbc371214ebe7816247bd16f8b62022dbd691c4ab2d08fdf4aab1a67871
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (12;12)\Locked.txt
text
MD5: 13024fa9438b4abdc17720c984040058
SHA256: 07f3671aaad450656fad138a763a44dfaff83fe163a42bee3e38c8cd36807e14
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (11;32)\Locked.txt
text
MD5: 2c2911ff693ea0f3932b52e572f6a7c3
SHA256: d522e4e3e7a23cb5191f805923fd9ec22b8db43a3c59b40df0797c0c2cefabb8
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (10;08)\Premium.txt
text
MD5: 571425809a2f5991431f83830263ac6a
SHA256: 560a3b6ed8adcb8733a29336079847979a45baf9690229fab1372fbe6fb719ef
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (11;26)\Locked.txt
text
MD5: 065505cab283166cff73105e54e31667
SHA256: d7a09f781b74236387e1b172fd807ed6037c6bc83b173e34ead74df6c083e5b7
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (09;52)\Locked.txt
text
MD5: 059dc07c90bd9c28af548e9149391372
SHA256: e32bb4cbfcf3e1e3d96f3bb0ee0462980bb82a0646b48c729cf6724591cee133
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (10;43)\Locked.txt
text
MD5: c6a8c268492bde3336a25bc674546a60
SHA256: 4bb162ed9c51a5c67738ee3bbd1cf9ffedb85b8b5e63f5931195e98b9f2a7dcf
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (07;22)\Locked.txt
text
MD5: 7840baea47854ac1d3f507deba3458cb
SHA256: fc0a87135de7f2451a966563e95e4426f38b2ce8b8c1bef0820268d9ee0976c9
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (09;19)\Premium.txt
text
MD5: 68678e23ad7894ac330d03a4062c1930
SHA256: 84ffd41d4b1dc1548a7c3656ea63a61c5585565ba91c33cb831024d54a082661
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (09;32)\Locked.txt
text
MD5: eda4c2307ec43e9e3559bbcc16ba6efe
SHA256: d6ff6b51f142f7bdf5fa0fa69b15179e8bde2a0edf8ac9fea61980ac3b4f79c6
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (07;12)\Free.txt
text
MD5: 771b95ac7b7e80e422781393b8efe3bf
SHA256: f2d3cc9e54a4ec639196b4a804afed4f2a14051597738e05f17dd0162c0dfd59
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (06;54)\Locked.txt
text
MD5: 4ada64cc1e2836d781ec47afe347de98
SHA256: 870f303b80ae67cab55f92d5c8084dfb49d6c62efed8e627fba1e8bf42a65625
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (06;53)\Locked.txt
text
MD5: c519f978563624cf9c46f6f50b8d8d0d
SHA256: 1c3506cc8a56d4f556a9c9d23094e4839a4a6ffe6118eeb1bd8e38c994247dd5
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (06;51)\Locked.txt
text
MD5: e489a54d0e6488ef7919a0605a9e02d8
SHA256: e92d906de3e5443607536bb8689973acfbca5a5ee766d75b98ca780ff967da7b
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (06;42)\Locked.txt
text
MD5: 7eeb83d1b06957cbdaa0c576b851f773
SHA256: 8e00c4911efd5f45ea25c98c4a50c19c7cb2f442b942e7ae393ac551950b7026
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (06;47)\Premium.txt
text
MD5: d7d01389d3ac30a071df1bd8111fbd76
SHA256: d05e7e7e805d1c3dda6234524b05c7ec2fc7a8bd0b986c95bd5df661f170a42a
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (06;27)\Locked.txt
text
MD5: 12951c456e86a005af1a7d135fa17dc7
SHA256: 54a28f56b30ff101998f878b9887e04e7579035da4526745ec5a3e1c3b440dc1
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (05;45)\Locked.txt
text
MD5: 185942f2738be546b118f5ea29219597
SHA256: 5761085e8e227735a188f0de0f001ab895210ed38262013753de375fe848c14d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (05;59)\Locked.txt
text
MD5: cc90e78ffd6733ed6f959dc831d160e2
SHA256: e25752421a9846c3d6f2f0a6fc3a0779423a71e26e2c957cbff1df305a2a8687
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (05;22)\Locked.txt
text
MD5: e2c2c5721a7edd456cc6db428e1ab4db
SHA256: fa74b7481bfc7da8a878163fa1cadb38a44edd770a98c8b5e369b04dde6609a3
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (04;28)\Free.txt
text
MD5: 9af2421ee6cde57b4e71073075ff8828
SHA256: 41fe58dea3fbbf738adc4bd073ef7a3eb4c3624c4fc69b1439e8d99257903375
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (05;09)\Free.txt
text
MD5: a673b3b6b6db10a1d98db46e61db48f8
SHA256: b266b3f26696ae4f24ddf0a848c32b671e5156f6234f2845e02e57c3ef3101a2
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (04;33)\Locked.txt
text
MD5: b8f2a10ec5d7eea3a20e00dbaaa406e1
SHA256: 9f6ac3536eb82b9396b65c316bf1cd933fd0d200b2c757a3c7adcf8de3f5dedd
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (03;59)\Premium.txt
text
MD5: 3231232af10cd6edbc9f1b90c815ca92
SHA256: 110ac6cc75b2d67251d7f5e50873f064693d59d57b7fe1746dc1f77ae49d61be
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\25 януари (08;09)\Locked.txt
text
MD5: 60361bb5a60f06e05f701407d9bb93cd
SHA256: 94ed1da37736cbb06d777d2fa484dfeb66d9dac63fdd96f7965536b41fbf4de4
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\25 януари (10;07)\Locked.txt
text
MD5: f77c23eea4c5e5ebf936d9e620c21abe
SHA256: 81ba775df83f62a939bf702ceecd800bb38bd534436dd9ccbebcd10e4c290b22
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (03;40)\Locked.txt
text
MD5: c090ae8d41678c24d5c97538d0d733a5
SHA256: 490575fd0062a045682f420ae856c41e901e4227fb78ce00748fced514b1cd55
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\27 януари (03;37)\Premium.txt
text
MD5: 51acaa693020e0d343fa44fc127bcf11
SHA256: 2657a86d823176feec93b07821697902a3b1f25a2a78b9a1c6528a1888fa48d2
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (09;12)\Free.txt
text
MD5: dc76169a8c3ea2c947f2e5fe2a86ebb4
SHA256: f4221682cfae46144aff070ad9c5e2ad59f835c74f3d01e68169a82fea0fbf88
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (08;56)\Premium.txt
text
MD5: e808438f5f0f93ce87bd39b6ad1e51dc
SHA256: 7fb702170bac0520f0dab4dc74c511a51f2c2390f7f6c1c552db97ab4a791113
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (09;01)\Locked.txt
text
MD5: 37ff6fac43db62ad673998d2f56d86c9
SHA256: f329783236671b912cac94fa74104c8412603725f481a0d8701c6dae20ea11c0
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (08;54)\Locked.txt
text
MD5: 6c366b86b271b27d919ccd46db6daad1
SHA256: 3cbb2f85a8fe741741f84561d61ef665422e8e2928d1e1bf4951fb33e6e377ca
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (08;48)\Locked.txt
text
MD5: 84ea3747c264382f9ace8fc8098db537
SHA256: d94ee5c154233c0c4bfa77edae717290a15d445b338c7b055730a2b9068c56f0
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (07;22)\Premium.txt
text
MD5: 202da722b6358acc859381b4fe353519
SHA256: 000b49e1638cb6f1d7aa1d1bc2fb81629dc3ebaeddef69772ef4706a50b6f5be
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (07;34)\Locked.txt
text
MD5: 7840baea47854ac1d3f507deba3458cb
SHA256: fc0a87135de7f2451a966563e95e4426f38b2ce8b8c1bef0820268d9ee0976c9
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (08;22)\Locked.txt
text
MD5: cc7130f76dbcff5b7411b07fb7775dc8
SHA256: be85d4948603da871de8871e0b353d9d8178ea5f3e7377c78c4a72627af697f9
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (07;22)\Free.txt
text
MD5: 771b95ac7b7e80e422781393b8efe3bf
SHA256: f2d3cc9e54a4ec639196b4a804afed4f2a14051597738e05f17dd0162c0dfd59
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (06;57)\Locked.txt
text
MD5: 4ada64cc1e2836d781ec47afe347de98
SHA256: 870f303b80ae67cab55f92d5c8084dfb49d6c62efed8e627fba1e8bf42a65625
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (06;56)\Locked.txt
text
MD5: c519f978563624cf9c46f6f50b8d8d0d
SHA256: 1c3506cc8a56d4f556a9c9d23094e4839a4a6ffe6118eeb1bd8e38c994247dd5
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (06;53)\Locked.txt
text
MD5: e489a54d0e6488ef7919a0605a9e02d8
SHA256: e92d906de3e5443607536bb8689973acfbca5a5ee766d75b98ca780ff967da7b
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (06;49)\Premium.txt
text
MD5: d7d01389d3ac30a071df1bd8111fbd76
SHA256: d05e7e7e805d1c3dda6234524b05c7ec2fc7a8bd0b986c95bd5df661f170a42a
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (06;24)\Locked.txt
text
MD5: 12951c456e86a005af1a7d135fa17dc7
SHA256: 54a28f56b30ff101998f878b9887e04e7579035da4526745ec5a3e1c3b440dc1
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (06;33)\Locked.txt
text
MD5: f65dbe7cd63eed54e4ece9c12e2a0719
SHA256: e0876ee69688d4ef9f4413b3240ed9316982cc82beaa4caf828edad1b0c31c2f
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (06;09)\Locked.txt
text
MD5: fa21433651d845ebe119be92f4ad438e
SHA256: 9d09439389c88dafa154ec6df3d3541cc817a4066cda87018e5e1d2f499db7dc
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (06;19)\Locked.txt
text
MD5: d5803796841afb52c33114854bfe1f4b
SHA256: 5fc7a93209cad68a2636dcde7bc8b20e56cec871b6c900f207008aceac5afcaa
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (05;48)\Locked.txt
text
MD5: cc90e78ffd6733ed6f959dc831d160e2
SHA256: e25752421a9846c3d6f2f0a6fc3a0779423a71e26e2c957cbff1df305a2a8687
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (05;57)\Premium.txt
text
MD5: f9c685768ac4baa36faa0be225679bb9
SHA256: 8216582c6734b3a13e6b34115c3e6f007c380e7f13de70ba36e7f9de541a28ba
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (05;29)\Locked.txt
text
MD5: 185942f2738be546b118f5ea29219597
SHA256: 5761085e8e227735a188f0de0f001ab895210ed38262013753de375fe848c14d
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (05;27)\Locked.txt
text
MD5: ab461c38c3551d73fba14ef2b795b10e
SHA256: a894c632dc82710812d8e3a050d493c15f9bf4eb5a9f8ae598bccaed3b284148
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (05;00)\Locked.txt
text
MD5: e2c2c5721a7edd456cc6db428e1ab4db
SHA256: fa74b7481bfc7da8a878163fa1cadb38a44edd770a98c8b5e369b04dde6609a3
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (04;48)\Locked.txt
text
MD5: ec9429b66d27ff7ba1ff9e386d328ddf
SHA256: 76b789821f649bcaf8fa58bc81c2295f9c4b50d9c67b4457dfad5b258c227ae0
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;57)\Locked.txt
text
MD5: b8f2a10ec5d7eea3a20e00dbaaa406e1
SHA256: 9f6ac3536eb82b9396b65c316bf1cd933fd0d200b2c757a3c7adcf8de3f5dedd
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (05;15)\Locked.txt
text
MD5: e65fd0175f90189cd8f7d1f6f8939d58
SHA256: 141c458397c93cd039f5ce4b4108a5953a66267036d314e1c4a2ad90c22b63bf
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;56)\Locked.txt
text
MD5: 08e1ce2abb3c374dc05a7f62d9823694
SHA256: 4e528856873bb771de4692697a671a2496f687a52f047708ad411e94aa8bccc4
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;15)\Free.txt
text
MD5: d456ff1295ade432b9d844014bd44ab8
SHA256: c16d913fbb84e16cfa399fa50ec955ad9a968df7e11b0983390f93a28258cba8
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;16)\Locked.txt
text
MD5: 4aad9ea5f618a9fa02847b6a33324464
SHA256: 0f12bf34a7dc5ed081ad63aaf2c018cf8beab06964b383fc3661aed6864a0b50
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;51)\Free.txt
text
MD5: 9af2421ee6cde57b4e71073075ff8828
SHA256: 41fe58dea3fbbf738adc4bd073ef7a3eb4c3624c4fc69b1439e8d99257903375
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;20)\Locked.txt
text
MD5: 3ec67c15eea8cc92dbe3523cffc46fe3
SHA256: 1725e2ef26652f14d3a65a15a074afc15252b1c5ea59ff0a2d1a98cbba26ea3e
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;13)\Premium.txt
text
MD5: 3231232af10cd6edbc9f1b90c815ca92
SHA256: 110ac6cc75b2d67251d7f5e50873f064693d59d57b7fe1746dc1f77ae49d61be
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Readme.txt
text
MD5: 6daebb9555014ea4ca81161fdf5955d9
SHA256: 63c60f2a04a1f40d3784f7818a816d111e3a9522f526bcca891edc2bb5e774fc
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (02;49)\Locked.txt
text
MD5: c090ae8d41678c24d5c97538d0d733a5
SHA256: 490575fd0062a045682f420ae856c41e901e4227fb78ce00748fced514b1cd55
3608
WinRAR.exe
C:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (02;45)\Premium.txt
text
MD5: 51acaa693020e0d343fa44fc127bcf11
SHA256: 2657a86d823176feec93b07821697902a3b1f25a2a78b9a1c6528a1888fa48d2
116
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019021020190211\index.dat
dat
MD5: 6493d7203f8286bf8b129a35cf44664e
SHA256: 27343e5626f3d7afab1aec0a00cf0d301cd07dfe6eb8d8d9ec52e0a902b5f44c
116
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\VyprVPN Checker by xRisky.7z.lnk
lnk
MD5: 0013ed8bb5f709af785c01792ec50637
SHA256: 2cf731cc13a0820e8c2eae23364c78acce4ac4f3ed63ba1905ee11004d67ffa8
116
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-ms
automaticdestinations-ms
MD5: db8c758e8c2adda398840846302613a5
SHA256: 9df02dd5a0b3e67f4aaee7fe8afe80b1ca97fdb05535eb285d3dab776937bed1
116
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
binary
MD5: d67095404f0e2d8362419d8393ed6ead
SHA256: 45f8b74ac8fe4cd19499d3b3b9e785ea03b7ea68331ea62489a3abfe496cc865

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

No debug info.